CISA added CVE-2026-12569 to its KEV catalog as attackers exploit the PTC Windchill flaw to deploy JSP web shells.

Hackers exploited a vulnerability in PTC Windchill in the wild, marking the first confirmed real-world abuse of the PLM platform.

CISA added CVE-2026-12569 to its KEV catalog as attackers exploit the PTC Windchill flaw to deploy JSP web shells.