Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2033+ Articles
153+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Clop Ransomware Targets PTC Windchill and FlexPLM in Mass Data Theft Campaign
Clop Ransomware Targets PTC Windchill and FlexPLM in Mass Data Theft Campaign
NEWS

Clop Ransomware Targets PTC Windchill and FlexPLM in Mass Data Theft Campaign

The Clop ransomware gang is exploiting CVE-2026-12569, a critical unauthenticated RCE flaw (CVSS 9.8) in PTC Windchill and FlexPLM, deploying webshells to exfiltrate sensitive product data from aerospace, automotive, and manufacturing organizations.

Dylan H.

News Desk

July 24, 2026
4 min read

The Clop ransomware gang (also tracked as Cl0p) has launched a new mass exploitation campaign targeting PTC Windchill PDMLink and FlexPLM installations exposed to the internet, leveraging a critical unauthenticated remote code execution vulnerability to steal sensitive product data and threaten extortion.

The Vulnerability: CVE-2026-12569

At the center of the campaign is CVE-2026-12569, a critical unsafe deserialization flaw affecting both Windchill PDMLink and FlexPLM. The vulnerability carries a CVSS v3.1 score of 9.8 (Critical) and PTC's own CVSS v4.0 assessment of 9.3 Critical.

The flaw requires no authentication and no user interaction — an attacker can send a crafted request to an exposed instance and achieve full remote code execution immediately. It is classified under CWE-502 (Deserialization of Untrusted Data) and CWE-20 (Improper Input Validation).

Affected versions include:

  • Windchill PDMLink: 11.1 M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0–13.1.3.0
  • FlexPLM: 11.1 M020, 11.2.1.0, 12.0.0.0–12.0.2.0, 12.1.2.0–12.1.3.0, 13.0.2.0–13.0.3.0

How Clop is Exploiting It

Clop operators are deploying JSP webshells on internet-facing PTC instances to gain persistent remote command execution, then pivoting to exfiltrate sensitive business and product data. The attack chain requires no credentials — once a system is identified via Shodan or similar reconnaissance, exploitation is straightforward.

Approximately 104 internet-exposed Windchill instances have been identified via Shodan, concentrated heavily in the United States (98 instances), with additional exposure in Australia, France, South Korea, the Netherlands, Portugal, and Slovakia. A significant share are hosted on Amazon Web Services infrastructure.

PTC's total customer base spans more than 30,000 organizations globally, and FlexPLM alone serves over 1,500 brand and retail customers in apparel and footwear.

Targeted Industries

The industries in Clop's crosshairs reflect the PLM user base:

  • Aerospace and defense
  • Automotive
  • Heavy machinery and industrial manufacturing
  • Retail and fashion (FlexPLM is the dominant platform for apparel/footwear PLM)
  • Medical devices and medtech

In the context of product lifecycle management platforms, "sensitive product data" means engineering designs, product blueprints, bills of materials, intellectual property, and supply chain configuration data — exactly the category of information that commands serious extortion leverage.

Clop's Extortion Playbook

Clop does not deploy ransomware encryption in these campaigns — this is pure data theft extortion. The gang uses previously compromised email accounts to contact hundreds of employees within each targeted organization, providing contact information and demanding payment.

Victims who don't pay have their data published on Clop's dark web leak site and made available for download via Torrent. This is the same methodology Clop used in their Oracle EBS campaign, which claimed victims including Harvard University, The Washington Post, GlobalLogic, and Korean Air.

Timeline

DateEvent
June 17, 2026PTC begins releasing security patches
June 26, 2026PTC warns customers of "heightened threat activity"
June 28, 2026CISA BOD 26-04 deadline for federal agencies
July 24, 2026Active exploitation confirmed by ReliaQuest and Ransom-ISAC

Government Response

CISA added CVE-2026-12569 to the Known Exploited Vulnerabilities (KEV) catalog and ordered federal agencies to secure affected systems within three days under BOD 26-04. Germany's BSI conducted emergency outreach to affected organizations via email and phone.

What Organizations Should Do

If your organization runs Windchill PDMLink or FlexPLM:

  1. Apply PTC patches immediately — reference support article CS473270 for patch and mitigation instructions
  2. Remove direct internet exposure — place instances behind a VPN or trusted access gateway
  3. Isolate affected servers immediately if compromise is suspected
  4. Rotate all exposed credentials before restoring service
  5. Hunt for JSP webshells on affected systems — check web directories for suspicious .jsp files with unusual names or timestamps

Clop's Pattern

Clop has now run this playbook across a remarkable list of enterprise file transfer and business application vulnerabilities: Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U, Cleo, MOVEit Transfer (2,770+ organizations), Oracle EBS, and now PTC PLM. The pattern is consistent — find a critical unauthenticated RCE in a widely deployed enterprise platform, mass-exploit before patches are applied, steal data, and threaten publication.

The window between patch release (June 17) and confirmed active exploitation (July 24) is roughly five weeks — more than enough time to patch, but clearly insufficient for a significant portion of exposed organizations. If your PLM instance is internet-facing and unpatched, treat it as already compromised pending forensic review.


Sources: BleepingComputer, CISA KEV Catalog, ReliaQuest, Ransom-ISAC

#ransomware#clop#vulnerability#CVE-2026-12569#supply chain#manufacturing

Related Articles

ChatGPT 'AgentForger' Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

Zenity Labs disclosed a critical cross-site agent forgery vulnerability in ChatGPT's Workspace Agent Builder that let a single phishing link silently create an autonomous AI agent inside a victim's organization — inheriting their identity, connectors, and permissions.

5 min read

Chick-fil-A Data Breach Affects More Than 13,000 Customers

Credential stuffing attacks hit Chick-fil-A One loyalty accounts in June 2026, exposing names, stored credit balances, mobile pay QR codes, and partial card data for over 13,000 customers.

4 min read

Kimi K3 AI Agents Discovered Redis Zero-Days and Built RCE Exploits in Under 90 Minutes

Autonomous AI agents powered by Moonshot AI's Kimi K3 model found 19 Redis zero-day vulnerabilities and produced working authenticated RCE proof-of-concept exploits in roughly 90 minutes, prompting Redis to ship seven security releases on July 23, 2026.

4 min read
Back to all News