Cl0p Ransomware Group Exploits Unauthenticated RCE in PTC Windchill and FlexPLM
Threat actors linked to the Cl0p ransomware campaign are exploiting unauthenticated remote code execution (RCE) vulnerabilities in internet-exposed PTC Windchill and FlexPLM systems to conduct data extortion. The attack leverages CVE-2026-12569, a critical vulnerability, and targets sectors including manufacturing, automotive, and aerospace.
Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign.
"Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling
*** END OF TRANSMISSION ***