Vendor
Arbitrary File Upload Vulnerability in Siemens Siveillance Control
2 TTPs 1 CVEA critical file upload vulnerability (CVE-2026-50093) in the Siemens Siveillance Control OIS web module allows unauthenticated or low-privileged remote attackers to achieve root-level code execution.
Path Traversal Vulnerability in Siemens SIMOVE and SIPLANT
1 rule 1 TTP 1 CVEAn unauthenticated path traversal vulnerability (CVE-2026-67367) in Siemens SIMOVE Fleetmanager and SIPLANT allows remote attackers to read arbitrary files from the underlying operating system.
Denial of Service Vulnerability in Siemens WTV676 and WTV776
1 TTP 1 CVEAn unauthenticated remote attacker can exploit an improper input validation vulnerability (CVE-2026-89207) in Siemens WTV676 and WTV776 devices to force them into protection mode, resulting in a permanent loss of remote web access.
Multiple Vulnerabilities in Siemens Reyrolle 7SR5 Firmware
1 CVESiemens Reyrolle 7SR5 devices running firmware versions earlier than V2.70 are impacted by multiple vulnerabilities within the embedded Mongoose Web Server, potentially leading to denial of service, information disclosure, or authentication bypass.
Reflected Cross-Site Scripting Vulnerability in Siemens Teamcenter
1 rule 1 TTP 1 CVEAn unauthenticated remote attacker can exploit a reflected XSS vulnerability in the Teamcenter authentication redirect flow to execute arbitrary JavaScript in the context of an authenticated user session.
Siemens Security Updates - September 2026
7 CVEsRoundup of Siemens security advisories published in September 2026.
Authentication Bypass in Mendix SAML Module
1 CVEAn authentication bypass vulnerability (CVE-2026-80465) in multiple Mendix SAML module versions allows unauthenticated attackers to hijack user sessions via improper SAML response signature validation.
Active Exploitation of Siemens S7 Series PLCs in US Critical Infrastructure
1 TTPThe IC3 has issued an advisory regarding the active exploitation of Siemens S7 Series PLCs within US critical infrastructure sectors using CVE-2026-4357 to disrupt operational technology.
Active Reconnaissance and Capability Development Against Siemens S7 PLCs
2 TTPsThreat actors are using AI-assisted scripts and the snap7 library to target Internet-exposed Siemens S7 Series PLCs for reconnaissance and potential operational disruption across critical infrastructure sectors.
Vulnerabilities in Siemens RUGGEDCOM APE1808 via Fortinet Integration
2 TTPs 2 CVEsSiemens RUGGEDCOM APE1808 devices are impacted by multiple vulnerabilities (CVE-2026-23573, CVE-2026-59839) within the integrated Fortinet NGFW software, potentially allowing remote code execution or filesystem deletion.
Arbitrary Code Execution in Siemens Simcenter Femap
2 TTPs 1 CVESiemens Simcenter Femap is susceptible to arbitrary code execution via two out-of-bounds read vulnerabilities when parsing specially crafted BMP files.
Multiple Memory Corruption Vulnerabilities in Siemens Solid Edge
1 TTP 1 CVESiemens Solid Edge is affected by multiple memory corruption vulnerabilities, including out-of-bounds read/write and use-after-free, allowing arbitrary code execution via specially crafted PAR, PSM, or DFT files.
Hardcoded Cryptographic Keys and Weak Password Hashing in Siemens LOGO! Soft Comfort
2 TTPs 2 CVEsSiemens LOGO! Soft Comfort versions prior to V9 contain hardcoded master keys and unsalted password hashes, allowing local attackers to decrypt project files or perform brute-force attacks.
Command Injection Vulnerability in Siemens Siveillance Video
1 TTP 1 CVEA critical OS command injection vulnerability (CVE-2026-3014) in Siemens Siveillance Video allows authenticated users with administrative permissions to achieve remote code execution in the context of the Management Server service.
Denial of Service Vulnerability in Siemens Desigo DXR and PXC Controllers
1 TTP 1 CVESiemens Desigo DXR and PXC controllers are vulnerable to a denial-of-service condition (CVE-2026-59693) triggered by malformed BACnet packets, requiring a manual device reboot.
Multiple Vulnerabilities in Siemens License Server
2 CVEsSiemens License Server (SLS) contains vulnerabilities allowing remote file disclosure (CVE-2026-69109) and local privilege escalation (CVE-2026-69108).
Out-of-Bounds Read Vulnerability in Siemens Parasolid
1 TTP 1 CVESiemens Parasolid contains an out-of-bounds read vulnerability (CVE-2026-64629) in its X_T file parsing logic that can lead to arbitrary code execution or application crashes.
Siemens Security Updates - August 2026
7 CVEsRoundup of Siemens security advisories published in August 2026.
Sandworm Targeted Polish Energy Facility via Private APN Pivot
6 TTPsIn December 2025, the threat actor Sandworm exploited an internet-facing firewall and a misconfigured cellular router to pivot through a private APN into a Polish energy facility's OT network, resulting in industrial sabotage.
Three Chained Zero-Days in Siemens ROX II OT Switches Lead to Root Access
3 rules 4 TTPs 5 CVEsUnit 42 and Siemens collaborated to disclose three critical chained zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, CVE-2025-40949) in Siemens ROX II operational technology switches, allowing an attacker to achieve arbitrary file disclosure, privilege escalation to root, and persistent root-level code execution.
Siemens Security Updates — July 2026
5 CVEs 2 IOCsRoundup of Siemens security advisories published in July 2026.
ClickFix Campaign Activity
30 IOCsTracking brief for the ClickFix campaign; individual sightings are folded in as reported.
Multiple Critical Vulnerabilities in Siemens SCALANCE Industrial Network Products, Including Unpatched Devices
3 rules 4 TTPs 1 CVEMultiple high-severity vulnerabilities, including CVE-2025-15467, affect various Siemens SCALANCE LPE, M, W, and X series industrial network devices, potentially allowing a remote attacker to achieve arbitrary code execution, provoke a denial of service, or compromise data confidentiality, with some products confirmed to receive no future patches.
CISA ICS Security Advisories Address Vulnerabilities in Multiple Vendor Products
2 rulesCISA published ICS advisories addressing vulnerabilities in products from ABB, Hitachi Energy, Kieback & Peter, ScadaBR, Siemens, and ZKTeco, recommending mitigations and updates.
Siemens SIPROTEC 5 Insufficient Session ID Randomness Leads to Session Hijacking (CVE-2024-54017)
2 rules 1 TTP 1 CVESiemens SIPROTEC 5 devices are vulnerable to session hijacking (CVE-2024-54017) due to the use of insufficiently random numbers in session identifier generation, potentially allowing an unauthenticated remote attacker to brute-force a valid session and gain unauthorized read access.
Siemens SIMATIC HMI Unified Comfort Panels Unauthenticated Access Vulnerability
2 rules 1 TTP 1 CVESiemens SIMATIC HMI Unified Comfort Panels before V21.0 are vulnerable to unauthenticated access via the help link and Control Panel (CVE-2026-27662), potentially leading to unauthorized configuration changes and discovery of backdoors.
Siemens Ruggedcom Rox Improper Access Control Vulnerability
2 rules 1 TTP 1 CVESiemens Ruggedcom Rox is vulnerable to improper access control, allowing an authenticated remote attacker to read arbitrary files with root privileges from the underlying operating system's filesystem via the web server's JSON-RPC interface, as tracked by CVE-2025-40948.
Siemens Opcenter RDnL Missing Authentication Vulnerability (CVE-2026-27446)
2 rules 1 TTP 1 CVESiemens Opcenter RDnL is vulnerable to missing authentication in critical function (CVE-2026-27446), where an unauthenticated attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker, potentially leading to availability impacts and message injection.
Siemens SENTRON 7KT PAC1261 Data Manager Request Smuggling Vulnerability
1 rule 1 TTP 1 CVEA request smuggling vulnerability exists in Siemens SENTRON 7KT PAC1261 Data Manager before V2.1.0, due to the web server improperly accepting a bare LF as a line terminator in chunked data chunk-size lines, potentially allowing an attacker to retrieve authorization tokens and gain administrative control over the device.
Siemens Simcenter Femap Heap-Based Buffer Overflow RCE
2 rules 1 TTP 1 CVEA heap-based buffer overflow vulnerability in Siemens Simcenter Femap, tracked as CVE-2025-12659, can be exploited by tricking a user into opening a malicious IPT file, leading to remote code execution.
Siemens Security Advisory Addressing Multiple Product Vulnerabilities
2 rulesSiemens released a security advisory on May 12, 2026, addressing vulnerabilities in a range of products including RUGGEDCOM, SCALANCE, Solid Edge, and SIMATIC, prompting users to apply necessary updates.
Siemens SIMATIC S7 PLCs Web Server Vulnerabilities Allow Cross-Site Scripting
2 rules 1 TTPA remote, authenticated attacker can exploit multiple vulnerabilities in Siemens SIMATIC S7 PLCs Web Server to perform cross-site scripting attacks, potentially leading to information disclosure or further unauthorized actions.
Siemens SIPROTEC 5 Information Disclosure Vulnerability
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in Siemens SIPROTEC 5 devices to disclose sensitive information.
Solid Edge SE2026 Stack-Based Overflow Vulnerability (CVE-2026-44412)
2 rules 1 TTP 1 CVEA stack-based overflow vulnerability in Solid Edge SE2026 (versions prior to V226.0 Update 5) allows for arbitrary code execution via specially crafted PAR files.
Solid Edge SE2026 Uninitialized Pointer Access Vulnerability (CVE-2026-44411)
2 rules 2 TTPs 1 CVESolid Edge SE2026 is vulnerable to uninitialized pointer access while parsing specially crafted PAR files, potentially leading to arbitrary code execution in the context of the current process (CVE-2026-44411).
Siemens Teamcenter Vulnerability CVE-2026-33862 - Cross-Site Scripting
2 rules 1 TTP 3 CVEs 3 IOCsSiemens Teamcenter versions V2312 (before V2312.0014), V2406 (before V2406.0012), V2412 (before V2412.0009), V2506 (before V2506.0005), and V2512 are vulnerable to cross-site scripting (XSS) due to improper encoding or filtering of user-supplied data, potentially leading to arbitrary code execution by other users.
Siemens RUGGEDCOM ROX Devices Vulnerable to Remote Code Execution via Feature Key Injection (CVE-2025-40947)
2 rules 1 TTP 1 CVECVE-2025-40947 describes a vulnerability in Siemens RUGGEDCOM ROX devices that allows authenticated remote attackers to inject arbitrary commands via a maliciously crafted feature key, resulting in remote code execution with root privileges.
Siemens SIMATIC CN 4100 Unauthenticated Resource Exhaustion (CVE-2026-22924)
2 rules 1 TTP 1 CVESiemens SIMATIC CN 4100 versions before V5.0 are vulnerable to resource exhaustion due to improper restriction of unauthenticated connections, potentially leading to disruption of operations and unauthorized actions.
CVE-2025-40949 - Siemens RUGGEDCOM ROX Web UI Command Injection
2 rules 1 TTP 1 CVEAn authenticated remote command injection vulnerability exists in the web UI scheduler functionality of multiple RUGGEDCOM ROX devices before V2.17.1, allowing arbitrary command execution with root privileges.