PTC Windchill Vulnerability Exploited in Ransomware Campaign

A Cl0p Ransomware Affiliate Exploits Critical PTC Windchill Vulnerability, Targeting Multiple Industries

A critical remote code execution (RCE) vulnerability in PTC’s product lifecycle management (PLM) platforms Windchill and FlexPLM has been exploited by a Cl0p ransomware affiliate. The bug, tracked as CVE-2026-12569 with a CVSS score of 9.3, allows attackers to execute code on vulnerable systems without authentication.

The vulnerability was patched by PTC on June 17, but it was flagged as exploited in the wild just a day later. Indicators of compromise (IoCs) were published by PTC, and the bug was added to CISA’s KEV catalog at the end of June. Despite this, a Cl0p affiliate has been observed exploiting the vulnerability to deploy ransomware, targeting organizations across multiple industries.

The attackers have been chaining a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet to achieve RCE and deploy JSP webshells. Once initial access is gained, the hackers enumerate filesystems, stage data, and exfiltrate data for extortion.

The ransomware campaign started on July 20, targeting organizations in the aerospace, automotive, manufacturing, and retail/apparel sectors. Extortion emails with a subject line “Windchill PDMLink module serious data leak” have been sent to hundreds of users within impacted organizations. However, Cl0p has not yet listed victims of this campaign on their dark web data leak site or publicly claimed credit.

Organizations affected by the vulnerability are advised to apply PTC’s patches and use previously published IoCs to conduct threat hunting. They should also follow PTC’s remediation steps to secure their systems. This serves as a stark reminder that even after patches are released, attackers can still exploit vulnerabilities if they move quickly enough.

The ease with which this vulnerability has been exploited highlights the ongoing cat-and-mouse game between attackers and defenders. As we’ve seen time and again, patched vulnerabilities can be weaponized by sophisticated threat actors. To mitigate this risk, organizations must prioritize timely patching, robust security monitoring, and regular threat hunting exercises to stay ahead of potential threats.

In practical terms, all users with PTC Windchill or FlexPLM systems should immediately review their system configurations and apply the available patches to prevent exploitation. Regular backups and a solid incident response plan can also help minimize the impact of such attacks. By taking proactive steps to secure their systems, organizations can reduce the likelihood of falling victim to these types of attacks.


Source: SecurityWeek — 2026-07-27