PT-2026-50580 · Ptc+1 · Windchill Pdmlink+2
CVE-2026-12569
·
Published
2026-06-18
·
Updated
2026-08-27
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PTC Windchill PDMlink versions prior to 11.0 M030
PTC FlexPLM versions prior to 11.0 M030
All CPS versions
Description
A critical remote code execution (RCE) issue exists due to improper input validation and the deserialization of untrusted data. This flaw allows an unauthenticated remote attacker to execute arbitrary code via specially crafted requests. The issue has been actively exploited by the Cl0p ransomware group, targeting over 40 organizations including Shell, Philips, and GE to steal sensitive engineering data, blueprints, and project plans.
Technical exploitation involves the deployment of a custom JavaServer Pages (JSP) web shell that integrates with internal Windchill APIs and classes such as
MethodContext, WTConnection, and WTKeyStoreUtil. The web shell includes a function gs to decrypt administrative credentials and LDAP manager passwords from the application keystore, and a function fl (using class Flst1) to enumerate the engineering vault for file paths and stream IDs. Additionally, a custom Java class loader named Cldr allows attackers to load compiled Java bytecode directly into memory to facilitate lateral movement and data exfiltration. Attackers have been observed using the X-windchill-req HTTP header for command traffic, with responses compressed via GZIP to evade monitoring systems. Initial reconnaissance often targets the FlexPLM WSDL endpoint.Recommendations
Update PTC Windchill PDMlink to version 11.0 M030 or later.
Update PTC FlexPLM to version 11.0 M030 or later.
Update all CPS versions to the latest patched release provided by the vendor.
Restrict access to the FlexPLM WSDL endpoint to minimize the risk of reconnaissance.
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cps
Flexplm
Windchill Pdmlink