Vendor
Siemens vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 421 vulnerabilities in Siemens: 0 in the last 7 days and 42 in the last 90 days, 56 of them critical and 9 exploited in the wild. The most recent, CVE-2026-89207, was published on 16 September 2026. 84 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 42
- Critical, all time
- 56
- Exploited in the wild
- 9
About Siemens
German conglomerate manufacturing industrial automation, control systems, and digital infrastructure products.
Siemens technologies
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP204
- Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP83
- Siemens SIMATIC CN 410074
- Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP70
- Siemens RUGGEDCOM APE180826
- Siemens RUGGEDCOM RST2428P16
- Siemens ROX II14
- Siemens SINEC OS12
- Siemens Solid Edge12
- Siemens SIMATIC S7-1500 TM MFP GNU/Linux subsystem11
- Siemens Ruggedcom Rox II10
- Siemens Reyrolle 7SR59
- Siemens Simcenter Femap6
- Siemens SIMATIC PCS neo5
- Siemens SIMATIC S7-1500 CPU family5
- Siemens SIMATIC S7-1500 TM MFP5
- Siemens CPCI85 Central Processing/Communication4
- Siemens RUGGEDCOM ROX MX50004
- Siemens RUGGEDCOM ROX MX5000RE4
- Siemens RUGGEDCOM ROX RX14004
- Siemens RUGGEDCOM ROX RX15004
- Siemens RUGGEDCOM ROX RX15014
- Siemens RUGGEDCOM ROX RX15104
- Siemens RUGGEDCOM ROX RX15114
- Siemens RUGGEDCOM ROX RX15124
- Siemens RUGGEDCOM ROX RX15244
- Siemens RUGGEDCOM ROX RX15364
- Siemens RUGGEDCOM ROX RX50004
- Siemens SCALANCE XR-5004
- Siemens SICORE Base system4
- Siemens SINEC INS4
- Siemens User Management Component4
- Siemens RUGGEDCOM APE1808 Virtual NGFW3
- Siemens SCALANCE XC-3003
- Siemens SCALANCE XC-4003
- Siemens SCALANCE XR-3003
- Siemens SCALANCE XR-500WG3
- Siemens SIMATIC Drive Controller CPU 1504D TF3
- Siemens SIMATIC Drive Controller CPU 1507D TF3
- Siemens SIMATIC ET 200SP Open Controller CPU 1515SP PC23
- Siemens SIPROTEC 5 6MD84 (CP300)3
- Siemens SIPROTEC 5 6MD85 (CP200)3
- Siemens SIPROTEC 5 6MD85 (CP300)3
- Siemens SIPROTEC 5 6MD86 (CP200)3
- Siemens SIPROTEC 5 6MD86 (CP300)3
- Siemens SIPROTEC 5 6MD89 (CP300)3
- Siemens SIPROTEC 5 6MU85 (CP300)3
- Siemens SIPROTEC 5 7KE85 (CP200)3
- Siemens SIPROTEC 5 7KE85 (CP300)3
- Siemens SIPROTEC 5 7SA82 (CP100)3
- Siemens SIPROTEC 5 7SA82 (CP150)3
- Siemens SIPROTEC 5 7SA86 (CP200)3
- Siemens SIPROTEC 5 7SA86 (CP300)3
- Siemens SIPROTEC 5 7SA87 (CP200)3
- Siemens SIPROTEC 5 7SA87 (CP300)3
- Siemens SIPROTEC 5 7SD82 (CP100)3
- Siemens SIPROTEC 5 7SD82 (CP150)3
- Siemens SIPROTEC 5 7SD86 (CP200)3
- Siemens SIPROTEC 5 7SD86 (CP300)3
- Siemens SIPROTEC 5 7SD87 (CP200)3
- Siemens SIPROTEC 5 7SD87 (CP300)3
- Siemens SIPROTEC 5 7SJ81 (CP100)3
- Siemens SIPROTEC 5 7SJ81 (CP150)3
- Siemens SIPROTEC 5 7SJ82 (CP100)3
- Siemens SIPROTEC 5 7SJ82 (CP150)3
- Siemens SIPROTEC 5 7SJ85 (CP300)3
- Siemens SIPROTEC 5 7SJ86 (CP300)3
- Siemens SIPROTEC 5 7SK82 (CP100)3
- Siemens SIPROTEC 5 7SK82 (CP150)3
- Siemens SIPROTEC 5 7SK85 (CP300)3
- Siemens SIPROTEC 5 7SL82 (CP100)3
- Siemens SIPROTEC 5 7SL82 (CP150)3
- Siemens SIPROTEC 5 7SL86 (CP300)3
- Siemens SIPROTEC 5 7SL87 (CP300)3
- Siemens SIPROTEC 5 7SS85 (CP300)3
- Siemens SIPROTEC 5 7ST85 (CP300)3
- Siemens SIPROTEC 5 7ST86 (CP300)3
- Siemens SIPROTEC 5 7SX82 (CP150)3
- Siemens SIPROTEC 5 7SX85 (CP300)3
- Siemens SIPROTEC 5 7SY82 (CP150)3
- Siemens SIPROTEC 5 7UM85 (CP300)3
- Siemens SIPROTEC 5 7UT82 (CP100)3
- Siemens SIPROTEC 5 7UT82 (CP150)3
- Siemens Teamcenter3
Latest Siemens vulnerabilities
- CVE-2026-89207: A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface…highCVSS 6.5EPSS 0.4%
- CVE-2026-67367: A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All…highCVSS 8.6EPSS 1.1%
- CVE-2026-62654: Siemens Reyrolle 7SR5 unsigned code execution in maintenance modemediumCVSS 6.8EPSS 0.2%
- CVE-2026-62653: Siemens Reyrolle 7SR5 memory corruption in firmware-update protocolmediumCVSS 6.8EPSS 0.3%
- CVE-2026-62652: Siemens Reyrolle 7SR5 unstripped debug symbols in firmwaremediumCVSS 5.3EPSS 0.4%
- CVE-2026-62650: Siemens Reyrolle 7SR5 privilege escalation via RBAC bypasshighCVSS 8.8EPSS 0.6%
- CVE-2026-62649: Siemens Reyrolle 7SR5 denial-of-service via resource exhaustionhighCVSS 7.5EPSS 0.6%
- CVE-2026-62648: Siemens Reyrolle 7SR5 out-of-bounds write in URL validationhighCVSS 7.5EPSS 0.6%
- CVE-2026-62647: Siemens Reyrolle 7SR5 weak random number generator in session ID generationhighCVSS 7.4EPSS 0.6%
- CVE-2026-62646: Siemens Reyrolle 7SR5 weak session identifier generationhighCVSS 7.4EPSS 0.5%
- CVE-2026-62645: Siemens Reyrolle 7SR5 session ID prediction in web interfacecriticalCVSS 9.8EPSS 0.7%
- CVE-2026-58113: Siemens Teamcenter reflected cross-site scripting in authentication redirectmediumCVSS 6.1EPSS 0.4%
- CVE-2026-50093: A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro…criticalCVSS 9EPSS 0.3%
- CVE-2026-34223: A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All…highCVSS 8.2EPSS 0.2%
- CVE-2026-80465: Mendix SAML cryptographic signature validation bypasshighCVSS 8.7EPSS 0.3%
- CVE-2026-66155: Siemens Element maps-ng cross-site scripting in si-map componenthighCVSS 7.6EPSS 0.3%
- CVE-2026-18963: Keycloak unauthenticated account takeover via reset-credentials bypasscriticalCVSS 9.1EPSS 3.2%
- CVE-2026-69109: Siemens License Server path traversalhighCVSS 7.5EPSS 0.6%
- CVE-2026-69108: Siemens License Server privilege escalation in sudoers policymediumCVSS 6EPSS 0.2%
- CVE-2026-64629: Siemens Parasolid out-of-bounds read in X_T file parsinghighCVSS 7.8EPSS 0.2%
- CVE-2026-59701: Siemens Simcenter Femap out-of-bounds read in BMP parsinghighCVSS 7.8EPSS 0.2%
- CVE-2026-59700: Siemens Simcenter Femap out-of-bounds read in BMP parsinghighCVSS 7.8EPSS 0.2%
- CVE-2026-59693: Siemens Desigo DXR and PXC DoS via malformed BACnet packetmediumCVSS 4.3EPSS 0.2%
- CVE-2026-59086: Siemens Simcenter stack overflow in argument parsinghighCVSS 7.8EPSS 0.1%
- CVE-2026-58115: Siemens SIMATIC IoT2050 Advanced missing authentication in Node-REDcriticalCVSS 10EPSS 0.9%
Most severe Siemens vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-59718: Fortinet Multiple Products auth bypass via improper SAML signature verificationcriticalexploited in the wildCVSS 9.8EPSS 9.5%
- CVE-2025-10585: Google Chrome type confusion in V8 enginecriticalexploited in the wildCVSS 9.8EPSS 5.4%
- CVE-2026-24858: Fortinet Multiple Products authentication bypass in FortiCloud SSOcriticalexploited in the wildCVSS 9.8EPSS 4.8%
- CVE-2025-39682: Linux Kernel memory corruption in TLS zero-length record handlingcriticalexploited in the wildCVSS 9.8EPSS 2.9%
- CVE-2025-13223: Google Chrome type confusion in V8 enginecriticalexploited in the wildCVSS 8.8EPSS 4.8%
- CVE-2025-25249: Fortinet FortiOS heap overflow in cw_acd daemoncriticalexploited in the wildCVSS 8.1EPSS 3.9%
- CVE-2026-31431: Linux Kernel crypto algif_aead improper memory handlingcriticalexploited in the wildCVSS 7.8EPSS 2.6%
- CVE-2016-8562: Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerabilitycriticalexploited in the wildCVSS 7.5
- CVE-2025-39964: Linux Kernel race condition in af_alg_sendmsgcriticalexploited in the wildCVSS 3.3EPSS 1.0%
- CVE-2026-58115: Siemens SIMATIC IoT2050 Advanced missing authentication in Node-REDcriticalCVSS 10EPSS 0.9%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 0 | |
| 6 Jul 2026 | 4 | 0 | |
| 13 Jul 2026 | 3 | 1 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 17 | 1 | |
| 17 Aug 2026 | 1 | 1 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 1 | 0 | |
| 7 Sep 2026 | 13 | 2 | |
| 14 Sep 2026 | 1 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/siemens.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Siemens vulnerabilities", https://junglewise.ai/threats/vendors/siemens, 26 September 2026.