{"id":"CVE-2026-12569","title":"A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM","summary":"A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.   *  This advisory also applies to all CPS…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-20","CWE-502"],"vendor":"ptc","product":"flexplm","affected":["flexplm <= 11.0m030","flexplm = 11.1m020","flexplm = 11.2.1.0","flexplm = 12.0.0.0","flexplm = 12.0.2.0","flexplm = 12.1.3.0","flexplm = 13.0.2.0","flexplm = 13.0.3.0","windchill_pdmlink < 11.0m030","windchill_pdmlink = 11.0m030","windchill_pdmlink = 11.1m020","windchill_pdmlink = 11.2.1.0","windchill_pdmlink = 12.0.2.0","windchill_pdmlink = 12.1.2.0","windchill_pdmlink = 13.0.2.0","windchill_pdmlink = 13.1.0.0","windchill_pdmlink = 13.1.1.0","windchill_pdmlink = 13.1.2.0","windchill_pdmlink = 13.1.3.0"],"patched":["windchill_pdmlink 11.0m030"],"published":"2026-06-18","updated":"2026-08-01","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-12569","references":[{"url":"https://www.ptc.com/en/support/article/CS473270","label":"0b655efc-079c-4cb9-9e8d-164871239f4e"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-12569","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild"],"epss":0.40586,"epssPercentile":0.9863,"kev":true,"kevDateAdded":"2026-06-25","kevDueDate":"2026-06-28","kevRansomware":true,"exploited":true,"ingestedAt":"2026-08-01T06:11:31.873Z","slug":"CVE-2026-12569","body":"## Overview\n\nA critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.   *  This advisory also applies to all CPS versions\n  *  The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030\n\n## Affected\n\n- `flexplm <= 11.0m030`\n- `flexplm = 11.1m020`\n- `flexplm = 11.2.1.0`\n- `flexplm = 12.0.0.0`\n- `flexplm = 12.0.2.0`\n- `flexplm = 12.1.3.0`\n- `flexplm = 13.0.2.0`\n- `flexplm = 13.0.3.0`\n- `windchill_pdmlink < 11.0m030`\n- `windchill_pdmlink = 11.0m030`\n- `windchill_pdmlink = 11.1m020`\n- `windchill_pdmlink = 11.2.1.0`\n- `windchill_pdmlink = 12.0.2.0`\n- `windchill_pdmlink = 12.1.2.0`\n- `windchill_pdmlink = 13.0.2.0`\n- `windchill_pdmlink = 13.1.0.0`\n- `windchill_pdmlink = 13.1.1.0`\n- `windchill_pdmlink = 13.1.2.0`\n- `windchill_pdmlink = 13.1.3.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `windchill_pdmlink 11.0m030`","depth":"hadal","depthScore":92,"depthScoreParts":{"impact":53.9,"likelihood":8.1,"exploitation":25,"ransomware":5},"changes":[{"seq":167,"id":"CVE-2026-12569","ts":1787603594099,"field":"epss","old":"0.30198","new":"0.40586"},{"seq":103,"id":"CVE-2026-12569","ts":1785699031260,"field":"epss","old":"0.02263","new":"0.30198"}]}