Product
PTC Windchill
- First Reported
- Aug 18, 2026
- Latest Reported
- Sep 30, 2026
Reported Context (3)
- period vs. the previous oneManufacturing also remained a prominent target, and the “Clop”-linked PTC Windchill campaign illustrated the value attackers see in this sector. After exploiting CVE-2026-12569, the ReliaQuest Report Tracks Top Attacker Techniques in June–August 2026
- CL0P (Clop) exploited vulnerabilities in PTC Windchill and FlexPLM product lifecycle management software, adding 42 companies and organizations from 33 countries worldwide to its list of victims in quick succession. AhnLab’s August 2026 Ransomware Report Details Victim Trends and Major Attacks
- “Clop's” exploitation of CVE-2026-12569 in PTC Windchill has returned the group to mass exploitation, delivering a custom web shell that provides full data-theft capability from the moment of deployment, with no Clop-linked Windchill Web Shell Steals Credentials and Maps Engineering Data
CVE (3)
Malware (6)
People (2)
Threat Actors (42)
MITRE ATT&CK (16)
Vendors (4)
Products (9)
Tools (2)
Industries (8)
Countries (9)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.