CVE-2026-12569

EUVD-2026-37831
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.   *  This advisory also applies to all CPS versions
  *  The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 81%
Affected Products (NVD)
VendorProductVersion
ptcflexplm
𝑥
≤ 11.0m030
ptcflexplm
11.1m020:m020
ptcflexplm
11.2.1.0
ptcflexplm
12.0.0.0
ptcflexplm
12.0.2.0
ptcflexplm
12.1.3.0
ptcflexplm
13.0.2.0
ptcflexplm
13.0.3.0
ptcwindchill_pdmlink
𝑥
< 11.0m030
ptcwindchill_pdmlink
11.0m030:m030
ptcwindchill_pdmlink
11.1m020:m020
ptcwindchill_pdmlink
11.2.1.0
ptcwindchill_pdmlink
12.0.2.0
ptcwindchill_pdmlink
12.1.2.0
ptcwindchill_pdmlink
13.0.2.0
ptcwindchill_pdmlink
13.1.0.0
ptcwindchill_pdmlink
13.1.1.0
ptcwindchill_pdmlink
13.1.2.0
ptcwindchill_pdmlink
13.1.3.0
𝑥
= Vulnerable software versions