CVE-2026-12569: PTC Windchill and FlexPLM Improper Input Validation
PTC Windchill and FlexPLM Improper Input Validation Vulnerability. PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.
- CISA KEV-listed (remediation due 2026-06-28)
- used in ransomware campaigns
- EPSS 30.2% (98.0% percentile)
- CVSS 9.3 critical