CVE-2026-25786
CVSS 9.1 CRITICAL: affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters… EPSS 0.4% (29th percentile).
Vulnerabilities & Exploits · Web App Attack
The weak point here is not the control logic. It is the SIMATIC S7 web server, so the exposure sits in the management interface that operators use to administer the PLCs, and some affected models still do not have a fix version yet.
CISA lists three cross-site scripting flaws, CVE-2026-25786, CVE-2026-25787, and CVE-2026-25789, across SIMATIC Drive Controller CPU 1504D TF and 1507D TF, plus multiple ET 200SP CPU 1510SP and 1512SP variants. Siemens has released new versions for some products, including Drive Controller versions below 3.1.6 and ET 200SP versions below 2.9.9 on certain models, and says other affected products need interim countermeasures until fixes arrive.
That leaves mixed exposure across the fleet. For operators, the main risk is not a uniform patch cycle but a split state where some controllers can be updated and others remain dependent on mitigation and continued web access control.
1 source · May 14
CVSS 9.1 CRITICAL: affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters… EPSS 0.4% (29th percentile).
CVSS 9.1 CRITICAL: affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the web interface. EPSS 0.4% (29th percentile).
CVSS 7.1 HIGH: affected devices do not properly validate and sanitize filenames on the Firmware Update page. EPSS 0.3% (20th percentile).
CISA Advisories
Siemens SIMATIC S7 PLC Web Server | CISA
Siemens SIMATIC S7 PLC Web Server Summary SIMATIC S7 PLCs contain multiple vulnerabilities in the web server that could allow an attacker to perform cross-site scripting attacks.
originalPart of the PlainSec briefing for 2026-05-14
Every edition of this story: Some Siemens PLC Web UIs Still Lack Fixes