Siemens Desigo, SIMATIC flaws enable RCE
Siemens Desigo building automation controllers and SIMATIC IoT2050 have vulnerabilities allowing remote code execution, denial of service, and security bypass.
CERT-FR has issued an advisory relaying two Siemens security bulletins (SSA-781903 and SSA-834709) covering multiple vulnerabilities in Siemens Desigo building automation controllers (DXR2, PXC3, PXC4, PXC5.E003, PXC5.E24, PXC7) and the SIMATIC IoT2050 Advanced with Industrial OS. The flaws, tracked as CVE-2026-58115 and CVE-2026-59693, could allow an attacker to achieve remote arbitrary code execution, cause a remote denial of service, or bypass security policy controls on affected devices.
Affected products span multiple firmware versions predating specific fixed builds (e.g., Desigo DXR2/PXC3 before 01.21.233.16-7862, Desigo PXC4/PXC5/PXC7 before 02.21.194.36-2715, and SIMATIC IoT2050 before 4.3.4.1). These are building automation and industrial edge devices commonly deployed in operational technology environments for HVAC and facility control, making exploitation a concern for organizations relying on Siemens Desigo systems for building management. No evidence of active exploitation is mentioned in the advisory; organizations are advised to apply vendor-supplied patches referenced in the Siemens bulletins.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1009
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free