All CVEs
Vulnerability intelligence

CVE-2026-4681

PTC Windchill PDMLink CWE-94

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. This issue affects Windchill PDMLink: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0, 13.1.1.0, 13.1.2.0, 13.1.3.0; FlexPLM: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.0.0, 12.0.2.0, 12.0.3.0, 12.1.2.0, 12.1.3.0, 13.0.2.0, 13.0.3.0.

CVSS Score
9.3
Critical
EPSS — Exploit Probability
0.8%
Riskier than 54% of all CVEs · checked 2026-09-23
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

4 articles across 3 outlets · first covered Jun 26, 2026 · latest Jun 26, 2026

Coverage timeline

Related CVEs — PTC