PTC Windchill Vulnerability Exploited in Ransomware Campaign

PTC Windchill Vulnerability Exploited in Ransomware Campaign
A Cl0p ransomware affiliate is exploiting CVE-2026-12569, a critical RCE flaw in PTC Windchill and FlexPLM, using chained vulnerabilities to gain access and deploy JSP webshells. The campaign targets aerospace, automotive, manufacturing, and retail/apparel organizations for data theft and extortion. #Cl0p #PTC #Windchill #FlexPLM #CVE-2026-12569

Keypoints

  • A Cl0p affiliate is abusing CVE-2026-12569 in PTC Windchill and FlexPLM.
  • The flaw is a critical unauthenticated RCE caused by deserialization of untrusted data.
  • Attackers chain information disclosure and login servlet flaws to deploy JSP webshells.
  • The campaign has targeted aerospace, automotive, manufacturing, and retail/apparel organizations.
  • Victims are being extorted through emails referencing a β€œWindchill PDMLink module serious data leak.”

Read More: https://www.securityweek.com/ptc-windchill-vulnerability-exploited-in-ransomware-campaign/