Back to Feed
VulnerabilitiesMay 14, 2026

Siemens SIMATIC S7 PLC Web Server

Siemens SIMATIC S7 PLC web servers contain multiple XSS vulnerabilities requiring urgent patching.

Summary

Siemens disclosed three critical cross-site scripting (XSS) vulnerabilities (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) in SIMATIC S7 PLC web servers affecting dozens of CPU models and variants. The vulnerabilities allow authenticated attackers to inject malicious scripts via unsanitized PLC/station names, Technology Object names, and firmware filenames. Siemens has released patches for some products (v2.9.9 and v3.1.6) and recommends restricting TIA project download and firmware update access to trusted personnel pending further fixes.

Full text

ICS Advisory Siemens SIMATIC S7 PLC Web Server Release DateMay 14, 2026 Alert CodeICSA-26-134-15 Related topics: Industrial Control System Vulnerabilities, Industrial Control Systems View CSAF Summary SIMATIC S7 PLCs contain multiple vulnerabilities in the web server that could allow an attacker to perform cross-site scripting attacks. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIMATIC S7 PLC Web Server are affected: SIMATIC Drive Controller CPU 1504D TF (6ES7615-4DF10-0AB0) vers:intdot/<3.1.6 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC Drive Controller CPU 1507D TF (6ES7615-7DF10-0AB0) vers:intdot/<3.1.6 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SJ00-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SJ01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SK03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC ET 200SP CPU 1510SP-1 PN (6ES7510-1DJ00-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC ET 200SP CPU 1510SP-1 PN (6ES7510-1DJ01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC ET 200SP CPU 1510SP-1 PN (6ES7510-1DK03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC ET 200SP CPU 1512SP F-1 PN (6ES7512-1SK00-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC ET 200SP CPU 1512SP F-1 PN (6ES7512-1SK01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC ET 200SP CPU 1512SP F-1 PN (6ES7512-1SM03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC ET 200SP CPU 1512SP-1 PN (6ES7512-1DK00-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC ET 200SP CPU 1512SP-1 PN (6ES7512-1DK01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC ET 200SP CPU 1512SP-1 PN (6ES7512-1DM03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC ET 200SP CPU 1514SP F-2 PN (6ES7514-2SN03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC ET 200SP CPU 1514SP-2 PN (6ES7514-2DN03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC ET 200SP CPU 1514SPT F-2 PN (6ES7514-2WN03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC ET 200SP CPU 1514SPT-2 PN (6ES7514-2VN03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V2 CPUs vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V3 CPUs vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC ET 200SP Open Controller CPU 1515SP PC3 V4 CPUs vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK00-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK02-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AL03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK00-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CL03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK00-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK02-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FL03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1511T-1 PN (6ES7511-1TK01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1511T-1 PN (6ES7511-1TL03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1511TF-1 PN (6ES7511-1UK01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1511TF-1 PN (6ES7511-1UL03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK00-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CM03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL00-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL02-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AM03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL00-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL02-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FM03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1513pro F-2 PN (6ES7513-2GM03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1513pro-2 PN (6ES7513-2PM03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM00-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM02-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AN03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM00-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM02-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FN03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1515T-2 PN (6ES7515-2TM01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1515T-2 PN (6ES7515-2TN03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1515TF-2 PN (6ES7515-2UM01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1515TF-2 PN (6ES7515-2UN03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3A

Indicators of Compromise

  • cve — CVE-2026-25786
  • cve — CVE-2026-25787
  • cve — CVE-2026-25789

Entities

Siemens (vendor)SIMATIC S7 PLC Web Server (product)SIMATIC S7-1500 (product)SIMATIC ET 200SP (product)Programmable Logic Controller (PLC) (technology)