CVE-2026-27662
CVSS 7.7 HIGH: affected devices do not properly restrict access to the web browser via the Control Panel when no corresponding… EPSS 0.1% (2nd percentile).
Vulnerabilities & Exploits · Web App Attack
The broken assumption is that the help link on a SIMATIC HMI panel is harmless UI. On affected Unified Comfort Panels, an unauthenticated attacker can reach the embedded web browser if the device is not protected by the intended security mechanisms, which can expose internals and reveal backdoors or misconfigurations.
CISA and Siemens say CVE-2026-27662 affects SIMATIC HMI Unified Comfort Panels before V21.0, including the MTP1000 Unified Comfort Panel and the listed hygienic variants. Siemens has released updated versions and recommends moving to V21.0 or later.
For OT teams, the risk is not just browser access. A network-reachable panel can leak enough internal surface to turn a narrow entry point into a foothold-finding exercise, especially where security controls were assumed to block that path.
1 source · May 14
CVSS 7.7 HIGH: affected devices do not properly restrict access to the web browser via the Control Panel when no corresponding… EPSS 0.1% (2nd percentile).
CISA Advisories
Siemens SIMATIC | CISA
Siemens SIMATIC Summary SIMATIC HMI Unified Comfort Panels before V21.0 are affected by a vulnerability that allows an unauthenticated attacker to access the web browser via the help link.
originalPart of the PlainSec briefing for 2026-05-14
Every edition of this story: SIMATIC HMI Panels Expose Browser Access via Help Link