logo

Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569)

ID: e442eda4-3d2c-54f2-a024-43c44cd66d15

STIX ID: report--e442eda4-3d2c-54f2-a024-43c44cd66d15

Feed Name: Ransomware ISAC Blog

Threat Score
90/100

Date Published: 2026-07-22

Date Updated: 2026-07-29

Author: [email protected] (Brandon Parsons)

...
...

This Ransom-ISAC advisory reports active Cl0p-affiliate exploitation of a critical PTC Windchill/FlexPLM RCE (CVE-2026-12569) chained with a FlexPLM WSDL information-disclosure to achieve unauthenticated RCE and deploy hex-named JSP webshells, followed by filesystem enumeration, data staging and a data extortion campaign; the report includes CVSS scores, IOCs (IPs, SHA-256, paths, malicious header), affected sectors (Manufacturing, Automotive, Aerospace, Retail), and remediation/hunting guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.