Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
PTC

PTC Vendor Cyber Rating & Cyber Score

ptc.co

PTC (NASDAQ: PTC) unleashes industrial innovation with award-winning, market-proven solutions that enable companies to differentiate their products and services, improve operational excellence, and increase workforce productivity. With PTC, and its partner ecosystem, manufacturers can capitalize on the promise of today’s new technology to drive digital transformation. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status Copyright 2025 PTC Inc. and its Licensors. All Rights Reserved


PTC A.I CyberSecurity Scoring

PTC
Company Information
Website:http://ptc.co/VLED30oHtEh
Employees number:8,126
Number of followers:399,514
NAICS:5112
Industry Type:Software Development
Homepage:ptc.co
PTC Risk Score (AI oriented)
Between 750 and 799
logo
PTCSoftware Development
Updated:
01/04/2026
778/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
PTC Global Score (TPRM)
xxxx
logo
PTCSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

PTC
PTCFair
Current Score
778Baa (FAIR)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
778Before Incident
JULY 2026
778Before Incident
JUNE 2026
778Before Incident
MAY 2026
778Before Incident
APRIL 2026
778Before Incident
MARCH 2026
780Before Incident
Vulnerability
25 Mar 2026PTC
PTC: PTC Warns of Critical Windchill, FlexPLM Flaw Enabling Remote Code Execution

Critical RCE Vulnerability in PTC Windchill and FlexPLM Exposes Systems to Attack

778After Incident
CRITICAL-2
PTC1774441546
Critical RCE Vulnerability in PTC Windchill and FlexPLM Exposes Systems to Attack PTC has issued an urgent advisory warning of a severe Remote Code Execution (RCE) vulnerability (CVE-2026-4681) affecting its Windchill PDMLink and FlexPLM platforms. The flaw, classified as a code injection vulnerability (CWE-94), carries a CVSS v3.1 score of 10.0 and a CVSS v4 score of 9.3, indicating maximum severity. ### Affected Versions The vulnerability impacts multiple releases, including: - Windchill PDMLink: Versions 11.0 M030 through 13.1.3.0 - FlexPLM: Versions 11.0 M030 through 13.0.3.0 - All CPS versions prior to 11.0 M030 are also vulnerable. PTC has confirmed no evidence of active exploitation but warns that the flaw poses a critical risk, particularly for publicly accessible instances. ### Exploitation Mechanism The vulnerability stems from improper handling of deserialized, untrusted data, allowing attackers to execute arbitrary code and potentially gain full system control. While internet-exposed deployments are at highest risk, PTC advises applying mitigations to all installations. ### Mitigation Steps Until official patches are released, PTC recommends the following workarounds: #### Apache HTTP Server - Create a configuration file (`90-app-Windchill-Auth.conf`) in `<APACHE_HOME>/conf/conf.d/` with the directive: ```apache <LocationMatch “^.servlet/(WindchillGW|WindchillAuthGW)/com.ptc.wvs.server.publish.Publish(?:;[^/])?/.*$”> Require all denied ``` - Ensure the file loads last and restart Apache. #### Microsoft IIS - Verify the URL Rewrite module is installed. - Modify `web.config` to include the rewrite rule as the first tag under `<system.webServer>`. - Restart IIS via `iisreset` and confirm the rule is active. PTC notes that File Server or Replica Server configurations may require adjusted steps, and older releases could need additional modifications. For organizations unable to implement mitigations immediately, PTC suggests shutting down services or disconnecting systems from the internet. ### Indicators of Compromise (IOCs) Security teams should monitor for: - Network patterns: - Suspicious User-Agent: `Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36` - Malicious HTTP requests: `run?p= .jsp?p=`, `run?c= .jsp?c=` - File system artifacts: - `GW.class` or `payload.bin` (SHA256: `C818011CAFF82272F8CC50B670304748984350485383EBAD5206D507A4B44FF1`) - `dpr_<8-hex-digits>.jsp` or other suspicious `.class` files (e.g., `Gen.class`, `HTTPRequest.class`). - Log anomalies: - Messages containing `GW_READY_OK`, `ClassNotFoundException for GW Windchill`, or `HTTP Gateway Exception`. PTC has deployed the Apache workaround for all cloud-hosted customers and is providing 24×7 support for affected users. Organizations detecting IOCs are urged to initiate incident response protocols.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Systems Affected: Potential full system controlOperational Impact: High risk for publicly accessible instances
FEBRUARY 2026
780Before Incident
JANUARY 2026
780Before Incident
DECEMBER 2025
780Before Incident
NOVEMBER 2025
780Before Incident
OCTOBER 2025
780Before Incident
SEPTEMBER 2025
780Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for PTC ?
?
What was PTC's A.I Rankiteo Cyber Score in July 2026 ?
?
What was PTC's A.I Rankiteo Cyber Score in June 2026 ?
?
What was PTC's A.I Rankiteo Cyber Score in May 2026 ?
?
What was PTC's A.I Rankiteo Cyber Score in April 2026 ?
?
What was PTC's A.I Rankiteo Cyber Score in March 2026 ?
?
What was PTC's A.I Rankiteo Cyber Score in February 2026 ?
?
What was PTC's A.I Rankiteo Cyber Score in January 2026 ?
?
What was PTC's A.I Rankiteo Cyber Score in December 2025 ?
?
What was PTC's A.I Rankiteo Cyber Score in November 2025 ?
?
What was PTC's A.I Rankiteo Cyber Score in October 2025 ?
?
What was PTC's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on PTC's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with PTC ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view PTC's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?