Skip to content
Critical RCE Vulnerability in PTC Windchill and FlexPLM Under Active Exploitation

Critical RCE Vulnerability in PTC Windchill and FlexPLM Under Active Exploitation

First seen 29 Jun 2026, 14:59 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 30, 2026 at 14:42 UTC
  • •CVE-2026-12569 allows remote code execution in PTC Windchill and FlexPLM software.
  • •Active exploitation has been confirmed, prompting urgent patching recommendations.
  • •PTC has provided indicators of compromise to help organizations detect potential intrusions.

Hackers are exploiting a critical vulnerability in PTC Windchill and FlexPLM, tracked as CVE-2026-12569, which allows remote code execution due to an unsafe deserialization flaw. This vulnerability affects product lifecycle management systems used across various industries, including defense and aerospace. PTC released patches on June 17, 2026, but reports of active exploitation have surged, prompting the US CISA to add it to its Known Exploited Vulnerabilities catalog on June 25. Organizations are urged to apply patches immediately to mitigate risks of data theft and system compromise. The vulnerability has a CVSS severity score of 9.3, indicating a high level of danger. Indicators of compromise have been shared, and organizations are advised to enhance monitoring capabilities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 93d ago How this analysis works

Timeline

2026-06-17
PTC releases patches for Windchill and FlexPLM
PTC issued updates to fix the critical vulnerability affecting multiple versions of its software.
Csoonline
2026-06-25
CISA adds CVE-2026-12569 to KEV catalog
The US Cybersecurity and Infrastructure Security Agency confirmed active exploitation of the vulnerability.
Csoonline
2026-06-29
CCB issues urgent patching advisory
The Centre for Cybersecurity Belgium emphasized the need for immediate patching due to confirmed exploitation.
Ccb.Belgium.Be

More articles in this cluster (2)

Following this threat?

Track CVE-2026-12569 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed