CVE-2026-27662
View CSAF Summary SIMATIC HMI Unified Comfort Panels before V21.0 are affected by a vulnerability that allows an unauthenticated attacker to access the web browser via the help link. This vulnerabi...
Affects 0 products across 2 vendors.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
The vulnerability in Siemens SIMATIC HMI Unified Comfort Panels prior to V21.0 allows an unauthenticated attacker to access the web browser through the Control Panel, potentially leading to misconfigurations and backdoor discovery. Siemens has released updated versions to mitigate this issue.
BSID: BS-2026-GLOBAL-076338-H • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-27662?
What is the CVSS score for CVE-2026-27662?
Is CVE-2026-27662 actively exploited?
How do I remediate CVE-2026-27662?
What systems are affected by CVE-2026-27662?
What NERC-CIP standard applies to CVE-2026-27662?
What IEC 62443 requirement maps to CVE-2026-27662?
| CVE ID | CVE-2026-27662 |
|---|---|
| BSID | BS-2026-GLOBAL-076338-H BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
| Published | 2026-05-14 |
| Last Modified | 2026-05-14 |
| ICS Relevance | 65% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
View CSAF Summary SIMATIC HMI Unified Comfort Panels before V21.0 are affected by a vulnerability that allows an unauthenticated attacker to access the web browser via the help link. This vulnerability allows an attacker to access the web browser through the Control Panel if it is not protected by the corresponding security mechanisms. This opens the possibility for the attacker to find backdoors, which might lead to unwanted misconfigurations. Siemens has released new versions for the affected
Source: NIST NVD / MITRE CVE Database
An unauthenticated attacker can exploit this vulnerability by accessing the web browser via the help link on the Control Panel. This can lead to the discovery of backdoors and potential misconfigurations, compromising the integrity and availability of the system.
Exploitation Likelihood: LOW
| Vendor | Product | Fixed Version |
|---|---|---|
| Fujitsu-Siemens | — | — |
| Siemens | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement network segmentation to isolate the affected HMI panels from the general network, and apply strict access controls to the Control Panel.
This vulnerability could allow unauthorized access to the control system, violating the requirement for securing electronic access to BES Cyber Systems.
This vulnerability impacts the secure access to the control system, which is a critical aspect of the security requirements for industrial automation and control systems.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | f58098dc5c71849edb9dfc224156b3b72850b1f43cdb201b717800c4dded79667149cce869b3fd254c5d606c514e44d8b84525a1edc47a03c2b4fea888c6e54f |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →