INTEL_REPORT
CISA Cybersecurity Advisories · published 5/14/2026, 12:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Siemens gWAP View CSAF Summary Siemens gPROMS Web Applications Publisher (gWAP) is affected by a remote code execution vulnerability introduced through a third-party component, namely the Axios HTTP client library. The vulnerability stems from a specific "Gadget" attack chain that allows prototype pollution in other third-party libraries, potentially allowing an attacker to execute arbitrary code. Siemens has released a new version for gWAP and recommends to update to the la…
https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-01
sha256:c5d6b99d71e8403fc85a2eaf3069633b2fad417337a1933ecaaeb5f146c3aa69
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| url |
| https://www.siemens.com/industrialsecurity |
| Open → |
| url | https://www.siemens.com/cert/advisories | Open → |
| url | https://www.siemens.com/productcert/terms-of-use | Open → |
| domain | support.sw.siemens.com | Open → |
| url | https://support.sw.siemens.com/product/284395347/ | Open → |
| cve | CVE-2026-40175 | Open → |