PTC Windchill Vulnerability Exploited in Ransomware Campaign
A Cl0p ransomware group is actively exploiting a critical remote code execution vulnerability in PTC's Windchill and FlexPLM platforms, tracked as CVE-2026-12569. The flaw allows unauthenticated attackers to execute arbitrary code due to unsafe deserialization of data. Despite being patched on June 17, it was confirmed exploited just one day later and added to CISA’s KEV list. Recent reports from ReliaQuest and Ransom-ISAC reveal that the exploit is now used in targeted attacks against multiple industries, including aerospace and manufacturing. Attackers combine pre-authentication flaws with server-side issues to deploy webshells and steal sensitive data. Organizations are urged to apply available patches and monitor for related indicators of compromise.