CVE-2026-12569
Remote Code Execution (RCE) vulnerability in Windchill PDMlink
Description
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030
In plain language
AI Act nowCVE-2026-12569 is a critical security hole in PTC Windchill PDMlink and PTC FlexPLM that lets an attacker run code on your server over the network—no login required—so typical small businesses should treat it as urgent if those products are exposed to the internet.
CVE-2026-12569 is an unauthenticated remote code execution flaw in PTC Windchill PDMlink (and PTC FlexPLM) caused by unsafe deserialization of untrusted input, enabling arbitrary code execution via crafted network requests; it is confirmed in CISA KEV with real-world exploitation and web shell deployment reports.
What to do now
- Check whether you use PTC Windchill PDMlink or PTC FlexPLM and identify your installed version.
- If you run Windchill PDMlink, upgrade to version 11.0m030 or later.
- If upgrading isn’t immediately possible, follow the vendor’s mitigation instructions for CVE-2026-12569 and reduce exposure of the service (especially if it can be reached from the internet).
- Hunt for compromise indicators consistent with web shell activity and confirm the system has no unauthorized files or unexpected scheduled tasks after the update.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
- Хак-группа Clop утверждает, что похитила у компании Shell 89 Гбайт данныхru-ru·Хакер (xakep.ru)·
- Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaignen-us·SecurityWeek· Exploited PTC Cl0p
- Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Dataen·The Hacker News· Exploited Windchill Cl0p
- Clop created custom web shell for Windchill data theft attacksen-us·BleepingComputer· Exploited PTC Windchill Clop
- Philips and GE investigating Clop ransomware data theft claimsen-us·BleepingComputer· Exploited PTC Windchill Clop
- Shell investigates 'potential incident' after Clop data theft claimsen-us·BleepingComputer· Exploited PTC Windchill Clop
- PTC Windchill Vulnerability Exploited in Ransomware Campaignen-us·SecurityWeek· Exploited PTC Windchill Cl0p
- Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCEen·The Hacker News· Exploited PTC Windmill Cl0p
- Clop ransomware targets Windchill, FlexPLM in data theft attacksen-us·BleepingComputer· Exploited Windchill Clop
- Week in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attacken-us·Help Net Security· Advisory
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-12569 and every CVE in our database. Create a free account — no credit card required.
Create Free Account