The web interface flaw can allow code injection if a legitimate user imports a specially crafted trace file. Siemens has released patches for multiple models and is preparing additional fixes.
Part of the PlainSec briefing for 2026-03-13