ctipilot.ch

PTC Windchill / FlexPLM — pre-auth deserialization RCE, CISA KEV-listed, now driving a Cl0p-attributed mass data-theft extortion campaign

cve · CVE-2026-12569

Coverage timeline
5
first 2026-06-20 → last 2026-08-02
Peak priority
critical
1 critical · 3 high · 1 notable
Sources cited
9
8 hosts
Sections touched
4
deep-dive, updates, weekly-top-stories
Co-occurring entities
2
see Related entities below
ATT&CK techniques
7
pinned v19.1 · see below

ATT&CK techniques

7 techniques observed across 3 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Resource Development TA0042

T1586.002Compromise Accounts: Email Accounts×1

Adversaries may compromise email accounts that can be used during targeting. Adversaries can use compromised email accounts to further their operations, such as leveraging them to conduct Phishing for Information, Phishing, or large-scale spam email campaigns. Utilizing an existing persona with a compromised email account may engender a level of trust in a potential victim if they have a relationship with, or knowledge of, the compromised persona. Compromised email accounts can also be used in the acquisition of infrastructure (ex: Domains).

Evidence: 2026-07-27/clop-windchill-flexplm-mass-extortion-wave-cve-2026-12569 · ATT&CK page ↗

Initial Access TA0001

T1190Exploit Public-Facing Application×3

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-27/clop-windchill-flexplm-mass-extortion-wave-cve-2026-12569 · 2026-06-22/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio · 2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ · ATT&CK page ↗

Persistence TA0003

T1505Server Software Component×1

Adversaries may abuse legitimate extensible development features of servers to establish persistent access to systems. Enterprise server applications may include features that allow developers to write and install software or scripts to extend the functionality of the main application. Adversaries may install malicious components to extend and abuse server applications.

Evidence: 2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×3

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-07-27/clop-windchill-flexplm-mass-extortion-wave-cve-2026-12569 · 2026-06-22/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio · 2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ · ATT&CK page ↗

Discovery TA0007

T1083File and Directory Discovery×1

Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-07-27/clop-windchill-flexplm-mass-extortion-wave-cve-2026-12569 · ATT&CK page ↗

Collection TA0009

T1074Data Staged×1

Adversaries may stage collected data in a central location or directory prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location.

Evidence: 2026-07-27/clop-windchill-flexplm-mass-extortion-wave-cve-2026-12569 · ATT&CK page ↗

Impact TA0040

T1657Financial Theft×1

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-07-27/clop-windchill-flexplm-mass-extortion-wave-cve-2026-12569 · ATT&CK page ↗

Story timeline

  1. 2026-07-27Cl0p-affiliated actors move the PTC Windchill / FlexPLM intrusions (CVE-2026-12569) into a mass extortion-email phase, with no victims named yet
    updatesWindchill exploitation turns to extortion: staff-wide emails name the PLM breach vector, victim listings still pending
  2. 2026-06-29CVE-2026-12569 — PTC Windchill / FlexPLM: pre-auth deserialization RCE, now confirmed exploited with JSP web shells (CISA KEV)
    weekly-vuln-rollup
  3. 2026-06-27PTC Windchill CVE-2026-12569 now confirmed exploited in the wild with JSP web shells
    updates
  4. 2026-06-22CVE-2026-12569 — PTC Windchill / FlexPLM pre-auth deserialization RCE, exploited, BSI calling admins at 02:30
    weekly-top-stories
  5. 2026-06-20PTC Windchill CVE-2026-12569: unauthenticated Java deserialization to RCE on the PLM management plane
    deep-dive

Where this entity is cited

  • updates2
  • deep-dive1
  • weekly-top-stories1
  • weekly-vuln-rollup1

Source distribution

  • attack.mitre.org2 (22%)
  • bleepingcomputer.com1 (11%)
  • euvd.enisa.europa.eu1 (11%)
  • heise.de1 (11%)
  • ptc.com1 (11%)
  • ransom-isac.org1 (11%)
  • security-hub.ncsc.admin.ch1 (11%)
  • thehackernews.com1 (11%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about PTC Windchill / FlexPLM — pre-auth deserialization RCE, CISA KEV-listed, now driving a Cl0p-attributed mass data-theft extortion campaign (5)

2026-07-27 · view entry permalink →

HIGHCVE-2026-12569exploitedupdateNATOB2

Cl0p-affiliated actors move the PTC Windchill / FlexPLM intrusions (CVE-2026-12569) into a mass extortion-email phase, with no victims named yet

UPDATE · originally covered PTC Windchill CVE-2026-12569 now confirmed exploited in the wild with JSP web shells (2026-06-27)

The PTC Windchill / FlexPLM deserialization RCE this pipeline covered when CISA confirmed exploitation has moved from quiet data theft into open extortion. From 20 July a joint advisory by Ransom-ISAC, eCrime.ch and DEFUSED records that it "began observing an alleged Cl0p ransomware (aka Graceful Spider, Chubby Scorpius, FIN11, Lace Tempest) data extortion campaign sending emails with a subject line, “Windchill PDMLink module serious data leak” to an unknown number of affected organizations" (Ransom-ISAC / eCrime.ch / DEFUSED, 2026-07-22). The delivery pattern is the operationally useful part: the messages are sent from randomly compromised accounts and go to hundreds of recipients inside the victim organisation at once, carrying the attacker's current contact addresses — an approach the same advisory notes is consistent with the Oracle E-Business Suite campaign of last year apart from the new addresses (same advisory).

Two facts bound the response window. First, no victim has been named: "As of 22 July, Cl0p ransomware has not begun listing victims of this latest campaign on their dark web data leak site or has publicly claimed credit for this latest campaign" (same advisory), so an affected organisation's first and possibly only warning is the staff-wide email, not a leak-site entry. Second, attribution is unsettled and the two reporting streams disagree in a way worth carrying: the joint advisory treats this as Cl0p affiliate activity, while ReliaQuest, quoted by BleepingComputer, states that "The actor behind these attacks remains unconfirmed. however, the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories" (BleepingComputer, 2026-07-24). The underlying access route is unchanged from the June coverage — a pre-authentication information disclosure in the FlexPLM WSDL endpoint chained with the Windchill login-servlet flaw, followed by JSP web shells and staged data theft (Ransom-ISAC / eCrime.ch / DEFUSED, 2026-07-22).

One correction to how this pipeline previously framed remediation, because it changes who is still exposed: there is no version floor above which an installation is safe. PTC ships a patch per version, and its own change log records the older Windchill lines being patched between 18 and 19 June — 13.0.2 on 18 June, and 11.0 M030 alongside 13.1.1 on 19 June — while the SUPs for 13.1.2 and 13.1.3, and the first release naming FlexPLM as well as Windchill, only arrived on 14 July 2026 (PTC, 2026-07-14). 11.0 M030 appears in that patch list as a version that receives a fix, not as a boundary below which systems are safe, and there is no lower bound at all: NVD states the flaw "also impacts Windchill and FlexPLM releases prior to 11.0 M030", and above that it enumerates discrete affected releases rather than a continuous range, topping out at Windchill 13.1.3 and FlexPLM 13.0.3. The practical consequence is narrower than a version number suggests but sharper for those it catches: an estate on 13.1.2 or 13.1.3 had no patch available between CISA's KEV confirmation on 25 June and the SUP release on 14 July, whereas a 13.1.1 estate could have patched from 19 June. Neither a high version number nor a version above 11.0 M030 is therefore evidence of remediation, and only the per-version list in PTC's eSupport article CS473270 answers the question.

Triage: the extortion email is itself a detectable event with a clean discriminator. A legitimate internal security notice originates from a known internal sender and the organisation's own mail infrastructure; this pattern is a large recipient set inside one organisation receiving mail from a compromised account with no prior relationship to it, referencing a specific internal application by name. Mail-flow telemetry showing that fan-out to a wide internal distribution list from a previously-unseen sender — rather than the message content — is the signal, and it should route to incident response rather than to the phishing-report queue.

On 20 July, Ransom-ISAC began observing an alleged Cl0p ransomware (aka Graceful Spider, Chubby Scorpius, FIN11, Lace Tempest) data extortion campaign sending emails with a subject line, “Windchill PDMLink module serious data leak” to an unknown number of affected organizations

As of 22 July, Cl0p ransomware has not begun listing victims of this latest campaign on their dark web data leak site or has publicly claimed credit for this latest campaign.

Ransom-ISAC / eCrime.ch / DEFUSED 2026-07-22

The actor behind these attacks remains unconfirmed. however, the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories.

BleepingComputer, quoting ReliaQuest
threat27 Jul 04:33Zmulti-sourceOpen finding ↗

2026-06-29 · view entry permalink →

NOTABLECVE-2026-12569exploited

CVE-2026-12569 — PTC Windchill / FlexPLM: pre-auth deserialization RCE, now confirmed exploited with JSP web shells (CISA KEV)

When first covered (06-20) and in the W25 weekly this was a pre-auth deserialization flaw with BSI escalating to admins out-of-hours. The in-window delta: CISA added it to KEV on 06-25 and JSP web-shell deployment against the login interface is now confirmed in the wild. Any internet-reachable Windchill PDMLink or FlexPLM instance should be treated as assume-compromise — manufacturing and defence-supplier PLM is exactly the externally-reachable engineering surface a Swiss/EU industrial estate forgets to inventory.

When first covered (06-20) and in the W25 weekly this was a pre-auth deserialization flaw with BSI escalating to admins out-of-hours.

ctipilot v2 brief (migrated)
vulnerability29 Jun 00:20Zmulti-sourceOpen finding ↗

2026-06-27 · view entry permalink →

HIGHCVE-2026-12569exploitedupdate

PTC Windchill CVE-2026-12569 now confirmed exploited in the wild with JSP web shells

UPDATE · originally covered PTC Windchill CVE-2026-12569: unauthenticated Java deserialization to RCE on the PLM management plane (2026-06-20)

CISA added the PTC Windchill PDMLink / FlexPLM pre-auth deserialization RCE (CVE-2026-12569) to its Known Exploited Vulnerabilities catalog on 2026-06-25, confirming active in-the-wild exploitation — the operational shift from the disclosure we deep-dived on June 20 (The Hacker News, 2026-06-26).

Reported post-exploitation deploys JSP web shells to /Windchill/login/<16-hex>.jsp plus a flst.txt persistence marker — concrete hunt artefacts beyond the earlier abstract RCE description. ENISA's EUVD entry corroborates the unauthenticated deserialization root cause (ENISA EUVD EUVD-2026-37831). The driver for Swiss/EU manufacturing, pharma and aerospace operators running Windchill is the confirmed exploitation and the web-shell pattern, not the US-only federal remediation date; patch per PTC CS473270 and hunt web-server logs for .jsp creation under /Windchill/login/.

UPDATE (originally covered 2026-06-20): CISA added the PTC Windchill PDMLink / FlexPLM pre-auth deserialization RCE (CVE-2026-12569) to its Known Exploited Vulnerabilities catalog on 2026-06-25, confirming active in-the-wild exploitation — the operational shift from the disclosure we deep-dived on …

ctipilot v2 brief (migrated)
vulnerability27 Jun 05:17Zmulti-sourceOpen finding ↗

Earlier coverage (2)