CL0P Mass-Exploitation of PTC Windchill and FlexPLM via Unauthenticated RCE
The threat actor CL0P is executing a large-scale campaign targeting PTC Windchill and FlexPLM environments by exploiting CVE-2026-12569, a critical unauthenticated Remote Code Execution (RCE) vulnerability. The flaw originates from unsafe Java deserialization, enabling the deployment of a custom JSP web shell designed to map enterprise data vaults for intellectual property theft. A significant force multiplier is the compromise of integrated AI agents, which inherit high-level PLM access permissions to automate mass data exfiltration. Over 40 organizations have been impacted, with CVSS scores reaching 10.0. Immediate remediation requires updating to versions beyond 11.0 M030.
PTC Windchill & FlexPLM: Critical RCE Vulnerability Added to CISA KEV
CISA has added CVE-2026-12569 to its Known Exploited Vulnerabilities (KEV) catalog, targeting PTC Windchill and FlexPLM product lifecycle management (PLM) software. This critical unsafe deserialization vulnerability (CVSS 9.3) allows unauthenticated remote attackers to achieve Remote Code Execution (RCE) via the Windchill PDMLink web component. Threat actors are actively leveraging this flaw to deploy web shells, facilitating persistent access and lateral movement within sensitive engineering and manufacturing environments. Given the concentration of proprietary CAD designs and bills of materials (BOM) within these systems, exploitation poses an extreme risk of industrial espionage and intellectual property theft across the defense, aerospace, and automotive sectors.