Siemens Security Updates - September 2026
Roundup of Siemens security advisories published in September 2026.
CVE search metadata
CVE search record: CVE-2026-50093. Severity: critical. CVSS: 9.0. KEV: no. Product: Siveillance Control Pro (< V3.0.12.2173). Brief: Siemens Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-siemens-security-updates/
CVE search record: CVE-2026-62645. Severity: critical. CVSS: 9.8. KEV: no. Product: Reyrolle 7SR5 (< V2.70). Brief: Siemens Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-siemens-security-updates/
CVE search record: CVE-2026-34223. Severity: high. CVSS: 8.2. KEV: no. Product: Desigo CC ClickOnce Client. Brief: Siemens Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-siemens-security-updates/
CVE search record: CVE-2026-62646. Severity: high. CVSS: 7.4. KEV: no. Product: Reyrolle 7SR5 (< V2.70). Brief: Siemens Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-siemens-security-updates/
CVE search record: CVE-2026-62647. Severity: high. CVSS: 7.4. KEV: no. Product: Reyrolle 7SR5 (< V2.70). Brief: Siemens Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-siemens-security-updates/
CVE search record: CVE-2026-62648. Severity: high. CVSS: 7.5. KEV: no. Product: Reyrolle 7SR5 (< V2.70). Brief: Siemens Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-siemens-security-updates/
CVE search record: CVE-2026-62650. Severity: high. CVSS: 8.8. KEV: no. Brief: Siemens Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-siemens-security-updates/
What's new
This roundup covers 8 Siemens security vulnerabilities. CVSS base scores range from 7.4 to 9.8. None are reported as actively exploited at the time of release. The issues affect Desigo CC ClickOnce Client, Reyrolle 7SR5, Siveillance Control Pro.
Summary
| CVE | Product | Severity | CVSS | EPSS | KEV | Source |
|---|---|---|---|---|---|---|
| CVE-2026-50093 | Siveillance Control Pro (< V3.0.12.2173) | Critical | 9.0 | no | NVD (authoritative) | |
| CVE-2026-62645 | Reyrolle 7SR5 (< V2.70) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-34223 | Desigo CC ClickOnce Client | High | 8.2 | no | NVD (authoritative) | |
| CVE-2026-62646 | Reyrolle 7SR5 (< V2.70) | High | 7.4 | no | NVD (authoritative) | |
| CVE-2026-62647 | Reyrolle 7SR5 (< V2.70) | High | 7.4 | no | NVD (authoritative) | |
| CVE-2026-62648 | Reyrolle 7SR5 (< V2.70) | High | 7.5 | no | NVD (authoritative) | |
| CVE-2026-62649 | Reyrolle 7SR5 (< V2.70) | no | NVD (authoritative) | |||
| CVE-2026-62650 | Reyrolle 7SR5 (< V2.70) | no | NVD (authoritative) |
CVE-2026-50093
A vulnerability in the OIS web module of Siemens Siveillance Control and Siveillance Control Pro allows an unauthenticated remote attacker to perform arbitrary file uploads. Exploitation of this flaw can lead to remote code execution and the attainment of root-level privileges on the host system, resulting in a full compromise of the affected environment.
Affected products:
- Siveillance Control Pro (< V3.0.12.2173)
- Siveillance Control Pro (< V4.0.9.2178)
- Siveillance Control (< V3.0.22.2177)
- Siveillance Control (< V4.0.11.2177)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-50093
CVE-2026-62645
A vulnerability in the Reyrolle 7SR5 web interface allows for the calculation of valid session IDs due to weak session management. An attacker can exploit this to bypass authentication and gain unauthorized administrative access to the device, potentially leading to full control over the relay unit.
Affected products:
- Reyrolle 7SR5 (< V2.70)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62645
Related in this roundup: CVE-2026-62646, CVE-2026-62647, CVE-2026-62648, CVE-2026-62649, CVE-2026-62650.
CVE-2026-34223
The Desigo CC family of products is vulnerable to arbitrary file write via a Client Code Execution (CCE) flaw triggered by insufficient input validation of scripts embedded in user-defined graphics documents. An attacker can craft a malicious document that, when opened by a privileged user, executes scripts to write arbitrary files to the host filesystem, potentially leading to full system compromise.
Affected products:
- Desigo CC ClickOnce Client
- Desigo CC family
- Desigo CC Flex Client
- Desigo CC Installed Client
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-34223
CVE-2026-62646
A vulnerability in Siemens Reyrolle 7SR5 relays versions prior to V2.70 allows an unauthenticated remote attacker to predict or brute-force session identifiers due to insufficient entropy in the generation algorithm. This flaw permits session hijacking and authentication bypass.
Affected products:
- Reyrolle 7SR5 (< V2.70)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62646
Related in this roundup: CVE-2026-62645, CVE-2026-62647, CVE-2026-62648, CVE-2026-62649, CVE-2026-62650.
CVE-2026-62647
Siemens Reyrolle 7SR5 relays prior to version V2.70 utilize an insufficiently initialized random number generator for security-sensitive values, such as session identifiers. This flaw allows an unauthenticated remote attacker to predict these values, facilitating session hijacking and unauthorized access to the device.
Affected products:
- Reyrolle 7SR5 (< V2.70)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62647
Related in this roundup: CVE-2026-62645, CVE-2026-62646, CVE-2026-62648, CVE-2026-62649, CVE-2026-62650.
CVE-2026-62648
A vulnerability in the Reyrolle 7SR5 protective relay device allows an unauthenticated remote attacker to trigger an out-of-bounds write via an overly long URL component in pre-authenticated HTTP messages. This vulnerability results in a device crash and reboot, leading to a denial-of-service condition.
Affected products:
- Reyrolle 7SR5 (< V2.70)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62648
Related in this roundup: CVE-2026-62645, CVE-2026-62646, CVE-2026-62647, CVE-2026-62649, CVE-2026-62650.
CVE-2026-62649
A denial-of-service vulnerability exists in the web server component of Siemens Reyrolle 7SR5 devices. An unauthenticated remote attacker can exploit the improper management of system resources during high-volume HTTP request processing to trigger a device crash and reboot.
Affected products:
- Reyrolle 7SR5 (< V2.70)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62649
Related in this roundup: CVE-2026-62645, CVE-2026-62646, CVE-2026-62647, CVE-2026-62648, CVE-2026-62650.
CVE-2026-62650
A vulnerability in the web-based management interface of Reyrolle 7SR5 relays allows an authenticated, low-privileged remote attacker to bypass RBAC restrictions due to insufficient server-side authorization checks. This flaw enables privilege escalation to an administrative level.
Affected products:
- Reyrolle 7SR5 (< V2.70)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62650
Related in this roundup: CVE-2026-62645, CVE-2026-62646, CVE-2026-62647, CVE-2026-62648, CVE-2026-62649.