databreaches.net 7/24/2026, 12:51:21 PM · external

Clop ransomware hits Windchill via CVE-2026-12569 flaw

Developing story vulnerability 12 articles tracked
Cisco Unified CM SSRF/RCE flaw (CVE-2026-20230) exploited in the wild
CyberSIXT Evidence Panel
Primary Source nvd.nist.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown
Threat Actor
Clop

THE Clop ransomware gang, also known as Cl0p, is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. They are exploiting a critical vulnerability, CVE-2026-12569, which allows execution of arbitrary code on the affected systems. According to cybersecurity company ReliaQuest, Clop operators are using JSP webshells to steal sensitive data from compromised Product Lifecycle Management (PLM) platforms.

View Primary Source Via databreaches.net

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline