Clop Exploits PTC PLM Zero Day for Major Data Breach

Clop exploits PLM zero-day in large-scale data breach

The recent exploitation of a zero day in PTC’s Product Lifecycle Management (PLM) suite by the Clop ransomware group has resulted in a significant data breach, impacting dozens of high-profile organisations. The attack leveraged a critical vulnerability in Windchill PDMLink and FlexPLM, enabling unauthenticated remote code execution (RCE) and large-scale data theft. This article examines the event in detail, including affected products, how the attack unfolded, and what UK businesses need to know now.

Clop’s Target: PTC Windchill and FlexPLM Zero Day Attack

In late July and August 2026, security researchers and national CERTs reported that the Russia-linked Clop (or Cl0p) group exploited a zero day flaw in PTC’s flagship PLM platforms. The vulnerability, now tracked as CVE 2026 12569, affects both Windchill PDMLink and FlexPLM, widely used by manufacturers, engineering firms, and retailers to manage product data and lifecycles.

Clop’s campaign used the flaw to breach exposed PLM servers, deploy web shells, and exfiltrate sensitive engineering and product information. Notably, organisations named as victims include Shell, Philips, and General Electric, with Shell and others confirming investigations into Clop’s claims of data theft. Reports suggest as many as 50 companies worldwide may have been affected, highlighting the broad impact of this attack vector.

Vulnerability Details: CVE 2026 12569 and Attack Chain

The exploited vulnerability is a critical RCE issue caused by deserialization of untrusted data in Windchill and FlexPLM. This flaw enables attackers to execute arbitrary code on unpatched PLM servers without any authentication, making it especially dangerous for internet-exposed systems.

  • Root cause: Improper input validation leads to deserialization of attacker-controlled data, allowing code execution.
  • CVSS: Assigned a base score of 10.0, reflecting maximum severity.

The observed attack chain involves two key steps:

  1. Information disclosure via FlexPLM WSDL endpoint provided attackers with material to target the next step.
  2. Windchill login servlet exploitation enabled unauthenticated RCE, letting attackers deploy JSP web shells under the Windchill login path.

Once inside, Clop affiliates used these web shells for remote command execution, file system enumeration, and exfiltration of high-value design and project data for double extortion. PTC and security advisories confirm active use of this chain in the wild, with victims later listed on Clop’s leak site.

Timeline of the Clop PLM Data Breach Operation

  • 26 March 2026: PTC issues an initial advisory for a critical Windchill and FlexPLM vulnerability, with mitigations while patches are developed. Early advisories reference CVE 2026 4681.
  • 17-18 June 2026: PTC releases updates and patches, reclassifying the main vulnerability as CVE 2026 12569. National Vulnerability Database (NVD) entries confirm unauthenticated RCE via deserialization.
  • 25-29 June 2026: CISA adds CVE 2026 12569 to the Known Exploited Vulnerabilities catalog. Reports emerge of active web shell deployment on unpatched Windchill servers.
  • 24-25 July 2026: Public reporting directly links ongoing exploitation to Clop affiliates. Technical details of the attack chain and indicators of compromise (IoCs) are released in a coordinated advisory. National CERTs and media issue alerts.
  • 12-15 August 2026: Clop lists dozens of breached organisations, including Shell, GE, and Philips, on its leak site. Press coverage and company investigations follow.

Throughout this period, PTC maintained rolling updates via its trust centre and eSupport articles, providing IoCs, patch guidance, and mitigation steps. Customers are urged to consult these resources for the latest remediation information.

Affected Products, Versions, and Exploitation Status

Products and Versions in Scope

  • PTC Windchill PDMLink: Versions 11.0_M030, 11.1_M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0, 13.1.1.0, 13.1.2.0, 13.1.3.0 and older releases before 11.0 M030.
  • PTC FlexPLM: Versions 11.0_M030, 11.1_M020, 11.2.1.0, 12.0.0.0, 12.0.2.0, 12.0.3.0, 12.1.2.0, 12.1.3.0, 13.0.2.0, 13.0.3.0 and older releases before 11.0 M030.

All CPS (Critical Patch Set) versions are in scope. For the full list of affected products and remediation instructions, refer to PTC’s eSupport article CS473270.

Current Exploitation and Threat Activity

  • Active exploitation confirmed, with CISA listing CVE 2026 12569 as a known exploited vulnerability.
  • Public indicators of compromise include specific attacker IPs and web shell file paths (for example, /Windchill/login/7c0a0a34c9d8d53b.jsp).
  • Clop affiliates used a sophisticated pre-authentication chain, combining a FlexPLM WSDL leak and Windchill login servlet flaw for RCE.
  • No public proof of concept exploit has been released, but attacker techniques and IoCs have been widely documented.

Indicators of Compromise and Remediation Actions

Key Indicators to Monitor

  • Network connections to or from the following IPs: 5.180.41.35 (primary C2), 38.60.157.212, 64.177.69.57, 104.243.35.0/24, 216.152.151.204, 104.243.35.63, and others listed by PTC.
  • Presence of hex-named JSP files under Windchill’s login directory (for example, /Windchill/login/7c0a0a34c9d8d53b.jsp).

PTC maintains a living list of IoCs on its trust centre and eSupport portals. Organisations should conduct targeted hunts for these indicators, especially on any internet-facing PLM systems or those with supplier access.

Why This Breach Matters to UK Businesses

UK manufacturing, engineering, and retail firms using PTC Windchill or FlexPLM, or relying on suppliers who do, are at risk of intellectual property and design data theft. Even if your own systems are not directly exposed, a supplier compromise could leak data hosted in their PLM environment. The scale of the breach and the targeting of high-value product data underscore the need for urgent action.

What Should Organisations Do Now?

  • Immediately verify the exposure of Windchill or FlexPLM systems to the internet.
  • Apply all patches and mitigations provided in PTC’s trust centre and eSupport CS473270.
  • Conduct threat hunts for the listed IoCs, especially suspicious JSP files and C2 connections.
  • Engage with suppliers to confirm their PLM security posture and potential data exposure.

Continued vigilance is essential as threat actors may shift tactics or target unpatched systems. Monitor vendor advisories and national CERT alerts for updates.

Originally reported by Unknown.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call