The cybercriminal group Cl0p has exploited vulnerability CVE-2026-12569 in PTC Windchill and FlexPLM manufacturing software. Security researchers at Ransomware-ISAC have documented and published details of the exploitation.
The Clop ransomware gang is conducting a data theft extortion campaign targeting internet-exposed instances of PTC Windchill and FlexPLM product lifecycle management systems. The attackers are attempting to steal data and extort affected organizations.