PTC Windchill Vulnerability Exploited in Ransomware Campaign Targeting Multiple Industries
A critical remote code execution vulnerability in PTC's Windchill and FlexPLM platforms, tracked as CVE-2026-12569, has been exploited by a Cl0p ransomware affiliate. This vulnerability, which allows for deserialization of untrusted data without authentication, was patched on June 17, 2026. However, it was quickly exploited in the wild, prompting PTC to release indicators of compromise. The attack has targeted organizations in sectors such as aerospace, automotive, manufacturing, and retail/apparel. The attackers have been using a combination of pre-authentication information disclosure and server-side flaws to achieve remote code execution and deploy webshells. They have also been sending extortion emails to affected organizations, although they have not yet publicly listed victims or claimed credit for the campaign.