Skip to main content
Back to Newswire
Security Infrastructure

Windchill web shell reported to decrypt credentials and map engineering vaults

Windchill web shell reported to decrypt credentials and map engineering vaults Image: Primary
ReliaQuest reported that a JSP web shell deployed after exploitation of CVE-2026-12569 in PTC Windchill and FlexPLM can decrypt credentials from the application keystore, enumerate engineering-data vaults and load attacker-supplied Java code in memory. An earlier advisory attributed malicious activity using JSP web shells against susceptible systems to the Clop ransomware operation. The researchers said the shell can obtain LDAP management credentials and use the application's database identity to query stored data, reducing the need for separate tooling.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire