Cl0p Targets PTC Windchill and FlexPLM: Exploit Chain to Unauth RCE

Colleagues, I’d like to flag a cybersecurity incident involving enterprise applications.
Reports indicate that Cl0p-linked threat actors are exploiting internet-exposed PTC Windchill and FlexPLM.
What we know:
• the attack relies on a vulnerability chain leading to unauthenticated RCE;
• JSP web shells are deployed;
• this is followed by data theft and double extortion;
• manufacturing, automotive, aerospace and retail are among the impacted sectors.
PTC has warned of increased activity, and CISA has added CVE-2026-12569 to the KEV catalog.
Why it matters: cases like this show how quickly an enterprise vulnerability can turn into a breach and disruption.
Are you reviewing internet exposure for such platforms and your patching timelines?
#cybersecurity #ransomware #vulnerability #infosec


Latest comments
No comments yet.