← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 21, 2026 · 07:15via Security Affairs

Cl0p Targets 40+ Organizations Through PTC Windchill Flaw

Brief

Cl0p claims over 40 organizations fell victim to attacks exploiting a PTC Windchill and FlexPLM vulnerability.

Cl0p is using a familiar strategy again: exploit one flaw in enterprise software to attack many companies, then publish the victims’ names if they refuse to pay. The group claims it has targeted more than 40 organizations through a vulnerability in PTC’s Windchill and FlexPLM platforms, which manufacturers and engineering companies use to manage product and design data.

CVE-2026-12569 (CVSS score of 9. 3) is a critical remote code execution (RCE) vulnerability in PTC Windchill PDMlink and PTC FlexPLM. An attacker can exploit this vulnerability through the deserialization of untrusted data. The flaw impacts all CPS versions and Windchill and FlexPLM releases prior to 11. 0 M030.

In June, the U. S.

Read more on Security Affairs