logo

Critical RCE Vulnerability in PTC Windchill and FlexPLM Under Active Exploitation

ID: 84081238-9995-5d56-a8b9-641f984aa5f9

STIX ID: report--84081238-9995-5d56-a8b9-641f984aa5f9

Feed Name: ThreatCluster

Threat Score
88/100

Date Published: 2026-06-29

Date Updated: 2026-07-02

...
...

Hackers are actively exploiting a critical unsafe-deserialization vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM that enables remote code execution; PTC released patches on June 17, 2026 and CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 25. With a CVSS score of 9.3 and reported active exploitation affecting industries including defense and aerospace, indicators of compromise have been shared and organizations are strongly urged to apply patches and enhance monitoring to mitigate data theft and system compromise risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.