Bulletins

CISA (ALL)
08/13/2026

View CSAF

Summary

Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges.

The following versions of Haiwell IoT Cloud HMI Gateway are affected:

  • Haiwell IoT Cloud HMI Gateway 3.40.1.12 (CVE-2026-19188)
CISA (ALL)
08/13/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization.

The following versions of AVEVA Enterprise SCADA are affected:

  • Enterprise SCADA 2025 (CVE-2025-7639)
  • Enterprise SCADA >=2024|<=2024_SP1_P01 (CVE-2025-7639)
  • Enterprise SCADA …
CISA (ALL)
08/13/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to manipulate brain stimulation parameters and override safety limits.

The following versions of Flow Neuroscience FL-100 are affected:

  • Flow Neuroscience FL-100
  • Halo Neuroscience FL-100
CISA (ALL)
08/13/2026

View CSAF

Summary

Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt project data or remove project passwords. The lack of password salting enables offline dictionary …

CISA (ALL)
08/13/2026

View CSAF

Summary

Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version.

The …

CISA (ALL)
08/13/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to read data from the device or gain access to affected workstations.

The following versions of ANDRITZ HIPASE-250 and 250 SCALA are affected:

  • HIPASE-250 <=7.20 (CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, CVE-2026-65313)
  • 250 SCALA <=7.20 …
SIEMENS CERT
08/13/2026
Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote …
CISA (ALL)
08/12/2026

View CSAF

Summary

Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens recommends to contact customer support for additional information, and follow Fortinet advisory for workarounds and mitigation measures.

The following versions of Siemens RUGGEDCOM APE1808 are affected: