Overview
- Security researchers and PTC have confirmed real‑world exploitation of CVE-2026-12569, with attackers deploying persistent JSP webshells that enable remote command execution and data theft.
- CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on Thursday, requiring federal civilian agencies to remediate the flaw by June 28.
- The bug is an improper input validation/deserialization remote code execution issue with a CVSS score of 9.3 that affects Windchill and FlexPLM releases prior to 11.0 M030.
- PTC issued patches and mitigations and published indicators of compromise and IOCs that include webshell file patterns, IP addresses, and a file hash for defenders to hunt for infections.
- Attribution remains unknown, law enforcement has been warning organizations, and the incident raises immediate supply‑chain and operational risks for automotive, aerospace, defense and other industrial users.