ransom-isac.org
Clop Ransomware Exploits Critical Vulnerability in Windchill and FlexPLM
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Clop ransomware gang is actively exploiting a critical vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM systems, allowing unauthenticated remote code execution. This exploitation involves deploying JSP webshells for data exfiltration, targeting sectors such as Manufacturing, Automotive, Aerospace, and Retail/Apparel. The vulnerability was disclosed on June 18, 2026, and added to CISA's Known Exploited Vulnerabilities catalog on June 25, 2026. Companies have begun receiving extortion emails from the Clop gang, demanding ransom for stolen data. PTC has released security patches, but unpatched systems remain at risk. The attacks were confirmed by Ransom-ISAC, which is monitoring the situation closely.
Key Points: • Clop ransomware exploits CVE-2026-12569, a critical RCE vulnerability in Windchill and FlexPLM. • Attacks involve deploying JSP webshells for data theft, affecting multiple industries. • PTC has issued patches, but many systems remain vulnerable due to lack of updates.