LR pixel

What is the Attack?

A critical unauthenticated remote code execution (RCE) vulnerability affecting PTC Windchill PDMlink and PTC FlexPLM is being actively exploited by Cl0p ransomware affiliates. The attackers are targeting vulnerable Internet-facing Product Lifecycle Management (PLM) systems to deploy web shells, steal intellectual property, and carry out double-extortion ransomware attacks.

The campaign chains a pre-authentication information disclosure vulnerability in the FlexPLM endpoint with CVE-2026-12569 to achieve unauthenticated remote code execution. Following compromise, attackers deploy JSP web shells, perform file system discovery, exfiltrate sensitive information, and ultimately issue ransom demands to affected organizations.

What is the recommended Mitigation?

Organizations using PTC Windchill or FlexPLM should:

• Apply the latest vendor security updates immediately.

• Verify whether systems are internet accessible and restrict external exposure where possible.

• Hunt for JSP web shells within the /Windchill/login/ directory.

• Review logs for suspicious requests targeting Windchill login endpoints.

• Rotate credentials and perform a full compromise assessment if exploitation is suspected.

What FortiGuard Coverage is available?

• FortiGuard IPS Service helps detect and block exploitation attempts targeting vulnerable PTC Windchill PDMlink and FlexPLM servers before attackers can gain remote code execution.

Intrusion Prevention | FortiGuard Labs


• FortiGuard Antivirus & Behavior Detection Service identifies and blocks malicious payloads and suspicious post-exploitation behavior associated with Cl0p intrusion activity.

• FortiGuard Web Filtering Service prevents access to known malicious domains, command-and-control (C2) infrastructure, and phishing sites used during the attack lifecycle.

• FortiGuard IOC Service provides up-to-date indicators of compromise (IOCs), enabling security teams to identify affected systems, detect attacker activity, and accelerate threat hunting.

• FortiGuard Incident Response Service assists organizations with incident investigation, containment, forensic analysis, eradication of attacker persistence, and recovery following a confirmed compromise.