CVE-2026-4681
Critical Remote Code Execution vulnerability reported in Windchill
Description
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. This issue affects Windchill PDMLink: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0, 13.1.1.0, 13.1.2.0, 13.1.3.0; FlexPLM: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.0.0, 12.0.2.0, 12.0.3.0, 12.1.2.0, 12.1.3.0, 13.0.2.0, 13.0.3.0.
In plain language
AI Worth attentionCVE-2026-4681 is a critical, remote “code execution” flaw in Windchill PDMLink and FlexPLM that can be triggered over the network without any login; if your business runs these products, you should act now to reduce risk.
CVE-2026-4681 is an unauthenticated remote code execution issue in PTC Windchill PDMLink and PTC FlexPLM, triggered by deserialization of untrusted data from the network.
What to do now
- Check whether your Windchill PDMLink or FlexPLM installation matches the affected versions listed for CVE-2026-4681.
- Apply the vendor’s immediately recommended Apache or IIS HTTP Server workaround/configuration steps for Windchill or FlexPLM, following the exact instructions provided by PTC.
- Confirm you have the vendor’s remediation/updated package or guidance applied across all environments (production and any public-facing systems).
- If you cannot apply the workaround right away, restrict network access to Windchill/FlexPLM so it is not reachable from the public internet while you complete the fix.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Clop ransomware targets Windchill, FlexPLM in data theft attacksen-us·BleepingComputer· Exploited Windchill Clop
- JSP webshells being dropped on unpatched PTC Windchill instancesen-us·Help Net Security· Exploited Windchill rce
- First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wilden-us·SecurityWeek· Exploited PTC Windchill rce
- CISA Adds Cisco Unified CM and PTC Windchill Flaws to KEV Catalogen-us·Daily CyberSecurity (securityonline.info)· Exploited Cisco Unified Communications Manager rce
- AVer PTC Cameras Hit by Critical RCE Flaw CVE-2026-40624 (CVSS 9.8)en-us·Daily CyberSecurity (securityonline.info)· Patch AVer PTC500S ics-ot-iot
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-4681 and every CVE in our database. Create a free account — no credit card required.
Create Free Account