CISA republishes four Siemens ICS flaws and retracts one CVE
CISA republished four Siemens ICS advisories for critical and high flaws, then revoked a Mendix Runtime advisory after CVE-2026-7891 was retracted.
On 22 September 2026 CISA republished four Siemens industrial-control advisories covering unauthenticated or low-privilege flaws in Edge Management, Siveillance Control, Desigo CC, and SIMOVE Fleetmanager/SIPLANT. CVE-2026-18963 (CVSS 9.1) lets an unauthenticated remote attacker finish a Keycloak password reset without the email link on listed Edge Management Cloud, Pro V1, Pro V2, and Virtual ranges. CVE-2026-50093 (CVSS 9.0) is unrestricted file upload that can yield root on the Siveillance OIS server; Siemens lists fixed Control and Control Pro builds. CVE-2026-34223 (CVSS 8.2) executes insufficiently validated scripts in Desigo CC graphics when a privileged user opens a crafted document, and CVE-2026-67367 (CVSS 8.6) is path traversal that can expose secrets over an embedded HTTP server. None of those four advisories report exploitation. On 24 September 2026 CISA revoked the Mendix Runtime advisory ICSA-26-209-02 after CVE-2026-7891 was retracted as expected configuration rather than a vulnerability; the reports do not otherwise conflict.
- On 2026-09-22 CISA republished four Siemens ProductCERT advisories: SSA-503852 (CVE-2026-18963, CVSS 3.1 9.1), SSA-254516 (CVE-2026-50093, CVSS 3.1 9.0), SSA-330084 (CVE-2026-34223, CVSS 3.1 8.2), and SSA-517424 (CVE-2026-67367, CVSS 3.1…
- CVE-2026-18963 is an unauthenticated remote password-reset flaw in Industrial Edge Management’s Keycloak reset-credentials flow; affected ranges are Cloud (all versions), Pro V1 from 1.14.9 before 1.15.20, Pro V2 from 2.2.0 before 2.2.2,…
- CVE-2026-50093 lets a low-privileged adjacent-network attacker upload arbitrary files and gain root on the Siveillance Open Interface Services server. Fixed builds start at Control Pro 3.0.12.2173 and 4.0.9.2178, and Control 3.0.22.2177…
- CVE-2026-34223, reported by Michelin CERT, lets scripts in crafted Desigo CC graphics run when a privileged user opens them and write arbitrary files on the client. All Desigo CC V6 and V7 versions are listed as affected; access is local…
- CVE-2026-67367 is unauthenticated relative path traversal in the embedded HTTP server of SIMOVE Fleetmanager and SIPLANT that can read credential stores, private keys, and configuration secrets. Fleetmanager builds before 3.1.13, 3.2.4,…
- On 2026-09-24 CISA Update A revoked ICSA-26-209-02 for Siemens Mendix Runtime. CVE-2026-7891, previously scored CVSS 9.1, was retracted as expected configuration that does not expose the protected attribute; Siemens revoked SSA-814963. No…
Coverage timelineoldest first · each row is one article
- · 4d agoSiemens Desigo CC family
CISA Advisories· 60
Siemens Desigo CC graphics documents can run attacker scripts and compromise client operating systems.
- · 4d agoSiemens Industrial Edge Management
CISA Advisories· 74
Siemens Industrial Edge Management has a critical unauthenticated password-reset flaw enabling remote account takeover.
- · 4d agoSiemens SIMOVE Fleetmanager and SIPLANT
CISA Advisories· 58
Siemens patched a high-severity path traversal in SIMOVE Fleetmanager and SIPLANT that can expose secrets.
Vulnerabilities in this storyAll →
- CVE-2026-189639.13%Unauthenticated Account Takeover via Password Reset Flow in Red Hat Build of Keycloakpublished · Red Hat Build of Keycloak (keycloak-services component, reset-credentials flow) PoC