CVE Tools

CVE-2026-4681

Critical Remote Code Execution vulnerability reported in Windchill

Published: Mar 23, 2026Updated: Mar 24, 2026 Sources: CVE List NVD csafCWE-94

Description

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. This issue affects Windchill PDMLink: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0, 13.1.1.0, 13.1.2.0, 13.1.3.0; FlexPLM: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.0.0, 12.0.2.0, 12.0.3.0, 12.1.2.0, 12.1.3.0, 13.0.2.0, 13.0.3.0.

In plain language

AI Worth attention

CVE-2026-4681 is a critical, remote “code execution” flaw in Windchill PDMLink and FlexPLM that can be triggered over the network without any login; if your business runs these products, you should act now to reduce risk.

Executive summary

CVE-2026-4681 is an unauthenticated remote code execution issue in PTC Windchill PDMLink and PTC FlexPLM, triggered by deserialization of untrusted data from the network.

If affected, business impact
Full application takeoverServer compromise and data theftBusiness service disruptionPotential ransomware risk

What to do now

  1. Check whether your Windchill PDMLink or FlexPLM installation matches the affected versions listed for CVE-2026-4681.
  2. Apply the vendor’s immediately recommended Apache or IIS HTTP Server workaround/configuration steps for Windchill or FlexPLM, following the exact instructions provided by PTC.
  3. Confirm you have the vendor’s remediation/updated package or guidance applied across all environments (production and any public-facing systems).
  4. If you cannot apply the workaround right away, restrict network access to Windchill/FlexPLM so it is not reachable from the public internet while you complete the fix.
Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:CC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:CScope
Changed
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

PTC
commercial·USaka thingworx industrial connectivity, kepware kepserverex, thingworx kepware server

Exploitability

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Execution
Initial Access
View detailed technique mapping

References

and 15 more references View all →
5

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-4681 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows