Cl0p Exploits Critical PTC Windchill Zero-Day to Steal Engineering Data in Active Attacks
Cybersecurity researchers have uncovered an active ransomware campaign in which Cl0p ransomware affiliates are exploiting a critical zero-day vulnerability, tracked as CVE-2026-12569, to compromise internet-facing PTC Windchill and PTC FlexPLM environments.
The campaign enables unauthenticated remote code execution (RCE), allowing attackers to deploy persistent JSP webshells, exfiltrate sensitive engineering and product lifecycle management (PLM) data, and conduct double-extortion operations.
The attacks, documented by Ransom-ISAC, primarily target organizations operating in manufacturing, aerospace, automotive, industrial engineering, and retail sectors where PLM platforms store valuable intellectual property, CAD files, product designs, and supply chain documentation.
Cl0p Exploits Critical PTC Windchill Zero-Day
According to the advisory, the attackers leverage a sophisticated exploit chain that combines a pre-authentication FlexPLM WSDL information disclosure vulnerability with a critical flaw affecting the Windchill login servlet.
This chained attack enables remote, unauthenticated threat actors to execute arbitrary code on vulnerable servers without requiring valid credentials.
Security researchers attribute the campaign to Cl0p ransomware affiliates, also tracked under aliases including Graceful Spider, FIN11, Lace Tempest, and Chubby Scorpius, a financially motivated cybercriminal group known for exploiting enterprise software vulnerabilities to steal data before initiating extortion campaigns.
The primary vulnerability, CVE-2026-12569, carries a CVSS v3.1 score of 9.8, making it one of the most severe vulnerabilities affecting enterprise Product Lifecycle Management (PLM) infrastructure this year.
The flaw stems from unsafe deserialization of untrusted data within web-accessible Windchill and FlexPLM components, enabling remote code execution through specially crafted requests.
PTC confirmed that all Windchill PDMlink and FlexPLM releases prior to 11.0 M030 are affected and has released updated software builds alongside mitigation guidance to eliminate the security risk.
During observed attacks, adversaries first perform reconnaissance against internet-exposed PLM servers using requests such as GET /Windchill/rfa/jsp/login/*.jsp?wsdl.
Specific HTTP response sizes are used to fingerprint vulnerable systems before attackers abuse the exposed WSDL endpoint to gather internal configuration details.
The harvested information is then used to trigger the vulnerable Windchill login servlet, ultimately resulting in unauthenticated remote code execution.
Once initial access is achieved, the attackers deploy hexadecimal-named JSP webshells within the /Windchill/login/ directory, typically following the naming convention [0-9a-f]{16}.jsp, providing persistent remote access for post-exploitation activities.
Following successful compromise, attackers conduct extensive reconnaissance by generating flst.txt file listings that enumerate directories containing engineering assets, CAD repositories, design documentation, and other high-value intellectual property.
These files are subsequently staged for bulk exfiltration before ransomware operators initiate their extortion phase. Investigators observed that malicious requests frequently contain the distinctive HTTP header “X-windchill-req: ?x8Fmgow,” providing defenders with an important hunting artifact that can be searched across web server, reverse proxy, and security monitoring logs to identify potentially compromised systems.
The campaign escalated significantly around 20 July 2026, when Cl0p affiliates launched a coordinated extortion effort targeting affected organizations.
Victims reportedly received mass emails with the subject line “Windchill PDMLink module serious data leak,” sent to large internal distribution lists using randomly compromised email accounts.
These messages claimed that attackers had successfully breached PTC Windchill environments, stolen confidential engineering data, and instructed victims to contact Cl0p through newly established negotiation channels.
Security analysts noted similarities between this campaign and previous Cl0p extortion operations targeting Oracle E-Business Suite environments, although the threat actors introduced new email infrastructure and communication tactics to increase psychological pressure on affected organizations.
As part of its response, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-12569 to its Known Exploited Vulnerabilities (KEV) catalog on 25 June 2026, requiring U.S. federal civilian agencies to immediately remediate vulnerable systems.
Ransom-ISAC has also published multiple indicators of compromise (IOCs), including four newly identified Cl0p infrastructure IP addresses, 216.152.148.54, 216.152.151.204, 104.243.35.63, and 5.180.41.35, alongside SHA-256 malware hashes, suspicious JSP webshell paths, and unique HTTP request patterns.
Security teams are advised to prioritize patching affected Windchill and FlexPLM installations, verify that no unauthorized JSP files exist within the /Windchill/login/ directory, inspect outbound network connections from PLM servers to known malicious infrastructure, and perform comprehensive threat hunting using the published indicators.
With Cl0p yet to publicly name victims from this campaign, organizations are urged to act immediately before stolen engineering data is leveraged for ransomware negotiations or public disclosure.
No Comment! Be the first one.