# Windchill web shell reported to decrypt credentials and map engineering vaults

_Wednesday, August 19, 2026 at 1:39 AM EDT · Security, Infrastructure · Developing · Tier 1 — Major_

![Windchill web shell reported to decrypt credentials and map engineering vaults — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEit3cCqpn48W_lqEDCb9ewKFToGQcvhUjO939N0Gja-aTvCvRTz8kdOPZG1bhyphenhyphenED2XNeB82rjCIeVO3Nw9akDlMnQZqc7keiel8H82zgtf1A7fhb6DP3z6Qh3Ehk6AGrMt77rXkoNhLaDeEl692kDHAHVsNb7AOcDxpsavM0Hj9TZRLLJsuQ-OT3oQOvFMi/s1700-e365/ptc.jpg)

ReliaQuest reported that a JSP web shell deployed after exploitation of CVE-2026-12569 in PTC Windchill and FlexPLM can decrypt credentials from the application keystore, enumerate engineering-data vaults and load attacker-supplied Java code in memory. An earlier advisory attributed malicious activity using JSP web shells against susceptible systems to the Clop ransomware operation. The researchers said the shell can obtain LDAP management credentials and use the application's database identity to query stored data, reducing the need for separate tooling.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/clop-linked-windchill-web-shell.html)

---
Canonical: https://techandbusiness.org/newswire/p7p8JaumPFwIgi6OWP-TVK
Retrieved: 2026-08-19T11:33:26.946Z
Publisher: Tech & Business (techandbusiness.org)
