July 25, 2026
July 25, 2026
SecurityWeek reports that threat actors have exploited a PTC Windchill vulnerability in the wild, marking the first confirmed real-world abuse of the widely used product lifecycle management platform. The flaw, tracked as CVE-2026-12569, affects PTC Windchill and FlexPLM and is an improper input validation vulnerability that can let a remote, unauthenticated attacker execute arbitrary code through specially crafted requests. CISA added the flaw to its Known Exploited Vulnerabilities catalog and ordered U.S. federal agencies to address it by June 28, 2026.
PTC began releasing patches and mitigations on June 17, then published indicators of compromise after warning that attackers were using the flaw to deploy persistent JSP webshells for remote command execution and data exfiltration. SecurityWeek notes that Windchill is widely used in industrial and manufacturing sectors, including automotive, aerospace, defense and heavy machinery, which makes the exploitation especially important for supply chains and OT-related environments. The article also says German authorities had warned companies about imminent attacks before exploitation was confirmed.
Source: SecurityWeek