Answer in brief
CVE-2026-12569 records a Critical severity (CVSS 9.8) vulnerability in Remote Code Execution (RCE) vulnerability in Windchill PDMlink. The current sources mark it as known exploited. The current feed maps PTC/FlexPLM (generic), PTC/Windchill PDMLink (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.8. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps PTC/FlexPLM (generic), PTC/Windchill PDMLink (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| PTC/FlexPLMgeneric | 0 || 11.1 M020 || 11.2.1.0 || 12.0.0.0 || 12.0.2.0 || 12.1.2.0 || 12.1.3.0 || 13.0.2.0 || 13.0.3.0 | Not reported |
| PTC/Windchill PDMLinkgeneric | 0 || 11.1 M020 || 11.2.1.0 || 12.0.2.0 || 12.1.2.0 || 13.0.2.0 || 13.1.0.0 || 13.1.1.0 || 13.1.2.0 || 13.1.3.0 | Not reported |
Published upstream
Jun 18, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 1, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 22, 2026
Added to CISA KEV
Jun 25, 2026
Evidence: source:kev:kev:kev:recordA critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-12569 records a Critical severity (CVSS 9.8) vulnerability in Remote Code Execution (RCE) vulnerability in Windchill PDMlink. The current sources mark it as known exploited. The current feed maps PTC/FlexPLM (generic), PTC/Windchill PDMLink (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.8. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps PTC/FlexPLM (generic), PTC/Windchill PDMLink (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| PTC/FlexPLMgeneric | 0 || 11.1 M020 || 11.2.1.0 || 12.0.0.0 || 12.0.2.0 || 12.1.2.0 || 12.1.3.0 || 13.0.2.0 || 13.0.3.0 | Not reported |
| PTC/Windchill PDMLinkgeneric | 0 || 11.1 M020 || 11.2.1.0 || 12.0.2.0 || 12.1.2.0 || 13.0.2.0 || 13.1.0.0 || 13.1.1.0 || 13.1.2.0 || 13.1.3.0 | Not reported |
Published upstream
Jun 18, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 1, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 22, 2026
Added to CISA KEV
Jun 25, 2026
Evidence: source:kev:kev:kev:recordA critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030
Quoted source text, attributed separately from HOL analysis.