CISA orders three-day fix as Clop hits PTC Windchill flaw
A critical bug in PTC's product design software, CVE-2026-12569, is being used by the Clop extortion crew to steal corporate data. Regulators in the US and Germany moved fast.

Key points
- Clop, a criminal group that steals company files and demands payment, is exploiting CVE-2026-12569, a critical flaw in PTC Windchill and FlexPLM rated 9.3 out of 10.
- PTC began issuing patches on 17 June and warned customers of "heightened threat activity" on 26 June.
- The US Cybersecurity and Infrastructure Security Agency added the bug to its Known Exploited Vulnerabilities catalog and gave federal agencies three days to fix it.
- Germany's Federal Office for Information Security phoned and emailed PTC customers overnight urging them to patch.
- PTC says its software is used by more than 30,000 customers, including over 1,500 brand and retail firms on FlexPLM.
A fresh extortion wave is hitting companies that design physical products, from aircraft parts to clothing lines, through a flaw in software most people have never heard of.
The victim software is PTC Windchill and PTC FlexPLM. Both are what the industry calls Product Lifecycle Management systems, essentially the digital filing cabinets where engineers keep every drawing, part list and supplier detail for a product from first sketch to factory floor. Aerospace, defence, car makers, medical device firms and large retailers all rely on them.
The bug carries the identifier CVE-2026-12569. It is an unsafe deserialization flaw, meaning the software can be tricked into running attacker-supplied code while processing incoming data. No password is required. Security firm ReliaQuest, which flagged the active exploitation, rates it 9.3 out of 10 on the standard severity scale.
Who is behind the attacks?
ReliaQuest attributes the campaign, with caveats, to the Clop ransomware gang. Its analysts say the techniques match earlier Clop operations against enterprise file-transfer and business platforms, though the group has not been definitively confirmed as the operator here.
Once inside, the attackers plant a JSP web shell, a small hidden script on the server that lets them run commands and pull data out at will. From there they take sensitive product files and send extortion emails demanding payment. BleepingComputer reports the current shakedown notes come from support@cryptohox.com, one of several new addresses Clop has rotated through.
What are regulators telling companies to do?
Patch now, and assume you may already be breached. PTC started shipping fixes on 17 June and followed with a heightened-threat warning on 26 June. CISA then added the flaw to its Known Exploited Vulnerabilities catalog and gave US federal civilian agencies three days to remediate, an unusually short deadline under Binding Operational Directive 22-01.
German authorities were just as forceful. The Federal Office for Information Security, known as the BSI, called and emailed PTC customers in the middle of the night to push them to patch. Berlin took the same posture in March around an earlier Windchill bug, CVE-2026-4681.
ReliaQuest advises customers to apply PTC's patch, put Windchill and FlexPLM behind a VPN or access gateway rather than exposing them to the open internet, and, if there are signs of intrusion, isolate the server, preserve forensic evidence and reset any credentials that may have been exposed.
Key facts
| Item | Detail |
|---|---|
| Vulnerability | CVE-2026-12569, unsafe deserialization, CVSS 9.3 |
| Affected products | PTC Windchill, PTC FlexPLM |
| First patch released | 17 June |
| PTC threat warning | 26 June |
| CISA remediation deadline | 3 days for federal agencies |
| Suspected actor | Clop (Cl0p) |
| PTC customer base | 30,000+ globally, 1,500+ on FlexPLM |
Why this matters beyond the IT team
Clop has a long record of mass-exploitation campaigns against business software: Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U, Cleo and MOVEit Transfer, the last of which affected more than 2,770 organisations. Since August 2025 the group has also worked through an Oracle E-Business Suite zero-day, hitting Harvard University, The Washington Post, Logitech, Estée Lauder, Korean Air and Envoy Air, among others.
Stolen data typically ends up on Clop's dark web leak site if a ransom is refused. The US State Department is offering a $10 million reward for information tying the group to a foreign government.



