CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

PTC Windchill, one of three new August 2026 CVEs, all PR:N, no obtainable fixed version for two of them

cve · CVE-2026-77644 single-source

Coverage
1
first 2026-08-22 → last 2026-08-22
Latest activity
2026-08-22
The advisory records carry no version data at all; a national CERT's structured copy yields the one fixed…
Peak priority
high
1 high
Targets
manufacturing
sectors: manufacturing, defense, energy
Sources cited
4
2 hosts

Action items (2)

Do-now tasks recorded on the entries about CVE-2026-77644, newest first. Check the date before acting on an older one.

  • Upgrade Windchill Risk and Reliability Enterprise Edition to 13.1.0.1, the one fixed version published outside PTC's login wall. For the remote-code-execution and request-forgery flaws, open a support case with PTC to obtain the fixed builds for support articles CS474818 and CS474826 rather than waiting for a public advisory to carry them; there is no version range in the public records to triage against, so an inventory cannot answer whether an instance is affected.
    2026-08-22CVE-2026-77644 +2
  • Treat any internet-reachable Windchill or FlexPLM instance as requiring exposure reduction now rather than after the version question is settled: all three are unauthenticated and network-reachable in PTC's own vectors, and this product line already has a mass-extortion campaign running against it on a different flaw.
    2026-08-22CVE-2026-77644 +2

Defender insights

What each entry about CVE-2026-77644 tells a defender to do, newest first.

2026-08-22HIGHThe advisory records carry no version data at all; a national CERT's structured copy yields the one fixed release

Story timeline

  1. 2026-08-22Three new PTC Windchill and FlexPLM CVEs land on the product line already under mass extortion, all three unauthenticated and flagged red by the vendor, and only one has a fixed version anyone outside PTC's login wall can find
    trending-vulnerabilitiesThe advisory records carry no version data at all; a national CERT's structured copy yields the one fixed release
ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-22/ptc-windchill-three-new-cves-unauth-rce-no-fixed-version · ATT&CK page ↗

Entries about PTC Windchill, one of three new August 2026 CVEs, all PR:N, no obtainable fixed version for two of them (1)

2026-08-22 · view entry permalink →

Three new PTC Windchill and FlexPLM CVEs land on the product line already under mass extortion, all three unauthenticated and flagged red by the vendor, and only one has a fixed version anyone outside PTC's login wall can find

PTC assigned three CVEs against Windchill and FlexPLM on 2026-08-20, and BSI CERT-Bund relayed them the same day. All three are network-reachable and need no authentication in PTC's own published vectors. CVE-2026-77644, scored 9.3, is described as a critical access-control bypass in the Windchill Risk and Reliability Enterprise Edition module, classified as missing authentication for a critical function (GitHub Security Advisory, 2026-08-20). CVE-2026-77645, scored 9.2, is described as a critical remote code execution in Windchill and FlexPLM which the advisory says may be exploited through the deserialization of untrusted data, though its own weakness classification is improper input validation, with the deserialization mechanism appearing in the description text rather than as a second formal class (GitHub Security Advisory, 2026-08-20). CVE-2026-77646, scored 7.7, is a server-side request forgery in Windchill PDMLink and FlexPLM reachable by the same deserialization mechanism (BSI CERT-Bund, 2026-08-20; GitHub Security Advisory, 2026-08-20). All three carry a provider urgency of red in PTC's own published vectors.

The remediation gap is the operational story, and it is a publication problem rather than a research one. All three advisory records were filed with no structured product or version data; the affected-versions and patched-versions fields are empty, which is PTC's own choice of record type rather than an artefact of how they were read. PTC's own support articles carry the real build numbers and sit behind an authentication wall. The one exception came from an unexpected direction: BSI CERT-Bund's structured advisory copy binds CVE-2026-77644 to Windchill Risk and Reliability Enterprise Edition below 13.1.0.1 and names 13.1.0.1 as the remediating version (BSI CERT-Bund, 2026-08-20). For the other two, the German CERT's record references only version-less product identifiers, so there is no public answer to "is my instance affected?" for either the unauthenticated code execution or the request forgery. For an asset owner that is a worse position than a high score: a CVSS 9.2 with no version boundary cannot be triaged, only assumed.

The context a reader will supply themselves needs stating carefully. This site has covered a mass-extortion campaign against internet-exposed Windchill and FlexPLM deployments since late July, including the reverse-engineering of a purpose-built implant found on compromised instances, all of it anchored to a different flaw. A targeted check on 2026-08-22 found no source connecting any of these three new identifiers to that campaign, and the campaign's exploited vulnerability remains the earlier one. Three unauthenticated flaws arriving on a product line under active mass exploitation is a reason to move, but it is not evidence that these particular flaws are being used, and this entry does not imply otherwise.

Builds on: PTC Windchill CVE-2026-12569: unauthenticated Java deserialization to RCE on the PLM management…

vulnerability22 Aug 05:12Zsingle-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • github.com3 (75%)
  • wid.cert-bund.de1 (25%)