VULNERABILITY OVERVIEW
Improper input validation and deserialization of untrusted data (CWE-502/CWE-20) in PTC Windchill and FlexPLM allows an unauthenticated remote attacker to execute arbitrary code with no credentials or user interaction by sending a crafted serialized payload to an exposed network endpoint. CISA and PTC confirmed active exploitation deploying JSP web shells on compromised PLM servers; threat intelligence associates exploitation with state-sponsored espionage actors targeting defense, aerospace, and manufacturing intellectual property. CISA added to KEV on June 25, 2026 with a June 28 federal remediation deadline.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONS
Windchill PDMlink and FlexPLM versions 11.2.1.0 through 13.1.3.0; all CPS versions prior to patched releaseCITATIONS
- → https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html
- → https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability
- → https://www.cisa.gov/news-events/alerts/2026/06/25/cisa-adds-two-known-exploited-vulnerabilities-catalog
- → https://fieldeffect.com/blog/ptc-windchill-flaw-allows-unauthenticated-rce