Skip to content
COOEY

FAIL › dossier

PTC

COMPANY FEDRAMP MARKET

FedRAMP provider · · dossier confidence 50%

PTC's core PLM platforms suffered a critical unauthenticated RCE that was actively exploited in the wild, revealing a severe vulnerability management gap in their industrial software.

PROFILE
CategoryIndustrial SoftwareWhat they doPTC develops and sells industrial software for product lifecycle management, including Windchill and FlexPLM.
SECURITY POSTURE

PTC has a critical vulnerability management gap, evidenced by a high-severity unauthenticated RCE in Windchill and FlexPLM that was actively exploited in the wild in mid-2026.

Notable failures
  • CVE-2026-12569: Unauthenticated RCE in Windchill/FlexPLM actively exploited
Patterns: Critical unpatched RCEs in core PLM products
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2026-06-25 CVE-2026-12569 high PTC Windchill and FlexPLM suffered a critical unauthenticated remote code execution vulnerability (CVE-2026-12569) actively exploited in the wild.
2026-06-18 CVE-2026-12569 critical CVE-2026-12569: A critical remote code execution (RCE) vulnerability has been reported in PTC Wi
FEDRAMP CATALOG PRODUCTS · 1
PRODUCTSTATUSIMPACT
PTC Cloud ServicesAuthorizedModerate
Open questions: PTC's patch deployment timeline for CVE-2026-12569 · Whether other PTC products share the same RCE vulnerability
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-27 04:07:14.030474+00:00