MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-23 · via Viakoo, Inc

Critical Siemens Industrial Edge Flaw Allows Account Takeover Without Verification

CISA has republished a Siemens advisory for a critical authentication-bypass vulnerability in Industrial Edge Management, rated CVSS 9.1. The flaw allows unauthenticated attackers to force password resets without email verification, enabling account takeover. Organizations using affected systems are urged to apply mitigations immediately.

Expanded Detail

The republished advisory covers CVE-2026-18963, a flaw in the Keycloak reset-credentials flow affecting Industrial Edge Management Cloud, Pro, and Virtual deployments. Because the vulnerability bypasses email verification during password resets, attackers need no prior access to exploit it. Siemens has issued fixed releases and recommends blocking direct internet exposure or the affected reset path where patching cannot happen immediately.

The same CISA bulletin also highlights two additional Siemens vulnerabilities: an arbitrary-file-upload flaw in Siveillance Control that can grant root-level host access, and a Desigo CC client-code-execution issue that remains unfixed, with least-privilege authorization advised as the interim mitigation. These advisories underscore the breadth of exposure across Siemens' industrial product line.

Context

This flaw could affect operators of industrial facilities who rely on Siemens Edge Management for remote oversight, potentially allowing outsiders to seize control of administrative accounts. Disruptions to manufacturing, energy, or logistics operations may follow if credentials are compromised. Organizations without rapid patching capacity face the greatest exposure, and the lack of a fix for the related Desigo issue suggests some industrial environments may remain vulnerable for an extended period, raising concerns about supply-chain and critical-infrastructure resilience.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Viakoo, Inc →
Related stories
OT Security Update: Surge in Vulnerabilities Targets Industrial Control Systems · Cybersecurity
NIST Expands OT Security Guidance to Broader Critical Infrastructure · Cybersecurity
CISA Adds TeamCity Flaw to KEV as Ransomware Gangs Join Exploitation · Cybersecurity
Critical Infrastructure Vulnerabilities Dominate OT Security Update · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Daily OT Security News: September 23, 2026.” Browse more stories.