The short version.
On September 15, 2026, CISA published ICSA-26-258-05 for Siemens Reyrolle 7SR5 protection relays. It republishes Siemens advisory SSA-142885, first published on September 8. It covers 14 CVEs in every version before V2.70.
The most severe is CVE-2026-62645, CVSS v3.1 9.8. The relay's web interface exposes information that lets an attacker calculate current and past session IDs. With a valid session ID, the attacker skips the login. Other flaws let an attacker with no login crash the web server. The fix is firmware V2.70 or later.
Relay firmware needs bench testing and an outage plan. Most fleets will not be patched this month. Until they are, the job is to control who can reach the relay's web interface. Neither advisory mentions known exploitation.
Why a protection relay matters.
A protection relay watches current and voltage on a line, feeder or transformer. When it sees a fault, it trips the breaker. That clears a short circuit before it damages equipment or spreads across the network.
The relay's settings decide when it trips. Bad settings can open a breaker for no reason and drop customers. They can also leave a breaker closed during a fault. That makes the relay's management interface one of the most sensitive logins in a substation.
Siemens adds one line for power systems. It recommends "multi-level redundant secondary protection schemes" for critical systems. In plain terms, no single relay should be the only thing between a fault and an outage.
What the advisory says.
- Product: Siemens Reyrolle 7SR5, all versions before V2.70.
- Fix: V2.70 or later, from the Siemens support portal.
- Sector: Energy, deployed worldwide.
- Known exploitation: not mentioned by CISA or Siemens.
| CVE | CVSS v3.1 | What it allows, per Siemens | Access needed |
|---|---|---|---|
| CVE-2026-62645 | 9.8 | Web interface leaks data used to calculate current and past session IDs | Network, no login |
| CVE-2026-62646 | 7.4 | Session IDs with too little entropy, open to prediction or brute force | Network, no login, high complexity |
| CVE-2026-62647 | 7.4 | Badly initialized random number generator for security tokens | Network, no login, high complexity |
| CVE-2026-62650 | 8.8 | Role-based access control bypass, privilege escalation to admin | Network, low-privilege login |
| CVE-2026-62648 | 7.5 | Unchecked URL length, out-of-bounds write, device crash | Network, no login |
| CVE-2026-62649 | 7.5 | Web server runs out of resources under many requests | Network, no login |
| CVE-2024-42384 | 7.5 | Integer overflow in the Mongoose web server, crash | Network, no login |
| CVE-2024-42386 | 8.2 | Out-of-range pointer offset in TLS processing | Network, no login |
| CVE-2024-42385 | 4.0 | Delimiter flaw leading to out-of-bounds write | Local, high privileges |
| CVE-2024-42391 | 4.3 | Pointer offset flaw exposing heap memory | Network, user interaction |
| CVE-2024-42392 | 4.0 | Infinite loop on unexpected input | Local, high privileges |
| CVE-2026-62652 | 5.3 | Debug symbols left in firmware, easier reverse engineering | Access to firmware files |
| CVE-2026-62653 | 6.8 | Memory corruption in firmware-update mode | Physical |
| CVE-2026-62654 | 6.8 | Unsigned code execution through a maintenance mode | Physical |
The five 2024 CVEs sit in Mongoose, the open-source embedded web server inside the relay. Access needed comes from the CVSS v3.1 vectors in SSA-142885. Seven flaws let an attacker with no login reach the relay over the network, most of them through the web interface.
What an attacker can do through the web interface.
The network flaws fall into three groups.
Session takeover. CVE-2026-62645, -62646 and -62647 all weaken the session ID. A session ID is the token that proves you already logged in. If an attacker can calculate or guess it, the password stops mattering.
Privilege escalation. CVE-2026-62650 lets a user with a low-privilege account bypass role checks and act as an admin. Every relay account becomes a possible admin account.
Denial of service. CVE-2026-62648, CVE-2026-62649 and the Mongoose flaws can crash the web server or the device. The advisories do not say whether a crash interrupts the protection functions. Test that on a bench relay before you assume either answer.
The table below maps the flaws to MITRE ATT&CK for ICS. It describes what the flaws allow. It does not describe an observed attack.
| Tactic | Technique (ID) | How it applies here |
|---|---|---|
| Initial Access | Exploitation of Remote Services (T0866) | Session ID flaws bypass the web login |
| Initial Access | Internet Accessible Device (T0883) | Only if the web interface is reachable from the internet |
| Privilege Escalation | Exploitation for Privilege Escalation (T0890) | CVE-2026-62650 turns a low-privilege user into an admin |
| Inhibit Response Function | Denial of Service (T0814) | URL, resource and Mongoose flaws crash the web server or device |
| Impair Process Control | Modify Parameter (T0836) | Possible with an admin session, if your firmware lets the web interface change settings |
| Persistence | System Firmware (T0857) | CVE-2026-62654, unsigned code in maintenance mode, physical access needed |
| Impact | Loss of Protection (T0837) | Worst case, if a crash or settings change stops the relay from tripping |
How long relay patching takes.
A relay update is a field job. Each relay is taken out of service, updated and tested again, often on a scheduled outage or with backup protection covering the bay.
The steps are familiar to any protection team. Read the release notes. Check that your settings files carry over to V2.70. Test the update on a bench relay. Plan the switching. Update, then run the functional checks again. Update the configuration baseline.
Across a fleet spread over many substations, that takes months. Plan for the gap between the advisory and the last updated relay.
NERC CIP builds that gap in. For medium and high impact systems, CIP-007-6 R2 asks you to evaluate a security patch, then, within 35 days, apply it or write a dated mitigation plan. The controls in the next sections are what goes in that plan. CIP-010 also treats firmware as part of the baseline, so the update follows your change process.
What NERC CIP asks for at the relay.
Which standard applies depends on the impact rating under CIP-002 of the system the relay belongs to. Many distribution and smaller transmission substations are low impact.
| Control | Requirement | Applies to |
|---|---|---|
| Allow only needed inbound and outbound access, deny the rest | CIP-005-7 R1.3 | Medium and high impact |
| Interactive remote access through an Intermediate System, encrypted, with MFA | CIP-005-7 R2.1 to R2.3 | Medium and high impact |
| See and cut active vendor remote sessions | CIP-005-7 R2.4 and R2.5 | Medium and high impact |
| Enable only the ports and services you need | CIP-007-6 R1.1 | Medium and high impact |
| Patch or write a dated mitigation plan | CIP-007-6 R2 | Medium and high impact |
| Limit electronic access to what is necessary | CIP-003-9 Attachment 1, Section 3 | Low impact |
| Control vendor electronic remote access, since April 1, 2026 | CIP-003-9 Attachment 1, Section 6 | Low impact |
Our NERC CIP compliance guide covers the evidence each requirement needs.
What to do before you can patch.
Start with the vendor's own steps. Siemens and CISA both say to keep the relay off the internet. Put it behind firewalls and away from the business network. Use a secure remote access method when remote access is needed. Follow the Siemens operational guidelines for grid security, and do an impact analysis before you change anything.
Then limit who can reach the web interface. The relay's protection protocols and its web interface do different jobs. SCADA needs to poll the relay. Very few people need its web pages. Allow the web interface only from named engineering workstations. Block it from everyone else on the substation and corporate networks.
Tie each session to a person. Every engineer signs in with their own account and MFA before reaching a relay. Every session is recorded. A session ID flaw then only helps someone who already passed that check.
Review relay accounts. CVE-2026-62650 turns a low-privilege account into an admin. Remove shared and unused accounts.
Watch for crashes. A relay web server that restarts for no reason, or a burst of HTTP requests, is worth a call to the substation team.
How Access Gate helps, and its limits.
Access Gate is an appliance installed at each site. It connects beside the existing substation network. You then steer relay web traffic through it, one relay or one subnet at a time. Nothing is installed on the relays. It is installed in a day per site.
Once traffic flows through the gate, the relay web interface answers only named engineers. Each one signs in with MFA and reaches only the relays the job needs. Each session is recorded. A vendor gets a time-limited session that you can see and cut. SCADA polling keeps its existing path. The access logs and recordings are the evidence for CIP-005-7 R2 and CIP-003-9 Section 6. See secure remote access and power grid security for how this works at a substation.
The limits are real. Access Gate does not fix the firmware. An engineer who is allowed in still reaches a vulnerable web server. Someone already plugged into the substation switch behind the gate is outside its control. The two physical-access flaws need locks and site security. V2.70 is still the fix. The gate controls who reaches the relays until every one runs it.
What to do this week.
- List every Reyrolle 7SR5 relay and its firmware version.
- Test who can reach each web interface, from the corporate network and from the internet.
- Restrict the web interface to named engineering workstations.
- Remove shared and unused relay accounts.
- Download V2.70 and start the bench test.
- Write the mitigation plan for relays you cannot update within 35 days.
- Check physical security at substations with 7SR5 relays.
Want to see where a gate would sit in your substation? Build your network in a few minutes. Every other advisory we have covered is in the ICS security advisories archive.
Sources: CISA ICS Advisory ICSA-26-258-05 (September 15, 2026), Siemens ProductCERT SSA-142885 (September 8, 2026), Siemens operational guidelines for grid security, and the NERC CIP-003-9, CIP-005-7 and CIP-007-6 standards. Verify affected and fixed versions against SSA-142885 before scheduling work.