CVE-2026-12569
Sfruttamento noto · CISA KEV
EPSS 46% (99º percentile).
Data di correzione federale CISA 28 giu · data superata
Vulnerabilità · 62 giorni fa
La falla non è solo un RCE in un PLM esposto: per chi gestisce Windchill, FlexPLM e PDMLink, il problema è che una correzione arrivata il 17 giugno non ha chiuso subito la finestra di rischio. Quando un exploit viene armato entro 24 ore dalla patch, la velocità di rilascio decide chi resta esposto.
PTC ha corretto CVE-2026-12569, una deserialization senza autenticazione, e ha pubblicato gli IoC il giorno dopo. Le segnalazioni più recenti confermano sfruttamento in the wild da parte di un affiliato Cl0p contro ambienti in settori come manufacturing, aerospace, automotive e retail/apparel, con web shell JSP, staging dei file ed esfiltrazione per estorsione.
Il punto non è la sola patch. Se l’app PLM è raggiungibile dalla rete, va trattata come una superficie già usata per l’accesso iniziale, non come un bug appena chiuso.
Sfruttamento noto · CISA KEV
EPSS 46% (99º percentile).
Data di correzione federale CISA 28 giu · data superata
4 fonti che coprono questa storia
FortiGuard Labs Threat Signals
Threat Signal Report | FortiGuard Labs
What is the Attack?A critical unauthenticated remote code execution (RCE) vulnerability affecting PTC Windchill PDMlink and PTC FlexPLM is being ac...
PTC Windchill Vulnerability Exploited in Ransomware Campaign
The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication.
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Suspected Cl0p actors chain a FlexPLM WSDL leak with a Windchill flaw for unauthenticated RCE, dropping JSP web shells and stealing product data.
Clop ransomware targets Windchill, FlexPLM in data theft attacks
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign.
Part of the PlainSec briefing for 2026-07-28