All stories

Unauthenticated attackers exploit critical remote code execution in PTC Windchill to steal engineering data

Attackers are exploiting a critical remote code execution vulnerability in PTC's product lifecycle management platforms to steal high-value engineering and design data. The campaign targets the aerospace, automotive, manufacturing, and retail sectors using unauthenticated access. Immediate patching of Windchill and FlexPLM instances is required.

Summary

A Cl0p ransomware affiliate is actively exploiting a critical vulnerability in PTC's Windchill and FlexPLM platforms to gain unauthorized access to enterprise environments. The attack involves chaining an information disclosure flaw with a server-side defect to achieve remote code execution (RCE). Once inside, attackers enumerate filesystems, stage sensitive data, and exfiltrate it for extortion purposes.

The campaign has been observed targeting organizations within the aerospace, automotive, manufacturing, and retail/apparel sectors. Attackers have also been sending extortion emails with the subject line "Windchill PDMLink module serious data leak" to hundreds of users within impacted companies to increase pressure.

Technical details

The exploitation relies on a chain involving two distinct vulnerabilities. First, attackers leverage a pre-authentication information disclosure in the FlexPLM WSDL endpoint. This is then paired with a server-side flaw in the Windchill login servlet to achieve unauthenticated remote code execution.

The RCE vulnerability, tracked as CVE-2026-12569, stems from the deserialization of untrusted data. This allows attackers to deploy JSP webshells under the /Windchill/login/ directory. Following successful deployment, the threat actors have been observed using a file named flst.txt for filesystem enumeration and staging engineering or design data before exfiltration.

Exploitation status

The vulnerability was patched by PTC on June 17, 2026. However, it was flagged as exploited in the wild the following day. CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities (KEV) catalog on June 25, 2026.

While the tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications, the specific actor behind this latest wave remains unconfirmed. As of July 22, 2026, the group has not publicly claimed credit for this campaign or listed victims on their dark web data leak site.

Detection opportunities

Defenders can hunt for signs of exploitation by looking for specific file patterns and malicious HTTP headers used during the attack chain.

Webshell Hunting Attackers deploy hex-named JSP webshells. Search for files matching this pattern: /Windchill/login/[0-9a-f]{16}.jsp

Network and Header Indicators The following header has been associated with the activity: X-windchill-req: ?x8Fmgow

File System Artifacts Look for the presence of a file used during filesystem enumeration: flst.txt

Defender guidance

Apply PTC's security patches immediately. The vulnerability impacts Windchill and FlexPLM releases prior to 11.0 M030. Internet-exposed instances of these products represent the primary attack surface.

Conduct threat hunting dating back to early June 2026. Monitor for unauthorized file access or staging activities involving engineering and design data. Organizations receiving emails with the subject "Windchill PDMLink module serious data leak" should treat them as part of an active extortion attempt following a breach.

Sources

  1. https://www.securityweek.com/ptc-windchill-vulnerability-exploited-in-ransomware-campaign/
  2. https://ransom-isac.org/blog/clop-windchill-flexplm-exploitation/
  3. https://event.on24.com/wcc/r/ 5410205/7BF2B1A3329F74BE93B2AE247EDCDE5B?partnerref=awidget
  4. https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -