CVE chain in PTC engineering tools opens door for Cl0p data heists

A pre-auth information leak combined with unauthenticated RCE in PTC products lets Cl0p affiliates steal intellectual property.

CSBadmin
1 Min Read

Cl0p ransomware affiliates have added PTC engineering platforms to their target list, chaining two flaws in Windchill and FlexPLM to break into manufacturing networks. The group, which previously devastated organizations through the MOVEit file-transfer campaign, is now weaponizing design-software vulnerabilities to steal CAD files and product specifications before deploying encryption.

The attack chain starts with CVE-2026-22395, an information disclosure that spills internal server paths. A second flaw then grants unauthenticated remote code execution, letting the intruders plant webshells and begin data exfiltration. Trend Micro observes that thousands of devices remain exposed on the public internet, making them sitting targets for the scanning campaigns Cl0p is known for.

PTC Windchill serves the manufacturing sector for product lifecycle management, while FlexPLM handles retail and apparel supply chains. Both store the kind of proprietary design data that extortionists can weaponize. Security teams running these systems should patch immediately, audit for signs of webshell deployment, and apply network-level access controls to limit who can reach the admin interfaces.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.