# Siemens SIMATIC S7-1500 and Desigo CC critical vulnerabilities

Published: 2026-07-15 · Severity: high · Sectors: manufacturing, infrastructure, energy
Canonical: https://vorant.io/reports/134483ca-c48c-52c2-a9db-51422ee623ec/siemens-simatic-s7-1500-and-desigo-cc-critical-vulnerabilities

> ANSSI advisory warns of multiple critical vulnerabilities in Siemens SIMATIC S7-1500 PLC and Desigo CC building automation systems enabling remote code execution and privilege escalation.

French national CERT ANSSI has published a security advisory covering multiple vulnerabilities affecting Siemens industrial automation and building management products. The most significantly affected product is SIMATIC S7-1500 PLC (versions 3.1.6 and later), with 146 documented CVEs ranging from 2021 to 2026, enabling remote code execution, privilege elevation, denial of service, confidentiality bypass, and security policy circumvention. Desigo CC (all versions affected for CVE-2025-15467; versions before 9.0.1 for multiple other flaws) and SIMATIC S7-PLCSIM Advanced also carry critical flaws. The advisory references three Siemens security bulletins (SSA-019113, SSA-734552, SSA-828211) published 14 July 2026 as the remediation source. The volume and severity of affected CVEs indicates this is a coordinated disclosure covering accumulated patches rather than an active exploitation event, though defenders operating these devices should prioritize patching immediately given remote code execution risk in critical infrastructure control systems.

## Mentioned in this report

- Vulnerabilities: CVE-2021-41617, CVE-2023-28531, CVE-2023-51384, CVE-2023-52927, CVE-2024-26783, CVE-2024-27056, CVE-2024-28956, CVE-2024-36903, CVE-2024-36927, CVE-2024-42079, CVE-2024-46786, CVE-2024-47736, CVE-2024-47809, CVE-2024-49968, CVE-2024-49994, CVE-2024-49998, CVE-2024-50014, CVE-2024-50063, CVE-2024-50164, CVE-2024-50298, CVE-2024-53124, CVE-2024-53170, CVE-2024-54458, CVE-2024-56631, CVE-2024-56703, CVE-2024-56719, CVE-2025-15467, CVE-2025-21645, CVE-2025-21648, CVE-2025-21655, CVE-2025-21676, CVE-2025-21682, CVE-2025-21702, CVE-2025-21705, CVE-2025-21706, CVE-2025-21707, CVE-2025-21718, CVE-2025-21731, CVE-2025-21745, CVE-2025-21758

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0880

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/134483ca-c48c-52c2-a9db-51422ee623ec/siemens-simatic-s7-1500-and-desigo-cc-critical-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
