[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:cl0p-affiliates-target-internet-exposed-ptc-windchill-and-flexplm-with-unauthent-ms2y03na":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":13,"action_required":16,"article_ids":17,"ioc_summary":19,"source_urls":20,"status":22,"expires_at":23,"created_at":24,"updated_at":25,"articles":26},"f8425460-0939-4098-939e-e1ab895b738f","Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE","cl0p-affiliates-target-internet-exposed-ptc-windchill-and-flexplm-with-unauthent-ms2y03na","Cl0p ransomware affiliates are actively exploiting unauthenticated RCE vulnerabilities in internet-exposed PTC Windchill and FlexPLM instances by chaining CVE-2026-12569 with a separate information disclosure flaw. Affected organizations in manufacturing, automotive, aerospace, and retail face data theft and potential ransomware deployment. Attackers are deploying web shells and exfiltrating sensitive product data.","critical","advisory",[12],"CVE-2026-12569",[14,15],"PTC Windchill","PTC FlexPLM","Immediately identify and inventory all internet-exposed PTC Windchill and FlexPLM instances. Apply PTC patches for CVE-2026-12569 and the FlexPLM information disclosure defect. Hunt for web shells in Windchill and FlexPLM directories. Review access logs for suspicious unauthenticated requests and data exfiltration patterns.",[18],"835a8eac-9b7b-4c3f-84e0-6bf869c8128e",null,[21],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fcl0p-affiliates-target-internet-exposed.html","active","2026-07-29T08:05:56.879+00:00","2026-07-27T08:05:59.625811+00:00","2026-07-27T08:10:06.667484+00:00",[27],{"id":18,"title":6,"url":21}]