CLOP Is Mass-Exploiting PTC Windchill at Scale. Every AI Agent Connected to It Inherits the Breach.
CVE-2026-12569 is an unauthenticated remote code execution vulnerability in PTC Windchill PDMLink and FlexPLM. The flaw, rooted in unsafe deserialization, carries a CVSS score of 9.8 according to the NVD, while PTC’s own assessments range from 9.3 to 10.0. Affected releases include versions prior to 11.0 M030 and multiple subsequent iterations. The threat actor identified…