A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versions), SIMATIC WinCC Unified PC Runtime V18 (All versions), SIMATIC WinCC Unified PC Runtime V19 (All versions), SIMATIC WinCC Unified PC Runtime V20 (All versions), SIMATIC WinCC Unified PC Runtime V21 (All versions < V21 Update 2). Insufficient protection of key material in WinCC Certificate Manager that could allow an attacker to extract sensitive information.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-24349 affects SIMATIC WinCC Unified PC Runtime across versions 16-21 (pre-Update 2), exposing a critical weakness in how the WinCC Certificate Manager protects cryptographic key material. This vulnerability allows attackers to extract sensitive information—likely private keys or certificate credentials—due to insufficient protective mechanisms around key storage and handling. Industrial control system operators using any affected WinCC version face significant risk, as compromised certificate material could enable credential theft, unauthorized system access, and potential lateral movement within critical infrastructure environments. The broad version impact (16-21) means patching is a priority for organizations managing SCADA, HMI, and process automation systems.
While this CVE carries no mapped MITRE ATT&CK techniques, Casky's skill set equipped with Claude's extended reasoning capabilities would detect attack patterns associated with CWE-313 (Cleartext Storage of Sensitive Information) by identifying credential access behaviors and potential T1552 (Unsecured Credentials) exploitation chains. Practitioners using Casky would observe findings related to insecure key material handling, unencrypted certificate storage locations, and unauthorized certificate extraction attempts. The platform's 754 mapped security skills would correlate this vulnerability with downstream risks—including T1078 (Valid Accounts) abuse if stolen credentials are leveraged—enabling practitioners to build comprehensive detection logic across their WinCC deployments and correlate suspicious certificate access or export activities in event logs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-24349. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation