Published Security3 min read
Edit Rights On The Video Server Now Mean Code Execution: Siveillance And XProtect Patched
CVE-2026-3014 lets accounts with edit permissions on the Siveillance Video Management Server run arbitrary code as the service. Siemens has shipped hotfixes across three release branches.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- CISA published ICS advisory ICSA-26-225-09 covering Siemens Siveillance Video, a verbatim republication of Siemens advisory SSA-825228.
- The advisory states that Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack, tracked as CVE-2026-3014.
- Per the advisory, Milestone released a new version of XProtect and several cumulative patch updates fixing a security vulnerability in the Management Server API; the vulnerability causes users with edit permissions to the Management Server to be able to execute arbitrary code in the context of the Management Server Service.
- The relevant weakness is CWE-78, Improper Neutralization of Special Elements used in an OS Command (OS Command Injection).
- Milestone PSIRT reported this vulnerability to Siemens, per the advisory's acknowledgments.
Compiled by The WatchSomething wrong?How this is made
Why it matters
CISA has republished Siemens advisory SSA-825228 as ICSA-26-225-09, covering a vulnerability in Siveillance Video Management Servers that the advisory says could allow a remote code execution attack, tracked as CVE-2026-3014 [1][2]. The mechanism matters more than the label: according to the advisory, the flaw causes users with edit permissions to the Management Server to be able to execute arbitrary code in the context of the Management Server Service [3].
That is a trust boundary collapsing inward. Edit rights on a video management server are routinely handed to integrators, contractors, and shift supervisors who need to add a camera, change a retention rule, or fix a broken recording profile. The advisory places the defect in the Management Server API and classifies the weakness as CWE-78, OS command injection [3][4]. Treated as an application permission, edit access is mundane. Treated as what it now is, it is code execution as the service account that runs the video plant.
The fix originates upstream: Siemens states that Milestone released a new version of XProtect plus several cumulative patch updates addressing the Management Server API issue [3], and Milestone PSIRT is credited with reporting the vulnerability to Siemens [5]. Three Siveillance branches are listed as affected: V2023 R3 below V23.3.27, V2024 R1 below V24.1.16, and V2025 below V25.1.15 [6][7][8]. The remediations are V23.3 HotfixRev27, V24.1 HotfixRev16, and V25.1 HotfixRev15 or later [9][10][11]. In each case the fix lands as a hotfix revision inside the existing branch rather than a version jump [12], which removes the usual excuse that patching means a migration project.
Two gaps are worth naming. The Metrics section of the republished advisory carries no CVSS score [13], so anyone whose patch queue is sorted by severity number has nothing to sort on here. And CISA notes the document is a verbatim conversion of the vendor CSAF advisory, provided as-is, with CISA not responsible for its editorial or technical accuracy [14]. There is no exploitation status in the material either way.
The general guidance is the standard set: Siemens recommends protecting network access to affected products with appropriate mechanisms and running them in a protected IT environment [15], while CISA repeats its usual advice to minimise network exposure, keep systems off the internet, and place them behind firewalls isolated from business networks [16]. Those controls reduce who can reach the Management Server. They do not help against a credentialed integrator account, which is the population this bug actually arms.
Siemens lists deployment as worldwide, across critical manufacturing, communications, and commercial facilities [17][18]. Video management servers in those settings tend to sit adjacent to door control, badge systems, and the operations network, and they hold service credentials for the devices they manage. Before patching, establish which accounts currently hold Management Server edit rights and what the Management Server Service account can reach; after patching, decide whether that permission should still be as widely granted as it is.
What to watch: whether a CVSS score and exploitation data get attached to CVE-2026-3014 as the advisory is updated, and whether other vendors shipping rebadged XProtect publish their own advisories on the same upstream fix. Siveillance is one badge on a Milestone codebase [3], and the branch-and-hotfix numbering means asset inventories that record only "Siveillance Video 2025" will not tell you whether you are patched [8][11].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
CISA published ICS advisory ICSA-26-225-09 covering Siemens Siveillance Video, a verbatim republication of Siemens advisory SSA-825228.
- [2]
The advisory states that Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack, tracked as CVE-2026-3014.
- [3]
Per the advisory, Milestone released a new version of XProtect and several cumulative patch updates fixing a security vulnerability in the Management Server API; the vulnerability causes users with edit permissions to the Management Server to be able to execute arbitrary code in the context of the Management Server Service.
- [4]
The relevant weakness is CWE-78, Improper Neutralization of Special Elements used in an OS Command (OS Command Injection).
ReportedView cited source - [5]
Milestone PSIRT reported this vulnerability to Siemens, per the advisory's acknowledgments.
ReportedView cited source - [6]
Siveillance Video V2023 R3 versions below V23.3.27 are affected by CVE-2026-3014.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- cisa.govCISAAug 13Siemens Siveillance Video
Additional citations
- CISA / Siemens ProductCERT
- Siemens advisory SSA-825228 via CISA
- CISA republication of SSA-825228
- CISA advisory conversion disclaimer



