[Control systems] Siemens security advisory (AV26-689)
Serial number: AV26-689 Date: July 14, 2026 On July 14, 2026, Siemens published security advisories to address vulnerabilities in the following products. Included were updates for the following products: CADRA - versions prior to V2511 Desigo CC family V7/V8 - all versions Desigo CC family V9 - versions prior to V9.0 QU1 IAM Client - multiple versions and models Mendix Runtime - all versions Opcenter X - versions prior to V2604 Palo Alto Networks PAN-OS on RUGGEDCOM APE1808 - all versions SIDIS Secured SmartPlug - versions prior to V7.26.0310 SIMATIC S7-1500 CPU family - versions prior to V3.1.6 SIMATIC S7-PLCSIM Advanced - all versions Simcenter STAR-CCM+ - all versions The Cyber Centre encourages users and administrators to review the web link provided, perform the suggested mitigations and apply the necessary updates. Siemens Security Advisories
CSIRTS triage
- What
- Siemens published security advisories to address vulnerabilities in various products.
- Who is affected
- Users of Siemens products including CADRA, Desigo CC, and SIMATIC.
- Urgency
- Remediation is necessary to ensure security, although the exploitation status is currently unknown.
- Action
- Review the advisories and apply the necessary updates.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/control-systems-siemens-security-advisory-av26-689
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-768)2026-07-31
- unknownRails security advisory (AV26-767)2026-07-31
- unknownSolarWinds security advisory (AV26-766)2026-07-31
- unknownGladinet security advisory (AV26-765)2026-07-30
- unknownPHP Group security advisory (AV26-764)2026-07-30