Siemens Kernel Flaw Spans SIMATIC and SIPLUS Fleets
CISA summarized Siemens advisories for CVE-2026-31431, a Linux kernel “Copy Fail” cryptography regression that affects multiple SIMATIC and SIPLUS products across runtime, HMI, and networking lines. Siemens says it has released new versions for some affected products and is still preparing follow-on fixes for others.
The issue is shared code, not a single box model: the same kernel defect shows up in SIMATIC AX Runtime Core on Debian, arm64, container, and VMware builds, plus SIMATIC CN 4100 and multiple SIMATIC HMI MTP panels. That means the exposure can recur across very different endpoints in the same fleet, and some devices will need countermeasures until Siemens publishes a fix.
For operators with mixed OT estates, the important part is the common root cause. If a plant runs several of these families side by side, patch status will not line up neatly by form factor, and part of the fleet may remain on mitigation rather than a clean update path.
CVSS 7.8 HIGH: in the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert to operating… EPSS 100% (100th percentile). Microsoft patch: CBL-Mariner Releases.
CISA federal remediation date May 15 · date passed