CVE-2026-12569
A critical remote code execution flaw exists in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability is triggered by deserializing untrusted data, allowing attackers to run arbitrary code on the affected system. It applies to all versions before 11.0 M030 and to the specific versions listed in the CPE data.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
PTC Windchill PDMlink and PTC FlexPLM, including all releases prior to 11.0 M030 and the following specific versions: FlexPLM 11.1 m020, 11.2.1.0, 12.0.0.0, 12.0.2.0, 12.1.3.0, 13.0.2.0, 13.0.3.0; Windchill PDMlink 11.0 m030, 11.1 m020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0.
Real-world impact
An attacker who can send crafted data to the vulnerable system can execute arbitrary code, potentially taking full control, stealing data, or disrupting services.
Why this severity
The CVSS score of 9.3 reflects that the flaw can be exploited remotely without authentication, giving attackers full control (high confidentiality, integrity, availability impact) and no user interaction is required.
What to do about it
- ›Follow vendor instructions to mitigate the vulnerability as per CISA guidance.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
CISA KEV required action
Timeline
- Jun 18, 2026 · Jun 18, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jun 25, 2026 · Jun 25, 2026Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Jun 28, 2026 · Jun 28, 2026CISA remediation deadlineFederal agencies are required to remediate by this date.
- Aug 1, 2026 · 3d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- ptc.com/en/support/article/CS473270permissions required
- cisa.gov/known-exploited-vulnerabili…us government resource