CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[Control systems] Siemens security advisory (AV26-802)

unknown
Serial Number: AV26-802 Date: August 11, 2026 As of August 11, 2026, Siemens is affected by vulnerabilities in the following products: Desigo DXR2 Prior to V01.21.233.16-7862 Desigo PXC3 Prior to V01.21.233.16-7862 Desigo PXC4 Prior to V02.21.194.36-2715 Desigo PXC5.E003 Prior to V02.21.194.36-2715 Desigo PXC5.E24 Prior to V02.21.194.36-2715 Desigo PXC7 Prior to V02.21.194.36-2715 LOGO! Soft Comfort Prior to V9 Parasolid V38.0 Prior to V38.0.235 Parasolid V38.1 Prior to V38.1.230 SIMATIC IoT2050 Advanced Prior to V4.3.4.1 Siemens License Server (SLS) Prior to V5.1 Prior to V5.3 Simcenter Femap Prior to V2606.0001 Simcenter Nastran Prior to V2606 Solid Edge SE2025 Prior to V225.0 Update 15 Solid Edge SE2026 Prior to V226.0 Update 7 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available CERT Services | Siemens

CSIRTS triage

vendor: SiemensOtheraffected: Desigo DXR2 Prior to V01.21.233.16-7862, Desigo PXC3 Prior to V01.21.233.16-7862, Desigo PXC4 Prior to V02.21.194.36-2715, Desigo PXC5.E003 Prior to V02.21.194.36-2715, Desigo PXC5.E24 Prior to V02.21
What
Multiple vulnerabilities affect Siemens industrial and engineering software products.
Who is affected
Organizations deploying affected versions of Siemens Desigo, LOGO!, Parasolid, IoT2050, License Server, Simcenter, and Solid Edge products.
Urgency
Moderate urgency given the diversity of products and control systems exposure, though specific vulnerability classes and CVSS scores are not disclosed.
Action
Review the Cyber Centre advisory link and apply all available updates to affected Siemens products as they become available.

AI-assisted analysis generated from the source advisory — verify against the original.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-08-11
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/control-systems-siemens-security-advisory-av26-802

More from Canadian Centre for Cyber Security