CVE Tools

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

The Hacker NewsBy The Hacker News

Reported exploitedPTC WindmillCl0pFlexPLM

Our summary

Threat actors associated with the Cl0p ransomware group are actively exploiting vulnerabilities in internet-facing instances of PTC Windchill and FlexPLM to achieve unauthenticated remote code execution (RCE). Attackers combine a pre-authentication information disclosure flaw in FlexPLM’s WSDL endpoint with a critical RCE vulnerability in Windchill, identified as CVE-2026-12569 (CVSS score: 9.3), to deploy malicious JSP web shells. These attacks primarily target manufacturing, automotive, aerospace, and retail industries, where adversaries steal sensitive design and engineering data through double extortion tactics. PTC has issued warnings about increased threat activity involving this flaw, which was recently added to CISA’s KEV catalog.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store