Skip to content
PTCCVE-2026-77645

PTC Windchill: remote code execution

Critical9.2CVE-2026-77645 · Published Aug 20, 2026 · updated Sep 9, 2026

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.

PTC advisory

Affected versions

PackageAffectedFixed in
FlexPLM
Product
<= 11.0 M030No fix yet
<= 11.1 M020No fix yet
<= 11.2.1.0No fix yet
<= 12.0.0.0No fix yet
Windchill PDMLink
Product
<= 11.0 M030No fix yet
<= 11.1 M020No fix yet
<= 11.2.1.0No fix yet
<= 12.0.2.0No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Red
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-20, CWE-502

More PTC advisories

All PTC
Advisory
PTC Windchill Risk and: improper access control
Critical9.3Aug 20
PTC Windchill PDMLink: server-side request forgery
High7.7Aug 20

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.