Clop Ransomware Gang Exploits Critical Flaw in PTC Windchill and FlexPLM Platforms

The Clop ransomware gang actively targets Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. The attackers exploit a critical improper input validation vulnerability tracked as CVE-2026-12569, which carries a CVSS score of 9.3 and enables unauthenticated remote code execution on affected systems.

Once inside, Clop operators deploy JSP web shells that grant them persistent remote access to compromised PLM platforms. According to cybersecurity firm ReliaQuest, the threat actors use this access to exfiltrate sensitive product data from targeted companies. The observed tradecraft closely matches previous Cl0p campaigns that focused on enterprise applications and high-value data repositories.

Clop delivers its extortion messages through previously compromised email accounts, sending them to hundreds of employees within impacted organizations. The emails include the gang's latest contact information and follow the same pattern seen in last year's Oracle EBS campaign. PTC began releasing security patches for the vulnerability on June 17 and urges customers to review their environments and apply remediation steps immediately.

Read More at the original source →