Update SIMATIC IoT2050 Advanced to version 4.3.4.1 or later. Harden the Node-RED installation following the Node-RED User Guide, or uninstall Node-RED if not required. Minimize network exposure by isolating control system devices behind firewalls and ensuring they are not internet-accessible. Use VPNs for remote access and keep VPN software updated.
Quick answers
What is CVE-2026-58115?
Update SIMATIC IoT2050 Advanced to version 4.3.4.1 or later. Harden the Node-RED installation following the Node-RED User Guide, or uninstall Node-RED if not required. Minimize network exposure by isolating control system devices behind firewalls and ensuring they are not internet-accessible. Use VPNs for remote access and keep VPN software updated.
How severe is CVE-2026-58115?
critical, CVSS 10
Is CVE-2026-58115 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-58115 be mitigated?
Update SIMATIC IoT2050 Advanced to version 4.3.4.1 or later. Harden the Node-RED installation following the Node-RED User Guide, or uninstall Node-RED if not required. Minimize network exposure by isolating control system devices behind firewalls and ensuring they are not internet-accessible. Use VPNs for remote access and keep VPN software updated.
CVSS
10
Vendor
Siemens
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) < V4.3.4.1 running Industrial OS with Node-RED installed
Mitigation
Update SIMATIC IoT2050 Advanced to version 4.3.4.1 or later. Harden the Node-RED installation following the Node-RED User Guide, or uninstall Node-RED if not required. Minimize network exposure by isolating control system devices behind firewalls and ensuring they are not internet-accessible. Use VPNs for remote access and keep VPN software updated.
Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed are affected by a missing authentication vulnerability in the Node-RED HTTP interface (CVE-2026-58115). An unauthenticated remote attacker could exploit this weakness to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. The vulnerability carries a CVSS 3.1 base score of 10.0 (CRITICAL) with a vector of AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Siemens has released version 4.3.4.1 or later as a fix. CISA and Siemens advise minimizing network exposure and isolating control system devices.