Skip to main content
1-Visitor
March 20, 2026
Question

Windchill and FlexPLM Critical Vulnerability

  • March 20, 2026
  • 2 replies
  • 813 views
I am using Windchill PDMLink Release 11.1 and Datecode with CPS M020-CPS23

Windchill and FlexPLM Critical Vulnerability

2 replies

24-Ruby III
March 20, 2026

Article - "Potential Impact of Apache HTTP Server (2.4 to 2.4.54) security vulnerability (CVE-2022-36760) in Windchill PDMLink & FlexPLM": https://www.ptc.com/en/support/article/CS386653 

avillanueva
23-Emerald I
23-Emerald I
March 21, 2026

Wow, 2 in short order. There was an email sent out being discussed here. Unrelated I think...

https://community.ptc.com/t5/Windchill/Windchill-and-FlexPLM-Critical-Vulnerability/td-p/1059534

 

5-Regular Member
March 21, 2026

To confirm, this is a legitimate PTC communication.  Please direct your administration teams to review https://www.ptc.com/support/article/CS466318 and take action.  Contact Technical Support with any questions.

Thank you,
Mike Jasperson
Vice President - PTC Software Operations and Support

avillanueva
23-Emerald I
23-Emerald I
March 21, 2026

Thanks Mike. Strange that there is a statement saying there is no evidence of exploited PTC customer BUT we are asked to look for very specific files as IOC. Hmmm