CVE-2026-12569
Known exploited · CISA KEV
EPSS 41% (99th percentile).
CISA federal remediation date Jun 28 · date passed
Vulnerabilities & Exploits · Ransomware
The break is the rollout gap, not the patch itself. Cl0p-linked operators moved from a disclosed PLM flaw to live exploitation fast enough that delayed deployment became the exposure window, and patching alone does not erase access already gained.
PTC’s CVE-2026-12569 affects Windchill, FlexPLM, and Windchill PDMLink. It is an unauthenticated deserialization flaw that can lead to remote code execution, and PTC released patches on June 17 before publishing IoCs after exploitation showed up in the wild the next day.
The current campaign has been tied to JSP web shells, file staging, and data theft for extortion across manufacturing, aerospace, automotive, and retail/apparel. For teams running these PLM apps on the network, the threat is no longer theoretical exploitation of a bug; it is a live extortion path that can outlast the patch cycle.
4 sources · Jul 28
Known exploited · CISA KEV
EPSS 41% (99th percentile).
CISA federal remediation date Jun 28 · date passed
FortiGuard Labs Threat Signals
Threat Signal Report | FortiGuard Labs
What is the Attack?A critical unauthenticated remote code execution (RCE) vulnerability affecting PTC Windchill PDMlink and PTC FlexPLM is being ac...
originalSecurityWeek
PTC Windchill Vulnerability Exploited in Ransomware Campaign
The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication.
originalThe Hacker News
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Suspected Cl0p actors chain a FlexPLM WSDL leak with a Windchill flaw for unauthenticated RCE, dropping JSP web shells and stealing product data.
originalPart of the PlainSec briefing for 2026-07-27
Every edition of this story: Windchill Patch Window Became Cl0p's Entry Point