Clop’s playbook keeps working because enterprises keep exposing the same class of software: internet facing business applications that hold years of sensitive records and rarely get patched on release day. The latest target is PTC’s Windchill and FlexPLM, product lifecycle management platforms used across defense, aerospace, automotive, medical device, and industrial manufacturing to store engineering data. A critical unauthenticated remote code execution flaw, tracked as CVE-2026-12569, is now under active exploitation, with attackers deploying JSP webshells to pull data out of compromised instances.

PTC shipped patches on July 14, 2026, and says in its advisory that “over the last several hours” it has continued receiving reports of heightened threat activity against unpatched instances, well after the fix was available. CISA added the flaw to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch within three days. Germany’s BSI ran emergency outreach to affected customers, an unusual step that signals how quickly exploitation followed disclosure.

The pattern is familiar to anyone who tracked Clop’s Oracle EBS campaign, which CyberTech covered as breach notices kept surfacing a full year after the initial exploitation. The original insight is what that timeline predicts here: patching Windchill closes the entry point, but it does not answer whether engineering data was already exfiltrated during the exploitation window between the June disclosure and the July patch. Security teams that run Windchill or FlexPLM should treat “we patched” as step one, not the end state, and start the forensic review now rather than waiting for a breach notice a year from now.

Source: PTC