CISA says attackers are exploiting PTC Windchill and FlexPLM remote-code-execution flaw CVE-2026-12569

Attackers are actively breaking into organizations that use PTC Windchill and FlexPLM, a product lifecycle management platform used by many industrial companies. The flaw, CVE-2026-12569, is an improper input validation bug that lets a remote unauthenticated attacker run arbitrary code through crafted requests. PTC began releasing patches and mitigations on June 17 and said attackers have used the bug to install persistent JSP web shells for remote command execution and data theft; CISA has added it to the Known Exploited Vulnerabilities catalog.
Why it matters: This is urgent for manufacturers and other firms that rely on Windchill or FlexPLM, because attackers can break in over the network without valid credentials and keep long-term access. Organizations should apply PTC's patches or mitigations immediately, check for the published indicators of compromise, and treat exposed servers as potentially compromised.

Sources

Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
Eduard Kovacs 2026.08.19 97% relevant
This updates the same underlying event by adding post-exploitation and victimology details: the campaign is tied to Cl0p, more than 40 organizations have been named, and ReliaQuest says attackers used web shells and a custom implant to decrypt Windchill keystore credentials, map vault data, and support data theft and follow-on access.
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
info@thehackernews.com (The Hacker News) 2026.08.19 92% relevant
This appears to be a follow-on report about the same PTC Windchill intrusion wave, adding details that a Clop-linked web shell on compromised Windchill servers can decrypt stored credentials and enumerate engineering data, which sharpens defender guidance for incident response after CVE-2026-12569 exploitation.
Clop created custom web shell for Windchill data theft attacks
Lawrence Abrams 2026.08.18 96% relevant
This is a direct update on the same exploitation campaign, adding that the intrusions are likely tied to Clop and documenting a purpose-built JSP web shell for Windchill that uses product-specific APIs to decrypt credentials, enumerate vaults, and steal files via a custom X-windchill-req header protocol.
Philips and GE investigating Clop ransomware data theft claims
Sergiu Gatlan 2026.08.17 95% relevant
This advances the same underlying event by adding named likely victims—Philips, GE, and Shell—and new details that Philips confirmed a contained breach of an internal enterprise server while Clop claims data theft from systems compromised via CVE-2026-12569.
Shell investigates 'potential incident' after Clop data theft claims
Sergiu Gatlan 2026.08.14 93% relevant
This article adds a named victim and alleged impact to the existing CVE-2026-12569 exploitation story: Shell says it is investigating after Clop claimed to steal 89GB including engineering drawings, facility testing reports, photos, and project plans in the same Windchill/FlexPLM campaign.
Clop ransomware targets Windchill, FlexPLM in data theft attacks
Sergiu Gatlan 2026.07.24 97% relevant
This article advances the same underlying event by tying the active exploitation of CVE-2026-12569 specifically to Clop-style data-theft extortion, adding details on JSP webshell deployment, exfiltration from PLM systems, and extortion emails sent from support@cryptohox.com.
CISA sets urgent deadline to fix Cisco flaw exploited in attacks
Bill Toulas 2026.06.26 93% relevant
This updates the same CVE-2026-12569 story with CISA's KEV addition and a June 28 federal remediation deadline for actively exploited PTC Windchill and FlexPLM systems.
CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
info@thehackernews.com (The Hacker News) 2026.06.26 97% relevant
This source updates the same underlying event by adding that CISA placed the PTC Windchill flaw into the Known Exploited Vulnerabilities catalog and that web-shell attacks against exposed systems are ongoing.
First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild
Eduard Kovacs 2026.06.26 100% relevant
This article establishes a new tracked story by reporting the first confirmed in-the-wild exploitation of CVE-2026-12569 in PTC Windchill and FlexPLM, along with CISA KEV listing and PTC's web-shell and data-exfiltration details.
← Back to all stories