Clop Ransomware Returns Targeting PTC Windchill/FlexPLM
Clop ransomware launches new campaign exploiting CVE-2026-12569 (CVSS 9.3) in PTC Windchill and FlexPLM. CISA and German BSI flag as urgent. Uses compromised email accounts for extortion, consistent with previous Oracle EBS playbook. Article provides IoCs and exploit chain details. Enterprise SOCs must patch PLM systems and update detection for JSP webshells.
Sources (2)
Updated Jul 26, 2026