THREAT OPS › CVEs › CVE-2026-12569
CVE-2026-12569 — PTC Windchill and FlexPLM Improper Input Validation Vulnerability
PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.
Vulnerability details
- Affected productsWindchill and FlexPLM
- KEV remediation due2026-06-28
Related reporting
- August 2026 CVE Landscaperecordedfuture
- 24th August – Threat Intelligence Reportcheckpoint_research
- July 2026 CVE Landscaperecordedfuture
- [NVD] CVE-2026-12569 (CRITICAL 9.8) — A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerabilitynvd
- [CISA KEV] CVE-2026-12569 — PTC Windchill and FlexPLM: PTC Windchill and FlexPLM Improper Input Validation Vulnerabilitycisa_kev
- June 2026 CVE Landscaperecordedfuture