logo

Cl0p Exploitation of PTC Windchill and FlexPLM Vulnerability (Campaign)

ID: 8036444a-144a-538b-a45d-83ca9251398f

STIX ID: report--8036444a-144a-538b-a45d-83ca9251398f

Feed Name: Wiz Cloud Threat Landscape

Threat Score
78/100

Date Published: 2026-07-22

Date Updated: 2026-07-26

Author: [email protected] (Wiz Threat Research)

...
...

Attackers target internet-exposed Windchill and FlexPLM deployments by first performing reconnaissance against a WSDL endpoint, exploiting an information-disclosure issue and CVE-2026-12569 (deserialization leading to unauthenticated RCE), and planting hex-named JSP webshells under /Windchill/login/ for persistent access. Post-compromise activity includes filesystem enumeration and file listing (e.g., flst.txt), staging of sensitive engineering and design data for exfiltration, and large-scale extortion emails from compromised accounts threatening public release of stolen data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.