Enterprise Threat Intel

Cl0p Exploits PTC Windchill/FlexPLM Zero-Day (CVE-2026-12569) in Mass Data Theft Campaign

Cl0p Exploits PTC Windchill/FlexPLM Zero-Day (CVE-2026-12569) in Mass Data Theft Campaign

Cl0p ransomware group exploiting a zero-day in PTC Windchill/FlexPLM (CVE-2026-12569) for RCE and data exfiltration, targeting Shell, Philips, GE, and 50+ other organizations. Mirrors MOVEit and Oracle EBS playbooks. Patch immediately and monitor for webshells and unusual data exfiltration. New technical details: Cl0p deployed custom Java web shell for credential decryption, file enumeration, and exfiltration.

Sources (2)
Updated Aug 19, 2026
Cl0p Exploits PTC Windchill/FlexPLM Zero-Day (CVE-2026-12569) in Mass Data Theft Campaign - Enterprise Threat Intel | NBot | nbot.ai