
PTC Inc. is alerting users to a serious security gap in Windchill and FlexPLM, popular PLM software, which could allow hackers to run code remotely.
The vulnerability, tracked as CVE-2026-4681, could be exploited through insecure data handling.
The seriousness of the issue has led to urgent action by German authorities, with the federal police (BKA) reportedly visiting companies to warn them about the cybersecurity threat.
Official fixes are not yet available, but PTC says it is “actively developing and releasing security patches for all supported Windchill versions” to fix the problem.
The vendor indicates that the vulnerability affects most supported versions of Windchill and FlexPLM, including all CPS versions.
Until patches are released, system admins should use the recommended Apache/IIS rule provided by the vendor to block access to the vulnerable part of the system. PTC says this fix does not affect functionality.
The same fix should be applied to all systems, including Windchill, FlexPLM, and file/replica servers, not just those accessible from the internet. However, PTC advises prioritizing internet-facing systems.
If the fix cannot be applied, the vendor suggests temporarily disconnecting the affected systems from the internet or shutting down the service.
The company states that it has not found any evidence that the vulnerability is being exploited against PTC customers. However, PTC has released specific indicators of compromise (IoCs) that include a user agent string and files.
The advisory also lists detection advice, including checks for webshells (GW.class, payload.bin, or dpr_<random>.jsp files), suspicious requests with patterns such as run?p= / .jsp?c= combined with unusual User-Agent activity, errors referencing GW, GW_READY_OK, or unexpected gateway exceptions.
Furthermore, in an email to customers viewed by BleepingComputer, the company stated that “there is credible evidence of an imminent threat by a third-party group to exploit the vulnerability.”
According to Heise, BKA officers were dispatched over the weekend to alert companies nationwide about the risk of CVE-2026-4681, even those that did not use the affected products.
The German news outlet reports that the BKA contacted system administrators during the night to provide them with PTC’s warning and also notified the state criminal investigation offices (LKA) in various German states.
This unusual and rapid response by authorities suggests that CVE-2026-4681 may be actively exploited or is very likely to be exploited soon.
Given that PLM systems are utilized by engineering firms in designing weapons systems, industrial manufacturing, and managing critical supply chains, the authorities’ response may be justified to protect against industrial espionage and other national security concerns.
#bug #code #critical #execution #flexplm #immediate #news #poses #ptc #remote #threat #warns #windchill, — News
© Bulletproof Servers. All rights reserved.