
AI Wrote the S7 Exploit. There Is No CVE to Patch.
AA26-231A carries no CVE because it documents a capability shift, not a flaw: AI-written snap7 scripts probing Siemens S7 PLCs while posing as OT monitoring tools. On modern controllers the whole attack surface is one TIA Portal checkbox.
August 23, 2026 · 13 min read