Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-12569 -- CVSS 9.8 Vulnerability Briefing

CVE-2026-12569 | CVSS 9.8 (Critical) | Exploit: PoC available

What Is It

CVE-2026-12569 is a critical remote code execution vulnerability in PTC Windchill PDMlink and PTC FlexPLM caused by deserialization of untrusted data.

Technical Detail

The affected applications may deserialize attacker-controlled data without sufficient validation, allowing malicious serialized objects to be processed. An attacker able to reach the vulnerable deserialization path may execute arbitrary code on the affected system. The advisory applies to all CPS versions and indicates that Windchill and FlexPLM releases earlier than 11.0 M030 are also impacted.

Exploitation Status

A proof-of-concept exploit is available. CISA has not listed CVE-2026-12569 in its Known Exploited Vulnerabilities Catalog, and active exploitation in the wild has not been confirmed by the available data.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Prioritize remediation as critical, particularly for internet-accessible Windchill PDMlink and FlexPLM deployments. Apply the vendor-provided security update or fixed release for the affected product and version, including applicable CPS updates; verify whether releases prior to 11.0 M030 remain in scope. Until patching is complete, restrict access to affected application interfaces to trusted users and networks, remove unnecessary internet exposure, and monitor application and server logs for unexpected deserialization errors, anomalous requests, suspicious child processes, and unauthorized changes to application or system files. No vendor workaround or specific detection indicators are provided in the available data.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →