VORANT. Threat Intelligence Sign in Get the full feed

Siemens WTV676/WTV776 DoS Vulnerability Patched

routine vulnerability energy

A CISA advisory details a DoS flaw in Siemens WTV676/WTV776 web interfaces that lets unauthenticated attackers disable remote Web Access; patches are available.

CISA republished a Siemens ProductCERT advisory (SSA-823812) describing a denial-of-service vulnerability, CVE-2026-89207, affecting Siemens WTV676 and WTV776 devices. The flaw stems from improper validation of input received from backend services (CWE-1287), allowing an unauthenticated remote attacker to force the device into 'protection mode,' which disables remote connectivity functions including Web Access. Affected versions are WTV676-HB6035 Web Interface prior to V3.94 and WTV776-HB6035 Web Interface prior to V4.17.

Siemens has released fixed versions (V3.94 and V4.17 respectively) and recommends updating affected devices. These products are deployed worldwide in the energy sector, per CISA's advisory classification. There is no indication of active exploitation in the wild; this is a vendor-disclosed vulnerability with a coordinated fix already available.

Defenders should apply the vendor updates promptly, and in the interim follow standard ICS network hardening: minimize internet exposure of control system devices, isolate them behind firewalls from business networks, and use VPNs (kept updated) for any required remote access. No IOCs, threat actors, or exploitation campaigns are associated with this advisory.

Mentioned in this report

Vulnerabilities CVE-2026-89207

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-08

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free