NCSC-2026-0282 [1.00] [M/H] Vulnerabilities fixed in Siemens products
Siemens has fixed vulnerabilities in various products such as Desigo, Parasolid, RUGGEDCOM, SIMATIC, Siveillance and Solid Edge. The vulnerabilities may enable a malicious actor to perform attacks that can lead to the following damage categories: - Denial-of-Service (DoS) - Data manipulation - Circumvention of a security measure - (Remote) code execution (root/admin rights) - (Remote) code execution (user rights) - Access to sensitive data - Privilege escalation The malicious actor requires access to the production environment for this. It is good practice not to have such an environment publicly accessible.
CSIRTS triage
- What
- Multiple vulnerabilities across Siemens products (Desigo, Parasolid, RUGGEDCOM, SIMATIC, Siveillance, Solid Edge) enable denial of service, code execution, privilege escalation, and data manipulation.
- Who is affected
- Deployments of affected Siemens products in production environments.
- Urgency
- High urgency; vulnerabilities enable remote code execution with root/admin rights and require production environment access.
- Action
- Apply Siemens patches for affected products addressing CVE-2026-3014, CVE-2026-23573, CVE-2026-50058 through CVE-2026-50063, and ensure production environments are not publicly accessible.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0282
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-30140.54% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-235730.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-500580.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-500590.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-500600.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-500610.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-500620.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-500630.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-500640.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-572620.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalSiemens Siveillance Videocisa
- criticalSiemens LOGO! Soft Comfortcisa
- criticalSiemens Simcenter Femapcisa
- criticalSiemens License Server (SLS)cisa
- criticalSiemens Parasolidcisa
- criticalSiemens Solid Edgecisa
- criticalSiemens Desigo DXR and PXC Controllerscisa
- criticalSiemens RUGGEDCOM APE1808cisa
- unknownMultiple vulnerabilities in Siemens products (August 12, 2026)cert-fr-avis
- highCVE-2026-69109: A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The…nvd
- mediumCVE-2026-69108: A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The…nvd
- highCVE-2026-64629: A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V…nvd
Recent advisories for Siemens products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownMultiple vulnerabilities in Siemens products (August 12, 2026)cert-fr-avis · 2026-08-12
- unknownMultiple vulnerabilities in Siemens products (July 15, 2026)cert-fr-avis · 2026-07-15
- unknownNCSC-2026-0229 [1.00] [M/H] Vulnerabilities fixed in Siemens productsncsc-nl · 2026-07-14
- unknownMultiple vulnerabilities in Siemens products (July 10, 2026)cert-fr-avis · 2026-07-10
- unknownSiemens Products using OpenSSLcisa · 2026-06-23
More from NCSC-NL Advisories
- unknownNCSC-2026-0302 [1.00] [M/H] Vulnerabilities patched in SAP Commerce Cloud Data Hub Adapter2026-08-15
- unknownNCSC-2026-0301 [1.00] [M/H] Vulnerabilities patched in IBM i operating system by IBM2026-08-14
- unknownNCSC-2026-0300 [1.00] [M/H] Vulnerabilities patched in Fortinet FortiWeb2026-08-13
- unknownNCSC-2026-0299 [1.00] [M/H] Vulnerability patched in Fortinet FortiManager2026-08-13
- unknownNCSC-2026-0298 [1.00] [M/H] Vulnerabilities patched in Autodesk AutoCAD2026-08-13