CVE Tools
Back to feed
Exploited in the wild PTC Windchill Clop ransomware PTC FlexPLM Philips

Philips and GE investigating Clop ransomware data theft claims

BleepingComputer·By Sergiu Gatlan··3 min read
CVE Tools coverage

General Electric, Philips, and Shell are currently investigating reports that the Clop ransomware group accessed their networks and exfiltrated data. These breaches stem from active exploitation of CVE-2026-12569, a critical input validation vulnerability affecting Internet-exposed instances of PTC Windchill and PTC FlexPLM. While Philips has stated its response contained the incident without impacting customer environments, GE is still assessing the scope of the potential compromise.

This campaign involves Clop deploying JSP webshells to steal sensitive assets such as blueprints and project plans from enterprises relying on these PLM platforms. As CISA has added this flaw to its Known Exploited Vulnerabilities catalog, organizations should apply available patches and audit their systems for signs of intrusion.