CVE-2026-4681: PTC FlexPLM

Critical severity, CVSS 9.3. EPSS: 0.8% chance of exploitation in the next 30 days.

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. This issue affects Windchill PDMLink: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0, 13.1.1.0, 13.1.2.0, 13.1.3.0; FlexPLM: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.0.0, 12.0.2.0, 12.0.3.0, 12.1.2.0, 12.1.3.0, 13.0.2.0, 13.0.3.0.

Affected products

  • PTC FlexPLM: version 11.0 M030 only; version 11.1 M020 only; version 11.2.1.0 only; version 12.0.0.0 only; version 12.0.2.0 only; version 12.0.3.0 only; …
  • PTC Windchill Pdmlink: version 11.0 M030 only; version 11.1 M020 only; version 11.2.1.0 only; version 12.0.2.0 only; version 12.1.2.0 only; version 13.0.2.0 only; …

Published 2026-03-23. Last modified 2026-06-17.