Cl0p Affiliate Exploits Critical PTC Windchill Flaw

A Cl0p affiliate is exploiting an unauthenticated RCE in PTC Windchill and FlexPLM (CVE-2026-12569) to install JSP webshells and exfiltrate data for extortion.

PTC released a patch for CVE-2026-12569 on June 17 and reported exploitation in the wild the next day. The vulnerability, a deserialization of untrusted data rated 9.3 in CVSS, allows remote code execution without authentication. CISA added the flaw to its Known Exploited Vulnerabilities catalog at the end of June.

Security teams have observed attackers chaining a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet to achieve remote code execution. Successful exploits have resulted in the deployment of JSP webshells on affected servers, which provide persistent remote access to intruders.

After gaining access, attackers have listed files, staged data and exfiltrated sensitive files for use in extortion. Analysts tracking the activity include Ransom-ISAC, ReliaQuest, eCrime.ch and Defused, which have published indicators of compromise and technical detection guidance.

ReliaQuest noted that “The actor behind these attacks remains unconfirmed. However, the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories.” Investigators have not publicly verified the identity of the actor responsible for the current campaign.

Ransom-ISAC reports a surge in targeting beginning July 20, with incidents affecting organizations in the aerospace, automotive, manufacturing and retail/apparel sectors. As part of the campaign, extortion emails with the subject line “Windchill PDMLink module serious data leak” have been sent to hundreds of users at impacted organizations. By July 22, the group commonly known as Cl0p had not posted a victim list or claimed responsibility for this campaign.

PTC and collaborating incident responders recommend applying the June 17 security update immediately and using published IoCs to hunt for signs of compromise. Remediation advice includes inspecting FlexPLM WSDL endpoints and Windchill login servlets for webshells, reviewing logs for unusual access, and isolating any infected systems. Ransom-ISAC and partners have provided detection queries and technical details to support response efforts.

Windchill and FlexPLM are widely used to manage product designs, bills of materials and engineering data. A deserialization flaw that permits unauthenticated remote code execution enables attackers to run arbitrary code on affected servers without valid credentials. Deployed JSP webshells can be used to maintain access, move laterally and extract large sets of confidential files over time.

Organizations running PTC Windchill or FlexPLM should treat CVE-2026-12569 as a high-priority patching and threat-hunting task, follow PTC’s published remediation steps and apply community IoCs to determine whether systems have been compromised.

Articles by this author