PTC Windchill Vulnerability Exploited in Ransomware Campaign Affecting Multiple Industries
A critical remote code execution vulnerability in PTC's Windchill and FlexPLM platforms has been exploited by a Cl0p ransomware affiliate. The vulnerability, tracked as CVE-2026-12569, allows attackers to execute code without authentication due to a deserialization of untrusted data issue. Despite being patched on June 17, the vulnerability was exploited in the wild shortly after, with indicators of compromise published by PTC. The exploitation has targeted organizations in sectors such as aerospace, automotive, manufacturing, and retail/apparel. Attackers have been sending extortion emails to hundreds of users within impacted organizations, threatening data leaks. Organizations are advised to apply patches and conduct threat hunting using published indicators of compromise.