CISA ICS Advisory: Siemens Mendix Runtime (Update A)
Here’s what this advisory affects, and what to do about it.
This advisory is revoked. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute. The following versions of Siemens Mendix Runtime are affected: Siemens Mendix Runtime vers:all/* (CVE-2026-7891)
Reported vulnerability disproven
On September 24, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) published and then immediately revoked an Industrial Control Systems (ICS) advisory concerning Siemens Mendix Runtime. After re-investigation, CISA confirmed that the reported behavior is an expected platform configuration and does not expose the protected attribute.
Watch this company
Get alerted the next time this company files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about this company’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
- Every indexed leak tied to your address — all of them, named and dated
- A deeper search of collected breach data — the kinds of your information it holds, where it finds you
- What this kind of incident typically exposes
- A ten-minute lock list written for this kind of organisation
Affected products
The original advisory had listed Siemens Mendix Runtime vers:all/* (CVE-2026-7891) as affected. Because the advisory has been revoked, no versions of the product are considered vulnerable under the reported issue.
What to do
- Disregard the original ICSA-26-209-02 advisory as it has been formally revoked by CISA.
- Confirm with Siemens whether any separate security guidance has been issued for Mendix Runtime.
- Continue following standard patching and configuration hardening practices for industrial and low-code runtime environments.
- Monitor both the CISA ICS advisories page and Siemens’ official security channel for any future updates on this CVE.
Revocations of this kind demonstrate the value of coordinated disclosure and post-publication validation in ICS environments where false positives can create unnecessary operational burden.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
CISA ICS Advisory: Eufy Omni C20, Omni X10 Pro
Successful exploitation of these vulnerabilities could allow an attacker to run system level command…
Gallagher Transport International Inc. Data Breach Notice (Vermont Attorney General)
Gallagher Transport International Inc. notified Vermont residents of a data breach in a filing repor…
Harbor Fish Market Data Breach Notice (Vermont Attorney General)
Harbor Fish Market notified Vermont residents of a data breach in a filing reported to the Vermont A…