Critical RCE Vulnerability reported in Windchill (PTC Article - CS466318)

Critical RCE Vulnerability reported in Windchill (PTC Article - CS466318)

Applies To

  • Windchill PDMLink 11.0 M030
  • Windchill PDMLink 11.1 M020
  • Windchill PDMLink 11.2.1.0
  • Windchill PDMLink 12.0.2.0
  • Windchill PDMLink 12.1.2.0
  • Windchill PDMLink 13.0.2.0
  • Windchill PDMLink 13.1.0.0
  • Windchill PDMLink 13.1.1.0
  • Windchill PDMLink 13.1.2.0
  • Windchill PDMLink 13.1.3.0
  • FlexPLM 11.0 M030
  • FlexPLM 11.1 M020
  • FlexPLM 11.2.1.0
  • FlexPLM 12.0.0.0
  • FlexPLM 12.0.2.0
  • FlexPLM 12.0.3.0
  • FlexPLM 12.1.2.0
  • FlexPLM 12.1.3.0
  • FlexPLM 13.0.2.0
  • FlexPLM 13.0.3.0
  • This advisory applies to all CPS versions
  • The identified vulnerability impacts Windchill and FlexPLM releases prior to 11.0 M030

Description

  • The vulnerability is a Remote Code Execution (RCE) issue that may be exploited through deserialization of untrusted data
  • CVE-2026-4681 has been reported
  • At this time, there is no evidence of confirmed exploitation affecting PTC customers

Resolution

    • Related Articles

    • Firewall Settings for Creo

      1) Checked the license file to make sure it was installed on the correct server. 2) Pinged the server to make sure computer and server were talking to each other 3) Created Outbound and Inbound rules on computer and server to accept port 7788 4) ...