PatchSiren cyber security CVE debrief
CVE-2026-25787 Siemens CVE debrief
CVE-2026-25787 is an authenticated cross-site scripting issue in the Siemens SIMATIC web interface. A Technology Object (TO) name shown on the Motion Control Diagnostics page is not properly validated or sanitized, so a user who can download a TIA project into the product may inject malicious scripts. If another user with suitable rights opens that page, the script runs in that user's web session.
- Vendor
- Siemens
- Product
- SIMATIC Drive Controller CPU 1504D TF (6ES7615-4DF10-0AB0)
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
OT administrators, Siemens SIMATIC owners, PLC engineering teams, and security teams responsible for the listed SIMATIC Drive Controller and S7-1500 / ET 200SP products should prioritize this advisory, especially where the web interface is enabled and TIA project import/download rights are broadly assigned.
Technical summary
The advisory describes a reflected/stored web UI injection condition on the Motion Control Diagnostics page. The vulnerable data path is the Technology Object name, which is rendered without adequate validation/sanitization. Exploitation requires authentication and authorization to download a TIA project into the device, but the impact is significant because the injected script executes in the scope of a benign user's web session. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, with a score of 9.1.
Defensive priority
Critical. Although the attack requires high privileges, the combination of network exposure, web-session impact, and possible abuse of trusted engineering workflows makes this a high-priority remediation item for OT environments.
Recommended defensive actions
- Apply Siemens vendor fixes where available: update to V3.1.6 or later for the affected Drive Controller CPU 1504D TF and related entries covered by that remediation.
- Apply Siemens vendor fixes where available: update to V2.9.9 or later for the affected ET 200SP / S7-1500 entries covered by that remediation.
- Where the advisory states no fix is currently available or no fix is planned, implement compensating controls and track vendor guidance for future updates.
- Restrict TIA project download privileges to trusted personnel only, as recommended in the advisory.
- Limit access to the device web interface to necessary administrative networks and users.
- Review OT account assignment and remove unnecessary high-privilege access that could allow project download into the product.
- Monitor for unexpected content or behavior on the Motion Control Diagnostics page and other web UI pages that render project-supplied names.
- Use Siemens and CISA recommended industrial-control-system hardening practices to reduce exposure while patching is pending.
Evidence notes
This debrief is based on the supplied CISA CSAF advisory ICSA-26-134-15 and the referenced Siemens ProductCERT advisory SSA-688146. The source corpus states the issue was published on 2026-05-12 and modified on 2026-05-14; those dates are used as the CVE timing context here. The corpus also links the remediation options to Siemens update paths and a compensating control to restrict TIA project download to trusted personnel only. No exploit code or offensive reproduction steps were used.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-25787 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-25787
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-25787 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-25787
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-15.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-688146.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-688146.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-15
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.