ZeroHour
Story · 1 source · 1 articlefirst updated ()

Canadian Cyber Centre relays two Siemens advisories: Mendix SAML account hijacking fix (SSA-887643) and multi-product vulnerabilities (AV26-881, AV26-890)

lowAdvisoryimportance 20
What's new: First merged summary for this story; no prior summary existed.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

The Canadian Centre for Cyber Security relayed two separate Siemens advisories in September 2026. AV26-881 (2026-09-03) covers Siemens advisory SSA-887643, an account hijacking vulnerability in the Mendix SAML module affecting Mendix 9.24, 10, and 11 releases…

The Canadian Centre for Cyber Security relayed two distinct Siemens advisories in early September 2026; the reports do not conflict, as they cover different advisories. The first (AV26-881, published 2026-09-03) relays Siemens advisory SSA-887643, which addresses an account hijacking vulnerability in the Mendix SAML module. Affected components are the Mendix 10 and Mendix 11 compatible modules prior to V4.2.3 and the Mendix 9.24 compatible module prior to V3.6.27. The second (AV26-890, dated 2026-09-08) flags Siemens vulnerabilities in Reyrolle 7SR5 (versions prior to V2.70), Teamcenter, Siveillance Control, SIMATIC AX Runtime, Desigo CC, Industrial Edge Management, and SIMOVE Fleetmanager and SIPLANT across multiple versions and models; Reyrolle 7SR5 is fixed in version V2.70. Neither relayed advisory provides CVE identifiers or exploitation details. In both cases the Cyber Centre encourages users and administrators to review the linked Siemens advisories and apply the available updates.

  • AV26-881, published 2026-09-03, relays Siemens advisory SSA-887643 covering an account hijacking vulnerability in the Mendix SAML module.
  • Affected: Mendix 10 and Mendix 11 compatible SAML modules prior to V4.2.3, and the Mendix 9.24 compatible SAML module prior to V3.6.27.
  • AV26-890, dated 2026-09-08, flags Siemens vulnerabilities in Reyrolle 7SR5 (versions prior to V2.70), Teamcenter, Siveillance Control, SIMATIC AX Runtime, Desigo CC, Industrial Edge Management, and SIMOVE Fleetmanager and SIPLANT across…
  • Reyrolle 7SR5 is fixed in version V2.70.
  • No CVE identifiers or exploitation details are provided in either relayed advisory.
  • The Canadian Centre for Cyber Security urges users and administrators to review the Siemens advisories and apply available updates.

Coverage timeline

  1. · 13d ago
    Canadian Centre for Cyber Security· 20
    [Control Systems] Siemens security advisory (AV26-881)

    Siemens patched an account hijacking vulnerability in the Mendix SAML module affecting Mendix 9.24, 10, and 11 releases before fixed versions.