Siemens Industrial Edge Management
Siemens Industrial Edge Management has a critical unauthenticated password-reset flaw enabling remote account takeover.
CISA republished Siemens ProductCERT SSA-503852 for CVE-2026-18963, a weak password-recovery flaw in Industrial Edge Management. An unauthenticated remote attacker can complete a password reset without the email verification link and take over accounts. CVSS 3.1 is 9.1. Affected ranges are Cloud (all versions), Pro V1 from 1.14.9 before 1.15.20, Pro V2 from 2.2.0 before 2.2.2, and Virtual from 2.6.0 before 2.9.1. The defect is in the Keycloak reset-credentials flow; the advisory does not report exploitation.