CVE-2026-12569: PTC Windchill and FlexPLM Improper Input Validation Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-06-25. EPSS: 46% chance of exploitation in the next 30 days.

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

Affected products

  • PTC FlexPLM: up to and including 11.0m030; version 11.1m020 only; version 11.2.1.0 only; version 12.0.0.0 only; version 12.0.2.0 only; version 12.1.3.0 only; …
  • PTC Windchill Pdmlink: before 11.0m030 (fixed in 11.0m030); version 11.0m030 only; version 11.1m020 only; version 11.2.1.0 only; version 12.0.2.0 only; version 12.1.2.0 only; …

Published 2026-06-18. Last modified 2026-08-01.