U.S. computer software and services provider PTC has alerted that potential exploitation of a critical flaw in its product lifecycle management solutions FlexPLM and Windchill via trusted data deserialization could result in remote code execution, reports BleepingComputer.
The bug, tracked as CVE-2026-4681, affects most supported FlexPLM and Windchill versions and critical patch set versions. The company released specific indicators of compromise, which include a user agent string and files. It also mentioned there is no evidence of the flaw being exploited, but that "there is credible evidence of an imminent threat by a third-party group to exploit the vulnerability."
The vendor urged system administrators to prioritize internet-facing instances but apply the mitigation to all deployments, including file/replica servers, and apply the provided Apache/IIS rule to deny access to the impacted servlet path. Affected instances that cannot be mitigated should be shut down or disconnected from the internet.
PTC said it is "actively developing and releasing security patches for all supported Windchill versions" to fix the flaw.
The bug, tracked as CVE-2026-4681, affects most supported FlexPLM and Windchill versions and critical patch set versions. The company released specific indicators of compromise, which include a user agent string and files. It also mentioned there is no evidence of the flaw being exploited, but that "there is credible evidence of an imminent threat by a third-party group to exploit the vulnerability."
The vendor urged system administrators to prioritize internet-facing instances but apply the mitigation to all deployments, including file/replica servers, and apply the provided Apache/IIS rule to deny access to the impacted servlet path. Affected instances that cannot be mitigated should be shut down or disconnected from the internet.
PTC said it is "actively developing and releasing security patches for all supported Windchill versions" to fix the flaw.
