Threat actors linked to the Cl0p ransomware group are actively exploiting vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments as part of a new data extortion campaign. According to a coordinated advisory from Ransom-ISAC, eCrime.ch, and DEFUSED, attackers chain a pre-authentication information disclosure flaw in the FlexPLM WSDL endpoint with a server-side vulnerability in the Windchill login servlet to achieve unauthenticated remote code execution (RCE). This allows them to deploy hex-named JSP web shells under the /Windchill/login/ directory.
Once initial access is gained, the attackers conduct file system enumeration, stage engineering and design data, and ultimately carry out double extortion data theft. The campaign primarily targets the manufacturing, automotive, aerospace, and retail sectors. The exploitation is believed to involve CVE-2026-12569 (CVSS score: 9.3), a critical flaw in PTC Windchill that was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog. PTC has warned customers of heightened threat activity and confirmed that attackers are deploying JSP web shells against susceptible systems.
Researchers Brandon Parsons, Corsin Camichel, and Simo Kohonen noted that the RCE is chained with a separate pre-authentication information-disclosure defect in the FlexPLM WSDL endpoint (CVSS v3.1 7.5) to enable unauthenticated exploitation. Ransom-ISAC has shared four IP addresses as indicators of compromise: 216.152.148.54, 216.152.151.204, 104.243.35.63, and 5.180.41.35. Extortion emails originate from previously compromised accounts and are sent to hundreds of users within impacted organizations, providing contact information for the Cl0p ransomware crew.
ReliaQuest observed threat actors actively exploiting CVE-2026-12569 for unauthenticated RCE and JSP web shell deployment, facilitating remote command execution and sensitive product data exfiltration. The actor behind these attacks remains unconfirmed, but the tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories. Cl0p has a history of weaponizing flaws in file transfer appliances from Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer, as well as a vulnerability in Oracle E-Business Suite.
CVEs: CVE-2026-12569
Attack groups: Cl0p, Chubby Scorpius, FIN11, Graceful Spider, Lace Tempest
Companies: PTC, Ransom-ISAC, eCrime.ch, DEFUSED, ReliaQuest
Products: PTC Windchill, PTC FlexPLM
Original source: thehackernews.com