PTC Windchill & FlexPLM RCE
What is the Attack? A critical unauthenticated remote code execution (RCE) vulnerability affecting PTC Windchill PDMlink and PTC FlexPLM is being actively exploited by Cl0p ransomware affiliates. The attackers are targeting vulnerable Internet-facing Product Lifecycle Management (PLM) systems to deploy web shells, steal intellectual property, and carry out double-extortion ransomware attacks. The campaign chains a…
|
What is the Attack? |
A critical unauthenticated remote code execution (RCE) vulnerability affecting PTC Windchill PDMlink and PTC FlexPLM is being actively exploited by Cl0p ransomware affiliates. The attackers are targeting vulnerable Internet-facing Product Lifecycle Management (PLM) systems to deploy web shells, steal intellectual property, and carry out double-extortion ransomware attacks. The campaign chains a pre-authentication information disclosure vulnerability in the FlexPLM endpoint with CVE-2026-12569 to achieve unauthenticated remote code execution. Following compromise, attackers deploy JSP web shells, perform file system discovery, exfiltrate sensitive information, and ultimately issue ransom demands to affected organizations. |
|
What is the recommended Mitigation? |
Organizations using PTC Windchill or FlexPLM should: |
|
What FortiGuard Coverage is available? |
• FortiGuard IPS Service helps detect and block exploitation attempts targeting vulnerable PTC Windchill PDMlink and FlexPLM servers before attackers can gain remote code execution. |
