Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569)

Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569)
This advisory describes an active Cl0p ransomware affiliate campaign targeting internet-exposed PTC Windchill and FlexPLM systems by chaining a FlexPLM WSDL information disclosure flaw with a Windchill login servlet vulnerability to gain unauthenticated remote code execution. It also details post-exploitation webshell deployment, data theft, and extortion emails sent to affected organizations across Manufacturing, Automotive, Aerospace, and Retail/Apparel sectors. #Cl0p #PTCWindchill #FlexPLM #CVE-2026-12569

Keypoints

  • Cl0p affiliates are exploiting exposed PTC Windchill and FlexPLM deployments.
  • The attack chains a FlexPLM WSDL disclosure flaw with a Windchill RCE vulnerability.
  • Intrusions deploy hex-named JSP webshells under /Windchill/login/.
  • Attackers enumerate files, stage engineering data, and conduct double-extortion theft.
  • PTC has released fixes, and unpatched internet-facing systems remain at highest risk.

Read More: https://ransom-isac.com/blog/clop-windchill-flexplm-exploitation/