PT-2026-50580 · Ptc+1 · Windchill Pdmlink+2
CVE-2026-12569
·
Published
2026-06-18
·
Updated
2026-07-27
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PTC Windchill PDMlink versions prior to 11.0 M030
PTC FlexPLM versions prior to 11.0 M030
CPS (affected versions not specified)
Description
A critical remote code execution (RCE) flaw exists due to the deserialization of untrusted data. Deserialization is the process of converting a data stream back into an object, which can be exploited if the input is not properly validated. This issue allows unauthenticated attackers to deploy JSP web shells to execute remote commands and access the file system.
Threat actors linked to the Cl0p ransomware group have actively exploited this flaw in the manufacturing, automotive, aerospace, and retail sectors to steal sensitive engineering and design data. The attack chain often begins with a pre-authentication information disclosure via the FlexPLM WSDL endpoint, which is then used to exploit the RCE flaw in Windchill to move laterally through enterprise networks and deploy ransomware.
Recommendations
Update PTC Windchill PDMlink to version 11.0 M030 or later.
Update PTC FlexPLM to version 11.0 M030 or later.
Restrict access to the FlexPLM WSDL endpoint to minimize the risk of initial information disclosure.
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cps
Flexplm
Windchill Pdmlink