ctipilot.ch

PTC Windchill — one of three new August 2026 CVEs, all PR:N, no obtainable fixed version for two of them

cve · CVE-2026-77644 single-source

Coverage timeline
1
first 2026-08-22 → last 2026-08-22
Peak priority
high
1 high
Sources cited
4
2 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
2
see Related entities below
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques
Affected products
PTC FlexPLMPTC WindchillPTC Windchill PDMLinkPTC Windchill Risk and Reliability

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-22/ptc-windchill-three-new-cves-unauth-rce-no-fixed-version · ATT&CK page ↗

Story timeline

  1. 2026-08-22Three new PTC Windchill and FlexPLM CVEs land on the product line already under mass extortion — all three unauthenticated and flagged red by the vendor, and only one has a fixed version anyone outside PTC's login wall can find
    trending-vulnerabilitiesThe advisory records carry no version data at all; a national CERT's structured copy yields the one fixed release

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • github.com3 (75%)
  • wid.cert-bund.de1 (25%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about PTC Windchill — one of three new August 2026 CVEs, all PR:N, no obtainable fixed version for two of them (1)

2026-08-22 · view entry permalink →

Three new PTC Windchill and FlexPLM CVEs land on the product line already under mass extortion — all three unauthenticated and flagged red by the vendor, and only one has a fixed version anyone outside PTC's login wall can find

PTC assigned three CVEs against Windchill and FlexPLM on 2026-08-20, and BSI CERT-Bund relayed them the same day. All three are network-reachable and need no authentication in PTC's own published vectors. CVE-2026-77644, scored 9.3, is described as a critical access-control bypass in the Windchill Risk and Reliability Enterprise Edition module, classified as missing authentication for a critical function. CVE-2026-77645, scored 9.2, is described as a critical remote code execution in Windchill and FlexPLM which the advisory says may be exploited through the deserialization of untrusted data — though its own weakness classification is improper input validation, with the deserialization mechanism appearing in the description text rather than as a second formal class. CVE-2026-77646, scored 7.7, is a server-side request forgery in Windchill PDMLink and FlexPLM reachable by the same deserialization mechanism (BSI CERT-Bund, 2026-08-20; GitHub Security Advisory, 2026-08-20). All three carry a provider urgency of red in PTC's own published vectors.

The remediation gap is the operational story, and it is a publication problem rather than a research one. All three advisory records were filed with no structured product or version data — the affected-versions and patched-versions fields are empty, which is PTC's own choice of record type rather than an artefact of how they were read. PTC's own support articles carry the real build numbers and sit behind an authentication wall. The one exception came from an unexpected direction: BSI CERT-Bund's structured advisory copy binds CVE-2026-77644 to Windchill Risk and Reliability Enterprise Edition below 13.1.0.1 and names 13.1.0.1 as the remediating version (BSI CERT-Bund, 2026-08-20). For the other two, the German CERT's record references only version-less product identifiers, so there is no public answer to "is my instance affected?" for either the unauthenticated code execution or the request forgery. For an asset owner that is a worse position than a high score: a CVSS 9.2 with no version boundary cannot be triaged, only assumed.

The context a reader will supply themselves needs stating carefully. This pipeline has covered a mass-extortion campaign against internet-exposed Windchill and FlexPLM deployments since late July, including the reverse-engineering of a purpose-built implant found on compromised instances, all of it anchored to a different flaw. A targeted check this run found no source connecting any of these three new identifiers to that campaign, and the campaign's exploited vulnerability remains the earlier one. Three unauthenticated flaws arriving on a product line under active mass exploitation is a reason to move, but it is not evidence that these particular flaws are being used, and this entry does not imply otherwise.

Builds on: 2026-08-19/clop-windchill-custom-implant-reverse-engineered · 2026-08-15/clop-windchill-philips-shell-first-victim-confirmations

vulnerability22 Aug 05:12Zsingle-sourceOpen finding ↗