THE Cl0p ransomware group has targeted over 40 organizations using a vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM platforms. The flaw allows remote, unauthenticated code execution, and its exploitation was first reported in June 2026. Cl0p has released the names of various victims, including Shell and Philips, detailing stolen information such as engineering documents and backups, ranging from 1 GB to several terabytes per organization.
Many companies have acknowledged the attacks but have not confirmed significant breaches. This incident marks the first known exploitation of a Windchill vulnerability in the wild.