CISA adds PTC Windchill and FlexPLM input-validation flaw to Known Exploited Vulnerabilities catalog after active exploitation
Manufacturers running PTC $PTC Windchill or FlexPLM should patch now. CISA added an improper input-validation flaw in the product lifecycle management software to its Known Exploited Vulnerabilities catalog on June 25 after confirming active exploitation. A federal patch deadline
CISA has added another actively exploited vulnerability to its Known Exploited Vulnerabilities catalog, the running list of flaws confirmed to be under attack in the wild. The June 25 entry names an improper input-validation weakness in PTC $PTC Windchill and FlexPLM, product lifecycle management software widely used across manufacturing and engineering to store and manage product data, designs and specifications. The catalog carries a binding remediation deadline for US federal agencies, but the exposure reaches well beyond government. Any company running the software faces the same risk, because attackers are already exploiting the flaw. Input-validation weaknesses are dangerous when the affected system handles untrusted data, since they can open a path to deeper access. Teams running Windchill or FlexPLM should confirm the vendor fix is applied and review access logs for anything unexpected.