VYPR
breachPublished Jul 24, 2026· Updated Jul 27, 2026· 5 sources

Clop Ransomware Exploits PTC Windchill and FlexPLM Vulnerabilities for Data Theft

The Clop ransomware gang is actively exploiting a critical vulnerability in PTC's Windchill and FlexPLM software to steal sensitive data and extort victims.

The notorious Clop ransomware gang has initiated a new extortion campaign targeting organizations using PTC's Windchill and FlexPLM product lifecycle management (PLM) software. Attackers are exploiting a critical vulnerability, identified as CVE-2026-12569, which allows for unauthenticated remote code execution on internet-exposed instances of these widely-used enterprise platforms.

This vulnerability, stemming from improper input validation and unsafe deserialization, has a high CVSS score of 9.3, indicating its severity. Once exploited, threat actors can deploy JavaServer Pages (JSP) webshells. These webshells grant them the ability to execute arbitrary commands remotely and, crucially, exfiltrate sensitive product design and manufacturing data stored within the compromised PLM systems.

Evidence of Clop's involvement comes from extortion emails sent to victims using a new email address, [email protected], a tactic the group frequently employs to mask its activities before launching new campaigns. While the specific threat actor behind these attacks remains unconfirmed by initial reports, cybersecurity firm ReliaQuest noted that the observed tradecraft bears similarities to previous Clop operations targeting valuable enterprise data repositories.

PTC began issuing patches for CVE-2026-12569 on June 17, 2026, and provided remediation guidance through a private advisory, urging customers to check for signs of compromise. Despite PTC not initially confirming in-the-wild exploitation, the Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on June 26, mandating U.S. federal agencies to patch their affected systems within three days.

German authorities also reacted with urgency, with the Federal Office for Information Security (BSI) alerting PTC customers to the critical nature of the flaw, reminiscent of their swift response to a similar Windchill and FlexPLM vulnerability (CVE-2026-4681) earlier in the year. ReliaQuest recommends that affected organizations immediately patch their Windchill and FlexPLM systems, ideally placing them behind VPNs or trusted access gateways, and to isolate any suspected compromised servers for forensic investigation.

PTC Windchill and FlexPLM are integral to the product lifecycle management process for numerous companies across high-profile sectors such as aerospace, defense, automotive, and medical technology. These platforms manage product data from initial concept through to final manufacturing, making them repositories of highly sensitive intellectual property.

The Clop ransomware group has a well-documented history of targeting enterprise file transfer and collaboration solutions, including Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U, Cleo, and most notably, MOVEit Transfer. Their modus operandi involves exploiting zero-day vulnerabilities to exfiltrate data before deploying ransomware, often publishing stolen information on their dark web leak site if ransoms are not paid. The U.S. Department of State has offered a substantial reward for information leading to the identification and prosecution of individuals associated with the Clop ransomware gang.

This new report details the specific attack chain used by Cl0p affiliates, involving the chaining of a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a weakness in the Windchill login servlet. It also highlights the campaign's origin in early June and the subsequent mass extortion emails sent to employees, a tactic designed to increase pressure on victims before public disclosure. The article further provides specific Indicators of Compromise (IoCs), including IP addresses, a malicious request header, and a webshell path, which were not present in the initial report.

This new report details the specific attack chain used by Cl0p affiliates, which involves chaining a pre-authentication information disclosure in FlexPLM's WSDL endpoint with a server-side vulnerability in Windchill's login servlet. This allows for unauthenticated remote code execution and the deployment of web shells, leading to data enumeration and extortion. The campaign is confirmed to be targeting manufacturing, automotive, aerospace, and retail sectors, with the exploitation of CVE-2026-12569 being a key component.

The new article provides specific details on the exploitation chain, noting that attackers are chaining a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet to achieve RCE. It also highlights that the threat actor has been targeting organizations across aerospace, automotive, manufacturing, and retail/apparel sectors since July 20th, sending extortion emails with a specific subject line.

This new reporting provides further details on the Clop group's exploitation of CVE-2026-12569 in PTC's Windchill and FlexPLM software. It highlights the chaining of a pre-authentication information disclosure with a server-side flaw to achieve unauthenticated remote code execution and the deployment of webshells. Additionally, the article notes that ransom notes, mirroring previous Clop campaigns, began appearing around July 20th, with specific email addresses used for contact that are also listed on Clop's darknet data-leak blog.

Synthesized by Vypr AI