LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-12569: PTC Windchill and FlexPLM Improper Input Validation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 25, 2026
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jun 28, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog on Jun 25, 2026, with a federal patch deadline of Jun 28, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.

PTC Windchill and FlexPLM contain an improper input validation vulnerability that permits an unauthenticated remote attacker to execute arbitrary code by sending a malicious request to the network. The flaw affects product lifecycle management deployments and requires attention from teams responsible for these systems.

How it works

The weakness is tracked under CWE-20 and CWE-502. An attacker supplies input that is not properly validated before processing, which can result in execution of arbitrary code on the server.

Am I affected? How to find it in your systems

PTC Windchill and FlexPLM are deployed in manufacturing and engineering environments for product data management. Locate all instances through asset inventories and configuration management databases.

How to remediate

Apply mitigations in accordance with vendor instructions while complying with CISA BOD 26-04 guidance on prioritizing security updates based on risk.

If you can't patch immediately

Until updates can be applied, limit exposure by evaluating internet accessibility of each instance.

If your data may have been exposed

Actively exploited vulnerabilities of this class can result in breaches. Run a free exposure scan of email addresses to check against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedPTC · Windchill and FlexPLM
WeaknessCWE-20
Added to CISA KEVJun 25, 2026
Federal patch deadlineJun 28, 2026
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities