CISA republished Siemens ProductCERT advisory SSA-127084 on August 12, following Siemens’ August 11 publication. The advisory ties every RUGGEDCOM APE1808 version to a cross-site scripting issue and a path traversal issue inherited from Fortinet software. Siemens does not provide an APE1808 image number, a direct download, or a product-specific fixed version; it instead tells customers to contact support and apply Fortinet’s upstream mitigation guidance.
That omission matters in an OT environment. The RUGGEDCOM APE1808 is an application-hosting module used in RX1500 industrial networking equipment, rather than a single-purpose FortiGate appliance. Siemens’ own previous APE1808 advisories describe the affected deployment explicitly as an APE1808 with Fortinet NGFW. An APE1808 running its standard Windows 10 Enterprise 2019 LTSC or Debian image, but without that Fortinet virtual firewall installation, is not shown in Fortinet’s affected-product lists for these CVEs.
Two Fortinet flaws, very different access assumptions
CVE-2026-23573 is a cross-site scripting vulnerability in FortiOS. Fortinet’s CVSS 3.1 score is 6.1, with a network attack vector, no required attacker privileges, and required user interaction. In practical terms, a user with access to a vulnerable FortiOS web interface could be lured into processing a crafted request; the risk is therefore tied to who can reach the management UI and whose browser session can be targeted.
The affected FortiOS scope reported in the NVD includes FortiOS 7.6.0 through 7.6.6, plus all versions in the 7.4 and 7.2 branches. Fortinet also lists affected FortiPAM and FortiProxy versions, but those products are outside Siemens’ APE1808 advisory scope. The important point for Siemens operators is that the issue is attached to the Fortinet firewall workload, not to Windows, Debian, the RX1500 switching software, or the APE1808’s hardware firmware.
CVE-2026-59839 is a path traversal flaw. Fortinet rates it 5.5 under CVSS 3.1 and describes a local attack vector requiring high privileges. The NVD record is unusually incomplete in one respect: its description still contains a placeholder where the attack vector should have been specified. That is a documentation defect, not evidence that the flaw is harmless. The CVSS vector and Fortinet’s advisory identifier indicate the weakness concerns a CLI command; third-party scanner coverage describes the likely consequence as deletion of root filesystem files by an already privileged user.
For an APE1808 deployment, that makes CVE-2026-59839 primarily a post-access and operational-resilience problem. It does not give an unauthenticated internet attacker a direct route into an industrial firewall. But an attacker or insider who has already obtained a sufficiently privileged FortiOS administrative session may be able to damage the firewall’s underlying file system, turning an administrative compromise into a denial-of-service or recovery event.
“All versions” does not mean every APE1808 configuration
CISA’s CSAF-derived presentation lists “RUGGEDCOM APE1808 vers:all/*” against both CVEs. Siemens also added the APE1808 as an affected product in the CVE records on August 11. That product-level statement is real and should drive asset discovery, but it is not a usable patch determination by itself.
The upstream Fortinet version ranges are more specific:
- CVE-2026-23573 affects FortiOS 7.6.0 through 7.6.6 and the 7.4 and 7.2 branches identified by Fortinet.
- CVE-2026-59839 affects FortiOS 6.4, 7.0, and 7.2 branches, FortiOS 7.4.0 through 7.4.9, and FortiOS 7.6.0 through 7.6.6.
- NVD’s version mapping identifies FortiOS 7.4.10 and 7.6.7 as outside the affected range for CVE-2026-59839. It similarly maps CVE-2026-23573 as fixed after FortiOS 7.6.6, while the upstream wording retains broad 7.4 and 7.2 branch exposure.
This is the central operational problem with Siemens’ notice: customers receive neither the Fortinet NGFW version bundled on their APE1808 nor a Siemens-supported upgrade target. Earlier Siemens advisories did publish appliance-specific guidance such as updating FortiGate NGFW on APE1808 systems to version 7.4.10 or 7.4.11 through Siemens support. SSA-127084 does not do so. Administrators should therefore resist the temptation to install a generic FortiOS image onto an industrial appliance module without Siemens’ support path and compatibility confirmation.
A Windows administrator managing the APE1808 host should also avoid conflating this alert with a Windows patching issue. Siemens documentation says APE1808 modules can run Windows 10 Enterprise 2019 LTSC or Debian Linux and can host other applications. Microsoft updates remain necessary for the host operating system, but neither CVE in this notice is a Windows vulnerability, and Windows Update will not remediate FortiOS running as the embedded NGFW workload.
The exposure that deserves attention first
CISA’s risk guidance—limit network exposure, isolate control-system networks from business networks, place remote devices behind firewalls, and use secured remote-access channels—is broad but appropriate here. The more concrete priority is to review management-plane exposure on each affected Fortinet NGFW instance.
For CVE-2026-23573, inspect whether the FortiOS administrative web interface is reachable from user workstations, jump hosts, vendor remote-access networks, or any internet-published address. A cross-site scripting flaw becomes more consequential when a browser-based administrator routinely accesses the same UI from an endpoint exposed to email, general web browsing, or less trusted network segments. Restricting management access to a dedicated administration network and hardened jump hosts reduces the opportunity for a crafted request to reach a privileged session.
For CVE-2026-59839, review who holds high-privilege FortiOS administrative and CLI access, how those accounts authenticate, and whether sessions are individually attributable. The CVSS vector says high privileges are required, so this is not a reason to take an industrial firewall offline preemptively. It is a reason to eliminate shared administrator accounts, remove stale vendor credentials, enforce MFA where supported, and confirm that configuration backups and appliance recovery procedures work before a file-system-impacting incident makes them urgently necessary.
CISA’s SSVC entries for both CVEs, created on July 14, assessed exploitation as “none,” automation as “no,” and technical impact as “partial.” Those entries should not be read as a guarantee that exploitation will not emerge; they establish that CISA had not recorded known exploitation at the time of its assessment. The access requirements and medium severity make this an urgent maintenance and segmentation task, rather than evidence of an internet-scale emergency.
What APE1808 owners should do now
Start with an inventory that separates hardware from hosted workloads. The relevant question is not simply whether the site owns RUGGEDCOM APE1808 modules, but whether those modules host the Siemens-supported Fortinet NGFW configuration and which FortiOS build is running.
Then take the following actions:
- Confirm every APE1808-hosted Fortinet NGFW version and compare it with Fortinet’s affected ranges for both CVE-2026-23573 and CVE-2026-59839.
- Contact Siemens ProductCERT or Siemens customer support for the supported APE1808 remediation image or upgrade procedure, because SSA-127084 does not name one.
- Remove direct internet exposure from FortiOS administration interfaces and restrict HTTPS and CLI management to dedicated administrative paths.
- Review privileged FortiOS accounts, revoke unnecessary access, rotate shared or vendor-maintenance credentials, and ensure administrative actions are logged.
- Verify an offline or otherwise protected configuration backup and a tested recovery procedure before upgrading or making access-control changes in a production OT segment.
- Keep the Windows 10 Enterprise 2019 LTSC or Debian host patched independently, but do not mistake host operating-system updates for a FortiOS fix.
The practical consequence of this advisory is not that every industrial APE1808 module must be replaced or immediately shut down. It is that any APE1808 running Fortinet NGFW needs a supported FortiOS remediation plan, and Siemens has left customers to obtain that plan through support rather than publishing it in SSA-127084.