Exploited in the wild PTC Windchill Clop ransomware FlexPLM PTC
Clop created custom web shell for Windchill data theft attacks
CVE Tools coverage
ReliaQuest identified a custom-built Java web shell attributed to the Clop ransomware gang, specifically engineered for PTC Windchill and FlexPLM servers. This implant leverages the critical remote code execution vulnerability CVE-2026-12569 to decrypt stored credentials and exfiltrate files from application vaults. Because the tool integrates directly with Windchill's internal APIs, database queries run under the application's service identity, potentially evading standard detection methods. Organizations running affected versions are urged to apply patches immediately and investigate any unusual JSP files referencing the 'X-windchill-req' header.