Siemens RUGGEDCOM Devices Vulnerable to Fortinet-Originating Flaws
Siemens RUGGEDCOM APE1808 devices are affected by two critical vulnerabilities originating from Fortinet products, impacting industrial control systems worldwide.

Siemens has issued a security advisory detailing two vulnerabilities affecting its RUGGEDCOM APE1808 devices, which stem from underlying issues in Fortinet products. The vulnerabilities, identified as CVE-2026-23573 and CVE-2026-59839, impact all versions of the RUGGEDCOM APE1808.
CVE-2026-23573 is a cross-site scripting (XSS) vulnerability (CWE-79) found in specific versions of FortiOS, FortiPAM, and FortiProxy. This flaw could allow an authenticated remote user to execute code or commands through crafted requests. The CVSS v3 base score for this vulnerability is 6.1 (MEDIUM).
The second vulnerability, CVE-2026-59839, is a path traversal flaw (CWE-22) present in FortiOS, FortiPAM, FortiProxy, and FortiSwitch Manager. A privileged authenticated attacker with physical access could exploit this to delete files from the file system via crafted CLI commands. This vulnerability carries a CVSS v3 base score of 5.5 (MEDIUM).
While the vulnerabilities originate in Fortinet products, Siemens has confirmed their presence in its RUGGEDCOM APE1808 devices, which are utilized across critical infrastructure sectors including Critical Manufacturing, Energy, and Transportation Systems. These devices are deployed globally, raising concerns about the potential impact on industrial operations.
Siemens is advising customers to contact their customer support for detailed information on fixes. In the interim, users are directed to follow Fortinet's advisories for workarounds and mitigation measures. Siemens also emphasizes general security best practices, including protecting network access to devices, configuring environments according to their operational guidelines for Industrial Security, and following product manual recommendations.
CISA has also issued an alert, recommending defensive measures such as minimizing network exposure for all control system devices, ensuring they are not accessible from the internet, and locating them behind firewalls and isolated from business networks. Secure remote access methods like VPNs are also advised, with a reminder that VPNs themselves require up-to-date versions and secure connected devices.
This advisory highlights the complex supply chain of industrial control systems, where vulnerabilities in third-party components can have significant downstream effects. The widespread use of Siemens RUGGEDCOM devices in critical infrastructure underscores the importance of timely patching and robust security practices across the entire ecosystem.