<- ALL CYBER NEWS

Critical

Cl0p, PTC Windchill, FlexPLM, CVE-2026-12569, CISA KEV, unauthenticated RCE, ransomware

Cl0p Exploits PTC Windchill CVE-2026-12569 (CVSS 9.3)

Cl0p ransomware affiliates are exploiting CVE-2026-12569, a CVSS 9.3 unauthenticated RCE in internet-exposed PTC Windchill and FlexPLM. It is now in CISA KEV.

Cl0p ransomware affiliates are exploiting CVE-2026-12569, a CVSS 9.3 unauthenticated remote code execution flaw in internet-exposed PTC Windchill PDMLink and FlexPLM. It is now in the CISA KEV catalog. If you run either product on the internet, treat this as an active incident, not a patch task.

What happened. Threat actors tied to the Cl0p campaign (also tracked as FIN11, Graceful Spider, and Lace Tempest) are exploiting CVE-2026-12569, a critical deserialization-of-untrusted-data flaw (CWE-20, CVSS 9.3) in PTC Windchill PDMLink and FlexPLM. The bug allows unauthenticated remote code execution against internet-exposed instances, and CISA has added it to its Known Exploited Vulnerabilities catalog.

How severe is CVE-2026-12569?

Detail

Value

CVE

CVE-2026-12569

CVSS

9.3 Critical (CWE-20, deserialization)

Products

PTC Windchill PDMLink, FlexPLM

Access required

None - unauthenticated

CISA KEV

Yes - actively exploited

Attacker

Cl0p (FIN11 / Graceful Spider / Lace Tempest)

Who is affected. Manufacturers and product-led companies running Windchill or FlexPLM - the PLM systems that hold design files, BOMs, and product IP. Any instance reachable from the internet is a target right now.

Is CVE-2026-12569 being exploited?

Yes. CISA only lists a CVE in KEV after confirming active exploitation, and reporting attributes this to Cl0p affiliates. This is the same playbook Cl0p ran against MOVEit and other enterprise apps: find one widely deployed, internet-exposed product and mass-exploit every instance that has not patched.

What should you do now?

Apply PTC's fix immediately. If you cannot patch today, take internet-exposed Windchill and FlexPLM offline or behind a VPN, and hunt for signs of deserialization exploitation and unexpected process execution. Because this is KEV-listed and Cl0p-operated, assume exploitation may already have occurred and begin incident response, not just patching.

Our read. Cl0p does not need a novel technique; it needs an internet-exposed enterprise app that most defenders forgot was internet-exposed. In our analysis of the 2025 KEV catalog, 67% of vulnerabilities that were actually exploited would have been missed by an organisation relying on an annual penetration test to find them - and internet-facing PLM is exactly the kind of asset that cadence skips. Knowing continuously what of yours is reachable and exploitable is the only thing that beats a mass-exploitation crew.

Reporting by The Hacker News; exploitation status per the CISA KEV catalog; severity and affected products per NVD. Sources linked above.

Related: Oracle E-Business Suite CVE-2026-46817 under attack and our KEV pentest analysis.

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.