Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569)
A coordinated Unified Threat Advisory covering active Cl0p ransomware affiliate exploitation of internet-exposed PTC Windchill and FlexPLM deployments — chaining a pre-auth FlexPLM WSDL information disclosure with a Windchill login servlet flaw for unauthenticated RCE, JSP webshell deployment, and double-extortion data theft.
Brandon Parsons
July 22, 2026
+2 contributors