CISA says attackers are exploiting PTC Windchill and FlexPLM remote-code-execution flaw CVE-2026-12569

Attackers are actively breaking into organizations that use PTC Windchill and FlexPLM, a product lifecycle management platform used by many industrial companies. The flaw, CVE-2026-12569, is an improper input validation bug that lets a remote unauthenticated attacker run arbitrary code through crafted requests. PTC began releasing patches and mitigations on June 17 and said attackers have used the bug to install persistent JSP web shells for remote command execution and data theft; CISA has added it to the Known Exploited Vulnerabilities catalog.
Why it matters: This is urgent for manufacturers and other firms that rely on Windchill or FlexPLM, because attackers can break in over the network without valid credentials and keep long-term access. Organizations should apply PTC's patches or mitigations immediately, check for the published indicators of compromise, and treat exposed servers as potentially compromised.

Sources

Clop ransomware targets Windchill, FlexPLM in data theft attacks
Sergiu Gatlan 2026.07.24 97% relevant
This article advances the same underlying event by tying the active exploitation of CVE-2026-12569 specifically to Clop-style data-theft extortion, adding details on JSP webshell deployment, exfiltration from PLM systems, and extortion emails sent from support@cryptohox.com.
CISA sets urgent deadline to fix Cisco flaw exploited in attacks
Bill Toulas 2026.06.26 93% relevant
This updates the same CVE-2026-12569 story with CISA's KEV addition and a June 28 federal remediation deadline for actively exploited PTC Windchill and FlexPLM systems.
CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
info@thehackernews.com (The Hacker News) 2026.06.26 97% relevant
This source updates the same underlying event by adding that CISA placed the PTC Windchill flaw into the Known Exploited Vulnerabilities catalog and that web-shell attacks against exposed systems are ongoing.
First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild
Eduard Kovacs 2026.06.26 100% relevant
This article establishes a new tracked story by reporting the first confirmed in-the-wild exploitation of CVE-2026-12569 in PTC Windchill and FlexPLM, along with CISA KEV listing and PTC's web-shell and data-exfiltration details.
← Back to all stories