Update affected devices to the latest firmware versions: Desigo DXR2 and PXC3 to V01.21.233.16-7862 or later; Desigo PXC4, PXC5.E003, PXC5.E24, and PXC7 to V02.21.194.36-2715 or later. Additionally, restrict network access to BACnet devices, isolate control networks from business networks, and use firewalls or VPNs for remote access.
Quick answers
What is CVE-2026-59693?
Update affected devices to the latest firmware versions: Desigo DXR2 and PXC3 to V01.21.233.16-7862 or later; Desigo PXC4, PXC5.E003, PXC5.E24, and PXC7 to V02.21.194.36-2715 or later. Additionally, restrict network access to BACnet devices, isolate control networks from business networks, and use firewalls or VPNs for remote access.
How severe is CVE-2026-59693?
medium, CVSS 4.3
Is CVE-2026-59693 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-59693 be mitigated?
Update affected devices to the latest firmware versions: Desigo DXR2 and PXC3 to V01.21.233.16-7862 or later; Desigo PXC4, PXC5.E003, PXC5.E24, and PXC7 to V02.21.194.36-2715 or later. Additionally, restrict network access to BACnet devices, isolate control networks from business networks, and use firewalls or VPNs for remote access.
Update affected devices to the latest firmware versions: Desigo DXR2 and PXC3 to V01.21.233.16-7862 or later; Desigo PXC4, PXC5.E003, PXC5.E24, and PXC7 to V02.21.194.36-2715 or later. Additionally, restrict network access to BACnet devices, isolate control networks from business networks, and use firewalls or VPNs for remote access.
Siemens has disclosed a denial-of-service vulnerability (CVE-2026-59693) affecting multiple Desigo DXR and PXC building automation controllers. An attacker on the local network can send a malformed BACnet packet to cause the device to stop responding, requiring a reset or reboot to recover. Siemens has released firmware updates to address the issue.