Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cve-2026-58115'

View all threats tagged with 'cve-2026-58115'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-58115

Threats Tagged 'cve-2026-58115'

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED… (CVE-2026-58115)CVE-2026-58115
0

A critical vulnerability exists in SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed, affecting all versions prior to V4.3.4.1. The issue arises because the Node-RED HTTP interface does not enforce authentication, allowing unauthenticated remote attackers to access programming nodes. This access enables attackers to create malicious flows that execute arbitrary system commands with maximum privileges on the underlying server.

Join the discussion
CVE-2026-58115: CWE-306: Missing Authentication for Critical Function in Siemens SIMATIC IoT2050 AdvancedCVE-2026-58115
0

A critical vulnerability in Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed (all versions prior to V4.3.4.1) allows unauthenticated remote attackers to access the Node-RED HTTP interface without authentication. This enables attackers to create malicious flows that execute arbitrary code on the underlying server with maximum privileges.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: cve-2026-58115
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses