CRITICALAdvisoryAug 20, 2026
Action required
Immediately patch PTC Windchill and FlexPLM to the latest version addressing CVE-2026-12569. Scan all Windchill servers for JSP web shells in web directories. Force password reset for all Windchill and LDAP service accounts. Review recent Windchill access logs for suspicious activity and lateral movement indicators.
Affected products
PTC WindchillFlexPLM
CVE IDs