The Clop ransomware gang actively targets Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. The attackers exploit a critical improper input validation vulnerability tracked as CVE-2026-12569, which carries a CVSS score of 9.3 and enables unauthenticated remote code execution on affected systems.
Once inside,