---
id: CVE-2026-77645
title: >-
  A critical remote code execution (RCE) vulnerability has been reported in PTC
  Windchill and PTC FlexPLM
summary: >-
  A critical remote code execution (RCE) vulnerability has been reported in PTC
  Windchill and PTC FlexPLM. The vulnerability may be exploited through the
  deserialization of untrusted data.
severity: none
cwe:
  - CWE-20
  - CWE-502
published: '2026-08-20'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T15:52:04.827'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77645'
references:
  - url: 'https://www.ptc.com/en/support/article/CS474826'
    label: 0b655efc-079c-4cb9-9e8d-164871239f4e
tags:
  - nvd
epss: 0.00472
epssPercentile: 0.4002
ingestedAt: '2026-09-09T16:14:05.514Z'
---

## Overview

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
