CVE-2026-77646: Server Side Request Forgery (SSRF) vulnerability reported in Windchill
Published Aug 20, 2026
·Updated
A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
Affected Software
2 affected components
PTC Windchill PDMlink
PTC FlexPLM
Event History
Aug 20, 2026
CVE Published
via MITRE·10:11 PM
Data Sourced
via MITRE·10:11 PM
DescriptionWeakness
Frequently Asked Questions
1
Which PTC products are reported to be affected?
The reported affected products are PTC Windchill PDMLink and PTC FlexPLM.
2
What exploitation condition is identified?
The vulnerability may be exploited through deserialization of untrusted data.