Critical Vulnerability in Windchill and FlexPLM
PTC has identified a critical vulnerability in Windchill and FlexPLM (CVE-2026-12569) that requires immediate action. This vulnerability could allow an unauthorized user to execute code remotely.
The following eSupport article includes the full list of affected Windchill and FlexPLM versions and the remediation steps customers should take immediately: https://www.ptc.com/en/support/article/CS473270
If you have any questions about the remediation steps, please log a technical support case.
If your instance of Windchill and/or FlexPLM is hosted by PTC, remediation steps are being taken on your behalf. PTC will contact you directly if any additional action is required.
Updates on availability of patches will be provided below.
Patch Information
Version 13.1.2.8: PTC Software Download - under "Release 13.1 -> PTC Windchill Security Update Patches-> Show all other available Versions -> Version: 13-1-2-8"
Version 13.1.3.4: PTC Software Download - under "Release 13.1 -> PTC Windchill Security Update Patches-> Most Recent Version -> Version: 13-1-3-4"
Version 13.0.2: PTC Software Download - under "Release 13.0 -> PTC Windchill 13.0 Service Pack - Critical Patch Sets Bundles -> Version: 13-0-2-12 -> 13-0-XXXX-CPSXB3-TPATCH"
Version 12.1.2: PTC Software Download - under "Release 12.1 -> PTC Windchill 12.1 Service Pack - Critical Patch Sets Bundles -> Version: 12-1-2-22"
- 12-1-XXXX-CPSXB8-Applies-to-F000-CPS04
- 12-1-XXXX-CPSXB9-Applies-to-CPS05-CPS08
- 12-1-XXXX-CPSXB10-Applies-to-CPS09-CPS22
NOTE: Only 1 patch is required to be installed on the Windchill system; select the patch that applies to the CPS release currently installed.
Version 12.0.2: PTC Software Download - under "Release 12.0 -> PTC Windchill 12.0 Service Pack - Critical Patch Sets Bundles -> Version: 12-0-2-27"
- 12-0-XXXX-CPSXB5-Applies-to-F000-CPS05
- 12-0-XXXX-CPSXB6-Applies-to-CPS06-CPS14
- 12-0-XXXX-CPSXB7-Applies-to-CPS015-CPS17
- 12-0-XXXX-CPSXB8-Applies-to-CPS018-CPS27
NOTE: Only 1 patch is required to be installed on the Windchill system; select the patch that applies to the CPS release currently installed.
Version 11.2.1: PTC Software Download - under "Release 11.2 -> PTC Windchill 11.2 Service Pack - Critical Patch Sets Bundles -> Version: 11-2-1-24".
- 11-2-XXXX-CPSXB6-Applies-to-F000-CPS04
- 11-2-XXXX-CPSXB7-Applies-to-CPS05-CPS24
NOTE: Only 1 patch is required to be installed on the Windchill system; select the patch that applies to the CPS release currently installed.
Version 11.1 M020: PTC Software Download - under "Release 11.1 -> PTC Windchill 11.1 Service Pack - Critical Patch Sets Bundles -> Version: M020".
- 11-1-XXXX-CPSXB4-Applies-to-F000-CPS08
- 11-1-M020-CPS09-CPSXB2-Applies-to-CPS09
- 11-1-XXXX-CPSXB5-Applies-to-CPS10-CPS14
- 11-1-XXXX-CPSXB6-Applies-to-CPS15-CPS36
NOTE: Only 1 patch is required to be installed on the Windchill system; select the patch that applies to the CPS release currently installed.
Version 11.0 M030: PTC Software Download - under "Release 11.0 -> PTC Windchill 11.0 Service Pack - Critical Patch Sets Bundles -> Version: M030".
- 11-0-XXXX-CPSXB6-Applies-to-F000-CPS16
- 11-0-XXXX-CPSXB7-Applies-to-CPS17-CPS24
Version 13.1.1: PTC Software Download - under "Release 13.1 -> PTC Windchill 13.1 Service Pack - Critical Patch Sets Bundles -> Version: 13-1-1-5".
- 13-1-XXXX-CPSXB3-Applies-to-F000-CPS05
For Windchill and FlexPLM releases prior to 11.0 M030, it is important to note that your primary means of reducing risk is to ensure your system is not connected to the internet, which significantly reduces exposure. For guidance on a potential workaround, please refer to CS473493.