ZeroHour
Canadian Centre for Cyber Securitypublished ()ingested Canadian Centre for Cyber Security

[Control Systems] Siemens security advisory (AV26-881)

lowAdvisoryimportance 20
AI summary · glm-5.3-flash

Siemens patched an account hijacking vulnerability in the Mendix SAML module affecting Mendix 9.24, 10, and 11 releases before fixed versions.

The Canadian Centre for Cyber Security relayed Siemens advisory SSA-887643, which addresses an account hijacking vulnerability in the Mendix SAML module. Affected components are the Mendix 10 and Mendix 11 compatible modules prior to V4.2.3 and the Mendix 9.24 compatible module prior to V3.6.27. Administrators are encouraged to review the linked advisories and apply the available updates.

  • Affects Mendix SAML modules for Mendix 9.24, 10, and 11 prior to fixed versions
  • Siemens advisory SSA-887643 covers account hijacking in the SAML module
  • Canadian Cyber Centre urges administrators to apply available updates
Full article80 words · extracted from cyber.gc.ca · click to collapse

Serial Number: AV26-881
Date: September 3, 2026

As of September 3, 2026, Siemens is affected by a vulnerability in the following products:

  • Mendix SAML (Mendix 10 compatible)
    • Prior to V4.2.3
  • Mendix SAML (Mendix 11 compatible)
    • Prior to V4.2.3
  • Mendix SAML (Mendix 9.24 compatible)
    • Prior to V3.6.27

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/control-systems-siemens-security-advisory-av26-881