CVE-2026-12569
flexplm: Improper Input Validation (CVE-2026-12569)
Situation assessment
A critical remote code execution (RCE) vulnerability in PTC Windchill PDMlink and PTC FlexPLM allows an unauthenticated attacker to execute arbitrary code by sending a malicious request over the network. This vulnerability is actively exploited in ransomware campaigns since June 2026. All versions of Windchill and FlexPLM prior to 11.0 M030 are affected. Immediate patching to version 11.0 M030 or later is urgently required to mitigate the vulnerability.
Affected
- ptc/flexplm
between *..11.0m030 - ptc/windchill_pdmlink
lt *..11.0m030
Response & Mitigation
Why act now?
Prioritisation rationale
CVE-2026-12569 scores CVSS 9.8 (AV:N/AC:L/PR:N/UI:N) with an EPSS percentile of 98.6 %, placing it among the most likely-to-be-exploited vulnerabilities across the entire CVE corpus. The attack requires no authentication, no user interaction, and no special conditions — a single malicious network request is sufficient for full system compromise via Java deserialization. CISA has confirmed active ransomware campaign use, indicating that exploitation is not merely theoretical but part of ongoing, opportunistic attack waves. For NIS2-scoped organisations running Windchill or FlexPLM in production or engineering environments, the risk is compounded by the sensitivity of PLM data (IP, design files) and frequent connectivity to OT networks, making this a patch-now, no-exception priority.
Runbook · Step 1
Immediate response (0-24 h)
- Apply the vendor patch: Consult the PTC security advisory for CVE-2026-12569 and upgrade PTC Windchill PDMLink and FlexPLM to version 11.0 M030 or later. Note that all CPS versions are also in scope — verify patch coverage across every instance. Confirm the exact patch identifier in the current PTC advisory.
- Network isolation: Immediately restrict inbound HTTP/HTTPS traffic (TCP 80/443) to Windchill and FlexPLM servers from the internet and from untrusted internal segments. Only authorised client subnets and integration servers should reach application ports.
- Enumerate exposed endpoints: Inventory all web-facing endpoints of Windchill/FlexPLM instances (servlet paths, REST APIs, SOAP endpoints). Disable any endpoint that is not operationally required.
- Verify authentication enforcement: Confirm that no Windchill or FlexPLM endpoint is reachable unauthenticated from the internet. Review reverse-proxy and load-balancer configurations for authentication bypass paths.
- Triage historical logs: Review web server access logs and application logs for the past 30 days for anomalous POST requests to known deserialization endpoints (e.g.
/Windchill/servlet/,/FlexPLM/servlet/). Treat suspicious entries as potential indicators of prior compromise.
Runbook · Step 2
Mitigation layers
- WAF rule (network layer): Enable a WAF signature that detects serialised Java objects in HTTP request bodies — match on Content-Type
application/x-java-serialized-objectand magic bytesAC ED 00 05. Block or quarantine matching requests. - IPS signature: Deploy a Suricata/Snort rule targeting Java deserialization payloads inbound to Windchill/FlexPLM ports. Suggested shape:
alert http any any -> $WINDCHILL_SERVERS [80,443] (msg:"CVE-2026-12569 Java Deserialization Attempt"; content:"|AC ED 00 05|"; http_client_body; sid:2026125690; rev:1;). - Network segmentation: Move PLM servers into a dedicated VLAN with strict east-west firewall rules. Block all outbound connections from the PLM server to the internet — this prevents reverse-shell callbacks following a successful RCE.
- JEP 290 deserialization filter: Configure a global Java Serialization Filter (JEP 290) on the application server to allow only explicitly whitelisted classes. Deny-list all classes not required by the application.
- Least-privilege service accounts: Ensure the Windchill/FlexPLM process runs under a service account with minimal OS privileges (no local admin, no SYSTEM/root). This limits the blast radius of a successful exploit.
- Credential rotation: Proactively rotate all service account credentials, API keys, and database passwords used by Windchill/FlexPLM — especially if log review reveals suspicious prior access.
Runbook · Step 3
Detection rules
- Web server access logs: Anomalous POST requests to servlet paths with unusually large body sizes (>10 KB) and Content-Type
application/x-java-serialized-objectorapplication/octet-stream. SPL snippet:index=webserver uri_path="*/servlet/*" method=POST bytes_in>10000 | stats count by src_ip, uri_path. - Process ancestry (EDR/Sysmon EID 1): Child processes spawned by the Windchill/FlexPLM JVM process (
java.exe,javaw.exe) that launch unexpected binaries (cmd.exe,powershell.exe,sh,bash,curl,wget). Sigma shape:ParentImage|endswith: 'java.exe'ANDImage|endswith: ['cmd.exe','powershell.exe','sh','bash']. - Network telemetry (Zeek/Suricata): Outbound connections from the PLM server to external IPs on non-standard ports shortly after inbound POST requests — indicative of a reverse-shell callback.
- Linux auditd:
execvesyscalls with a parent PID matching the Java process that invoke shell interpreters or network utilities. Rule:-a always,exit -F arch=b64 -S execve -F ppid=<java_pid> -k cve_2026_12569. - Windows Event ID 4688 / Sysmon EID 1: Process creation events where
ParentCommandLinecontainswindchillorflexplmandCommandLinecontainspowershell,cmd,certutil,bitsadmin, ormshta.
Description
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
11.0m03011.0m030fixed from 11.0m030Metrics
Show all metrics
Weakness classes (CWE)
CWE-20Class
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
cwe.mitre.org →CWE-502Base
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
cwe.mitre.org →
Public exploit references
Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.