#FlexPLM
CVE-2026-12569: PTC Windchill and FlexPLM Improper Input Validation Vulnerability

PTC Windchill and FlexPLM contain an improper input valida…

https://planetbriefing.com/events/cve-2026-12569-ptc-windchill-and-flexplm-improper-input-validation-vulnerability-38c0f145a1f5

#Technology #UnitedStates
September 27, 2026 at 12:44 PM
CISA and BSI warn orgs of critical PTC Windchill and FlexPLM flaw securityaffairs.com/190049/secur...
CISA and BSI warn orgs of critical PTC Windchill and FlexPLM flaw
CISA warns of a critical flaw in PTC Windchill and FlexPLM (CVE-2026-4681), with no patch yet and potential for imminent exploitation.
securityaffairs.com
March 27, 2026 at 11:42 PM
PTC Inc. is warning of a critical vulnerability in Windchill and FlexPLM, widely used product lifecycle management (PLM) solutions, that could allow remote code execution.
PTC warns of imminent threat from critical Windchill, FlexPLM RCE bug
PTC Inc. is warning of a critical vulnerability in Windchill and FlexPLM, widely used product lifecycle management (PLM) solutions, that could allow remote code execution.
www.bleepingcomputer.com
March 24, 2026 at 11:04 PM
Clop ransomware targets Windchill, FlexPLM in data theft attacks

via @bleepingcomputer.com
Clop ransomware targets Windchill, FlexPLM in data theft attacks
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign.
www.bleepingcomputer.com
July 27, 2026 at 1:57 AM
~Asec~
Ransomware incidents surged, led by Qilin and Gentlemen, while Clop exploited Windchill and FlexPLM in a global supply-chain campaign.
-
IOCs: Qilin, CL0P, Windchill
-
#Qilin #Ransomware #ThreatIntel
August 2026 Ransomware Trends
asec.ahnlab.com
September 28, 2026 at 8:02 PM
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign.
Clop ransomware targets Windchill, FlexPLM in data theft attacks
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign.
www.bleepingcomputer.com
July 24, 2026 at 7:36 AM
Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569) | Ransom-ISAC Blog - Ransom-ISAC

A coordinated Unified Threat Advisory covering active Cl0p ransomware affiliate exploitation of internet-expose

Read more: https://ransom-isac.com/blog/clop-windchill-flexplm-exploitation/
July 23, 2026 at 6:18 AM
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files.
Clop created custom web shell for Windchill data theft attacks
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files.
www.bleepingcomputer.com
August 18, 2026 at 5:30 PM
PTC warns of imminent threat from critical Windchill, FlexPLM RCE bug
PTC warns of imminent threat from critical Windchill, FlexPLM RCE bug
PTC Inc. is warning of a critical vulnerability in Windchill and FlexPLM, widely used product lifecycle management (PLM) solutions, that could allow remote code execution.
www.bleepingcomputer.com
March 24, 2026 at 11:25 PM
Guys, there is a ton of important infosec news in today's Metacurity -- some of it stupid or crazy -- that you won't want to miss, including

--Leaked DarkSword iPhone spyware lowers bar for mass exploitation, 1/6
www.metacurity.com/leaked-darks...
Leaked DarkSword iPhone spyware lowers bar for mass exploitation
FCC bans import of all new foreign-made routers, Foster City officially declares state of emergency following attack, German federal police visited Windchill and FlexPLM users in the wee hours to warn...
www.metacurity.com
March 24, 2026 at 3:05 PM
-Clop targets PTC Windchill and FlexPLM servers
-New AfterCall adware
-New Dolphin X Stealer and msaRAT
-OpSec leak exposes JadeProx operations
-UAC-0099 distributes malicious Notepad++ plugins
-DPRK job interviews adopt ClickFix
-Lots of Kimsuky ops
-Review of the Iran cyber war landscape
July 24, 2026 at 8:02 AM
CVSS 10.0 in PTC Windchill PDMLink and FlexPLM
CVSS 10.0 in PTC Windchill PDMLink and FlexPLM
There is a critical vulnerability in PTC's Windchill PDMLink and FlexPLM: https://community.ptc.com/t5/Windchill/Critical-vulnerability-CVSS10-0/m-p/1059587 https://support.eacpds.com/hc/en-us/art...
reddit.com
March 22, 2026 at 11:42 PM
Das gab es wohl noch nie - die Polizei rückt bei Unternehmen und Admins an, um sie persönlich vor Sicherheitslücken in einem IT-Produkt zu warnen.

Mit einigen Nebenwirkungen - einige der aus dem Bett geklingelten Admins nutzen das betroffene Produkt gar nicht. 🤦‍♂️
BKA warnt PTC-Kunden vor Zero-Day in Windchill & FlexPLM
(Bild: Lila Patel - stock.adobe.com / KI-generiert) Polizei warnt PTC-Kunden vor Zero-Day CVE-2026-4681 in Windchill/FlexPLM: Deserialisierung ermöglicht Codeausführung. BKA initiiert.
www.security-insider.de
March 27, 2026 at 8:33 AM
U.S. CISA adds Cisco and PTC Windchill and FlexPLM flaws to its Known Exploited Vulnerabilities catalog
U.S. CISA adds Cisco and PTC Windchill and FlexPLM flaws to its Known Exploited Vulnerabilities catalog
U.S. CISA adds Cisco and PTC Windchill and FlexPLM vulnerabilities to its Known Exploited Vulnerabilities catalog.
securityaffairs.com
June 26, 2026 at 11:27 AM
Critical RCE Flaw in PTC Windchill and FlexPLM Puts Product Data at Risk
Critical RCE Flaw in PTC Windchill and FlexPLM Puts Product Data at Risk
PTC issues a critical advisory for Windchill and FlexPLM. CVE-2026-4681 is an RCE flaw allowing full server control via deserialization. Patch now!
securityonline.info
March 26, 2026 at 5:06 PM
April 2, 2026 at 6:00 PM
PTC Windchill/FlexPLM zero-day RCE under active exploitation. No patch yet—only mitigations. Self-hosted instances exposed. IP on the clock. 🏭🔓

https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-critical-vulnerability
March 29, 2026 at 4:05 AM
Cl0p Ransomware Actively Exploiting Critical Unauthenticated RCE in PTC Windchill and FlexPLM Systems – Rescana www.rescana.com/post/cl0p-ra...
Cl0p Ransomware Actively Exploiting Critical Unauthenticated RCE in PTC Windchill and FlexPLM Systems
Executive SummaryAffiliates of the Cl0p ransomware group are actively exploiting a critical unauthenticated remote code execution (RCE) vulnerability in internet-exposed PTC Windchill and FlexPLM envi
www.rescana.com
July 27, 2026 at 9:35 AM
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deploy…
#hackernews #news
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign. "Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling
thehackernews.com
July 26, 2026 at 1:42 PM
⚠️ Cl0p names 40 Windchill victims

Cl0p exploited CVE-2026-12569 to deploy web shells and steal blueprints and project data.

🔗 read more: securityaffairs.com/...

#ransomNews #cyberthreats #Cl0p
Cl0p Targets 40+ Organizations Through PTC Windchill Flaw
Cl0p claims over 40 organizations fell victim to attacks exploiting a PTC Windchill and FlexPLM vulnerability.
securityaffairs.com
August 23, 2026 at 7:37 AM
Der Hersteller warnt und bittet Admins, dringend ihre Instanzen mit einer Notlösung abzusichern. Ein Patch steht noch aus.
Zero-Day erlaubt Codeausführung in WindChill und FlexPLM
www.heise.de
March 22, 2026 at 2:31 PM
🌑 HADAL · actively exploited critical
CVE-2026-12569: A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM
CVSS 9.8 · EPSS 2.3% · CISA KEV
https://beta.vulnsea.com/cve/CVE-2026-12569

#CVE #infosec #cybersecurity #threatintel
CVE-2026-12569 — A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS…
beta.vulnsea.com
August 1, 2026 at 7:00 AM
Thx, 61st floor aka the Ohana floor of the sf.com tower
Software Factory - Your Partner for Digital Transformation
SF bietet die Lösungen für intelligente Prozesse im Bereich CAD/CAM, PLM, ALM, IoT, Industrie 4.0, PTC, Creo, Windchill, Integrity, ThingWorx und FlexPLM
sf.com
November 18, 2024 at 4:39 AM
CISA adds CVE-2026-12569 to the KEV catalog as adversaries actively exploit PTC Windchill & FlexPLM platforms. This is an immediate threat to supply chain integrity and intellectual property. Access our complete executive risk mitigation framework for corporate leadership:…
(CISA CDUAL) The Cyber Mind CSUITE Brief: CVE-2026-12569 – PTC Windchill and FlexPLM Improper Input Validation Vulnerability
Active exploitation verified by CISA KEV. This high-level corporate briefing equips CEOs, Chief Risk Officers, and Boards of Directors with the governance frameworks and asset assurance protocols needed to defend the PLM pipeline against input validation vectors.
thecybermind.co
June 26, 2026 at 1:11 PM