Siemens SICAM 8 patches four flaws
Siemens fixed four vulnerabilities in SICAM A8000/EGS/S8000 firmware that could allow denial of service, privilege escalation, or malicious firmware installation.
Siemens disclosed four vulnerabilities affecting SICAM 8 product firmware (CPCI85 and SICORE base systems) used in SICAM A8000, SICAM EGS, and SICAM S8000 devices deployed in critical manufacturing and energy sectors worldwide. The issues range from an exposed debug interface reachable via HTTP that could crash the web process (CVE-2026-54798), to insufficient firmware update signature validation enabling installation of malicious firmware and persistent code execution (CVE-2026-54799), a default configuration that disables OPC UA security mechanisms (CVE-2026-54800), and insufficient credential validation in the web API allowing authenticated privilege escalation via administrative account modification (CVE-2026-54801).
Siemens has released fixed firmware versions (CPCI85 V26.20, SICORE V26.20.0) and recommends organizations update via official packages. No active exploitation has been reported; this is a proactive vendor disclosure. CISA republished the advisory verbatim and recommends standard ICS hardening practices including network segmentation, firewalling control system networks, and avoiding direct internet exposure, alongside cautious use of VPNs for remote access.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-05
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free