The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign.
Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026–12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances.
As cybersecurity company ReliaQuest reported on Thursday, Clop operators have been deploying JSP webshells that allow them to exfiltrate sensitive data from targeted companies’ compromised PLM platforms.
