Bulletins

CISA (ALL)
08/13/2026

View CSAF

Summary

A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the …

SIEMENS CERT
08/13/2026
Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote …
CISA (ALL)
08/12/2026

View CSAF

Summary

Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens recommends to contact customer support for additional information, and follow Fortinet advisory for workarounds and mitigation measures.

The following versions of Siemens RUGGEDCOM APE1808 are affected:

CISA (ALL)
08/11/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token information, and obtain control of user accounts.

The following versions of Mira Hormone Monitor, Mira Android App …

CISA (ALL)
08/11/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution.

The following versions of Johnson Controls C-CURE 9000 and Victor application server (Update A) are affected:

  • C-CURE 9000 <=v3.10.1 (CVE-2026-21655)
  • victor Application Server <=v4.10 …
CISA (ALL)
08/11/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to use hidden commands to disable electrical safety mechanisms or modify other stimulation output settings.

The following versions of Pulsetto Vagus Nerve Stimulator are affected:

  • Pulsetto Vagus Nerve Stimulator vers:all/* (CVE-2026-18844)
SIEMENS CERT
08/11/2026
The installers used to install several Siemens products are affected by a DLL hijacking vulnerability. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected installer component. This vulnerability poses a risk only during setup and installation phase of the …
SIEMENS CERT
08/11/2026
Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the …