Apply vendor-supplied patches to update affected Siveillance Control products to the minimum patched versions (V3.0.12.2173 or later for Pro V3.0, V4.0.9.2178 or later for Pro V4.0, V3.0.22.2177 or later for V3.0, V4.0.11.2177 or later for V4.0). Minimize network exposure by isolating OIS web module devices behind firewalls and ensuring they are not accessible from the internet. When remote access is required, use VPNs updated to the most recent version. Follow Siemens ProductCERT advisory SSA-254516 for additional guidance.
Quick answers
What is CVE-2026-50093?
Apply vendor-supplied patches to update affected Siveillance Control products to the minimum patched versions (V3.0.12.2173 or later for Pro V3.0, V4.0.9.2178 or later for Pro V4.0, V3.0.22.2177 or later for V3.0, V4.0.11.2177 or later for V4.0). Minimize network exposure by isolating OIS web module devices behind firewalls and ensuring they are not accessible from the internet. When remote access is required, use VPNs updated to the most recent version. Follow Siemens ProductCERT advisory SSA-254516 for additional guidance.
How severe is CVE-2026-50093?
critical, CVSS 9
Is CVE-2026-50093 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-50093 be mitigated?
Apply vendor-supplied patches to update affected Siveillance Control products to the minimum patched versions (V3.0.12.2173 or later for Pro V3.0, V4.0.9.2178 or later for Pro V4.0, V3.0.22.2177 or later for V3.0, V4.0.11.2177 or later for V4.0). Minimize network exposure by isolating OIS web module devices behind firewalls and ensuring they are not accessible from the internet. When remote access is required, use VPNs updated to the most recent version. Follow Siemens ProductCERT advisory SSA-254516 for additional guidance.
CVSS
9
Vendor
Siemens
Published
Sep 30, 2026 · 08:42
Patch
Unknown / not confirmed
Affected products
Siveillance Control Pro V3.0 < V3.0.12.2173, Siveillance Control Pro V4.0 < V4.0.9.2178, Siveillance Control V3.0 < V3.0.22.2177, Siveillance Control V4.0 < V4.0.11.2177
Mitigation
Apply vendor-supplied patches to update affected Siveillance Control products to the minimum patched versions (V3.0.12.2173 or later for Pro V3.0, V4.0.9.2178 or later for Pro V4.0, V3.0.22.2177 or later for V3.0, V4.0.11.2177 or later for V4.0). Minimize network exposure by isolating OIS web module devices behind firewalls and ensuring they are not accessible from the internet. When remote access is required, use VPNs updated to the most recent version. Follow Siemens ProductCERT advisory SSA-254516 for additional guidance.
Siemens has identified a critical vulnerability in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro. Tracked as CVE-2026-50093, the flaw permits unrestricted file upload (CWE-434), enabling an attacker to upload arbitrary files and gain unauthorized root-level access on the OIS server. The vulnerability carries a CVSS v3.1 base score of 9.0 (CRITICAL). Affected versions include Siveillance Control Pro V3.0 before 3.0.12.2173, Siveillance Control Pro V4.0 before 4.0.9.2178, Siveillance Control V3.0 before 3.0.22.2177, and Siveillance Control V4.0 before 4.0.11.2177. Siemens has released vendor fixes and recommends updating to the latest patched versions. CISA has added the vulnerability to its ICS advisories and issued defensive guidance to minimize exploitation risk.