CVE-2026-27664
CVSS 7.5 HIGH: a vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), SICORE Base system (All versions < V26.10.0). EPSS 0.5% (41st percentile).
Vulnerabilities & Exploits · IoT / OT Attack
Multiple Siemens SICAM 8 product components have denial-of-service vulnerabilities (CVE-2026-27663, CVE-2026-27664) that cause resource exhaustion when exposed to high volumes of requests. These flaws affect firmware in CPCI85 Central Processing/Communication, RTUM85 RTU Base, and SICORE Base system devices, all used in critical manufacturing and infrastructure sectors.
Exploitation leads to device unavailability requiring reset or reboot, not data compromise. Siemens has released fixed firmware versions 26.10 or later for each affected component. Operators must verify no devices run vulnerable versions below 26.10 and coordinate updates across multiple SICAM 8 product lines. Network-level rate limiting can help mitigate attack impact.
This is an availability risk for OT environments, not a breach risk. No active exploitation is reported, but patching is important to prevent disruption in critical infrastructure.
1 source · Apr 2
CVSS 7.5 HIGH: a vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), SICORE Base system (All versions < V26.10.0). EPSS 0.5% (41st percentile).
CVSS 6.5 MEDIUM: a vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), RTUM85 RTU Base (All versions < V26.10). EPSS 0.3% (19th percentile).
CISA Advisories
Siemens SICAM 8 Products | CISA
Siemens SICAM 8 Products Summary Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: - SICAM A8000 Device firmware - CPCI85 for CP-8031/CP-8050 - SICORE for CP-8010/CP-8012 - RTUM85 for CP-8010/CP-8012 - SICAM EGS…
originalPart of the PlainSec briefing for 2026-04-03
Every edition of this story: Siemens SICAM 8 Firmware Flaws Cause Denial of Service via Resource Exhaustion