Skip to content

Clop Group Exploits CVE-2026-12569 Against PTC Windchill and FlexPLM

In brief: Clop exploits critical deserialization vulnerability (CVSS 9.3) in PLM systems for data theft and extortion, affecting over 30,000 customers, security patches available since June 2026.

The ransomware group Clop is exploiting a critical vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM for unauthenticated remote code execution and data theft. Authorities in the USA and Germany are warning affected organizations of increased attack activity.

The threat group Clop is conducting active attacks against internet-facing instances of PTC Windchill and FlexPLM. The attackers exploit vulnerability CVE-2026-12569, which is based on faulty input validation and insecure deserialization of data. According to ReliaQuest, the vulnerability has a CVSS score of 9.3 and enables unauthenticated attackers to execute remote code (RCE) without prior authentication.

After successfully compromising systems, the attackers deploy JSP web shells on the affected systems to gain persistent access and execute remote commands. Subsequently, they exfiltrate sensitive product data and send extortion letters from email addresses such as support@cryptohox.com. The practice of changing contact addresses before launching new extortion campaigns is an established tactic of the group.

Windchill and FlexPLM are Product Lifecycle Management (PLM) systems used worldwide by over 30,000 customers to manage product data, designs, and manufacturing processes — particularly in aerospace, defense, automotive, heavy industry, and medical technology. The vendor PTC released initial patches beginning June 17, 2026. The US agency CISA added the vulnerability to its catalog of known actively exploited vulnerabilities. The German BSI contacted affected organizations in Germany directly by phone and email to accelerate patching efforts.

Security researchers recommend affected organizations apply available security updates immediately and position systems behind VPN solutions or hardened access gateways. If compromise is suspected, affected servers should be isolated and digital evidence preserved.


Source: www.it-daily.net · Published July 26, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: