CVE Tools

JSP webshells being dropped on unpatched PTC Windchill instances

Help Net SecurityBy Zeljka Zorz

Reported exploitedWindchillFlexPLM

Our summary

CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog, warning that PTC Windchill and FlexPLM are being targeted in the wild. PTC reports that attackers can exploit the improper input validation flaw (unauthenticated remote code execution) and has observed indicators consistent with JSP webshells being deployed on vulnerable systems.
Organizations using affected PTC product lifecycle management deployments should apply the relevant patches and check their environments for indicators of compromise.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store