THREAT OPS › Threat News › Siemens SIMATIC IoT2050 Advanced
Siemens SIMATIC IoT2050 Advanced
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-03.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- CVE-2026-58115cve
- https://www.cve.org/CVERecord?id=CVE-2026-58115url
- https://support.industry.siemens.com/cs/ww/en/view/109741799/url
- https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:Hurl
- https://www.siemens.com/cert/operational-guidelines-industrial-securityurl
- https://www.siemens.com/industrialsecurityurl
- https://www.siemens.com/cert/advisoriesurl
- https://www.siemens.com/productcert/terms-of-useurl
- 4.3.4.1ipv4
Original source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-03
Same event, other sources
- Siemens SIMATIC IoT2050 Advancedcisa_ics · 2026-08-25