VORANT. Threat Intelligence Sign in Get the full feed

Siemens CPCI85 and SICORE flaws patched

medium vulnerability energymanufacturinginfrastructure

CERT-FR advises multiple vulnerabilities in Siemens CPCI85 and SICORE products could allow code execution, privilege escalation, and denial of service.

CERT-FR published an advisory detailing multiple vulnerabilities affecting Siemens CPCI85 Central Processing/Communication (versions prior to 26.20) and SICORE Base system (versions prior to 26.20.0). The flaws, tracked under four CVE identifiers, could allow an attacker to bypass security policies, cause remote denial of service, execute arbitrary code, or escalate privileges on affected systems.

Siemens released a corresponding security bulletin (SSA-229470) on July 9, 2026, providing patches for the affected products. No evidence of active exploitation is mentioned in the advisory; organizations using these Siemens products, which are typically deployed in industrial and infrastructure environments, are advised to apply the vendor's fixes as soon as possible.

Mentioned in this report

Vulnerabilities CVE-2026-54798CVE-2026-54799CVE-2026-54800CVE-2026-54801

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0860

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free