The record
Written from the 2 reports below. Nothing here is unsourced.
- Ransomware-affiliated attackers, identified by researchers as linked to the Clop extortion gang, are actively exploiting a critical remote code execution flaw in PTC's Windchill and FlexPLM product lifecycle management platforms.
- The vulnerability, tracked as CVE-2026-12569 with a CVSS score of 9.8, stems from unsafe deserialization of untrusted data and allows unauthenticated attackers to execute arbitrary code on exposed instances.
- Exploitation has already been observed in the wild, with threat actors deploying web shells for persistent access and conducting double-extortion data theft campaigns — stealing sensitive engineering and product data before deploying ransomware or threatening to leak it.
- PTC has warned customers and the vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog, signaling active government concern.
- Organizations in manufacturing, aerospace, automotive, and other sectors relying on these PLM tools face immediate risk if internet-facing instances remain unpatched.
- The situation is evolving rapidly, with no public workaround short of applying vendor patches and isolating exposed systems.
What to watch next
- CISA KEV listing mandates federal agency patching; private sector should treat as urgent.
- Clop's double-extortion playbook means data theft precedes ransom demands.
- Internet-exposed Windchill/FlexPLM instances are primary targets — audit external attack surface.
- Monitor for web shell artifacts and anomalous file system enumeration post-exploitation.
What changed2
Every report on this story, newest first. Times are when each outlet published.
Why it matters4
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- Organizations running PTC Windchill or FlexPLM remote code execution· immediate
- Organizations running PTC Windchill or FlexPLM data exposed· days
- Organizations running PTC Windchill or FlexPLM web shell persistence· immediate
- PTC patch required· days
Coverage2
2 reports
English national1International1
Filed from United States ×2, India ×1
Named United States · FlexPLM · PTC · Windchill · Ascent Solutions · Brandon Parsons · BSI · CISA · Cl0p · Clop · Corsin Camichel · Defused · eCrime.ch
The 2 reports are listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.

