CVE-2026-12569Critical· 9.8▾ Hadal⚠ Exploited in the wildA critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS…
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 53.9 · likelihood 8.1 · exploitation 25 · ransomware 5
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 1.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Jun 28, 2026
Last analysed / modified upstream
2.3%
2.3% → 41%
Added to the CISA catalog on Jun 25, 2026. Federal remediation due Jun 28, 2026. View catalog ↗
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions
flexplm <= 11.0m030flexplm = 11.1m020flexplm = 11.2.1.0flexplm = 12.0.0.0flexplm = 12.0.2.0flexplm = 12.1.3.0flexplm = 13.0.2.0flexplm = 13.0.3.0windchill_pdmlink < 11.0m030windchill_pdmlink = 11.0m030windchill_pdmlink = 11.1m020windchill_pdmlink = 11.2.1.0windchill_pdmlink = 12.0.2.0windchill_pdmlink = 12.1.2.0windchill_pdmlink = 13.0.2.0windchill_pdmlink = 13.1.0.0windchill_pdmlink = 13.1.1.0windchill_pdmlink = 13.1.2.0windchill_pdmlink = 13.1.3.0Upgrade past the affected range:
windchill_pdmlink 11.0m030Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-29499Critical· 9.8The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation
CVE-2015-2291High· 7.8(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted …
CVE-2018-15454High· 8.6A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an …
CVE-2011-0627High· 8.8Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content…
CVE-2025-6558High· 8.8Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
CVE-2025-13805Low· 3.7A weakness has been identified in nutzam NutzBoot up to 2.6.0-SNAPSHOT