securityonline.info 8/12/2026, 9:51:19 AM · external

Siemens warns of CVE-2026-58115 RCE in SIMATIC IoT2050 devices

Siemens warns of CVE-2026-58115 RCE in SIMATIC IoT2050 devices
Developing story vulnerability 2 articles tracked
Siemens SIMATIC IoT2050 RCE vulnerability (CVE-2026-58115)
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

SIEMENS has issued a critical alert for CVE-2026-58115, a severe vulnerability in the SIMATIC IoT2050 Advanced devices, rated 10.0 on the CVSS scale. This flaw allows unauthenticated remote code execution via the Node-RED HTTP interface, posing significant risks to industrial systems. Users are advised to update to version V4.3.4.1 or later to mitigate this vulnerability. The issue affects all versions below V4.3.4.1 and has not been confirmed as exploited in the wild, despite its low complexity of attack. Alternative mitigation steps include uninstalling Node-RED or hardening its installation.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline