SIMATIC HMI Panels Expose Browser Access via Help Link

The broken assumption is that the help link on a SIMATIC HMI panel is harmless UI. On affected Unified Comfort Panels, an unauthenticated attacker can reach the embedded web browser if the device is not protected by the intended security mechanisms, which can expose internals and reveal backdoors or misconfigurations. CISA and Siemens say CVE-2026-27662 affects SIMATIC HMI Unified Comfort Panels before V21.0, including the MTP1000 Unified Comfort Panel and the listed hygienic variants. Siemens has released updated versions and recommends moving to V21.0 or later. For OT teams, the risk is not just browser access. A network-reachable panel can leak enough internal surface to turn a narrow entry point into a foothold-finding exercise, especially where security controls were assumed to block that path.

Part of the PlainSec briefing for 2026-05-15

Sources