Siemens Video Server Bug Opens Management RCE

CISA flagged CVE-2026-3014 in Siemens Siveillance Video Management Servers, and Siemens shipped fixed versions for V2023 R3, V2024 R1, and V2025. The affected deployments are listed as worldwide, including critical manufacturing and communications. The flaw sits in the Management Server API: a user with edit permissions can make the server run arbitrary code in the context of the Management Server service account. In plain terms, a trusted administration role can cross into server-level execution, so the exposure is on the system that runs the video platform, not on a single camera or endpoint. For organizations that use Siveillance Video as the control plane for physical security, the risk follows the management server wherever it is deployed. If that server has broad reach into the rest of the system, a weakness in its admin interface can matter more than the video feed itself.

Sources