Security · 2h ago
CISA Flags Actively Exploited PTC Windchill RCE Bug
CISA added a critical remote code execution vulnerability in PTC Windchill PDMlink and FlexPLM to its Known Exploited Vulnerabilities catalog due to active exploitation. The flaw allows attackers to execute arbitrary code on affected systems. Organizations are urged to apply patches immediately.
Meridian48 take
While CISA's KEV inclusion is standard, the ongoing web shell attacks suggest this bug is being widely weaponized, making patching urgent for manufacturers.
Read the full reporting
CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue →
The Hacker News
cisa-kevptc-windchill