Attackers are actively breaking into organizations that use PTC Windchill and FlexPLM, a product lifecycle management platform used by many industrial companies. The flaw, CVE-2026-12569, is an improper input validation bug that lets a remote unauthenticated attacker run arbitrary code through crafted requests. PTC began releasing patches and mitigations on June 17 and said attackers have used the bug to install persistent JSP web shells for remote command execution and data theft; CISA has added it to the Known Exploited Vulnerabilities catalog.
Eduard Kovacs
2026.08.19
97% relevant
This updates the same underlying event by adding post-exploitation and victimology details: the campaign is tied to Cl0p, more than 40 organizations have been named, and ReliaQuest says attackers used web shells and a custom implant to decrypt Windchill keystore credentials, map vault data, and support data theft and follow-on access.
info@thehackernews.com (The Hacker News)
2026.08.19
92% relevant
This appears to be a follow-on report about the same PTC Windchill intrusion wave, adding details that a Clop-linked web shell on compromised Windchill servers can decrypt stored credentials and enumerate engineering data, which sharpens defender guidance for incident response after CVE-2026-12569 exploitation.
Lawrence Abrams
2026.08.18
96% relevant
This is a direct update on the same exploitation campaign, adding that the intrusions are likely tied to Clop and documenting a purpose-built JSP web shell for Windchill that uses product-specific APIs to decrypt credentials, enumerate vaults, and steal files via a custom X-windchill-req header protocol.
Sergiu Gatlan
2026.08.17
95% relevant
This advances the same underlying event by adding named likely victims—Philips, GE, and Shell—and new details that Philips confirmed a contained breach of an internal enterprise server while Clop claims data theft from systems compromised via CVE-2026-12569.
Sergiu Gatlan
2026.08.14
93% relevant
This article adds a named victim and alleged impact to the existing CVE-2026-12569 exploitation story: Shell says it is investigating after Clop claimed to steal 89GB including engineering drawings, facility testing reports, photos, and project plans in the same Windchill/FlexPLM campaign.
Sergiu Gatlan
2026.07.24
97% relevant
This article advances the same underlying event by tying the active exploitation of CVE-2026-12569 specifically to Clop-style data-theft extortion, adding details on JSP webshell deployment, exfiltration from PLM systems, and extortion emails sent from support@cryptohox.com.
Bill Toulas
2026.06.26
93% relevant
This updates the same CVE-2026-12569 story with CISA's KEV addition and a June 28 federal remediation deadline for actively exploited PTC Windchill and FlexPLM systems.
info@thehackernews.com (The Hacker News)
2026.06.26
97% relevant
This source updates the same underlying event by adding that CISA placed the PTC Windchill flaw into the Known Exploited Vulnerabilities catalog and that web-shell attacks against exposed systems are ongoing.
Eduard Kovacs
2026.06.26
100% relevant
This article establishes a new tracked story by reporting the first confirmed in-the-wild exploitation of CVE-2026-12569 in PTC Windchill and FlexPLM, along with CISA KEV listing and PTC's web-shell and data-exfiltration details.