Attackers are actively breaking into organizations that use PTC Windchill and FlexPLM, a product lifecycle management platform used by many industrial companies. The flaw, CVE-2026-12569, is an improper input validation bug that lets a remote unauthenticated attacker run arbitrary code through crafted requests. PTC began releasing patches and mitigations on June 17 and said attackers have used the bug to install persistent JSP web shells for remote command execution and data theft; CISA has added it to the Known Exploited Vulnerabilities catalog.
Why it matters: This is urgent for manufacturers and other firms that rely on Windchill or FlexPLM, because attackers can break in over the network without valid credentials and keep long-term access. Organizations should apply PTC's patches or mitigations immediately, check for the published indicators of compromise, and treat exposed servers as potentially compromised.
Sergiu Gatlan
2026.07.24
97% relevant
This article advances the same underlying event by tying the active exploitation of CVE-2026-12569 specifically to Clop-style data-theft extortion, adding details on JSP webshell deployment, exfiltration from PLM systems, and extortion emails sent from support@cryptohox.com.
Bill Toulas
2026.06.26
93% relevant
This updates the same CVE-2026-12569 story with CISA's KEV addition and a June 28 federal remediation deadline for actively exploited PTC Windchill and FlexPLM systems.
info@thehackernews.com (The Hacker News)
2026.06.26
97% relevant
This source updates the same underlying event by adding that CISA placed the PTC Windchill flaw into the Known Exploited Vulnerabilities catalog and that web-shell attacks against exposed systems are ongoing.
Eduard Kovacs
2026.06.26
100% relevant
This article establishes a new tracked story by reporting the first confirmed in-the-wild exploitation of CVE-2026-12569 in PTC Windchill and FlexPLM, along with CISA KEV listing and PTC's web-shell and data-exfiltration details.
← Back to all stories