ThreatPaper
Verified

CVE-2026-12569 has a CVSS score of 9.8

Assessment

Three scores circulate for this flaw and all three are correct on their own scale. 9.8 is NVD's CVSS 3.1 base score (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). 9.3 is PTC's CVSS 4.0 score, also carried in the NVD record and cited by ReliaQuest and The Hacker News. 10.0 is the CVSS 3.1 figure cited by heise and, for the March flaw CVE-2026-4681, by the BSI. Coverage that reports one figure without the scale, or presents them as disagreement, is incomplete rather than wrong. ThreatPaper checked the NVD record directly on 11 September 2026.

Where this claim appeared

Ransom-ISAC · 2026-07-22

https://ransom-isac.org/blog/clop-windchill-flexplm-exploitation/

What “Verified” means

Established by primary sources — the original disclosure, a vendor incident report, a court filing, a government advisory, or the affected party itself. Where a claim is material, at least two independent sources agree.

5 of 5 · rating scale

Assessed in

Cl0p and PTC Windchill: The Custom Implant That Turned Engineering Vaults Into an Extortion Campaign

Think this assessment is wrong? Report an error.