Remote Code Execution Vulnerability in PTC Windchill and FlexPLM
CVE-2026-77645

9.2CRITICAL

Key Information:

Vendor

Ptc

Vendor
CVE Published:
20 August 2026

What is CVE-2026-77645?

A remote code execution vulnerability has been identified in PTC Windchill and PTC FlexPLM that could be exploited via the deserialization of untrusted data. Attackers could leverage this flaw to execute arbitrary code on the system, impacting the integrity and availability of the affected software. Mitigation efforts should focus on securing data deserialization processes and implementing stringent input validation measures to protect against potential exploitation.

Affected Version(s)

FlexPLM 11.0 M030

FlexPLM 11.1 M020

FlexPLM 11.2.1.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arthur Aires (https://arthurair.es/)
brenocss (LinkedIn: @brenocss)
Bruno Milreu (LinkedIn: @bruno-milreu)
.