CISA Adds PTC Windchill RCE Flaw to KEV Catalog

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- CISA added CVE-2026-12569, an improper input validation / deserialization RCE flaw in PTC Windchill PDMlink and PTC FlexPLM (CVSS 9.3), to its KEV catalog on Thursday, citing active exploitation
- PTC confirmed on June 25 that 'heightened threat activity' is continuing despite patches being released the prior week, with attackers deploying JSP web shells against vulnerable systems
- The web shells follow a distinct naming pattern — /Windchill/login/[0-9a-f]{16}.jsp — making filesystem scanning a primary detection method per PTC's advisory
- PTC's IoC list includes five IP addresses (172.111.38.31, 216.152.148.54, 104.243.35.131, 74.50.76.146, 5.180.41.35), with 5.180.41.35 explicitly identified as the attacker command-and-control address
- Detection guidance from PTC includes a specific file hash (55a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c), a check for flst.txt in /tmp or the Windchill working directory, and a WAF rule blocking requests with the header X-windchill-req:
- This is the first PTC product vulnerability ever added to the KEV catalog, underscoring how threat actors are rapidly weaponizing newly disclosed flaws in industrial PLM/PDM software
Why it matters: Federal civilian agencies now face a binding remediation deadline under CISA's KEV process, and the fact that patches shipped last week yet exploitation is already deploying JSP web shells illustrates how quickly attackers are industrializing attacks on PTC's enterprise PLM platform.




