Skip to content
Threat Feed
high threat

Siemens Security Updates - August 2026

Roundup of Siemens security advisories published in August 2026.

CVE search metadata

CVE search record: CVE-2026-58115. Severity: critical. CVSS: 10.0. KEV: no. Product: SIMATIC IoT2050 Advanced (< V4.3.4.1). Brief: Siemens Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-siemens-security-updates/

CVE search record: CVE-2026-50058. Severity: high. CVSS: 7.8. KEV: no. Product: Solid Edge SE2025 (< V225.0 Update 15). Brief: Siemens Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-siemens-security-updates/

CVE search record: CVE-2026-50059. Severity: high. CVSS: 7.8. KEV: no. Brief: Siemens Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-siemens-security-updates/

CVE search record: CVE-2026-50060. Severity: high. CVSS: 7.8. KEV: no. Brief: Siemens Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-siemens-security-updates/

CVE search record: CVE-2026-50061. Severity: high. CVSS: 7.8. KEV: no. Product: Solid Edge SE2025 (< V225.0 Update 15). Brief: Siemens Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-siemens-security-updates/

CVE search record: CVE-2026-50062. Severity: high. CVSS: 7.8. KEV: no. Brief: Siemens Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-siemens-security-updates/

CVE search record: CVE-2026-50063. Severity: high. CVSS: 7.8. KEV: no. Brief: Siemens Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-siemens-security-updates/

What's new

  • 1. added CVE-2026-50062 +1 Aug 11, 14:02 via nvd
  • 2. added CVE-2026-50058 +3 Aug 11, 14:02 via nvd, source, source, source

This roundup covers 6 Siemens security vulnerabilities. CVSS base scores range from 7.8 to 10.0. None are reported as actively exploited at the time of release. The issues affect SIMATIC IoT2050 Advanced, Solid Edge SE2025.

Summary

CVEProductSeverityCVSSEPSSKEVSource
CVE-2026-58115SIMATIC IoT2050 Advanced (< V4.3.4.1)Critical10.0noNVD (authoritative)
CVE-2026-50058Solid Edge SE2025 (< V225.0 Update 15)High7.8noNVD (authoritative)
CVE-2026-50059n/aHigh7.8noNVD (authoritative)
CVE-2026-50060n/aHigh7.8noNVD (authoritative)
CVE-2026-50061Solid Edge SE2025 (< V225.0 Update 15)High7.8noNVD (authoritative)
CVE-2026-50062n/anoNVD (authoritative)

CVE-2026-58115

Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed are vulnerable to unauthorized access due to a lack of authentication on the Node-RED HTTP interface. An unauthenticated remote attacker can exploit this flaw to deploy malicious flows, resulting in arbitrary code execution with root-level privileges on the target system.

Affected products:

  • SIMATIC IoT2050 Advanced (< V4.3.4.1)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-58115

CVE-2026-50058

An out-of-bounds read vulnerability exists in Siemens Solid Edge SE2025 and SE2026 due to improper parsing of crafted DFT files. An attacker could exploit this flaw by enticing a user to open a malicious file, potentially leading to arbitrary code execution within the context of the application process.

Affected products:

  • Solid Edge SE2025 (< V225.0 Update 15)
  • Solid Edge SE2026 (< V226.0 Update 7)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-50058

Related in this roundup: CVE-2026-50061.

CVE-2026-50059

Siemens Solid Edge SE2025 and SE2026 are vulnerable to an out-of-bounds write when parsing specially crafted DFT files. An attacker could exploit this vulnerability to execute arbitrary code within the context of the current process, typically requiring user interaction.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-50059

CVE-2026-50060

A use-after-free vulnerability exists in Siemens Solid Edge SE2025 and SE2026 due to improper handling of specially crafted DFT files. An attacker could exploit this by tricking a user into opening a malicious DFT file, leading to potential arbitrary code execution within the context of the Solid Edge application process.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-50060

CVE-2026-50061

A use-after-free vulnerability exists in Siemens Solid Edge SE2025 and SE2026 software when parsing specially crafted DFT files. An attacker could exploit this vulnerability to execute arbitrary code within the context of the current process, typically requiring user interaction.

Affected products:

  • Solid Edge SE2025 (< V225.0 Update 15)
  • Solid Edge SE2026 (< V226.0 Update 7)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-50061

Related in this roundup: CVE-2026-50058.

CVE-2026-50062

An out-of-bounds read vulnerability exists in Siemens Solid Edge SE2025 and SE2026 when parsing maliciously crafted PAR files. Successful exploitation of this vulnerability could allow an attacker to achieve code execution within the context of the running application process.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-50062