{"id":1465,"date":"2026-06-26T15:48:19","date_gmt":"2026-06-26T15:48:19","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1465"},"modified":"2026-06-26T15:48:19","modified_gmt":"2026-06-26T15:48:19","slug":"cisa-adds-exploited-ptc-windchill-rce-flaw-to-kev-as-web-shell-attacks-continue","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1465","title":{"rendered":"CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 26, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Software Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhzGOpsiL9b-uwhocEgzazTFR251KJL6pnZAVCmzty7Nx0uR-vZ9r2-WP95IrRaKJtFoUxmBFbqrkt31Yn2MTmD0bZAaPFTlmDfHxRURuWSsRzeTWHmyZF93QR94AOrSkbLnBYEQtVGJxI5VlRinwq8cLnEVCmGWk6wCnL1zpW_LbbZ-3-yTSdAmZ-0tqO6\/s1700-e365\/ptc.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/06\/25\/cisa-adds-two-known-exploited-vulnerabilities-catalog\">added<\/a> a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise Product Data Management (PDM) and Product Lifecycle Management (PLM) software to its Known Exploited Vulnerabilities (<a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\">KEV<\/a>) catalog, citing evidence of active exploitation.<\/p>\n<p>The vulnerability in question is <b><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-12569\">CVE-2026-12569<\/a><\/b> (CVSS score: 9.3), a case of improper input validation that could allow an attacker to execute arbitrary code by sending a malicious request to the network.\u00a0<\/p>\n<p>\u00abThe vulnerability is a remote code execution (RCE) issue that may be exploited through deserialization of untrusted data,\u00bb according to an advisory released by PTC.<\/p>\n<p>Although patches for the flaw were released last week, PTC has since confirmed, as of June 25, that \u00abwe&#8217;ve received continued reports of heightened threat activity,\u00bb with the company disclosing that unknown attackers are exploiting the vulnerability to deploy JSP web shells against susceptible systems.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>PTC has also <a href=\"https:\/\/www.ptc.com\/en\/about\/trust-center\/advisory-center\/active-advisories\/windchill-flexplm-rce-vulnerability\">released<\/a> the following indicators of compromise (IoCs) associated with the activity &#8211;<\/p>\n<ul>\n<li>172.111.38.31<\/li>\n<li>216.152.148.54<\/li>\n<li>104.243.35.131<\/li>\n<li>74.50.76.146<\/li>\n<li>5.180.41.35<\/li>\n<li>216.152.148.54<\/li>\n<li>5.180.41.35 (Attacker command-and-control address)<\/li>\n<li>Web shell files following the naming pattern \/Windchill\/login\/[0-9a-f]{16}.jsp<\/li>\n<\/ul>\n<p>As mitigations, users are advised to perform the following actions &#8211;<\/p>\n<ul>\n<li>Block <b>5.180.41.35<\/b> at the perimeter firewall immediately<\/li>\n<li>Search HTTP access logs for any POST requests to <b>\/Windchill\/login\/*.jsp<\/b><\/li>\n<li>Scan the filesystem for JSP files matching the 16-hex-char pattern <b>\/Windchill\/login\/[0-9a-f]{16}.jsp<\/b><\/li>\n<li>Hash-check any suspicious JSP files against <b>55a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c<\/b><\/li>\n<li>Check for <b>flst.txt<\/b> in \/tmp or the Windchill working directory, the presence of which confirms attacker file-listing activity<\/li>\n<li>Add WAF \/ IDS rule blocking any request containing the header <b>X-windchill-req:<\/b><\/li>\n<li>Restrict internet exposure of the Windchill login endpoint where operationally possible<\/li>\n<\/ul>\n<p>The development makes it the first-ever PTC product vulnerability added to CISA&#8217;s KEV catalog, not to mention highlighting how threat actors are rapidly weaponizing newly disclosed vulnerabilities to their advantage.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jun 26, 2026Vulnerability \/ Software Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1466,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[200,24,62,2214,128,70,203,2212,316,303,213,2213],"class_list":["post-1465","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-adds","tag-attacks","tag-cisa","tag-continue","tag-exploited","tag-flaw","tag-kev","tag-ptc","tag-rce","tag-shell","tag-web","tag-windchill"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1465","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1465"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1465\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1466"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1465"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1465"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1465"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}