Back to advisories

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Cl0p ransomware affiliates are actively exploiting unauthenticated RCE vulnerabilities in internet-exposed PTC Windchill and FlexPLM instances by chaining CVE-2026-12569 with a separate information disclosure flaw. Affected organizations in manufacturing, automotive, aerospace, and retail face data theft and potential ransomware deployment. Attackers are deploying web shells and exfiltrating sensitive product data.

CRITICALAdvisoryJul 27, 2026
Action required
Immediately identify and inventory all internet-exposed PTC Windchill and FlexPLM instances. Apply PTC patches for CVE-2026-12569 and the FlexPLM information disclosure defect. Hunt for web shells in Windchill and FlexPLM directories. Review access logs for suspicious unauthenticated requests and data exfiltration patterns.
Affected products
PTC WindchillPTC FlexPLM