Update Siemens License Server (SLS) to V5.1 or later for CVE-2026-69108 and V5.3 or later for CVE-2026-69109. Minimize network exposure, segment control system networks, and use VPNs for remote access. Follow Siemens operational guidelines for industrial security.
Quick answers
What is CVE-2026-69108?
Update Siemens License Server (SLS) to V5.1 or later for CVE-2026-69108 and V5.3 or later for CVE-2026-69109. Minimize network exposure, segment control system networks, and use VPNs for remote access. Follow Siemens operational guidelines for industrial security.
How severe is CVE-2026-69108?
high, CVSS 7.5
Is CVE-2026-69108 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-69108 be mitigated?
Update Siemens License Server (SLS) to V5.1 or later for CVE-2026-69108 and V5.3 or later for CVE-2026-69109. Minimize network exposure, segment control system networks, and use VPNs for remote access. Follow Siemens operational guidelines for industrial security.
CVSS
7.5
Vendor
Siemens
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Siemens License Server (SLS)
Mitigation
Update Siemens License Server (SLS) to V5.1 or later for CVE-2026-69108 and V5.3 or later for CVE-2026-69109. Minimize network exposure, segment control system networks, and use VPNs for remote access. Follow Siemens operational guidelines for industrial security.
Siemens has released updates for the Siemens License Server (SLS) to address two actively tracked vulnerabilities. CVE-2026-69108 is a local privilege escalation flaw stemming from an insecure sudoers policy that could allow an attacker to execute arbitrary commands as root. CVE-2026-69109 is a path traversal vulnerability that could enable a remote attacker to read arbitrary files on the system. Both flaws affect SLS versions prior to 5.1 and 5.3 respectively, and Siemens recommends immediate updating to the latest released versions.