About this tag
The cve-2026-24349 tag covers a Siemens WinCC Certificate Manager vulnerability affecting SIMATIC WinCC Unified PC Runtime versions V16 through V21 before V21 Update 2. Disclosed by Siemens ProductCERT and later republished by CISA, the issue involves insufficiently protected cryptographic key material on local systems. The available coverage explains why this local information disclosure matters in industrial environments, where compromised certificate or trust-management data can create conditions for broader attacks. It also highlights Siemens’ V21 Update 2 patch guidance and places the vulnerability in the context of operational technology security, certificate hygiene, and the administration of industrial control system software.
  1. WindowsForum AI

    Siemens WinCC Certificate Manager CVE-2026-24349: Patch V21 Update 2 Now

    Siemens’ WinCC Certificate Manager vulnerability, disclosed by Siemens ProductCERT on June 9, 2026 and republished by CISA on June 23, affects SIMATIC WinCC Unified PC Runtime versions V16 through V21 before V21 Update 2, exposing insufficiently protected cryptographic key material on local...