VulnSea

siemens has 29 CVEs on record between 2022 and 2026. Disclosure cadence is accelerating: 21 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 14. The median CVSS is 7.8 (high), with 2 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-787 (4) and CWE-125 (3). Most affected products: Reyrolle 7SR5 (9), solid_edge_se2025 (7), scalance_lpe9403_firmware (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.8
Publish → KEV
Last 90 days
21 prev 0

Products

  • Reyrolle 7SR5 9
  • solid_edge_se2025 7
  • scalance_lpe9403_firmware 3
  • SIMATIC Field PG M5 2
  • Automation License Manager V6.0 1
  • Desigo CC ClickOnce Client V6 1
29
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

siemens vulnerabilities

CVEs affecting siemens, newest first. Open any entry for full detail, references, and exploit status.

29 CVEsRSS

CVE-2026-89207Medium· 6.5
6d ago

A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (All versions < V4.17)

A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (All versions < V4.17). Affected devices do not properly validate input received from backend services. This could al…

SunlitSiemens · WTV676-HB6035 Web InterfaceEPSS 0.34%via NVD
CVE-2026-67367High· 8.6
2w ago

A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1…

A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1…

TwilightSiemens · SIMOVE Fleetmanager V3.1EPSS 0.81%via NVD
CVE-2026-62654Medium· 6.8
2w ago

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70)

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special maintenance mode can be activated via a physical key sequence during device boot, in which the device downloads and executes program code from a netwo…

SunlitSiemens · Reyrolle 7SR5EPSS 0.11%via NVD
CVE-2026-62653Medium· 6.8
2w ago

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70)

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The input received over a proprietary communication protocol that is exposed when the device is placed into a special firmware-update mode is not properly valid…

SunlitSiemens · Reyrolle 7SR5EPSS 0.18%via NVD
CVE-2026-62652Medium· 5.3
2w ago

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70)

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from which debugging symbols have not been removed. This could allow an unauthenticated attacker with access to the public…

SunlitSiemens · Reyrolle 7SR5EPSS 0.21%via NVD
CVE-2026-62650High· 8.8
2w ago

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70)

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks in the web-based management interface are not properly enforced, allowing role-based access control (RBAC) restrictions to be b…

TwilightSiemens · Reyrolle 7SR5EPSS 0.32%via NVD
CVE-2026-62649High· 7.5
2w ago

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70)

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The web server does not properly limit or manage system resources when processing a high volume of concurrent HTTP requests. This could allow an unauthenticated…

TwilightSiemens · Reyrolle 7SR5EPSS 0.33%via NVD
CVE-2026-62648High· 7.5
2w ago

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70)

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the URL component contained in pre-authenticated HTTP messages is not properly validated before appending additional data to it, resulting in an o…

TwilightSiemens · Reyrolle 7SR5EPSS 0.33%via NVD
CVE-2026-62647High· 7.4
2w ago

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70)

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generator is used to generate security-relevant values (such as session identifiers used for authentication purposes) that is not initialized wi…

TwilightSiemens · Reyrolle 7SR5EPSS 0.34%via NVD
CVE-2026-62646High· 7.4
2w ago

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70)

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A session identifier is generated using an algorithm with insufficient randomness, resulting in a token with low entropy that can be predicted or brute-forced w…

TwilightSiemens · Reyrolle 7SR5EPSS 0.32%via NVD
CVE-2026-62645Critical· 9.8
2w ago

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70)

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate the current and past session ID numbers. This could allow an attacker to bypass t…

MidnightSiemens · Reyrolle 7SR5EPSS 0.35%via NVD
CVE-2026-58113Medium· 6.1
2w ago

A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607)

A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected appli…

SunlitSiemens · Teamcenter V2412EPSS 0.22%via NVD
CVE-2026-50093Critical· 9.0
2w ago

A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control V3.0 (All versions < V3.0.22.2177), Siveillance Control V4.…

A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control V3.0 (All versions < V3.0.22.2177), Siveillance Control V4.…

MidnightSiemens · Siveillance Control Pro V3.0EPSS 0.19%via NVD
CVE-2026-34223High· 8.2
2w ago

A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All vers…

A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All vers…

TwilightSiemens · Desigo CC ClickOnce Client V6EPSS 0.13%via NVD
CVE-2026-50059High· 7.8
1mo ago

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7)

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds write vulnerability while parsing special…

Twilightsiemens · solid_edge_se2025EPSS 0.11%via NVD
CVE-2026-50060High· 7.8
1mo ago

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7)

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered whil…

Twilightsiemens · solid_edge_se2025EPSS 0.11%via NVD
CVE-2026-50062High· 7.8
1mo ago

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7)

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing speciall…

Twilightsiemens · solid_edge_se2025EPSS 0.11%via NVD
CVE-2026-50064High· 7.8
1mo ago

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7)

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds write vulnerability while parsing special…

Twilightsiemens · solid_edge_se2025EPSS 0.11%via NVD
CVE-2026-50058High· 7.8
1mo ago

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7)

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing speciall…

Twilightsiemens · solid_edge_se2025EPSS 0.11%via NVD
CVE-2026-50063High· 7.8
1mo ago

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7)

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing speciall…

Twilightsiemens · solid_edge_se2025EPSS 0.11%via NVD
CVE-2026-50061High· 7.8
1mo ago

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7)

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered whil…

Twilightsiemens · solid_edge_se2025EPSS 0.11%via NVD
CVE-2025-30033High· 7.8
1y ago

The affected setup component is vulnerable to DLL hijacking

The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup component.

TwilightSiemens · Automation License Manager V6.0EPSS 0.21%via NVD
CVE-2025-40583Medium· 4.4
1y ago

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed)

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices do transmit sensitive information in cleartext. This could allow a…

Sunlitsiemens · scalance_lpe9403_firmwareEPSS 0.11%via NVD
CVE-2025-40582High· 7.8
1y ago

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed)

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices do not properly sanitize configuration parameters. This could allo…

Twilightsiemens · scalance_lpe9403_firmwareEPSS 0.18%via NVD
CVE-2025-40581High· 7.1
1y ago

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed)

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices are vulnerable to an authentication bypass. This could allow a non…

Twilightsiemens · scalance_lpe9403_firmwareEPSS 0.15%via NVD
CVE-2024-56182High· 8.2
1y ago

A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC Field PG M6 (All versions < V26.01.12), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32A (All versions < V29.01.07), SIMATIC IPC BX-39A (…

A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC Field PG M6 (All versions < V26.01.12), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32A (All versions < V29.01.07), SIMATIC IPC BX-39A (…

TwilightSiemens · SIMATIC Field PG M5EPSS 0.21%via NVD
CVE-2024-56181High· 8.2
1y ago

A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32A (All versions < V29.01.07), SIMATIC IPC BX-39A (All versions < V29.01.07), SIMATIC IPC BX-59A (A…

A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32A (All versions < V29.01.07), SIMATIC IPC BX-39A (All versions < V29.01.07), SIMATIC IPC BX-59A (A…

TwilightSiemens · SIMATIC Field PG M5EPSS 0.21%via NVD
CVE-2022-34659Medium· 5.3
4y ago

A vulnerability has been identified in Simcenter STAR-CCM+ (All versions only if the Power-on-Demand public license server is used)

A vulnerability has been identified in Simcenter STAR-CCM+ (All versions only if the Power-on-Demand public license server is used). Affected applications expose user, host and display name of users, when the public license server is use…

Sunlitsiemens · simcenter_star-ccm+_viewerEPSS 0.62%via NVD
CVE-2022-34821High· 7.6
4y ago

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2), SCALANCE M804PB (6GK5804-0AP00-2AA2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2), SCALANCE …

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2), SCALANCE M804PB (6GK5804-0AP00-2AA2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2), SCALANCE …

Twilightsiemens · simatic_cp_1242-7_v2_firmwareEPSS 2.4%via NVD
siemens vulnerabilities (CVEs) · VulnSea