Vulnerabilities · 124 days ago

Some Siemens PLC Web UIs Still Lack Fixes

The weak point here is not the control logic. It is the SIMATIC S7 web server, so the exposure sits in the management interface that operators use to administer the PLCs, and some affected models still do not have a fix version yet.

CISA lists three cross-site scripting flaws, CVE-2026-25786, CVE-2026-25787, and CVE-2026-25789, across SIMATIC Drive Controller CPU 1504D TF and 1507D TF, plus multiple ET 200SP CPU 1510SP and 1512SP variants. Siemens has released new versions for some products, including Drive Controller versions below 3.1.6 and ET 200SP versions below 2.9.9 on certain models, and says other affected products need interim countermeasures until fixes arrive.

That leaves mixed exposure across the fleet. For operators, the main risk is not a uniform patch cycle but a split state where some controllers can be updated and others remain dependent on mitigation and continued web access control.

CVE-2026-25786

NVD KEV

CVSS 9.1 CRITICAL: affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters… EPSS 0.4% (29th percentile).

CVE-2026-25787

NVD KEV

CVSS 9.1 CRITICAL: affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the web interface. EPSS 0.4% (29th percentile).

CVE-2026-25789

NVD KEV

CVSS 7.1 HIGH: affected devices do not properly validate and sanitize filenames on the Firmware Update page. EPSS 0.3% (20th percentile).

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-05-14

Editions

Related stories