Particle.news

PTC Windchill Remote‑Code Flaw Confirmed Exploited in the Wild

CISA listed CVE-2026-12569 with a June 28 federal patch deadline, heightening the threat to manufacturers that use Windchill.

Overview

  • Security researchers and PTC have confirmed real‑world exploitation of CVE-2026-12569, with attackers deploying persistent JSP webshells that enable remote command execution and data theft.
  • CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on Thursday, requiring federal civilian agencies to remediate the flaw by June 28.
  • The bug is an improper input validation/deserialization remote code execution issue with a CVSS score of 9.3 that affects Windchill and FlexPLM releases prior to 11.0 M030.
  • PTC issued patches and mitigations and published indicators of compromise and IOCs that include webshell file patterns, IP addresses, and a file hash for defenders to hunt for infections.
  • Attribution remains unknown, law enforcement has been warning organizations, and the incident raises immediate supply‑chain and operational risks for automotive, aerospace, defense and other industrial users.