Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
2026-07-20T20:51:37Z•2bf4b7f3a2a32fa4ba170e08c70f5dba8b7019d6d6eb8c677676c5fcbeec2688
chained-vulnerabilitiescritical-infrastructurefirmwareicsmitigationotpaloalto_unit42persistenceprivilege-escalationremote-exploitroot-accessrox-iisiemens-rox-iiunit42vulnerability-disclosurezero-day
What happened
Unit 42 disclosed three chained zero-day vulnerabilities in Siemens ROX II OT switches that together enable local privilege escalation and persistent root access. The chain allows attackers to gain and maintain high-privilege control of affected switches, posing significant risk to industrial and critical infrastructure networks. Unit 42 provides technical details, indicators, and mitigation guidance; organizations should treat these as high-priority fixes and isolate/segregate affected devices until patched.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 2bf4b7f3a2a32fa4ba170e08c70f5dba8b7019d6d6eb8c677676c5fcbeec2688
- Enrichment time
- 2026-07-20T20:51:37Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.