{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-4681",
        "tracking": {
            "current_release_date": "2026-03-29T14:53:02.561130Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-4681",
            "initial_release_date": "2026-03-20T19:36:46.035347Z",
            "revision_history": [
                {
                    "date": "2026-03-20T19:36:46.035347Z",
                    "number": "1",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-24T20:41:37.579115Z",
                    "number": "2",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-24T20:41:40.069115Z",
                    "number": "3",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-24T20:41:52.086137Z",
                    "number": "4",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (20).| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-24T20:42:21.907186Z",
                    "number": "5",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-24T20:44:00.923372Z",
                    "number": "6",
                    "summary": "Source created.| CVE status created. (valid)| Products connected (8).| Product Identifiers created (20).| Products created (12).| References created (4)."
                },
                {
                    "date": "2026-03-24T20:44:08.598802Z",
                    "number": "7",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-24T20:51:00.757898Z",
                    "number": "8",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-24T21:33:41.867288Z",
                    "number": "9",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-24T21:33:45.135524Z",
                    "number": "10",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-25T00:05:44.758191Z",
                    "number": "11",
                    "summary": "Source created.| CVE status created. (valid)| News created (1)."
                },
                {
                    "date": "2026-03-25T00:05:50.815859Z",
                    "number": "12",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-26T14:57:13.889162Z",
                    "number": "13",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-27T09:31:11.425121Z",
                    "number": "14",
                    "summary": "Source created.| CVE status created. (valid)| News created (1)."
                },
                {
                    "date": "2026-03-27T09:31:20.962031Z",
                    "number": "15",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-27T11:29:24.246617Z",
                    "number": "16",
                    "summary": "Source created.| CVE status created. (valid)| News created (1)."
                },
                {
                    "date": "2026-03-27T11:29:34.286882Z",
                    "number": "17",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-28T07:07:31.607555Z",
                    "number": "18",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-29T14:52:54.712470Z",
                    "number": "19",
                    "summary": "EPSS updated."
                }
            ],
            "status": "interim",
            "version": "19"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/11.0 m030",
                                "product": {
                                    "name": "vers:unknown/11.0 m030",
                                    "product_id": "CSAFPID-5901956",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:ptc:flexplm:11.0_m030"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/11.0m030",
                                "product": {
                                    "name": "vers:unknown/11.0m030",
                                    "product_id": "CSAFPID-5901527"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/11.1 m020",
                                "product": {
                                    "name": "vers:unknown/11.1 m020",
                                    "product_id": "CSAFPID-5901958",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:ptc:flexplm:11.1_m020"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/11.1m020",
                                "product": {
                                    "name": "vers:unknown/11.1m020",
                                    "product_id": "CSAFPID-5901528"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/11.2.1.0",
                                "product": {
                                    "name": "vers:unknown/11.2.1.0",
                                    "product_id": "CSAFPID-5901529",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:ptc:flexplm:11.2.1.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.0.0",
                                "product": {
                                    "name": "vers:unknown/12.0.0.0",
                                    "product_id": "CSAFPID-5901530",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:ptc:flexplm:12.0.0.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.2.0",
                                "product": {
                                    "name": "vers:unknown/12.0.2.0",
                                    "product_id": "CSAFPID-5901531",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:ptc:flexplm:12.0.2.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.3.0",
                                "product": {
                                    "name": "vers:unknown/12.0.3.0",
                                    "product_id": "CSAFPID-5901532",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:ptc:flexplm:12.0.3.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.1.2.0",
                                "product": {
                                    "name": "vers:unknown/12.1.2.0",
                                    "product_id": "CSAFPID-5901533",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:ptc:flexplm:12.1.2.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.1.3.0",
                                "product": {
                                    "name": "vers:unknown/12.1.3.0",
                                    "product_id": "CSAFPID-5901534",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:ptc:flexplm:12.1.3.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/13.0.2.0",
                                "product": {
                                    "name": "vers:unknown/13.0.2.0",
                                    "product_id": "CSAFPID-5901535",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:ptc:flexplm:13.0.2.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/13.0.3.0",
                                "product": {
                                    "name": "vers:unknown/13.0.3.0",
                                    "product_id": "CSAFPID-5901536",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:ptc:flexplm:13.0.3.0"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "FlexPLM"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/11.0 m030",
                                "product": {
                                    "name": "vers:unknown/11.0 m030",
                                    "product_id": "CSAFPID-5901948",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:ptc:windchill:11.0_m030"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/11.1 m020",
                                "product": {
                                    "name": "vers:unknown/11.1 m020",
                                    "product_id": "CSAFPID-5901957",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:ptc:windchill:11.1_m020"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/11.2.1.0",
                                "product": {
                                    "name": "vers:unknown/11.2.1.0",
                                    "product_id": "CSAFPID-5901959",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:ptc:windchill:11.2.1.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.2.0",
                                "product": {
                                    "name": "vers:unknown/12.0.2.0",
                                    "product_id": "CSAFPID-5901954",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:ptc:windchill:12.0.2.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.1.2.0",
                                "product": {
                                    "name": "vers:unknown/12.1.2.0",
                                    "product_id": "CSAFPID-5901950",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:ptc:windchill:12.1.2.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/13.0.2.0",
                                "product": {
                                    "name": "vers:unknown/13.0.2.0",
                                    "product_id": "CSAFPID-5901955",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:ptc:windchill:13.0.2.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/13.1.0.0",
                                "product": {
                                    "name": "vers:unknown/13.1.0.0",
                                    "product_id": "CSAFPID-5901952",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:ptc:windchill:13.1.0.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/13.1.1.0",
                                "product": {
                                    "name": "vers:unknown/13.1.1.0",
                                    "product_id": "CSAFPID-5901953",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:ptc:windchill:13.1.1.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/13.1.2.0",
                                "product": {
                                    "name": "vers:unknown/13.1.2.0",
                                    "product_id": "CSAFPID-5901951",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:ptc:windchill:13.1.2.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/13.1.3.0",
                                "product": {
                                    "name": "vers:unknown/13.1.3.0",
                                    "product_id": "CSAFPID-5901949",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:ptc:windchill:13.1.3.0"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Windchill"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/11.0m030",
                                "product": {
                                    "name": "vers:semver/11.0m030",
                                    "product_id": "CSAFPID-5901517"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/11.1m020",
                                "product": {
                                    "name": "vers:semver/11.1m020",
                                    "product_id": "CSAFPID-5901518"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/11.2.1.0",
                                "product": {
                                    "name": "vers:semver/11.2.1.0",
                                    "product_id": "CSAFPID-5901519"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/12.0.2.0",
                                "product": {
                                    "name": "vers:semver/12.0.2.0",
                                    "product_id": "CSAFPID-5901520"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/12.1.2.0",
                                "product": {
                                    "name": "vers:semver/12.1.2.0",
                                    "product_id": "CSAFPID-5901521"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/13.0.2.0",
                                "product": {
                                    "name": "vers:semver/13.0.2.0",
                                    "product_id": "CSAFPID-5901522"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/13.1.0.0",
                                "product": {
                                    "name": "vers:unknown/13.1.0.0",
                                    "product_id": "CSAFPID-5901523"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/13.1.1.0",
                                "product": {
                                    "name": "vers:unknown/13.1.1.0",
                                    "product_id": "CSAFPID-5901524"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/13.1.2.0",
                                "product": {
                                    "name": "vers:unknown/13.1.2.0",
                                    "product_id": "CSAFPID-5901525"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/13.1.3.0",
                                "product": {
                                    "name": "vers:unknown/13.1.3.0",
                                    "product_id": "CSAFPID-5901526"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Windchill PDMLink"
                    }
                ],
                "category": "vendor",
                "name": "PTC"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-4681",
            "cwe": {
                "id": "CWE-94",
                "name": "Improper Control of Generation of Code ('Code Injection')"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.\n\nThis issue affects Windchill PDMLink: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0, 13.1.1.0, 13.1.2.0, 13.1.3.0; FlexPLM: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.0.0, 12.0.2.0, 12.0.3.0, 12.1.2.0, 12.1.3.0, 13.0.2.0, 13.0.3.0.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-4681"
                },
                {
                    "category": "description",
                    "text": "A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.\n\nThis issue affects Windchill PDMLink: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0, 13.1.1.0, 13.1.2.0, 13.1.3.0; FlexPLM: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.0.0, 12.0.2.0, 12.0.3.0, 12.1.2.0, 12.1.3.0, 13.0.2.0, 13.0.3.0.",
                    "title": "cveprojectv5 - https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/4xxx/CVE-2026-4681.json"
                },
                {
                    "category": "other",
                    "text": "0.00497",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Red",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "9.3",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "5.9",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "There is product data available from source Certbundde, There is product data available from a private source, There is news data available from source Bleepingcomputer, There is cvss data available from a private source",
                    "title": "NCSC Score top increasing factors"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5901517",
                    "CSAFPID-5901518",
                    "CSAFPID-5901519",
                    "CSAFPID-5901520",
                    "CSAFPID-5901521",
                    "CSAFPID-5901522",
                    "CSAFPID-5901523",
                    "CSAFPID-5901524",
                    "CSAFPID-5901525",
                    "CSAFPID-5901526",
                    "CSAFPID-5901527",
                    "CSAFPID-5901528",
                    "CSAFPID-5901529",
                    "CSAFPID-5901530",
                    "CSAFPID-5901531",
                    "CSAFPID-5901532",
                    "CSAFPID-5901533",
                    "CSAFPID-5901534",
                    "CSAFPID-5901535",
                    "CSAFPID-5901536",
                    "CSAFPID-5901948",
                    "CSAFPID-5901949",
                    "CSAFPID-5901950",
                    "CSAFPID-5901951",
                    "CSAFPID-5901952",
                    "CSAFPID-5901953",
                    "CSAFPID-5901954",
                    "CSAFPID-5901955",
                    "CSAFPID-5901956",
                    "CSAFPID-5901957",
                    "CSAFPID-5901958",
                    "CSAFPID-5901959"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-4681"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/4xxx/CVE-2026-4681.json"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0822.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - bleepingcomputer",
                    "url": "https://www.bleepingcomputer.com/news/security/ptc-warns-of-imminent-threat-from-critical-windchill-flexplm-rce-bug/"
                },
                {
                    "category": "external",
                    "summary": "Source - securityweek",
                    "url": "https://www.securityweek.com/cisa-flags-critical-ptc-vulnerability-that-had-german-police-mobilized/"
                },
                {
                    "category": "external",
                    "summary": "Source - securitynl",
                    "url": "https://www.security.nl/posting/930105/Duitse+politie+bezoekt+bedrijven+wegens+kritieke+PTC-kwetsbaarheid?channel=rss"
                },
                {
                    "category": "external",
                    "summary": "News - bleepingcomputer",
                    "url": "https://www.bleepingcomputer.com/news/security/ptc-warns-of-imminent-threat-from-critical-windchill-flexplm-rce-bug/"
                },
                {
                    "category": "external",
                    "summary": "News - securityweek",
                    "url": "https://www.securityweek.com/cisa-flags-critical-ptc-vulnerability-that-had-german-police-mobilized/"
                },
                {
                    "category": "external",
                    "summary": "News - securitynl",
                    "url": "https://www.security.nl/posting/930105/Duitse+politie+bezoekt+bedrijven+wegens+kritieke+PTC-kwetsbaarheid?channel=rss"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd",
                    "url": "https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-critical-vulnerability?srsltid=AfmBOop3e7Nthx5-BsrjKdpZi50wL6l6Bt21Fz0gUub2cIPgdPGV5bNl"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0822.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0822"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.ptc.com/en/support/article/CS466318"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-critical-vulnerability"
                }
            ],
            "title": "CVE-2026-4681"
        }
    ]
}