CISA KEV · Known exploitedCritical

CVE-2026-12569

PTC Windchill PDMLink, FlexPLM, flexplm

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

CVSS
9.3
EPSS
30.2%
98.0% percentile
CISA KEV
Listed
Published
2026.06.18
PRIORITY ASSESSMENT

Immediate review

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.

Known exploitationConfirmed by CISA KEV
Exploit probability30.2%
Technical severityCVSS 9.3

Vulnerability overview

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

Affected product and versions

Product
PTC Windchill PDMLink, FlexPLM, flexplm
Affected versions
<= 11.0 M030, >= 11.1 M020, >= 11.2.1.0, >= 12.0.2.0, >= 12.1.2.0, >= 13.0.2.0, >= 13.1.0.0, >= 13.1.1.0, >= 13.1.2.0, >= 13.1.3.0, >= 12.0.0.0, >= 12.1.3.0, >= 13.0.3.0, <= 11.0m030, 11.1m020, 11.2.1.0, 12.0.0.0, 12.0.2.0, 12.1.3.0, 13.0.2.0
Fixed versions
11.0m030

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
CISA required action

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Due date: 2026.06.28
  1. 1
    Identify

    Confirm that PTC Windchill PDMLink, FlexPLM, flexplm and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:X/U:Red
CWE
CWE-20, CWE-502
KEV added
2026.06.25
Ransomware use
확인됨
CVE-2026-12569 — PTC Windchill PDMLink, FlexPLM, flexplm | SECUFOCUS NOW