Siemens Product Security Update Advisory

Siemens Product Security Update Advisory

overview

Siemens has released security updates to address vulnerabilities in its products. users of affected products are encouraged to update to the latest version.

affected products

CVE-2026-27663

CPCI85 Central Processing/Communication Versions: V26.10 and earlier
RTUM85 RTU Base Version: V26.10 and earlier

CVE-2026-27664

CPCI85 Central Processing/Communication Version: V26.10 or earlier
SICORE Base system version: V26.10.0 or earlier

resolved Vulnerabilities

Denial of Service Vulnerability in CPCI85 Central Processing/Communication and RTUM85 RTU Base (CVE-2026-27663)
Out-of-bound write vulnerability in the CPCI85 Central Processing/Communication and SICORE Base systems (CVE-2026-27664)

vulnerability patches

Vulnerability patches have been made available in the latest update. please follow the instructions on the reference site to update to the latest version of the vulnerability patch.

CVE-2026-27663

CPCI85 Central Processing/Communication Version: V26.10 or later
RTUM85 RTU Base Version: V26.10 or later

CVE-2026-27664

CPCI85 Central Processing/Communication Version: V26.10 or later
SICORE Base system version: V26.10.0 or later

references

[1] SSA-246443: Multiple Vulnerabilities in SICAM 8 Products
https://cert-portal.siemens.com/productcert/html/ssa-246443.html