The Cl0p ransomware group claims to have compromised over 40 organizations by exploiting a critical vulnerability in PTC's Windchill and FlexPLM product lifecycle management (PLM) software. This vulnerability, identified as CVE-2026-12569, is a remote code execution (RCE) flaw with a CVSS score of 9.3, stemming from the deserialization of untrusted data. It affects all CPS versions and Windchill and FlexPLM releases prior to 11.0 M030.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this flaw to its Known Exploited Vulnerabilities (KEV) catalog in June, indicating active exploitation. German authorities reportedly issued direct warnings to organizations about impending attacks, suggesting the exploitation window was not covert.
According to security firm ReliaQuest, Cl0p deployed a sophisticated custom implant rather than a basic web shell. This implant functions as a comprehensive extortion platform, capable of mapping sensitive vault data, decrypting credentials stored in the Windchill keystore, and executing additional code within the application process via a custom Java class loader. This functionality effectively transforms the initial access into an extensive backdoor, facilitating lateral movement, ransomware deployment, or persistent access for prolonged periods.
The group's strategy mirrors its past campaigns against other enterprise software platforms like Oracle E-Business Suite, MOVEit, Cleo, and GoAnywhere. Cl0p exploits a single vulnerability in widely used enterprise software to target numerous companies, subsequently publishing the names of victims who refuse to pay a ransom.
Cl0p initially listed partial company names on its leak site, transitioning to full names starting August 12. The victim count has steadily increased since then. For each organization, the listings specify the type and approximate volume of stolen data, which ranges from a single gigabyte to several terabytes. The compromised data reportedly includes databases, project files, backups, engineering documents, blueprints, diagrams, corporate files, and images.
Prominent organizations named on Cl0p's leak site include Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, Toast, Mindray, and Largan Precision, a supplier of camera lenses for Apple devices. Notably, GE briefly appeared on the list before being removed, a move that often indicates either a ransom payment or ongoing negotiations. Shell, Philips, Fiserv, and GE have publicly acknowledged awareness of Cl0p's claims and stated they are investigating, though none have confirmed a significant breach at this time.
The targeting of PLM software is particularly significant because these systems are deeply embedded within manufacturing supply chains and contain sensitive engineering data that would be valuable to competitors or state-sponsored actors. Organizations utilizing Windchill or FlexPLM are strongly advised to prioritize checking for and patching this specific CVE.






