THREAT OPS › Threat News › [NVD] CVE-2026-12569 (CRITICAL 9.8) — A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions
* The identified vulnerability
[NVD] CVE-2026-12569 (CRITICAL 9.8) — A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerability
CVE-2026-12569 CVSS: 9.8 CRITICAL Published: 2026-06-18T01:18:12.040
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior
Indicators of compromise
- CVE-2026-12569cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-12569