THE Clop ransomware gang, also known as Cl0p, is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. They are exploiting a critical vulnerability, CVE-2026-12569, which allows execution of arbitrary code on the affected systems. According to cybersecurity company ReliaQuest, Clop operators are using JSP webshells to steal sensitive data from compromised Product Lifecycle Management (PLM) platforms.
Clop ransomware hits Windchill via CVE-2026-12569 flaw
CyberSIXT Evidence Panel
Primary Source
nvd.nist.gov
CVE Intel
CISA KEV
Listed in KEV
Patch
Patch Status Unknown
Threat Actor
Clop
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Cl0p ransomware exploits PTC Windchill flaw, hits Shell, Philips
securityaffairs.com
-
Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
securityweek.com
-
Cl0p Gang Hits PTC Windchill via CVE-2026-12569 Flaw
securityweek.com
-
Clop ransomware hits Windchill via CVE-2026-12569 flaw
databreaches.net