Skip to content
Threat Feed
high threat

Siemens Security Updates - September 2026

Roundup of Siemens security advisories published in September 2026.

CVE search metadata

CVE search record: CVE-2026-50093. Severity: critical. CVSS: 9.0. KEV: no. Product: Siveillance Control Pro (< V3.0.12.2173). Brief: Siemens Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-siemens-security-updates/

CVE search record: CVE-2026-62645. Severity: critical. CVSS: 9.8. KEV: no. Product: Reyrolle 7SR5 (< V2.70). Brief: Siemens Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-siemens-security-updates/

CVE search record: CVE-2026-34223. Severity: high. CVSS: 8.2. KEV: no. Product: Desigo CC ClickOnce Client. Brief: Siemens Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-siemens-security-updates/

CVE search record: CVE-2026-62646. Severity: high. CVSS: 7.4. KEV: no. Product: Reyrolle 7SR5 (< V2.70). Brief: Siemens Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-siemens-security-updates/

CVE search record: CVE-2026-62647. Severity: high. CVSS: 7.4. KEV: no. Product: Reyrolle 7SR5 (< V2.70). Brief: Siemens Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-siemens-security-updates/

CVE search record: CVE-2026-62648. Severity: high. CVSS: 7.5. KEV: no. Product: Reyrolle 7SR5 (< V2.70). Brief: Siemens Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-siemens-security-updates/

CVE search record: CVE-2026-62650. Severity: high. CVSS: 8.8. KEV: no. Brief: Siemens Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-siemens-security-updates/

What's new

This roundup covers 8 Siemens security vulnerabilities. CVSS base scores range from 7.4 to 9.8. None are reported as actively exploited at the time of release. The issues affect Desigo CC ClickOnce Client, Reyrolle 7SR5, Siveillance Control Pro.

Summary

CVEProductSeverityCVSSEPSSKEVSource
CVE-2026-50093Siveillance Control Pro (< V3.0.12.2173)Critical9.0noNVD (authoritative)
CVE-2026-62645Reyrolle 7SR5 (< V2.70)Critical9.8noNVD (authoritative)
CVE-2026-34223Desigo CC ClickOnce ClientHigh8.2noNVD (authoritative)
CVE-2026-62646Reyrolle 7SR5 (< V2.70)High7.4noNVD (authoritative)
CVE-2026-62647Reyrolle 7SR5 (< V2.70)High7.4noNVD (authoritative)
CVE-2026-62648Reyrolle 7SR5 (< V2.70)High7.5noNVD (authoritative)
CVE-2026-62649Reyrolle 7SR5 (< V2.70)noNVD (authoritative)
CVE-2026-62650Reyrolle 7SR5 (< V2.70)noNVD (authoritative)

CVE-2026-50093

A vulnerability in the OIS web module of Siemens Siveillance Control and Siveillance Control Pro allows an unauthenticated remote attacker to perform arbitrary file uploads. Exploitation of this flaw can lead to remote code execution and the attainment of root-level privileges on the host system, resulting in a full compromise of the affected environment.

Affected products:

  • Siveillance Control Pro (< V3.0.12.2173)
  • Siveillance Control Pro (< V4.0.9.2178)
  • Siveillance Control (< V3.0.22.2177)
  • Siveillance Control (< V4.0.11.2177)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-50093

CVE-2026-62645

A vulnerability in the Reyrolle 7SR5 web interface allows for the calculation of valid session IDs due to weak session management. An attacker can exploit this to bypass authentication and gain unauthorized administrative access to the device, potentially leading to full control over the relay unit.

Affected products:

  • Reyrolle 7SR5 (< V2.70)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62645

Related in this roundup: CVE-2026-62646, CVE-2026-62647, CVE-2026-62648, CVE-2026-62649, CVE-2026-62650.

CVE-2026-34223

The Desigo CC family of products is vulnerable to arbitrary file write via a Client Code Execution (CCE) flaw triggered by insufficient input validation of scripts embedded in user-defined graphics documents. An attacker can craft a malicious document that, when opened by a privileged user, executes scripts to write arbitrary files to the host filesystem, potentially leading to full system compromise.

Affected products:

  • Desigo CC ClickOnce Client
  • Desigo CC family
  • Desigo CC Flex Client
  • Desigo CC Installed Client

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-34223

CVE-2026-62646

A vulnerability in Siemens Reyrolle 7SR5 relays versions prior to V2.70 allows an unauthenticated remote attacker to predict or brute-force session identifiers due to insufficient entropy in the generation algorithm. This flaw permits session hijacking and authentication bypass.

Affected products:

  • Reyrolle 7SR5 (< V2.70)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62646

Related in this roundup: CVE-2026-62645, CVE-2026-62647, CVE-2026-62648, CVE-2026-62649, CVE-2026-62650.

CVE-2026-62647

Siemens Reyrolle 7SR5 relays prior to version V2.70 utilize an insufficiently initialized random number generator for security-sensitive values, such as session identifiers. This flaw allows an unauthenticated remote attacker to predict these values, facilitating session hijacking and unauthorized access to the device.

Affected products:

  • Reyrolle 7SR5 (< V2.70)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62647

Related in this roundup: CVE-2026-62645, CVE-2026-62646, CVE-2026-62648, CVE-2026-62649, CVE-2026-62650.

CVE-2026-62648

A vulnerability in the Reyrolle 7SR5 protective relay device allows an unauthenticated remote attacker to trigger an out-of-bounds write via an overly long URL component in pre-authenticated HTTP messages. This vulnerability results in a device crash and reboot, leading to a denial-of-service condition.

Affected products:

  • Reyrolle 7SR5 (< V2.70)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62648

Related in this roundup: CVE-2026-62645, CVE-2026-62646, CVE-2026-62647, CVE-2026-62649, CVE-2026-62650.

CVE-2026-62649

A denial-of-service vulnerability exists in the web server component of Siemens Reyrolle 7SR5 devices. An unauthenticated remote attacker can exploit the improper management of system resources during high-volume HTTP request processing to trigger a device crash and reboot.

Affected products:

  • Reyrolle 7SR5 (< V2.70)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62649

Related in this roundup: CVE-2026-62645, CVE-2026-62646, CVE-2026-62647, CVE-2026-62648, CVE-2026-62650.

CVE-2026-62650

A vulnerability in the web-based management interface of Reyrolle 7SR5 relays allows an authenticated, low-privileged remote attacker to bypass RBAC restrictions due to insufficient server-side authorization checks. This flaw enables privilege escalation to an administrative level.

Affected products:

  • Reyrolle 7SR5 (< V2.70)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62650

Related in this roundup: CVE-2026-62645, CVE-2026-62646, CVE-2026-62647, CVE-2026-62648, CVE-2026-62649.