🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.

PTC Windchill FlexPLM Unauthenticated RCE (CVE-2026-12569) | MSSP Advisory

Critical🔴 KEV ALERTConfirmed
DateJune 25, 2026
CVECVE-2026-12569
Risk Assessment
Client Exposure:High
Briefing Priority:Immediate
Barrier to Entry:Low
📋Executive Summary
CISA has added CVE-2026-12569 to the Known Exploited Vulnerabilities catalog, flagging an unauthenticated remote code execution flaw in PTC Windchill and FlexPLM, two product lifecycle management platforms common in manufacturing, aerospace, and defense supply chains. The patch deadline is June 28, 2026, but CISA does not add vulnerabilities to the KEV catalog speculatively — active exploitation is already happening. If your clients operate in industrial, engineering, or manufacturing sectors, this is a live fire situation.
⚠️Why It Matters for MSSPs
Your direct stack exposure here is lower than a typical enterprise software flaw, but your advisory obligation is immediate and high. Any MSSP serving manufacturers, defense contractors, or engineering firms has clients who may be running Windchill or FlexPLM on internet-accessible infrastructure, and an unauthenticated RCE means an attacker needs no credentials to own the system. If a client gets hit through this vulnerability and you had not surfaced the advisory, that is a retention conversation you do not want to have.
Recommended Action
In the next 24 hours, pull your client asset inventory and identify any Windchill or FlexPLM deployments, then flag every instance that has any internet-facing exposure for emergency patching ahead of the June 28 deadline. Send a direct written advisory to all manufacturing, engineering, and defense sector clients today regardless of whether you have confirmed exposure, because the documentation of that outreach protects you contractually and demonstrates the advisory value they are paying for.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Vulnerability Disclosure

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.