FAIL › dossier
PTC
COMPANY FEDRAMP MARKETFedRAMP provider · · dossier confidence 50%
PTC's core PLM platforms suffered a critical unauthenticated RCE that was actively exploited in the wild, revealing a severe vulnerability management gap in their industrial software.
PROFILE
CategoryIndustrial SoftwareWhat they doPTC develops and sells industrial software for product lifecycle management, including Windchill and FlexPLM.
SECURITY POSTURE
PTC has a critical vulnerability management gap, evidenced by a high-severity unauthenticated RCE in Windchill and FlexPLM that was actively exploited in the wild in mid-2026.
Notable failures
- CVE-2026-12569: Unauthenticated RCE in Windchill/FlexPLM actively exploited
Patterns: Critical unpatched RCEs in core PLM products
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-06-25 | CVE-2026-12569 | high | PTC Windchill and FlexPLM suffered a critical unauthenticated remote code execution vulnerability (CVE-2026-12569) actively exploited in the wild. |
| 2026-06-18 | CVE-2026-12569 | critical | CVE-2026-12569: A critical remote code execution (RCE) vulnerability has been reported in PTC Wi |
FEDRAMP CATALOG PRODUCTS · 1
| PRODUCT | STATUS | IMPACT |
|---|---|---|
| PTC Cloud Services | Authorized | Moderate |
Open questions: PTC's patch deployment timeline for CVE-2026-12569 · Whether other PTC products share the same RCE vulnerability
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-27 04:07:14.030474+00:00