kevrichment CVE enrichment
← Dashboard
CVE-2026-12569 9.8 3-Day Required PoC Available KEV Automatable Active Exploitation
PTC · Windchill and FlexPLM · Added Jun 25, 2026 · Published Jun 18, 2026
Details
VendorPTC
ProductWindchill and FlexPLM
Vulnerability NamePTC Windchill and FlexPLM Improper Input Validation Vulnerability
Date AddedJun 25, 2026
Due DateJun 28, 2026
Required ActionApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CWECWE-20 CWE-502
PublishedJun 18, 2026
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
🎯 Hunting Hypothesis
Monitor for unauthenticated HTTP requests to PTC Windchill or FlexPLM servers carrying serialized payloads targeting deserialization vulnerabilities to achieve remote code execution.
Research Details
ComponentPTC Windchill PDMlink / FlexPLM deserialization handler
PreconditionsNetwork reachability to PTC Windchill or FlexPLM server on HTTP/HTTPS ports; no authentication required; vulnerable versions prior to 11.0 M030, all CPS versions affected.
Deliverycrafted HTTP request carrying serialized payload to Windchill/FlexPLM endpoint
Public PoCyes
Exploit NotesCVSS 9.8 CRITICAL | No auth required | Deserialization of untrusted data (CWE-502) | Actively exploited — added to KEV June 25, 2026 | PTC advisory published with remediation