3 techniques observed across 2 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)
Initial Access TA0001
T1190Exploit Public-Facing Application×2
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Adversaries may abuse legitimate extensible development features of servers to establish persistent access to systems. Enterprise server applications may include features that allow developers to write and install software or scripts to extend the functionality of the main application. Adversaries may install malicious components to extend and abuse server applications.
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
When first covered (06-20) and in the W25 weekly this was a pre-auth deserialization flaw with BSI escalating to admins out-of-hours. The in-window delta: CISA added it to KEV on 06-25 and JSP web-shell deployment against the login interface is now confirmed in the wild. Any internet-reachable Windchill PDMLink or FlexPLM instance should be treated as assume-compromise — manufacturing and defence-supplier PLM is exactly the externally-reachable engineering surface a Swiss/EU industrial estate forgets to inventory.
When first covered (06-20) and in the W25 weekly this was a pre-auth deserialization flaw with BSI escalating to admins out-of-hours.
CISA added the PTC Windchill PDMLink / FlexPLM pre-auth deserialization RCE (CVE-2026-12569) to its Known Exploited Vulnerabilities catalog on 2026-06-25, confirming active in-the-wild exploitation — the operational shift from the disclosure we deep-dived on June 20 (The Hacker News, 2026-06-26).
Reported post-exploitation deploys JSP web shells to /Windchill/login/<16-hex>.jsp plus a flst.txt persistence marker — concrete hunt artefacts beyond the earlier abstract RCE description. ENISA's EUVD entry corroborates the unauthenticated deserialization root cause (ENISA EUVD EUVD-2026-37831). The driver for Swiss/EU manufacturing, pharma and aerospace operators running Windchill is the confirmed exploitation and the web-shell pattern, not the US-only federal remediation date; patch per PTC CS473270 and hunt web-server logs for .jsp creation under /Windchill/login/.
UPDATE (originally covered 2026-06-20): CISA added the PTC Windchill PDMLink / FlexPLM pre-auth deserialization RCE (CVE-2026-12569) to its Known Exploited Vulnerabilities catalog on 2026-06-25, confirming active in-the-wild exploitation — the operational shift from the disclosure we deep-dived on …
If you did nothing this week: if you run an internet-reachable PTC Windchill or FlexPLM instance, assume compromise — a pre-auth deserialization flaw on the login interface is being exploited to drop backdoors, and the German BSI considered it urgent enough to phone operators in the middle of the night.
CVE-2026-12569 (CVSS 3.1 10.0; CVSS 4.0 9.3) is an unsafe deserialization of untrusted data reachable on the web-based Windchill/FlexPLM login interface before authentication — no credentials, no prior foothold, no user interaction (NCSC-CH Security Hub, 2026-06-19; daily 06-20 deep dive). PTC shipped fixes on 2026-06-15 and auto-patched cloud tenants; affected on-premises builds span the 11.x, 12.0.x, 12.1.x, 13.0.x and 13.1.0.0–13.1.3.0 lines as well as releases prior to 11.0 M030 (PTC PSIRT). Both BSI and NCSC-CH treat it as actively exploited, with Heise reporting backdoor deployment on vulnerable servers and the BSI escalating to direct after-hours phone calls — a step reserved for its highest-urgency advisories (Heise Security, 2026-06-19).
Windchill and FlexPLM are the product-lifecycle-management backbone across DACH manufacturing, aerospace, automotive and the defence-industrial base, holding engineering crown jewels (CAD, BOMs, supplier data) behind increasingly internet-reachable supplier portals — which is exactly why the BSI mobilised. Patch every on-premises instance, confirm cloud tenants were auto-patched, and until then pull the login interface off the internet behind a VPN or authenticating reverse proxy. Hunt for Java deserialization exception bursts on the login path and for the Windchill application-server process (JBoss/WildFly/WebLogic) spawning shells or scripting interpreters (T1190 → T1505.003).
Attacks on the deserialization vulnerability are apparently already underway to place backdoors on vulnerable servers.
At 2:30 AM, a BSI employee called the company, reported a new zero-day vulnerability, and urged immediate patches.