CVE-2026-12569 has a CVSS score of 9.8
Assessment
Three scores circulate for this flaw and all three are correct on their own scale. 9.8 is NVD's CVSS 3.1 base score (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). 9.3 is PTC's CVSS 4.0 score, also carried in the NVD record and cited by ReliaQuest and The Hacker News. 10.0 is the CVSS 3.1 figure cited by heise and, for the March flaw CVE-2026-4681, by the BSI. Coverage that reports one figure without the scale, or presents them as disagreement, is incomplete rather than wrong. ThreatPaper checked the NVD record directly on 11 September 2026.
Where this claim appeared
Ransom-ISAC · 2026-07-22
https://ransom-isac.org/blog/clop-windchill-flexplm-exploitation/What “Verified” means
Established by primary sources — the original disclosure, a vendor incident report, a court filing, a government advisory, or the affected party itself. Where a claim is material, at least two independent sources agree.
5 of 5 · rating scale
Assessed in
Cl0p and PTC Windchill: The Custom Implant That Turned Engineering Vaults Into an Extortion CampaignThink this assessment is wrong? Report an error.