ransom-isac.org
Clop Ransomware Exploits Critical Vulnerability in Windchill and FlexPLM
Article Content
The Clop ransomware gang is actively exploiting a critical vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM systems, allowing unauthenticated remote code execution. This exploitation involves deploying JSP webshells for data exfiltration, targeting sectors such as Manufacturing, Automotive, Aerospace, and Retail/Apparel. The vulnerability was disclosed on June 18, 2026, and added to CISA's Known Exploited Vulnerabilities catalog on June 25, 2026. Companies have begun receiving extortion emails from the Clop gang, demanding ransom for stolen data. PTC has released security patches, but unpatched systems remain at risk. The attacks were confirmed by Ransom-ISAC, which is monitoring the situation closely.
Key Points: • Clop ransomware exploits CVE-2026-12569, a critical RCE vulnerability in Windchill and FlexPLM. • Attacks involve deploying JSP webshells for data theft, affecting multiple industries. • PTC has issued patches, but many systems remain vulnerable due to lack of updates.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.