Government Advisory

Siemens Building Controllers Vulnerable to Network-Based Disruption

CISA · 13 Aug 2026
Key Takeaway If your business uses Siemens Desigo controllers for building automation, update firmware to the latest version promptly to avoid potential service disruptions.

Siemens has disclosed a vulnerability affecting its Desigo DXR and PXC controllers, which are commonly used to manage building automation systems such as heating, ventilation, and access control. The flaw, tracked as CVE-2026-59693, allows an attacker to send malformed BACnet network packets to the device, potentially causing it to stop working. Restoring normal operation requires a manual reset or reboot of the affected controller.

While the vulnerability has a moderate severity rating (CVSS 4.3), any disruption to building management systems can have real operational impact, especially for businesses relying on these controllers for climate control, security, or safety systems. Several product lines are affected, including Desigo DXR2, PXC3, PXC4, PXC5, and PXC7, across various firmware versions.

Siemens has released updated firmware that resolves the issue and is urging all customers using the affected controllers to update as soon as possible. Businesses that operate building management systems, particularly those in commercial property, healthcare, and facilities management, should check whether their infrastructure includes any of the listed models.

ICS Security Siemens Building Automation Vulnerability Management BACnet

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.