CVE Tools

CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue

The Hacker NewsBy The Hacker News

Reported exploitedPTC WindchillPTC FlexPLM

Our summary

CISA has added a actively exploited remote code execution flaw to its Known Exploited Vulnerabilities (KEV) catalog, affecting PTC Windchill PDMlink and PTC FlexPLM. The issue is tracked as CVE-2026-12569 (CVSS 9.3), where improper input validation can enable arbitrary code execution. PTC reports that attackers are continuing to use the vulnerability to install JSP web shells on vulnerable systems, underscoring the risk of rapid weaponization after patch releases.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store