# Siemens CPCI85 and SICORE flaws patched

Published: 2026-07-10 · Severity: medium · Sectors: energy, manufacturing, infrastructure
Canonical: https://vorant.io/reports/47303e44-5bec-5ca8-830b-1d896d79ff5f/siemens-cpci85-and-sicore-flaws-patched

> CERT-FR advises multiple vulnerabilities in Siemens CPCI85 and SICORE products could allow code execution, privilege escalation, and denial of service.

CERT-FR published an advisory detailing multiple vulnerabilities affecting Siemens CPCI85 Central Processing/Communication (versions prior to 26.20) and SICORE Base system (versions prior to 26.20.0). The flaws, tracked under four CVE identifiers, could allow an attacker to bypass security policies, cause remote denial of service, execute arbitrary code, or escalate privileges on affected systems.

Siemens released a corresponding security bulletin (SSA-229470) on July 9, 2026, providing patches for the affected products. No evidence of active exploitation is mentioned in the advisory; organizations using these Siemens products, which are typically deployed in industrial and infrastructure environments, are advised to apply the vendor's fixes as soon as possible.

## Mentioned in this report

- Vulnerabilities: CVE-2026-54798, CVE-2026-54799, CVE-2026-54800, CVE-2026-54801

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0860

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/47303e44-5bec-5ca8-830b-1d896d79ff5f/siemens-cpci85-and-sicore-flaws-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
