
Hackers believed to be Cl0p ransomware operatives are exploiting a critical flaw in PTC Windchill and FlexPLM to deploy web shells and steal sensitive enterprise data.
While the threat actor has not been identified with absolute certainty, the observed tactics closely match those used in previous data theft campaigns attributed to the Cl0p ransomware gang.
ReliaQuest reported that it has observed active exploitation of CVE-2026-12569, a critical unsafe deserialization flaw affecting PTC Windchill and PTC FlexPLM. The vulnerability allows unauthenticated remote code execution, enabling attackers to deploy JSP web shells, execute commands, and exfiltrate sensitive product data.
ReliaQuest said the tradecraft closely resembles Cl0p’s previous campaigns targeting enterprise applications that store high-value corporate data.
PTC Windchill and FlexPLM are Product Lifecycle Management (PLM) platforms used to manage products from design through manufacturing. The software is widely deployed across the aerospace, defense, automotive, manufacturing, retail, and medical technology sectors. PTC says its products are used by more than 30,000 organizations worldwide, including over 1,500 FlexPLM customers.
PTC released patches for CVE-2026-12569 on June 17, accompanied by a private advisory urging customers to review their environments for signs of compromise. After warning customers of “heightened threat activity” on June 26, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog and ordered federal agencies to secure affected systems within three days.
Previously, the Federal Office for Information Security (BSI) contacted PTC customers directly by phone and email, urging them to apply the updates immediately. Earlier this year, the agency issued similar warnings over another critical Windchill vulnerability, CVE-2026-4681.
The activity fits Cl0p's long-standing strategy of exploiting zero-day vulnerabilities in widely used enterprise software to steal sensitive data. Previous campaigns targeted Accellion FTA, SolarWinds Serv-U, GoAnywhere MFT, MOVEit Transfer, Cleo, and, most recently, an Oracle E-Business Suite zero-day that compromised numerous organizations, including The Washington Post, Logitech, and Estée Lauder.
Rather than relying solely on file encryption, Cl0p primarily extorts victims by threatening to publish stolen data on its leak site, often making it available via BitTorrent if ransom demands are not met.
ReliaQuest urges organizations to apply PTC's security update (CS473270) immediately and, where possible, restrict Windchill and FlexPLM access behind a VPN or trusted access gateway. If a compromise is suspected, affected servers should be isolated, forensic evidence preserved, exposed credentials rotated, and systems thoroughly investigated before being returned to production.







Leave a Reply