Skip to content

Build1 publisher2 min readPublished

Sizing AA26-231A with ZoomEye returns 173 assets or 161,764, depending on the query

Five US agencies told PLC owners that scanners are finding exposed Siemens S7 controllers. ZoomEye puts that surface at 173 assets by product fingerprint, or 161,764 by open port.

The Engineer · Build desk

Illustration accompanying Sizing AA26-231A with ZoomEye returns 173 assets or 161,764, depending on the query

What happened

  • AA26-231A was issued on 2026-08-19 by the NSA, CISA, the FBI, the Department of Energy and the Environmental Protection Agency, and describes actors using internet scanning services to find exposed PLCs running outdated software.
  • It names the S7-200, S7-300, S7-400, S7-1200 and S7-1500 families including F-series safety controllers, and includes no indicators of compromise.
  • Four ZoomEye queries run on 2026-09-16 returned 173 assets fingerprinted as Siemens S7, 10,160 as Siemens SIMATIC, 95,395 classified as PLCs of any vendor, and 161,764 with TCP port 102 reachable.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • constraint Anyone budgeting remediation against 161,764 is sizing a port, so the resulting work list will include equipment from vendors that never shipped an S7 controller.
  • decision An ICS owner has to choose the query that matches the question before the audit scope is set: product fingerprint joined to internal inventory for a fleet answer, port sweep for a protocol answer.
  • exposure Because the actors work from scanning-service results, any controller left internet-reachable is discoverable by a query a defender could have run first.
  • contradiction Siemens says there is no new S7 defect while the agencies advise installing ProductCERT firmware; read together they mean patching alone does not close what the advisory describes, and misconfiguration and exposure carry the rest.

The tooling AA26-231A describes is assembled from open-source parts. According to the advisory, actors wrapped snap7.dll and python-snap7 in AI-generated scripts disguised as legitimate monitoring tools [4], and used them to read and write PLC memory, configuration data and ladder logic over S7comm, usually on TCP port 102 [5]. The AI part changes how quickly such a script gets written. No CVE identifiers appear in the advisory [7].

The advisory did not include a count of the devices at risk [3]. Which count fits depends on what the scanner had to prove before it incremented. ZoomEye's `app="Siemens S7"` query counts a host only once it matches specific product characteristics, and on 2026-09-16 it matched 173 [8][13]. The `port="102"` query counts a host when something answers there, and it returned 161,764 the same day [10]. That is about 935 times the fingerprint count [21].

For the larger figure to stand in for exposed S7 controllers, nearly everything answering on port 102 would have to be a Siemens PLC. The post states that reachability on that port establishes neither the vendor nor a vulnerability, and that other services and other vendors' equipment can occupy it [12]. So 173 is the population ZoomEye can recognise by fingerprint.

The two queries answer two different questions, and the post is explicit that presenting them together without that distinction would be misleading [23]. An owner asking how many of its own S7 controllers are reachable needs the narrow fingerprint joined to internal inventory data; a researcher sizing the S7comm surface needs the port query, labelled as a protocol surface [14].

AA26-231A points past Siemens as well. It says the targeting activity is broader than Siemens devices and that all PLC owners and operators should apply relevant mitigations [15]. ZoomEye's all-vendor PLC device class holds 95,395 assets [11], and Siemens SIMATIC fingerprints are about 11 percent of it [22].

Exposure reduction is the mitigation a defender can check with the same kind of tool the actors use. The advisory makes external exposure the operative risk factor, on the reasoning that a controller not reachable from the internet cannot be located by an internet scanning service [20]. Firmware from Siemens ProductCERT closes known defects [17], while Siemens has said the advisory does not describe a new vulnerability in the S7 series [18].

Both statements hold if the response is layered: reduce exposure, update firmware, strengthen authentication, monitor for anomalous protocol activity [19]. Its list of consequences of unauthorised access includes disruption of industrial processes, safety incidents, equipment damage, data compromise, cascading effects and compliance violations [16].

What to watch

  • A second ZoomEye collection would show whether the port-102 population moves after the advisory; 161,764 is one snapshot dated 2026-09-16.
  • Whether CISA adds CVE identifiers or indicators of compromise to AA26-231A, which would let owners match devices to specific defects instead of a general known-vulnerabilities framing.
  • Whether Siemens ProductCERT publishes firmware advisories tied to the activity the five agencies described.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories