YogSotho[verified]@YogSoth0Disclosure
The post announces CVE‑2026‑12569 for Windchill, FlexPLM, and CPS, describing a Java deserialization RCE and listing affected versions, but no PoC, exploit code, or mitigation is provided.
ReliaQuest Threat Research[verified]@ReliaQuestTRActive Exploitation
ReliaQuest uncovered a custom Clop web shell that exploits CVE‑2026‑12569 on PTC Windchill, detailing its data‑theft capabilities and urging immediate patching, indicating active exploitation in the wild.
Hunt.io[verified]@HuntioActive Exploitation
Cl0p ransomware exploited the critical RCE flaw CVE‑2026‑12569 in PTC Windchill, infecting over 40 organizations with a custom web shell, demonstrating active exploitation in the wild.
ReliaQuest Threat Research[verified]@ReliaQuestTRActive Exploitation
ReliaQuest reports active exploitation of CVE-2026-12569, an unsafe deserialization vulnerability in PTC Windchill and FlexPLM, enabling remote code execution and web shell deployment, and offers immediate mitigations including a vendor patch.
Dark Web Intelligence[verified]@DailyDarkWebActive Exploitation
Clop is actively exploiting CVE-2026-12569 against PTC Windchill/FlexPLM, deploying JSP webshells and extorting victims.
ReliaQuest Threat Research[verified]@ReliaQuestTRActive Exploitation
The text reports that Cl0p is actively exploiting CVE-2026-12569 in PTC Windchill, detailing webshell behavior, custom authentication, server-side code execution via a Java class loader and credential theft, indicating an urgent threat.
CTI Academy[verified]@CTIAcademyActive Exploitation
Clop ransomware is actively exploiting CVE‑2026‑12569 in PTC Windchill with a custom JSP web shell that extracts keystore credentials, prompting inclusion in CISA's KEV and a three‑day patch mandate.
piyokango[verified]@piyokangoActive Exploitation
The announcement confirms CVE‑2026‑12569 and CVE‑2026‑20230 are added to CISA’s known‑exploited catalog, with evidence of in‑the‑wild attacks, partial PoC disclosures, and references to vendor patches.