The weak point here is not the control logic. It is the SIMATIC S7 web server, so the exposure sits in the management interface that operators use to administer the PLCs, and some affected models still do not have a fix version yet.
CISA lists three cross-site scripting flaws, CVE-2026-25786, CVE-2026-25787, and CVE-2026-25789, across SIMATIC Drive Controller CPU 1504D TF and 1507D TF, plus multiple ET 200SP CPU 1510SP and 1512SP variants. Siemens has released new versions for some products, including Drive Controller versions below 3.1.6 and ET 200SP versions below 2.9.9 on certain models, and says other affected products need interim countermeasures until fixes arrive.
That leaves mixed exposure across the fleet. For operators, the main risk is not a uniform patch cycle but a split state where some controllers can be updated and others remain dependent on mitigation and continued web access control.