CVE-2026-12569
Sfruttamento noto · CISA KEV
EPSS 46% (99º percentile).
Data di correzione federale CISA 28 giu · data superata
Vulnerabilità ed exploit · Ransomware
La falla non è solo un RCE in un PLM esposto: per chi gestisce Windchill, FlexPLM e PDMLink, il problema è che una correzione arrivata il 17 giugno non ha chiuso subito la finestra di rischio. Quando un exploit viene armato entro 24 ore dalla patch, la velocità di rilascio decide chi resta esposto.
PTC ha corretto CVE-2026-12569, una deserialization senza autenticazione, e ha pubblicato gli IoC il giorno dopo. Le segnalazioni più recenti confermano sfruttamento in the wild da parte di un affiliato Cl0p contro ambienti in settori come manufacturing, aerospace, automotive e retail/apparel, con web shell JSP, staging dei file ed esfiltrazione per estorsione.
Il punto non è la sola patch. Se l’app PLM è raggiungibile dalla rete, va trattata come una superficie già usata per l’accesso iniziale, non come un bug appena chiuso.
4 fonti · 28 lug
Sfruttamento noto · CISA KEV
EPSS 46% (99º percentile).
Data di correzione federale CISA 28 giu · data superata
FortiGuard Labs Threat Signals
Threat Signal Report | FortiGuard Labs
What is the Attack?A critical unauthenticated remote code execution (RCE) vulnerability affecting PTC Windchill PDMlink and PTC FlexPLM is being ac...
originaleSecurityWeek
PTC Windchill Vulnerability Exploited in Ransomware Campaign
The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication.
originaleThe Hacker News
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Suspected Cl0p actors chain a FlexPLM WSDL leak with a Windchill flaw for unauthenticated RCE, dropping JSP web shells and stealing product data.
originalePart of the PlainSec briefing for 2026-07-27
Every edition of this story: PTC Windchill è già un punto d’ingresso per Cl0p