Siemens Product Family: September 2026 Regular Security Update Advisory
Overview
Siemens has released its September 2026 regular security update to address vulnerabilities found in several of its product lines. Affected products include Desigo CC, Industrial Edge Management, Reyrolle 7SR5, SIMOVE Fleetmanager, SIPLANT, SIMATIC HMI and SIPLUS HMI, Siveillance Control, and certain SIMATIC products.
Key Vulnerabilities
- A code injection vulnerability (CVE-2026-34223, CVSS 8.2) Caused by insufficient code generation controls in the Desigo CC product family has been resolved.
- An authentication bypass vulnerability (CVE-2026-18963, CVSS 9.1) Caused by a weakness in the password recovery mechanism in Industrial Edge Management has been resolved.
- A resource transfer error vulnerability (CVE-2026-31431, CVSS 7.8) Caused by issues in handling resource transfers between security zones in multiple Siemens industrial products has been resolved.
- A vulnerability in the OIS Web Module allowing the upload of files in dangerous formats due to insufficient file upload restrictions (CVE-2026-50093, CVSS 9.0) Has been resolved.
- Multiple vulnerabilities were identified in versions of Reyrolle 7SR5 prior to V2.70, Including insufficient entropy, inadequate input validation, integer overflow, out-of-bounds writes, unrestricted resource allocation, use of out-of-bounds pointer offsets, authentication bypass, and lack of authentication for critical functions.
- In SIMOVE Fleetmanager and SIPLANT, a relative path traversal vulnerability (CVE-2026-67367, CVSS 8.6) Caused by insufficient validation of relative paths has been resolved.
Recommended Actions
- SIMOVE Fleetmanager must be updated to the latest version compatible with each product version.
- SIPLANT should be updated to the latest version according to the support guidelines or users should contact Siemens Customer Support.
- Industrial Edge Management Cloud was mitigated via firewall rules on August 26, 2026, and fixed via an update on September 2, 2026; no further action is required.
- Industrial Edge Management Pro V1, Pro V2, and Virtual must be updated to the specified baseline version or higher.
- For Desigo CC-related clients, review the authorization policy for the Graphics application and restrict access to configuration functions to only authorized users.
- For the SIMATIC AX Runtime Core Linux family, SIMATIC IPC Industrial Edge Device OS (IED-OS), SIMATIC IoT2050 Advanced, and SIMATIC S7-1500 TM MFP, access to the interactive shell of the GNU/Linux subsystem must be restricted to trusted personnel.
- SIMATIC CN 4100 must be updated to V6.0 Or later.
- SIMATIC HMI and SIPLUS HMI Unified Basic and Unified Comfort must be updated to V21 Update 2 SR1 or later.
- Siveillance Control must be updated to the specified version or higher for each product family.
- Reyrolle 7SR5 must be updated to V2.70 Or later.