CVE
CVE-2026-12569
- First Reported
- Aug 18, 2026
- Latest Reported
- Sep 30, 2026
Reported Context (2)
- PTC Windchill campaign illustrated the value attackers see in this sector. After exploiting CVE-2026-12569, the group deployed a custom web shell built specifically for Windchill, an industry-standard product ReliaQuest Report Tracks Top Attacker Techniques in June–August 2026
- “Clop's” exploitation of CVE-2026-12569 in PTC Windchill has returned the group to mass exploitation, delivering a custom web shell that provides full data-theft capability from the moment of deployment, with no Clop-linked Windchill Web Shell Steals Credentials and Maps Engineering Data
CVE (2)
Malware (6)
People (2)
Threat Actors (6)
MITRE ATT&CK (16)
Vendors (3)
Products (9)
Tools (2)
Industries (2)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.