Skip to content
Threat Feed

Vendor

Siemens

39 briefs RSS
critical advisory

Arbitrary File Upload Vulnerability in Siemens Siveillance Control

A critical file upload vulnerability (CVE-2026-50093) in the Siemens Siveillance Control OIS web module allows unauthenticated or low-privileged remote attackers to achieve root-level code execution.

Siveillance Control Pro +1 ics scada cve-2026-50093 arbitrary-file-upload
2t 1c
high advisory

Path Traversal Vulnerability in Siemens SIMOVE and SIPLANT

An unauthenticated path traversal vulnerability (CVE-2026-67367) in Siemens SIMOVE Fleetmanager and SIPLANT allows remote attackers to read arbitrary files from the underlying operating system.

SIMOVE Fleetmanager +1 cve-2026-67367 path-traversal industrial-security siemens
1r 1t 1c
medium advisory

Denial of Service Vulnerability in Siemens WTV676 and WTV776

An unauthenticated remote attacker can exploit an improper input validation vulnerability (CVE-2026-89207) in Siemens WTV676 and WTV776 devices to force them into protection mode, resulting in a permanent loss of remote web access.

WTV676 +1 industrial-control-systems denial-of-service energy
1t 1c
high advisory

Multiple Vulnerabilities in Siemens Reyrolle 7SR5 Firmware

Siemens Reyrolle 7SR5 devices running firmware versions earlier than V2.70 are impacted by multiple vulnerabilities within the embedded Mongoose Web Server, potentially leading to denial of service, information disclosure, or authentication bypass.

Reyrolle 7SR5 ics energy firmware-vulnerability
1c
low advisory

Reflected Cross-Site Scripting Vulnerability in Siemens Teamcenter

An unauthenticated remote attacker can exploit a reflected XSS vulnerability in the Teamcenter authentication redirect flow to execute arbitrary JavaScript in the context of an authenticated user session.

Teamcenter +3 web-vulnerability xss siemens
1r 1t 1c
high threat

Siemens Security Updates - September 2026

Roundup of Siemens security advisories published in September 2026.

roundup
7c
high advisory

Authentication Bypass in Mendix SAML Module

An authentication bypass vulnerability (CVE-2026-80465) in multiple Mendix SAML module versions allows unauthenticated attackers to hijack user sessions via improper SAML response signature validation.

Mendix SAML +2 vulnerability authentication-bypass sso mendix
1c updated
critical threat

Active Exploitation of Siemens S7 Series PLCs in US Critical Infrastructure

The IC3 has issued an advisory regarding the active exploitation of Siemens S7 Series PLCs within US critical infrastructure sectors using CVE-2026-4357 to disrupt operational technology.

exploited S7 Series PLC critical-infrastructure ot-security vulnerability-management
1t
high advisory

Active Reconnaissance and Capability Development Against Siemens S7 PLCs

Threat actors are using AI-assisted scripts and the snap7 library to target Internet-exposed Siemens S7 Series PLCs for reconnaissance and potential operational disruption across critical infrastructure sectors.

S7-200 Series +4 ics ot reconnaissance siemens plc
2t
low advisory

Vulnerabilities in Siemens RUGGEDCOM APE1808 via Fortinet Integration

Siemens RUGGEDCOM APE1808 devices are impacted by multiple vulnerabilities (CVE-2026-23573, CVE-2026-59839) within the integrated Fortinet NGFW software, potentially allowing remote code execution or filesystem deletion.

RUGGEDCOM APE1808 +4
2t 2c
high advisory

Arbitrary Code Execution in Siemens Simcenter Femap

Siemens Simcenter Femap is susceptible to arbitrary code execution via two out-of-bounds read vulnerabilities when parsing specially crafted BMP files.

Simcenter Femap +1 vulnerability industrial-control-systems ics cve-2026-59086 stack-overflow rce
2t 1c updated
high advisory

Multiple Memory Corruption Vulnerabilities in Siemens Solid Edge

Siemens Solid Edge is affected by multiple memory corruption vulnerabilities, including out-of-bounds read/write and use-after-free, allowing arbitrary code execution via specially crafted PAR, PSM, or DFT files.

Solid Edge SE2025 +1 critical-manufacturing memory-corruption cve-report
1t 1c
medium advisory

Hardcoded Cryptographic Keys and Weak Password Hashing in Siemens LOGO! Soft Comfort

Siemens LOGO! Soft Comfort versions prior to V9 contain hardcoded master keys and unsalted password hashes, allowing local attackers to decrypt project files or perform brute-force attacks.

LOGO! Soft Comfort
2t 2c
high advisory

Command Injection Vulnerability in Siemens Siveillance Video

A critical OS command injection vulnerability (CVE-2026-3014) in Siemens Siveillance Video allows authenticated users with administrative permissions to achieve remote code execution in the context of the Management Server service.

Siveillance Video vulnerability cve ics industrial-control-systems
1t 1c
low advisory

Denial of Service Vulnerability in Siemens Desigo DXR and PXC Controllers

Siemens Desigo DXR and PXC controllers are vulnerable to a denial-of-service condition (CVE-2026-59693) triggered by malformed BACnet packets, requiring a manual device reboot.

Desigo DXR2 +5
1t 1c
high advisory

Multiple Vulnerabilities in Siemens License Server

Siemens License Server (SLS) contains vulnerabilities allowing remote file disclosure (CVE-2026-69109) and local privilege escalation (CVE-2026-69108).

Siemens License Server
2c
high advisory

Out-of-Bounds Read Vulnerability in Siemens Parasolid

Siemens Parasolid contains an out-of-bounds read vulnerability (CVE-2026-64629) in its X_T file parsing logic that can lead to arbitrary code execution or application crashes.

Parasolid vulnerability industrial-control-systems ics cve-2026-64629
1t 1c
high threat

Siemens Security Updates - August 2026

Roundup of Siemens security advisories published in August 2026.

roundup
7c
high threat

Sandworm Targeted Polish Energy Facility via Private APN Pivot

In December 2025, the threat actor Sandworm exploited an internet-facing firewall and a misconfigured cellular router to pivot through a private APN into a Polish energy facility's OT network, resulting in industrial sabotage.

VPN and firewall +5 Sandworm +4
6t
critical threat

Three Chained Zero-Days in Siemens ROX II OT Switches Lead to Root Access

Unit 42 and Siemens collaborated to disclose three critical chained zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, CVE-2025-40949) in Siemens ROX II operational technology switches, allowing an attacker to achieve arbitrary file disclosure, privilege escalation to root, and persistent root-level code execution.

exploited PoC ROX II OT switches +2 industrial-control-systems ot-security zero-day privilege-escalation command-injection persistence siemens vulnerability-exploit
3r 4t 5c updated
high advisory

Siemens Security Updates — July 2026

Roundup of Siemens security advisories published in July 2026.

PoC CPCI85 Central Processing/Communication < V26.20 +27 roundup
5c 2i updated
high advisory

ClickFix Campaign Activity

Tracking brief for the ClickFix campaign; individual sightings are folded in as reported.

open source packages +51 campaign clickfix
30i updated
high threat

Multiple Critical Vulnerabilities in Siemens SCALANCE Industrial Network Products, Including Unpatched Devices

Multiple high-severity vulnerabilities, including CVE-2025-15467, affect various Siemens SCALANCE LPE, M, W, and X series industrial network devices, potentially allowing a remote attacker to achieve arbitrary code execution, provoke a denial of service, or compromise data confidentiality, with some products confirmed to receive no future patches.

SCALANCE LPE9413 +99 industrial_control_systems ics_scada vulnerability siemens network_device ot
3r 4t 1c
medium advisory

CISA ICS Security Advisories Address Vulnerabilities in Multiple Vendor Products

CISA published ICS advisories addressing vulnerabilities in products from ABB, Hitachi Energy, Kieback & Peter, ScadaBR, Siemens, and ZKTeco, recommending mitigations and updates.

B&R Automation Runtime +10 ics scada vulnerability
2r
medium advisory

Siemens SIPROTEC 5 Insufficient Session ID Randomness Leads to Session Hijacking (CVE-2024-54017)

Siemens SIPROTEC 5 devices are vulnerable to session hijacking (CVE-2024-54017) due to the use of insufficiently random numbers in session identifier generation, potentially allowing an unauthenticated remote attacker to brute-force a valid session and gain unauthorized read access.

SIPROTEC 5 6MD84 +62 ics session hijacking cve-2024-54017 siemens critical infrastructure
2r 1t 1c
medium advisory

Siemens SIMATIC HMI Unified Comfort Panels Unauthenticated Access Vulnerability

Siemens SIMATIC HMI Unified Comfort Panels before V21.0 are vulnerable to unauthenticated access via the help link and Control Panel (CVE-2026-27662), potentially leading to unauthorized configuration changes and discovery of backdoors.

SIMATIC HMI MTP1000 Unified Comfort Panel +49 ics siemens hmi cve-2026-27662 unauthenticated access
2r 1t 1c
medium advisory

Siemens Ruggedcom Rox Improper Access Control Vulnerability

Siemens Ruggedcom Rox is vulnerable to improper access control, allowing an authenticated remote attacker to read arbitrary files with root privileges from the underlying operating system's filesystem via the web server's JSON-RPC interface, as tracked by CVE-2025-40948.

RUGGEDCOM ROX MX5000 +10 cve siemens ruggedcom ics file-access attack.credential_access
2r 1t 1c
high advisory

Siemens Opcenter RDnL Missing Authentication Vulnerability (CVE-2026-27446)

Siemens Opcenter RDnL is vulnerable to missing authentication in critical function (CVE-2026-27446), where an unauthenticated attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker, potentially leading to availability impacts and message injection.

Opcenter RDnL +1 cve vulnerability siemens activemq
2r 1t 1c
critical advisory

Siemens SENTRON 7KT PAC1261 Data Manager Request Smuggling Vulnerability

A request smuggling vulnerability exists in Siemens SENTRON 7KT PAC1261 Data Manager before V2.1.0, due to the web server improperly accepting a bare LF as a line terminator in chunked data chunk-size lines, potentially allowing an attacker to retrieve authorization tokens and gain administrative control over the device.

SENTRON 7KT PAC1261 Data Manager request-smuggling cve-2025-22871 siemens ot
1r 1t 1c
high advisory

Siemens Simcenter Femap Heap-Based Buffer Overflow RCE

A heap-based buffer overflow vulnerability in Siemens Simcenter Femap, tracked as CVE-2025-12659, can be exploited by tricking a user into opening a malicious IPT file, leading to remote code execution.

Simcenter Femap cve-2025-12659 heap overflow remote code execution siemens critical manufacturing
2r 1t 1c
medium advisory

Siemens Security Advisory Addressing Multiple Product Vulnerabilities

Siemens released a security advisory on May 12, 2026, addressing vulnerabilities in a range of products including RUGGEDCOM, SCALANCE, Solid Edge, and SIMATIC, prompting users to apply necessary updates.

RUGGEDCOM ROX II family +20 siemens security-advisory industrial-control-systems
2r
medium advisory

Siemens SIMATIC S7 PLCs Web Server Vulnerabilities Allow Cross-Site Scripting

A remote, authenticated attacker can exploit multiple vulnerabilities in Siemens SIMATIC S7 PLCs Web Server to perform cross-site scripting attacks, potentially leading to information disclosure or further unauthorized actions.

SIMATIC S7 PLCs Web Server xss web-application plc
2r 1t
medium advisory

Siemens SIPROTEC 5 Information Disclosure Vulnerability

A remote, anonymous attacker can exploit a vulnerability in Siemens SIPROTEC 5 devices to disclose sensitive information.

SIPROTEC 5 information-disclosure ics siemens
2r 1t
high advisory

Solid Edge SE2026 Stack-Based Overflow Vulnerability (CVE-2026-44412)

A stack-based overflow vulnerability in Solid Edge SE2026 (versions prior to V226.0 Update 5) allows for arbitrary code execution via specially crafted PAR files.

Solid Edge SE2026 cve stack overflow code execution siemens
2r 1t 1c
high advisory

Solid Edge SE2026 Uninitialized Pointer Access Vulnerability (CVE-2026-44411)

Solid Edge SE2026 is vulnerable to uninitialized pointer access while parsing specially crafted PAR files, potentially leading to arbitrary code execution in the context of the current process (CVE-2026-44411).

Solid Edge SE2026 cve rce solid edge uninitialized pointer
2r 2t 1c
medium advisory

Siemens Teamcenter Vulnerability CVE-2026-33862 - Cross-Site Scripting

Siemens Teamcenter versions V2312 (before V2312.0014), V2406 (before V2406.0012), V2412 (before V2412.0009), V2506 (before V2506.0005), and V2512 are vulnerable to cross-site scripting (XSS) due to improper encoding or filtering of user-supplied data, potentially leading to arbitrary code execution by other users.

PoC Teamcenter V2312 +6 cve xss siemens teamcenter
2r 1t 3c 3i updated
high threat

Siemens RUGGEDCOM ROX Devices Vulnerable to Remote Code Execution via Feature Key Injection (CVE-2025-40947)

CVE-2025-40947 describes a vulnerability in Siemens RUGGEDCOM ROX devices that allows authenticated remote attackers to inject arbitrary commands via a maliciously crafted feature key, resulting in remote code execution with root privileges.

RUGGEDCOM ROX MX5000 +10 cve rce siemens ruggedcom ics
2r 1t 1c
medium advisory

Siemens SIMATIC CN 4100 Unauthenticated Resource Exhaustion (CVE-2026-22924)

Siemens SIMATIC CN 4100 versions before V5.0 are vulnerable to resource exhaustion due to improper restriction of unauthenticated connections, potentially leading to disruption of operations and unauthorized actions.

SIMATIC CN 4100 resource-exhaustion dos ics cve-2026-22924
2r 1t 1c
critical advisory

CVE-2025-40949 - Siemens RUGGEDCOM ROX Web UI Command Injection

An authenticated remote command injection vulnerability exists in the web UI scheduler functionality of multiple RUGGEDCOM ROX devices before V2.17.1, allowing arbitrary command execution with root privileges.

RUGGEDCOM ROX MX5000 +10 command-injection rce ruggedcom
2r 1t 1c