Cl0p Ransomware Exploits PTC Windchill Vulnerability, Targeting Multiple Industries
A critical remote code execution (RCE) vulnerability in PTC's product lifecycle management platforms, Windchill and FlexPLM, is being actively exploited by a Cl0p ransomware affiliate. The vulnerability, identified as CVE-2026-12569 with a CVSS score of 9.3, involves the deserialization of untrusted data and can be exploited without authentication. Although PTC patched the vulnerability on June 17, it was quickly exploited in the wild, prompting PTC to release indicators of compromise (IoCs). Recent reports from ReliaQuest and Ransom-ISAC indicate that the Cl0p affiliate is targeting organizations in the aerospace, automotive, manufacturing, and retail/apparel sectors. The attackers have been using a combination of pre-authentication information disclosure and server-side flaws to achieve RCE and deploy webshells. They have also been sending extortion emails to affected organizations, although they have not yet publicly listed victims or claimed credit for the campaign.