logo

CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue

ID: b3568f66-79a3-5fd2-b5fa-2a56e96019d6

STIX ID: report--b3568f66-79a3-5fd2-b5fa-2a56e96019d6

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-06-26

Date Updated: 2026-06-26

Author: [email protected] (The Hacker News)

...
...

CISA and PTC have warned of active exploitation of CVE-2026-12569, a critical deserialization-based RCE in PTC Windchill PDMlink and FlexPLM (CVSS 9.3). Attackers are deploying JSP web shells (matching /Windchill/login/[0-9a-f]{16}.jsp) and using identified IP command-and-control hosts; the advisory provides IoCs (IPs and a suspicious JSP file hash), detection steps, and immediate mitigations including firewall blocks, log searches, filesystem scans, and WAF/IDS rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.