Threat actors affiliated with the Cl0p ransomware campaign are targeting vulnerabilities in internet-exposed PTC Windchill and FlexPLM systems, exploiting a combination of pre-authentication information disclosure and server-side flaws to achieve unauthenticated remote code execution (RCE). Specifically, attackers are chaining a vulnerability in the FlexPLM WSDL endpoint with a flaw in the Windchill login servlet, allowing them to gain unauthorized access to sensitive data. This campaign highlights the risks associated with internet-exposed deployments of these systems, particularly those with outdated or unpatched versions1. The Cl0p group, also known as Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest, has been linked to various high-profile ransomware attacks in the past. The success of this campaign underscores the importance of securing internet-exposed systems and applying timely patches to prevent such exploits, making it crucial for practitioners to prioritize the security of their PTC Windchill and FlexPLM deployments.