The recent exploitation of a zero day in PTC’s Product Lifecycle Management (PLM) suite by the Clop ransomware group has resulted in a significant data breach, impacting dozens of high-profile organisations. The attack leveraged a critical vulnerability in Windchill PDMLink and FlexPLM, enabling unauthenticated remote code execution (RCE) and large-scale data theft. This article examines the event in detail, including affected products, how the attack unfolded, and what UK businesses need to know now.
Clop’s Target: PTC Windchill and FlexPLM Zero Day Attack
In late July and August 2026, security researchers and national CERTs reported that the Russia-linked Clop (or Cl0p) group exploited a zero day flaw in PTC’s flagship PLM platforms. The vulnerability, now tracked as CVE 2026 12569, affects both Windchill PDMLink and FlexPLM, widely used by manufacturers, engineering firms, and retailers to manage product data and lifecycles.
Clop’s campaign used the flaw to breach exposed PLM servers, deploy web shells, and exfiltrate sensitive engineering and product information. Notably, organisations named as victims include Shell, Philips, and General Electric, with Shell and others confirming investigations into Clop’s claims of data theft. Reports suggest as many as 50 companies worldwide may have been affected, highlighting the broad impact of this attack vector.
Vulnerability Details: CVE 2026 12569 and Attack Chain
The exploited vulnerability is a critical RCE issue caused by deserialization of untrusted data in Windchill and FlexPLM. This flaw enables attackers to execute arbitrary code on unpatched PLM servers without any authentication, making it especially dangerous for internet-exposed systems.
- Root cause: Improper input validation leads to deserialization of attacker-controlled data, allowing code execution.
- CVSS: Assigned a base score of 10.0, reflecting maximum severity.
The observed attack chain involves two key steps:
- Information disclosure via FlexPLM WSDL endpoint provided attackers with material to target the next step.
- Windchill login servlet exploitation enabled unauthenticated RCE, letting attackers deploy JSP web shells under the Windchill login path.
Once inside, Clop affiliates used these web shells for remote command execution, file system enumeration, and exfiltration of high-value design and project data for double extortion. PTC and security advisories confirm active use of this chain in the wild, with victims later listed on Clop’s leak site.
Timeline of the Clop PLM Data Breach Operation
- 26 March 2026: PTC issues an initial advisory for a critical Windchill and FlexPLM vulnerability, with mitigations while patches are developed. Early advisories reference CVE 2026 4681.
- 17-18 June 2026: PTC releases updates and patches, reclassifying the main vulnerability as CVE 2026 12569. National Vulnerability Database (NVD) entries confirm unauthenticated RCE via deserialization.
- 25-29 June 2026: CISA adds CVE 2026 12569 to the Known Exploited Vulnerabilities catalog. Reports emerge of active web shell deployment on unpatched Windchill servers.
- 24-25 July 2026: Public reporting directly links ongoing exploitation to Clop affiliates. Technical details of the attack chain and indicators of compromise (IoCs) are released in a coordinated advisory. National CERTs and media issue alerts.
- 12-15 August 2026: Clop lists dozens of breached organisations, including Shell, GE, and Philips, on its leak site. Press coverage and company investigations follow.
Throughout this period, PTC maintained rolling updates via its trust centre and eSupport articles, providing IoCs, patch guidance, and mitigation steps. Customers are urged to consult these resources for the latest remediation information.
Affected Products, Versions, and Exploitation Status
Products and Versions in Scope
- PTC Windchill PDMLink: Versions 11.0_M030, 11.1_M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0, 13.1.1.0, 13.1.2.0, 13.1.3.0 and older releases before 11.0 M030.
- PTC FlexPLM: Versions 11.0_M030, 11.1_M020, 11.2.1.0, 12.0.0.0, 12.0.2.0, 12.0.3.0, 12.1.2.0, 12.1.3.0, 13.0.2.0, 13.0.3.0 and older releases before 11.0 M030.
All CPS (Critical Patch Set) versions are in scope. For the full list of affected products and remediation instructions, refer to PTC’s eSupport article CS473270.
Current Exploitation and Threat Activity
- Active exploitation confirmed, with CISA listing CVE 2026 12569 as a known exploited vulnerability.
- Public indicators of compromise include specific attacker IPs and web shell file paths (for example, /Windchill/login/7c0a0a34c9d8d53b.jsp).
- Clop affiliates used a sophisticated pre-authentication chain, combining a FlexPLM WSDL leak and Windchill login servlet flaw for RCE.
- No public proof of concept exploit has been released, but attacker techniques and IoCs have been widely documented.
Indicators of Compromise and Remediation Actions
Key Indicators to Monitor
- Network connections to or from the following IPs: 5.180.41.35 (primary C2), 38.60.157.212, 64.177.69.57, 104.243.35.0/24, 216.152.151.204, 104.243.35.63, and others listed by PTC.
- Presence of hex-named JSP files under Windchill’s login directory (for example, /Windchill/login/7c0a0a34c9d8d53b.jsp).
PTC maintains a living list of IoCs on its trust centre and eSupport portals. Organisations should conduct targeted hunts for these indicators, especially on any internet-facing PLM systems or those with supplier access.
Why This Breach Matters to UK Businesses
UK manufacturing, engineering, and retail firms using PTC Windchill or FlexPLM, or relying on suppliers who do, are at risk of intellectual property and design data theft. Even if your own systems are not directly exposed, a supplier compromise could leak data hosted in their PLM environment. The scale of the breach and the targeting of high-value product data underscore the need for urgent action.
What Should Organisations Do Now?
- Immediately verify the exposure of Windchill or FlexPLM systems to the internet.
- Apply all patches and mitigations provided in PTC’s trust centre and eSupport CS473270.
- Conduct threat hunts for the listed IoCs, especially suspicious JSP files and C2 connections.
- Engage with suppliers to confirm their PLM security posture and potential data exposure.
Continued vigilance is essential as threat actors may shift tactics or target unpatched systems. Monitor vendor advisories and national CERT alerts for updates.
Originally reported by Unknown.







