TL;DR
Siemens has disclosed CVE-2026-58115, a maximum-severity flaw in SIMATIC IoT2050 Advanced devices. The bug scores a perfect CVSS 10.0 and enables remote code execution through Node-RED. An unauthenticated attacker can run commands with the highest privileges.
- CVE: CVE-2026-58115
- CVSS: 10.0 (Critical · CVSSv3)
- Product: Siemens SIMATIC IoT2050 Advanced
- Affected: < V4.3.4.1
- Impact: A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All...
- Status: No confirmed exploitation yet
- Patched in: V4.3.4.1
- Action: Update to V4.3.4.1 now
Why it matters
A CVSS 10.0 rating is as bad as it gets. This remote code execution flaw needs no login and no user interaction. As a result, any exposed device is at direct risk.
The IoT2050 is an industrial gateway used in factories and OT networks. So a full takeover can put both data and physical processes in danger. Siemens published the advisory on August 11, 2026.
How the attack works
The flaw lives in the Node-RED HTTP interface. That interface does not enforce authentication. Therefore, anyone who reaches it can access programming nodes.
According to Siemens, those nodes can run system commands. The advisory warns that affected devices “do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server.” An attacker builds a malicious flow, then triggers remote code execution.
Exploitation status
No public proof-of-concept or in-the-wild exploitation has been confirmed for CVE-2026-58115. Still, the low complexity makes fast action wise.
Affected versions
The issue affects SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2). Specifically, all versions below V4.3.4.1 running Industrial OS with Node-RED installed are vulnerable.
Patch and mitigation steps
Update to version V4.3.4.1 or later right away. If you cannot patch, Siemens suggests two options. First, uninstall Node-RED. Second, harden the Node-RED install per its user guide.
Beyond that, restrict network access to the device. Siemens also points users to its operational guidelines for industrial security. Prompt patching remains the strongest fix for this remote code execution flaw.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.