Siemens Widens Patch Work Across OT Estates

Siemens and national CSIRTs issued coordinated advisories on September 8 for multiple product families, including Desigo CC, SIMOVE Fleetmanager, SIPLANT, Siveillance Control, and Reyrolle 7SR5. The notices cover two critical and seven high-severity flaws across a broad mix of industrial and building-management versions. The listed issues include arbitrary file write, authentication bypass, arbitrary code execution, denial of service, and privilege escalation. In plain terms, the same site may have more than one Siemens component exposed at once, so a fix can land in one layer while another family stays vulnerable until its own bulletin-driven update cycle runs. For operators with mixed Siemens deployments, the story is coordination rather than a single broken box: these products sit across operational and enterprise contexts, and the remaining exposure depends on which family is still awaiting its own update. The advisory does not report active exploitation, but it does leave patch sequencing and uptime dependencies squarely in the reader's estate.

Part of the PlainSec briefing for 2026-09-09

Every edition of this story: Siemens Widens Patch Work Across OT Estates

Sources