Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cve-2026-34223'

View all threats tagged with 'cve-2026-34223'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-34223

Threats Tagged 'cve-2026-34223'

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family… (CVE-2026-34223)CVE-2026-34223
0

A high-severity vulnerability (CVE-2026-34223) affects all versions of multiple Desigo CC client applications, including ClickOnce Client V6 and V7, family V8 and V9, Flex Client V6 and V7, and Installed Client V6 and V7. The flaw allows client code execution due to insufficient input validation of scripts embedded in user-defined graphics documents. An attacker who crafts a malicious graphics document and convinces a user with sufficient privileges to open it can execute arbitrary commands on the client system, potentially writing files and enabling system compromise and lateral movement.

Join the discussion
CVE-2026-34223: CWE-94: Improper Control of Generation of Code ('Code Injection') in Siemens Desigo CC ClickOnce Client V6CVE-2026-34223
0

A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All versions), Desigo CC Flex Client V7 (All versions), Desigo CC Installed Client V6 (All versions), Desigo CC Installed Client V7 (All versions). The affected application is vulnerable to Client Code Execution (CCE) due to insufficient input validation when handling scripts embedded within user-defined graphics documents. Specifically, when the script within a graphics document is designed or modified by an attacker to include malicious commands. When a user opens a compromised graphics document, the embedded script is executed on the client application instance, allowing an attacker to write arbitrary files to the client's operating system. Successful exploitation requires an attacker to craft a malicious graphics document and entice a user with sufficient privileges to display it. This could lead to compromise of the client operating system and potential lateral movement within the organization.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: cve-2026-34223
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses