This advisory describes an active Cl0p ransomware affiliate campaign targeting internet-exposed PTC Windchill and FlexPLM systems by chaining a FlexPLM WSDL information disclosure flaw with a Windchill login servlet vulnerability to gain unauthenticated remote code execution. It also details post-exploitation webshell deployment, data theft, and extortion emails sent to affected organizations across Manufacturing, Automotive, Aerospace, and Retail/Apparel sectors. #Cl0p #PTCWindchill #FlexPLM #CVE-2026-12569
Keypoints
- Cl0p affiliates are exploiting exposed PTC Windchill and FlexPLM deployments.
- The attack chains a FlexPLM WSDL disclosure flaw with a Windchill RCE vulnerability.
- Intrusions deploy hex-named JSP webshells under /Windchill/login/.
- Attackers enumerate files, stage engineering data, and conduct double-extortion theft.
- PTC has released fixes, and unpatched internet-facing systems remain at highest risk.
Read More: https://ransom-isac.com/blog/clop-windchill-flexplm-exploitation/