logo

Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569)

ID: d567a138-dd3e-539d-b738-8abab48711c8

STIX ID: report--d567a138-dd3e-539d-b738-8abab48711c8

Feed Name: Ransomware ISAC Blog

Threat Score
90/100

Date Published: 2026-07-22

Date Updated: 2026-08-21

Author: [email protected] (Brandon Parsons)

...
...

Ransom-ISAC advisory detailing active Cl0p-affiliate exploitation of unpatched PTC Windchill and FlexPLM (CVE-2026-12569 chained with a FlexPLM WSDL disclosure) resulting in unauthenticated RCE, deployment of hex-named JSP webshells under /Windchill/login/, staging and theft of engineering/design data, and extortion; includes network and file IOCs, a structural YARA rule for webshell detection, and recommended hunting and remediation actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.