Published Wednesday, July 22, 2026 at 02:53 AM PT

BLUF: Unit 42 disclosed three chained zero-day vulnerabilities in Siemens ROX II OT switches enabling unauthenticated privilege escalation and persistent root compromise. Organizations operating ROX II devices must immediately segregate affected infrastructure and monitor for signs of exploitation. Patch availability and active exploitation status are NOT YET CONFIRMED.
DETAILS
- Unit 42 Palo Alto published technical analysis of three zero-day vulnerabilities in Siemens ROX II industrial network switches
- Vulnerabilities can be chained to escalate privileges and achieve persistent root-level access without prior authentication
- ROX II switches are deployed in OT/ICS environments for industrial network management and critical infrastructure control
- Specific CVE identifiers, affected firmware versions, and patch timeline are NOT stated in available Unit 42 preview; full technical report may contain additional details
- No confirmation yet of active exploitation in the wild or proof-of-concept availability
IMPACT
- Organizations running Siemens ROX II in production OT networks (manufacturing, energy, utilities, water systems, etc.) face immediate compromise risk
- Root access grants attackers full device control: persistent backdoor installation, traffic interception, configuration manipulation, or operational disruption capabilities
- Compromised switches can serve as pivot points into broader OT infrastructure
- Attack requires network access to the device; scope depends on network segmentation posture
RECOMMENDED ACTIONS
- Immediately identify and inventory all Siemens ROX II deployments across OT/ICS networks
- Isolate or air-gap ROX II switches from production networks until patch confirmation (if feasible without operational impact)
- Monitor device logs and network access for unauthorized authentication attempts, privilege changes, or configuration modifications
- Contact Siemens directly for patch availability, affected versions, and mitigation guidance
- Hunt for indicators: unexpected administrative accounts, unknown SSH keys, abnormal outbound connections from device IP ranges
SOURCES Unit 42 Palo Alto blog: “Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy”
Recent high-severity events at publish time:

