CVE-2026-77645
published 2026-08-20CVE-2026-77645: A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the…
PriorityP260critical9.2CVSS 4.0
AVNACHATNPRNUINVCHVIHVAHSCLSILSALEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUYRUVCREMURed
EPSS
0.47%
38.8th percentile
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ptc | flexplm | — | — |
| ptc | flexplm | — | — |
| ptc | flexplm | — | — |
| ptc | flexplm | — | — |
| ptc | flexplm | — | — |
| ptc | flexplm | — | — |
| ptc | flexplm | — | — |
| ptc | flexplm | — | — |
| ptc | flexplm | — | — |
| ptc | flexplm | — | — |
| ptc | windchill_pdmlink | — | — |
| ptc | windchill_pdmlink | — | — |
| ptc | windchill_pdmlink | — | — |
| ptc | windchill_pdmlink | — | — |
| ptc | windchill_pdmlink | — | — |
| ptc | windchill_pdmlink | — | — |
| ptc | windchill_pdmlink | — | — |
| ptc | windchill_pdmlink | — | — |
| ptc | windchill_pdmlink | — | — |
| ptc | windchill_pdmlink | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
PTC Windchill/FlexPLM input validation (EUVD-2026-63755)
vuldb·2026-08-21·CVSS 9.2
CVE-2026-77645 [CRITICAL] PTC Windchill/FlexPLM input validation (EUVD-2026-63755)
A vulnerability, which was classified as critical, was found in PTC Windchill and FlexPLM. Impacted is an unknown function. The manipulation results in improper input validation.
This vulnerability was named CVE-2026-77645. The attack may be performed from remote. There is no available exploit.
GHSA
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM.
ghsa_unreviewed·2026-08-21
CVE-2026-77645 [CRITICAL] CWE-20 A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM.
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-20
Published