security1 publisher
Crafted Desigo CC graphics documents execute code on the operator client that opens them
CVE-2026-34223 lets a script embedded in a user-defined graphics document write arbitrary files on any Desigo CC V6 or V7 client. Siemens has no fix and points operators at who is allowed to open graphics.
Publishers:cisa.gov
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap−10
- Incentives25
- Confidence68