Cl0p Exploits PTC Windchill/FlexPLM Zero-Day (CVE-2026-12569) in Mass Data Theft Campaign
Cl0p ransomware group exploiting a zero-day in PTC Windchill/FlexPLM (CVE-2026-12569) for RCE and data exfiltration, targeting Shell, Philips, GE, and 50+ other organizations. Mirrors MOVEit and Oracle EBS playbooks. Patch immediately and monitor for webshells and unusual data exfiltration. New technical details: Cl0p deployed custom Java web shell for credential decryption, file enumeration, and exfiltration.
Sources (2)
Updated Aug 19, 2026