CVE-2026-4681: Critical Remote Code Execution vulnerability reported in Windchill
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
This issue affects Windchill PDMLink: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0, 13.1.1.0, 13.1.2.0, 13.1.3.0; FlexPLM: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.0.0, 12.0.2.0, 12.0.3.0, 12.1.2.0, 12.1.3.0, 13.0.2.0, 13.0.3.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4681?
CVE-2026-4681 is classified as a critical remote code execution vulnerability.
How do I fix CVE-2026-4681?
To fix CVE-2026-4681, you should apply the latest security patches provided by PTC for Windchill and FlexPLM.
Which versions are affected by CVE-2026-4681?
CVE-2026-4681 affects specific versions of PTC Windchill PDMLink and PTC FlexPLM from 11.0 M030 through various versions up to 13.1.3.0.
What type of attack can exploit CVE-2026-4681?
CVE-2026-4681 can be exploited through the deserialization of untrusted data leading to remote code execution.
Who should be concerned about CVE-2026-4681?
Organizations using the affected versions of PTC Windchill PDMLink and PTC FlexPLM should be concerned about CVE-2026-4681 due to its critical nature.