PTCCVE-2026-77646
PTC Windchill PDMLink: server-side request forgery
High7.7CVE-2026-77646 · Published Aug 20, 2026 · updated Sep 9, 2026
A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| FlexPLM Product | <= 11.0 M030 | No fix yet |
| <= 11.1 M020 | No fix yet | |
| <= 11.2.1.0 | No fix yet | |
| <= 12.0.0.0 | No fix yet | |
| Windchill PDMLink Product | <= 11.0 M030 | No fix yet |
| <= 11.1 M020 | No fix yet | |
| <= 11.2.1.0 | No fix yet | |
| <= 12.0.2.0 | No fix yet |
Details and references
More PTC advisories
All PTC| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 20 | PTC Windchill Risk and: improper access control | Critical9.3 | No fix yet |
| Aug 20 | PTC Windchill: remote code execution | Critical9.2 | No fix yet |