Back to News
Cybersecurity

Cl0p Ransomware Campaign Exploits Vulnerabilities in PTC Windchill and FlexPLM

Cl0p affiliates are leveraging critical vulnerabilities in PTC's Windchill and FlexPLM systems, highlighting significant risks for exposed enterprises.

Recent findings reveal that threat actors affiliated with the Cl0p ransomware group are actively exploiting vulnerabilities in PTC Windchill and FlexPLM, specifically targeting internet-exposed deployments. By chaining a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, attackers are able to execute unauthenticated remote code execution (RCE). This tactic represents a significant escalation in Cl0p's data extortion strategies, emphasizing the need for heightened vigilance among organizations using these platforms.

For businesses utilizing PTC's Windchill and FlexPLM, the implications are profound. The ability of attackers to execute RCE without prior authentication underscores a critical security gap that must be addressed immediately. Companies are urged to prioritize patching these vulnerabilities and implement robust security measures, including network segmentation and enhanced monitoring of exposed systems. This situation not only highlights the evolving tactics of ransomware groups but also underscores the importance of cybersecurity resilience in safeguarding sensitive data against increasingly sophisticated cyber threats.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html)*