← All stories
● Covered by 3 sources · 3 reportsMedium impact3 negative

Clop Ransomware Exploits PTC Windchill and FlexPLM Vulnerability for Data Theft

🔄 Updated 22d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Clop ransomware exploits CVE-2026-12569 in PTC Windchill/FlexPLM.
  • Vulnerability allows remote code execution and data exfiltration.
  • CISA and German authorities issued urgent patching directives.
  • PTC released security patches starting June 17.
  • Clop deploys JSP webshells to exfiltrate data.
  • The vulnerability has a CVSS score of 9.3.
  • Attackers chain a pre-authentication information disclosure with a server-side flaw.
  • Attackers deploy hex-named JSP web shells under /Windchill/login/.
  • Targets include manufacturing, automotive, aerospace, and retail sectors.
  • The campaign leads to double extortion data theft.

Clop Ransomware Exploits PTC Vulnerability

The Clop ransomware gang is actively targeting Internet-exposed instances of PTC Windchill and FlexPLM. They are exploiting a critical improper input validation vulnerability, identified as CVE-2026-12569, to conduct data theft and extortion campaigns.

Technical Details of the Attack

ReliaQuest reported that Clop operators are deploying JSP webshells after exploiting CVE-2026-12569. This vulnerability, rated CVSS 9.3, enables unauthenticated remote code execution, allowing attackers to exfiltrate sensitive product data from compromised Product Lifecycle Management (PLM) platforms. The tradecraft observed shares characteristics with previous Clop campaigns targeting enterprise applications.

Extortion and Official Response

Companies have begun receiving extortion emails from the Clop gang, using new email addresses like support@cryptohox.com. In response to the active exploitation, PTC started releasing security patches for CVE-2026-12569 on June 17 and issued remediation guidance. The Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating U.S. federal agencies to secure their systems within three days. German authorities also issued urgent warnings to PTC customers.

Updates

🕒 2026-07-25 · new reporting from The Hacker News
  • Clop deploys JSP webshells to exfiltrate data.
  • The vulnerability has a CVSS score of 9.3.
  • Attackers chain a pre-authentication information disclosure with a server-side flaw.
  • Attackers deploy hex-named JSP web shells under /Windchill/login/.
  • Targets include manufacturing, automotive, aerospace, and retail sectors.
  • The campaign leads to double extortion data theft.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~11 min · 9 stories · Aug 16

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

A Cl0p ransomware affiliate is actively exploiting a critical remote code execution (RCE) vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM platforms. This exploitation allows attackers to gain initial access, exfiltrate data, and send extortion emails to affected organizations in aerospace, automotive, manufacturing, and retail sectors.

Threat actors linked to the Cl0p ransomware campaign are exploiting vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments to achieve unauthenticated remote code execution and steal data. This campaign targets manufacturing, automotive, aerospace, and retail sectors, leading to double extortion attempts.

The Clop ransomware group is exploiting a critical vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM to exfiltrate data from targeted companies. This exploitation has led to extortion campaigns and prompted urgent warnings from cybersecurity agencies and authorities.