Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

PTC Inc.

First CVE: Oct 18, 2007Active for: 19 yearsTotal CVEs: 35
56.2
VTI Score
TOP TARGET

PTC develops a focused but strategically important portfolio of industrial IoT and connectivity platforms, including ThingWorx, Kepware, and Axeda product lines, that enable real-time data exchange and device management across manufacturing and enterprise environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting the memory-safety and access-control demands of industrial middleware and device-agent software that often runs with elevated privileges in operational technology networks. The recurring exposure centers on products such as ThingWorx Industrial Connectivity, Kepware Server, and Axeda Agent and recurs through weakness classes including heap-based buffer overflows, path-traversal flaws, memory-boundary violations, and missing authentication on critical functions—patterns consistent with native code processing of untrusted network input in industrial protocols. Defenders tracking PTC deployments should prioritize severity assessments and treat industrial connectivity products as high-risk given their operational-technology integration and the criticality of the flaws observed. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
35
Total CVEs
More Total CVEs than 98% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
2.9%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by PTC Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 18, 2007
18 years ago
Most Recent CVE
Jun 18, 2026
36 days ago

Self-Reporting Analysis

Of all the CVEs published by PTC Inc. as a CNA, 50.0% affect products that PTC Inc. develops as a vendor.

50.0%
50.0%
Self-reported: 1 (50.0%)
Third-party: 1 (50.0%)

Of all the CVEs published that affect products developed by PTC Inc., 2.9% are self-published by PTC Inc. as a CNA.

97.1%
Self-published: 1 (2.9%)
Other CNAs: 34 (97.1%)

Products(21 total)

Top CVEs

Signals from CVEs in this vendor scope (35 CVEs).

35 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-12569CRITICAL
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of u
Jun 18, 20269.882YESNO
CVE-2023-0755CRITICAL
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.
Feb 23, 20239.835NONO
CVE-2020-27265CRITICAL
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Ent
Jan 14, 20219.833NONO
CVE-2022-25247CRITICAL
Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port without authentication. Successful
Mar 16, 20229.832NONO
CVE-2022-2848CRITICAL
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vul
Mar 29, 20239.131NONO
CVE-2022-2825CRITICAL
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vul
Mar 29, 20239.830NONO
CVE-2023-0754CRITICAL
The affected products are vulnerable to an integer overflow or wraparound, which could  allow an attacker to crash the server and remotely execute arbitrary code.
Feb 23, 20239.830NONO
CVE-2022-25246HIGH
Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful exploitation of this vulnerabil
Mar 16, 20228.829NONO
CVE-2020-27267CRITICAL
KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Rockwell Automation KEPServer Ent
Jan 14, 20219.129NONO
CVE-2023-5908CRITICAL
KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.
Nov 30, 20239.128NONO
View all 35 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products35 CVEs
26%
37%
34%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (11.4%)
Network27 (77.1%)
Unknown3 (8.6%)
Physical0 (0.0%)
Adjacent Network1 (2.9%)
Attack Complexity
Low30 (85.7%)
High2 (5.7%)
Unknown3 (8.6%)
User Interaction
None28 (80.0%)
Unknown3 (8.6%)
Required4 (11.4%)
Privileges Required
Low11 (31.4%)
High0 (0.0%)
None21 (60.0%)
Unknown3 (8.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (35 CVEs).

CISA KEV
1 CVE
2.9% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by PTC Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by PTC Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For PTC Inc.'s Products

View all 5 CNAs →

Top CWEs