PatchSiren

PTC CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH PTC CVE published 2026-08-20

CVE-2026-77646

A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data, potentially allowing attackers to make unauthorized requests. Organizations should verify their installations and mitigate potential risks. This CVE record was published on 2026-08-20T22:18:06.657Z and has not been [truncated]

CRITICAL PTC CVE published 2026-08-20

CVE-2026-77645

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability, identified as CVE-2026-77645, may be exploited through the deserialization of untrusted data. Organizations using these products should be aware of the potential risks and take necessary actions to mitigate them. The CVE record was published on 2026-08-20T22:18:06.510Z and has not be [truncated]

CRITICAL PTC CVE published 2026-08-20

CVE-2026-77644

A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition. This vulnerability, CVE-2026-77644, has a CVSS score of 9.3, indicating a high severity level. Organizations using this product should verify their inventory and apply vendor remediation as necessary. The CVE record was published on 2026-08-20T22:18:06.357Z and has not been modi [truncated]

Known exploited PTC CVE published 2026-06-25

CVE-2026-12569

A critical vulnerability exists in PTC Windchill and FlexPLM, which are susceptible to improper input validation. This vulnerability has been added to the CISA Known Exploited Vulnerabilities catalog, indicating known exploitation in the wild. PTC has provided an official article (CS473270) addressing this issue. The CVE Program and NVD have also documented this vulnerability, providing additional details.

CRITICAL PTC CVE published 2026-03-26

CVE-2026-4681

CVE-2026-4681 is a critical remote code execution vulnerability affecting PTC Windchill PDMLink and PTC FlexPLM. The CISA CSAF advisory states the issue may be exploited through deserialization of untrusted data and assigns a CVSS v3.1 score of 10.0. CISA’s record republishes PTC’s CS466318 and notes workaround guidance is available while PTC develops a fix. Publicly accessible Windchill systems are calle [truncated]

MEDIUM PTC CVE published 2024-08-15

CVE-2024-6098

PTC Kepware ThingWorx Kepware Server is affected by a denial-of-service vulnerability in the ControlLogix protocol online tag generation feature. When this feature is enabled, a machine-in-the-middle attacker or a misconfigured device can send a crafted response that triggers unrestricted resource allocation, crashing the Kepware application. The vulnerability is rated CVSS 3.1 5.3 (Medium) with an attack [truncated]

CRITICAL PTC CVE published 2024-06-25

CVE-2024-6071

PTC Creo Elements/Direct License Server contains a critical unauthenticated remote code execution vulnerability. The license server's web interface allows unauthenticated remote attackers to execute arbitrary operating system commands on the server, resulting in complete system compromise. This vulnerability affects multiple products in the Creo Elements/Direct product family that rely on the affected lic [truncated]

HIGH PTC CVE published 2024-05-07

CVE-2024-3951

PTC Codebeamer contains a cross-site scripting (XSS) vulnerability that could allow an attacker to inject and execute malicious code. The vulnerability was disclosed by CISA on May 7, 2024, with a CVSS 3.1 score of 7.1 (HIGH). Affected versions include Codebeamer 22.10 SP9 and earlier, 2.0.0.3 and earlier, and version 2.1.0.0. PTC has released patches addressing this issue.