[DigitalToday reporter Chi-gyu Hwang] Signs have been detected that an affiliate group of the Cl0p ransomware operation is seeking to exploit a critical remote code execution (RCE) vulnerability in PTC’s product lifecycle management (PLM) platforms Windchill and FlexPLM.
A vulnerability registered as CVE-2026-12569 has a CVSS (Common Vulnerability Scoring System) score of 9.3, SecurityWeek reported on July 27 local time. The flaw arises in the process of handling externally supplied data without validation and allows attacks without login.
A patch was released on June 17. SecurityWeek reported that real-world exploitation was confirmed after PTC disclosed indicators of compromise (IoCs) a day later. The vulnerability was also added in late June to the U.S. Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities (KEV) catalog.
Cl0p affiliates are currently exploiting the vulnerability, according to an alert issued by Rilladquest and Ransom-ISAC together with eCrime.ch and Diffused.
Rilladquest said, "The party behind the attacks has not yet been identified, but the techniques observed show characteristics similar to past Cl0p campaigns that targeted enterprise applications and high-value data repositories."