Threat Management, Threat Intelligence, Vulnerability Management, Patch/Configuration Management

Critical PTC Windchill, FlexPLM vulnerability poses RCE risk

Laptop Screen Warning Alert: Cyber Attack, Virus, Malware, Spyware, System Hacked

U.S. computer software and services provider PTC has alerted that potential exploitation of a critical flaw in its product lifecycle management solutions FlexPLM and Windchill via trusted data deserialization could result in remote code execution, reports BleepingComputer.

The bug, tracked as CVE-2026-4681, affects most supported FlexPLM and Windchill versions and critical patch set versions. The company released specific indicators of compromise, which include a user agent string and files. It also mentioned there is no evidence of the flaw being exploited, but that "there is credible evidence of an imminent threat by a third-party group to exploit the vulnerability."

The vendor urged system administrators to prioritize internet-facing instances but apply the mitigation to all deployments, including file/replica servers, and apply the provided Apache/IIS rule to deny access to the impacted servlet path. Affected instances that cannot be mitigated should be shut down or disconnected from the internet.

PTC said it is "actively developing and releasing security patches for all supported Windchill versions" to fix the flaw.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds