A critical exploit (CVE-2026-21962) affecting Oracle HTTP Server and Weblogic has been leveraged in a new Clop extortion campaign targeting PTC Windchill users. This custom Java web shell allows attackers to decrypt stored credentials and access sensitive data rapidly, exploiting a remote code execution vulnerability rated with a CVSS score of 9.3. PTC released patches on June 17, 2026, yet the web shell can persist if already planted.
Clop's methods indicate a shift back to mass exploitation, threatening enterprise-wide credential compromise. Recommendations include applying patches, searching for suspicious JSP files, and enhancing detection capabilities to mitigate risks.