CVE-2026-58115Patch

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-12); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-08-11: 1Mentions · 2026-08-12: 2Mentions · 2026-08-26: 1Patch / Workaround · 2026-08-11: 1Patch / Workaround · 2026-08-12: 2Technical Details · 2026-08-11: 1Technical Details · 2026-08-12: 2Technical Details · 2026-08-26: 108-1108-1208-26
Signal classification2 categories
Patch
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-111
Patch1
2026-08-122
Patch2
2026-08-261
General1
Full discourse4 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    CVE-2026-58115 is a CVSS 10 flaw letting unauthenticated attackers run code on SIMATIC IoT2050 via Node-RED. Siemens urges an immediate update. #CVE202658115 #Siemens #NodeRED #RCE #SIMATIC #ICS #Cybersecurity http://securityonline.info/simatic-iot2050-node-red-rce/

    Post summary

    A critical zero‑day RCE vulnerability (CVSS 10) in Siemens SIMATIC IoT2050 via Node‑RED has been disclosed, and Siemens recommends an immediate update; no active exploitation or PoC details are provided.

    03051687
    13.0K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    General

    TRC analysis shows attackers exploiting CVE-2026-58115 can bypass authentication on Siemens SIMATIC IoT2050 devices to execute arbitrary code with maximum privileges. The missing auth controls in Node-RED interfaces enable direct system takeover of industrial control systems. Runtime segmentation helps limit blast radius when OT devices are compromised. #ZeroDay #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/siemens-simatic-iot2050-cve-2026-58115-node-red-authentication-bypass-2026

    Post summary

    CVE‑2026‑58115 allows attackers to bypass authentication on Siemens SIMATIC IoT2050 devices, enabling arbitrary code execution with full privileges; the post outlines the technical nature of the flaw but no exploit code or patch is referenced.

    0000056
    1.9K followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🏭 Siemens SIMATIC IoT2050 Advanced: CVE-2026-58115 is CVSS 10. No auth enforced on devices running Node-RED — network accessible, no interaction needed. Update to Industrial OS V4.3.4.1+ now. #cybersecurity #ciso #ics #siemens #vulnerabilities https://secalerts.co/vulnerability/CVE-2026-58115?utm_campaign=x https://t.co/HehG7vjKQN

    Post summary

    The post announces a CVSS 10 vulnerability in Siemens SIMATIC IoT2050 Advanced devices (Node‑RED) that allows unauthenticated network access, and directs users to update to Industrial OS V4.3.4.1+ to remediate it.

    00000130
    878 followersView on X
  • ThreatAft@ThreatAft
    Patch

    🔐🚨 Siemens SIMATIC IoT2050 — CVSS 10.0 CRITICAL CVE-2026-58115: Node-RED HTTP interface lacks authentication Patch to V4.3.4.1 NOW. → http://threataft.com/articles/siemens-simatic-iot2050-cve-2026-58115 #cybersecurity #infosec #Siemens #ICS #OTSecurity #PatchTuesday #ThreatIntel

    Post summary

    A critical vulnerability (CVE-2026-58115) in the Node‑RED HTTP interface of Siemens SIMATIC IoT2050 has been announced, with an immediate patch (V4.3.4.1) available.

    00000149
    36 followersView on X

Explore more