NCSC-2026-0229 [1.00] [M/H] Vulnerabilities fixed in Siemens products
Siemens has fixed vulnerabilities in various products such as CADRA, IAM, Mendix, OpCenter, RUGGEDCOM, SIDIS, and SIMATIC. The vulnerabilities may allow an attacker to execute attacks that can lead to the following categories of damage: - Denial-of-Service (DoS) - Cross-Site Scripting - Data manipulation - Bypassing a security measure - (Remote) code execution (SYSTEM rights) - (Remote) code execution (User rights) - Access to sensitive data - Privilege escalation. The attacker needs access to the production environment for this. It is good practice not to have such an environment publicly accessible.
CSIRTS triage
- What
- The vulnerabilities may allow an attacker to execute various attacks including denial of service and remote code execution.
- Who is affected
- Deployments of Siemens products such as CADRA, IAM, Mendix, OpCenter, RUGGEDCOM, SIDIS, and SIMATIC.
- Urgency
- Remediation is urgent due to the potential for exploitation and the severity of the vulnerabilities.
- Action
- It is recommended to apply the latest updates and ensure the production environment is not publicly accessible.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0229
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2005-20965.5% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 92% of all scored CVEs.
- Moderate exploitation riskCVE-2016-98404.8% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 91% of all scored CVEs.
- Moderate exploitation riskCVE-2016-98417.5% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 94% of all scored CVEs.
- Moderate exploitation riskCVE-2016-98425.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 92% of all scored CVEs.
- Moderate exploitation riskCVE-2017-149198.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 94% of all scored CVEs.
- Exploitation likely imminentCVE-2018-25032EPSS puts this in the most-targeted tier (52.1% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99% of all scored CVEs.
- Moderate exploitation riskCVE-2019-94943.9% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 89% of all scored CVEs.
- Moderate exploitation riskCVE-2019-94953.4% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 88% of all scored CVEs.
- Moderate exploitation riskCVE-2022-233033.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 86% of all scored CVEs.
- Moderate exploitation riskCVE-2022-233041.9% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 78% of all scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] IBM QRadar SIEM: Multiple vulnerabilitiescert-bund
- criticalSiemens Mendix Runtimecisa
- criticalSiemens SIMATIC S7-PLCSIM Advancedcisa
- medium[UPDATE] [medium] OpenSSL and LibreSSL: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Siebel CRM: Multiple vulnerabilitiescert-bund
- criticalSiemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFWcisa
- criticalexploitedSiemens CADRAcisa
- criticalSiemens IAM Clientcisa
- criticalSiemens SIDIS Secured SmartPlugcisa
- criticalSiemens Opcenter Xcisa
- high[UPDATE] [high] Dell PowerProtect Data Domain OS: Multiple vulnerabilitiescert-bund
- critical[UPDATE] [critical] Apple macOS: Multiple Vulnerabilitiescert-bund
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30