Cl0p Actively Exploiting CVE-2026-12569 in PTC Windchill/FlexPLM — Manufacturing, Aerospace, Automotive Sectors Under Active Exfiltration
Cl0p affiliates (aka Lace Tempest, FIN11, Graceful Spider) are chaining a pre-auth FlexPLM WSDL information disclosure flaw with a critical unsafe deserialization bug in the Windchill login servlet (CVE-2026-12569, CVSS 9.3) to achieve unauthenticated RCE, drop hex-named JSP webshells under /Windchill/login/, and stage engineering IP for double-extortion. Ransom-ISAC confirmed four new C2 indicators as of July 22, and extortion emails with the subject 'Windchill PDMLink module serious data leak' are being mass-distributed from compromised internal accounts to hundreds of users per victim organization. PTC serves over 30,000 organizations worldwide — including 1,500+ FlexPLM customers in aerospace, defense, and automotive — and patches released June 17 remain widely unapplied; threat hunting should extend back to early June 2026.
PTC serves over 30,000 organizations worldwide — including 1,500+ FlexPLM customers in aerospace, defense, and automotive — and patches released June 17 remain widely unapplied; threat hunting should extend back to early June 2026.
This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the critical severity rating as a guide to prioritization within their environment.
For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.