Cybercriminals associated with the Cl0p ransomware group are actively exploiting vulnerabilities in PTC’s Windchill and FlexPLM software to execute unauthorized remote code and deploy web shells. This campaign primarily targets sectors such as manufacturing, automotive, aerospace, and retail.
The attackers utilize a combination of a pre-authentication information disclosure flaw in the FlexPLM WSDL endpoint and a server-side vulnerability in the Windchill login servlet. This exploitation allows them to achieve unauthenticated remote code execution and install JSP web shells within the Windchill login directory.
Once access is gained, the threat actors conduct file system enumeration, stage engineering and design data, and engage in double extortion by stealing sensitive information. The specific vulnerability being exploited is identified as CVE-2026-12569, a critical security flaw in PTC Windchill with a CVSS score of 9.3. This vulnerability was recently added to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities catalog.
PTC has acknowledged reports of increased threat activity and confirmed that unknown attackers are leveraging this vulnerability to deploy JSP web shells on vulnerable systems. The company has provided a list of indicators of compromise (IoCs), including specific IP addresses associated with the attacks:
- 216.152.148.54
- 216.152.151.204
- 104.243.35.63
- 5.180.41.35
Extortion emails from the attackers are being sent from previously compromised accounts to numerous users within affected organizations, providing instructions on how to contact the Cl0p ransomware group.
ReliaQuest has observed active exploitation of CVE-2026-12569, facilitating unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive data exfiltration. While the exact identity of the attackers remains unconfirmed, their methods are consistent with previous Cl0p campaigns targeting enterprise applications and high-value data repositories.
Historically, the Cl0p gang has exploited vulnerabilities in widely-used enterprise products, including file transfer appliances from Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer, as well as vulnerabilities in Oracle E-Business Suite.
This development underscores the critical importance of promptly applying security patches and maintaining robust monitoring of internet-exposed systems. Organizations should prioritize updating their PTC Windchill and FlexPLM deployments to mitigate the risk of exploitation and potential data breaches.