SIEMENS has issued a critical alert for CVE-2026-58115, a severe vulnerability in the SIMATIC IoT2050 Advanced devices, rated 10.0 on the CVSS scale. This flaw allows unauthenticated remote code execution via the Node-RED HTTP interface, posing significant risks to industrial systems. Users are advised to update to version V4.3.4.1 or later to mitigate this vulnerability. The issue affects all versions below V4.3.4.1 and has not been confirmed as exploited in the wild, despite its low complexity of attack. Alternative mitigation steps include uninstalling Node-RED or hardening its installation.
Siemens warns of CVE-2026-58115 RCE in SIMATIC IoT2050 devices
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Siemens, Schneider, Phoenix Patch Critical ICS Flaws in August
cybersixt.com
-
Siemens warns of CVE-2026-58115 RCE in SIMATIC IoT2050 devices
securityonline.info