Knox CVE Database
/
CVE-2026-12569
Critical
9.8
Ransomware use

CVE-2026-12569: PTC Windchill and FlexPLM Improper Input Validation Vulnerability

PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.

Added to the CISA KEV catalog:
June 25, 2026

Overview

PTC Windchill PDMLink and FlexPLM contain a deserialization vulnerability that allows an unauthenticated remote attacker to execute arbitrary code on the server. No credentials or user interaction are required: an attacker with network access to the application can send a crafted payload and gain full control of the host. Multiple specific releases across both products are affected, spanning versions through 13.1.1.0 for Windchill PDMLink and through 13.0.2.0 for FlexPLM. This vulnerability is actively exploited and has been associated with ransomware campaigns.

Vulnerability details

Affected vendor
PTC
Affected product
Windchill and FlexPLM
Weakness type (CWE)
CWE-20, CWE-502

Windchill PDMLink and FlexPLM expose a network-accessible endpoint that accepts and deserializes data from the network without validating its integrity or enforcing type safety before processing. This is the core failure described by CWE-502: the application trusts attacker-supplied serialized objects and instantiates them, allowing the deserialization process itself to trigger unintended code paths. CWE-20 captures the root cause: the input is never validated before it reaches the deserialization routine. Because the endpoint requires no authentication, the attack surface is the full network perimeter of any reachable deployment.


An attacker sends a crafted serialized payload directly to the vulnerable endpoint, requiring no prior authentication and no action from any user. The application deserializes the payload, and the attacker achieves arbitrary code execution on the server with the full privileges of the application process. The result is complete confidentiality, integrity, and availability impact on the host. This vulnerability is confirmed as exploited in the wild and has been associated with ransomware activity, making any internet-reachable instance an immediate priority for remediation.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Known

Detection and monitoring

  • Review application server logs for deserialization exceptions, class-not-found errors, or unexpected Java gadget-chain class names appearing in stack traces or error output, which indicate a malformed or weaponized payload was processed.
  • Monitor for anomalous child processes spawned by the Windchill or FlexPLM application server process (such as cmd.exe, powershell.exe, or shell interpreters on Linux) with no corresponding scheduled task or administrative session, a pattern consistent with post-deserialization code execution.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
June 28, 2026

Additional hardening

  • Apply PTC patches for the specific affected builds listed in the vendor advisory (see References); the advisory is behind a login wall and names per-release patch targets for both Windchill PDMLink and FlexPLM.
  • Restrict network access to Windchill and FlexPLM service ports to known, authorized IP ranges using perimeter firewall rules or host-based controls, reducing exposure to unauthenticated attackers.
  • Place the application behind a web application firewall or reverse proxy configured to inspect and block requests carrying known Java deserialization gadget-chain signatures (for example, ysoserial payloads).
  • If the application cannot be patched immediately and internet exposure cannot be eliminated, take the instance offline or isolate it to a management-only network segment until the patch is applied.

Key dates

Published (NVD)
June 17, 2026
Added to CISA KEV
June 25, 2026
Remediation deadline
June 28, 2026
Last updated
August 1, 2026

References

Frequently asked questions

Does CVE-2026-12569 affect my FedRAMP authorization?

If PTC Windchill and FlexPLM runs inside your authorization boundary, yes, CVE-2026-12569 affects your FedRAMP authorization. The vulnerability appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, which sets a remediation deadline of June 28, 2026. An unpatched KEV inside your boundary is an assessor finding. Before your assessor or sponsoring agency raises it, you must either remediate it or formally document a mitigation.

How does Knox help me handle CVE-2026-12569?

Knox does not patch PTC Windchill and FlexPLM for you. Under the FedRAMP shared-responsibility model, remediating CVE-2026-12569 is your obligation. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, along with continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. Applying the patch is yours to own; managing your compliance posture while you do it is not something you handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. That means exposure to something like CVE-2026-12569 surfaces during routine monitoring rather than only when an assessor flags it at review time, giving you more time to act before a deadline becomes a finding.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-12569 isn't remediated by June 28, 2026?

Missing the June 28, 2026 deadline turns CVE-2026-12569 into a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what converts a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Remediating on time keeps your authorization standing clean and the agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting