VORANT. Threat Intelligence Sign in Get the full feed

Siemens WinCC key-material exposure affects industrial HMI

medium vulnerability manufacturingenergytransportationhealthcarefinancial-servicesgovernment-national

WinCC Certificate Manager stores cryptographic keys insecurely, enabling extraction of sensitive material across multiple SIMATIC runtime versions.

Siemens has disclosed CVE-2026-24349, an insufficient protection vulnerability in the WinCC Certificate Manager component of SIMATIC WinCC Unified PC Runtime. The flaw allows attackers to extract sensitive key material stored in cleartext, potentially compromising cryptographic operations in industrial human-machine interface (HMI) systems. Affected versions span V16 through V20 (all versions) and V21 prior to update 2.

Siemens has released V21 Update 2 as a fix for the latest runtime version, but no patches are planned for V16-V20. The vulnerability impacts critical infrastructure sectors including manufacturing, energy, transportation, healthcare, and government facilities worldwide. CISA and Siemens recommend network segmentation, restricting device access, and operating affected systems only in protected IT environments per Siemens operational guidelines for Industrial Security.

The disclosure follows coordinated reporting by Siemens ProductCERT to CISA. Organizations running affected versions should prioritize the V21 update where feasible and implement compensating controls—such as isolating WinCC systems behind firewalls and limiting physical/logical access—for legacy versions where patches are unavailable.

Mentioned in this report

Vulnerabilities CVE-2026-24349

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-01

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free