securityonline.info 8/25/2026, 9:06:11 AM · external

Clop uses Oracle CVE-2026-21962 to hit PTC Windchill credentials

Clop uses Oracle CVE-2026-21962 to hit PTC Windchill credentials
Developing story vulnerability 6 articles tracked
CISA adds exploited Oracle HTTP Server flaw CVE-2026-21962 to KEV catalog
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor
Clop

A critical exploit (CVE-2026-21962) affecting Oracle HTTP Server and Weblogic has been leveraged in a new Clop extortion campaign targeting PTC Windchill users. This custom Java web shell allows attackers to decrypt stored credentials and access sensitive data rapidly, exploiting a remote code execution vulnerability rated with a CVSS score of 9.3. PTC released patches on June 17, 2026, yet the web shell can persist if already planted.

Clop's methods indicate a shift back to mass exploitation, threatening enterprise-wide credential compromise. Recommendations include applying patches, searching for suspicious JSP files, and enhancing detection capabilities to mitigate risks.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline