Post
CRITICAL ⚡ MUST-KNOW

CISA Adds Actively Exploited PTC Windchill RCE Flaw to KEV Catalog

· vulnerability · cve · rce

CISA added a critical remote code execution flaw in PTC Windchill PDMLink and PTC FlexPLM, tracked as CVE-2026-12569, to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. SecurityWeek reported the first confirmed in-the-wild exploitation of the flaw, and Hacker News reports web shell attacks against vulnerable instances are continuing. Organizations running Windchill PDM/PLM software should patch immediately and check for indicators of compromise.