← Incidents
INCIDENT 260IntrusionLOW / UNDER REVIEWSourced
Siemens SIMATIC IoT2050 Advanced
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-03.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released a new version for SIMATIC IoT2050 Advanced and strongly recommends to update to the latest version.<…
Last evidence update
25 AUG 2026 · 12:00 UTC
Source count
1
Status
reported
GermanyManufacturingEnergyTransportationDefenseCVE-2026-58115
Preceded by
Weak signals the observatory recorded before this incident became visible.
Observation history
How this record has evolved as evidence accumulated.
26 AUG · 05:17 UTC
Initial report
Evidence