THREATOPS
THREAT OPSThreat News › Siemens Teamcenter

Siemens Teamcenter

highcisa_advisoriesPublished 2026-09-15

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-07.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user's session by crafting a malicious URL.

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-07

Same event, other sources