2026-08-22HIGHThe advisory records carry no version data at all; a national CERT's structured copy yields the one fixed release
PTC Windchill, one of three new August 2026 CVEs, all PR:N, no obtainable fixed version for two of them
cve · CVE-2026-77644 single-source
Coverage
1
first 2026-08-22 → last 2026-08-22
Latest activity
2026-08-22
The advisory records carry no version data at all; a national CERT's structured copy yields the one fixed…
Peak priority
high
1 high
Targets
manufacturing
sectors: manufacturing, defense, energy
Sources cited
4
2 hosts
Action items (2)
Do-now tasks recorded on the entries about CVE-2026-77644, newest first. Check the date before acting on an older one.
- Upgrade Windchill Risk and Reliability Enterprise Edition to 13.1.0.1, the one fixed version published outside PTC's login wall. For the remote-code-execution and request-forgery flaws, open a support case with PTC to obtain the fixed builds for support articles CS474818 and CS474826 rather than waiting for a public advisory to carry them; there is no version range in the public records to triage against, so an inventory cannot answer whether an instance is affected.2026-08-22CVE-2026-77644 +2
- Treat any internet-reachable Windchill or FlexPLM instance as requiring exposure reduction now rather than after the version question is settled: all three are unauthenticated and network-reachable in PTC's own vectors, and this product line already has a mass-extortion campaign running against it on a different flaw.2026-08-22CVE-2026-77644 +2
Defender insights
What each entry about CVE-2026-77644 tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-22/ptc-windchill-three-new-cves-unauth-rce-no-fixed-version · ATT&CK page ↗
Entries about PTC Windchill, one of three new August 2026 CVEs, all PR:N, no obtainable fixed version for two of them (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- PTC FlexPLM×1
- PTC Windchill×1
- PTC Windchill PDMLink×1
- PTC Windchill PDMLink, one of three new August 2026 CVEs, all PR:N×1
- PTC Windchill Risk and Reliability×1
- PTC Windchill, one of three new August 2026 CVEs, all PR:N×1
Where this entity is cited
Source distribution
- github.com3 (75%)
- wid.cert-bund.de1 (25%)
External references
All cited sources (4)
- github.comGitHub Security Advisory (PTC as numbering authority)https://github.com/advisories/GHSA-2698-qwmx-3r6f
- github.comGitHub Security Advisory (PTC as numbering authority)https://github.com/advisories/GHSA-5hvp-9mcx-5245
- github.comGitHub Security Advisory (PTC as numbering authority)https://github.com/advisories/GHSA-qxmv-9q88-wwmw
- wid.cert-bund.deBSI CERT-Bund (WID-SEC-2026-2963)https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2963