CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[Control systems] Siemens security advisory (AV26-689)

unknown
Serial number: AV26-689 Date: July 14, 2026 On July 14, 2026, Siemens published security advisories to address vulnerabilities in the following products. Included were updates for the following products: CADRA - versions prior to V2511 Desigo CC family V7/V8 - all versions Desigo CC family V9 - versions prior to V9.0 QU1 IAM Client - multiple versions and models Mendix Runtime - all versions Opcenter X - versions prior to V2604 Palo Alto Networks PAN-OS on RUGGEDCOM APE1808 - all versions SIDIS Secured SmartPlug - versions prior to V7.26.0310 SIMATIC S7-1500 CPU family - versions prior to V3.1.6 SIMATIC S7-PLCSIM Advanced - all versions Simcenter STAR-CCM+ - all versions The Cyber Centre encourages users and administrators to review the web link provided, perform the suggested mitigations and apply the necessary updates. Siemens Security Advisories

CSIRTS triage

What
Siemens published security advisories to address vulnerabilities in various products.
Who is affected
Users of Siemens products including CADRA, Desigo CC, and SIMATIC.
Urgency
Remediation is necessary to ensure security, although the exploitation status is currently unknown.
Action
Review the advisories and apply the necessary updates.

AI-assisted analysis generated from the source advisory — verify against the original.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-07-14
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/control-systems-siemens-security-advisory-av26-689

More from Canadian Centre for Cyber Security