logo

Critical-Severity XSS Flaws Uncovered in Siemens SIMATIC S7 Web Servers

ID: 94155f23-61bd-5d52-8689-5e8e908cd069

STIX ID: report--94155f23-61bd-5d52-8689-5e8e908cd069

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

Author: Ddos

...
...

Siemens ProductCERT published an urgent advisory (SSA-688146) describing multiple high-severity XSS vulnerabilities (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) in SIMATIC S7 PLC web interfaces with CVSS up to 9.3; flaws allow injection of malicious scripts via unsanitized inputs and a crafted firmware selection, risking session hijacking, credential theft, or unauthorized control across critical industrial systems. Siemens provides affected product lists, available updates for some devices, mitigations where fixes are not yet available, and recommends restricting project and firmware update access and protecting device network access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.