CVE-2026-4681 – Windchill and FlexPLM
CVSS 9.3
CRITICAL
“When product data systems are exposed, the entire supply chain is at risk.”
This patch addresses CVE-2026-4681 in PTC Windchill and FlexPLM, a critical vulnerability that could allow attackers to gain unauthorized access or manipulate product lifecycle management data. Exploitation could impact intellectual property, design integrity, and downstream manufacturing processes. The CVSS score is 9.3, which is Critical severity.
There is no verified evidence of active exploitation or publicly available proof-of-concept code at this time. However, due to the central role of these platforms in managing product data and workflows, the potential business impact is significant if left unpatched.
Key Details
- CWE Classification
- CWE-94
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.