VORANT. Threat Intelligence Sign in Get the full feed

Siemens SIMATIC S7-1500 and Desigo CC critical vulnerabilities

high vulnerability manufacturinginfrastructureenergy

ANSSI advisory warns of multiple critical vulnerabilities in Siemens SIMATIC S7-1500 PLC and Desigo CC building automation systems enabling remote code execution and privilege escalation.

French national CERT ANSSI has published a security advisory covering multiple vulnerabilities affecting Siemens industrial automation and building management products. The most significantly affected product is SIMATIC S7-1500 PLC (versions 3.1.6 and later), with 146 documented CVEs ranging from 2021 to 2026, enabling remote code execution, privilege elevation, denial of service, confidentiality bypass, and security policy circumvention. Desigo CC (all versions affected for CVE-2025-15467; versions before 9.0.1 for multiple other flaws) and SIMATIC S7-PLCSIM Advanced also carry critical flaws. The advisory references three Siemens security bulletins (SSA-019113, SSA-734552, SSA-828211) published 14 July 2026 as the remediation source. The volume and severity of affected CVEs indicates this is a coordinated disclosure covering accumulated patches rather than an active exploitation event, though defenders operating these devices should prioritize patching immediately given remote code execution risk in critical infrastructure control systems.

Mentioned in this report

Vulnerabilities CVE-2021-41617CVE-2023-28531CVE-2023-51384CVE-2023-52927CVE-2024-26783CVE-2024-27056CVE-2024-28956CVE-2024-36903CVE-2024-36927CVE-2024-42079CVE-2024-46786CVE-2024-47736CVE-2024-47809CVE-2024-49968CVE-2024-49994CVE-2024-49998CVE-2024-50014CVE-2024-50063CVE-2024-50164CVE-2024-50298CVE-2024-53124CVE-2024-53170CVE-2024-54458CVE-2024-56631CVE-2024-56703CVE-2024-56719CVE-2025-15467CVE-2025-21645CVE-2025-21648CVE-2025-21655CVE-2025-21676CVE-2025-21682CVE-2025-21702CVE-2025-21705CVE-2025-21706CVE-2025-21707CVE-2025-21718CVE-2025-21731CVE-2025-21745CVE-2025-21758

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0880

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free