All incidents

Siemens SIMATIC IoT2050 RCE vulnerability (CVE-2026-58115)

vulnerabilityopenAug 12, 2026 — Aug 12, 2026
Siemens warns of CVE-2026-58115 RCE in SIMATIC IoT2050 devices

SIEMENS has issued a critical alert for CVE‑2026-58115, a severe vulnerability affecting SIMATIC IoT2050 Advanced devices that carries a CVSS score of 10.0. The flaw permits unauthenticated remote code execution through the Node‑RED HTTP interface, putting industrial control systems at immediate risk. Users are urged to update to version V4.3.4.1 or later to close the gap.

The vulnerability resides in the way the Node‑RED component handles incoming HTTP requests, allowing an attacker to craft a specially formed packet that executes arbitrary code with root privileges. No authentication is required and the attack complexity is rated low, making it relatively easy to exploit. All firmware releases prior to V4.3.4.1 are impacted, while the patched version includes fixes for the insecure request handling.

Exploitation does not rely on any user interaction; an external actor can send a malicious HTTP request to the exposed Node‑RED port and gain full control of the device. Although there is no public evidence of active exploitation in the wild, the low barrier to entry means that threat actors could quickly adopt the technique if they discover exposed devices. The advisory notes that the issue is present in the default Node‑RED installation bundled with the SIMATIC IoT2050 Advanced.

This alert forms part of Siemens’ Patch Tuesday release for August 2026, during which the company published ten security advisories covering various products. Similar critical updates were issued by Schneider Electric and Phoenix Contact, highlighting a broader trend of hardening industrial control hardware. No specific threat actors have been linked to CVE‑2026-58115 at this time, and the vulnerability is not yet listed in the Known Exploited Vulnerabilities catalogue.

Defenders should prioritize applying the update to V4.3.4.1 or a newer release as soon as possible. If patching cannot be performed immediately, consider uninstalling the Node‑RED package or disabling its HTTP interface until a fix can be deployed. Restricting network access to the Node‑RED port through firewalls or VPN gateways adds an additional layer of protection.

Further steps include reviewing asset inventories to identify any SIMATIC IoT2050 devices running vulnerable firmware, monitoring logs for unexpected HTTP POST or GET requests to the Node‑RED endpoint, and enforcing network segmentation to isolate industrial equipment from untrusted zones. Detailed guidance and the full advisory are available via the Siemens security portal.

Intelligence briefing updated Aug 12, 2026

CVE-2026-58115 10.0
Root sourcecert-portal.siemens.com
Timeline Coverage

Swipe to explore timeline