Siemens disclosed multiple high-severity vulnerabilities in SINEC INS that affect all versions before V1.0 SP2 Update 6, including CVE-2026-46746 and CVE-2026-46748. The first flaw is an OS command injection issue in the /api/sftp/uploadFiles endpoint, where crafted directory names can plant shell payloads that execute when directory listings are viewed; Siemens said an authenticated remote attacker with low privileges could run arbitrary commands on the underlying operating system as the sinecins service user. The second flaw stems from a binary configured with the Linux capability CAP_DAC_OVERRIDE, allowing a local attacker to bypass file permission checks, modify files arbitrarily, and escalate privileges to root.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-09, CERT-FR issued an advisory stating that multiple vulnerabilities had been discovered in Siemens products. The notice said the flaws could enable arbitrary code execution, denial of service, and compromise of data confidentiality.
On 2026-06-09, Siemens published a broader security advisory covering multiple vulnerabilities across several industrial and automation products, including SINEC INS, SIPROTEC 5, TIA Portal, and products affected by an OpenSSL buffer overflow issue. The advisory included updates or mitigation guidance for the listed issues.
On 2026-06-09, Siemens published a security advisory covering multiple vulnerabilities in SINEC INS versions earlier than V1.0 SP2 Update 6, including CVE-2026-46746 and CVE-2026-46748. The issues include authenticated remote command injection and local privilege escalation to root.
On 2026-06-02, Siemens published advisory SSA-253495 covering multiple critical vulnerabilities affecting RUGGEDCOM RST2428P devices before version V4.0. The Canadian Centre for Cyber Security relayed the notice and urged users to apply mitigations and updates.
Siemens provided firmware version V2.4.24 as the fixed release for CVE-2025-40771, a missing-authentication flaw affecting several SIMATIC CP 1542SP-1, CP 1543SP-1, and SIPLUS ET 200SP variants. The vulnerability allows unauthenticated access to configuration data on affected devices running firmware earlier than V2.4.24.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcecvefeed.io
Open sourcecert.ssi.gouv.fr
Open sourcecvefeed.io
Open sourcecyber.gc.ca
Open sourcezeropath.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.