Historical snapshot · Cybersecurity

CISA Advisories

Cybersecurity advisories and mitigation guidance for networks and critical infrastructure.

This page is an archived snapshot of the CISA Advisories feed collected on Oct 1, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
30 recordsOfficial source · JSON
· CISA Cybersecurity Advisory

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability CVE-2026-94127 F5 BIG-IP APM…
Read full source summary
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
· CISA Cybersecurity Advisory

Siemens SIPLUS and SIMATIC Products

View CSAF Summary Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIPLUS and SIMATIC Products are affected:…
Read full source summary
View CSAF Summary Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIPLUS and SIMATIC Products are affected: SIMATIC AX Runtime Core Linux Common Debian vers:all/* (CVE-2026-31431) SIMATIC AX Runtime Core Linux Common Debian arm64 vers:all/* (CVE-2026-31431) SIMATIC AX Runtime Core Linux Platform Container Common Debian Development vers:all/* (CVE-2026-31431) SIMATIC AX Runtime Core Linux VMWare Development vers:all/* (CVE-2026-31431) SIMATIC CN 4100 vers:intdot/<6.0 (CVE-2026-31431) SIMATIC HMI MTP1000 Unified Basic (6AV2123-3KB32-0AW0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1000 Unified Comfort Panel (6AV2128-3KB06-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1000 Unified Comfort Panel hygienic (6AV2128-3KB40-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1000 Unified Comfort Panel hygienic neutral design (6AV2128-3KB70-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1000, Unified Comfort Panel neutral (6AV2128-3KB36-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1200 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3MB27-1BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1200 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3MB27-0BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1200 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3MB27-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1200 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3MB57-1BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3MB57-0BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3MB57-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1200 Unified Basic (6AV2123-3MB32-0AW0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1200 Unified Comfort Panel (6AV2128-3MB06-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1200 Unified Comfort Panel hygienic (6AV2128-3MB40-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1200 Unified Comfort Panel hygienic neutral design (6AV2128-3MB70-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1200 Unified Comfort Panel neutral design (6AV2128-3MB36-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1500 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3QB27-1BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1500 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3QB27-0BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1500 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3QB27-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1500 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3QB57-1BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1500 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3QB57-0BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1500 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3QB57-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1500 Unified Comfort Panel (6AV2128-3QB06-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1500 Unified Comfort Panel hygienic (6AV2128-3QB40-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1500 Unified Comfort Panel hygienic neutral design (6AV2128-3QB70-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1500 Unified Comfort Panel neutral design (6AV2128-3QB36-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1900 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3UB27-1BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1900 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3UB27-0BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1900 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3UB27-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1900 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3UB57-1BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1900 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3UB57-0BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1900 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3UB57-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1900 Unified Comfort Panel (6AV2128-3UB06-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1900 Unified Comfort Panel hygienic (6AV2128-3UB40-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1900 Unified Comfort Panel hygienic neutral design (6AV2128-3UB70-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1900 Unified Comfort Panel neutral design (6AV2128-3UB36-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP2200 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3XB27-1BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP2200 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3XB27-0BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP2200 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3XB27-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP2200 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3XB57-1BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3XB57-0BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3XB57-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP2200 Unified Comfort Hygienic (6AV2128-3XB40-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP2200 Unified Comfort Hygienic neutral design (6AV2128-3XB70-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP2200 Unified Comfort Panel (6AV2128-3XB06-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP2200 Unified Comfort Panel neutral design (6AV2128-3XB36-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP400 Unified Basic (6AV2123-3DB32-0AW0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP700 Unified Basic (6AV2123-3GB32-0AW0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP700 Unified Comfort Panel (6AV2128-3GB06-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP700 Unified Comfort Panel hygienic neutral design (6AV2128-3GB40-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP700 Unified Comfort Panel hygienic neutral design (6AV2128-3GB70-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP700, Unified Comfort Panel neutral design (6AV2128-3GB36-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) vers:all/* (CVE-2026-31431) SIMATIC IPC Industrial Edge Device OS (IED-OS) vers:all/* (CVE-2026-31431) SIMATIC S7-1500 TM MFP (6ES7558-1AA00-0AB0) vers:all/* (CVE-2026-31431) SIPLUS HMI MTP1000 Unified Basic (6AG1123-3KB32-2AW0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIPLUS HMI MTP1000 Unified Comfort (6AG1128-3KB06-4AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIPLUS HMI MTP1200 Unified Basic (6AG1123-3MB32-2AW0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIPLUS HMI MTP1200 Unified Comfort (6AG1128-3MB06-4AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIPLUS HMI MTP400 Unified Basic (6AG1123-3DB32-2AW0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIPLUS HMI MTP700 Unified Basic (6AG1123-3GB32-2AW0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIPLUS HMI MTP700 Unified Comfort (6AG1128-3GB06-4AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431) CVSS Vendor Equipment Vulnerabilities v3 7.8 Siemens Siemens SIPLUS and SIMATIC Products Incorrect Resource Transfer Between Spheres Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-31431 In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly. View CVE Details Affected Products Siemens SIPLUS and SIMATIC Products Vendor: Siemens Product Version: SIMATIC AX Runtime Core Linux Common Debian, SIMATIC HMI MTP1000, Unified Comfort Panel neutral (6AV2128-3KB36-0AX1) < V21.2.1, SIMATIC HMI MTP1200 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3MB27-1BX0) < V21.2.1, SIMATIC HMI MTP1200 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3MB27-0BX0) < V21.2.1, SIMATIC HMI MTP1200 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3MB27-0AX0) < V21.2.1, SIMATIC HMI MTP1200 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3MB57-1BX0) < V21.2.1, SIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3MB57-0BX0) < V21.2.1, SIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3MB57-0AX0) < V21.2.1, SIMATIC HMI MTP1200 Unified Basic (6AV2123-3MB32-0AW0) < V21.2.1, SIMATIC HMI MTP1200 Unified Comfort Panel (6AV2128-3MB06-0AX1) < V21.2.1, SIMATIC HMI MTP1200 Unified Comfort Panel hygienic (6AV2128-3MB40-0AX0) < V21.2.1, SIMATIC AX Runtime Core Linux Common Debian arm64, SIMATIC HMI MTP1200 Unified Comfort Panel hygienic neutral design (6AV2128-3MB70-0AX0) < V21.2.1, SIMATIC HMI MTP1200 Unified Comfort Panel neutral design (6AV2128-3MB36-0AX1) < V21.2.1, SIMATIC HMI MTP1500 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3QB27-1BX0) < V21.2.1, SIMATIC HMI MTP1500 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3QB27-0BX0) < V21.2.1, SIMATIC HMI MTP1500 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3QB27-0AX0) < V21.2.1, SIMATIC HMI MTP1500 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3QB57-1BX0) < V21.2.1, SIMATIC HMI MTP1500 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3QB57-0BX0) < V21.2.1, SIMATIC HMI MTP1500 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3QB57-0AX0) < V21.2.1, SIMATIC HMI MTP1500 Unified Comfort Panel (6AV2128-3QB06-0AX1) < V21.2.1, SIMATIC HMI MTP1500 Unified Comfort Panel hygienic (6AV2128-3QB40-0AX0) < V21.2.1, SIMATIC AX Runtime Core Linux Platform Container Common Debian Development, SIMATIC HMI MTP1500 Unified Comfort Panel hygienic neutral design (6AV2128-3QB70-0AX0) < V21.2.1, SIMATIC HMI MTP1500 Unified Comfort Panel neutral design (6AV2128-3QB36-0AX1) < V21.2.1, SIMATIC HMI MTP1900 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3UB27-1BX0) < V21.2.1, SIMATIC HMI MTP1900 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3UB27-0BX0) < V21.2.1, SIMATIC HMI MTP1900 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3UB27-0AX0) < V21.2.1, SIMATIC HMI MTP1900 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3UB57-1BX0) < V21.2.1, SIMATIC HMI MTP1900 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3UB57-0BX0) < V21.2.1, SIMATIC HMI MTP1900 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3UB57-0AX0) < V21.2.1, SIMATIC HMI MTP1900 Unified Comfort Panel (6AV2128-3UB06-0AX1) < V21.2.1, SIMATIC HMI MTP1900 Unified Comfort Panel hygienic (6AV2128-3UB40-0AX0) < V21.2.1, SIMATIC AX Runtime Core Linux VMWare Development, SIMATIC HMI MTP1900 Unified Comfort Panel hygienic neutral design (6AV2128-3UB70-0AX0) < V21.2.1, SIMATIC HMI MTP1900 Unified Comfort Panel neutral design (6AV2128-3UB36-0AX1) < V21.2.1, SIMATIC HMI MTP2200 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3XB27-1BX0) < V21.2.1, SIMATIC HMI MTP2200 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3XB27-0BX0) < V21.2.1, SIMATIC HMI MTP2200 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3XB27-0AX0) < V21.2.1, SIMATIC HMI MTP2200 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3XB57-1BX0) < V21.2.1, SIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3XB57-0BX0) < V21.2.1, SIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3XB57-0AX0) < V21.2.1, SIMATIC HMI MTP2200 Unified Comfort Hygienic (6AV2128-3XB40-0AX0) < V21.2.1, SIMATIC HMI MTP2200 Unified Comfort Hygienic neutral design (6AV2128-3XB70-0AX0) < V21.2.1, SIMATIC CN 4100 < V6.0, SIMATIC HMI MTP2200 Unified Comfort Panel (6AV2128-3XB06-0AX1) < V21.2.1, SIMATIC HMI MTP2200 Unified Comfort Panel neutral design (6AV2128-3XB36-0AX1) < V21.2.1, SIMATIC HMI MTP400 Unified Basic (6AV2123-3DB32-0AW0) < V21.2.1, SIMATIC HMI MTP700 Unified Basic (6AV2123-3GB32-0AW0) < V21.2.1, SIMATIC HMI MTP700 Unified Comfort Panel (6AV2128-3GB06-0AX1) < V21.2.1, SIMATIC HMI MTP700 Unified Comfort Panel hygienic neutral design (6AV2128-3GB40-0AX0) < V21.2.1, SIMATIC HMI MTP700 Unified Comfort Panel hygienic neutral design (6AV2128-3GB70-0AX0) < V21.2.1, SIMATIC HMI MTP700, Unified Comfort Panel neutral design (6AV2128-3GB36-0AX1) < V21.2.1, SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2), SIMATIC IPC Industrial Edge Device OS (IED-OS), SIMATIC HMI MTP1000 Unified Basic (6AV2123-3KB32-0AW0) < V21.2.1, SIMATIC S7-1500 TM MFP (6ES7558-1AA00-0AB0), SIPLUS HMI MTP1000 Unified Basic (6AG1123-3KB32-2AW0) < V21.2.1, SIPLUS HMI MTP1000 Unified Comfort (6AG1128-3KB06-4AX1) < V21.2.1, SIPLUS HMI MTP1200 Unified Basic (6AG1123-3MB32-2AW0) < V21.2.1, SIPLUS HMI MTP1200 Unified Comfort (6AG1128-3MB06-4AX1) < V21.2.1, SIPLUS HMI MTP400 Unified Basic (6AG1123-3DB32-2AW0) < V21.2.1, SIPLUS HMI MTP700 Unified Basic (6AG1123-3GB32-2AW0) < V21.2.1, SIPLUS HMI MTP700 Unified Comfort (6AG1128-3GB06-4AX1) < V21.2.1, SIMATIC HMI MTP1000 Unified Comfort Panel (6AV2128-3KB06-0AX1) < V21.2.1, SIMATIC HMI MTP1000 Unified Comfort Panel hygienic (6AV2128-3KB40-0AX0) < V21.2.1, SIMATIC HMI MTP1000 Unified Comfort Panel hygienic neutral design (6AV2128-3KB70-0AX0) < V21.2.1 Product Status: known_affected Remediations Mitigation Limit access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only. Mitigation Only build and run applications from trusted sources. None available Currently no fix is available Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825897/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825897/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825897/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825897/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 SP2 Update 1 or later version TODO: download link missing Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V21 Update 2 SR1 or later version https://support.industry.siemens.com/cs/ww/en/view/109825605/ Vendor fix Update to V6.0 or later version https://support.industry.siemens.com/cs/ww/en/view/109814144/ Vendor fix For more information see the associated Siemens security advisory SSA-328642: "Copy Fail" Vulnerability in Multiple Industrial Products - CSAF Version, SSA-328642: "Copy Fail" Vulnerability in Multiple Industrial Products - HTML Version Relevant CWE: CWE-669 Incorrect Resource Transfer Between Spheres Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Acknowledgments Siemens ProductCERT reported this vulnerability to CISA. General Recommendations As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity Additional Resources For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories Terms of Use The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Siemens ProductCERT SSA-328642 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory. Revision History Initial Release Date: 2026-09-08 Date Revision Summary 2026-09-08 1 Publication Date 2026-09-22 2 Initial CISA Republication of Siemens ProductCERT SSA-328642 advisory Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Siemens SIMOVE Fleetmanager and SIPLANT

View CSAF Summary SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens SIMOVE Fleetmanager and SIPLANT are affected: SIMOVE Fleetmanager V3.1 vers:intdot/<3.1.13 (CVE-2026-67367) SIMOVE…
Read full source summary
View CSAF Summary SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens SIMOVE Fleetmanager and SIPLANT are affected: SIMOVE Fleetmanager V3.1 vers:intdot/<3.1.13 (CVE-2026-67367) SIMOVE Fleetmanager V3.2 vers:intdot/<3.2.4 (CVE-2026-67367) SIMOVE Fleetmanager V3.3 vers:intdot/<3.3.2 (CVE-2026-67367) SIMOVE Fleetmanager V4.0 vers:intdot/<4.0.1 (CVE-2026-67367) SIPLANT V1.7 vers:all/* (CVE-2026-67367) SIPLANT V2.2 vers:all/* (CVE-2026-67367) SIPLANT V3.0 vers:all/* (CVE-2026-67367) SIPLANT V3.1 vers:intdot/<3.1.4 (CVE-2026-67367) CVSS Vendor Equipment Vulnerabilities v3 8.6 Siemens Siemens SIMOVE Fleetmanager and SIPLANT Relative Path Traversal Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-67367 Affected devices do not properly validate and neutralize directory traversal sequences in the file-serving endpoint of the embedded HTTP server. This could allow an unauthenticated remote attacker to read arbitrary files from the underlying operating system without any credentials, potentially exposing sensitive data such as credential stores, private keys, and configuration secrets. View CVE Details Affected Products Siemens SIMOVE Fleetmanager and SIPLANT Vendor: Siemens Product Version: SIMOVE Fleetmanager V3.1 < V3.1.13, SIMOVE Fleetmanager V3.2 < V3.2.4, SIMOVE Fleetmanager V3.3 < V3.3.2, SIMOVE Fleetmanager V4.0 < V4.0.1, SIPLANT V1.7, SIPLANT V2.2, SIPLANT V3.0, SIPLANT V3.1 < V3.1.4 Product Status: known_affected Remediations Mitigation Configure appropriate user management by restricting services' access rights to project files. Mitigation Restrict network access to affected devices. Vendor fix Update to V3.1.13 or later version https://support.industry.siemens.com/cs/ww/en/view/109813191/ Vendor fix Update to V3.1.4 or later version Contact customer support siplant-support.de@siemens.com Vendor fix Update to V3.2.4 or later version https://support.industry.siemens.com/cs/ww/en/view/109813191/ Vendor fix Update to V3.3.2 or later version https://support.industry.siemens.com/cs/ww/en/view/109813191/ Vendor fix Update to V4.0.1 or later version https://support.industry.siemens.com/cs/ww/en/view/110004946/ Vendor fix Contact customer support siplant-support.de@siemens.com Mitigation For more information see the associated Siemens security advisory SSA-517424: Path Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT - CSAF Version, SSA-517424: Path Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT - HTML Version. Relevant CWE: CWE-23 Relative Path Traversal Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.6 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N Acknowledgments Siemens ProductCERT reported this vulnerability to CISA. General Recommendations As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity Additional Resources For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories Terms of Use The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Siemens ProductCERT SSA-517424 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory. Revision History Initial Release Date: 2026-09-08 Date Revision Summary 2026-09-08 1 Publication Date 2026-09-22 2 Initial CISA Republication of Siemens ProductCERT SSA-517424 advisory Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Siemens Desigo CC family

View CSAF Summary A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client…
Read full source summary
View CSAF Summary A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization. The following versions of Siemens Desigo CC family are affected: Desigo CC family V6 vers:all/* (CVE-2026-34223) Desigo CC family V7 vers:all/* (CVE-2026-34223) CVSS Vendor Equipment Vulnerabilities v3 8.2 Siemens Siemens Desigo CC family Improper Control of Generation of Code ('Code Injection') Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-34223 The affected application is vulnerable to Client Code Execution (CCE) due to insufficient input validation when handling scripts embedded within user-defined graphics documents. Specifically, when the script within a graphics document is designed or modified by an attacker to include malicious commands. When a user opens a compromised graphics document, the embedded script is executed on the client application instance, allowing an attacker to write arbitrary files to the client's operating system. Successful exploitation requires an attacker to craft a malicious graphics document and entice a user with sufficient privileges to display it. This could lead to compromise of the client operating system and potential lateral movement within the organization. View CVE Details Affected Products Siemens Desigo CC family Vendor: Siemens Product Version: Desigo CC family V6, Desigo CC family V7 Product Status: known_affected Remediations Mitigation Evaluate authorization policy for Graphics application following Least Privilege principle, so only required users have access to the configuration. None available Currently no fix is available. Mitigation For more information see the associated Siemens security advisory SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family - CSAF Version, SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family - HTML Version. Relevant CWE: CWE-94 Improper Control of Generation of Code ('Code Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.2 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H Acknowledgments Michelin CERT reported this vulnerability to Siemens. General Recommendations As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity Additional Resources For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories Terms of Use The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Siemens ProductCERT SSA-330084 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory. Revision History Initial Release Date: 2026-09-08 Date Revision Summary 2026-09-08 1 Publication Date 2026-09-22 2 Initial CISA Republication of Siemens ProductCERT SSA-330084 advisory Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Siemens Siveillance Control

View CSAF Summary A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server. Siemens has released patches and updates for Siveillance OIS to apply to the products…
Read full source summary
View CSAF Summary A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server. Siemens has released patches and updates for Siveillance OIS to apply to the products that incorporate the OIS service, and recommends to update to the latest versions. The following versions of Siemens Siveillance Control are affected: Siveillance Control Pro V3.0 vers:intdot/<3.0.12.2173 (CVE-2026-50093) Siveillance Control Pro V4.0 vers:intdot/<4.0.9.2178 (CVE-2026-50093) Siveillance Control V3.0 vers:intdot/<3.0.22.2177 (CVE-2026-50093) Siveillance Control V4.0 vers:intdot/<4.0.11.2177 (CVE-2026-50093) CVSS Vendor Equipment Vulnerabilities v3 9 Siemens Siemens Siveillance Control Unrestricted Upload of File with Dangerous Type Background Critical Infrastructure Sectors: Critical Manufacturing, Communications, Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-50093 A vulnerability in the OIS web module allows an attacker to upload arbitrary files to the server. Successful exploitation of this vulnerability could allow an attacker to gain root access on the host system, potentially leading to a full compromise of the affected OIS environment. View CVE Details Affected Products Siemens Siveillance Control Vendor: Siemens Product Version: Siveillance Control Pro V3.0 < V3.0.12.2173, Siveillance Control Pro V4.0 < V4.0.9.2178, Siveillance Control V3.0 < V3.0.22.2177, Siveillance Control V4.0 < V4.0.11.2177 Product Status: known_affected Remediations Vendor fix Update to V3.0.12.2173 or later version https://support.industry.siemens.com/cs/ww/en/view/110004860/ Vendor fix Update to V3.0.22.2177 or later version https://support.industry.siemens.com/cs/ww/en/view/110004859/ Vendor fix Update to V4.0.11.2177 or later version https://support.industry.siemens.com/cs/ww/en/view/110004859/ Vendor fix Update to V4.0.9.2178 or later version https://support.industry.siemens.com/cs/ww/en/view/110004860/ Vendor fix For more information see the associated Siemens security advisory SSA-254516: Arbitrary File Upload in OIS Web Module - CSAF Version, SSA-254516: Arbitrary File Upload in OIS Web Module - HTML Version. Relevant CWE: CWE-434 Unrestricted Upload of File with Dangerous Type Metrics CVSS Version Base Score Base Severity Vector String 3.1 9 CRITICAL CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Acknowledgments Siemens ProductCERT reported this vulnerability to CISA. General Recommendations As a general security measure Siemens strongly recommends to protect network access to affected products with appropriate mechanisms. It is advised to follow recommended security practices in order to run the devices in a protected IT environment. Additional Resources For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories Terms of Use The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Siemens ProductCERT SSA-254516 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory. Revision History Initial Release Date: 2026-09-08 Date Revision Summary 2026-09-08 1 Publication Date 2026-09-22 2 Initial CISA Republication of Siemens ProductCERT SSA-254516 advisory Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Siemens Industrial Edge Management

View CSAF Summary Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Industrial Edge Management…
Read full source summary
View CSAF Summary Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Industrial Edge Management are affected: Industrial Edge Management Cloud vers:all/* (CVE-2026-18963) Industrial Edge Management Pro V1 vers:intdot/>=1.14.9|<1.15.20 (CVE-2026-18963) Industrial Edge Management Pro V2 vers:intdot/>=2.2.0|<2.2.2 (CVE-2026-18963) Industrial Edge Management Virtual vers:intdot/>=2.6.0|<2.9.1 (CVE-2026-18963) CVSS Vendor Equipment Vulnerabilities v3 9.1 Siemens Siemens Industrial Edge Management Weak Password Recovery Mechanism for Forgotten Password Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-18963 A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials. View CVE Details Affected Products Siemens Industrial Edge Management Vendor: Siemens Product Version: Industrial Edge Management Cloud, Industrial Edge Management Pro V1 >= V1.14.9 < V1.15.20, Industrial Edge Management Pro V2 >= V2.2.0 < V2.2.2, Industrial Edge Management Virtual >= V2.6.0 < V2.9.1 Product Status: known_affected Remediations Mitigation Block direct internet access to IEM Pro / IEM Virtual The most effective immediate measure is to block direct internet access to your IEM Pro or IEM V instance. This ensures that no external attacks can occur via this vulnerability. Mitigation Configure a Web Application Firewall (WAF) or Reverse Proxy If complete blocking of internet access is not immediately feasible, you can use a Web Application Firewall (WAF) or a Reverse Proxy to block the affected path. Please configure your WAF or Reverse Proxy to block the following path: /auth/realms/customer/login-actions/reset-credentials Please note that by blocking this path, the password reset functionality will be unavailable. Mitigation Deactivate Password Reset in Keycloak Realm Settings Deactivate the password reset functionality directly within the Keycloak realm settings. To do this, navigate to: Identity & access management > realm settings > Login > Forgot password > Off Please note that by deactivating this setting, the password reset functionality will be unavailable. Vendor fix Update to V1.15.20 or later version https://iehub.eu1.edge.siemens.cloud/ Vendor fix Update to V2.2.2 or later version https://iehub.eu1.edge.siemens.cloud/ Vendor fix Update to V2.9.1 or later version https://iehub.eu1.edge.siemens.cloud/ Vendor fix Vulnerability mitigated with firewall rules on 2026-08-26 and fixed with update on 2026-09-02; no user actions necessary. Mitigation For more information see the associated Siemens security advisory SSA-503852: Authentication Bypass Vulnerability in Industrial Edge Management - CSAF Version, SSA-503852: Authentication Bypass Vulnerability in Industrial Edge Management - HTML Version Relevant CWE: CWE-640 Weak Password Recovery Mechanism for Forgotten Password Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.1 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Acknowledgments Siemens ProductCERT reported this vulnerability to CISA. General Recommendations As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity Additional Resources For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories Terms of Use The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Siemens ProductCERT SSA-503852 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory. Revision History Initial Release Date: 2026-09-08 Date Revision Summary 2026-09-08 1 Publication Date 2026-09-22 2 Initial CISA Republication of Siemens ProductCERT SSA-503852 advisory Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

lwIP (Lightweight IP)

View CSAF Summary Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system. The following versions of lwIP (Lightweight IP) are affected: API >=2.0.1|<=2.2.1 (CVE-2026-91018) CVSS Vendor Equipment Vulnerabilities v3 8.8 lwIP lwIP (Lightweight IP) Double Free Background Critical Infrastructure Sectors: Chemical,…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system. The following versions of lwIP (Lightweight IP) are affected: API >=2.0.1|<=2.2.1 (CVE-2026-91018) CVSS Vendor Equipment Vulnerabilities v3 8.8 lwIP lwIP (Lightweight IP) Double Free Background Critical Infrastructure Sectors: Chemical, Communications, Critical Manufacturing, Energy, Financial Services, Healthcare and Public Health, Transportation Systems, Water and Wastewater Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Sweden Vulnerabilities Expand All + CVE-2026-91018 The affected product has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system. View CVE Details Affected Products lwIP (Lightweight IP) Vendor: lwIP Product Version: lwIP API: >=2.0.1|<=2.2.1 Product Status: known_affected Remediations Mitigation Users of lwIP are encouraged to update their version of lwIP using the repository found at https://cgit.git.savannah.gnu.org/cgit/lwip.git. The commit identifier that contains the fix is f873b6295933e4149a2132adf3e9a2d2a676a5ec. Relevant CWE: CWE-415 Double Free Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments Eric Evenchick of Tetrel Security reported this vulnerability to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely. Revision History Initial Release Date: 2026-09-22 Date Revision Summary 2026-09-22 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

OpenPLC Runtime v3

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives. The following versions of OpenPLC Runtime v3 are affected: OpenPLC 3 (CVE-2026-88020) CVSS Vendor Equipment Vulnerabilities v3 6.1 Autonomy…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives. The following versions of OpenPLC Runtime v3 are affected: OpenPLC 3 (CVE-2026-88020) CVSS Vendor Equipment Vulnerabilities v3 6.1 Autonomy Logic OpenPLC Runtime v3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Transportation Systems, Water and Wastewater Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-88020 The affected product is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding. View CVE Details Affected Products OpenPLC Runtime v3 Vendor: Autonomy Logic Product Version: Autonomy Logic OpenPLC: 3 Product Status: known_affected Remediations Vendor fix Autonomy Logic recommends users upgrade to OpenPLC v4 as OpenPLC v3 is end-of-life and is no longer receiving patches, bug fixes, or security updates. Relevant CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 4.0 5.3 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N Acknowledgments Rajivarnan R. and Shirshak of Secnora reported this vulnerability to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-09-22 Date Revision Summary 2026-09-22 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security…
Read full source summary
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
· CISA Cybersecurity Advisory

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-39964 Linux Kernel Race Condition Vulnerability CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational…
Read full source summary
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-39964 Linux Kernel Race Condition Vulnerability CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
Browse saved snapshots