Siemens published security advisories for multiple products, prompting both CISA ICS advisories and a Canadian Centre for Cyber Security alert covering a broad set of affected industrial/engineering software and OT-adjacent components. Reported issues include a stored XSS in Siemens Polarion (CVE-2025-40587; CVSS 7.6) where authenticated users can inject JavaScript via crafted document titles, and local privilege escalation paths in Siemens SINEC NMS and its User Management Component (UMC) (CVE-2026-25655, CVE-2026-25656; CVSS 7.8) that allow low-privileged users to modify configuration/search paths to load malicious DLLs and potentially gain elevated execution (including SYSTEM-level impact). Siemens also addressed a missing authorization condition affecting Siveillance Video Management Servers Webhooks/MIP Webhooks API (CVSS 6.3), enabling a read-only user to obtain full API access.
Additional advisories cover file-parsing and third-party component risks that can lead to crashes or potential code execution. Siemens NX is affected by multiple CGM file parsing flaws (CVE-2026-22923/22924/22925; CVSS 7.8) that can be triggered when a user opens a malicious file, and Siemens Solid Edge includes an out-of-bounds read in the PS/IGES Parasolid translator when processing crafted IGS files (CVSS 7.8). Desigo CC and SENTRON Powermanager are impacted via the third-party WIBU Systems CodeMeter Runtime chain tied to CVE-2023-38545 (curl SOCKS5 heap overflow; CVSS 8.8), with Siemens providing component update instructions. Siemens SINEC OS before V3.3 aggregates a large set of third-party CVEs across supported platforms, and Siemens COMOS advisories include multiple issues (up to CVSS 10) spanning potential code execution, DoS, data exposure, and access control violations; Siemens recommends updating where fixes are available and applying countermeasures where they are not yet released.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
22 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-14, CISA republished Siemens ProductCERT advisory SSA-827383 covering three vulnerabilities in Siemens Teamcenter, including a missing type check issue in PDF.js handling, a cross-site scripting flaw, and a hard-coded credential issue. Siemens identified affected Teamcenter versions across V2312 through V2512, released updated versions to remediate the issues, and recommended customers update and follow standard ICS exposure-reduction measures.
On 2026-05-14, CISA republished a Siemens ProductCERT advisory for a high-severity missing authentication vulnerability in Apache ActiveMQ Artemis affecting Siemens Opcenter RDnL. Siemens recommended updating to the latest ActiveMQ Artemis version and applying network protection and ICS segmentation measures to reduce risks including message injection, message exfiltration, and availability impacts.
On 2026-05-14, CISA republished a Siemens advisory for a stored cross-site scripting vulnerability in the SIMATIC S7 PLC Web Server affecting numerous SIMATIC and SIPLUS industrial automation products. Siemens said the flaw stems from improper validation of the PLC or station name shown on the communication parameters page, allowing an authenticated attacker who can download a TIA project to inject script that executes in another authorized user's browser session.
On 2026-05-14, CISA republished a Siemens ProductCERT advisory for a critical HTTP request smuggling vulnerability in Siemens SENTRON 7KT PAC1261 Data Manager before version 2.1.0. Siemens said exploitation could let an attacker retrieve authorization tokens and gain administrative control, and recommended updating to version 2.1.0 or later and restricting network access.
On 2026-05-14, CISA republished Siemens ProductCERT advisory SSA-032379 covering numerous third-party and product-specific vulnerabilities affecting Siemens SIMATIC CN 4100. The advisory highlighted multiple high- and critical-severity flaws, including Linux kernel, OpenSSL, Apache Tomcat, Oracle Java, and Siemens-specific denial-of-service and unauthenticated connection issues, and recommended network isolation and exposure-reduction measures.
On 2026-05-14, CISA republished a Siemens ProductCERT advisory for a high-severity remote code execution vulnerability affecting Siemens gPROMS Web Applications Publisher (gWAP) through vulnerable versions of the third-party Axios HTTP client library. Siemens identified gWAP as affected, released a new version, and recommended customers update while CISA also advised standard ICS exposure-reduction and network-segmentation measures.
On 2026-05-12, Zero Day Initiative publicly disclosed ZDI-26-316 / CVE-2025-12659, a CVSS 7.8 remote code execution vulnerability in Siemens Simcenter Femap caused by improper validation when parsing IPT files. Siemens issued an update to remediate the flaw, which had been responsibly reported to the vendor in August 2025.
On 2026-05-12, Siemens ProductCERT published security advisory SSA-870926. The reference indicates a new Siemens vulnerability disclosure event distinct from previously tracked advisories, though no synopsis or affected-product details are provided in the source summary.
On 2026-05-12, the Canadian Centre for Cyber Security published alert AV26-448 covering a new Siemens security advisory addressing vulnerabilities across numerous industrial, networking, engineering, and management products. The notice urged administrators to review Siemens guidance, apply mitigations, and install updates; for RUGGEDCOM APE1808, Siemens directed customers to contact support for patch information.
On 2026-04-21, CISA republished a Siemens ProductCERT advisory covering multiple high-severity vulnerabilities in SCALANCE W-700 IEEE 802.11n family devices before version 6.6.0, including flaws that could enable packet injection, privilege escalation, root shell execution, denial of service, information disclosure, or web compromise. Siemens released version 6.6.0 to address the issues and recommended customers update affected devices and follow network isolation and exposure-reduction measures.
On 2026-04-21, CISA republished a Siemens ProductCERT advisory for a high-severity authentication bypass vulnerability in Siemens SINEC NMS when used with the User Management Component (UMC). Siemens said the flaw could allow an unauthenticated remote attacker to gain unauthorized access and released a new version of SINEC NMS, while CISA and Siemens recommended updating and applying standard network isolation measures.
On 2026-04-21, CISA republished a Siemens ProductCERT advisory for CVE-2025-40745, an improper certificate validation flaw in Siemens Analytics Toolkit that could enable man-in-the-middle attacks against Analytics Service connections. The advisory identified affected Siemens applications including Siemens Software Center, Simcenter products, Solid Edge, and Tecnomatix Plant Simulation, and noted Siemens had released updated versions and recommended customers upgrade.
On 2026-04-21, CISA republished a Siemens ProductCERT advisory for a high-severity authorization bypass flaw in Siemens SINEC NMS before V4.0 SP3 that could let an authenticated remote attacker reset arbitrary user passwords. Siemens released version 4.0 SP3 to fix the issue and advised customers to update.
On 2026-04-14, the Canadian Centre for Cyber Security published alert AV26-347 covering newly issued Siemens security advisories for a broad range of software, industrial, networking, and engineering products. The notice urged administrators to review Siemens guidance, apply mitigations, and install updates for affected products including Siemens Software Center, Simcenter products, Solid Edge, SINEC NMS, RUGGEDCOM CROSSBOW, SIPROTEC 5, SIMATIC systems, Industrial Edge Management, and SCALANCE W-700 devices.
On 2026-03-26, Siemens ProductCERT published security advisory SSA-246443. The reference indicates a new Siemens vulnerability disclosure event distinct from the February advisory set and preceding the broader April 2026 advisory activity.
On 2026-02-12, CISA republished Siemens ProductCERT advisories for the affected Siemens products, including SINEC NMS, Siveillance Video Management Servers, NX, Desigo CC, SENTRON Powermanager, Solid Edge, SINEC OS, COMOS, and Polarion. The republications summarized the disclosed vulnerabilities, available fixes, and standard ICS hardening recommendations.
On 2026-02-10, the Canadian Centre for Cyber Security issued alert AV26-106 summarizing Siemens' advisories and urging administrators to review the vendor guidance, apply mitigations, and install necessary updates. The notice highlighted affected engineering, OT management, building management, power management, video management, and ALM products.
On 2026-02-10, Siemens published a coordinated set of security advisories covering multiple products including SINEC NMS, Siveillance Video Management Servers, NX, Desigo CC, SENTRON Powermanager, Solid Edge, SINEC OS, COMOS, and Polarion. The advisories disclosed vulnerabilities and provided updates, hotfixes, or mitigation guidance for affected customers.
By 2025-11-20, reporting indicated that CISA had stopped publishing ICS security advisories for Siemens product vulnerabilities. This marked a change in how Siemens vulnerability disclosures were being surfaced through U.S. government ICS advisory channels.
Between 2024-10-08 and 2024-10-14, ICS advisories covered 34 Siemens vulnerabilities across products including Tecnomatix Plant Simulation, SENTRON 7KM PAC3200, Simcenter Nastran, and SINEC Security Monitor. Reported issues included arbitrary code execution, denial of service, argument injection, and an improper authentication flaw in SENTRON 7KM PAC3200 for which Siemens said no fix was planned.
On 2024-03-12, Siemens released 22 security advisories, including 11 new advisories and 11 updated advisories. The batch included three critical and six high-severity new advisories, and most were later correlated with CISA ICS advisories, except SSA-552874 covering a denial-of-service flaw in SIPROTEC 5 Devices.
Siemens ProductCERT published security advisory SSA-626968, indicating a new vendor vulnerability disclosure event distinct from the previously tracked February, March, and April 2026 Siemens advisories. The reference establishes the existence of a separate advisory, though affected products and technical details are not provided in the source summary.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
30 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcelinkedin.com
Open sourcedecisioninsights.ai
Open sourcecyble.com
Open sourcecert-portal.siemens.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.