Siemens SIMATIC S7-1500 and Desigo CC critical vulnerabilities
ANSSI advisory warns of multiple critical vulnerabilities in Siemens SIMATIC S7-1500 PLC and Desigo CC building automation systems enabling remote code execution and privilege escalation.
French national CERT ANSSI has published a security advisory covering multiple vulnerabilities affecting Siemens industrial automation and building management products. The most significantly affected product is SIMATIC S7-1500 PLC (versions 3.1.6 and later), with 146 documented CVEs ranging from 2021 to 2026, enabling remote code execution, privilege elevation, denial of service, confidentiality bypass, and security policy circumvention. Desigo CC (all versions affected for CVE-2025-15467; versions before 9.0.1 for multiple other flaws) and SIMATIC S7-PLCSIM Advanced also carry critical flaws. The advisory references three Siemens security bulletins (SSA-019113, SSA-734552, SSA-828211) published 14 July 2026 as the remediation source. The volume and severity of affected CVEs indicates this is a coordinated disclosure covering accumulated patches rather than an active exploitation event, though defenders operating these devices should prioritize patching immediately given remote code execution risk in critical infrastructure control systems.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0880
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free