Executive brief
PTC Windchill and FlexPLM, software used by manufacturers to manage product lifecycles and data, contain a critical security flaw. An attacker can remotely take control of the system without needing a username or password. This could lead to the theft of sensitive intellectual property, disruption of manufacturing operations, or full system takeover.
Technical details
A critical remote code execution (RCE) vulnerability exists in PTC Windchill PDMLink and PTC FlexPLM due to the deserialization of untrusted data (CWE-502) and improper input validation (CWE-20). The flaw allows an unauthenticated, remote attacker to execute arbitrary code with the privileges of the application by sending a specially crafted request over the network. The vulnerability impacts multiple versions including those prior to 11.0 M030 and various specific releases up to 13.1.3.0. Exploitation in the wild has been reported.
Affected products
- PTC Windchill PDMLink <= 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0, 13.1.1.0, 13.1.2.0, 13.1.3.0
- PTC FlexPLM <= 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.0.0, 12.0.2.0, 12.1.2.0, 12.1.3.0, 13.0.2.0, 13.0.3.0
Timeline
- 2026-06-17: disclosed: Initial disclosure by PTC
- 2026-06-17: advisory: NVD publication date
- 2026-06-25: other: Reported exploited in the wild status noted in advisory summary