www.securityweek.com 7/27/2026, 1:31:27 PM · external

Cl0p Gang Hits PTC Windchill via CVE-2026-12569 Flaw

Cl0p Gang Hits PTC Windchill via CVE-2026-12569 Flaw
Developing story vulnerability 12 articles tracked
Cisco Unified CM SSRF/RCE flaw (CVE-2026-20230) exploited in the wild
CyberSIXT Evidence Panel
Primary Source ptc.com
CISA KEV Listed in KEV
Patch Patch Status Unknown
Threat Actor
Cl0p

CL 0p ransomware affiliates are exploiting a critical RCE vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM platforms, with a CVSS score of 9.3. This vulnerability allows for unauthenticated exploitation and was patched on June 17. ReliaQuest and Ransom-ISAC warn that attackers are using advanced techniques, including chaining a pre-authentication information disclosure with a server-side flaw, leading to RCE and deployment of JSP webshells.

Targeted sectors include aerospace, automotive, manufacturing, and retail/apparel. Cl0p has begun sending extortion emails to organizations, leveraging this vulnerability for data exfiltration and ransom demands. Organizations are urged to apply patches and follow PTC's remediation steps.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline