9.8
CVSS score for CVE-2026-12569 -- Critical unauthenticated RCE in PTC Windchill and FlexPLM, no credentials required
56 days
Cl0p operated silently inside Windchill systems from early June before sending extortion emails on July 20
4 sectors
confirmed under active Cl0p targeting: manufacturing, automotive, aerospace, and retail/apparel
3 days
remediation deadline CISA gave U.S. federal agencies after adding CVE-2026-12569 to the KEV catalog on June 25

SponsoredHorizon3.ai

Proactive Security for the AI Era

NodeZero continuously and autonomously pentests infrastructure, identity, cloud, and now web applications, chaining weaknesses across every domain the way real attackers do. Every finding ships with replayable proof showing exploitable business impact, not theoretical risk.

See NodeZero WebApp in action

Cl0p ransomware affiliates have stolen engineering blueprints, product designs, and manufacturing specifications from organizations across manufacturing, automotive, aerospace, and retail since early June 2026 -- exploiting CVE-2026-12569, a CVSS 9.8 unauthenticated remote code execution flaw in PTC Windchill and FlexPLM that CISA added to its Known Exploited Vulnerabilities catalog on June 25.

CVE-2026-12569 is an improper input validation vulnerability in PTC Windchill and FlexPLM, the product lifecycle management (PLM) platforms used by manufacturers to store engineering designs, CAD models, component specifications, and production workflows. The flaw allows an unauthenticated attacker to chain a pre-authentication information disclosure in FlexPLM's WSDL endpoint with a server-side deserialization weakness in the Windchill login servlet, achieving unauthenticated remote code execution without any credentials. PTC published patches via advisory CS473270 on June 18, 2026. CISA added CVE-2026-12569 to its KEV catalog on June 25 and directed U.S. federal agencies to remediate within three days under Binding Operational Directive 26-04.

Cl0p operators did not wait for patching. Threat intelligence from ReliaQuest and Ransom-ISAC confirmed that Cl0p -- also tracked as Lace Tempest, FIN11, Graceful Spider, and Chubby Scorpius -- exploited CVE-2026-12569 as a zero-day in early June 2026, weeks before PTC published its advisory. Attackers deployed hex-named JSP webshells to the /Windchill/login/ directory, used a filesystem enumeration utility to inventory and stage engineering data, then exfiltrated the data over weeks before activating the extortion phase on July 20, 2026 with mass emails reading "Windchill PDMLink module serious data leak." Any organization running an unpatched internet-facing Windchill or FlexPLM instance that has not verified for webshell presence should treat their PLM environment as compromised and initiate incident response now.

How Does Cl0p Exploit CVE-2026-12569 in Windchill and FlexPLM?

CVE-2026-12569 enables unauthenticated remote code execution by chaining two distinct weaknesses in the PTC Windchill and FlexPLM architecture: a pre-authentication information disclosure and a deserialization flaw in the login servlet.

The first step targets FlexPLM's WSDL (Web Services Description Language) endpoint. This endpoint is reachable without authentication and returns service configuration details including system path information, internal API structure, and deployment metadata. Cl0p operators use this disclosure to map the target environment and craft the correct payload for the second step.

The second step targets the Windchill login servlet. The servlet processes user-supplied input during authentication and passes certain parameters into a deserialization operation without proper validation. Cl0p sends a crafted HTTP POST containing a serialized Java object payload that, when deserialized, triggers code execution in the context of the Windchill application server. The exploit requires no credentials -- the login servlet processes the malicious payload before any authentication check occurs.

Post-exploitation follows a consistent pattern documented by Ransom-ISAC. Cl0p deploys a JSP webshell to /Windchill/login/ using a randomized hex-format filename (for example, 3f7b2d4e9a1c.jsp), which provides persistent command execution on the compromised server. Attackers then deploy flst.txt, a filesystem enumeration utility, to catalog engineering data: CAD files, design specifications, manufacturing process documentation, regulatory submissions, and product roadmaps. Data is staged locally before exfiltration over HTTPS to Cl0p-controlled infrastructure.

From a MITRE ATT&CK perspective, the campaign maps to T1190 (Exploit Public-Facing Application) for initial access, T1505.003 (Server Software Component: Web Shell) for persistence, T1083 (File and Directory Discovery) for enumeration, and T1537 (Transfer Data to Cloud Account) for exfiltration. See the Cl0p summary in the Monday threat roundup for additional context on concurrent campaigns.

1

Reconnaissance and Target Identification

Cl0p scans for internet-exposed PTC Windchill and FlexPLM instances using passive scanning and Shodan queries for Windchill login pages and FlexPLM WSDL endpoint responses.

2

Pre-Authentication WSDL Enumeration

Attacker queries the FlexPLM WSDL endpoint without credentials, extracting system path configuration and internal API structure needed to craft the exploitation payload.

3

Deserialization Exploit via Windchill Login Servlet

Attacker sends a crafted HTTP POST to the Windchill login servlet containing a serialized Java object payload. Improper input validation triggers code execution with application-server privileges before any authentication check occurs.

4

JSP Webshell Deployment to /Windchill/login/

Attacker writes a hex-named JSP webshell to /Windchill/login/ providing persistent command execution. Randomized filenames evade signature-based detection tuned to known webshell names.

5

Filesystem Enumeration and Data Staging

Attacker deploys flst.txt to inventory the PLM system -- identifying CAD files, design specifications, manufacturing process documentation, regulatory submissions, and product roadmaps for exfiltration staging.

6

Exfiltration and Double Extortion Activation

Engineering data is exfiltrated over HTTPS to Cl0p-controlled infrastructure. On July 20, Cl0p launched the extortion phase: mass emails with subject 'Windchill PDMLink module serious data leak' sent to hundreds of employees per compromised organization, directing victims to support@cryptohox.com.

Active Targeting Evidence: Manufacturing, Automotive, and Aerospace Confirmed

Cl0p has confirmed victims across four sectors where PTC Windchill and FlexPLM are widely deployed: manufacturing, automotive, aerospace, and retail/apparel. All four sectors rely on Windchill or FlexPLM as core PLM infrastructure -- Windchill is deployed in over 300 Global 2000 industrial manufacturers, and FlexPLM is the dominant PLM platform in apparel, footwear, and consumer products.

Active targeting in manufacturing focuses on discrete manufacturing firms running Windchill to manage complex assembly bill-of-materials data, production engineering workflows, and supplier integration portals. The engineering data stored in these deployments includes proprietary process specifications and competitive product designs -- intellectual property with high value to competitors and nation-state actors who may purchase stolen data from Cl0p's leak infrastructure.

Automotive sector targeting concentrates on Tier 1 and Tier 2 suppliers using Windchill to manage electronic control unit specifications, powertrain designs, and platform-sharing agreements across original equipment manufacturers. The exfiltration of powertrain design data or chassis specifications from a single Tier 1 supplier can expose proprietary data for models across multiple vehicle brands.

Aerospace targeting involves organizations using Windchill for DO-178C and AS9100D-compliant quality management and design documentation workflows. Regulatory documentation stored in Windchill -- including certification records, test procedures, and supplier qualification data -- is particularly sensitive and creates compliance exposure if leaked.

The extortion campaign beginning July 20 used previously compromised internal email accounts to send mass messages to hundreds of employees within each targeted organization. This approach bypasses spam filtering because the sender domain is trusted, and it maximizes internal visibility of the breach -- a technique Cl0p refined during the MOVEit campaign and has now adapted to PLM-specific targeting. Any organization that has received the "Windchill PDMLink module serious data leak" extortion email should treat its Windchill deployment as compromised regardless of patching status.

Free daily briefing

Briefings like this, every morning before 9am.

Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.

Cl0p's Double Extortion Playbook: Engineering IP as the Lever

Cl0p is the ransomware group most associated with mass-exploitation campaigns against enterprise file transfer and PLM infrastructure. The group executed the MOVEit Transfer campaign in 2023 using the same data-theft-first, no-encryption model now deployed against Windchill.

Cl0p's double extortion model operates without file encryption. The group exfiltrates data, then demands ransom for the promise of deletion and silence. This approach is particularly effective against manufacturing targets because the value of stolen PLM data to competitors and nation-state actors is often higher than what Cl0p charges for deletion -- creating a payment incentive even for organizations whose security posture would otherwise resist extortion.

The extortion email currently in circulation uses the subject line "Windchill PDMLink module serious data leak" and directs victims to support@cryptohox.com. Ransom demands are calibrated per victim based on organization size and apparent value of the exfiltrated data, consistent with Cl0p's previous campaigns. Security researchers documented multiple cases from the MOVEit campaign where Cl0p leaked data from organizations that paid.

The July 20 extortion escalation followed approximately 56 days of silent access. This dwell time -- from early June exploitation through mid-July data staging -- is characteristic of Cl0p campaigns. The group prioritizes comprehensive data collection over speed, maximizing extortion leverage by ensuring they have the most sensitive data before making contact. For organizations that ran unpatched Windchill during June and July, the realistic assumption is that Cl0p has already copied everything of value from the platform. Related context on how ransomware groups leverage similar TTPs is in our Qilin ransomware campaign deep dive.

Cl0p's PLM targeting is a calculated bet: engineering IP is worth more to competitors than any ransom demand, which means victims face extortion pressure from two directions simultaneously.

ReliaQuest threat research, July 2026

Confirmed Indicators of Compromise for the CVE-2026-12569 Campaign

The following indicators are confirmed by Ransom-ISAC, ReliaQuest, and The Hacker News reporting on the CVE-2026-12569 campaign. Add these to SIEM blocklists and network detection rules immediately. The four IP addresses are Cl0p-controlled infrastructure confirmed in this campaign; they supplement earlier IOCs from late June and early July collected during the initial exploitation wave.

Check for hex-named JSP webshells in /Windchill/login/ before blocking IPs at the perimeter -- if Cl0p webshells are already deployed, blocking C2 IPs will not remove them or stop local data staging from continuing. Run a file integrity scan on the Windchill installation directory first. Any JSP file with a randomized alphanumeric hex-format filename that does not appear in the original Windchill installation manifest is a confirmed indicator of compromise. The presence of flst.txt in any web-accessible or temporary directory confirms active Cl0p post-exploitation activity.

Subscribe to unlock Indicators of Compromise

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Sigma Detection Rules for Cl0p Windchill Webshell Activity

No CVE-2026-12569-specific Sigma detection rule exists in the SigmaHQ library as of July 29, 2026 -- expected for a vulnerability with active exploitation beginning less than 60 days ago. The two rules below target the webshell behavior Cl0p deploys post-exploitation: JSP webshell command execution and Java file upload patterns. Both rules were authored for SAP NetViewer (CVE-2025-31324) and directly apply to Windchill because both products run Java servlet containers with identical file-upload and command-execution attack surfaces.

Deploy both rules against web server access logs (IIS, Apache, Nginx, or Windchill's native servlet log). The first detects webshell command execution patterns (cmd=, exec=, whoami, /etc/passwd) in JSP URI parameters. The second detects the initial webshell write via POST with Content-Type application/octet-stream.

Priority log sources: Windchill application access logs, web server access logs, and Windows Sysmon event ID 11 (FileCreate) for Windows-hosted deployments. Alert on any POST request to the Windchill login servlet from external IPs that does not originate from known integration partners -- any such request warrants immediate investigation.

Subscribe to unlock Sigma Detection Rules

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Subscribe to unlock WAF Detection Rules

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Apply PTC Advisory CS473270 Before Cl0p Stages Your Data for Leak

CVE-2026-12569 has a patch. PTC published advisory CS473270 on June 18, 2026, and released patches for all affected Windchill and FlexPLM versions simultaneously. CISA added the vulnerability to the KEV catalog on June 25 with a three-day remediation deadline for U.S. federal agencies. Any organization running an unpatched instance as of today is exposed to a vulnerability with confirmed active exploitation, a CVSS score of 9.8, and a threat actor that has been actively targeting this attack surface for eight weeks.

Affected versions requiring patching are all Windchill and FlexPLM releases prior to: 11.0 M030, 11.1 M020, 11.2.1, 12.0.2, 12.1.2, 13.0.2, and 13.1.1. All Creo Parametric Server (CPS) versions are also affected. Organizations with active PTC maintenance agreements can download patches through the PTC Support portal via the advisory link.

Patching stops new exploitation but does not remove webshells already deployed during the June-July window. Treat patching and incident response as parallel tracks, not sequential. If your Windchill deployment was internet-exposed and unpatched during June or July, assume compromise and conduct a full forensic investigation alongside patching.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Why Cl0p Targeting PLM Systems Matters for Your Organization

PLM platforms like Windchill and FlexPLM contain the most competitively sensitive data in manufacturing organizations -- engineering designs representing years of R&D investment, regulatory documentation built over decades, and process specifications defining how products are made. Ransomware groups historically targeted financial systems and operational databases. The Cl0p Windchill campaign marks a deliberate shift to IP-rich PLM platforms as the primary exfiltration target.

The competitive impact of PLM data theft differs from traditional ransomware. Encrypted files can be restored from backup. Stolen engineering IP cannot be unexposed. A competitor or nation-state actor purchasing Cl0p's exfiltrated Windchill data may gain years of competitive advantage: production process optimization data, product roadmaps, supplier agreements, and specification data that would cost tens of millions of dollars to redevelop. For aerospace and automotive suppliers, leaked regulatory documentation creates certification and qualification exposure that can disqualify them from active programs.

Cl0p's choice of CVE-2026-12569 reflects a trend toward mass exploitation of enterprise application vulnerabilities rather than endpoint compromise. The group identified that a single critical unauthenticated RCE in a widely-deployed enterprise platform provides access to more valuable data than any number of endpoint compromises. Organizations running internet-exposed enterprise applications -- ERP, PLM, MES, ITSM -- should treat these platforms as the highest-priority targets in their external attack surface and apply critical patches within 24 hours of release.

See the BlueHammer ransomware campaign analysis for additional context on ransomware groups targeting enterprise platform vulnerabilities for mass exfiltration.

The bottom line

Cl0p ransomware has been inside PTC Windchill and FlexPLM deployments since early June, stealing engineering IP from manufacturing, automotive, aerospace, and retail via CVE-2026-12569 (CVSS 9.8). The extortion phase launched July 20. Three immediate actions: apply PTC advisory CS473270, scan /Windchill/login/ for hex-named JSP webshells, and block the four confirmed Cl0p C2 IP addresses. If webshells are present, treat the system as compromised and initiate incident response before patching.

This analysis is generic. create a free account to score threats like this against your own stack.

Frequently asked questions

What is Cl0p ransomware and how does it work?

Cl0p (also written Clop) is a ransomware-as-a-service operation tracked by threat intelligence vendors as Lace Tempest, FIN11, and Graceful Spider. Cl0p specializes in mass exploitation of enterprise application vulnerabilities to steal data at scale, then uses that data as extortion leverage. Unlike most ransomware groups, Cl0p typically does not encrypt files -- instead exfiltrating sensitive data and threatening to publish it on their leak site unless a ransom is paid. The group executed the MOVEit Transfer campaign in 2023 and is currently running an active campaign against PTC Windchill and FlexPLM systems via CVE-2026-12569.

Is PTC Windchill affected by CVE-2026-12569?

Yes. CVE-2026-12569 affects all Windchill and FlexPLM releases prior to 11.0 M030, 11.1 M020, 11.2.1, 12.0.2, 12.1.2, 13.0.2, and 13.1.1. All Creo Parametric Server versions are also affected. PTC published patches via advisory CS473270 on June 18, 2026. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on June 25. Cl0p began exploiting CVE-2026-12569 as a zero-day in early June before the patch was released.

How do I detect Cl0p webshells on Windchill?

Check /Windchill/login/ for JSP files with randomized hex-alphanumeric filenames such as 3f7b2d4e9a1c.jsp. Run: find /Windchill/login/ -name '*.jsp' | xargs ls -la and compare against your installation manifest. Also search for flst.txt in /Windchill/, /tmp/, and /var/tmp/. In web server access logs, look for GET or POST requests to /Windchill/login/*.jsp from external IP addresses with HTTP 200 responses. Any of these findings confirms active Cl0p post-exploitation activity requiring immediate incident response.

What sectors does Cl0p ransomware target in the Windchill campaign?

Confirmed targeted sectors in the CVE-2026-12569 campaign are manufacturing, automotive, aerospace, and retail and apparel. All four sectors rely on PTC Windchill or FlexPLM as core PLM infrastructure. Manufacturing and automotive organizations use Windchill for product design and BOM management. Aerospace firms use it for DO-178C and AS9100D compliance documentation. Retail and apparel companies use FlexPLM for product design and supplier management.

What data does Cl0p steal from PLM systems?

Cl0p targets the most competitively sensitive data in PLM systems: CAD files and engineering drawings, product design specifications, manufacturing process documentation, component bill-of-materials data, regulatory certification records, supplier qualification data, and product roadmaps. This data represents years of R&D investment and is valuable to competitors and nation-state actors. Unlike encrypted operational data that can be restored from backup, stolen PLM intellectual property cannot be unexposed -- making PLM extortion particularly effective.

How do I patch CVE-2026-12569 in Windchill?

Download and apply the patch via PTC Advisory CS473270 at ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability. You need an active PTC maintenance agreement to access the patch through the PTC Support portal. Affected versions are all Windchill and FlexPLM releases prior to 11.0 M030, 11.1 M020, 11.2.1, 12.0.2, 12.1.2, 13.0.2, and 13.1.1. Creo Parametric Server is also affected. After patching, conduct a webshell search -- patching stops new exploitation but does not remove webshells already deployed.

What is a JSP webshell in web application attacks?

A JSP webshell is a malicious Java Server Pages file uploaded to a web server after initial exploitation of a vulnerability. It provides the attacker with persistent access and command execution via HTTP requests -- functioning as a backdoor accessible through the web server. Cl0p deploys JSP webshells with randomized hex-format filenames to /Windchill/login/ after exploiting CVE-2026-12569. Detecting webshells requires file integrity monitoring on web-accessible directories and web log analysis for access to unexpected JSP paths.

How does Cl0p's double extortion campaign work against manufacturing firms?

Cl0p's double extortion model operates without file encryption. The group exfiltrates data first, then demands ransom for the promise of deletion and silence. In the Windchill campaign, Cl0p spent approximately 56 days silently collecting engineering data before activating extortion on July 20, 2026. Extortion emails with subject 'Windchill PDMLink module serious data leak' were sent to hundreds of employees per organization using compromised internal email accounts. Security researchers documented cases in Cl0p's previous MOVEit campaign where data was leaked despite victims paying the ransom.

Sources & references

  1. BleepingComputer: Clop ransomware targets Windchill, FlexPLM in data theft attacks
  2. CISA Known Exploited Vulnerabilities Catalog: CVE-2026-12569
  3. PTC Advisory CS473270: Windchill and FlexPLM RCE Vulnerability
  4. The Hacker News: Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM
  5. SentinelOne Vulnerability Database: CVE-2026-12569

Free resources

25
Free download

Critical CVE Reference Card 2025–2026

25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.

No spam. Unsubscribe anytime.

Free download

Ransomware Incident Response Playbook

Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.

No spam. Unsubscribe anytime.

Free newsletter

Get threat intel before your inbox does.

50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.

Unsubscribe anytime. We never sell your data.

Eric Bang
Author

Founder & Cybersecurity Evangelist, Decryption Digest

Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.

Related Questions: Answer Hub

Giveaway: InfoSec World 2026 All Access Pass ($3,895 value)

Details →
Daily Briefing

Subscribe to enter the giveaway

Every subscriber is automatically entered. You also get daily threat intel every morning: zero-days, ransomware, and nation-state campaigns. Free. No spam.

Already subscribed? You're already entered.

Giveaway

Win a $3,895 InfoSec World 2026 pass.