Exploited in the wild Windchill Clop ransomware FlexPLM PTC
Clop ransomware targets Windchill, FlexPLM in data theft attacks
CVE Tools coverage
The Clop ransomware group is actively exploiting a critical vulnerability in PTC’s Windchill and FlexPLM platforms, tracked as CVE-2026-12569. This flaw allows unauthenticated attackers to execute arbitrary code and deploy JSP webshells for data exfiltration. The exploit has already led to extortion attempts against affected organizations. PTC issued patches on June 17, but CISA added the flaw to its Known Exploited Vulnerabilities catalog due to ongoing threats. Cybersecurity firm ReliaQuest warns users to apply updates and isolate compromised systems immediately.