Siemens Product Security Update Advisory
overview
Siemens has released security updates to address vulnerabilities in its products. users of affected products are encouraged to update to the latest version.
affected products
CVE-2026-27663
CPCI85 Central Processing/Communication Versions: V26.10 and earlier
RTUM85 RTU Base Version: V26.10 and earlier
CVE-2026-27664
CPCI85 Central Processing/Communication Version: V26.10 or earlier
SICORE Base system version: V26.10.0 or earlier
resolved Vulnerabilities
Denial of Service Vulnerability in CPCI85 Central Processing/Communication and RTUM85 RTU Base (CVE-2026-27663)
Out-of-bound write vulnerability in the CPCI85 Central Processing/Communication and SICORE Base systems (CVE-2026-27664)
vulnerability patches
Vulnerability patches have been made available in the latest update. please follow the instructions on the reference site to update to the latest version of the vulnerability patch.
CVE-2026-27663
CPCI85 Central Processing/Communication Version: V26.10 or later
RTUM85 RTU Base Version: V26.10 or later
CVE-2026-27664
CPCI85 Central Processing/Communication Version: V26.10 or later
SICORE Base system version: V26.10.0 or later
references
[1] SSA-246443: Multiple Vulnerabilities in SICAM 8 Products
https://cert-portal.siemens.com/productcert/html/ssa-246443.html