Skip to content
Cl0p Ransomware Exploits Critical Vulnerability in PLM Software, Compromising 40+ Firms

Cl0p Ransomware Exploits Critical Vulnerability in PLM Software, Compromising 40+ Firms

First seen 22 Aug 2026, 12:19 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 23, 2026 at 11:16 UTC
  • •Cl0p exploited CVE-2026-12569 in PTC Windchill, affecting over 40 companies.
  • •The attack involved mass exploitation tactics targeting widely used enterprise software.
  • •Sensitive engineering data from major firms like Shell and Philips was compromised.

The Cl0p ransomware group has exploited a critical vulnerability, CVE-2026-12569, in PTC Windchill, affecting over 40 industrial companies, including Shell, Philips, and key Apple suppliers. This attack involved mass exploitation tactics, allowing Cl0p to simultaneously compromise multiple organizations by targeting widely used enterprise software. The vulnerability was published on June 18, 2026, and was added to the CISA KEV list for active exploitation on June 25, 2026. The attack highlights the ongoing threat posed by ransomware groups leveraging critical software flaws to steal sensitive engineering data. The situation remains urgent as organizations scramble to assess and mitigate the impact of this breach.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 49d ago How this analysis works

Timeline

2026-06-18
CVE-2026-12569 published
A critical vulnerability in PTC Windchill was disclosed, affecting numerous organizations.
Ciberseguridadlatam
2026-06-25
CVE-2026-12569 added to CISA KEV
CISA confirmed active exploitation of the vulnerability in the wild, prompting urgent warnings.
Ciberseguridadlatam
2026-08-22
Cl0p attack reported
Cl0p ransomware exploited the vulnerability, compromising over 40 industrial firms, including Shell and Philips.
Ciberseguridadlatam

More articles in this cluster (2)

Following this threat?

Track Cl0p, Apple and CVE-2026-12569 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed