CVE-2026-25786Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page of the web interface. This could allow an authenticated attacker who is authorized to download a TIA project into the product, to inject malicious scripts into the page. If a benign user with appropriate rights accesses the "communication" parameters page, the malicious code would be executed in the scope of their web session.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-05-13); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-13: 1Mentions · 2026-05-19: 1Mentions · 2026-07-04: 1Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-13: 1Technical Details · 2026-07-04: 105-1305-1907-04
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-131
Patch1
2026-05-191
Disclosure1
2026-07-041
Disclosure1
Full discourse3 posts
  • BREACHSPIDER@breachspider
    Disclosure

    [CVE Analysis] CVE-2026-25786: Siemens SIMATIC S7 PLC Web Server XSS Reaches CVSS 9.1 https://breachspider.com/intel/2026-07-04-cve-2026-25786-siemens-simatic-s7-plc-web-server-xss-reaches #ICS #OTSecurity #SCADA #CriticalInfrastructure

    Post summary

    This source discloses a new high‑severity cross‑site scripting flaw (CVE‑2026‑25786) in Siemens SIMATIC S7 PLC Web Server, noting a CVSS 9.1 score, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    0000061
    2.3K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Siemens ❗ CVE-2026-25787 ❗ CVE-2026-25786 ❗ CVE-2025-40949 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-siemens-6/ https://t.co/UF347jb2IS

    Post summary

    The tweet lists three Siemens product vulnerabilities (CVE‑2026‑25787, CVE‑2026‑25786, CVE‑2025‑40949) and links to external pages for additional information, but it does not provide any PoC, exploit details, patch information, or technical specifics.

    000001.2K
    6.7K followersView on X
  • Cyber Netsec IO@NetSecIO
    Patch

    Siemens drops 18 security advisories for ICS Patch Tuesday, fixing critical flaws in SIMATIC S7 PLCs and RUGGEDCOM devices. Key bugs (CVE-2026-25786, CVE-2026-25787) could lead to device takeover. 🏭 #ICSsecurity #OTsecurity #Siemens #PLC https://t.co/mDaB4b5JOR

    Post summary

    Siemens released 18 advisories for critical flaws in SIMATIC S7 PLCs and RUGGEDCOM devices, with the CVEs potentially allowing device takeover; patches are now available.

    0000077
    53 followersView on X

Explore more