Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

July 25, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Organizations in manufacturing, automotive, aerospace, and retail sectors
Incident: Exploitation of unauthenticated RCE in PTC Windchill and FlexPLM to steal sensitive data.
Impact: Loss of high-value engineering and design data leading to double extortion.
Attacker: Cl0p and affiliates
Analysis: The attackers are exploiting CVE-2026-12569 by chaining it with a pre-authentication information disclosure flaw in FlexPLM. This combination allows for unauthenticated remote code execution and the deployment of JSP web shells. Once inside, the actors focus on exfiltrating sensitive design and engineering data for double extortion.
Recommendations: Immediately patch PTC Windchill and FlexPLM deployments to remediate CVE-2026-12569.; Audit logs and file systems for the presence of JSP web shells in the /Windchill/login/ directory.; Restrict internet exposure of PTC Windchill and FlexPLM interfaces using VPNs or strict IP whitelisting.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *