Clop Ransomware Gang Exploits Critical PTC Windchill & FlexPLM Vulnerability in New Extortion Campaign
The Clop ransomware gang (also tracked as Cl0p) is actively exploiting a critical improper input validation vulnerability (CVE-2026-12569, CVSS 9.3) in PTC Windchill and FlexPLM instances exposed to the internet. The flaw, a remote code execution (RCE) vulnerability, allows unauthenticated attackers to deploy JSP webshells, enabling data exfiltration from compromised Product Lifecycle Management (PLM) platforms.
Cybersecurity firm ReliaQuest reported the attacks on Thursday, noting that the observed tactics align with Clop’s previous campaigns targeting high-value enterprise applications. While the threat actor remains unconfirmed, victims have begun receiving extortion emails from support@cryptohox.com, a newly adopted address by the gang, which frequently rotates contact details between campaigns.
PTC released security patches for CVE-2026-12569 on June 17, issuing private advisories urging customers to apply fixes and check for indicators of compromise (IOCs). Following reports of "heightened threat activity" on June 26, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to secure affected systems within three days. German authorities, including the Federal Office for Information Security (BSI), took emergency measures, directly contacting PTC customers to expedite patching.
Windchill and FlexPLM are widely used PLM platforms in aerospace, defense, automotive, and medtech sectors, with PTC reporting over 30,000 global customers. Clop’s history includes high-profile data theft campaigns targeting Accellion FTA, GoAnywhere MFT, MOVEit Transfer, and most recently, an Oracle EBS zero-day flaw in August 2025, which impacted organizations like Harvard University, The Washington Post, and Korean Air. The gang typically publishes stolen data on its dark web leak site if ransom demands are unmet.
The U.S. Department of State has offered a $10 million reward for information linking Clop’s operations to a foreign government.
PTC cybersecurity rating report: https://www.rankiteo.com/company/ptc
Washington University in St. Louis cybersecurity rating report: https://www.rankiteo.com/company/washington-university-in-st-louis
"id": "PTCWAS1784881471",
"linkid": "ptc, washington-university-in-st-louis",
"type": "Vulnerability",
"date": "6/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': ['Aerospace',
'Defense',
'Automotive',
'Medtech'],
'location': 'Global',
'name': 'PTC Customers',
'type': 'Organizations'},
{'industry': 'Education',
'location': 'United States',
'name': 'Harvard University',
'type': 'Educational Institution'},
{'industry': 'Media',
'location': 'United States',
'name': 'The Washington Post',
'type': 'Media Organization'},
{'industry': 'Aviation',
'location': 'South Korea',
'name': 'Korean Air',
'type': 'Airline'}],
'attack_vector': 'Remote Code Execution (RCE)',
'data_breach': {'data_exfiltration': True,
'sensitivity_of_data': 'High (enterprise-sensitive)',
'type_of_data_compromised': 'Product Lifecycle Management '
'(PLM) data'},
'date_publicly_disclosed': '2024-06-27',
'description': 'The Clop ransomware gang (also tracked as Cl0p) is actively '
'exploiting a critical improper input validation vulnerability '
'(CVE-2026-12569, CVSS 9.3) in PTC Windchill and FlexPLM '
'instances exposed to the internet. The flaw, a remote code '
'execution (RCE) vulnerability, allows unauthenticated '
'attackers to deploy JSP webshells, enabling data exfiltration '
'from compromised Product Lifecycle Management (PLM) '
'platforms.',
'impact': {'data_compromised': 'Product Lifecycle Management (PLM) data',
'systems_affected': 'PTC Windchill and FlexPLM instances'},
'initial_access_broker': {'backdoors_established': 'JSP webshells',
'entry_point': 'Exposed PTC Windchill and FlexPLM '
'instances'},
'investigation_status': 'Ongoing',
'motivation': 'Extortion',
'post_incident_analysis': {'corrective_actions': 'Patch management, system '
'hardening, and monitoring '
'for IOCs',
'root_causes': 'Unpatched critical vulnerability '
'(CVE-2026-12569) in exposed PLM '
'systems'},
'ransomware': {'data_exfiltration': True, 'ransomware_strain': 'Clop'},
'recommendations': 'Apply PTC security patches immediately, check for '
'indicators of compromise (IOCs), and secure exposed '
'Windchill/FlexPLM instances.',
'references': [{'source': 'ReliaQuest'},
{'source': 'PTC Security Advisory'},
{'source': 'CISA Known Exploited Vulnerabilities Catalog'},
{'source': 'U.S. Department of State'}],
'regulatory_compliance': {'regulatory_notifications': ['CISA Known Exploited '
'Vulnerabilities '
'Catalog',
'BSI (German Federal '
'Office for '
'Information '
'Security)']},
'response': {'communication_strategy': 'Private advisories to customers, '
'public disclosures by CISA and BSI',
'remediation_measures': 'Security patches released by PTC on '
'June 17, 2024',
'third_party_assistance': 'ReliaQuest'},
'stakeholder_advisories': 'PTC private advisories, CISA and BSI public alerts',
'threat_actor': 'Clop Ransomware Gang (Cl0p)',
'title': 'Clop Ransomware Gang Exploits Critical PTC Windchill & FlexPLM '
'Vulnerability in New Extortion Campaign',
'type': 'Ransomware',
'vulnerability_exploited': 'CVE-2026-12569 (Improper Input Validation, CVSS '
'9.3)'}