ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

JSP webshells being dropped on unpatched PTC Windchill instances

criticalVulnerability exploited in the wildimportance 60CVE-2026-12569CVE-2026-4681

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-12569
Unauthenticated RCE in PTC Windchill and FlexPLM

PTC Windchill and FlexPLM contain an improper input validation flaw (CWE-20) with an associated deserialization of untrusted data weakness (CWE-502) that allows an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request over the network. An attacker who can reach a vulnerable Windchill or FlexPLM server can run arbitrary code on it, potentially gaining a foothold for lateral movement; CISA notes the flaw is being used in ransomware campaigns. All organizations running PTC Windchill or FlexPLM are affected, and the available data does not specify affected version ranges. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-06-25 with known ransomware use, and EPSS assigns a 40.6% probability of exploitation within 30 days (99th percentile). No CVSS score or public proof-of-concept is available yet, but the KEV listing confirms exploitation in the wild.

Do: Apply the fixes in PTC's security advisory for CVE-2026-12569 to both Windchill and FlexPLM as soon as possible, prioritizing internet-facing instances, and comply with the CISA KEV required action under BOD 26-04 (patch within the required window or discontinue use if mitigations are unavailable). Until patched, restrict network exposure of Windchill/FlexPLM servers and hunt for signs of exploitation or ransomware precursor activity; the available data does not list specific patched versions, so defer to PTC's advisory.

9.341% KEV ransomware
  • PTC Windchill
  • PTC FlexPLM
moderatelikely on the order of thousands of enterprise deployments (a few thousand Windchill/FlexPLM servers, with only a subset internet-exposed)
CVE-2026-4681
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM.

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. This issue affects Windchill PDMLink: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0, 13.1.1.0, 13.1.2.0, 13.1.3.0; FlexPLM: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.0.0, 12.0.2.0, 12.0.3.0, 12.1.2.0, 12.1.3.0, 13.0.2.0, 13.0.3.0.

NVD description · AI analysis pending
9.3<1%
Full article429 words · extracted from helpnetsecurity.com · click to collapse

The US Cybersecurity and Infrastructure Security Agency (CISA) added a vulnerability (CVE-2026-12569) in Windchill and FlexPLM, two product lifecycle management software platforms developed by PTC, to its Known Exploited Vulnerabilities (KEV) catalog.

Entries in the KEV catalog don’t contain links to reports of exploitation, but PTC’s advisory keeps getting updated with indicators of compromise and advice for defenders, confirming that attackers are dropping JSP webshells on vulnerable systems.

CISA ordered US federal civilian government agencies to address CVE-2026-12569 by June 28, but all organizations using one of these two PLM platform should patch (if they haven’t already) and check for the presence of indicators of compromise.

PTC Windchill under attack via CVE-2026-12569

Windchill is PTC’s product lifecycle management platform for manufacturing and engineering-intensive industries, while FlexPLM is a PLM platform for retail, footwear, apparel, and consumer goods industries,

CVE-2026-12569 is an improper input validation vulnerability that allows unauthenticated, remote attackers to execute arbitrary code just by sending a malicious request to the network.

PTC warned about the flaw on June 17 and proposed remediation steps, then followed up with the release of a patch on June 18, when it confirmed in-the-wild exploitation. Patches for additional versions of the software were released soon after.

News outlet Heise Online reported that, around June 17, Germany’s Federal Office for Information Security (BSI) started notifying German companies of “impending cyberattacks on vulnerable Windchill instances”, and urged them to verify they had applied the patch.

Interestingly enough, a similar warning by the Federal Criminal Police Office (BKA) on behalf of the BSI was given to German companies in late March 2026, when a code injection vulnerability (CVE-2026-4681) in those same two platforms was publicly disclosed.

CVE-2026-4681 also allowed remote code execution and the indicators of compromise provided in the related advisory suggest it was also exploited in the wild, even though the advisory still states that “there is no evidence of confirmed exploitation affecting PTC customers.”

UPDATE (July 27, 2026, 08:30 a.m. ET):

Indicators of compromise and a report by Ransom-ISAC have tied this exploitation campaign to Cl0p ransomware affiliates.

“Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling unauthenticated remote code execution and deployment of hex-named JSP webshells under /Windchill/login/,” Ransom-ISAC analysts noted.

“Post-exploitation includes filesystem enumeration via flst.txt, staging of engineering/design data, and double-extortion data theft. Confirmed victim sectors include Manufacturing, Automotive, Aerospace, and Retail/Apparel.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/06/29/ptc-windchill-cve-2026-12569-exploited/