CVE-2026-77645

Windchill: Improper Input Validation (CVE-2026-77645)

Affected

  • PTC/Windchill range_unparsed *..Risk and Reliability (WRR) Enterprise Edition <13.1.0.1
  • PTC/Windchill = PDMLink..PDMLink

Description

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.

Source: BSI

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

PTCWindchill
PDMLinkRisk and Reliability (WRR) Enterprise Edition <13.1.0.1

Metrics

9.2
Source: cna-v4
44.9 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
high
no public PoC known
0.6 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-21 11:51 UTC
CWE-20, CWE-502

Weakness classes (CWE)

  • CWE-20Class

    Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

    cwe.mitre.org →
  • CWE-502Base

    Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-08-22 04:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-77645","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI… → {"id":"CVE-2026-77645","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  2. CVE Modified2026-08-21 15:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-77645","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…

Linked CVEs