PTC Windchill and FlexPLM
CriticalSoftwareCVE-2026-12569
Actively exploited. Listed in CISA’s Known Exploited Vulnerabilities catalog: exploitation is observed, not theoretical.
What to do
Check the vendor advisory for the fixed version. This flaw is being actively exploited: patch now.
An unsafe deserialisation flaw affects PTC Windchill and FlexPLM. Apply the vendor’s patch. It is being actively exploited: patch now.
What the flaw allows: Attacker-crafted objects are rebuilt without validation.
- Ecosystem
- Application software
- Class
- Unsafe deserialisation
- Published on
- June 25, 2026
Sources
Entry built automatically from the cited security advisory, with no model rewriting. Acknowledged by the organisation or vendor, notified to an authority, or established by two independent sources.