Ask Siemens Industrial Edge Management to reset a user's password and, on unpatched versions, it will let you set a new one without ever clicking the verification link it emails out. That is enough to take over any account on the platform, including an administrator's, and it needs no credentials to start.
The flaw is CVE-2026-18963, rated 9.1, and it is not really Siemens' own bug. It sits in the reset-credentials flow of keycloak-services, the identity engine from the Red Hat build of Keycloak that Industrial Edge Management embeds. CISA published the advisory on 22 September as one of six Siemens advisories issued the same day.
What an Edge Management account is worth
Industrial Edge Management is the console that pushes applications and configuration to edge devices on a plant floor, so an account on it is not a login to a reporting tool. Siemens lists Industrial Edge Management Cloud in all versions as affected, Pro V1 from 1.14.9 to below 1.15.20, Pro V2 from 2.2.0 to below 2.2.2, and Virtual from 2.6.0 to below 2.9.1.
Customers on the hosted version are already covered. Siemens states it mitigated the cloud instance with firewall rules on 26 August and fixed it with an update on 2 September, with no action required from users. Everyone running Pro or Virtual on their own infrastructure has to move themselves.
Block one URL path if you cannot patch today
Update to 1.15.20, 2.2.2 or 2.9.1 through the Siemens Industrial Edge hub. Where that has to wait, Siemens gives three interim options, in its own order of preference: cut direct internet access to the instance, which it calls the most effective immediate measure; or put a web application firewall or reverse proxy in front of it and block the path /auth/realms/customer/login-actions/reset-credentials; or turn password reset off inside Keycloak under realm settings, login, forgot password. The last two disable password resets for legitimate users as well, which is the trade being offered.
Five more Siemens advisories the same day
The rest of the batch, ordered by severity:
- Siveillance Control (CVE-2026-50093, 9.0): the Open Interface Services web module accepts arbitrary file uploads, which CISA says could give an attacker root on the OIS host and full compromise of that environment. Fixed in 3.0.12.2173, 3.0.22.2177, 4.0.9.2178 and 4.0.11.2177.
- SIMOVE Fleetmanager and SIPLANT (CVE-2026-67367, 8.6): a path traversal flaw allowing access to files outside the intended scope.
- Desigo CC family (CVE-2026-34223, 8.2): specially crafted graphics documents containing embedded scripts run on client application instances, which Siemens describes as client code execution. Michelin CERT reported this one to Siemens.
- SIPLUS and SIMATIC products (CVE-2026-31431, 7.8): the "Copy Fail" issue, classed as incorrect resource transfer between spheres. Siemens has shipped fixes for several affected products and is preparing more, with specific countermeasures recommended where no fix exists yet.
- WTV676 and WTV776 (CVE-2026-89207, 6.5): a denial of service that forces the devices into protection mode and disables their web access.
Siemens ProductCERT is named as the reporter on the Industrial Edge Management, Siveillance Control, SIMOVE and WTV676 advisories, with Desigo CC credited to Michelin CERT. None of the advisories reports known public exploitation.
The Industrial Edge Management entry is the one to act on first, and it is worth noting why: it is the only one in the batch where the vulnerable component came from somewhere else. A plant operator patching Siemens kit this week is, in that one case, patching Keycloak. Our coverage of AI-assisted probing of Siemens S7 controllers covers the other end of the same estate.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.