PTC Windchill Vulnerability Exploited in Ransomware Campaign
ID: 3d2824bf-cf2f-5dd2-99c9-2685dd7496f1
STIX ID: report--3d2824bf-cf2f-5dd2-99c9-2685dd7496f1
Feed Name: CosmicBytez Labs
Executive Summary: A critical vulnerability (CVE-2026-12569, CVSS 9.3) in PTC Windchill is being actively exploited by the Cl0p ransomware group via a chained FlexPLM information leak and an unsafe deserialization in Windchill, enabling unauthenticated remote code execution and JSP webshell deployment; the campaign targets high-value industrial organizations (aerospace, automotive, manufacturing, retail) for data exfiltration and double-extortion, and organizations are urged to apply the June 17, 2026 patch, hunt IOCs, audit logs, and segment PLM systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
