Clop is exploiting CVE-2026-12569 in exposed PTC Windchill and FlexPLM instances for data theft extortion. Patch it and keep those systems off the public internet.Cyber Resilience desk
Sources (2)
- bleeping · bleeping
- databreaches · databreaches
What this means for you — CISO:If you run PTC Windchill or FlexPLM, confirm whether any instances are internet-exposed and apply the fix for CVE-2026-12569 immediately; treat unpatched edge PLM as a data-theft priority. Inventory PLM and related file stores for unusual access or bulk download.
What this means for you — Lean IT orgs:Most resource-constrained shops do not run Windchill or FlexPLM. If a manufacturer or supplier you depend on does, ask them whether their PLM is patched and not left on the public internet.
What this means for you — MSP:Scan managed estates for internet-facing PTC Windchill and FlexPLM; patch CVE-2026-12569 and pull exposed instances behind VPN or remove them from the edge. Flag manufacturing and product-engineering clients first.
What this means for you — Researcher:Corroborated Clop data-theft campaign abusing CVE-2026-12569 on exposed Windchill/FlexPLM — watch for exploit details, IoCs, and new leak-site victim posts tied to PTC PLM.