Siemens Discloses Vulnerabilities Across 11 Product Lines, Urges Patching
Siemens published security advisories on July 14, 2026, covering 11 product lines. The Canadian Cyber Centre recommends prompt patching.
This article was drafted with AI assistance from multiple sources and was reviewed and approved by a human editor before publication.
Siemens disclosed security vulnerabilities affecting 11 product lines on July 14, 2026, according to advisories published by the company. The affected products span industrial control, building automation, and software platforms.
Among the impacted products are CADRA versions prior to V2511 and the Desigo CC family, with all versions of V7 and V8 affected, as well as V9 versions prior to V9.0 QU1. The IAM Client is affected across multiple versions and models, while all versions of Mendix Runtime are vulnerable. Opcenter X versions prior to V2604 are also listed.
In the networking and industrial hardware segment, the Palo Alto Networks PAN-OS running on RUGGEDCOM APE1808 is affected across all versions. The SIDIS Secured SmartPlug is impacted in versions prior to V7.26.0310. Siemens also identified vulnerabilities in the SIMATIC S7-1500 CPU family for versions prior to V3.1.6, and all versions of SIMATIC S7-PLCSIM Advanced are affected. Additionally, all versions of Simcenter STAR-CCM+ are vulnerable.
The Canadian Centre for Cyber Security has urged users to review the Siemens Security Advisories and apply the recommended mitigations. Siemens has provided details on each advisory and expects customers to update or patch affected systems promptly.