German police contacted and in some cases visited corporate IT administrators at their homes during the early hours of Sunday morning to warn them about a critical, unpatched deserialization vulnerability in PTC Windchill and FlexPLM. The flaw, tracked as CVE-2026-4681 and WID-SEC-2026-0822, can enable remote code execution and carries a CVSS v4 score of 9.3 and a CVSS v3.1 score of 10. Authorities said they believed criminal actors were likely to exploit the issue imminently to compromise systems, steal data, and deploy ransomware.
The warning effort was coordinated by Germany’s Federal Criminal Police Office with state police, including Lower Saxony investigators, to quickly notify affected companies and reduce the risk of serious damage. PTC said it had no confirmed evidence of customer exploitation but released indicators of compromise and urgent mitigation guidance for Apache and IIS deployments, while advising organizations to disconnect internet-exposed systems if workarounds could not be applied quickly.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
PTC disclosed CVE-2026-4681 / WID-SEC-2026-0822, an unpatched deserialization vulnerability in Windchill and FlexPLM that can enable remote code execution. The company said it had no confirmed evidence of customer exploitation, published indicators of compromise, and urged immediate mitigations or disconnection of internet-exposed systems.
During the early hours of Sunday morning, German police contacted and in some cases visited corporate IT administrators at home to warn them about the critical PTC vulnerability. The outreach was coordinated by the Federal Criminal Police Office and state police after authorities assessed that criminal actors were likely to exploit the flaw imminently for data theft and ransomware deployment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceheise.de
Open sourceborncity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.