# Siemens vulnerabilities & exploitation

**CISA KEV** · **Ransomware**

> As of 2026-10-05, Threadlinqs tracks 6 Siemens CVEs, 3 in the CISA Known Exploited Vulnerabilities catalog, 1 used in ransomware campaigns, linked to 28 tracked threat campaigns and 12 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 6 Siemens CVEs published between 2020-09-15 and 2026-05-15. The busiest month was 2026-05 (2 new CVEs). 3 of them (50%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 6 of 6 tracked Siemens CVEs.

- [CVE-2023-44487](https://intel.threadlinqs.com/cve/CVE-2023-44487) — HIGH 7.5 · KEV · EPSS 100% · 2023-10-10
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228) — CRITICAL 10 · KEV · Ransomware · EPSS 94.4% · 2021-12-10
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034) — HIGH 7.8 · KEV · EPSS 87.8% · 2022-01-28
- [CVE-2025-40947](https://intel.threadlinqs.com/cve/CVE-2025-40947) — HIGH 7.5 · EPSS 0.4% · 2026-05-12
- [CVE-2025-40948](https://intel.threadlinqs.com/cve/CVE-2025-40948) — MEDIUM 6.8 · EPSS 0.3% · 2026-05-12
- [CVE-2020-15791](https://intel.threadlinqs.com/cve/CVE-2020-15791) — MEDIUM 6.5 · EPSS 0.1% · 2020-09-09

## Products affected

Threadlinqs normalises CPE and CNA product records across all 6 CVEs; 100 distinct Siemens products are affected. The most frequently affected (top 20):

- RUGGEDCOM ROX MX5000 — 2 CVEs
- RUGGEDCOM ROX MX5000RE — 2 CVEs
- RUGGEDCOM ROX RX1400 — 2 CVEs
- RUGGEDCOM ROX RX1500 — 2 CVEs
- RUGGEDCOM ROX RX1501 — 2 CVEs
- RUGGEDCOM ROX RX1510 — 2 CVEs
- RUGGEDCOM ROX RX1511 — 2 CVEs
- RUGGEDCOM ROX RX1512 — 2 CVEs
- RUGGEDCOM ROX RX1524 — 2 CVEs
- RUGGEDCOM ROX RX1536 — 2 CVEs
- RUGGEDCOM ROX RX5000 — 2 CVEs
- 6bk1602-0aa12-0tp0 — 1 CVE
- 6bk1602-0aa12-0tp0 Firmware — 1 CVE
- 6bk1602-0aa22-0tp0 — 1 CVE
- 6bk1602-0aa22-0tp0 Firmware — 1 CVE
- 6bk1602-0aa32-0tp0 — 1 CVE
- 6bk1602-0aa32-0tp0 Firmware — 1 CVE
- 6bk1602-0aa42-0tp0 — 1 CVE
- 6bk1602-0aa42-0tp0 Firmware — 1 CVE
- 6bk1602-0aa52-0tp0 — 1 CVE

## Threat activity

28 tracked threat campaigns reference Siemens products or exploit Siemens CVEs; the 25 most recent are listed.

- [CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables SNAT Privilege Escalation, and AF_ALG Race Condition (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964)](https://intel.threadlinqs.com/threat/TL-2026-2582) — CRITICAL — 2026-09-19
- [CVE-2025-39682 — Linux Kernel net/tls rx_list Zero-Length Record Use-After-Free Added to CISA KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2570) — CRITICAL — 2026-09-18
- [Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)](https://intel.threadlinqs.com/threat/TL-2026-2514) — HIGH — 2026-09-15
- [Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)](https://intel.threadlinqs.com/threat/TL-2026-2486) — CRITICAL — 2026-09-13
- [Multiple Vulnerabilities in Nozomi Guardian/CMC Before 25.4.0 on Siemens RUGGEDCOM APE1808 Devices (CVE-2024-13089, CVE-2024-13090, CVE-2025-3719, CVE-2025-40889, et al.)](https://intel.threadlinqs.com/threat/TL-2026-2487) — HIGH — 2026-09-13
- [Multiple Fortinet FortiOS Vulnerabilities (incl. CVE-2024-23113) Affect Siemens RUGGEDCOM APE1808 via Bundled Fortinet NGFW < V7.4.3 (SSA-832273)](https://intel.threadlinqs.com/threat/TL-2026-2489) — CRITICAL — 2026-09-13
- [DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec References](https://intel.threadlinqs.com/threat/TL-2026-2364) — CRITICAL — 2026-09-06
- [Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-2325) — HIGH — 2026-09-04
- [ORB Networks and Nation-State CNI Targeting: Destructive Wiper Attack on Polish Energy Infrastructure via Exposed FortiGate Devices](https://intel.threadlinqs.com/threat/TL-2026-2317) — HIGH — 2026-09-03
- [EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign Adopted by Criminal, North Korean, and Iran-Linked Actors](https://intel.threadlinqs.com/threat/TL-2026-2273) — HIGH — 2026-09-01
- [LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)](https://intel.threadlinqs.com/threat/TL-2026-2094) — HIGH — 2026-08-21
- [AI-Generated Exploit Scripts Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-2093) — HIGH — 2026-08-20
- [AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-2076) — CRITICAL — 2026-08-19
- [Rapid7 Q2 2026 Threat Landscape Report: Vulnerability Disclosures Double, AI-Assisted Exploitation Compresses Patch Timelines](https://intel.threadlinqs.com/threat/TL-2026-2058) — HIGH — 2026-08-18
- [Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic manipulation bypasses pump safeguards](https://intel.threadlinqs.com/threat/TL-2026-1882) — HIGH — 2026-08-04
- [CVE-2026-31431: Linux Local Privilege Escalation Actively Exploited by UMBRAL BISON Within 24 Hours of Disclosure](https://intel.threadlinqs.com/threat/TL-2026-1831) — HIGH — 2026-08-03
- [Iran-Linked CyberAv3ngers (BAUXITE) Exploiting Internet-Exposed Rockwell, Schneider Electric, and Siemens PLCs Across US Water, Energy, and Government Infrastructure (CISA AA26-097A)](https://intel.threadlinqs.com/threat/TL-2026-1697) — CRITICAL — 2026-07-25
- [ThreatsDay Bulletin: Iran-Linked CyberAv3ngers PLC Intrusion Campaign (AA26-097A) and OctagonPanel/Ward RAT 'BH Alert' Android Spyware Targeting Bahrain](https://intel.threadlinqs.com/threat/TL-2026-1659) — HIGH — 2026-07-23
- [Siemens Ruggedcom ROX II Three-Stage Zero-Day Exploit Chain (CVE-2025-40948, CVE-2025-40947, CVE-2025-40949)](https://intel.threadlinqs.com/threat/TL-2026-1442) — CRITICAL — 2026-07-17
- [XZ Utils Multithreaded Decoder Race Condition (CVE-2025-31115) - B&R & Siemens ICS Impact](https://intel.threadlinqs.com/threat/TL-2026-1001) — HIGH — 2026-06-30
- [Aquatic Panda (Earth Lusca) APT - Log4Shell Exploitation and Multi-Platform Backdoor Campaigns Targeting 17 Countries](https://intel.threadlinqs.com/threat/TL-2026-0986) — CRITICAL — 2026-06-28
- [PCPJack Covert SMTP Relay Network — 230 Hijacked AWS/Google Cloud/Azure Servers via Sliver C2 + Chisel SOCKS Tunneling](https://intel.threadlinqs.com/threat/TL-2026-0701) — HIGH — 2026-06-07
- [SHADOW-AETHER-040 & SHADOW-AETHER-064 — Agentic AI-Driven Intrusion Campaigns Targeting LATAM Government and Financial Sectors (Vibe Hacking)](https://intel.threadlinqs.com/threat/TL-2026-0498) — CRITICAL — 2026-05-12
- [ZionSiphon — Ideologically Motivated .NET OT Malware Targeting Israeli Water & Desalination Infrastructure (Mekorot, Sorek, Hadera, Ashdod, Palmachim, Shafdan)](https://intel.threadlinqs.com/threat/TL-2026-0458) — CRITICAL — 2026-05-05
- [APT41/Silver Dragon Expanding Enterprise Attack Surface — Google Drive C2, AppDomain Hijacking, Cloud/Supply Chain Targeting](https://intel.threadlinqs.com/threat/TL-2026-0292) — HIGH — 2026-03-27

## Threat actors targeting Siemens

Named threat actors attributed to campaigns that involve Siemens products or CVEs, with the number of linked campaigns:

- [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers) — 5 campaigns
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1 campaign
- [APT33](https://intel.threadlinqs.com/actor/APT33) — 1 campaign
- [APT34](https://intel.threadlinqs.com/actor/APT34) — 1 campaign
- [APT35](https://intel.threadlinqs.com/actor/APT35) — 1 campaign
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 1 campaign
- [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) — 1 campaign
- [Earth Lusca](https://intel.threadlinqs.com/actor/Earth%20Lusca) — 1 campaign
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 1 campaign
- [Handala Hack Team](https://intel.threadlinqs.com/actor/Handala%20Hack%20Team) — 1 campaign
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 1 campaign
- [PCPJack](https://intel.threadlinqs.com/actor/PCPJack) — 1 campaign

## How to prioritise Siemens patching

This order follows the data Threadlinqs holds for Siemens, not a generic severity checklist:

- 3 of 6 Siemens CVEs (50%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2023-44487](https://intel.threadlinqs.com/cve/CVE-2023-44487), [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228), [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034).
- 1 CVE is known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are [CVE-2025-40947](https://intel.threadlinqs.com/cve/CVE-2025-40947) (0.4%), [CVE-2025-40948](https://intel.threadlinqs.com/cve/CVE-2025-40948) (0.3%), [CVE-2020-15791](https://intel.threadlinqs.com/cve/CVE-2020-15791) (0.1%).
- 1 CVE scores Critical and 3 High on CVSS v3 (maximum 10, average 7.7); sequence these after KEV and high-EPSS items.
- 1 CVE has a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/siemens
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
