Cl0p mass-exploits unauthenticated RCE in PTC Windchill and FlexPLM (CVE-2026-12569)
Cl0p today publicly named more than 40 victims of its Windchill/FlexPLM exploitation campaign — including Shell, Philips, and Fiserv — and any team still running an unpatched, reachable instance this week risks data theft and appearance on the leak site.
An improper input validation flaw in PTC Windchill PDMLink and FlexPLM lets an unauthenticated remote attacker execute arbitrary code with a single crafted network request. The Cl0p ransomware group has used it in a mass data-theft and extortion campaign against dozens of major organizations.
Affected: PTC Windchill PDMLink <= 11.0 M030; PTC Windchill PDMLink 11.1 M020; PTC Windchill PDMLink 11.2.1.0; PTC Windchill PDMLink 12.0.2.0; PTC Windchill PDMLink 12.1.2.0; PTC Windchill PDMLink 13.0.2.0; PTC Windchill PDMLink 13.1.0.0; PTC Windchill PDMLink 13.1.1.0; PTC Windchill PDMLink 13.1.2.0; PTC Windchill PDMLink 13.1.3.0; PTC FlexPLM (same code base and fix line)
How to Test
Confirm your Windchill/FlexPLM build against the affected list above (any 11.x–13.1.3.0 build is vulnerable). Treat any internet-reachable instance as potentially compromised: review web-tier access logs for anomalous unauthenticated POST requests to Windchill servlet endpoints since late June 2026, hunt for newly written JSP/webshell files under the Windchill web application directories, and check for large outbound data transfers consistent with Cl0p exfiltration.
How to Patch
Apply the fixes and mitigations in PTC article CS473270 (https://www.ptc.com/en/support/article/CS473270), upgrading to the patched CPS builds for your release line. If you cannot patch immediately, remove the appliance from direct internet exposure (VPN-gate it) and perform forensic triage before restoring access — this CVE's KEV remediation deadline passed on 2026-06-28.