On June 25, 2026, CISA—the Cybersecurity and Infrastructure Security Agency—added an exploit to its Known Exploited Vulnerabilities record, or KEV. Affecting PTC Windchill Product Data Management and Product Lifecycle Management software, the vulnerability involves improper input validation when users send requests to the network, leaving the system susceptible to remote code execution. To mitigate the vulnerability and potential exploitation, CISA recommends that users block 5.180.41.35 on the network firewall, audit for suspicious POST requests, and add WAF/IDS rule blocking against X-windchill-req headers.