CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Defending Against an Active Threat to Siemens S7 Series PLCs

critical
Executive summary Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape. Top Mitigations Inventory all Siemens S7 Series programmable logic controllers (PLCs) Apply critical security patches Ensure PLCs are not accessible from the Internet Strengthen access controls Monitor for unauthorized activity Harden PLC services, protocols, and ladder logic integrity Hunt for anomalies that may indicate a compromise The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA)—hereafter referred to as the authoring agencies—are releasing this Cybersecurity Advisory to warn owners and operators of industrial control systems (ICSs) of an active cyber threat to Siemens S7 Series PLCs and provide relevant mitigations to protect and defend them. The threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools. The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected. The U.S. critical infrastructure sectors most targeted by this threat activity include Critical Manufacturing , Energy , Water and Wastewater , Chemical , Food and Agriculture , and Commercial Facilities . This is not a theoretical risk—it is an active threat. Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents

CSIRTS triage

What
Active threat targeting Siemens S7 Series programmable logic controllers and broader PLC infrastructure.
Who is affected
Siemens S7 Series PLC deployments and all PLC environments facing broader targeting activity.
Urgency
Critical; active threat in the wild with ongoing PLC targeting activity.
Action
Inventory all S7 Series PLCs, apply critical security patches, ensure PLCs are not Internet-accessible, strengthen access controls, and monitor for unauthorized activity.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch S7 Series PLCs

Get an email when a new S7 Series PLCs advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-08-19
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a

Recent advisories for Defending Against an

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CISA Cybersecurity Advisories