{"id":703,"date":"2026-06-30T16:49:16","date_gmt":"2026-06-30T11:19:16","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=703"},"modified":"2026-08-18T16:49:54","modified_gmt":"2026-08-18T11:19:54","slug":"ptc-windchill-vulnerability-added-to-cisa-kev","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/ptc-windchill-vulnerability-added-to-cisa-kev\/","title":{"rendered":"PTC Windchill Vulnerability Added to CISA KEV After Web Shell Exploitation"},"content":{"rendered":"<p>The PTC Windchill vulnerability tracked as CVE-2026-12569 has moved from patch priority to active incident-response concern. CISA added the flaw to its Known Exploited Vulnerabilities catalog after evidence of active <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-exploitation-in-cyber-security\/\">exploitation<\/a>.<\/p>\n<p>PTC has also reported continued heightened threat activity and published indicators tied to JSP web shell deployment. Those indicators include suspicious Windchill login paths, attacker infrastructure, and log patterns that organizations should review during compromise assessment.<\/p>\n<p>For manufacturers, engineering teams, and enterprises running PLM environments, this issue requires more than software patching. Windchill and FlexPLM support product data, engineering workflows, supplier coordination, and manufacturing processes, which means a remotely exploitable flaw in that layer can quickly become a product lifecycle management security concern.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/xdr\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tStrengthen endpoint security with Hexnode XDR<\/a>\r\n    \t\t<\/center><\/p>\n<h2>Why this KEV listing deserves immediate attention<\/h2>\n<p>CVE-2026-12569 affects PTC Windchill PDMlink and PTC FlexPLM. NVD describes the flaw as a critical remote code execution vulnerability that attackers may exploit through deserialization of untrusted data. The CNA-provided CVSS v4.0 score is 9.3 Critical.<\/p>\n<p>The KEV listing changes the operational priority. CISA added the flaw to its <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-are-known-exploited-vulnerabilities-kev\/\">Known Exploited Vulnerabilities<\/a> catalog based on evidence of active exploitation, which means security teams should treat exposed vulnerable systems as potentially targeted until patch status, logs, and file-system indicators confirm otherwise.<\/p>\n<h3>The timeline adds to the urgency:<\/h3>\n<ul>\n<li>PTC had already begun releasing remediation guidance before the KEV listing, and SecurityWeek reported that patches and mitigations started rolling out ahead of CISA\u2019s action.<\/li>\n<li>The vendor later published its public advisory and shared indicators of compromise.<\/li>\n<li>CISA added <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-12569utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=ptc_windchill_vulnerability\" target=\"_blank\" rel=\"noopener\">CVE-2026-12569<\/a> to KEV after evidence of active exploitation.<\/li>\n<li>PTC\u2019s latest public update reported continued heightened threat activity and added new <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-are-indicators-of-compromise-iocs-in-edr\/\">indicators of compromise<\/a>.<\/li>\n<\/ul>\n<p>CISA added the flaw to KEV after active exploitation and noted PTC\u2019s confirmation of continued reports of heightened threat activity. SecurityWeek also reported that the vendor had already started releasing patches and mitigations before the KEV listing, and that IOCs were later published for persistent JSP web shells.<\/p>\n    \t\t<div class=\"hts-messages hts-messages--alert    \"   >\r\n    \t\t\t    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<\/p>\n<p><strong>Note:<\/strong> CISA KEV remediation deadlines apply specifically to U.S. Federal Civilian Executive Branch agencies under BOD 22-01. Private-sector and non-federal organizations are not legally bound by those deadlines, but CISA recommends prioritizing KEV vulnerabilities because they involve known exploitation.    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h2>What the exploitation activity shows<\/h2>\n<p>PTC\u2019s advisory points to active web shell activity, not a theoretical exploit scenario. The published IOCs include attacker IPs, a command-and-control IP, JSP web shell paths, and the X-windchill-req request header. PTC also advises hunting beyond listed filenames because web shells may use a 16-character lowercase hexadecimal pattern under <code>\/Windchill\/login\/<\/code>.<\/p>\n<h3>Key signals include:<\/h3>\n<ul>\n<li>POST requests to <code>\/Windchill\/login\/[0-9a-f]{16}.jsp<\/code><\/li>\n<li>Suspicious JSP files under Windchill login paths<\/li>\n<li>Possible flst.txt presence in \/tmp or the Windchill working directory<\/li>\n<li>Large POST responses from JSP files in the application tier<\/li>\n<\/ul>\n<p>The JSP web shell detail matters because PTC says these shells can enable remote command execution and possible <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-data-exfiltration\/\">data exfiltration<\/a>. Public reporting reviewed does not name a threat actor, ransomware group, <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-a-malware-family\/\">malware family<\/a>, or defined campaign. The confirmed issue is narrower but serious: vulnerable systems are being exploited, and persistent JSP web shells have been observed.<\/p>\n<section>\n<h2>Exposure signals security teams should prioritize<\/h2>\n<table style=\"width: 100%;\">\n<thead>\n<tr>\n<th style=\"width: 30.444%; text-align: left;\">Signal<\/th>\n<th style=\"width: 34.8837%; text-align: left;\">Why it matters<\/th>\n<th style=\"width: 33.6152%; text-align: left;\">Action priority<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 30.444%;\">Publicly exposed Windchill login endpoint<\/td>\n<td style=\"width: 34.8837%;\">Increases reachability for unauthorized remote exploitation<\/td>\n<td style=\"width: 33.6152%;\">Restrict exposure where operationally possible<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 30.444%;\">POST requests to <code>\/Windchill\/login\/*.jsp<\/code><\/td>\n<td style=\"width: 34.8837%;\">PTC states legitimate Windchill traffic does not POST to this path<\/td>\n<td style=\"width: 33.6152%;\">Review HTTP access logs immediately<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 30.444%;\">JSP files matching 16 lowercase hex characters<\/td>\n<td style=\"width: 34.8837%;\">Matches the published attacker naming pattern<\/td>\n<td style=\"width: 33.6152%;\">Scan application directories<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 30.444%;\"><code>X-windchill-req<\/code> request header<\/td>\n<td style=\"width: 34.8837%;\">PTC lists this as a malicious request header with no legitimate Windchill use<\/td>\n<td style=\"width: 33.6152%;\">Add WAF\/IDS detection or blocking<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 30.444%;\"><code>flst.txt<\/code> in <code>\/tmp<\/code> or Windchill working directory<\/td>\n<td style=\"width: 34.8837%;\">PTC says its presence confirms attacker file-listing activity<\/td>\n<td style=\"width: 33.6152%;\">Escalate to incident response<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/section>\n<h2>Why PLM Systems raise the business risk<\/h2>\n<p>An RCE in Windchill or FlexPLM does not affect a generic back-office application. PLM systems sit close to product design, engineering change control, BOM workflows, supplier coordination, and manufacturing release processes.<\/p>\n<p>That makes the business context important. A compromised PLM environment may expose intellectual property, engineering records, product documentation, internal workflows, and systems reachable from the application environment.<\/p>\n<p>Public reporting has not confirmed broad data theft or lateral movement from this activity, but security teams should still treat a JSP web shell as a serious foothold.<\/p>\n<h3>For manufacturing cybersecurity teams, the priority is to verify:<\/h3>\n<ul>\n<li>Whether Windchill or FlexPLM is internet-reachable<\/li>\n<li>Whether teams applied the required patches and mitigations.<\/li>\n<li>Whether historical logs show suspicious access before remediation<\/li>\n<\/ul>\n<h2>Response actions beyond applying the patch<\/h2>\n<p>Teams should patch first, but observed exploitation requires compromise assessment as well. Security teams should use PTC\u2019s indicators to check for compromise, not just confirm update status.<\/p>\n<h3>Priority actions include:<\/h3>\n<ul>\n<li>Block the reported C2 address at the perimeter.<\/li>\n<li>Review HTTP logs for POST requests to \/Windchill\/login\/*.jsp.<\/li>\n<li>Scan for suspicious JSP files under the Windchill login directory.<\/li>\n<li>Check for flst.txt in \/tmp or the Windchill working directory.<\/li>\n<li>Add WAF or IDS rules for the X-windchill-req header.<\/li>\n<li>Restrict internet exposure of the Windchill login endpoint where possible.<\/li>\n<\/ul>\n<p>Preserve relevant logs before rebuilding systems or rotating credentials. If teams confirm a JSP web shell, they should treat the system as compromised instead of simply deleting the file.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework.png?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity framework\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework.png?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-300x225.png?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-768x576.png?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-133x100.png?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity framework\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Building a cybersecurity framework for your enterprise\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Learn how cybersecurity frameworks and UEM strengthen security posture, reduce risk, and improve organizational resilience.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/building-a-cybersecurity-framework-for-your-enterprise\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>Where Hexnode fits in the response workflow<\/h2>\n<p>This incident fits both endpoint management and endpoint investigation, but Hexnode should not be positioned as a direct detector or blocker for the PTC Windchill vulnerability unless coverage is validated in the organization\u2019s environment.<\/p>\n<p>Hexnode\u2019s role is strongest in three areas:<\/p>\n<ul>\n<li>Endpoint readiness: <a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> can help teams apply policies and compliance rules to managed devices and configure Windows patches and updates for enrolled endpoints.<\/li>\n<li>Investigation support: Hexnode XDR can help security teams review device health, threat and alert logs, action history, and remote response actions on managed Windows endpoints.<\/li>\n<li>Operational boundaries: Hexnode should complement Windchill server log review, WAF telemetry, vulnerability management, and PLM-specific remediation. It should not replace those controls or be framed as direct CVE detection.<\/li>\n<\/ul>\n<h2>Conclusion<\/h2>\n<p>The PTC Windchill vulnerability shows how quickly a PLM flaw can become an incident-response priority when vulnerable systems are exposed to malicious network requests. For organizations running Windchill or FlexPLM, the priority is clear: patch, verify exposure, hunt for JSP web shell indicators, and treat confirmed findings as a compromise investigation.<\/p>\n<p>Engineering and manufacturing environments need layered visibility across application logs, managed endpoints, access controls, and administrative workflows. That visibility helps teams reduce uncertainty when a business-critical platform becomes part of an active exploitation campaign.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Secure PLM-connected endpoints with clarity<\/h5><p>Start your 14-day free trial and strengthen endpoint oversight.\r\n<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What is CVE-2026-12569?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>CVE-2026-12569 is a critical remote code execution vulnerability affecting PTC Windchill PDMlink and PTC FlexPLM. NVD describes the vulnerability as one that may be exploited through deserialization of untrusted data.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Why did CISA add this issue to KEV?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>CISA added the flaw to the Known Exploited Vulnerabilities catalog based on evidence of active exploitation. The KEV entry identifies it as an improper input validation vulnerability that could allow an unauthenticated remote attacker to execute arbitrary code through a malicious network request.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What should organizations check first?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Start with patch and remediation status, then verify whether the Windchill login endpoint is exposed. Review HTTP access logs for POST requests to<code>\/Windchill\/login\/*.jsp<\/code>, scan for suspicious JSP files, check for flst.txt, block the reported C2 IP, and restrict internet exposure where operationally possible.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The PTC Windchill vulnerability tracked as CVE-2026-12569 has moved from patch priority to active incident-response&#8230;<\/p>\n","protected":false},"author":5,"featured_media":707,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,21],"class_list":["post-703","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-patch-management","product_category-unified-endpoint-management","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>PTC Windchill Vulnerability Added to CISA KEV<\/title>\n<meta name=\"description\" content=\"Review the PTC Windchill vulnerability, CVE-2026-12569, active JSP web shell exploitation, CISA KEV action, and PLM security steps.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/ptc-windchill-vulnerability-added-to-cisa-kev\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"PTC Windchill Vulnerability Added to CISA KEV\" \/>\n<meta property=\"og:description\" content=\"Review the PTC Windchill vulnerability, CVE-2026-12569, active JSP web shell exploitation, CISA KEV action, and PLM security steps.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/ptc-windchill-vulnerability-added-to-cisa-kev\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-30T11:19:16+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-18T11:19:54+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/ptc-windchill-vulnerability.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ptc-windchill-vulnerability-added-to-cisa-kev\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ptc-windchill-vulnerability-added-to-cisa-kev\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"PTC Windchill Vulnerability Added to CISA KEV After Web Shell Exploitation\",\"datePublished\":\"2026-06-30T11:19:16+00:00\",\"dateModified\":\"2026-08-18T11:19:54+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ptc-windchill-vulnerability-added-to-cisa-kev\\\/\"},\"wordCount\":1299,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ptc-windchill-vulnerability-added-to-cisa-kev\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ptc-windchill-vulnerability.jpeg?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Patch Management\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ptc-windchill-vulnerability-added-to-cisa-kev\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ptc-windchill-vulnerability-added-to-cisa-kev\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ptc-windchill-vulnerability-added-to-cisa-kev\\\/\",\"name\":\"PTC Windchill Vulnerability Added to CISA KEV\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ptc-windchill-vulnerability-added-to-cisa-kev\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ptc-windchill-vulnerability-added-to-cisa-kev\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ptc-windchill-vulnerability.jpeg?format=webp\",\"datePublished\":\"2026-06-30T11:19:16+00:00\",\"dateModified\":\"2026-08-18T11:19:54+00:00\",\"description\":\"Review the PTC Windchill vulnerability, CVE-2026-12569, active JSP web shell exploitation, CISA KEV action, and PLM security steps.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ptc-windchill-vulnerability-added-to-cisa-kev\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ptc-windchill-vulnerability-added-to-cisa-kev\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ptc-windchill-vulnerability-added-to-cisa-kev\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ptc-windchill-vulnerability.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ptc-windchill-vulnerability.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"ptc windchill vulnerability\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ptc-windchill-vulnerability-added-to-cisa-kev\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"PTC Windchill Vulnerability Added to CISA KEV After Web Shell Exploitation\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"PTC Windchill Vulnerability Added to CISA KEV","description":"Review the PTC Windchill vulnerability, CVE-2026-12569, active JSP web shell exploitation, CISA KEV action, and PLM security steps.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/ptc-windchill-vulnerability-added-to-cisa-kev\/","og_locale":"en_US","og_type":"article","og_title":"PTC Windchill Vulnerability Added to CISA KEV","og_description":"Review the PTC Windchill vulnerability, CVE-2026-12569, active JSP web shell exploitation, CISA KEV action, and PLM security steps.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/ptc-windchill-vulnerability-added-to-cisa-kev\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-06-30T11:19:16+00:00","article_modified_time":"2026-08-18T11:19:54+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/ptc-windchill-vulnerability.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/ptc-windchill-vulnerability-added-to-cisa-kev\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ptc-windchill-vulnerability-added-to-cisa-kev\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"PTC Windchill Vulnerability Added to CISA KEV After Web Shell Exploitation","datePublished":"2026-06-30T11:19:16+00:00","dateModified":"2026-08-18T11:19:54+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ptc-windchill-vulnerability-added-to-cisa-kev\/"},"wordCount":1299,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ptc-windchill-vulnerability-added-to-cisa-kev\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/ptc-windchill-vulnerability.jpeg?format=webp","articleSection":["Identity Abuse","Patch Management"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/ptc-windchill-vulnerability-added-to-cisa-kev\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/ptc-windchill-vulnerability-added-to-cisa-kev\/","url":"https:\/\/www.hexnode.com\/threat-watch\/ptc-windchill-vulnerability-added-to-cisa-kev\/","name":"PTC Windchill Vulnerability Added to CISA KEV","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ptc-windchill-vulnerability-added-to-cisa-kev\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ptc-windchill-vulnerability-added-to-cisa-kev\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/ptc-windchill-vulnerability.jpeg?format=webp","datePublished":"2026-06-30T11:19:16+00:00","dateModified":"2026-08-18T11:19:54+00:00","description":"Review the PTC Windchill vulnerability, CVE-2026-12569, active JSP web shell exploitation, CISA KEV action, and PLM security steps.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ptc-windchill-vulnerability-added-to-cisa-kev\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/ptc-windchill-vulnerability-added-to-cisa-kev\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/ptc-windchill-vulnerability-added-to-cisa-kev\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/ptc-windchill-vulnerability.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/ptc-windchill-vulnerability.jpeg?format=webp","width":1340,"height":700,"caption":"ptc windchill vulnerability"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/ptc-windchill-vulnerability-added-to-cisa-kev\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"PTC Windchill Vulnerability Added to CISA KEV After Web Shell Exploitation"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/703","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=703"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/703\/revisions"}],"predecessor-version":[{"id":710,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/703\/revisions\/710"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/707"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=703"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=703"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}