<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — PTC</title><description>Coverage of PTC&apos;s Product Lifecycle Management and Product Data Management platforms — Windchill PDMLink and FlexPLM — the enterprise engineering software that owns CAD, BOMs, and manufacturing releases at large industrial and defense firms. Not ICS itself, but the pipeline into it. Combined article + CVE feed for the PTC beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2026-12569 — PTC Windchill PDMLink &amp; FlexPLM unauthenticated RCE via untrusted deserialization</title><link>https://0daynews.com/cve/cve-2026-12569/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-12569/</guid><description>Unauthenticated remote code execution in PTC Windchill PDMLink and FlexPLM via untrusted-data deserialization. Added to CISA KEV 2026-06-25 with a three-day patch mandate. JSP webshells observed being dropped on unpatched instances.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>PTC</category><category>critical</category><category>cve</category></item><item><title>Clop&apos;s Windchill Implant Decrypts Passwords, Steals Files</title><link>https://0daynews.com/articles/2026-08-18-clop-windchill-webshell-credential-theft/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-18-clop-windchill-webshell-credential-theft/</guid><description>ReliaQuest finds a Clop-linked JSP implant engineered for PTC Windchill that decrypts LDAP credentials and maps file vaults to steal engineering data.</description><pubDate>Tue, 18 Aug 2026 18:00:00 GMT</pubDate><category>PTC</category><category>article</category></item><item><title>Clop Hits Windchill and FlexPLM in Data-Theft Push</title><link>https://0daynews.com/articles/2026-07-25-clop-targets-ptc-windchill-flexplm-data-theft/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-25-clop-targets-ptc-windchill-flexplm-data-theft/</guid><description>Clop is running an active data-theft campaign against internet-exposed PTC Windchill and FlexPLM. No encryption — straight to exfiltration and extortion.</description><pubDate>Sat, 25 Jul 2026 09:00:00 GMT</pubDate><category>PTC</category><category>article</category></item><item><title>PTC Windchill PLM RCE is on KEV — shells still landing</title><link>https://0daynews.com/articles/2026-07-11-ptc-windchill-flexplm-cve-2026-12569-kev-jsp-webshell/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-11-ptc-windchill-flexplm-cve-2026-12569-kev-jsp-webshell/</guid><description>PTC Windchill PDMLink and FlexPLM ship an unauth deserialization RCE. CISA added it to KEV on 2026-06-25. Unpatched instances are still catching JSP webshells.</description><pubDate>Sat, 11 Jul 2026 17:15:00 GMT</pubDate><category>PTC</category><category>article</category></item></channel></rss>