CVE-2026-12569Active Exploitation(ptc / flexplm)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 15 mentions and remains active

Immediate actions

  • Patch ptc flexplm systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-06-28. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-20CWE-502

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flexplm
  • windchill_pdmlink

Threat summary

  • Active exploitation appears in 136 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 162 mentions across 44 observed days

What's happening

  • Active exploitation reported across 136 signals
  • Exploit tool or code specified in 11 signals
  • PoC mentioned or linked in 21 signals
  • Patch or workaround mentioned in 64 signals
  • Technical details provided in 98 signals
  • Disclosure: 9 classified signals
  • Peaked 6d ago at 15 mentions (2026-08-19); latest day: 1
  • 162 total mentions across 44 days

Affected systems

Vendors
Products
flexplmwindchill_pdmlink

13 versions affected across 2 products

Deep dive

Activity timeline162 mentions / 44d
0481115Mentions · 2026-06-23: 1Mentions · 2026-06-24: 1Mentions · 2026-06-25: 2Mentions · 2026-06-26: 12Mentions · 2026-06-27: 8Mentions · 2026-06-29: 6Mentions · 2026-06-30: 5Mentions · 2026-07-01: 3Mentions · 2026-07-03: 2Mentions · 2026-07-06: 2Mentions · 2026-07-07: 1Mentions · 2026-07-09: 1Mentions · 2026-07-14: 1Mentions · 2026-07-16: 2Mentions · 2026-07-17: 5Mentions · 2026-07-22: 1Mentions · 2026-07-23: 1Mentions · 2026-07-24: 8Mentions · 2026-07-25: 9Mentions · 2026-07-26: 6Mentions · 2026-07-27: 6Mentions · 2026-07-28: 2Mentions · 2026-07-29: 4Mentions · 2026-07-30: 2Mentions · 2026-07-31: 4Mentions · 2026-08-02: 1Mentions · 2026-08-03: 1Mentions · 2026-08-05: 3Mentions · 2026-08-06: 7Mentions · 2026-08-07: 1Mentions · 2026-08-10: 3Mentions · 2026-08-13: 1Mentions · 2026-08-14: 3Mentions · 2026-08-15: 3Mentions · 2026-08-16: 4Mentions · 2026-08-17: 3Mentions · 2026-08-18: 8Mentions · 2026-08-19: 15Mentions · 2026-08-20: 3Mentions · 2026-08-21: 4Mentions · 2026-08-22: 2Mentions · 2026-08-23: 2Mentions · 2026-08-25: 2Mentions · 2026-08-27: 1PoC Mentioned / Linked · 2026-06-26: 1PoC Mentioned / Linked · 2026-06-29: 1PoC Mentioned / Linked · 2026-07-03: 1PoC Mentioned / Linked · 2026-07-06: 1PoC Mentioned / Linked · 2026-07-09: 1PoC Mentioned / Linked · 2026-07-23: 1PoC Mentioned / Linked · 2026-07-25: 2PoC Mentioned / Linked · 2026-07-29: 1PoC Mentioned / Linked · 2026-08-18: 5PoC Mentioned / Linked · 2026-08-19: 4PoC Mentioned / Linked · 2026-08-20: 1PoC Mentioned / Linked · 2026-08-21: 2Exploit Tool / Code · 2026-07-01: 1Exploit Tool / Code · 2026-07-17: 1Exploit Tool / Code · 2026-07-24: 1Exploit Tool / Code · 2026-08-18: 3Exploit Tool / Code · 2026-08-19: 3Exploit Tool / Code · 2026-08-20: 1Exploit Tool / Code · 2026-08-21: 1Active Exploitation · 2026-06-25: 1Active Exploitation · 2026-06-26: 11Active Exploitation · 2026-06-27: 4Active Exploitation · 2026-06-29: 6Active Exploitation · 2026-06-30: 5Active Exploitation · 2026-07-01: 2Active Exploitation · 2026-07-03: 2Active Exploitation · 2026-07-06: 2Active Exploitation · 2026-07-09: 1Active Exploitation · 2026-07-16: 1Active Exploitation · 2026-07-17: 1Active Exploitation · 2026-07-22: 1Active Exploitation · 2026-07-23: 1Active Exploitation · 2026-07-24: 8Active Exploitation · 2026-07-25: 9Active Exploitation · 2026-07-26: 5Active Exploitation · 2026-07-27: 5Active Exploitation · 2026-07-28: 2Active Exploitation · 2026-07-29: 4Active Exploitation · 2026-07-30: 2Active Exploitation · 2026-07-31: 4Active Exploitation · 2026-08-02: 1Active Exploitation · 2026-08-03: 1Active Exploitation · 2026-08-05: 3Active Exploitation · 2026-08-06: 7Active Exploitation · 2026-08-07: 1Active Exploitation · 2026-08-10: 1Active Exploitation · 2026-08-13: 1Active Exploitation · 2026-08-14: 2Active Exploitation · 2026-08-15: 2Active Exploitation · 2026-08-16: 4Active Exploitation · 2026-08-17: 3Active Exploitation · 2026-08-18: 7Active Exploitation · 2026-08-19: 13Active Exploitation · 2026-08-20: 3Active Exploitation · 2026-08-21: 4Active Exploitation · 2026-08-22: 2Active Exploitation · 2026-08-23: 1Active Exploitation · 2026-08-25: 2Active Exploitation · 2026-08-27: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-06-24: 1Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-06-26: 9Patch / Workaround · 2026-06-27: 4Patch / Workaround · 2026-06-29: 2Patch / Workaround · 2026-06-30: 4Patch / Workaround · 2026-07-03: 1Patch / Workaround · 2026-07-09: 1Patch / Workaround · 2026-07-22: 1Patch / Workaround · 2026-07-24: 2Patch / Workaround · 2026-07-25: 5Patch / Workaround · 2026-07-26: 3Patch / Workaround · 2026-07-27: 3Patch / Workaround · 2026-07-28: 1Patch / Workaround · 2026-07-29: 1Patch / Workaround · 2026-07-30: 1Patch / Workaround · 2026-07-31: 2Patch / Workaround · 2026-08-02: 1Patch / Workaround · 2026-08-03: 1Patch / Workaround · 2026-08-10: 1Patch / Workaround · 2026-08-13: 1Patch / Workaround · 2026-08-14: 1Patch / Workaround · 2026-08-15: 2Patch / Workaround · 2026-08-16: 3Patch / Workaround · 2026-08-17: 2Patch / Workaround · 2026-08-18: 3Patch / Workaround · 2026-08-19: 3Patch / Workaround · 2026-08-20: 1Patch / Workaround · 2026-08-21: 1Patch / Workaround · 2026-08-25: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-24: 1Technical Details · 2026-06-25: 2Technical Details · 2026-06-26: 10Technical Details · 2026-06-27: 6Technical Details · 2026-06-29: 3Technical Details · 2026-06-30: 4Technical Details · 2026-07-01: 2Technical Details · 2026-07-03: 2Technical Details · 2026-07-07: 1Technical Details · 2026-07-09: 1Technical Details · 2026-07-14: 1Technical Details · 2026-07-16: 1Technical Details · 2026-07-17: 3Technical Details · 2026-07-22: 1Technical Details · 2026-07-23: 1Technical Details · 2026-07-24: 5Technical Details · 2026-07-25: 7Technical Details · 2026-07-26: 6Technical Details · 2026-07-27: 2Technical Details · 2026-07-28: 1Technical Details · 2026-07-29: 2Technical Details · 2026-07-30: 2Technical Details · 2026-07-31: 4Technical Details · 2026-08-02: 1Technical Details · 2026-08-03: 1Technical Details · 2026-08-10: 1Technical Details · 2026-08-13: 1Technical Details · 2026-08-15: 2Technical Details · 2026-08-16: 1Technical Details · 2026-08-17: 1Technical Details · 2026-08-18: 5Technical Details · 2026-08-19: 8Technical Details · 2026-08-20: 1Technical Details · 2026-08-21: 2Technical Details · 2026-08-22: 1Technical Details · 2026-08-23: 2Technical Details · 2026-08-25: 1Technical Details · 2026-08-27: 106-2306-2707-0307-1407-2307-2707-3108-0608-1408-1808-2208-27
Signal classification5 categories
Active Exploitation
13382.1%
Patch
95.6%
Disclosure
95.6%
General
74.3%
Exploit
42.5%
Referenced assets113 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-231
Patch1
2026-06-241
Patch1
2026-06-252
Active Exploitation1Patch1
2026-06-2612
Active Exploitation11Disclosure1
2026-06-278
Active Exploitation4Disclosure1Patch3
2026-06-296
Active Exploitation6
2026-06-305
Active Exploitation5
2026-07-013
Active Exploitation2Disclosure1
2026-07-032
Active Exploitation2
2026-07-062
Active Exploitation2
2026-07-071
Disclosure1
2026-07-091
Active Exploitation1
2026-07-141
General1
2026-07-162
Active Exploitation1Disclosure1
2026-07-175
Active Exploitation1Disclosure2Exploit1General1
2026-07-221
Active Exploitation1
2026-07-231
Active Exploitation1
2026-07-248
Active Exploitation8
2026-07-259
Active Exploitation9
2026-07-266
Active Exploitation5Patch1
2026-07-276
Active Exploitation4General1Patch1
2026-07-282
Active Exploitation2
2026-07-294
Active Exploitation4
2026-07-302
Active Exploitation2
2026-07-314
Active Exploitation4
2026-08-021
Active Exploitation1
2026-08-031
Active Exploitation1
2026-08-053
Active Exploitation3
2026-08-067
Active Exploitation7
2026-08-071
Active Exploitation1
2026-08-103
Active Exploitation1General2
2026-08-131
Active Exploitation1
2026-08-143
Active Exploitation2General1
2026-08-153
Active Exploitation2Patch1
2026-08-164
Active Exploitation4
2026-08-173
Active Exploitation3
2026-08-188
Active Exploitation7Exploit1
2026-08-1915
Active Exploitation11Disclosure1Exploit2General1
2026-08-203
Active Exploitation3
2026-08-214
Active Exploitation4
2026-08-222
Active Exploitation2
2026-08-232
Active Exploitation1Disclosure1
2026-08-252
Active Exploitation2
2026-08-271
Active Exploitation1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Attackers are exploiting a critical PTC flaw to drop JSP web shells. CISA added CVE-2026-12569 to its KEV catalog after active exploitation was confirmed. — Affected: PTC Windchill PDMlink and FlexPLM. — Patch now. Hunt for IoCs. Read more: https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html

    Post summary

    CISA confirmed CVE-2026-12569 is actively exploited, with attackers deploying JSP web shells on PTC Windchill systems. A patch has been released and users are urged to hunt for indicators of compromise.

    515361924.9K
    2.2M followersView on X
  • YogSotho@YogSoth0
    Disclosure

    #CVE-2026-12569 — Advanced Exploit Kit #PTC #Windchill / #FlexPLM#Java Deserialization #RCE Affected Versions: | Product | Affected versions | |---------|-------------------| | Windchill PDMLink | 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0, 13.1.1.0, 13.1.2.0, 13.1.3.0 | | FlexPLM | 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.0.0, 12.0.2.0, 12.0.3.0, 12.1.2.0, 12.1.3.0, 13.0.2.0, 13.0.3.0 | | CPS | All versions | #security #hacking #exploit #0days #vulnerability #antisec

    Post summary

    The post announces CVE‑2026‑12569 for Windchill, FlexPLM, and CPS, describing a Java deserialization RCE and listing affected versions, but no PoC, exploit code, or mitigation is provided.

    17042142.9K
    1.8K followersView on X
  • ReliaQuest Threat Research@ReliaQuestTR
    Active Exploitation

    🚨 ReliaQuest discovered a custom web shell highly likely linked to Clop, deployed following exploitation of CVE-2026-12569 in PTC Windchill. Our analysis found that the implant is not a generic command shell, rather, it is a purpose-built data-theft and extortion platform developed with detailed knowledge of Windchill’s APIs, database schema, keystore, and file-vault structure. The web shell can map sensitive engineering files, read and transfer arbitrary data, and decrypt every credential stored in the Windchill keystore, including LDAP, administrative, and object-storage credentials. It also contains a custom Java class loader that can execute attacker-supplied code directly in memory, enabling follow-on activity such as lateral movement, persistence, ransomware deployment, and further data theft. The implant uses Windchill’s own application classes and database identity, delivers commands through the custom X-windchill-req HTTP header, and compresses responses with GZIP. These techniques allow its activity to resemble legitimate application traffic and reduce visibility across traditional network and database monitoring. Organizations should immediately patch CVE-2026-12569, hunt for suspicious JSP files in Windchill codebase directories, and rotate all credentials stored in the Windchill keystore on any server suspected of compromise. IOCs: 321e1fb01eb3462b48ff6ccdef132acc1182e3f7456548439f0d4ead12fd98bf 5.180.41[.]35 78.128.113[.]10 104.194.9[.]14 104.243.35[.]63 185.227.83[.]236 209.222.98[.]44 216.152.151[.]204 Read more: https://reliaquest.com/blog/clop-returns-with-custom-implant-in-mass-extortion-campaign

    Post summary

    ReliaQuest uncovered a custom Clop web shell that exploits CVE‑2026‑12569 on PTC Windchill, detailing its data‑theft capabilities and urging immediate patching, indicating active exploitation in the wild.

    018032103.9K
    7.8K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ Clop-linked Windchill web shell decrypts credentials and maps engineering data. Deployed after CVE-2026-12569 exploitation, the custom implant can extract LDAP and admin credentials and load Java payloads in memory. See what the implant can do: https://thehackernews.com/2026/08/clop-linked-windchill-web-shell.html

    Post summary

    The post confirms that CVE-2026-12569 is actively exploited, allowing Clop-linked Windchill implants to harvest LDAP/admin credentials and deliver in‑memory Java payloads.

    210036525.7K
    2.4M followersView on X
  • CISA Cyber@CISACyber
    Patch

    🛡️ ️We added PTC Windchill & FlexPLM improper input validation vulnerability CVE-2026-12569 and Cisco Unified Communications Manager vulnerability CVE-2026-20230 to our Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. https://t.co/q33CcWUk6w

    Post summary

    The tweet announces the addition of two CVEs to a catalog and urges users to follow a DHS link to apply mitigations, providing minimal product and vulnerability details.

    41113248.8K
    301.2K followersView on X
  • Unit 42@Unit42_Intel
    Active Exploitation

    We are monitoring exploitation of CVE-2026-12569, an RCE flaw documented in a PTC advisory from June 2026. Our analysis + third-party reports indicate these observed indicators align with activity attributed to Hazy Scorpius (behind CLOP ransomware): https://bit.ly/4xw6bPG https://t.co/gPvGDyCrGU

    Post summary

    The post indicates that CVE-2026-12569, an RCE flaw, is currently being exploited by actors linked to the CLOP ransomware family, though no PoC, exploit code, or patch details are provided.

    0702684.9K
    71.0K followersView on X
  • Hunt.io@Huntio
    Active Exploitation

    🚨 Cl0p Exploits PTC Windchill Flaw to Target 40+ Organizations https://securityaffairs.com/197587/cyber-crime/cl0p-targets-40-organizations-through-ptc-windchill-flaw.html The Cl0p ransomware group claims more than 40 organizations were hit via CVE-2026-12569, a critical RCE flaw in PTC Windchill and FlexPLM. The group used a custom web shell built for data theft, credential decryption, malware delivery, and follow-on access. Victims include major manufacturing and industrial firms, with stolen data ranging from project files and backups to engineering documents, blueprints, and databases. #ThreaIntel #Cl0p #Windchill #CyberSecurity

    Post summary

    Cl0p ransomware exploited the critical RCE flaw CVE‑2026‑12569 in PTC Windchill, infecting over 40 organizations with a custom web shell, demonstrating active exploitation in the wild.

    11101771.9K
    7.2K followersView on X
  • ReliaQuest Threat Research@ReliaQuestTR
    Active Exploitation

    ReliaQuest has observed threat actors actively exploiting CVE-2026-12569, a critical unsafe deserialization vulnerability (CVSS 9.3) affecting PTC Windchill and FlexPLM. Exploitation enables unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration. The actor behind these attacks remains unconfirmed. however, the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories. Immediate mitigations: 🔴 Apply PTC's vendor patch (CS473270) 🔴 Place Windchill and FlexPLM interfaces behind a VPN or trusted access gateway where possible 🔴 If exploitation is suspected, isolate the affected server, preserve forensic artifacts, and rotate exposed credentials before restoring service

    Post summary

    ReliaQuest reports active exploitation of CVE-2026-12569, an unsafe deserialization vulnerability in PTC Windchill and FlexPLM, enabling remote code execution and web shell deployment, and offers immediate mitigations including a vendor patch.

    0501511.6K
    7.8K followersView on X
  • Dark Web Intelligence@DailyDarkWeb
    Active Exploitation

    Clop launches a new mass data-theft campaign against PTC Windchill and FlexPLM The Clop extortion operation is targeting internet-exposed PTC Windchill and FlexPLM product-lifecycle-management systems. Researchers observed exploitation of CVE-2026-12569, a critical unauthenticated remote-code-execution vulnerability, followed by JSP webshell deployment and theft of sensitive product data. Clop-style extortion emails have been sent broadly within affected organizations, sometimes through previously compromised email accounts. #DDW #Vulnerability #Clop #ransomware

    Post summary

    Clop is actively exploiting CVE-2026-12569 against PTC Windchill/FlexPLM, deploying JSP webshells and extorting victims.

    1201436.8K
    202.5K followersView on X
  • CTI Traffic@CTITraffic
    Active Exploitation

    Censys: Cl0p is exploiting CVE-2026-12569, a critical (CVSS 9.8) remote code execution flaw in PTC Windchill, likely as a zero-day, continuing its pattern of mass-exploiting enterprise back-office software. Extortion emails to victims began July 20. https://censys.com/blog/cl0p-targets-windchill/

    Post summary

    Cl0p is actively exploiting the CVE-2026-12569 RCE vulnerability in PTC Windchill, with extortion emails sent since July 20, indicating real‑world attacks are underway.

    030871.2K
    217 followersView on X
  • ReliaQuest Threat Research@ReliaQuestTR
    Active Exploitation

    Update on CVE-2026-12569 / Cl0p / PTC Windchill It is likely that Cl0p is actively exploiting CVE-2026-12569 in PTC Windchill. The deployed webshells use a custom HTTP header (X-windchill-req) as their authentication mechanism, running within Windchill's own process context to blend into legitimate application traffic, while spawning background SQL threads that enumerate the full Windchill file vault to map data ahead of exfiltration. A built-in custom Java class loader allows attackers to execute arbitrary compiled code server-side via Base64-encoded ZIPs, without ever modifying the webshell again. The webshell also harvests and decrypts LDAP credentials directly from Windchill's keystore, enabling follow-on access well beyond the initial foothold. Given Cl0p's history of rapid, widespread campaigns and the speed at which copycat actors replicate their techniques, organizations using PTC Windchill and PTC FlexPLM should treat this CVE with the highest priority.

    Post summary

    The text reports that Cl0p is actively exploiting CVE-2026-12569 in PTC Windchill, detailing webshell behavior, custom authentication, server-side code execution via a Java class loader and credential theft, indicating an urgent threat.

    1201121.2K
    7.8K followersView on X
  • CTI Academy@CTIAcademy
    Active Exploitation

    Clop is back in mass-exploitation mode. ReliaQuest has detailed a custom JSP web shell, highly likely Clop, dropped after exploiting CVE-2026-12569 (CVSS 9.3) in PTC Windchill and FlexPLM. Already in CISA's KEV with a three-day patch mandate. This is not a generic shell. It is purpose-built for Windchill's keystore, schema and file vault. One "S" command reads ieStructProperties.txt and decrypts the LDAP manager password plus every admin and site-admin key in the keystore to plaintext. Since LDAP governs AD, email and VPN, one app compromise becomes enterprise-wide credential loss. A built-in Java class loader runs bytecode in memory (no disk artifacts) as a reusable backdoor, and vault enumeration writes a ready-made theft map through Windchill's own DB identity. Commands hide in an X-windchill-req header with GZIP responses, so detection needs header logging + decompression + TLS inspection. Same playbook as DEWMODE (Accellion) and LEMURLOOT (MOVEit). Patch now, hunt JSP files in windchill/codebase/login, rotate the full keystore. #ThreatIntelligence #Ransomware #Clop #CVE

    Post summary

    Clop ransomware is actively exploiting CVE‑2026‑12569 in PTC Windchill with a custom JSP web shell that extracts keystore credentials, prompting inclusion in CISA's KEV and a three‑day patch mandate.

    03083308
    750 followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(6/25追加) 🛡CVE-2026-12569 ✅概要 ・深刻度:緊急 9.3 (CVSS Base) / PTC (CNA) ・種別:不適切な入力確認 (CWE-20) / 信頼できないデータのデシリアライゼーション (CWE-502) ・CVSS:CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/AU:Y/R:U/V:C/U:Red PTC Windchill PDMLink および PTC FlexPLM に存在するリモートコード実行の脆弱性です。 信頼できないデータのデシリアライゼーションを通じて悪用される可能性があります。 本脆弱性は、すべての CPS バージョン、および Windchill / FlexPLM 11.0 M030 以前のリリースにも影響します。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ✅攻撃前提条件 ・PTC Windchill PDMLink または PTC FlexPLM を使用している ・影響を受けるバージョンまたは CPS を使用している ・攻撃者が対象環境へネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・PTC が提供する修正パッチまたは緩和策が適用されていない ✅悪用時影響 ・リモートコード実行につながる可能性がある ・Windchill login ディレクトリ配下に JSP Web シェルを設置される可能性がある ・不正なコマンド実行やファイル一覧取得に悪用される可能性がある ・製品データや業務データへ不正アクセスされる可能性がある ・機密性、完全性、可用性に高い影響が生じる ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(PTC) PTC は、CVE-2026-12569 に関連して継続的な脅威活動を受けていると公表。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-12569 ・https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability ・https://www.ptc.com/en/support/article/CS473270 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/12xxx/CVE-2026-12569.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-12569 🛡CVE-2026-20230 Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability ✅概要 ・深刻度:重要 8.6 (CVSS Base) / Cisco Systems, Inc. (CNA) ・種別:サーバサイドのリクエストフォージェリ (CWE-918) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N Cisco Unified Communications Manager および Cisco Unified Communications Manager Session Management Edition に存在する SSRF の脆弱性です。 WebDialer サービスが有効な構成で、未認証のリモート攻撃者が細工した HTTP リクエストを送信することで悪用できる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ✅CISA 評価 ・攻撃自動化:自動化は困難 ・技術的影響:完全制御 ✅攻撃前提条件 ・Cisco Unified Communications Manager または Unified CM SME を使用している ・WebDialer サービスが有効である ・攻撃者が対象機器へネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・修正済みソフトウェアまたは Cisco 提供の修正が適用されていない ✅悪用時影響 ・SSRF により内部サービスへ不正アクセスされる可能性がある ・基盤 OS 上へファイルを書き込まれる可能性がある ・書き込まれたファイルを後続の root 権限昇格に利用される可能性がある ・Unified CM 環境を侵害される可能性がある ・音声・通信基盤の完全性に高い影響が生じる ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(Defused) Defused は、CVE-2026-20230 の悪用試行を観測し、WebDialer コンポーネントに対する file:// URI ペイロードにより /tmp/cve-2026-20230-test.txt のようなテストファイルを書き込む偵察活動を確認したと報告。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-20230 ・https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW ・https://github.com/cisagov/vulnrichment/blob/develop/2026/20xxx/CVE-2026-20230.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20230 ・https://denizhalil.com/2026/06/12/cve-2026-20230-cisco-unified-cm-ssrf/ ・https://www.kital.com.ph/cisco-unified-communications-vulnerability-reconnaissance/ https://www.cisa.gov/news-events/alerts/2026/06/25/cisa-adds-two-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The announcement confirms CVE‑2026‑12569 and CVE‑2026‑20230 are added to CISA’s known‑exploited catalog, with evidence of in‑the‑wild attacks, partial PoC disclosures, and references to vendor patches.

    0001116.9K
    44.1K followersView on X
  • Rahmi Demir ⭐⭐⭐⭐⭐@rahmid3mir
    Patch

    🪲 #GüvenlikBülteni #SiberGüvenlik: PTC Windchill ve FlexPLM Hatalı Girdi Doğrulama Zafiyeti (CVE-2026-12569) Merhaba #Brolyz 👉 Bülten Tarihi: 27 Haziran 2026 👉 Referans: CVE-2026-12569 / CISA BOD 26-04 👉 Etkilenen Sistemler: PTC Windchill ve FlexPLM 👉 Etki Seviyesi: KRİTİK (Hatalı Girdi Doğrulama / Rastgele Kod Çalıştırma) 👉 Son Aksiyon Tarihi: 28 Haziran 2026 📌 Özet PTC Windchill ve FlexPLM sistemlerinde, kimliği doğrulanmamış uzaktaki bir saldırganın zararlı istekler göndererek sistem üzerinde rastgele kod çalıştırmasına (RCE) olanak tanıyan hatalı girdi doğrulama (Improper Input Validation) zafiyeti tespit edilmiştir. Açık, 25 Haziran 2026 tarihinde CISA KEV listesine eklenmiştir. 🔍 Zafiyetin Teknik Detayları ve Risk Saldırı Vektörü: Kimlik doğrulaması gerektirmeyen uzaktaki bir saldırgan, ağ üzerinden gönderdiği zararlı isteklerle zafiyeti doğrudan istismar edebilir. İlgili Zayıflıklar (CWE): CWE-20 (Hatalı Girdi Doğrulama) ve CWE-502 (Güvensiz Verinin Serileştirmeden Çıkarılması - Deserialization). Fidye Yazılımı Durumu: Açığın fidye yazılımı kampanyalarında aktif olarak kullanıldığına dair doğrulanmış bir bilgi bulunmamaktadır. 🛡️ Çözüm ve Alınması Gereken Aksiyonlar Kurumsal sistemlerin güvenliği ve 28 Haziran 2026 son aksiyon tarihine uyum için aşağıdaki adımlar uygulanmalıdır: 1️⃣ Yama ve Mitigasyonları Uygulayın: Üretici tarafından yayımlanan güncellemeler ve hafifletici önlemler, CISA BOD 26-04 ve adli bilişim gereksinimleri doğrultusunda uygulanmalıdır. 2️⃣ Bulut ve İzolasyon: Bulut ortamlarında CISA rehberliği takip edilmeli; geçerli yama veya mitigasyon yoksa sistem geçici olarak devre dışı bırakılmalı ya da izole edilmelidir. 3️⃣ İnternet Maruziyetini Değerlendirin: Etkilenen sistemlerin dış erişimi gözden geçirilmeli ve BOD 26-04 kapsamındaki yama süreçleri gecikmeden tamamlanmalıdır.

    Post summary

    The bulletin discloses a critical RCE vulnerability in PTC Windchill and FlexPLM and recommends applying vendor patches and mitigations.

    03060283
    540 followersView on X
  • Megatron@TheM3gatr0n
    Exploit

    A web shell deployed by Clop during the exploitation of PTC Windchill instances. Deployed via a directory traversal vulnerability (CVE-2026-12569), the web shell runs inside the Java Virtual Machine (JVM) process space to decrypt administrative credentials, harvest active session tokens, and map target file vaults. The threat actor uses specialized custom HTTP headers (X-windchill-req) and GZIP compression to hide command-and-control communication from deep packet inspection. API Interactions: Command Run: java.exe -jar Windchill/codebase/WEB-INF/lib/[custom_loader].jar System Changes: C:\ptc\Windchill\codebase\**\* (exploited file drops) C:\ptc\Windchill\db\ (directory database and vault mapping) Attack Chain: [CVE-2026-12569 RCE Exploit] --> [JSP arbitrary file write] --> [Memory Loading of custom ClassLoader] --> [Web Shell Command Execution] --> [Credential Decryption and Vault Mapping] --> [GZIP Encrypted C2 Exfiltration] PTC Windchill system configuration extract and decrypt in Attachment @ReliaQuestTR #webshell #clop #ransomware #CyberSecurity #malware

    Post summary

    The excerpt details how the CVE-2026-12569 directory traversal flaw was actively exploited by Clop, deploying a Java‑based web shell that decrypts credentials, harvests tokens, and uses hidden GZIP‑based C2, with specific exploit commands and file paths supplied.

    01061537
    678 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2026-12569, a CVSS 9.3 unsafe deserialization flaw in PTC Windchill and FlexPLM, is actively exploited by Clop, now in CISA KEV. Attackers deploy JSP webshells to exfiltrate PLM data. #DFIR_Radar https://t.co/rkfTRkIHqP

    Post summary

    CVE-2026-12569 is a high‑severity unsafe deserialization issue in PTC Windchill and FlexPLM, actively exploited by Clop attackers using JSP webshells to exfiltrate PLM data, and is listed in the CISA KEV database.

    11041273
    1.9K followersView on X
  • Cyber_OSINT@Cyber_O51NT
    Active Exploitation

    Cl0p claims it attacked over 40 organizations by exploiting CVE-2026-12569 in PTC Windchill and FlexPLM, leveraging a custom data-thieving implant for extensive exfiltration and credential theft. https://securityaffairs.com/197587/cyber-crime/cl0p-targets-40-organizations-through-ptc-windchill-flaw.html

    Post summary

    Cl0p reports using CVE-2026-12569 to breach over 40 organizations, deploying a custom data‑thieving implant for credential theft and exfiltration, with no patch or mitigation identified.

    020311.2K
    22.9K followersView on X
  • ransomNews@ransomnews
    Active Exploitation

    ⚠️ Cl0p names 40 Windchill victims Cl0p exploited CVE-2026-12569 to deploy web shells and steal blueprints and project data. 🔗 read more: https://securityaffairs.com/197587/cyber-crime/cl0p-targets-40-organizations-through-ptc-windchill-flaw.html?utm_source=twitter&utm_medium=social&utm_campaign=fedica-Calendario-Editoriale #ransomNews #cyberthreats #Cl0p

    Post summary

    Cl0p has leveraged CVE‑2026‑12569 in PTC Windchill to deploy web shells against at least 40 victims, demonstrating ongoing exploitation.

    01040539
    3.6K followersView on X
  • Sudarshana@Sudarshana_io
    Active Exploitation

    Ask your team this week: is Windchill or FlexPLM exposed to the internet? Then prove it's clean. CVE-2026-12569 is unauth RCE via untrusted deserialization, live-exploited to drop JSP webshells at /Windchill/login/[hex].jsp. 'We patched it' is not 'we tested it.'

    Post summary

    The post reports that CVE-2026-12569 is actively exploited via unauthenticated deserialization, with a patch applied, yet confirmation of the patch’s effectiveness remains uncertain.

    00050463
    288 followersView on X
  • ボス@サイバーセキュリティの専門家@boss_sec_labo
    Active Exploitation

    AIエージェント8体が政府機関へ自律侵攻し、PLMのVaultが掘られ、WordPressがC2(攻撃指令サーバ)に化けた。 「対策済み」という言葉を信じる前に読め。 ・中国系攻撃者、AIエージェント8体でAPAC政府機関へ自律攻撃 ・ClopがPTC Windchill CVE-2026-12569(CVSS 9.3)悪用——JSPシェルでVaultを掘削 ・WordPressプラグインCVE-2026-15748(CVSS 9.8)、認証不要RCEで30万サイト危機 ・StopAndProtect、約2,000の侵害WordPressサイトをC2・マルウェア配信に転用 ・ジェックス、ランサムウェアによる不正アクセスで個人情報の一時閲覧を正式確認 ・サカタのタネ、不正アクセスで約5.7万件漏えいの可能性——侵入経路は特定済 攻撃者がAIを8体動かす時代に、君の現場はまだ人海戦術で守れているか。 WordPressが武器になり、PLMのVaultが掘られた今日—— ログの「異常なし」を信じる根拠を今すぐ声に出せ。

    Post summary

    Japanese report highlights AI‑driven attacks on APAC government agencies, with exploit of PTC Windchill and a WordPress plugin, showing active and widespread exploitation.

    01021572
    1.5K followersView on X
CPE platform detail19 entries

19 of 19 entries

PartVendorProductVersionTarget SWTarget HW
Appptcflexplm---
Appptcflexplm11.1m020--
Appptcflexplm11.2.1.0--
Appptcflexplm12.0.0.0--
Appptcflexplm12.0.2.0--
Appptcflexplm12.1.3.0--
Appptcflexplm13.0.2.0--
Appptcflexplm13.0.3.0--
Appptcwindchill_pdmlink---
Appptcwindchill_pdmlink11.0m030--
Appptcwindchill_pdmlink11.1m020--
Appptcwindchill_pdmlink11.2.1.0--
Appptcwindchill_pdmlink12.0.2.0--
Appptcwindchill_pdmlink12.1.2.0--
Appptcwindchill_pdmlink13.0.2.0--
Appptcwindchill_pdmlink13.1.0.0--
Appptcwindchill_pdmlink13.1.1.0--
Appptcwindchill_pdmlink13.1.2.0--
Appptcwindchill_pdmlink13.1.3.0--

Explore more