PTC develops a focused but strategically important portfolio of industrial IoT and connectivity platforms, including ThingWorx, Kepware, and Axeda product lines, that enable real-time data exchange and device management across manufacturing and enterprise environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting the memory-safety and access-control demands of industrial middleware and device-agent software that often runs with elevated privileges in operational technology networks. The recurring exposure centers on products such as ThingWorx Industrial Connectivity, Kepware Server, and Axeda Agent and recurs through weakness classes including heap-based buffer overflows, path-traversal flaws, memory-boundary violations, and missing authentication on critical functions—patterns consistent with native code processing of untrusted network input in industrial protocols. Defenders tracking PTC deployments should prioritize severity assessments and treat industrial connectivity products as high-risk given their operational-technology integration and the criticality of the flaws observed. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by PTC Inc. over time
Of all the CVEs published by PTC Inc. as a CNA, 50.0% affect products that PTC Inc. develops as a vendor.
Of all the CVEs published that affect products developed by PTC Inc., 2.9% are self-published by PTC Inc. as a CNA.
Signals from CVEs in this vendor scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-12569CRITICAL A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of u | Jun 18, 2026 | 9.8 | 82 | YES | NO |
CVE-2023-0755CRITICAL
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.
| Feb 23, 2023 | 9.8 | 35 | NO | NO |
CVE-2020-27265CRITICAL KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Ent | Jan 14, 2021 | 9.8 | 33 | NO | NO |
CVE-2022-25247CRITICAL Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port without authentication. Successful | Mar 16, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-2848CRITICAL This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vul | Mar 29, 2023 | 9.1 | 31 | NO | NO |
CVE-2022-2825CRITICAL This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vul | Mar 29, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-0754CRITICAL
The affected products are vulnerable to an integer
overflow or wraparound, which could allow an attacker to crash the server and remotely
execute arbitrary code.
| Feb 23, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-25246HIGH Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful exploitation of this vulnerabil | Mar 16, 2022 | 8.8 | 29 | NO | NO |
CVE-2020-27267CRITICAL KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Rockwell Automation KEPServer Ent | Jan 14, 2021 | 9.1 | 29 | NO | NO |
CVE-2023-5908CRITICAL
KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.
| Nov 30, 2023 | 9.1 | 28 | NO | NO |
Signals from CVEs in this vendor scope (35 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by PTC Inc..
Media articles that mention a CVE ID that affects a product developed by PTC Inc. — matched by CVE ID, not by vendor name.