Back to signals
CISA advisoryVulnerabilitiesPublished September 22, 2026

Siemens WTV676 and WTV776

View CSAF Summary The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens WTV676 and WTV776 are affected: WTV676-HB6035 Web Interface vers:intdot/<3.94 (CVE-2026-89207) WTV776-HB6035 Web Interface vers:intdot/<4.17 (CVE-2026-89207) CVSS Vendor Equipment Vulnerabilities v3 6.5 Siemens Siemens WTV676 and WTV776 Improper Validation of Specified Type of Input Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-89207 Affected devices do not properly validate input received from backend services. This could allow an unauthenticated remote attacker to force the device into protection mode, which results in losing remote connectivity functions (Web Access). View CVE Details Affected Products Siemens WTV676 and WTV776 Vendor: Siemens Product Version: WTV676-HB6…

Open the source record
Tags
CISA
Related exam domains
CISM 2: Information Security Risk Management
Source record id
/node/25528
First seen by InfoSec Signals
9/23/2026

Exam domain labels come from a keyword heuristic and are study hints, not an official mapping. The summary is the publisher's own text, shortened; the linked record is authoritative.