DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-12569PUBLISHED: 2026-06-18
CRITICALCVE-2026-12569★ CISA KEV LISTED

PTC Windchill / FlexPLM Unauthenticated RCE via Deserialization

VENDOR: PTC//PRODUCT: Windchill PDMlink, FlexPLM, Creo Parametric Server (CPS)
9.8
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
LIMITED EXPLOITATION

Improper input validation and deserialization of untrusted data (CWE-502/CWE-20) in PTC Windchill and FlexPLM allows an unauthenticated remote attacker to execute arbitrary code with no credentials or user interaction by sending a crafted serialized payload to an exposed network endpoint. CISA and PTC confirmed active exploitation deploying JSP web shells on compromised PLM servers; threat intelligence associates exploitation with state-sponsored espionage actors targeting defense, aerospace, and manufacturing intellectual property. CISA added to KEV on June 25, 2026 with a June 28 federal remediation deadline.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSWindchill PDMlink and FlexPLM versions 11.2.1.0 through 13.1.3.0; all CPS versions prior to patched release
  • https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html
  • https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability
  • https://www.cisa.gov/news-events/alerts/2026/06/25/cisa-adds-two-known-exploited-vulnerabilities-catalog
  • https://fieldeffect.com/blog/ptc-windchill-flaw-allows-unauthenticated-rce
SHARE BRIEF:✕ Post on Xin Share on LinkedIn