CVE-2026-4681Disclosure

MEDIUMCVSS 9.3 · CRITICAL

Exploitation observed; activity peaked at 9 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. This issue affects Windchill PDMLink: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0, 13.1.1.0, 13.1.2.0, 13.1.3.0; FlexPLM: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.0.0, 12.0.2.0, 12.0.3.0, 12.1.2.0, 12.1.3.0, 13.0.2.0, 13.0.3.0.

5.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 8 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 41 mentions across 14 observed days

What's happening

  • Active exploitation reported across 8 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 16 signals
  • Technical details provided in 34 signals
  • Disclosure: 23 classified signals
  • Peaked 11d ago at 9 mentions (2026-03-25); latest day: 1
  • 41 total mentions across 14 days

Deep dive

Activity timeline41 mentions / 14d
02579Mentions · 2026-03-23: 2Mentions · 2026-03-24: 5Mentions · 2026-03-25: 9Mentions · 2026-03-26: 5Mentions · 2026-03-27: 9Mentions · 2026-03-28: 1Mentions · 2026-03-29: 2Mentions · 2026-03-30: 2Mentions · 2026-04-01: 1Mentions · 2026-04-06: 1Mentions · 2026-04-15: 1Mentions · 2026-06-23: 1Mentions · 2026-07-07: 1Mentions · 2026-07-31: 1PoC Mentioned / Linked · 2026-03-23: 1Active Exploitation · 2026-03-25: 2Active Exploitation · 2026-03-27: 3Active Exploitation · 2026-03-29: 2Active Exploitation · 2026-07-07: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-24: 1Patch / Workaround · 2026-03-25: 5Patch / Workaround · 2026-03-26: 3Patch / Workaround · 2026-03-27: 4Patch / Workaround · 2026-03-29: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-03-23: 2Technical Details · 2026-03-24: 5Technical Details · 2026-03-25: 8Technical Details · 2026-03-26: 5Technical Details · 2026-03-27: 7Technical Details · 2026-03-28: 1Technical Details · 2026-03-29: 1Technical Details · 2026-03-30: 2Technical Details · 2026-04-06: 1Technical Details · 2026-06-23: 1Technical Details · 2026-07-31: 103-2303-2403-2503-2603-2703-2803-2903-3004-0104-0604-1506-2307-0707-31
Signal classification4 categories
Disclosure
2356.1%
Active Exploitation
819.5%
Patch
717.1%
General
37.3%
Referenced assets26 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-232
Disclosure2
2026-03-245
Disclosure4Patch1
2026-03-259
Active Exploitation2Disclosure4Patch3
2026-03-265
Disclosure4Patch1
2026-03-279
Active Exploitation3Disclosure5Patch1
2026-03-281
General1
2026-03-292
Active Exploitation2
2026-03-302
Disclosure2
2026-04-011
General1
2026-04-061
Disclosure1
2026-04-151
Patch1
2026-06-231
General1
2026-07-071
Active Exploitation1
2026-07-311
Disclosure1
Full discourse20 posts
  • Gray Hats@the_yellow_fall
    Patch

    PTC issues a critical advisory for Windchill and FlexPLM. CVE-2026-4681 is an RCE flaw allowing full server control via deserialization. Patch now! #PTC #Windchill #FlexPLM #CyberSecurity #InfoSec #RCE #PatchAlert #Vulnerability #PLM #Manufacturing https://securityonline.info/ptc-windchill-flexplm-critical-rce-vulnerability-cve-2026-4681/ https://t.co/hXfJkpGf8q

    Post summary

    PTC has issued a critical advisory for Windchill and FlexPLM, highlighting CVE‑2026‑4681 as an RCE flaw and urging users to apply the available patch immediately.

    03042339
    10.9K followersView on X
  • Misbar | مسبار@MisbarSec
    Disclosure

    📌 تحذير من PTC بشأن ثغرة حرجة في Windchill و FlexPLM تسمح بتنفيذ تعليمات برمجية عن بعد أصدرت شركة PTC تحذيراً عاجلاً بخصوص ثغرات أمنية حرجة في منتجاتها Windchill و FlexPLM. تسمح هذه الثغرات، المحددة مثل CVE-2026-4681، بتنفيذ تعليمات برمجية عن بعد (RCE) على الأنظمة المتأثرة. يُشير هذا الخلل إلى خطر جسيم يهدد سلامة الأنظمة وقد يؤدي إلى التحكم غير المصرح به. يُنصح بتطبيق التحديثات الأمنية الصادرة عن PTC فوراً للتخفيف من هذا التهديد. 🔗 للمزيد: https://thecyberexpress.com/flexplm-vulnerability-cve-2026-4681/

    Post summary

    PTC issues a critical warning about CVE‑2026‑4681, which permits remote code execution in Windchill and FlexPLM. The advisory stresses applying the released security patches but provides no PoC or exploit details.

    00040539
    83 followersView on X
  • DFIR Radar@DFIR_Radar
    General

    Detection engineering digest covers 48 new and 47 updated rules across 10 repos, with standout additions for CVE-2026-33825 LPE, BYOVD, RMM abuse, and cross-platform credential theft. Key updates: - Splunk added 9+ rules for CVE-2026-33825 (BlueHammer/RedSun LPE exploits), monitoring MsMpEng writing to System32, VSSVC accessing Defender engine binaries, cldapi.dll loaded by uncommon processes, and TieringEngineService.exe spawning suspicious children. Separately, CVE-2026-4681 PTC Windchill rules hunt for GW_READY_OK probe strings in MethodServer log4j events signaling pre-exploitation recon. - LOLDrivers updated MD5, SHA1, SHA256, and IMPHASH blocklists plus driver filename filters to catch current BYOVD campaigns bypassing HVCI for kernel-level access. LOLRMM added JumpCloud*.exe, Remotely_Agent.exe, and Remotely_Desktop.exe process detections for RMM-based persistence. - SigmaHQ added a rule for registry enumeration via WMIC StdRegProv (EnumKey, EnumValues, GetStringValue), a technique adversaries use to bypass reg.exe-focused monitors. Splunk updated SmartScreen and Defender disable rules to match both integer 0 and hex 0x00000000 registry values, closing an evasion gap tied to SalatStealer. - Cross-platform coverage expanded: Neo23x0 added YARA for Arch Linux ALPM hook supply chain attacks (npm/bun in post-install scripts redirecting stderr to /dev/null). #DFIR_Radar

    Post summary

    The digest details new detection rules covering CVE-2026-33825 (LPE), BYOVD, RMM abuse, and other techniques, but does not mention any PoC, exploit, patch, or active exploitation evidence.

    10002265
    1.7K followersView on X
  • Mr.Rabbit@01ra66it
    Active Exploitation

    この1週間を一言でまとめると、「公開直後の高危険CVEがすぐ実戦投入される一方で、認証情報・セッション・開発基盤を狙う“静かな侵害”が広がった週」でした。特に、Langflow の CVE-2026-33017、PTC Windchill/FlexPLM の CVE-2026-4681、F5 BIG-IP APM の CVE-2025-53521 など、AI基盤・設計基盤・境界機器にまたがる実悪用・高優先パッチ案件が並びました。 同時に、TeamPCP による OSS サプライチェーン汚染が週を通じて拡大しました。Trivy から始まった侵害は、Docker Hub、VS Code、PyPI、さらに Telnyx パッケージへと波及し、CI/CD・クラウド資格情報・Kubernetes シークレットまでを視野に入れた横断的な脅威になっています。 国家系・実害面では、ロシア系による Signal/WhatsApp 利用者へのフィッシング、欧州委員会のクラウド基盤侵害調査、Stryker 事案の医療現場への波及が象徴的でした。週後半には、macOS 向け ClickFix + Infiniti Stealer も表面化し、ゼロデイだけでなく 認証・操作誘導・周辺面の弱点 が攻撃面として定着していることがはっきりしました。

    Post summary

    Publicly disclosed high‑risk CVEs—CVE-2026-33017, CVE-2026-4681, CVE-2025-53521—were actively exploited across AI, design, and perimeter platforms, driving urgent patch responses while also highlighting widespread OSS supply‑chain contamination.

    000211.0K
    3.5K followersView on X
  • Mr.Rabbit@01ra66it
    General

    03/27は、PTC Windchill/FlexPLM の実悪用級RCE、欧州委のクラウド侵害、公的機関へのフィッシング侵害、開発者を狙うGitHub経由マルウェア拡散、イラン系による hack-and-leak が目立ちました。 特に CVE-2026-4681 は PTC Windchill/FlexPLM の未認証RCEとして警戒度が高く、ドイツでは警察が組織へ直接注意喚起したと報じられています。 欧州委員会は 3月24日に Europa Web Platform を支えるクラウド基盤への攻撃を受け、一部データ流出の可能性を調査中です。オランダ警察もフィッシング起点の侵害を公表しました。 CVE-2026-4681 は PTC Windchill/FlexPLM の未認証RCEで、原因は信頼できないデータのデシリアライズとされています。SecurityWeek は、CISA がこの脆弱性を強く警戒し、ドイツでは警察が組織を直接訪問して注意喚起したと伝えています。 欧州委員会の件は、Reuters が 3月24日にクラウド基盤が攻撃され、初期調査ではデータが取得された可能性があるが内部システムは非影響 と報じ、BleepingComputer は 少なくとも1つの AWS アカウントが影響した と伝えています。オランダ警察の件は、フィッシング成功後の侵害で、市民データへの影響は確認されていないものの、攻撃者アクセスの遮断と調査継続が公表されています。 開発者向けの偽 VS Code 警告では、GitHub Discussions から外部配布へ誘導し、Google Drive 経由のダウンロード と drnatashachinn[.]com を使った JavaScript ベースの選別が確認されています。さらに Reuters と The Record は、Handala が FBI 長官の個人メール侵害を主張し、300件超のメールや写真を公開したと報じています。

    Post summary

    The text reports a high‑risk, unauthenticated RCE in PTC Windchill/FlexPLM (CVE‑2026‑4681), highlights police and CISA alerts, but offers no PoC, exploit code, or confirmed active exploitation, and no patch or mitigation details are provided.

    01002642
    3.5K followersView on X
  • Cyber Daily News@CyberDaily_News
    Disclosure

    CVE-2026-4681 in PTC Windchill/FlexPLM scores a perfect CVSS 10.0 - RCE via deserialization, no patch available yet. German police are physically showing up at companies to warn admins. That's how serious this is. https://securityaffairs.com/190049/security/cisa-and-bsi-warn-orgs-of-critical-ptc-windchill-and-flexplm-flaw.html #cybersecurity #PLM #RCE #CISA

    Post summary

    A new critical flaw, CVE‑2026‑4681, in PTC Windchill/FlexPLM has been disclosed—RCE via deserialization, CVSS 10.0, with no patch available and law enforcement now warning administrators.

    01020111
    16 followersView on X
  • Mr.Rabbit@01ra66it
    Patch

    PTCは、Windchill と FlexPLM の重大RCEである CVE-2026-4681 について、差し迫った悪用リスクがあると警告した。重要なのは、まだ修正パッチが揃っていない一方で、ドイツ当局が企業へ直接警告に回るほど緊急度が高い点。 原因は trusted data の unsafe deserialization で、影響はWindchillとFlexPLMの広いサポート対象バージョンに及ぶ。PTCは、Apache/IISルールで該当サーブレットパスへのアクセス遮断を直ちに入れるよう勧告し、無理ならインターネット切断か停止を推奨している。 現時点でPTCは顧客への実悪用は確認していないが、GW.class、payload.bin、dpr_.jsp、run?p=、.jsp?c=、GW_READY_OK などのIoCと検知ポイントを公開している。PTCの顧客向け通知では「第三者グループによる差し迫った脅威の信頼できる証拠」があるとされる。 APT: 未特定 Malware: webshell系 CVE: CVE-2026-4681 IoC: GW.class, payload.bin, dpr_.jsp, run?p=, .jsp?c=, GW_READY_OK #CyberSecurity #ThreatIntel #RCE #Windchill #FlexPLM #CVE20264681 https://www.bleepingcomputer.com/news/security/ptc-warns-of-imminent-threat-from-critical-windchill-flexplm-rce-bug/

    Post summary

    PTC warns of an imminent RCE threat in Windchill/FlexPLM, highlights the lack of patches, and urges mitigation via web‑server rules or disconnection, while confirming no current evidence of active exploitation.

    01011326
    3.4K followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    Critical vulnerability in PTC's Windchill and FlexPLM may lead to RCE on affected systems. Info, incl. fix info, at #SecAlerts: CVE-2026-4681, CVSS 9.3 - https://secalerts.co/vulnerability/CVE-2026-4681 #ciso #cio #cto #vulnerabilities #cybersecurity #msp #mssp #CVE20264681 #PTC #windchill #flexplm https://t.co/QGRNgEVtDK

    Post summary

    The tweet announces a critical RCE vulnerability (CVE-2026-4681) in PTC's Windchill and FlexPLM, provides a CVSS 9.3 score, and links to a SecAlerts page containing fix information.

    00012160
    801 followersView on X
  • Andrew Northern 𓅓@ex_raritas
    Disclosure

    On June 17, 2026, product lifecycle management (PLM) and industrial/IoT software vendor PTC disclosed a critical remote code execution vulnerability in their PLM tool Windchill and add-on FlexPLM (CVE-2026-12569). #CVE202612569 On July 20, Ransom-ISAC reported that multiple organizations began receiving emails confirmed to be from the Cl0p ransom/extortion group, warning that their “confidential information” had been stolen. PTC’s customer base includes organizations across aerospace and defense, electronics, energy, industrial systems, and medical technology verticals, among others. This disclosure comes just three months after PTC disclosed an earlier critical RCE affecting the same products (CVE-2026-4681); there is no currently known exploitation of this earlier vulnerability. #CVE20264681 As far back as June 1, 2026, Censys observed fewer than 100 instances of PTC Windchill exposed to the Internet, with a decline in exposed instances shortly after PTC’s initial advisory publication on June 17, 2026. 80% of observed #Windchill instances are found in the U.S., and nearly a quarter of hosts running Windchill are on Akamai infrastructure, which aligns with the product’s enterprise customer profile. To date, vendor PTC has published 12 IOC IP addresses associated with this campaign. During the suspected attack time frame of early to mid June, Censys observed rapid service churn–in some cases, up and down in less than 24 hours–across these IP addresses, pointing to the short-lived nature of attack infrastructure. #Cl0p has new email contact information and infrastructure, powered by registrar CNOBIN, Cloudflare nameservers, and Roundcube Webmail on their own self-hosted mail server.

    Post summary

    PTC announced a critical RCE vulnerability (CVE‑2026‑12569) in its Windchill product, but no PoC, exploit, patch details, or active exploitation evidence is provided.

    00020329
    5.3K followersView on X
  • watchcatcyber@watchcatcyber
    Active Exploitation

    CVE-2026-4681 is being actively exploited in the wild. Today, we detected an actor exploiting this vulnerability against our PTC Windchill PLM honeypots. This vulnerability has no public POC code exists. https://trap.biu.life/intelligence/6a4b567cbf6da21c4bbb1e6a https://t.co/7eYK7uuGrh

    Post summary

    The text announces that CVE‑2026‑4681 is being actively exploited in the wild, with no PoC code, exploitation tools, patches, or technical details provided.

    00011119
    2 followersView on X
  • Lucas@lucasverdan
    Disclosure

    PTC warns of imminent Windchill and FlexPLM RCE… (CVE-2026-4681) deserves defender attention because this vulnerability… The flaw affects Windchill and FlexPLM, carries critical severity, and can be exploited for remote code execu…

    Post summary

    PTC highlights a critical RCE flaw (CVE-2026-4681) in Windchill and FlexPLM, emphasizing its severity but providing no PoC, exploit, active exploitation, patch, or detailed technical breakdown beyond the RCE classification.

    0101066
    307 followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    PTC warns of critical RCE bug CVE-2026-4681 in Windchill/FlexPLM with credible imminent threat. German 🇩🇪 federal police dispatching agents to alert companies nationwide shows severity of this PLM supply chain risk. #DFIR_Radar https://t.co/3n9H4ntEzM

    Post summary

    PTC has announced a critical RCE vulnerability, CVE‑2026‑4681, affecting Windchill/FlexPLM, prompting German federal police to alert companies of a serious supply‑chain risk.

    10010134
    1.0K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis reveals attackers exploiting CVE-2026-4681 in PTC Windchill PLM systems to achieve remote code execution through deserialization flaws. Post-compromise lateral movement across manufacturing networks demonstrates the critical need for runtime segmentation to limit blast radius. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/ptc-windchill-2026-remote-code-execution-vulnerability

    Post summary

    The text confirms attackers are actively exploiting CVE-2026-4681 in PTC Windchill PLM systems for remote code execution, enabling lateral movement and underscoring the need for runtime segmentation. No POCs, patches, or false‑positive claims are mentioned.

    00010108
    1.9K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    CISA warns of a critical deserialization vulnerability (CVE-2026-4681) in PTC Windchill and FlexPLM that allows remote code execution without authentication. German police have issued physical alerts. #PTCFlaw #Germany #RemoteCode https://ift.tt/HMI34r2

    Post summary

    CISA warns of a critical deserialization flaw (CVE-2026-4681) in PTC Windchill and FlexPLM that allows RCE without authentication; German police alerts indicate potential active exploitation in the wild.

    00010145
    3.9K followersView on X
  • Andre Gironda@AndreGironda
    Disclosure

    CVE-2026-4681 FlexPLM vulnerability enables critical RCE risk now -- https://thecyberexpress.com/flexplm-vulnerability-cve-2026-4681

    Post summary

    The post announces the discovery of CVE-2026-4681, identifying it as a critical remote code execution flaw in FlexPLM, but does not detail PoC, exploitation, or mitigation.

    00010119
    3.6K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    PTC warns of a critical deserialization bug (CVE-2026-4681) in Windchill and FlexPLM leading to remote code execution risks across most versions. German authorities issue emergency alerts. Patches and mitigations underway. #Windchill #RemoteCodeExec https://ift.tt/sEOhVgG

    Post summary

    PTC warns of a critical deserialization bug (CVE‑2026‑4681) in Windchill and FlexPLM that could allow remote code execution; German authorities have issued emergency alerts and patches are in progress.

    00010209
    3.8K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: A critical #RCE vulnerability, #CVE-2026-4681, affects #PTC Windchill and FlexPLM. It allows full compromise of C/I/A of core PLM, risking IP theft, supply chain exposure, and disruption. Updates and remediations are available https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-critical-vulnerability?srsltid=AfmBOop3e7Nthx5-BsrjKdpZi50wL6l6Bt21Fz0gUub2cIPgdPGV5bNl #Patch #Patch #Patch

    Post summary

    PTC Windchill and FlexPLM are affected by a critical RCE vulnerability (CVE-2026-4681). Updates and remediations are available through PTC’s vendor advisory.

    00010230
    7.2K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4681: CRITICAL] Critical RCE vulnerability found in PTC Windchill & FlexPLM. Exploitable through untrusted data deserialization. Versions impacted detailed. Patch advised ASAP.#cve,CVE-2026-4681,#cybersecurity https://cvefind.com/CVE-2026-4681

    Post summary

    The post announces a critical remote code execution flaw in PTC Windchill and FlexPLM that can be exploited through untrusted deserialization, and it urges users to apply the patch immediately.

    00001158
    606 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity Critical PTC Windchill Vulnerability: How to Patch and Defend Against CVE-2026-… "For organizations relying on PTC Windchill Product Lifecycle Management (PLM) software,…" 🔗 https://securityarsenal.com/blog/critical-ptc-windchill-vulnerability-how-to-patch-and-defend-against-cve-2026-4681 #CyberSecurity #ThreatIntel #soc #threatintel #managedsoc

    Post summary

    The post emphasizes patching and defensive measures for the PTC Windchill CVE-2026-4681 vulnerability, without providing exploit details or evidence of active attacks.

    0000024
    10 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-4681: PTC Windchill and FlexPLM Remote Code Execution Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q049G_fF0

    Post summary

    The snippet is a headline announcing CVE‑2026‑4681, a remote code execution flaw in PTC Windchill and FlexPLM; it does not contain PoC, exploit code, or evidence of active exploitation, nor does it mention a patch.

    0000050
    28 followersView on X

Explore more