Skip to main content

Actively exploited

Listed in CISA’s Known Exploited Vulnerabilities catalog since June 25, 2026.

CVE-2026-12569

PTC Windchill and FlexPLM Improper Input Validation Vulnerability

PTC · Windchill and FlexPLM

Published July 21, 2026

What happened

PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.

What it means for your business

PTC Windchill and FlexPLM is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-12569). PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network. CISA remediation due date: 2026-06-28. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Required action

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA due date: June 28, 2026

Sources

Related briefs

Actively exploited (KEV)

CVE-2021-27137

DD-WRT Stack-Based Buffer Overflow Vulnerability

DD-WRT DD-WRT is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-27137). DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability. CISA remediation due date: 2026-07-24. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

DD-WRT · DD-WRT
Actively exploited (KEV)

CVE-2023-4346

KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability

KNX Association KNX Protocol Connection Authorization Option 1 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-4346). KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device. CISA remediation due date: 2026-07-29. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

KNX Association · KNX Protocol Connection Authorization Option 1
Actively exploited (KEV)

CVE-2025-67038

Lantronix EDS5000 Code Injection Vulnerability

Lantronix EDS5000 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-67038). Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges. CISA remediation due date: 2026-06-26. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Lantronix · EDS5000
Actively exploited (KEV)

CVE-2026-0770

Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Langflow Langflow is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-0770). Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. CISA remediation due date: 2026-07-24. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Langflow · Langflow

Need help patching?

PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.