Skip to content

PTC Windchill and FlexPLM (CVE-2026-12569)

CVE-2026-12569CWE-502CWE-20OWASP A08:2021CVSS 9.8Updated October 1, 20264 min read

CVE-2026-12569 is an insecure deserialization flaw in PTC Windchill PDMLink and FlexPLM that lets an unauthenticated attacker run code on the server. Attackers most likely exploited it as a zero-day from early June 2026 to plant web shells and steal engineering data. Researchers link the campaign to the Cl0p group, which extorted its victims with the data instead of encrypting it.

Affected
Windchill PDMLink up to 13.1.3.0 and FlexPLM up to 13.0.3.0, including older releases and all CPS versions (full list in PTC CS473270)
Patched in
PTC patches per release line from 18 June 2026 (CS473270), followed by the security patches of 14 July 2026 (SUPs 13.1.2 and 13.1.3, CPSXB patches for older lines)
Actively exploited
yes

In June 2026 PTC warned of a critical flaw in Windchill and FlexPLM, the systems in which manufacturers keep their product designs. By then attackers were most likely already inside. In Germany the BSI, tipped off about impending attacks by a partner authority, phoned Windchill customers at night (one call came at 2:30 a.m.), heise reported. Two months later the Cl0p group began naming the companies it claimed to have robbed.

What is CVE-2026-12569

Windchill PDMLink and FlexPLM are PTC’s product lifecycle management (PLM) platforms. Manufacturers use Windchill to store engineering data and product designs; FlexPLM serves retail and consumer brands. The flaw is an insecure deserialization: the server rebuilt Java objects from data sent by a visitor who had not logged in, and a crafted payload made it run code. That is remote code execution without a password. NVD rates it 9.8 under CVSS v3.1; PTC itself only published a CVSS v4.0 score of 9.3.

The CVE record lists Windchill PDMLink from releases before 11.0 M030 up to 13.1.3.0, FlexPLM up to 13.0.3.0, and all CPS versions. PTC keeps the exact list in eSupport article CS473270, behind a customer login. It published remediation steps on 17 June, patches per release line on 18 and 19 June and further security patches on 14 July. Its interim workaround was a Java serialization filter, a standard mitigation for this class of flaw.

What the attackers did

Ransom-ISAC suspects that Cl0p affiliates “most likely” exploited the flaw as a zero-day in early June 2026, before any advisory existed. The indicators PTC published from 18 June show what followed: JSP web shells with hexadecimal names in the Windchill login directory, controlled through a custom HTTP header. According to Ransom-ISAC, the attackers combined the flaw with a separate information leak in a FlexPLM WSDL endpoint. On 25 June PTC reported “heightened threat activity”, and CISA added the flaw to its catalogue of exploited vulnerabilities, marking ransomware use as known.

From 20 July Ransom-ISAC saw extortion e-mails titled “Windchill PDMLink module serious data leak” reach hundreds of employees per affected organisation. In mid-August Cl0p named more than 40 alleged victims on its leak site, among them Shell and Philips, according to BleepingComputer. Philips said in a statement shared with Reuters that it had “identified and contained an attempted cybersecurity compromise” of an enterprise server; Shell said it was investigating a “potential incident”. As of 1 October 2026 the most recent indicators from PTC date from 26 August, and no new exploitation has been publicly confirmed since.

ReliaQuest analysed the web shell in August and describes a tool built for Windchill: it decrypts the credentials in the Windchill keystore, including the LDAP manager password, writes an inventory of the file vault to flst.txt and loads additional Java code straight into memory. ReliaQuest considers it “highly likely” that Cl0p is behind it. No government agency has publicly named the attacker.

Why a PLM server is a crown jewel

Many organisations treat PLM as an engineering tool rather than as critical infrastructure. This campaign shows the cost of that view. A Windchill server holds the designs and drawings that make up a manufacturer’s intellectual property, and it is wired into the corporate directory. ReliaQuest warns that the LDAP credentials in its keystore can turn one compromised application into an enterprise-wide credential compromise.

The extortion model makes detection harder. Cl0p is a ransomware group, yet in the reported attacks nothing was encrypted and nothing stopped working, so nothing forced an incident response. For organisations that missed the indicators, the first sign could be an extortion e-mail to their staff, weeks after the break-in. Cl0p ran the same playbook against MOVEit Transfer in 2023. Patching in June closed the door, but it did not tell anyone whether someone had already walked through it.

What to do now

  • Install PTC’s patch for your release line via CS473270, including the security patches of 14 July 2026. On 20 August PTC added two further deserialization-related flaws, CVE-2026-77645 and CVE-2026-77646, to the same advisory; make sure you are covered for those too.
  • Do not stop at patching. If the server was reachable from the internet, search back to early June for POST requests to /Windchill/login/*.jsp, unfamiliar JSP files under codebase/login, flst.txt and the X-windchill-req header.
  • On any sign of compromise, rotate the LDAP manager password and every other credential in the Windchill keystore, and check where else those accounts are used.
  • Take Windchill and FlexPLM off the open internet. A VPN or access gateway in front of them removes most of the attack surface.
  • Have internet-facing business applications tested, not just the website. Deserialization flaws are standard ground in a penetration test.

Sources

Frequently asked questions

Is patching enough?

No. The attacks most likely started before PTC's advisory of 17 June 2026. If your Windchill or FlexPLM server was reachable from the internet, hunt for web shells back to early June and, on any sign of compromise, rotate the credentials stored in the Windchill keystore, starting with the LDAP manager password.

Was ransomware involved?

Cl0p is a ransomware group and CISA lists the flaw as used in ransomware campaigns, but the reported attacks involved data theft and extortion e-mails, not encryption. It is the same model Cl0p used against MOVEit Transfer and Oracle E-Business Suite.

How do I know if we were hit?

PTC's indicators are concrete: POST requests to /Windchill/login/*.jsp, which legitimate Windchill traffic never sends, JSP files with hexadecimal names in the codebase/login directory, a file called flst.txt, and requests carrying an X-windchill-req header. The advisory also lists the attackers' IP addresses and file hashes.

Related articles

Press / to search · Esc