started · updated
Cl0p ransomware targets 50 companies via PTC Windchill vulnerability
The Cl0p ransomware group has claimed responsibility for targeting nearly 50 major international corporations, including Shell, Philips, General Electric, and Fiserv, by exploiting a critical vulnerability in PTC software.
The vulnerability, identified as CVE-2026-12569, affects PTC Windchill and FlexPLM systems used by industrial enterprises to manage design drawings. The flaw carries a CVSS score of 9.8, allowing attackers to perform unauthorized remote code execution without credentials. The attack vector involves an unauthenticated access point via the WSDL endpoint of FlexPLM, followed by insecure deserialization of Java objects in the login servlet.
PTC released patches for the vulnerability on June 17, 2026, and reported persistent hostile activity by June 25. However, extortion emails sent by Cl0p were reportedly distributed around July 19 and 20. While Philips confirmed a compromised internal server, Fiserv stated it found no evidence of leaked customer data. Censys reported that fewer than 100 Windchill servers were exposed to the internet at the time of the incident.
Entities
Cl0p · General Electric · PTC · Philips · Shell