Breaking: Cl0p Exploiting PTC Windchill RCE in Manufacturing Campaign — 4 Aug 2026
Cl0p Ransomware Exploiting PTC Windchill RCE in Manufacturing Campaign
Unauthenticated RCE in PTC Windchill and FlexPLM Under Active Cl0p Exploitation
Cl0p ransomware affiliates are actively exploiting internet-exposed PTC Windchill and FlexPLM deployments in a data extortion campaign targeting manufacturing, automotive, aerospace, and retail organisations. The attack chains CVE-2026-12569 (CVSS 9.3), a critical unauthenticated remote code execution vulnerability in PTC Windchill, with a separate pre-authentication information disclosure flaw in the FlexPLM WSDL endpoint (CVSS 7.5) to achieve full compromise without any credentials.
CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog in late July. PTC has since issued continued warnings about heightened threat activity and confirmed that attackers are deploying hex-named JSP web shells under /Windchill/login/ for persistent remote command execution. Ransom-ISAC, eCrime.ch, and DEFUSED published a coordinated advisory on August 3 with full indicators of compromise.
Attack Pattern: From Initial Access to Double Extortion
The tradecraft follows Cl0p's established playbook: gain initial access through the RCE vulnerability, enumerate file systems for engineering and design data, then exfiltrate and extort. Extortion emails are sent from previously compromised accounts to hundreds of users within each target organisation, directing victims to contact the Cl0p crew. JSP web shells provide persistent command execution even after the initial vulnerability is patched, meaning remediation without forensic sweeps leaves backdoors in place.
ReliaQuest confirmed active exploitation of CVE-2026-12569 for unauthenticated RCE and JSP web shell deployment for remote command execution and sensitive product data exfiltration. The observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories, including MOVEit Transfer, GoAnywhere MFT, Cleo, and Accellion FTA.
Why This Matters for Critical Infrastructure
PTC Windchill is product lifecycle management software used pervasively in manufacturing, defence, aerospace, and automotive supply chains. The data it holds — CAD files, engineering designs, bill of materials, supplier information — represents the intellectual property crown jewels of its users. An RCE vulnerability in this software, actively exploited by a ransomware group with 885 claimed victims, poses a direct threat to the manufacturing sector's confidentiality and operational continuity. Fewer than 100 instances were internet-exposed as of June, but that number has been declining as organisations respond to the threat, meaning the remaining exposed instances are disproportionately valuable targets.
So What / Action
If you run PTC Windchill or FlexPLM, treat this as an active incident. Patch immediately if any instance is internet-facing — check PTC's security advisories for the latest hotfixes. Audit web application logs for POST requests to /Windchill/login/ containing JSP filenames, and search for hex-named JSP files in that directory. Hunt for the four published IOC IPs (216.152.148.54, 216.152.151.204, 104.243.35.63, 5.180.41.35) in firewall and proxy logs. If your organisation is in manufacturing, aerospace, or automotive, verify with your PLM and engineering teams that Windchill is not exposed to the internet and that patching is current. Assume that a successful RCE leaves persistent web shells — patching alone is not remediation without a thorough forensic review.

