VORANT. Threat Intelligence Sign in Get the full feed

Fortinet flaws hit Siemens RUGGEDCOM APE1808

routine vulnerability manufacturingenergytransportation

Siemens RUGGEDCOM APE1808 devices bundling Fortinet NGFW inherit two FortiOS vulnerabilities allowing XSS-based code execution and CLI-driven file system deletion.

CISA republished a Siemens ProductCERT advisory noting that RUGGEDCOM APE1808 devices, which can be deployed with a bundled Fortinet NGFW, are affected by two vulnerabilities disclosed by Fortinet in FortiOS, FortiPAM, FortiProxy, and FortiSwitch Manager. CVE-2026-23573 is a cross-site scripting flaw (CWE-79) that could allow an authenticated remote user to execute code or commands via crafted requests across multiple FortiOS, FortiPAM, and FortiProxy versions. CVE-2026-59839 is a path traversal vulnerability (CWE-22) that could allow a privileged authenticated attacker with physical access to delete the device's file system using crafted CLI commands.

RUGGEDCOM APE1808 is deployed worldwide in Critical Manufacturing, Energy, and Transportation Systems environments, making the advisory relevant to ICS/OT operators using these devices alongside embedded Fortinet security appliances. There is no evidence of active exploitation; Siemens has no direct fix and instead directs customers to Fortinet's advisory and customer support for mitigation guidance, alongside general recommendations to isolate control system networks and restrict remote access. Both vulnerabilities require authentication (and physical access in the case of the path traversal issue), which limits the immediate attack surface but underscores the need for network segmentation and strict access controls in industrial deployments.

Mentioned in this report

Vulnerabilities CVE-2026-23573CVE-2026-59839

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-06

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free