CL 0p ransomware affiliates are exploiting a critical RCE vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM platforms, with a CVSS score of 9.3. This vulnerability allows for unauthenticated exploitation and was patched on June 17. ReliaQuest and Ransom-ISAC warn that attackers are using advanced techniques, including chaining a pre-authentication information disclosure with a server-side flaw, leading to RCE and deployment of JSP webshells.
Targeted sectors include aerospace, automotive, manufacturing, and retail/apparel. Cl0p has begun sending extortion emails to organizations, leveraging this vulnerability for data exfiltration and ransom demands. Organizations are urged to apply patches and follow PTC's remediation steps.