Clop ransomware exploits critical PTC Windchill FlexPLM flaw CVE-2026-12569 data theft
Companies still running unpatched PTC $PTC Windchill or FlexPLM servers are being actively drained of data. The Clop ransomware gang is exploiting CVE-2026-12569, a critical remote-code-execution flaw, deploying webshells to steal files, per ReliaQuest. Patches have existed since
Companies still running unpatched PTC Windchill or FlexPLM servers are having sensitive product data stolen right now. The Clop ransomware gang, also tracked as Cl0p, is exploiting CVE-2026-12569, a critical unsafe deserialization vulnerability with a CVSS score of 9.3, in PTC's Windchill and FlexPLM product lifecycle management platforms. According to cybersecurity firm ReliaQuest, the flaw allows unauthenticated remote code execution and lets attackers deploy JSP webshells to exfiltrate data from compromised servers. PTC began releasing patches for the vulnerability on June 17, and the Cybersecurity and Infrastructure Security Agency added it to its Known Exploited Vulnerabilities catalog in late June, ordering US federal agencies to secure their systems within three days. Germany's Federal Office for Information Security also called and emailed PTC customers overnight to warn them to patch immediately. Windchill and FlexPLM are used by more than 30,000 customers globally, including firms in aerospace, defense, automotive, heavy machinery, retail and medtech. Clop is now sending extortion emails from a new address, support@cryptohox.com, a pattern the gang has used before launching data-leak campaigns tied to past breaches at MOVEit customers, Harvard, The Washington Post, Logitech and Korean Air. More than five weeks after patches became available, the organizations now losing data are largely those that have not yet applied them, turning a known, fixable vulnerability into an ongoing breach event.