[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fLBBzAvlKnUEoME-DqlBKqjN-0e7IvbREo2aru0iLZRs":3},{"article":4,"iocs":58},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"a39b5149-cbb3-470e-9702-91627f460a92","PTC Windchill Vulnerability Exploited in Ransomware Campaign","ptc-windchill-vulnerability-exploited-in-ransomware-campaign-10f165","The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication. The post PTC Windchill Vulnerability Exploited in Ransomware Campaign appeared first on SecurityWeek.","A critical-severity unsafe deserialization vulnerability (CVE-2026-12569, CVSS 9.3) in PTC's Windchill and FlexPLM platforms is being actively exploited by a Cl0p ransomware affiliate to execute arbitrary code without authentication. The attackers chain pre-authentication information disclosure with server-side flaws to deploy JSP webshells, then enumerate filesystems, stage data, and exfiltrate information for extortion from aerospace, automotive, manufacturing, and retail sectors. The vulnerability was patched June 17, confirmed exploited in the wild June 18, and added to CISA's KEV catalog by end of June.","Cl0p ransomware affiliate exploits critical PTC Windchill deserialization flaw for RCE attacks","A Cl0p ransomware affiliate has been observed exploiting a critical-severity remote code execution (RCE) vulnerability in PTC’s product lifecycle management (PLM) platforms Windchill and FlexPLM. Tracked as CVE-2026-12569 (CVSS score of 9.3), the security defect is described as a deserialization of untrusted data issue that can be exploited without authentication. Patched on June 17, the bug was flagged as exploited in the wild the next day, when PTC published indicators of compromise (IoCs). It was added to CISA’s KEV catalog at the end of June. Fresh warnings from ReliaQuest and Ransom-ISAC (in collaboration with eCrime.ch and Defused) show that the vulnerability is now exploited in the wild by a Cl0p affiliate. “The actor behind these attacks remains unconfirmed. However, the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories,” ReliaQuest says. A detailed Ransom-ISAC advisory shows that the attackers have been chaining a “pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet” to achieve RCE and deploy JSP webshells.Advertisement. Scroll to continue reading. Following initial access, the hackers have been observed enumerating filesystems, staging data, and exfiltrating data for extortion. Starting July 20, the attackers have been targeting organizations across the aerospace, automotive, manufacturing, and retail\u002Fapparel sectors, Ransom-ISAC’s advisory reads. As part of the observed campaign, the threat actor has been sending extortion emails with a subject line “Windchill PDMLink module serious data leak” to hundreds of users within the impacted organizations. “As of 22 July, Cl0p ransomware has not begun listing victims of this latest campaign on their dark web data leak site or has publicly claimed credit for this latest campaign,” Ransom-ISAC says. Organizations are advised to apply PTC’s patches and to use previously published and newly shared IoCs to conduct threat hunting. They should also follow PTC’s remediation steps. Related: US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices Related: Rockwell Patches Code Execution Flaws in Arena Simulation Software Related: Is Patching Dead? Vulnerability Management in the Post-Mythos Era Related: New Check Point Zero-Day Vulnerability Exploited in the Wild Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire StrongestLayer Raises $4.1 Million in Seed Funding ExtensionEndpoint Security Firm Glow Launches With $180M in Funding at $1.2B ValuationEmpirical Security Raises $25 Million in Series A FundingNew HollowGraph Malware Abuses Microsoft 365 Calendar for C&C CommunicationEstée Lauder Discloses Impact From Oracle EBS Zero-Day HackClover Health Investments Discloses Data BreachZimbra Update Patches Critical VulnerabilitiesOpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Latest News MedusaHVNC Malware Uses Hidden Windows Desktops to Evade DetectionNvidia and Tech Giants Launch AI Security AllianceCoca-Cola Confirms Data Breach After Fairlife Ransomware AttackBeelzebub Raises $3.4 Million for Hacker-Trapping PlatformWhat’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find OutHacked Public Wi-Fi Gateways Used to Harvest Corporate CredentialsAnthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on ExploitsDentaQuest Data Breach Potentially Impacts Over 23 Million People Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Closing the Exploitation Gap July 22, 2026 Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveBarry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer.John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox.Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer.More People On The MoveExpert Insights Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fptc-windchill-vulnerability-exploited-in-ransomware-campaign\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2024\u002F12\u002Fransomware.jpeg","2026-07-27T13:19:30+00:00","2026-07-27T14:00:12.772418+00:00",9,[18,21,23,26,29],{"name":19,"type":20},"PTC Windchill","product",{"name":22,"type":20},"PTC FlexPLM",{"name":24,"type":25},"PTC","vendor",{"name":27,"type":28},"Cl0p ransomware affiliate","threat_actor",{"name":30,"type":31},"JSP webshells","technology","7d8b5ab8-ea0b-4ced-ae97-ec251b86993a",{"id":32,"icon":34,"name":35,"slug":36},null,"Ransomware","ransomware",[38,43,48,53],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":44},{"id":45,"icon":34,"name":46,"slug":47},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":49},{"id":50,"icon":34,"name":51,"slug":52},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":54},{"id":55,"icon":34,"name":56,"slug":57},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",[59,63],{"type":60,"value":61,"context":62},"cve","CVE-2026-12569","Critical unsafe deserialization RCE vulnerability in PTC Windchill and FlexPLM, CVSS 9.3, exploited by Cl0p affiliate",{"type":64,"value":65,"context":66},"malware","Cl0p ransomware","Ransomware affiliate exploiting Windchill vulnerability in active campaign targeting enterprise sectors"]