vulnerability Siemens Teamcenter Siemens Teamcenter versions 2312, 2406, 2412, and 2506 are affected by multiple vulnerabilities, including a PDF.js flaw and hardcoded credentials. These vulnerabilities could allow for arbitrary code execution and unaut… CISA Advisories · May 14, 2026 High CVE-2026-33862CVE-2026-33893CVE-2024-4367DEpdfjscredentialscve-2024-4367
vulnerability Siemens Siemens ROS# This advisory details a critical vulnerability in Siemens ROS# (version 2.2.2 and earlier) due to a path traversal flaw. An attacker could potentially access and modify arbitrary files on a system hosting the ROS# file_s… CISA Advisories · May 14, 2026 Critical CVE-2026-41551DEpath traversalindustrial control systemscwe-23
vulnerability Siemens SIMATIC S7 PLC Web Server This CISA advisory details multiple vulnerabilities discovered within Siemens SIMATIC S7 PLCs, specifically within their web servers. These vulnerabilities, identified as CVE-2026-25786 through CVE-2026-25789, allow for… CISA Advisories · May 14, 2026 Medium CVE-2026-25786CVE-2026-25787CVE-2026-25789plcwebserverxss
threat-intel Siemens SIMATIC Siemens has released a security update for its SIMATIC CN 4100 system to address multiple vulnerabilities discovered within its Linux kernel components and libxml2. These vulnerabilities, including null pointer dereferen… CISA Advisories · May 14, 2026 High CVE-2024-47704CVE-2024-57924CVE-2024-58240DElinuxkernelvulnerability
vulnerability Siemens Simcenter Femap A heap-based buffer overflow vulnerability has been identified in Siemens Simcenter Femap, specifically within the Datakit library. The vulnerability, reported by TrendAI Zero Day Initiative, allows for remote code execu… CISA Advisories · May 14, 2026 High CVE-2025-12659GEheap-overflowremote-code-executionipt
vulnerability Siemens SIPROTEC 5 This CISA advisory details a critical vulnerability in Siemens SIPROTEC 5 devices due to the use of insufficiently random session identifiers. An unauthenticated remote attacker could potentially exploit this weakness to… CISA Advisories · May 14, 2026 Critical CVE-2024-54017session_hijackingauthenticationrandomness
vulnerability Siemens Ruggedcom Rox A vulnerability has been identified in Siemens Ruggedcom Rox devices, specifically within the Scheduler functionality, allowing authenticated remote attackers to execute arbitrary commands with root privileges. This is d… CISA Advisories · May 14, 2026 Critical CVE-2025-40949DEinput validationroot privilegescheduler
vulnerability Siemens gWAP A remote code execution vulnerability has been identified in Siemens gWAP, stemming from a prototype pollution issue within the Axios HTTP client library. This vulnerability, exploitable through a ‘Gadget’ attack chain,… CISA Advisories · May 14, 2026 High CVE-2026-40175DEremote code executionprototype pollutionaxios
vulnerability Siemens Industrial Devices This article details a vulnerability (CVE-2025-40833) affecting multiple Siemens industrial devices, including IE/PB LINK HA, SCALANCE M series routers, and RuggedCom RM1224 LTE devices. The vulnerability allows an attac… CISA Advisories · May 14, 2026 High CVE-2025-40833industrial controldenial of servicefirmware update
vulnerability Siemens Opcenter RDnL This advisory details a critical vulnerability in Siemens Opcenter RDnL software, specifically related to missing authentication in the ActiveMQ Artemis component. An attacker within an adjacent network could exploit thi… CISA Advisories · May 14, 2026 Critical CVE-2026-27446DEauthenticationcore protocolactivemq artemis
vulnerability Siemens Solid Edge Siemens Solid Edge SE2026 is affected by two file parsing vulnerabilities that could allow an attacker to crash the application or execute arbitrary code when processing specially crafted PAR files. Siemens has released… CISA Advisories · May 14, 2026 High CVE-2026-44411CVE-2026-44412DEbuffer overflowfile parsingstack overflow
vulnerability Siemens Ruggedcom Rox This advisory details a vulnerability in Siemens Ruggedcom Rox devices due to improper input validation within the JSON-RPC interface. An authenticated remote attacker could potentially read arbitrary files from the devi… CISA Advisories · May 14, 2026 High CVE-2025-40948DEjson-rpcroot accessfile disclosure
ransomware State of ransomware in 2026 Kaspersky’s 2026 ransomware threat report highlights a shift in the landscape, with ransomware attacks declining overall but becoming more sophisticated. Key trends include the emergence of post-quantum cryptography rans… Securelist · May 12, 2026 High USransomwarequantum cryptographyedr