CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
ID: b3568f66-79a3-5fd2-b5fa-2a56e96019d6
STIX ID: report--b3568f66-79a3-5fd2-b5fa-2a56e96019d6
Feed Name: The Hacker News
Threat Score
CISA and PTC have warned of active exploitation of CVE-2026-12569, a critical deserialization-based RCE in PTC Windchill PDMlink and FlexPLM (CVSS 9.3). Attackers are deploying JSP web shells (matching /Windchill/login/[0-9a-f]{16}.jsp) and using identified IP command-and-control hosts; the advisory provides IoCs (IPs and a suspicious JSP file hash), detection steps, and immediate mitigations including firewall blocks, log searches, filesystem scans, and WAF/IDS rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
