threat-intel Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data A sophisticated, custom-built web shell, specifically designed for PTC Windchill and FlexPLM, has been deployed by the Clop ransomware gang. This web shell is capable of decrypting credentials, mapping sensitive data, and running attacker-supplied code, offering a complete toolkit for data theft and post-exploitation a… The Hacker News · Aug 19, 2026 High CVE-2026-12569CVE-2021-27101CVE-2023-34362web shellcredential theftransomware
vulnerability CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue CISA has added a critical remote code execution (RCE) vulnerability, CVE-2026-12569, affecting PTC Windchill PDMlink and FlexPLM to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability, stemming from imp… The Hacker News · Jun 26, 2026 Critical CVE-2026-12569rcewindchillweb shell