PT-2026-50580 · Ptc+1 · Windchill Pdmlink+2

CVE-2026-12569

·

Published

2026-06-18

·

Updated

2026-07-27

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PTC Windchill PDMlink versions prior to 11.0 M030 PTC FlexPLM versions prior to 11.0 M030 CPS (affected versions not specified)
Description A critical remote code execution (RCE) flaw exists due to the deserialization of untrusted data. Deserialization is the process of converting a data stream back into an object, which can be exploited if the input is not properly validated. This issue allows unauthenticated attackers to deploy JSP web shells to execute remote commands and access the file system.
Threat actors linked to the Cl0p ransomware group have actively exploited this flaw in the manufacturing, automotive, aerospace, and retail sectors to steal sensitive engineering and design data. The attack chain often begins with a pre-authentication information disclosure via the FlexPLM WSDL endpoint, which is then used to exploit the RCE flaw in Windchill to move laterally through enterprise networks and deploy ransomware.
Recommendations Update PTC Windchill PDMlink to version 11.0 M030 or later. Update PTC FlexPLM to version 11.0 M030 or later. Restrict access to the FlexPLM WSDL endpoint to minimize the risk of initial information disclosure.

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12569

Affected Products

Cps
Flexplm
Windchill Pdmlink