CVE Tools
Back to feed
Exploited in the wild Windchill Clop ransomware FlexPLM PTC

Clop ransomware targets Windchill, FlexPLM in data theft attacks

BleepingComputer·By Sergiu Gatlan··3 min read
CVE Tools coverage

The Clop ransomware group is actively exploiting a critical vulnerability in PTC’s Windchill and FlexPLM platforms, tracked as CVE-2026-12569. This flaw allows unauthenticated attackers to execute arbitrary code and deploy JSP webshells for data exfiltration. The exploit has already led to extortion attempts against affected organizations. PTC issued patches on June 17, but CISA added the flaw to its Known Exploited Vulnerabilities catalog due to ongoing threats. Cybersecurity firm ReliaQuest warns users to apply updates and isolate compromised systems immediately.