PTC Inc. is alerting users about a serious flaw in the popular product lifecycle management (PLM) programs Windchill and FlexPLM that may permit remote code execution.
The deserialization of trusted data could be used to exploit the security flaw known as CVE-2026-4681.
Because of its seriousness, German authorities have taken emergency action. According to reports, the federal police (BKA) have sent agents to the impacted organizations to warn them about the cybersecurity danger.
Although PTC claims to be “actively developing and releasing security patches for all supported Windchill versions” to fix the problem, there are currently no official patches available.
The company claims that the vulnerability affects all critical patch sets (CPS) versions as well as the majority of supported Windchill and FlexPLM versions read more about PTC warns of imminent threat from critical Windchill FlexPLM RCE bug.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
