CISA

Siemens Industrial Edge Management

From Cybersecurity and Infrastructure Security Agency ↗

Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification. Siemens has released new versions for the affected products and recommends to update to the latest versions.

The following versions of Siemens Industrial Edge Management are affected:

Industrial Edge Management Cloud vers:all/* (CVE-2026-18963)

Industrial Edge Management Pro V1 vers:intdot/>=1.14.9|=2.2.0|=2.6.0|= V1.14.9 < V1.15.20, Industrial Edge Management Pro V2 >= V2.2.0 < V2.2.2, Industrial Edge Management Virtual >= V2.6.0 < V2.9.1

MitigationBlock direct internet access to IEM Pro / IEM Virtual The most effective immed...