CVE-2026-12569: PTC Windchill PDMLink / FlexPLM Unauthenticated Deserialization RCE (CISA KEV, JSP Web Shell Campaign) — Threadlinqs Intelligence
As of 2026-07-26, CVE-2026-12569: PTC Windchill PDMLink / FlexPLM Unauthenticated Deserialization RCE (CISA KEV, JSP Web Shell Campaign) is a critical-severity vulnerability threat attributed to Cl0p, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 46 indicators of compromise.
Threat ID: TL-2026-0954 · Severity: CRITICAL · CVSS: 9.3 · Status: ACTIVE · Category: VULNERABILITY
Updated: 2026-07-26 · 2 updates · revalidated 2× · latest source
Attribution: Cl0p · FINANCIAL
CVE-2026-12569 is a critical (CVSS 9.3) unauthenticated remote code execution flaw in PTC Windchill PDMLink and FlexPLM caused by deserialization of untrusted data (CWE-502 / CWE-20). A single crafted
CVE-2026-12569 is an improper-input-validation / unsafe-deserialization vulnerability (CWE-20, CWE-502) in PTC Windchill PDMLink and PTC FlexPLM, the Product Lifecycle Management (PLM) platforms used across manufacturing, engineering, aerospace, defense, automotive, footwear/apparel and consumer-goods sectors (PTC reports over 1.5 million users globally, including organisations such as BMW, Lockheed Martin, Boeing and NVIDIA).
The flaw resides in the Windchill Visualization Service (WVS) Publish servlet path family (e.g. /servlet/WindchillGW/com.ptc.wvs.server.publish.Publish and the /servlet/WindchillAuthGW/ variant), which deserializes attacker-controlled data from network requests without adequate validation. Because the affected endpoint is reachable pre-authentication and the attack vector is network-based (AV:N/AC:L/PR:N/UI:N), a remote unauthenticated attacker can submit a crafted serialized payload that executes arbitrary code with the privileges of the Windchill/FlexPLM service process. CVSS v3.1 is scored 9.3-9.8 critical (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Post-exploitation, the actors write JSP web shells to the application's web root under the login path, using a randomised naming convention matching /Windchill/login/[0-9a-f]{16}.jsp. These web shells provide persistent remote command execution and data-exfiltration capability. Observed tradecraft from the closely-related Windchill/FlexPLM RCE research (CVE-2026-4681, same products and deserialization vector) includes payload parameters such as run?p=, .jsp?p=, run?c=, .jsp?c=, dropped class artifacts (GW.class, Gen.class) and randomly-named JSP files (dpr_<hex>.jsp). A telemetry artifact, flst.txt, written to /tmp or the Windchill working directory, confirms attacker file-listing/discovery activity. Requests carrying an X-windchill-req: header have been recommended as a WAF/IDS detection signal.
Network IOCs published with the campaign include the C2/exploitation IP 5.180.41.35 (command-and-control) plus exploitation sources 172.111.38.31, 216.152.148.54, 104.243.35.131 and 74.50.76.146. A BeaconBeagle lookup for the C2 IP 5.180.41.35 returned no indexed beacon/framework record at research time, so no specific C2 framework (e.g. Cobalt Strike/Sliver) attribution can be made from infrastructure correlation.
PTC alerted customers and issued mitigations on 2026-06-17, published IOCs on 2026-06-18, and released patches across the supported branches (11.0 M030, 11.1 M020, 11.2.1, 12.0.2, 12.1.2, 13.0.2, 13.1.1) by 2026-06-19. CISA added the CVE to the KEV catalog (2026-06-25, with the BOD 22-01 federal remediation deadline of 2026-06-28). Attribution remains unknown; targeting of PLM systems is consistent with intellectual-property theft against high-value industrial and defense supply chains. Interim mitigation where patching is not yet possible is to deny access to the vulnerable WVS Publish servlet path via an Apache LocationMatch "Require all denied" rule or an equivalent IIS URL-rewrite rule returning HTTP 403, and to restrict internet exposure of the Windchill login endpoint.
Weaknesses (CWE)
CWE-502, CWE-20
Target sectors: defense, aerospace, automotive, manufacturing, healthcare, electronics, industrial machinery, consumer goods, footwear and apparel, retail
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-08-07, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 46 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-12569, T1595, T1588, T1583, T1190, T1059, T1203, T1505, T1036, T1083, T1082