Clop Ransomware Exploits Critical Vulnerability in Windchill and FlexPLM
ID: 0256006c-f2f4-5e00-9747-868b62627baa
STIX ID: report--0256006c-f2f4-5e00-9747-868b62627baa
Feed Name: ThreatCluster
Threat Score
Clop is actively exploiting CVE-2026-12569 — a critical unauthenticated RCE in PTC Windchill and FlexPLM — to deploy JSP webshells for data exfiltration and subsequent extortion across industries (Manufacturing, Automotive, Aerospace, Retail). The vulnerability was disclosed on June 18, 2026, added to CISA's KEV on June 25, patches are available from PTC, and Ransom-ISAC has confirmed ongoing activity and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
