PTC Warns of Critical Windchill, FlexPLM Flaw Enabling Remote Code Execution
ID: 12f37193-de88-51f5-9a38-4726368d012c
STIX ID: report--12f37193-de88-51f5-9a38-4726368d012c
Feed Name: The Cyber Express
Threat Score
**PTC advisory:** Critical deserialization-based remote code execution (CVE-2026-4681, CVSSv3.1 10.0) affects multiple Windchill PDMLink and FlexPLM releases; PTC published Apache and IIS workarounds, recommends disconnecting or shutting down unpatched instances, and supplied IOCs (file names including GW.class and payload.bin with SHA256, JSP artifacts, user-agent and suspicious HTTP request patterns) for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
