logo

PTC Warns of Critical Windchill, FlexPLM Flaw Enabling Remote Code Execution

ID: 12f37193-de88-51f5-9a38-4726368d012c

STIX ID: report--12f37193-de88-51f5-9a38-4726368d012c

Feed Name: The Cyber Express

Threat Score
80/100

Date Published: 2026-03-25

Date Updated: 2026-05-05

Author: Ashish Khaitan

...
...

**PTC advisory:** Critical deserialization-based remote code execution (CVE-2026-4681, CVSSv3.1 10.0) affects multiple Windchill PDMLink and FlexPLM releases; PTC published Apache and IIS workarounds, recommends disconnecting or shutting down unpatched instances, and supplied IOCs (file names including GW.class and payload.bin with SHA256, JSP artifacts, user-agent and suspicious HTTP request patterns) for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.