Remote Code Execution Vulnerability in PTC Windchill and FlexPLM
CVE-2026-77645
9.2CRITICAL
What is CVE-2026-77645?
A remote code execution vulnerability has been identified in PTC Windchill and PTC FlexPLM that could be exploited via the deserialization of untrusted data. Attackers could leverage this flaw to execute arbitrary code on the system, impacting the integrity and availability of the affected software. Mitigation efforts should focus on securing data deserialization processes and implementing stringent input validation measures to protect against potential exploitation.
Affected Version(s)
FlexPLM 11.0 M030
FlexPLM 11.1 M020
FlexPLM 11.2.1.0
References
CVSS V4
Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Arthur Aires (https://arthurair.es/)
brenocss (LinkedIn: @brenocss)
Bruno Milreu (LinkedIn: @bruno-milreu)
