Clop Ransomware Exploits Critical Vulnerability in Windchill and FlexPLM

Clop Ransomware Exploits Critical Vulnerability in Windchill and FlexPLM

First seen 24 Jul 2026, 11:43 UTC Bleepingcomputerransom-isac.org 85% similarity 72.8

Article Content

Browse articles
ThreatCluster

The Clop ransomware gang is actively exploiting a critical vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM systems, allowing unauthenticated remote code execution. This exploitation involves deploying JSP webshells for data exfiltration, targeting sectors such as Manufacturing, Automotive, Aerospace, and Retail/Apparel. The vulnerability was disclosed on June 18, 2026, and added to CISA's Known Exploited Vulnerabilities catalog on June 25, 2026. Companies have begun receiving extortion emails from the Clop gang, demanding ransom for stolen data. PTC has released security patches, but unpatched systems remain at risk. The attacks were confirmed by Ransom-ISAC, which is monitoring the situation closely.

Key Points: • Clop ransomware exploits CVE-2026-12569, a critical RCE vulnerability in Windchill and FlexPLM. • Attacks involve deploying JSP webshells for data theft, affecting multiple industries. • PTC has issued patches, but many systems remain vulnerable due to lack of updates.

ThreatCluster AI

Timeline

2026-03-23
CVE-2026-4681 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-18
CVE-2026-12569 published
PTC disclosed a critical RCE vulnerability in Windchill and FlexPLM, allowing remote code execution.
BleepingComputer
2026-06-25
CVE added to CISA KEV catalog
CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog, indicating active exploitation.
BleepingComputer
2026-07-20
Clop extortion emails observed
Ransom-ISAC reported Clop sending extortion emails claiming data breaches linked to Windchill.
ransom-isac.org
Recent
PTC releases security patches
PTC issued patches for CVE-2026-12569, urging customers to secure their systems immediately.
BleepingComputer

Community

Browse all →