← Back to Feed
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
CVE-2026-12569
July 25, 2026 · The Hacker News · Severity: CRITICAL
Cl0p ransomware affiliates are exploiting flaws in internet-exposed PTC Windchill and FlexPLM deployments in a new data extortion campaign. Attackers chain a pre-authentication information disclosure in FlexPLM's WSDL endpoint with a server-side flaw in Windchill's login servlet to achieve unauthenticated RCE and deploy JSP web shells. Targets include manufacturing, automotive, aerospace, and retail sectors. The exploitation is linked to CVE-2026-12569 (CVSS 9.3), which CISA added to its Known Exploited Vulnerabilities catalog.
Key Takeaways
- Attack chain chains FlexPLM WSDL info disclosure with Windchill login servlet flaw for JSP web shell deployment. CVE-2026-12569 (CVSS 9.3) in PTC Windchill is the suspected vulnerability, listed in CISA's KEV catalog.
- Campaign targets manufacturing, automotive, aerospace, and retail sectors for double extortion data theft.
- Attackers conduct file system enumeration, stage engineering/design data, and perform double extortion.