logo

PTC warns of imminent threat from critical Windchill, FlexPLM RCE bug

ID: 863a2f1d-642a-550e-9170-0b3dad4320a5

STIX ID: report--863a2f1d-642a-550e-9170-0b3dad4320a5

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-03-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

PTC disclosed a critical RCE vulnerability (CVE-2026-4681) in Windchill and FlexPLM that affects most supported versions; patches are in development while the vendor has published mitigations (Apache/IIS rule to block the affected servlet path) and IoCs including webshell filenames (GW.class, payload.bin, dpr_<8-hex-digits>.jsp) and suspicious request patterns. German federal police (BKA) have urgently warned organizations and contacted administrators directly, citing a credible imminent threat to exploit the flaw, and PTC recommends prioritizing mitigations for internet-facing instances or disconnecting affected systems until patches are available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.