VYPR
breachPublished Jul 24, 2026· 1 source

Clop Ransomware Exploits PTC Windchill and FlexPLM Vulnerabilities for Data Theft

The Clop ransomware gang is actively exploiting a critical vulnerability in PTC's Windchill and FlexPLM software to steal sensitive data and extort victims.

The notorious Clop ransomware gang has initiated a new extortion campaign targeting organizations using PTC's Windchill and FlexPLM product lifecycle management (PLM) software. Attackers are exploiting a critical vulnerability, identified as CVE-2026-12569, which allows for unauthenticated remote code execution on internet-exposed instances of these widely-used enterprise platforms.

This vulnerability, stemming from improper input validation and unsafe deserialization, has a high CVSS score of 9.3, indicating its severity. Once exploited, threat actors can deploy JavaServer Pages (JSP) webshells. These webshells grant them the ability to execute arbitrary commands remotely and, crucially, exfiltrate sensitive product design and manufacturing data stored within the compromised PLM systems.

Evidence of Clop's involvement comes from extortion emails sent to victims using a new email address, support@cryptohox.com, a tactic the group frequently employs to mask its activities before launching new campaigns. While the specific threat actor behind these attacks remains unconfirmed by initial reports, cybersecurity firm ReliaQuest noted that the observed tradecraft bears similarities to previous Clop operations targeting valuable enterprise data repositories.

PTC began issuing patches for CVE-2026-12569 on June 17, 2026, and provided remediation guidance through a private advisory, urging customers to check for signs of compromise. Despite PTC not initially confirming in-the-wild exploitation, the Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on June 26, mandating U.S. federal agencies to patch their affected systems within three days.

German authorities also reacted with urgency, with the Federal Office for Information Security (BSI) alerting PTC customers to the critical nature of the flaw, reminiscent of their swift response to a similar Windchill and FlexPLM vulnerability (CVE-2026-4681) earlier in the year. ReliaQuest recommends that affected organizations immediately patch their Windchill and FlexPLM systems, ideally placing them behind VPNs or trusted access gateways, and to isolate any suspected compromised servers for forensic investigation.

PTC Windchill and FlexPLM are integral to the product lifecycle management process for numerous companies across high-profile sectors such as aerospace, defense, automotive, and medical technology. These platforms manage product data from initial concept through to final manufacturing, making them repositories of highly sensitive intellectual property.

The Clop ransomware group has a well-documented history of targeting enterprise file transfer and collaboration solutions, including Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U, Cleo, and most notably, MOVEit Transfer. Their modus operandi involves exploiting zero-day vulnerabilities to exfiltrate data before deploying ransomware, often publishing stolen information on their dark web leak site if ransoms are not paid. The U.S. Department of State has offered a substantial reward for information leading to the identification and prosecution of individuals associated with the Clop ransomware gang.

Synthesized by Vypr AI