# Siemens Desigo, SIMATIC flaws enable RCE

Published: 2026-08-12 · Severity: routine · Sectors: manufacturing, infrastructure
Canonical: https://vorant.io/reports/17470aec-8dfb-54ef-af73-c5594ce3a724/siemens-desigo-simatic-flaws-enable-rce

> Siemens Desigo building automation controllers and SIMATIC IoT2050 have vulnerabilities allowing remote code execution, denial of service, and security bypass.

CERT-FR has issued an advisory relaying two Siemens security bulletins (SSA-781903 and SSA-834709) covering multiple vulnerabilities in Siemens Desigo building automation controllers (DXR2, PXC3, PXC4, PXC5.E003, PXC5.E24, PXC7) and the SIMATIC IoT2050 Advanced with Industrial OS. The flaws, tracked as CVE-2026-58115 and CVE-2026-59693, could allow an attacker to achieve remote arbitrary code execution, cause a remote denial of service, or bypass security policy controls on affected devices.

Affected products span multiple firmware versions predating specific fixed builds (e.g., Desigo DXR2/PXC3 before 01.21.233.16-7862, Desigo PXC4/PXC5/PXC7 before 02.21.194.36-2715, and SIMATIC IoT2050 before 4.3.4.1). These are building automation and industrial edge devices commonly deployed in operational technology environments for HVAC and facility control, making exploitation a concern for organizations relying on Siemens Desigo systems for building management. No evidence of active exploitation is mentioned in the advisory; organizations are advised to apply vendor-supplied patches referenced in the Siemens bulletins.

## Mentioned in this report

- Vulnerabilities: CVE-2026-58115, CVE-2026-59693

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1009

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/17470aec-8dfb-54ef-af73-c5594ce3a724/siemens-desigo-simatic-flaws-enable-rce.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
