CVE-2026-12569
KEV · ransomware Critical · CVSS 9.8PTC Windchill PDMLink / PTC FlexPLM — Deserialization of untrusted data RCE (CWE-502 / CWE-20)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- Listed
- ransomware
- Class
- other
- CWE-20, CWE-502
Description
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030
Search profile — drives PoC discovery
Symbols WindchillFlexPLMPDMLinkCPSdeserializationuntrusted dataRCECS473270
Keywords CVE-2026-12569PTC Windchill RCEPTC FlexPLM deserializationPDMLink remote code executionWindchill deserialization exploitFlexPLM CWE-502 PoCPTC Windchill 11.0 M030 vulnerabilityCS473270 exploitPTC CPS deserialization RCE
Versions: Prior to Windchill/FlexPLM 11.0 M030 (all CPS versions also affected)
References
Status: enriched · ingested 2026-07-01T00:00:14.000Z · profiled 2026-07-01T00:30:14.000Z