Vulnerability Intelligence Report
Server Side Request Forgery (SSRF) vulnerability reported in Windchill
CVE-2026-77646
A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
Deserialization
No Active Exploit Signals
CVSS Base Score
7.7
HIGH
EPSS Probability:0.35%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| No affected products specified. | ||
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | PTC Inc. · Vendor · USA |
| Reserved | 2026-08-20T22:07:22 |
| Published | 2026-08-20T22:11:25 |
| Last Updated | 2026-08-21T20:08:38 |
Community Chatter & Buzz