Listen to the full episode.
The problem is not the patch. It is the evidence left behind.
PTC disclosed a critical remote-code-execution vulnerability affecting Windchill and FlexPLM. The episode starts where conventional remediation often stops: closing the entry point does not demonstrate that engineering files, source code, release approvals or supplier copies remained unchanged while arbitrary code execution was possible.
The discussion follows the digital thread beyond the PLM boundary and asks how much independent evidence is required before a high-consequence release can again be trusted.
The decision at the centre of the episode
A blanket stop-and-revalidate response may be technically conservative but operationally destructive. Focus assurance on the releases with the highest consequence, preserve evidence and escalate only what cannot be defended.
Read the technical analysis
The companion analysis sets out the evidence, technical implications and verification work in a concise written reference.
Related analysisWhy Patching Windchill Is Not EnoughRead analysis →
