🔐 CVE Alert

CVE-2026-77646

UNKNOWN 0.0

Server Side Request Forgery (SSRF) vulnerability reported in Windchill

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.

CWE CWE-502 CWE-918
Vendor ptc
Product windchill pdmlink
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for ptc windchill pdmlink

Be the first to know when new unknown vulnerabilities affecting ptc windchill pdmlink are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

PTC / Windchill PDMLink
11.0 M030 11.1 M020 11.2.1.0 12.0.2.0 12.1.2.0 13.0.2.0 13.1.0.0 13.1.1.0 13.1.2.0 13.1.3.0
PTC / FlexPLM
11.0 M030 11.1 M020 11.2.1.0 12.0.0.0 12.0.2.0 12.0.3.0 12.1.2.0 12.1.3.0 13.0.2.0 13.0.3.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
ptc.com: https://www.ptc.com/en/support/article/CS474826

Credits

🔍 Richard Clifford of Rootshell Security (https://www.rootshellsecurity.net/)