[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-siemens-patches-critical-account-takeover-flaw-in-edge-tool":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},7217,"siemens-patches-critical-account-takeover-flaw-in-edge-tool","Siemens Patches Critical Account Takeover Flaw in Edge Tool","A critical bug in Siemens Industrial Edge Management let attackers reset passwords and hijack accounts without email verification; Siemens has patched it.","A critical bug in Siemens' Industrial Edge Management let anyone on the internet reset a user's password and take over their account, no verification required.\n\nSiemens disclosed CVE-2026-18963, a CVSS 9.1 authentication bypass affecting Industrial Edge Management Cloud (all versions) and Industrial Edge Management Pro V1 (builds from 1.14.9 through 2.6.0). The flaw lets an unauthenticated remote attacker complete a password reset without finishing email verification, handing over full control of an account. Siemens mitigated the Cloud service with firewall rules on August 26 and shipped a full fix on September 2. Pro V1 users need to update to version 1.15.20, 2.2.2, or 2.9.1, depending on which branch they run; until then, the only workaround is disabling password reset entirely under realm settings.\n\nIndustrial Edge Management sits at the center of Siemens' industrial IoT stack, overseeing edge devices on factory floors. A hijacked account here is not just a stolen login. It is a foothold into systems that manage physical industrial processes, which is exactly why the bug scores 9.1 out of 10. The underlying cause, tracked as CWE-640, is a weak password recovery mechanism, a fairly basic mistake for software managing critical infrastructure.\n\nTelling customers to just turn off password reset until they patch is a workaround, not a fix, and a reminder that convenience features in industrial software tend to get less scrutiny than the control systems they sit next to.","[\"siemens\",\"industrial-edge\",\"vulnerability\",\"ics-security\"]","2026-09-22T12:00:00.000Z","2026-09-22T16:37:33.163Z","2026-09-22T16:37:39.270Z","published",null,[],"security",[26,27,28,29],"siemens","industrial-edge","vulnerability","ics-security",[31],{"name":32,"url":33},"CISA Advisories","https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-advisories\u002Ficsa-26-265-06",0,{"sections":36},[37,42,46,51,56,61,66,70,75,80,85,90,95,100],{"name":38,"slug":39,"count":40,"latest_published_at":41},"AI","ai",4195,"2026-09-22T19:28:23.000Z",{"name":43,"slug":24,"count":44,"latest_published_at":45},"Security",702,"2026-09-22T21:01:05.000Z",{"name":47,"slug":48,"count":49,"latest_published_at":50},"Policy","policy",366,"2026-09-22T18:04:41.000Z",{"name":52,"slug":53,"count":54,"latest_published_at":55},"Deals","deals",200,"2026-09-22T19:28:55.000Z",{"name":57,"slug":58,"count":59,"latest_published_at":60},"Hardware","hardware",167,"2026-09-22T20:00:00.000Z",{"name":62,"slug":63,"count":64,"latest_published_at":65},"Science","science",131,"2026-09-22T16:26:30.000Z",{"name":67,"slug":68,"count":69,"latest_published_at":60},"Consumer Tech","consumer-tech",110,{"name":71,"slug":72,"count":73,"latest_published_at":74},"Software","software",79,"2026-09-22T19:44:31.000Z",{"name":76,"slug":77,"count":78,"latest_published_at":79},"Dev Tools","dev-tools",78,"2026-09-18T04:00:00.000Z",{"name":81,"slug":82,"count":83,"latest_published_at":84},"Startups","startups",63,"2026-09-22T21:24:11.000Z",{"name":86,"slug":87,"count":88,"latest_published_at":89},"Gaming","gaming",45,"2026-09-22T15:35:06.000Z",{"name":91,"slug":92,"count":93,"latest_published_at":94},"General","general",43,"2026-09-21T23:48:56.000Z",{"name":96,"slug":97,"count":98,"latest_published_at":99},"Reviews","reviews",27,"2026-09-22T13:00:00.000Z",{"name":101,"slug":102,"count":103,"latest_published_at":104},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]