CVE-2026-89207 lets an unauthenticated remote attacker trip protection mode on Siemens WTV676-HB6035 and WTV776-HB6035 web interfaces. The fixed builds, V3.94 and V4.17, are available now.
Reality
- Evidence72
- Adoption22
- Hype gap0
- Incentives45
- Confidence68
CVE-2026-50093 lets an attacker upload arbitrary files to the Open Interface Services web module and take root on the host running Siveillance Control. Siemens reported it to CISA and has fixed builds out for all four affected branches.
Reality
- Evidence66
- Adoption28
- Hype gap+14
- Incentives58
- Confidence64
Since September 17, 2026, reports to CISA go through VINCE-NT, a platform the agency owns and manages itself, and anyone with an open case will be told individually when it moves across.
Reality
- Evidence66
- Adoption45
- Hype gap+18
- Incentives58
- Confidence72
CVE-2026-58113 sits in the /auth/ redirect flow of Siemens Teamcenter. The attacker needs no credentials and no more than a link an engineer loads, and Siemens has shipped fixed builds for four release branches.
Reality
- Evidence74
- Adoption18
- Hype gap+8
- Incentives45
- Confidence66
CVE-2026-80465 lets an unauthenticated remote attacker hijack an account in some single sign-on setups. The fix is a Mendix Marketplace module update. It has to be taken app by app across three version trains.
Reality
- Evidence64
- Adoption
- Insufficient
- Hype gap−15
- Incentives55
- Confidence68
CVE-2026-59086 yields code execution in Simcenter Femap and Nastran below V2606. The fix already exists; the engineering workstations that need it rarely sit inside the monthly cycle.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence62
CVE-2026-64629 is an out-of-bounds read in Siemens' Parasolid, triggered by reading a file. The remediation is a version bump on two separate branches, with no listed workaround.
Reality
- Evidence70
- Adoption22
- Hype gap+8
- Incentives58
- Confidence68