peter bassill · operator
$ cve CVE-2026-12569 JSON

CVE-2026-12569 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 46% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2026-06-28.

Description

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS46.05% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-20
On CISA KEVyes — remediate by 2026-06-28
Public exploitnone known
Published2026-06-18
Last modified2026-08-01

CISA KEV

NamePTC Windchill and FlexPLM Improper Input Validation Vulnerability
Added2026-06-25
Due2026-06-28
Vendor / productPTC / Windchill and FlexPLM
Ransomware useknown

Affected (2)

VendorProduct
ptcflexplm
ptcwindchill pdmlink

References

→ the Explorer  ·  watch your stack  ·  NVD