logo

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

ID: b7870c22-54f6-5963-96d1-02b60ebfb1f4

STIX ID: report--b7870c22-54f6-5963-96d1-02b60ebfb1f4

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-07-25

Date Updated: 2026-07-25

Author: [email protected] (The Hacker News)

...
...

Threat actors associated with Cl0p are actively exploiting a critical PTC Windchill/Windmill vulnerability (CVE-2026-12569, CVSS 9.3) chained with a FlexPLM pre-auth information-disclosure flaw to achieve unauthenticated RCE and deploy hex-named JSP web shells, enabling file-system enumeration, theft of engineering/design data, and double-extortion ransom demands; Ransom-ISAC, eCrime.ch and DEFUSED released a coordinated advisory and published four IoC IP addresses tied to the campaign, which has impacted manufacturing, automotive, aerospace, and retail organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.