Cl0p Ransomware Affiliates Exploit Unpatched RCE in PTC Windchill and FlexPLM

Cl0p Ransomware Affiliates Exploit Unpatched RCE in PTC Windchill and FlexPLM

The Cl0p ransomware group is actively exploiting an unauthenticated remote code execution flaw in PTC's Windchill and FlexPLM products, targeting internet-exposed servers to deploy ransomware. Immediate patching and acce…

Security researchers have detected a new wave of attacks by affiliates of the Cl0p ransomware operation, this time focusing on internet-exposed instances of PTC's Windchill and FlexPLM software. The threat actors are leveraging an unauthenticated remote code execution (RCE) vulnerability to gain full control over vulnerable systems, subsequently deploying ransomware and exfiltrating sensitive data.

PTC Windchill is a widely used product lifecycle management (PLM) platform, while FlexPLM serves the retail, fashion, and consumer goods industries. Both applications are designed to manage critical business data, making them attractive targets for extortion. The exploited vulnerability allows an attacker to execute arbitrary commands on the server without any prior authentication, meaning any unpatched system directly reachable over the internet is at immediate risk.

Organizations running these PTC products should treat this threat with the highest urgency. Successful exploitation can lead to complete network compromise, data theft, operational disruption, and significant financial and reputational damage. Given Cl0p’s history of large-scale supply chain attacks—such as those involving Accellion FTA and MOVEit Transfer—the impact could extend well beyond a single victim if interconnected systems are affected.

Mitigation requires immediate action. Organizations should promptly check for and apply any available security patches from PTC. In the interim, internet-facing access to Windchill and FlexPLM servers must be severely restricted using firewalls or VPNs, and strong authentication measures like multi-factor authentication (MFA) must be enforced. Continuous monitoring for unusual activity and regular vulnerability assessments are also essential to catch any early signs of compromise.

For organizations lacking the in-house expertise to handle such threats, engaging with specialist security providers can make the difference between a secure environment and a costly breach. AEU-I, the security-first IT and consulting arm of AEU Group, assists businesses in hardening their infrastructure, performing vulnerability assessments, and building proactive defense strategies tailored to their unique risk profile.