CISA revoked its Siemens Mendix Runtime advisory and marked all versions not affected by CVE-2026-7891, now retracted as expected configuration. OT and application teams holding tickets for it can close them with no Runtime upgrade to schedule.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence68
CVE-2026-89207 lets an unauthenticated remote attacker trip protection mode on Siemens WTV676-HB6035 and WTV776-HB6035 web interfaces. The fixed builds, V3.94 and V4.17, are available now.
Reality
- Evidence72
- Adoption22
- Hype gap0
- Incentives45
- Confidence68
Siemens ProductCERT reported the traversal itself, and fixed builds are out for four SIMOVE Fleetmanager branches and SIPLANT V3.1. For SIPLANT V1.7, V2.2 and V3.0 the advisory's remedy is an email to support.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence72
CVE-2026-50093 lets an attacker upload arbitrary files to the Open Interface Services web module and take root on the host running Siveillance Control. Siemens reported it to CISA and has fixed builds out for all four affected branches.
Reality
- Evidence66
- Adoption28
- Hype gap+14
- Incentives58
- Confidence64
Five US agencies told PLC owners that scanners are finding exposed Siemens S7 controllers. ZoomEye puts that surface at 173 assets by product fingerprint, or 161,764 by open port.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+5
- Incentives40
- Confidence55
CVE-2026-80465 lets an unauthenticated remote attacker hijack an account in some single sign-on setups. The fix is a Mendix Marketplace module update. It has to be taken app by app across three version trains.
Reality
- Evidence64
- Adoption
- Insufficient
- Hype gap−15
- Incentives55
- Confidence68
A CISA advisory says SIMATIC IoT2050 Advanced units below firmware V4.3.4.1 let an unauthenticated request reach Node-RED programming nodes and run code at maximum privileges.
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap−8
- Incentives45
- Confidence70
CVE-2026-59086 yields code execution in Simcenter Femap and Nastran below V2606. The fix already exists; the engineering workstations that need it rarely sit inside the monthly cycle.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence62
CVE-2026-64629 is an out-of-bounds read in Siemens' Parasolid, triggered by reading a file. The remediation is a version bump on two separate branches, with no listed workaround.
Reality
- Evidence70
- Adoption22
- Hype gap+8
- Incentives58
- Confidence68