CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-12569

KEV · ransomware Critical · CVSS 9.8

PTC Windchill PDMLink / PTC FlexPLM — Deserialization of untrusted data RCE (CWE-502 / CWE-20)

CVSS
9.8
nvd
EPSS
KEV
Listed
ransomware
Class
other
CWE-20, CWE-502

Description

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

Search profile — drives PoC discovery

Symbols WindchillFlexPLMPDMLinkCPSdeserializationuntrusted dataRCECS473270
Keywords CVE-2026-12569PTC Windchill RCEPTC FlexPLM deserializationPDMLink remote code executionWindchill deserialization exploitFlexPLM CWE-502 PoCPTC Windchill 11.0 M030 vulnerabilityCS473270 exploitPTC CPS deserialization RCE
Versions: Prior to Windchill/FlexPLM 11.0 M030 (all CPS versions also affected)

References

Status: enriched · ingested 2026-07-01T00:00:14.000Z · profiled 2026-07-01T00:30:14.000Z