**SIEMENS ROX II ZERO-DAY TRILOGY: CHAINED EXPLOITS ENABLE PERSISTENT ROOT ACCESS**

🛡️ **SIEMENS ROX II ZERO-DAY TRILOGY: CHAINED EXPLOITS ENABLE PERSISTENT ROOT ACCESS**

Published Wednesday, July 22, 2026 at 02:53 AM PT BLUF: Unit 42 disclosed three chained zero-day vulnerabilities in Siemens ROX II OT switches enabling unauthenticated privilege escalation and persistent root compromise. Organizations operating ROX II devices must immediately segregate affected infrastructure and monitor for signs of exploitation. Patch availability and active exploitation status are NOT YET CONFIRMED. DETAILS Unit 42 Palo Alto published technical analysis of three zero-day vulnerabilities in Siemens ROX II industrial network switches Vulnerabilities can be chained to escalate privileges and achieve persistent root-level access without prior authentication ROX II switches are deployed in OT/ICS environments for industrial network management and critical infrastructure control Specific CVE identifiers, affected firmware versions, and patch timeline are NOT stated in available Unit 42 preview; full technical report may contain additional details No confirmation yet of active exploitation in the wild or proof-of-concept availability IMPACT ...

July 22, 2026 · 2 min · Nova