Siemens ProductCERT disclosed two critical Siemens vulnerabilities on September 8, 2026. One allows full account takeover in Industrial Edge Management. The other permits root-level access on Siveillance Control servers. Both carry CVSS scores above 9.0, so operators should act fast.
- Product: org.keycloak:keycloak-services (maven), Siemens Siveillance Control Pro V3.0
- Vulnerabilities: 2 flaws (CVE-2026-18963, CVE-2026-50093)
- Highest severity: 9.1 (Critical · CVSSv3)
- Worst impact: Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
- Status: No confirmed exploitation yet; patches available
- Action: Update to 26.4.15, 26.6.6, 26.7.2, 26.4.15-1 (+7) now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-18963 | 9.1 | CWE-640 | 26.4.15-1, 26.4-23, 26.6.6-1 (+4) | Not exploited |
| CVE-2026-50093 | 9 | Awaiting analysis | V3.0.12.2173, V4.0.9.2178, V3.0.22.2177 (+1) | Not exploited |
Why These Siemens Vulnerabilities Matter
Both flaws sit inside operational technology used at sensitive sites. Industrial Edge runs edge computing across factory and plant networks. Siveillance Control protects ports, airports, and power generation facilities.
A successful attack could hand adversaries control of identity systems or host servers. Consequently, the blast radius reaches far beyond a single device. No public proof-of-concept or in-the-wild exploitation has been confirmed for either flaw at this time.
Authentication Bypass in Industrial Edge Management
The first bug, tracked as CVE-2026-18963, earns a CVSS v3.1 score of 9.1. It lives in the password reset flow of Industrial Edge Management. According to the Siemens advisory, the flaw “could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification.”
How the Attack Works
The root cause traces to the Keycloak identity engine. Siemens explains that the issue “allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link.” As a result, an attacker sets new credentials directly and hijacks the target account.
Affected Versions and Fixes
The flaw affects Industrial Edge Management Cloud, Pro V1, Pro V2, and Virtual. Siemens fixed the Cloud version on September 2 with no user action needed. Pro V1 users should update to V1.15.20, Pro V2 to V2.2.2, and Virtual to V2.9.1. Full details appear in the Siemens advisory SSA-503852.
Arbitrary File Upload in Siveillance OIS
The second issue, CVE-2026-50093, scores 9.0 on CVSS v3.1. It affects the Open Interface Services web module in Siveillance Control and Control Pro. The advisory warns that exploitation “could allow an attacker to gain root access on the host system, potentially leading to a full compromise of the affected OIS environment.”
Affected Versions and Fixes
The bug hits OIS 3.x and 4.x builds across both products. Siemens released fixed versions, including Control V3.0.22.2177 and Control Pro V4.0.9.2178. Administrators can find version details in the Siemens advisory SSA-254516.
Mitigation Steps
Patching remains the primary fix for both Siemens vulnerabilities. For the Edge flaw, Siemens also suggests blocking direct internet access to affected instances. Additionally, teams can deactivate password reset in Keycloak realm settings or filter the reset path with a web application firewall.
Operators should restrict network access to all affected products. Moreover, following Siemens‘ industrial security guidelines lowers overall exposure. Given the high severity, prompt action is the safest course.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!