CVE-2026-27668Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). User Administrators are allowed to administer groups they belong to. This could allow an authenticated User Administrator to escalate their own privileges and grant themselves access to any device group at any access level.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 4 mentions (2026-04-14); latest day: 1
  • 8 total mentions across 3 days

Deep dive

Activity timeline8 mentions / 3d
01234Mentions · 2026-04-14: 4Mentions · 2026-04-21: 3Mentions · 2026-04-22: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-21: 2Technical Details · 2026-04-14: 3Technical Details · 2026-04-21: 2Technical Details · 2026-04-22: 104-1404-2104-22
Signal classification3 categories
Disclosure
337.5%
Patch
337.5%
General
225.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-04-144
Disclosure3Patch1
2026-04-213
General1Patch2
2026-04-221
General1
Full discourse8 posts
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Siemens RUGGEDCOM CROSSBOW Secure Access Manager Primary (CVE-2026-27668) https://vuldb.com/vuln/357301

    Post summary

    The text announces a new vulnerability (CVE‑2026‑27668) in Siemens RUGGEDCOM CROSSBOW Secure Access Manager Primary with elevated criticality, but provides no additional details or links to PoC, exploits, or patches.

    0101060
    2.1K followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    General

    🔒 #CyberSecurity CVE-2026-27668: Siemens RUGGEDCOM CROSSBOW Privilege Escalation – Detection and… "Siemens RUGGEDCOM SAM-P vulnerability (CVSS 8.8) allows privilege escalation." 🔗 https://securityarsenal.com/blog/cve-2026-27668-siemens-ruggedcom-crossbow-privilege-escalation-detection-and-hardening #CyberSecurity #ThreatIntel #managedsoc #mdr #securitymonitoring

    Post summary

    The post announces a privilege escalation CVE with a CVSS score, but does not detail PoC, exploit, active use, or patches, and therefore is categorized as general informational.

    0000049
    11 followersView on X
  • WindowsForum@windowsforum
    Patch

    🪟 CVE-2026-27668: even industrial “secure access” gear lets a User Admin role grab more power than it should. Patch ASAP—because Windows taught us trust is never free. https://windowsforum.com/threads/cve-2026-27668-patch-siemens-ruggedcom-crossbow-sam-p-to-v5-8.414557/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #PrivilegeEscalation #IndustrialCybersecurity #SiemensCrossbow #Cve202627668 https://t.co/WB3oAnQKrN

    Post summary

    The tweet announces CVE-2026-27668 as a privilege escalation issue in industrial secure access gear and urges users to apply a patch immediately.

    0000034
    1.1K followersView on X
  • WindowsForum@windowsforum
    Patch

    🪟 Management-plane flaw (CVE-2026-27668) with CVSS 8.8? Classic: the “security manager” gets pwned and suddenly every user’s an admin. Upgrade V5.8+ or enjoy chaos. https://windowsforum.com/threads/cve-2026-27668-siemens-ruggedcom-crossbow-secure-access-manager-fix-for-admin-escalation.414555/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #AccessControl #IndustrialCybersecurity #SiemensAdvisories #CvePatching https://t.co/bwLxgUzkoX

    Post summary

    The post discusses the CVE‑2026‑27668 vulnerability in Siemens RuggedCom Secure Access Manager that allows privilege escalation, advising users to upgrade to version 5.8 or later to mitigate the risk.

    0000025
    1.1K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Siemens ❗ CVE-2026-27668 ❗ CVE-2026-25654 ❗ CVE-2026-24032 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-siemens-5/ https://t.co/xaUvGrjHyI

    Post summary

    The text enumerates three Siemens-related CVEs but offers no further technical details, exploit evidence, or mitigation information.

    0000098
    6.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27668 Privilege Escalation in RUGGEDCOM CROSSBOW Secure Access Manager Primary Versions Below 5.8 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27668

    Post summary

    The text announces a new privilege‑escalation vulnerability (CVE‑2026‑27668) in Ruggedcom CROSSBOW Secure Access Manager versions <5.8, without providing PoC, exploit details, or patch information.

    0000039
    4.0K followersView on X
  • dbugs@ptdbugs
    Disclosure

    CVE: CVE-2026-27668 PT ID: PT-2026-32609 Vendor: Siemens Product: RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) CVSS: 8.8 Credits: n/a Description: A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). User Administrators are allowed to administer groups they belong to. This could allow an authenticated User Administrator to escalate their own privileges and grant themselves access to any device group at any access level. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-27668 • https://cert-portal.siemens.com/productcert/html/ssa-741509.html #dbugs_vuln

    Post summary

    The post announces CVE‑2026‑27668, detailing a privilege‑escalation flaw in Siemens RUGGEDCOM Secure Access Manager for versions below 5.8, with no evidence of exploitation or available fixes.

    0000078
    797 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-27668: HIGH] Vulnerability alert: RUGGEDCOM CROSSBOW SAM-P (All versions &lt; V5.8) allows User Admins to escalate privileges, granting unauthorized access. Update recommended for security.#cve,CVE-2026-27668,#cybersecurity https://cvefind.com/CVE-2026-27668

    Post summary

    The tweet alerts to a CVE‑2026‑27668 privilege‑escalation vulnerability in Ruggedcom Crossbow SAM‑P and recommends an update, with no PoC or exploit evidence provided.

    0000052
    620 followersView on X

Explore more