CVE-2026-41551Disclosure

HIGHCVSS 9.3 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability has been identified in ROS# (All versions < V2.2.2). Affected versions contain a path traversal vulnerability because user input is not properly sanitized. This could allow a remote attacker to access arbitrary files on the device.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-23

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-05-12); latest day: 1
  • 7 total mentions across 5 days

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-05-12: 2Mentions · 2026-05-13: 2Mentions · 2026-05-14: 1Mentions · 2026-07-04: 1Mentions · 2026-08-25: 1PoC Mentioned / Linked · 2026-08-25: 1Exploit Tool / Code · 2026-08-25: 1Active Exploitation · 2026-05-14: 1Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-12: 2Technical Details · 2026-05-13: 2Technical Details · 2026-05-14: 1Technical Details · 2026-07-04: 1Technical Details · 2026-08-25: 105-1205-1305-1407-0408-25
Signal classification5 categories
Disclosure
342.9%
General
114.3%
Patch
114.3%
Active Exploitation
114.3%
PoC
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-122
Disclosure1General1
2026-05-132
Disclosure1Patch1
2026-05-141
Active Exploitation1
2026-07-041
Disclosure1
2026-08-251
PoC1
Full discourse7 posts
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-41551 Vendor: Siemens Product: ROS# Description: A vulnerability has been identified in ROS# (All versions < V2.2.2). Affected versions contain a path traversal vulnerability because user input is not properly sanitized. This could allow a remote attacker to access arbitrary files on the device. Link: https://github.com/selecthch/cve-2026-41551 #dbugs_vuln

    Post summary

    A PoC and exploit code for a path‑traversal vulnerability in Siemens ROS# versions below 2.2.2 has been released, allowing remote attackers to read arbitrary files.

    00043492
    3.6K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Urgent: Siemens patches a 9.3 severity Path Traversal (CVE-2026-41551) in ROS#. Attackers can read/write arbitrary files on robotics systems. Update to V2.2.2! #RoboticsSecurity #Siemens #ROSsharp #CyberSecurity #InfoSec #IndustrialAutomation #CVE https://securityonline.info/siemens-ros-sharp-vulnerability-cve-2026-41551-path-traversal/ https://t.co/zNSBDrzBqf

    Post summary

    Siemens has issued a patch (V2.2.2) for a 9.3‑severity Path Traversal vulnerability (CVE-2026‑41551) in ROS# that enables attackers to read/write arbitrary files on robotics systems.

    01010370
    11.9K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - ROS# Path Traversal in file server (CVE-2026-41551) A path traversal vulnerability in the ROS# file_server service (all versions < V2.2.2) occurs due to insufficient sanitization of user-supplied input. This allows remote unauthenticated attackers to read and write arbitrary files on the host system with the privileges of the running service. The flaw can lead to sensitive data exfiltration, configuration tampering, or full system compromise depending on service permissions. 👉Affected: ROS# < V2.2.2

    Post summary

    The text discloses a critical path traversal vulnerability (CVE-2026-41551) affecting ROS# file_server versions below V2.2.2, enabling unauthenticated remote attackers to read and write arbitrary files, potentially leading to data exfiltration or full system compromise.

    0002071
    187 followersView on X
  • BREACHSPIDER@breachspider
    Disclosure

    [CVE Analysis] CVE-2026-41551: Path Traversal in Siemens ROS# file_server Enables Arbitrary File Read and Write https://breachspider.com/intel/2026-07-04-cve-2026-41551-path-traversal-in-siemens-ros-file-server-ena #ICS #OTSecurity #SCADA #CriticalInfrastructure

    Post summary

    The tweet announces CVE-2026-41551, a path traversal flaw in Siemens ROS# file_server allowing arbitrary file read/write, and links to an external analysis without mentioning PoCs, exploits, or patches.

    0000054
    2.3K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers exploited CVE-2026-41551, a path traversal flaw in Siemens ROS#, to access arbitrary files and escalate privileges. TRC analysis shows lateral movement to other network systems followed this initial compromise. Runtime segmentation helps contain such post-compromise activity in industrial environments. #Vulnerability 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/icsa-26-134-08-cve-2026-41551

    Post summary

    The post confirms that CVE-2026-41551 was actively exploited by attackers to traverse paths, access files, and elevate privileges in a Siemens ROS# environment, with lateral movement observed thereafter.

    0000046
    1.9K followersView on X
  • Enigma-Global@EnigmaGlobalSW
    Disclosure

    Intel Report [HIGH] - Siemens ProductCERT has disclosed a critical path traversal vulnerability tracked as CVE-2026-41551 in the ROS# (ROS Sharp) library, an open-source .NET implementation used for Robot Operating System (ROS) communications. This... https://www.enigma-global.com/og/report/critical-siemens-ros-path-traversal-vulnerability-cve-2026-41551-enables-mp31z0ym-wgny

    Post summary

    Siemens ProductCERT has announced a critical path traversal flaw in the ROS# (ROS Sharp) library (CVE‑2026‑41551), but no exploit code, active exploitation, or patch information is provided.

    0000028
    7 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-41551 Path Traversal Vulnerability in ROS# Versions Below 2.2.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41551

    Post summary

    The post merely announces a path traversal vulnerability in ROS# versions below 2.2.2 without any details on PoC, exploitation, or remediation, classifying it as a general disclosure.

    0000044
    4.0K followersView on X

Explore more