<- ALL CYBER NEWS
Critical
Cl0p, PTC Windchill, FlexPLM, CVE-2026-12569, CISA KEV, unauthenticated RCE, ransomware
Cl0p Exploits PTC Windchill CVE-2026-12569 (CVSS 9.3)
Cl0p ransomware affiliates are exploiting CVE-2026-12569, a CVSS 9.3 unauthenticated RCE in internet-exposed PTC Windchill and FlexPLM. It is now in CISA KEV.
Cl0p ransomware affiliates are exploiting CVE-2026-12569, a CVSS 9.3 unauthenticated remote code execution flaw in internet-exposed PTC Windchill PDMLink and FlexPLM. It is now in the CISA KEV catalog. If you run either product on the internet, treat this as an active incident, not a patch task.
What happened. Threat actors tied to the Cl0p campaign (also tracked as FIN11, Graceful Spider, and Lace Tempest) are exploiting CVE-2026-12569, a critical deserialization-of-untrusted-data flaw (CWE-20, CVSS 9.3) in PTC Windchill PDMLink and FlexPLM. The bug allows unauthenticated remote code execution against internet-exposed instances, and CISA has added it to its Known Exploited Vulnerabilities catalog.
How severe is CVE-2026-12569?
Detail | Value |
|---|---|
CVE | CVE-2026-12569 |
CVSS | 9.3 Critical (CWE-20, deserialization) |
Products | PTC Windchill PDMLink, FlexPLM |
Access required | None - unauthenticated |
CISA KEV | Yes - actively exploited |
Attacker | Cl0p (FIN11 / Graceful Spider / Lace Tempest) |
Who is affected. Manufacturers and product-led companies running Windchill or FlexPLM - the PLM systems that hold design files, BOMs, and product IP. Any instance reachable from the internet is a target right now.
Is CVE-2026-12569 being exploited?
Yes. CISA only lists a CVE in KEV after confirming active exploitation, and reporting attributes this to Cl0p affiliates. This is the same playbook Cl0p ran against MOVEit and other enterprise apps: find one widely deployed, internet-exposed product and mass-exploit every instance that has not patched.
What should you do now?
Apply PTC's fix immediately. If you cannot patch today, take internet-exposed Windchill and FlexPLM offline or behind a VPN, and hunt for signs of deserialization exploitation and unexpected process execution. Because this is KEV-listed and Cl0p-operated, assume exploitation may already have occurred and begin incident response, not just patching.
Our read. Cl0p does not need a novel technique; it needs an internet-exposed enterprise app that most defenders forgot was internet-exposed. In our analysis of the 2025 KEV catalog, 67% of vulnerabilities that were actually exploited would have been missed by an organisation relying on an annual penetration test to find them - and internet-facing PLM is exactly the kind of asset that cadence skips. Knowing continuously what of yours is reachable and exploitable is the only thing that beats a mass-exploitation crew.
Reporting by The Hacker News; exploitation status per the CISA KEV catalog; severity and affected products per NVD. Sources linked above.
Related: Oracle E-Business Suite CVE-2026-46817 under attack and our KEV pentest analysis.