How can teams determine whether their SIMOVE Fleetmanager or SIPLANT version is affected by CVE-2026-67367?
Teams should compare their installed SIMOVE Fleetmanager or SIPLANT version with the affected versions listed in CISA’s September 22, 2026 advisory.
What to compare
The advisory says Siemens SIMOVE Fleetmanager and SIPLANT products contain a path traversal vulnerability associated with CVE-2026-67367.
The affected SIMOVE Fleetmanager versions listed in the context include:
- V3.1 below the fixed release
- V3.2 below the fixed release
- V3.3 below the fixed release
- V4.0 below the fixed release
The context also says several SIPLANT versions are associated with CVE-2026-67367, but it does not list those versions.
What to do with the result
If the product and version match the affected range, Siemens has released new versions and recommends updating to the latest versions.
If you are checking SIPLANT, use the official advisory for the exact affected versions because the summary here does not contain the full SIPLANT list.
What should Siemens SIMOVE Fleetmanager and SIPLANT users do after the September 22, 2026 CISA advisory?

After CISA’s September 22, 2026 advisory, affected Siemens SIMOVE Fleetmanager and SIPLANT users should update to the latest versions when Siemens has provided them.
The main action
Siemens has released new versions for affected products and recommends updating to the latest versions.
That guidance applies to products affected by the path traversal vulnerability described in the CISA advisory.
Why the update matters
CISA says the issue could let an attacker reach files beyond the intended scope. The available context does not describe a broader impact than that, so the practical focus is version verification and updating.
Check before scheduling changes
Confirm your exact product and version against the advisory. SIMOVE Fleetmanager V3.1, V3.2, V3.3, and V4.0 are listed as affected when they are below specified fixed releases. Several SIPLANT versions are also associated with CVE-2026-67367.
Because vendor advisories can be updated, review the CISA page before taking final action.
What could the path traversal vulnerability allow an attacker to access?

CISA describes the Siemens SIMOVE Fleetmanager and SIPLANT issue as a path traversal vulnerability. The confirmed impact is that an attacker could reach files beyond the intended scope.
What that means in plain English
A path traversal issue generally concerns file access boundaries. In this case, the important confirmed detail is CISA’s description: the vulnerability could allow access to files outside the intended scope.
The context does not say which files, how an attack would be carried out, or whether any exploitation has occurred.
Which products are tied to the issue
The advisory covers Siemens SIMOVE Fleetmanager and SIPLANT products associated with CVE-2026-67367.
The affected SIMOVE Fleetmanager versions mentioned are V3.1, V3.2, V3.3, and V4.0 when below specified fixed releases. The context also notes several affected SIPLANT versions.
What users should do next
Siemens has released new versions for affected products and recommends updating to the latest versions. For exact affected versions and current mitigation details, use the CISA advisory rather than relying on a summary.
Which SIMOVE Fleetmanager versions are listed as affected before the fixed releases?

The SIMOVE Fleetmanager versions listed as affected are V3.1, V3.2, V3.3, and V4.0 when they are below the specified fixed releases.
Affected versions named in the advisory summary
The context identifies these SIMOVE Fleetmanager version lines:
| Product | Versions listed as affected |
|---|---|
| SIMOVE Fleetmanager | V3.1 below specified fixed releases |
| SIMOVE Fleetmanager | V3.2 below specified fixed releases |
| SIMOVE Fleetmanager | V3.3 below specified fixed releases |
| SIMOVE Fleetmanager | V4.0 below specified fixed releases |
The issue is associated with CVE-2026-67367.
What the version list does not include
The context does not provide the exact fixed release numbers. It also does not list every SIPLANT version, only that several SIPLANT versions are associated with the same CVE.
What to check next
If your system uses one of the listed SIMOVE Fleetmanager version lines, compare it with the fixed release information in the official CISA advisory. Siemens recommends updating affected products to the latest versions.
Sources / Learn more
Related reading
- What should NetScaler ADC and Gateway administrators do first after CISA added CVE-2026-88771 and CVE-2026-88772 to the KEV Catalog?; Which Citrix products are affected by CVE-2026-88771 and CVE-2026-88772?; How are CVE-2026-88771 and CVE-2026-88772 different?; When did CISA add the two Citrix NetScaler vulnerabilities to the Known Exploited Vulnerabilities Catalog?
- How do I update a Eufy Omni C20 or Omni X10 Pro to firmware version 1.6.4 or later?; Which Eufy Omni C20 and Omni X10 Pro firmware versions are affected by the September 24, 2026 CISA advisory?; What should I do if my Eufy Omni C20 or Omni X10 Pro was paired while running firmware before 1.6.4?; What changed in the CISA advisory for Eufy Omni C20 and Omni X10 Pro released on September 24, 2026?
- What should Siemens Mendix Runtime users do after CISA revoked the advisory and CVE-2026-7891 was retracted?; What changed in CISA’s September 24, 2026 Siemens Mendix Runtime Update A?; Does the Siemens Mendix Runtime issue expose the protected application-specific attribute?
- Is Oceans Calling 2026 still happening despite the small craft advisory and coastal flood warning?

Leave a Reply