Cl0p Ransomware Exploits Critical Vulnerability in PLM Software, Compromising 40+ Firms

Cl0p Ransomware Exploits Critical Vulnerability in PLM Software, Compromising 40+ Firms

First seen 22 Aug 2026, 12:19 UTC Ciberseguridadlatam 82% similarity 69.9

Article Content

Browse articles
ThreatCluster

The Cl0p ransomware group has exploited a critical vulnerability, CVE-2026-12569, in PTC Windchill, affecting over 40 industrial companies, including Shell, Philips, and key Apple suppliers. This attack involved mass exploitation tactics, allowing Cl0p to simultaneously compromise multiple organizations by targeting widely used enterprise software. The vulnerability was published on June 18, 2026, and was added to the CISA KEV list for active exploitation on June 25, 2026. The attack highlights the ongoing threat posed by ransomware groups leveraging critical software flaws to steal sensitive engineering data. The situation remains urgent as organizations scramble to assess and mitigate the impact of this breach.

Key Points: • Cl0p exploited CVE-2026-12569 in PTC Windchill, affecting over 40 companies. • The attack involved mass exploitation tactics targeting widely used enterprise software. • Sensitive engineering data from major firms like Shell and Philips was compromised.

ThreatCluster AI How this analysis works

Timeline

2026-06-18
CVE-2026-12569 published
A critical vulnerability in PTC Windchill was disclosed, affecting numerous organizations.
Ciberseguridadlatam
2026-06-25
CVE-2026-12569 added to CISA KEV
CISA confirmed active exploitation of the vulnerability in the wild, prompting urgent warnings.
Ciberseguridadlatam
2026-08-22
Cl0p attack reported
Cl0p ransomware exploited the vulnerability, compromising over 40 industrial firms, including Shell and Philips.
Ciberseguridadlatam

Community

Browse all →

Tracked Entities in This Story