Critical RCE vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM allows unauthenticated remote exploitation. Patch immediately.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| flexplm | * | 11.0m030 | vulnerable |
| flexplm | 11.1m020 | 11.1m020 | vulnerable |
| flexplm | 11.2.1.0 | 11.2.1.0 | vulnerable |
| flexplm | 12.0.0.0 | 12.0.0.0 | vulnerable |
| flexplm | 12.0.2.0 | 12.0.2.0 | vulnerable |
| flexplm | 12.1.3.0 | 12.1.3.0 | vulnerable |
| flexplm | 13.0.2.0 | 13.0.2.0 | vulnerable |
| flexplm | 13.0.3.0 | 13.0.3.0 | vulnerable |
| windchill_pdmlink | * | 11.0m030 | vulnerable |
| windchill_pdmlink | 11.0m030 | 11.0m030 | vulnerable |
| windchill_pdmlink | 11.1m020 | 11.1m020 | vulnerable |
| windchill_pdmlink | 11.2.1.0 | 11.2.1.0 | vulnerable |
| windchill_pdmlink | 12.0.2.0 | 12.0.2.0 | vulnerable |
| windchill_pdmlink | 12.1.2.0 | 12.1.2.0 | vulnerable |
| windchill_pdmlink | 13.0.2.0 | 13.0.2.0 | vulnerable |
| windchill_pdmlink | 13.1.0.0 | 13.1.0.0 | vulnerable |
| windchill_pdmlink | 13.1.1.0 | 13.1.1.0 | vulnerable |
| windchill_pdmlink | 13.1.2.0 | 13.1.2.0 | vulnerable |
| windchill_pdmlink | 13.1.3.0 | 13.1.3.0 | vulnerable |
Consult PTC security advisory CS473270 to download and apply the specific Critical Patch Sets (CPS) for your version of Windchill PDMLink or FlexPLM.
Ensure systems are upgraded beyond the identified vulnerable versions, including 11.0 M030, 12.0.2.0, and 13.1.3.0, following the specific patch path provided by PTC.
Limit network access to Windchill and FlexPLM interfaces to authorized users via VPN or internal networks, and implement strict firewall rules to block untrusted external traffic.
Conduct a forensic triage of PLM server logs for signs of suspicious Java deserialization activity, unauthorized remote command execution, or unusual child processes.
"Monitor web server and application logs for unusual Java deserialization errors or unexpected incoming traffic to PDMlink endpoints. Look for suspicious child processes spawned by the PTC application service, such as cmd.exe or /bin/sh. Security teams should also deploy network signatures to detect common deserialization gadget chains (e.g., CommonsCollections) being sent to the affected PLM ports, which may indicate an exploitation attempt."
Experience superior visibility and a simpler approach to cyber risk management