type: cve ยท created: 2026-07-26 ยท updated: 2026-07-26 ยท tags: [cve, rce, cl0p, ransomware, ptc, windchill, flexplm, manufacturing, supply-chain, web-shell] ยท confidence: high ยท severity: critical ยท affected_sectors: [manufacturing, automotive, aerospace, retail, technology] ยท au_impact: true
CVE-2026-12569 โ PTC Windchill/FlexPLM Unauthenticated RCE
CVE-2026-12569 is a critical vulnerability (CVSS 9.3) in PTC Windchill and FlexPLM that chains an information disclosure flaw with a server-side issue to achieve unauthenticated Remote Code Execution.
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-12569 |
| CVSS | 9.3 (Critical) |
| Type | Unauthenticated RCE via information disclosure chain |
| Product | PTC Windchill, PTC FlexPLM |
| Exploitation | Active โ exploited by Cl0p ransomware affiliates |
Exploitation
Cl0p ransomware affiliates are actively exploiting internet-exposed PTC Windchill and FlexPLM deployments to deploy JSP web shells on target systems. Targeted sectors include:
- Manufacturing
- Automotive
- Aerospace
- Retail
Impact
Organisations using PTC Windchill or FlexPLM for product lifecycle management should immediately restrict internet exposure and apply patches if available.
Sources
- The Hacker News โ July 25, 2026