Product lines listed as affected: 4 (Source: Siemens ProductCERT SSA-503852, republished by CISA ICSA-26-265-06 (2026-09-22))
An email check that can be skipped
Siemens Industrial Edge Management carries an authentication bypass, tracked as CVE-2026-18963. Siemens ProductCERT describes it in advisory SSA-503852, which CISA republished on September 22, 2026 as ICSA-26-265-06. A remote attacker with no account can abuse the password-reset function to take over any user's account. The email confirmation that should gate a reset is never completed. The attacker simply sets new credentials, and the advisory says this gives full control of the targeted account. CISA's notice names Critical Manufacturing as the affected sector.
The flaw is in the recovery path
Siemens attributes the defect to the credential-reset logic inside keycloak-services, a component of Red Hat Build of Keycloak that the advisory calls its "core engine" for identity and access management. The advisory files the flaw under CWE-640, a category covering weak forgotten-password recovery. Recovery exists for people who cannot log in, so it is a side entrance to the same account. If that entrance can be opened without proving control of the mailbox, an attacker has no need to defeat the login screen. For a budget-holder, the useful question is whether the recovery paths in your industrial and operational platforms are tested as thoroughly as the login pages.
Which deployments need action
For customer-run instances, the advisory lists Industrial Edge Management Pro V1 (1.14.9 up to but excluding 1.15.20), Pro V2 (2.2.0 up to but excluding 2.2.2) and Virtual (2.6.0 up to but excluding 2.9.1). The Cloud product is listed as affected in all versions. A separate entry gives two dates, August 26, 2026 for a firewall-rule mitigation and September 2, 2026 for an update, and says customers have nothing to do. The advisory does not name the product that entry covers. Do not read it as covering self-managed Pro or Virtual installs. Confirm its scope with Siemens.
The workarounds cost self-service reset
Siemens lists three interim measures. First, take the Pro or Virtual instance off direct internet exposure. Second, filter traffic at a web application firewall or reverse proxy so that requests to the reset-credentials endpoint (/auth/realms/customer/login-actions/reset-credentials) never reach the instance. Third, turn off the forgot-password option in the Keycloak realm's login settings. Siemens notes that the second and third leave password reset unavailable. That is an operational trade-off someone has to own. Until the update is installed, users who forget a password will need a manual route back in.
The advisory text does not report exploitation. CISA says the notice reproduces Siemens' advisory word for word and that it does not vouch for its editorial or technical accuracy. The general guidance is to keep control system devices off the internet and behind firewalls, isolated from business networks.
Questions to put to your team
1. Do we run IEM Pro V1, Pro V2 or Virtual, and which exact versions are deployed? 2. Is any instance reachable from the internet, and if so, why? 3. If we cannot update this week, which of Siemens' three measures are we applying, and who owns the reset-support gap? 4. If we use the Cloud product, has Siemens confirmed in writing what was mitigated and when? 5. The advisory names only Siemens IEM, but it describes the flaw in a component of Red Hat Build of Keycloak, so it is reasonable to ask any vendor that embeds Keycloak whether this flaw applies to its product. Have we asked the vendors we know embed it?
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: CISA.





