Government Advisory

Critical Flaw Found in Siemens Video Management Software—Update Now

CISA · 13 Aug 2026
Key Takeaway If your business uses Siemens Siveillance Video systems, update to the latest patched version immediately or confirm with your IT provider that this has been done.

Siemens has disclosed a serious security flaw in its Siveillance Video Management servers, software widely used to manage surveillance and security camera systems across critical infrastructure sectors including manufacturing, communications, and commercial facilities. The vulnerability, tracked as CVE-2026-3014, stems from an OS command injection issue and carries a high severity score of 9.1 out of 10, meaning it could allow an attacker to remotely execute malicious commands on affected systems.

The flaw affects several product versions: Siveillance Video V2023 R3 (before 23.3.27), V2024 R1 (before 24.1.16), and V2025 (before 25.1.15). Siemens has already released updated versions to address the issue and strongly recommends all users upgrade immediately. This type of vulnerability is particularly concerning because video management systems often control physical security infrastructure, and a successful attack could give bad actors deep access into an organisation's network or physical security operations.

While this vulnerability primarily affects larger organisations and critical infrastructure operators, small and medium businesses using Siemens security camera or video management systems—whether directly or through a managed security provider—should check whether they are running an affected version. Businesses relying on third-party installers for their surveillance systems should contact their provider to confirm patch status.

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.