Bulletins

CISA (ALL)
09/22/2026

View CSAF

Summary

A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the …

CISA (ALL)
09/22/2026

View CSAF

Summary

SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope. Siemens has released new versions for the affected products and recommends to update to the latest versions.

The following versions of Siemens SIMOVE …

CISA (ALL)
09/22/2026

View CSAF

Summary

The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices. Siemens has released new versions for the affected products and …

CISA (ALL)
09/22/2026

View CSAF

Summary

Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system.

The following versions of lwIP (Lightweight IP) are affected:

  • API >=2.0.1|<=2.2.1 (CVE-2026-91018)
CISA (ALL)
09/22/2026

View CSAF

Summary

Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not …

CISA (ALL)
09/22/2026

View CSAF

Summary

A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation …

CISA (ALL)
09/22/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives.

The following versions of OpenPLC Runtime v3 …

CISA (ALL)
09/22/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to gain full code execution on the device.

The following versions of lwIP TCP/IP Stack MQTT Client Application are affected:

  • MQTT Client Application >=2.0.1|<=2.2.1 (CVE-2026-87121)
CVSS