← Back to home
ICSA-26-085-03  ·  Published 2026-03-26  ·  View on CISA ICS-CERT ↗

PTC Windchill Product Lifecycle Management

CVSS 10.0 CRITICAL

Risk Summary

Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution.

CVEs (1)

Remediations

  • PTC is aware of the issue and is actively developing a fix. In the meantime, PTC recommends applying the recommended workaround. Until official patches are available, customers must take urgent steps to safeguard their environments. Specifically: Protect any publicly accessible Windchill systems
  • While publicly accessible Windchill and FlexPLM systems are at higher risk and require immediate attention, PTC strongly recommends applying the mitigation steps to all deployments, regardless of Internet exposure
  • Apply the same precautions to FlexPLM deployments
  • The following Apache and IIS HTTP Server configuration update should be IMMEDIATELY applied to every Windchill or FlexPLM system: Customers using Apache HTTP Server should only follow "Apache HTTP Server Configuration – Workaround Steps" section steps
  • Customers using Microsoft IIS should only follow "IIS Configuration - Workaround Steps" section steps
  • Please explicitly note that the same mitigation steps must also be applied on File Server / Replica Server configurations where applicable
  • For Windchill releases prior to 11.0 M030, workarounds may need to be altered to apply to unsupported previous releases
  • For Apache HTTP Server and IIS configuration workaround steps, please refer to the official advisory at:https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-critical-vulnerability.
  • If immediate remediation is not feasible, additional guidance and remediation options are available:https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-critical-vulnerability.

Affected Vendors

PTC

Affected Products (20)

PTC · Windchill PDMLink 11.0_M030
PTC · Windchill PDMLink 11.1_M020
PTC · Windchill PDMLink 11.2.1.0
PTC · Windchill PDMLink 12.0.2.0
PTC · Windchill PDMLink 12.1.2.0
PTC · Windchill PDMLink 13.0.2.0
PTC · Windchill PDMLink 13.1.0.0
PTC · Windchill PDMLink 13.1.1.0
PTC · Windchill PDMLink 13.1.2.0
PTC · Windchill PDMLink 13.1.3.0
PTC · FlexPLM 11.0_M030
PTC · FlexPLM 11.1_M020
PTC · FlexPLM 11.2.1.0
PTC · FlexPLM 12.0.0.0
PTC · FlexPLM 12.0.2.0
PTC · FlexPLM 12.0.3.0
PTC · FlexPLM 12.1.2.0
PTC · FlexPLM 12.1.3.0
PTC · FlexPLM 13.0.2.0
PTC · FlexPLM 13.0.3.0

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more