Exploited in the wild PTC Windmill Cl0p ransomware FlexPLM PTC
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
CVE Tools coverage
Threat actors associated with the Cl0p ransomware group are actively exploiting vulnerabilities in internet-facing instances of PTC Windchill and FlexPLM to achieve unauthenticated remote code execution (RCE). Attackers combine a pre-authentication information disclosure flaw in FlexPLM’s WSDL endpoint with a critical RCE vulnerability in Windchill, identified as CVE-2026-12569 (CVSS score: 9.3), to deploy malicious JSP web shells. These attacks primarily target manufacturing, automotive, aerospace, and retail industries, where adversaries steal sensitive design and engineering data through double extortion tactics. PTC has issued warnings about increased threat activity involving this flaw, which was recently added to CISA’s KEV catalog.