PT-2026-50580 · Ptc+1 · Windchill Pdmlink+2

CVE-2026-12569

·

Published

2026-06-18

·

Updated

2026-08-27

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PTC Windchill PDMlink versions prior to 11.0 M030 PTC FlexPLM versions prior to 11.0 M030 All CPS versions
Description A critical remote code execution (RCE) issue exists due to improper input validation and the deserialization of untrusted data. This flaw allows an unauthenticated remote attacker to execute arbitrary code via specially crafted requests. The issue has been actively exploited by the Cl0p ransomware group, targeting over 40 organizations including Shell, Philips, and GE to steal sensitive engineering data, blueprints, and project plans.
Technical exploitation involves the deployment of a custom JavaServer Pages (JSP) web shell that integrates with internal Windchill APIs and classes such as MethodContext, WTConnection, and WTKeyStoreUtil. The web shell includes a function gs to decrypt administrative credentials and LDAP manager passwords from the application keystore, and a function fl (using class Flst1) to enumerate the engineering vault for file paths and stream IDs. Additionally, a custom Java class loader named Cldr allows attackers to load compiled Java bytecode directly into memory to facilitate lateral movement and data exfiltration. Attackers have been observed using the X-windchill-req HTTP header for command traffic, with responses compressed via GZIP to evade monitoring systems. Initial reconnaissance often targets the FlexPLM WSDL endpoint.
Recommendations Update PTC Windchill PDMlink to version 11.0 M030 or later. Update PTC FlexPLM to version 11.0 M030 or later. Update all CPS versions to the latest patched release provided by the vendor. Restrict access to the FlexPLM WSDL endpoint to minimize the risk of reconnaissance.

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12569

Affected Products

Cps
Flexplm
Windchill Pdmlink