CVE Tools
Back to feed
Exploited in the wild PTC Windmill Cl0p ransomware FlexPLM PTC

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

Threat actors associated with the Cl0p ransomware group are actively exploiting vulnerabilities in internet-facing instances of PTC Windchill and FlexPLM to achieve unauthenticated remote code execution (RCE). Attackers combine a pre-authentication information disclosure flaw in FlexPLM’s WSDL endpoint with a critical RCE vulnerability in Windchill, identified as CVE-2026-12569 (CVSS score: 9.3), to deploy malicious JSP web shells. These attacks primarily target manufacturing, automotive, aerospace, and retail industries, where adversaries steal sensitive design and engineering data through double extortion tactics. PTC has issued warnings about increased threat activity involving this flaw, which was recently added to CISA’s KEV catalog.