Threat actors affiliated with the Cl0p ransomware campaign are targeting vulnerabilities in internet-exposed PTC Windchill and FlexPLM systems, exploiting a combination of pre-authentication information disclosure and server-side flaws to achieve unauthenticated remote code execution (RCE). Specifically, attackers are chaining a vulnerability in the FlexPLM WSDL endpoint with a flaw in the Windchill login servlet, allowing them to gain unauthorized access to sensitive data. This campaign highlights the risks associated with internet-exposed deployments of these systems, particularly those with outdated or unpatched versions1. The Cl0p group, also known as Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest, has been linked to various high-profile ransomware attacks in the past. The success of this campaign underscores the importance of securing internet-exposed systems and applying timely patches to prevent such exploits, making it crucial for practitioners to prioritize the security of their PTC Windchill and FlexPLM deployments.
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
⚡ High Priority
Why This Matters
Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and.
References
- The Hacker News. (2026, July 25). Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE. *The Hacker News*. https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html
Original Source
The Hacker News
Read original →