Siemens patches RCE flaws in SIMATIC, Desigo CC
ANSSI advisory covers multiple Siemens SIMATIC HMI/Runtime products and Desigo CC affected by arbitrary code execution and privilege escalation vulnerabilities.
ANSSI (CERT-FR) has republished two Siemens security advisories (SSA-328642 and SSA-330084) covering multiple vulnerabilities across a broad range of Siemens industrial products. The flaws, tracked as CVE-2026-31431 and CVE-2026-34223, allow an attacker to achieve arbitrary code execution and privilege escalation. Affected products include Desigo CC building management software (all versions), various SIMATIC AX Runtime Core Linux builds, SIMATIC CN 4100, the SIMATIC IoT2050 Advanced device, SIMATIC Industrial Edge Device OS, SIMATIC S7-1500 TM MFP module, and a large family of SIMATIC HMI MTP unified/comfort panel touch panels (MTP400 through MTP2200 series) running versions prior to 21.0.2.1.
No indication of active exploitation is provided in the advisory; this is a vendor-driven patch notification distributed via the French national CERT. Given the operational technology nature of the affected products (HMI panels, industrial controllers, building management systems), successful exploitation could impact plant floor visibility/control or building automation systems, making timely patching important for asset owners in manufacturing and infrastructure environments. No proof-of-concept exploit, IOCs, or attribution are included; organizations should consult the linked Siemens bulletins for patched versions and apply fixes according to their change-management processes.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1133
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free