A Cl0p ransomware affiliate is exploiting CVE-2026-12569, a critical RCE flaw in PTC Windchill and FlexPLM, using chained vulnerabilities to gain access and deploy JSP webshells. The campaign targets aerospace, automotive, manufacturing, and retail/apparel organizations for data theft and extortion. #Cl0p #PTC #Windchill #FlexPLM #CVE-2026-12569
Keypoints
- A Cl0p affiliate is abusing CVE-2026-12569 in PTC Windchill and FlexPLM.
- The flaw is a critical unauthenticated RCE caused by deserialization of untrusted data.
- Attackers chain information disclosure and login servlet flaws to deploy JSP webshells.
- The campaign has targeted aerospace, automotive, manufacturing, and retail/apparel organizations.
- Victims are being extorted through emails referencing a βWindchill PDMLink module serious data leak.β
Read More: https://www.securityweek.com/ptc-windchill-vulnerability-exploited-in-ransomware-campaign/