Vulnerability Details CVE-2026-12569
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions
* The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 61.7%
CVSS Severity
CVSS v3 Score 9.8
Proposed Action
PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.
Ransomware Campaign
Unknown
Products affected by CVE-2026-12569
-
cpe:2.3:a:ptc:flexplm:10.1m040
-
cpe:2.3:a:ptc:flexplm:10.2m030
-
cpe:2.3:a:ptc:flexplm:11.0f000
-
cpe:2.3:a:ptc:flexplm:11.0m010
-
cpe:2.3:a:ptc:flexplm:11.0m030
-
cpe:2.3:a:ptc:flexplm:11.1m020
-
cpe:2.3:a:ptc:flexplm:11.2.1.0
-
cpe:2.3:a:ptc:flexplm:12.0.0.0
-
cpe:2.3:a:ptc:flexplm:12.0.2.0
-
cpe:2.3:a:ptc:flexplm:12.1.3.0
-
cpe:2.3:a:ptc:flexplm:13.0.2.0
-
cpe:2.3:a:ptc:flexplm:13.0.3.0
-
cpe:2.3:a:ptc:windchill_pdmlink:10.1m020
-
cpe:2.3:a:ptc:windchill_pdmlink:10.2m022
-
cpe:2.3:a:ptc:windchill_pdmlink:10.2m030
-
cpe:2.3:a:ptc:windchill_pdmlink:11.0m030
-
cpe:2.3:a:ptc:windchill_pdmlink:11.1m020
-
cpe:2.3:a:ptc:windchill_pdmlink:11.2.1.0
-
cpe:2.3:a:ptc:windchill_pdmlink:12.0.2.0
-
cpe:2.3:a:ptc:windchill_pdmlink:12.1.2.0
-
cpe:2.3:a:ptc:windchill_pdmlink:13.0.2.0
-
cpe:2.3:a:ptc:windchill_pdmlink:13.1.0.0
-
cpe:2.3:a:ptc:windchill_pdmlink:13.1.1.0
-
cpe:2.3:a:ptc:windchill_pdmlink:13.1.2.0
-
cpe:2.3:a:ptc:windchill_pdmlink:13.1.3.0