Junglewise Threat Intelligence

CVE-2026-27662: Siemens SIMATIC HMI Unified Comfort Panels unauthenticated browser escape

CVE-2026-27662 · Severity: high · CVSS 7.7 · Published 2026-05-12

Vendors: Siemens.

Executive brief

Siemens SIMATIC HMI Unified Comfort Panels, which are touchscreens used to control and monitor industrial machinery, contain a security flaw in their help link functionality. An unauthorized person could bypass intended security restrictions to access the device's web browser and control panel. This could allow an attacker to change system settings or discover other ways to interfere with industrial operations.

Technical details

A vulnerability in Siemens SIMATIC HMI Unified Comfort Panels before V21.0 stems from the initialization of a resource with an insecure default. An unauthenticated attacker can exploit this by using the help link to gain unauthorized access to the device's web browser and Control Panel. If the Control Panel is not otherwise protected by secondary security mechanisms, the attacker can modify device configurations or identify further backdoors. The vulnerability is tracked as CVE-2026-27662. Siemens has released version V21.0 to address this issue.

Affected products

  • Siemens SIMATIC HMI MTP1000 Unified Comfort Panel < V21.0
  • Siemens SIMATIC HMI MTP1200 Unified Comfort Panel < V21.0
  • Siemens SIMATIC HMI MTP1500 Unified Comfort Panel < V21.0
  • Siemens SIMATIC HMI MTP1900 Unified Comfort Panel < V21.0
  • Siemens SIMATIC HMI MTP2200 Unified Comfort Panel < V21.0
  • Siemens SIMATIC HMI MTP700 Unified Comfort Panel < V21.0
  • Siemens SIPLUS HMI MTP1000 Unified Comfort < V21.0
  • Siemens SIPLUS HMI MTP1200 Unified Comfort < V21.0
  • Siemens SIPLUS HMI MTP700 Unified Comfort < V21.0

Timeline

  • 2026-05-14: advisory: CISA and Siemens published the advisory.

References

Related threats