PTC Windchill PDMLink and FlexPLM are facing active exploitation of CVE-2026-4681, a critical remote code execution flaw caused by deserialization of untrusted data. Splunk published detection guidance describing suspicious HTTP patterns tied to exploitation, including requests containing run?c=, run?p=, .jsp?c=, and .jsp?p=, as well as the indicator GW_READY_OK. The activity suggests attackers may deploy staged gateway or JSP components, use the c= parameter to run operating system commands such as whoami, and abuse the p= parameter to read files from affected servers.
Defenders are being urged to apply PTC’s mitigation and patching guidance and to hunt for related artifacts across compromised environments. Splunk recommends monitoring Windchill MethodServer log4j telemetry, particularly servlet-related loggers, and checking file systems for indicators such as GW.class, payload.bin, and randomly named dpr_<8 hex>.jsp files. A Siemens product advisory was also referenced in the reporting set, indicating broader vendor awareness around the issue and the need for rapid validation of exposure in enterprise environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-14, Splunk published an analytics story covering exploitation activity related to CVE-2026-4681 in PTC Windchill PDMLink and FlexPLM. The guidance described suspicious HTTP request patterns, indicators such as GW_READY_OK, attacker use of c= and p= parameters, and recommended correlating detections with PTC mitigation, patching, and IOC checks.
Siemens issued product advisory SSA-661247 related to the story context. The reference does not provide a publication date or additional event details in the supplied content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.