Siemens S7 PLC Vulnerability: AI Exploits Hit US Infrastructure


A joint advisory from five U.S. agencies details AI-generated exploit scripts targeting Siemens S7 PLCs across critical infrastructure. This week also brings a deep dive into Google’s new AI vulnerability discovery pipeline and a critical file-upload flaw in Elementor Pro for WordPress.

How This Was Verified

This roundup is based on the official advisory, vendor disclosures, and primary reporting — we did not run the tools hands-on. We verified information against primary sources: the CISA advisory AA26-231A, the Google Threat Intelligence Group blog, the National Vulnerability Database (NVD), the Patchstack advisory, and BleepingComputer reporting.

We cross-checked advisory dates, CVSS scores, affected version numbers, advisory authoring agencies, CVE identifiers, and disclosure timelines, with all HTTP links returning 200 on August 24, 2026.

We did not perform hands-on OT lab testing of the S7 exploitation scripts or independently verify the internal pipeline of the Agentic Vulnerability Discovery Harness (AVDH). The unverified claim of “confirmed water-system disruptions in 12+ states” circulating in some secondary coverage does not appear in the CISA advisory and is excluded from this roundup.

Last verified: August 2026.

How serious is the Siemens S7 PLC vulnerability?

The Siemens S7 PLC vulnerability described in CISA advisory AA26-231A is an active, not theoretical, threat according to a joint warning from the NSA, CISA, FBI, DOE, and EPA issued August 19, 2026. The advisory confirms adversaries are using AI to develop exploitation scripts targeting a wide range of Siemens controllers in U.S. critical infrastructure sectors.

What attackers are doing The adversaries are scanning the internet for exposed PLCs using platforms like Censys and ZoomEye. They then deploy AI-generated Python scripts disguised as legitimate OT monitoring tools. These scripts utilize the open-source snap7.dll/python-snap7 libraries to communicate via the S7comm protocol on TCP port 102. This provides read and write access to PLC memory, configuration data, and ladder logic. The targeted models include the S7-200, S7-300, S7-400, S7-1200, and S7-1500 series, including S7-1500 F-series safety controllers. Most-targeted sectors are Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities, with activity also seen in the Defense Industrial Base. The agencies assess the activity is persistent reconnaissance and capability development to prepare for operational effects, with actors testing exploits against specific CPU models.

What to check today CISA’s advisory provides concrete mitigations and detection steps. Your OT and IT teams should:

  1. Inventory all S7 PLCs across your environment.
  2. Ensure no S7 PLCs are internet-accessible; block TCP port 102 at perimeter firewalls.
  3. Apply critical Siemens patches as detailed in the advisory.
  4. Enable password protection and set protection levels on all S7 CPUs.
  5. Use TIA Portal “know-how protection” and “complete restart protection.”
  6. Disable unused web servers and protocols on the PLCs.
  7. Deploy ICS-aware monitoring solutions like Claroty, Dragos Platform, or Nozomi Networks.
  8. Detect compromise by watching for anomalous S7comm connections from non-engineering workstations, sequential IP scanning on port 102, snap7.dll usage outside approved workstations, off-hours activity, and connections from unexpected geographies.

For mapping these mitigations against established controls, our ICS and OT security frameworks hub is a practical starting point.

This advisory follows a pattern of escalating ICS threats, including July 2026 attacks on 30+ Minnesota water utilities and a joint April 2026 warning about Iranian-linked targeting of internet-exposed Rockwell Automation PLCs. The advisory is clear: “This is not a theoretical risk—it is an active threat.”

How is Google Mandiant using AI agents to find zero-days?

Google Mandiant’s Agentic Vulnerability Discovery Harness (AVDH) is a multi-stage AI pipeline that discovered over 100 vulnerabilities in proprietary codebases in just two days. The tool coordinates a network of specialized AI agents to automate complex source code analysis and triage.

Mandiant researchers Alex Tselevich and Michael Maturi first disclosed AVDH on August 18, 2026, in a Google Cloud Blog post. During a recent incident response investigation involving stolen corporate repositories, AVDH found more than 100 “true-positive critical vulnerabilities” within 48 hours. Over ten months, the system has analyzed millions of lines of code across multiple environments, generating tens of thousands of findings. The pipeline stages include an Explorer agent for initial analysis, a human-gated Threat Model Synthesis phase, Discovery agents powered by Gemini Flash Lite, enrichment, and access control analysis. A confidence filter then selects findings for validation by high-temperature agents, with final synthesis and human verification of proof-of-concepts.

So far, 12 CVEs have been assigned from this research, including CVE-2026-13242 (Drupal Geolocation Field SQL injection, CVSS 6.5 MEDIUM) and CVE-2026-55803 (Drupal core object injection, CVSS 5.9 MEDIUM). The pipeline is built on the Google Agent Development Kit (ADK). Mandiant will present further research at the Cyber Defense Summit on September 15–16, 2026, in Washington, D.C. For more on the security risks that agentic AI tooling introduces, see our MCP security deep-dive.

What is the Elementor Pro RCE vulnerability (CVE-2026-32475)?

CVE-2026-32475 is a critical unauthenticated remote code execution (RCE) flaw in Elementor Pro, allowing an attacker to upload and execute arbitrary files on a WordPress server. The vulnerability requires a specific, non-default configuration to be present on the affected site for exploitation.

The flaw, tracked as CVE-2026-32475 with a CVSS 9.0 CRITICAL score, affects Elementor Pro versions up to 4.2.1. It was fixed in version 4.2.2. Exploitation requires a published Elementor Pro Form that has the File Upload field enabled with the multiple-file upload option activated (which is off by default). The root cause is a disagreement between the validation and processing loops when handling multipart entries with empty filenames. This allows a malicious file to be moved to the wp-content/uploads/elementor/forms/ directory. The filename is generated via uniqid(), which is time-based and therefore brute-forceable.

The vulnerability was reported by Tin Pham on July 16, with a fix prepared the next day and verified on August 3. The advisory was published on August 19. Per BleepingComputer reporting, no exploitation was observed as of August 20, 2026. To remediate, site owners must update to Elementor Pro 4.2.2. Because updating does not remove previously uploaded files, they must also manually audit the wp-content/uploads/elementor/forms/ directory for rogue PHP files. You can track CVE-2026-32475 and other active disclosures in our CVE database hub. This flaw adds to the ongoing risks for the WordPress ecosystem, as highlighted in our analysis of the UniFi OS Mirai botnet chain.

FAQ

These are the questions readers ask most about this week’s disclosures. Each answer below is sourced from the primary advisories cited above and stands on its own, so you can jump straight to the PLC, AI tooling, or WordPress issue that matters for your environment.

What PLCs are affected by CISA advisory AA26-231A?

The advisory explicitly states that the S7-200, S7-300, S7-400, S7-1200, and S7-1500 series are affected. This includes all CPU variants within those lines, notably the S7-1500 F-series safety controllers, according to the CISA advisory.

Are the Google Mandiant AVDH CVEs critical severity?

No. The two publicly named CVEs — CVE-2026-13242 (CVSS 6.5) and CVE-2026-55803 (CVSS 5.9) — are both rated MEDIUM by CISA-ADP in the NVD. The “100+ critical vulnerabilities” figure cited in Mandiant’s blog refers to findings within stolen proprietary source-code repositories, not publicly published CVEs.

Has CVE-2026-32475 in Elementor Pro been exploited in the wild?

As of August 20, 2026, no exploitation was observed per BleepingComputer and CISA’s SSVC data in the NVD. However, the exploit mechanics are public, and mass exploitation is a realistic near-term risk for sites running the affected configuration.

  • ToolBrain — tool reviews, LLM comparisons, and AI workflow guides
  • NiteAgent — AI agent development, frameworks, and production patterns

Cross-links automatically generated from None.