CVE-2026-12569

flexplm: Improper Input Validation (CVE-2026-12569)

Situation assessment

A critical remote code execution (RCE) vulnerability in PTC Windchill PDMlink and PTC FlexPLM allows an unauthenticated attacker to execute arbitrary code by sending a malicious request over the network. This vulnerability is actively exploited in ransomware campaigns since June 2026. All versions of Windchill and FlexPLM prior to 11.0 M030 are affected. Immediate patching to version 11.0 M030 or later is urgently required to mitigate the vulnerability.

Affected

  • ptc/flexplm between *..11.0m030
  • ptc/windchill_pdmlink lt *..11.0m030

Response & Mitigation

Why act now?

Prioritisation rationale

CVE-2026-12569 scores CVSS 9.8 (AV:N/AC:L/PR:N/UI:N) with an EPSS percentile of 98.6 %, placing it among the most likely-to-be-exploited vulnerabilities across the entire CVE corpus. The attack requires no authentication, no user interaction, and no special conditions — a single malicious network request is sufficient for full system compromise via Java deserialization. CISA has confirmed active ransomware campaign use, indicating that exploitation is not merely theoretical but part of ongoing, opportunistic attack waves. For NIS2-scoped organisations running Windchill or FlexPLM in production or engineering environments, the risk is compounded by the sensitivity of PLM data (IP, design files) and frequent connectivity to OT networks, making this a patch-now, no-exception priority.

Runbook · Step 1

Immediate response (0-24 h)

  • Apply the vendor patch: Consult the PTC security advisory for CVE-2026-12569 and upgrade PTC Windchill PDMLink and FlexPLM to version 11.0 M030 or later. Note that all CPS versions are also in scope — verify patch coverage across every instance. Confirm the exact patch identifier in the current PTC advisory.
  • Network isolation: Immediately restrict inbound HTTP/HTTPS traffic (TCP 80/443) to Windchill and FlexPLM servers from the internet and from untrusted internal segments. Only authorised client subnets and integration servers should reach application ports.
  • Enumerate exposed endpoints: Inventory all web-facing endpoints of Windchill/FlexPLM instances (servlet paths, REST APIs, SOAP endpoints). Disable any endpoint that is not operationally required.
  • Verify authentication enforcement: Confirm that no Windchill or FlexPLM endpoint is reachable unauthenticated from the internet. Review reverse-proxy and load-balancer configurations for authentication bypass paths.
  • Triage historical logs: Review web server access logs and application logs for the past 30 days for anomalous POST requests to known deserialization endpoints (e.g. /Windchill/servlet/, /FlexPLM/servlet/). Treat suspicious entries as potential indicators of prior compromise.

Runbook · Step 2

Mitigation layers

  • WAF rule (network layer): Enable a WAF signature that detects serialised Java objects in HTTP request bodies — match on Content-Type application/x-java-serialized-object and magic bytes AC ED 00 05. Block or quarantine matching requests.
  • IPS signature: Deploy a Suricata/Snort rule targeting Java deserialization payloads inbound to Windchill/FlexPLM ports. Suggested shape: alert http any any -> $WINDCHILL_SERVERS [80,443] (msg:"CVE-2026-12569 Java Deserialization Attempt"; content:"|AC ED 00 05|"; http_client_body; sid:2026125690; rev:1;).
  • Network segmentation: Move PLM servers into a dedicated VLAN with strict east-west firewall rules. Block all outbound connections from the PLM server to the internet — this prevents reverse-shell callbacks following a successful RCE.
  • JEP 290 deserialization filter: Configure a global Java Serialization Filter (JEP 290) on the application server to allow only explicitly whitelisted classes. Deny-list all classes not required by the application.
  • Least-privilege service accounts: Ensure the Windchill/FlexPLM process runs under a service account with minimal OS privileges (no local admin, no SYSTEM/root). This limits the blast radius of a successful exploit.
  • Credential rotation: Proactively rotate all service account credentials, API keys, and database passwords used by Windchill/FlexPLM — especially if log review reveals suspicious prior access.

Runbook · Step 3

Detection rules

  • Web server access logs: Anomalous POST requests to servlet paths with unusually large body sizes (>10 KB) and Content-Type application/x-java-serialized-object or application/octet-stream. SPL snippet: index=webserver uri_path="*/servlet/*" method=POST bytes_in>10000 | stats count by src_ip, uri_path.
  • Process ancestry (EDR/Sysmon EID 1): Child processes spawned by the Windchill/FlexPLM JVM process (java.exe, javaw.exe) that launch unexpected binaries (cmd.exe, powershell.exe, sh, bash, curl, wget). Sigma shape: ParentImage|endswith: 'java.exe' AND Image|endswith: ['cmd.exe','powershell.exe','sh','bash'].
  • Network telemetry (Zeek/Suricata): Outbound connections from the PLM server to external IPs on non-standard ports shortly after inbound POST requests — indicative of a reverse-shell callback.
  • Linux auditd: execve syscalls with a parent PID matching the Java process that invoke shell interpreters or network utilities. Rule: -a always,exit -F arch=b64 -S execve -F ppid=<java_pid> -k cve_2026_12569.
  • Windows Event ID 4688 / Sysmon EID 1: Process creation events where ParentCommandLine contains windchill or flexplm and CommandLine contains powershell, cmd, certutil, bitsadmin, or mshta.

Description

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

ptcflexplm
11.0m030
ptcwindchill_pdmlink
11.0m030fixed from 11.0m030

Metrics

9.8
Source: nvd-v3
98.8 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Actively exploited
Show all metrics
Severity
critical
actively exploited (KEV)
46.1 %
Elevated — model estimates 10-50% exploitation likelihood.
Published
2026-06-25 00:00 UTC
CWE-20, CWE-502

Weakness classes (CWE)

  • CWE-20Class

    Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

    cwe.mitre.org →
  • CWE-502Base

    Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

    cwe.mitre.org →

Public exploit references

Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.

References & sources

Linked advisories