Post

Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569)

Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569)

Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569) 🚨

The Unified Threat Advisory is a coordinated Cyber Intelligence effort led by Ransom-ISAC, in collaboration with eCrime.ch and DEFUSED. This update covers active Cl0p ransomware affiliate exploitation targeting internet-exposed PTC Windchill and FlexPLM deployments.

Key Findings 🔍

  • Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet.
  • This enables unauthenticated remote code execution and deployment of hex-named JSP webshells under /Windchill/login/.
  • Post-exploitation includes filesystem enumeration via flst.txt, staging of engineering/design data, and double-extortion data theft.

Confirmed victim sectors include Manufacturing, Automotive, Aerospace, and Retail/Apparel.

Vulnerability Details ⚠️

We suspect that threat actors affiliated with Cl0p ransomware exploited CVE-2026-12569 as a zero-day vulnerability in early June 2026. This critical-severity remote code execution (RCE) vulnerability in PTC Windchill PDMlink and PTC FlexPLM may be exploited through the deserialization of untrusted data.

CVE-2026-12569 was disclosed on 17 June 2026 and impacts Windchill and FlexPLM releases prior to 11.0 M030. CISA added CVE-2026-12569 to their known exploited vulnerabilities (KEV) catalog on 25 June 2026.

Recent Campaign Observations đź“§

On 20 July, Ransom-ISAC began observing an alleged Cl0p ransomware data extortion campaign. Emails with the subject line, “Windchill PDMLink module serious data leak” were sent to an unknown number of affected organizations. These extortion emails appear to originate from randomly compromised accounts and are sent to hundreds of users within an impacted organization.

Recommendations âś…

Organizations receiving emails matching this pattern should conduct threat hunting dating back to early June 2026, using the indicators of compromise (IOCs) in PTC’s advisory as soon as possible and follow PTC’s remediation steps outlined in PTC’s Support Article.

For more details, check the full article here: Read full article

This post is licensed under CC BY 4.0 by the author.