Critical Known exploited (KEV) Ransomware use CVE-2026-12569

Unauthenticated RCE in PTC Windchill / FlexPLM (CVE-2026-12569) — the heart of manufacturing design under attack, CVSS 9.8

PTC Windchill and FlexPLM Added to KEV Jun 25, 2026 Federal remediation due 2026-06-28

PTC Windchill / FlexPLM, product lifecycle management (PLM) platforms for manufacturing, contain an improper-input-validation flaw (CWE-20/CWE-502). An unauthenticated remote attacker can execute arbitrary code just by sending a crafted request. The official NVD score is CVSS 9.8 (CRITICAL). CISA added it to KEV on June 25, 2026, with remediation due three days later, June 28.

Key facts

  • CVE IDCVE-2026-12569
  • CVSS base score9.8 CRITICAL
  • CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Affected (vendor / product)PTC Windchill and FlexPLM
  • CWECWE-20, CWE-502
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2026-06-28 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • Improper input validation (CWE-20/CWE-502) in manufacturing PLM platforms PTC Windchill / FlexPLM
  • No authentication, no user interaction, remote code execution — the dangerous "pre-auth RCE"
  • Official NVD score: CVSS 9.8 (CRITICAL)
  • Added to KEV June 25, 2026 (confirmed exploitation); remediation due June 28 — a 3-day deadline (BOD 26-04)
  • The hub of designs, BOMs, and manufacturing know-how — a breach reaches from data theft to interference with production
  • Of the 1,687 records held as of 2026-09-01, 86 carry a three-day deadline, led by Cisco at 9 and Microsoft at 8.

1The design data PLM holds

PLM (product lifecycle management) systems centralize the core information of making things — design data, bills of materials (BOM), engineering changes, supplier information. PTC Windchill is a leading example widely used in manufacturing; FlexPLM is a retail/apparel-oriented variant.

These systems concentrate the drawings, blueprints, and manufacturing know-how that are a company's competitive edge, so a breach reaches beyond data theft into interference with manufacturing itself.

2No authentication, no user interaction

The severity comes from the combination of conditions: no authentication (PR:N), no user interaction (UI:N), code execution over the network (AV:N) — the most attacker-friendly "pre-auth RCE," which is why NVD assigned 9.8.

That the root cause is improper input validation and deserialization (restoring external data into internal objects, where insufficient validation lets planted code run) echoes the SharePoint case (CVE-2026-45659): a fatal pattern that recurs in server products.

3Infrastructure deep inside manufacturing

Manufacturing PLM sits deep inside the network, is connected to partners, and is hard to take offline — like a call platform (Cisco Unified CM), it is a place where attackers can linger. The KEV listing (confirmed exploitation) and the 3-day deadline (top priority under BOD 26-04) show this core system is actually being targeted.

The baseline response is PTC's fixed release; also review external reachability and consider spillover across the supply chain (partners using the same PLM).

4A three-day deadline is exceptional

KEV deadlines are not uniform. The three days attached to this record put it among a small group within the catalog.

Records with a three-day deadline86of the 1,687 held as of 2026-09-01
By vendorCisco 9, Microsoft 8, Fortinet 5then Oracle 4 and Ivanti 4
This record3 daysPTC Windchill and FlexPLM

PLM systems hold the core information of manufacturing in one place: design data, bills of material, specification changes, supplier information. The drawings and manufacturing know-how that make up a company's competitive position gather there, so a breach reaches past information loss into interference with the production plan itself.

Sitting deep inside, connected to suppliers, and hard to take offline, it is also a place where an attacker can stay a long time.

Why it matters

A flaw that lets the heart of design and manufacturing be taken over without authentication leads directly to IP theft and supply-chain spillover. Manufacturers and PLM operators should patch and cut external reachability. As a peer to SharePoint (deserialization) among "pre-auth RCE in server products," it is a prompt to re-examine exposing core systems.

FAQ

What is PLM (Windchill)?
A system that centralizes product design data, bills of materials, engineering changes, and supplier information. PTC Windchill is widely used in manufacturing; FlexPLM is a retail/apparel variant. It is the hub of a company's design and manufacturing information.
Why is "pre-auth RCE" especially dangerous?
Because it needs no login (pre-auth) and runs code over the network (RCE), the preconditions for attack are almost nil. Not even a stolen account is needed — if it is reachable externally, it can be hit directly.
What should I do?
Apply PTC's fixed release per its security advisory. CISA requires BOD 26-04-based prioritization. Also review external reachability and check for spillover to partners using the same PLM.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#PTC#Windchill#PLM#Manufacturing#RCE#CWE-502#KEV
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.