Vulnerabilities & Exploits

Siemens Kernel Flaw Spans SIMATIC and SIPLUS Fleets

CISA summarized Siemens advisories for CVE-2026-31431, a Linux kernel “Copy Fail” cryptography regression that affects multiple SIMATIC and SIPLUS products across runtime, HMI, and networking lines. Siemens says it has released new versions for some affected products and is still preparing follow-on fixes for others.

The issue is shared code, not a single box model: the same kernel defect shows up in SIMATIC AX Runtime Core on Debian, arm64, container, and VMware builds, plus SIMATIC CN 4100 and multiple SIMATIC HMI MTP panels. That means the exposure can recur across very different endpoints in the same fleet, and some devices will need countermeasures until Siemens publishes a fix.

For operators with mixed OT estates, the important part is the common root cause. If a plant runs several of these families side by side, patch status will not line up neatly by form factor, and part of the fleet may remain on mitigation rather than a clean update path.

1 source · 13h ago

CVE-2026-31431

NVD KEV

Known exploited · CISA KEV

CVSS 7.8 HIGH: in the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating… EPSS 100% (100th percentile). Microsoft patch: CBL-Mariner Releases.

CISA federal remediation date May 15 · date passed

Timeline

Sources

Vendor digest: VMware

Part of the PlainSec briefing for 2026-09-22

Every edition of this story: Siemens Kernel Flaw Spans SIMATIC and SIPLUS Fleets

More from today