logo

Clop Ransomware Exploits Critical Vulnerability in Windchill and FlexPLM

ID: 0256006c-f2f4-5e00-9747-868b62627baa

STIX ID: report--0256006c-f2f4-5e00-9747-868b62627baa

Feed Name: ThreatCluster

Threat Score
80/100

Date Published: 2026-07-24

Date Updated: 2026-07-25

...
...

Clop is actively exploiting CVE-2026-12569 — a critical unauthenticated RCE in PTC Windchill and FlexPLM — to deploy JSP webshells for data exfiltration and subsequent extortion across industries (Manufacturing, Automotive, Aerospace, Retail). The vulnerability was disclosed on June 18, 2026, added to CISA's KEV on June 25, patches are available from PTC, and Ransom-ISAC has confirmed ongoing activity and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.