Overview
- CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog on Thursday, requiring federal civilian agencies to remediate the flaw by June 28.
- PTC published patches on June 17 and released indicators of compromise the next day after confirming attackers were deploying persistent JSP web shells that enable remote command execution and data theft.
- The vulnerability is a critical remote‑code‑execution bug in Windchill and FlexPLM caused by improper input validation and deserialization of untrusted data.
- PTC and security firms published IoCs including attacker IP addresses and a web‑shell filename pattern (/Windchill/login/[16-hex].jsp) and advised customers to block listed IPs, scan logs and files, and limit internet exposure of Windchill endpoints.
- Because Windchill is widely used in automotive, aerospace, defense and heavy machinery sectors, successful exploitation could affect product design, downstream supply chains and operational technology, increasing the chance of disruptive follow‑on incidents.