Critical-Severity XSS Flaws Uncovered in Siemens SIMATIC S7 Web Servers
ID: 94155f23-61bd-5d52-8689-5e8e908cd069
STIX ID: report--94155f23-61bd-5d52-8689-5e8e908cd069
Feed Name: securityonline.info
Siemens ProductCERT published an urgent advisory (SSA-688146) describing multiple high-severity XSS vulnerabilities (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) in SIMATIC S7 PLC web interfaces with CVSS up to 9.3; flaws allow injection of malicious scripts via unsanitized inputs and a crafted firmware selection, risking session hijacking, credential theft, or unauthorized control across critical industrial systems. Siemens provides affected product lists, available updates for some devices, mitigations where fixes are not yet available, and recommends restricting project and firmware update access and protecting device network access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
