ICSA-26-085-03
·
Published 2026-03-26
·
View on CISA ICS-CERT ↗
PTC Windchill Product Lifecycle Management
CVSS 10.0
CRITICAL
Risk Summary
Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution.
CVEs (1)
Remediations
- PTC is aware of the issue and is actively developing a fix. In the meantime, PTC recommends applying the recommended workaround. Until official patches are available, customers must take urgent steps to safeguard their environments. Specifically: Protect any publicly accessible Windchill systems
- While publicly accessible Windchill and FlexPLM systems are at higher risk and require immediate attention, PTC strongly recommends applying the mitigation steps to all deployments, regardless of Internet exposure
- Apply the same precautions to FlexPLM deployments
- The following Apache and IIS HTTP Server configuration update should be IMMEDIATELY applied to every Windchill or FlexPLM system: Customers using Apache HTTP Server should only follow "Apache HTTP Server Configuration – Workaround Steps" section steps
- Customers using Microsoft IIS should only follow "IIS Configuration - Workaround Steps" section steps
- Please explicitly note that the same mitigation steps must also be applied on File Server / Replica Server configurations where applicable
- For Windchill releases prior to 11.0 M030, workarounds may need to be altered to apply to unsupported previous releases
- For Apache HTTP Server and IIS configuration workaround steps, please refer to the official advisory at:https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-critical-vulnerability.
- If immediate remediation is not feasible, additional guidance and remediation options are available:https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-critical-vulnerability.
Affected Vendors
PTC
Affected Products (20)
PTC
·
Windchill PDMLink
11.0_M030
PTC
·
Windchill PDMLink
11.1_M020
PTC
·
Windchill PDMLink
11.2.1.0
PTC
·
Windchill PDMLink
12.0.2.0
PTC
·
Windchill PDMLink
12.1.2.0
PTC
·
Windchill PDMLink
13.0.2.0
PTC
·
Windchill PDMLink
13.1.0.0
PTC
·
Windchill PDMLink
13.1.1.0
PTC
·
Windchill PDMLink
13.1.2.0
PTC
·
Windchill PDMLink
13.1.3.0
PTC
·
FlexPLM
11.0_M030
PTC
·
FlexPLM
11.1_M020
PTC
·
FlexPLM
11.2.1.0
PTC
·
FlexPLM
12.0.0.0
PTC
·
FlexPLM
12.0.2.0
PTC
·
FlexPLM
12.0.3.0
PTC
·
FlexPLM
12.1.2.0
PTC
·
FlexPLM
12.1.3.0
PTC
·
FlexPLM
13.0.2.0
PTC
·
FlexPLM
13.0.3.0
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more