Particle.news
Download on the App Store

CISA Lists PTC Windchill RCE in KEV as Vendor Confirms Active Web‑Shell Attacks

The KEV listing forces expedited fixes for federal agencies and raises urgent risk to manufacturers that use Windchill for design and supply‑chain data.

Overview

  • CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog on Thursday, requiring federal civilian agencies to remediate the flaw by June 28.
  • PTC published patches on June 17 and released indicators of compromise the next day after confirming attackers were deploying persistent JSP web shells that enable remote command execution and data theft.
  • The vulnerability is a critical remote‑code‑execution bug in Windchill and FlexPLM caused by improper input validation and deserialization of untrusted data.
  • PTC and security firms published IoCs including attacker IP addresses and a web‑shell filename pattern (/Windchill/login/[16-hex].jsp) and advised customers to block listed IPs, scan logs and files, and limit internet exposure of Windchill endpoints.
  • Because Windchill is widely used in automotive, aerospace, defense and heavy machinery sectors, successful exploitation could affect product design, downstream supply chains and operational technology, increasing the chance of disruptive follow‑on incidents.