Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569)
ID: d567a138-dd3e-539d-b738-8abab48711c8
STIX ID: report--d567a138-dd3e-539d-b738-8abab48711c8
Feed Name: Ransomware ISAC Blog
Threat Score
Ransom-ISAC advisory detailing active Cl0p-affiliate exploitation of unpatched PTC Windchill and FlexPLM (CVE-2026-12569 chained with a FlexPLM WSDL disclosure) resulting in unauthenticated RCE, deployment of hex-named JSP webshells under /Windchill/login/, staging and theft of engineering/design data, and extortion; includes network and file IOCs, a structural YARA rule for webshell detection, and recommended hunting and remediation actions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
