CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Siemens SICAM 8

criticalCVE-2026-54798CVE-2026-54799CVE-2026-54800CVE-2026-54801
View CSAF Summary Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: - SICAM A8000 Device firmware - CPCI85 for CP-8031/CP-8050 - SICORE for CP-8010/CP-8012 - SICAM EGS Device firmware - CPCI85 - SICAM S8000 - SICORE Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens SICAM 8 are affected: CPCI85 Central Processing/Communication vers:intdot/<26.20 (CVE-2026-54798, CVE-2026-54799, CVE-2026-54800, CVE-2026-54801) SICORE Base system vers:intdot/<26.20.0 (CVE-2026-54798, CVE-2026-54799, CVE-2026-54800, CVE-2026-54801) CVSS Vendor Equipment Vulnerabilities v3 7.2 Siemens Siemens SICAM 8 Active Debug Code, Initialization of a Resource with an Insecure Default, Unverified Password Change Background Critical Infrastructure Sectors: Critical Manufacturing, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-54798 The affected application includes a debugging interface that is accessible through HTTP endpoints. This could allow an authenticated attacker to disrupt the system by crashing the web process causing denial of service conditions. View CVE Details Affected Products Siemens SICAM 8 Vendor: Siemens Product Version: CPCI85 Central Processing/Communication < V26.20, SICORE Base system < V26.20.0 Product Status: known_affected Remediations Vendor fix Update to V26.20 or later version The firmware CPCI85 V26.20 is present within “CP-8031/CP-8050 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109804985/ and also within “SICAM EGS Package” V26.20 https://support.industry.siemens.com/cs/document/109972536/ Vendor fix Update to V26.20.0 or later version The firmware SICORE V26.20.0 is present within “CP-8010/CP-8012 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109972894/ and also within “SICAM S8000 Package” V26.20 htt

CSIRTS triage

vendor: Siemensproduct: SICAM 8Denial of serviceaffected: CPCI85 Central Processing/Communication vers:intdot/<26.20, SICORE Base system vers:intdot/<26.20.0
What
Multiple vulnerabilities could lead to denial of service.
Who is affected
Multiple SICAM 8 products including CPCI85 and SICORE with versions below 26.20.
Urgency
Remediation is urgent due to the critical nature of the vulnerabilities and the risk of service interruption.
Action
Update to the latest versions as recommended by Siemens.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch SICAM 8

Get an email when a new SICAM 8 advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-07-16
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-05

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-54798coverage & exploitation statusNVD · CVE.org
CVE-2026-54799coverage & exploitation statusNVD · CVE.org
CVE-2026-54800coverage & exploitation statusNVD · CVE.org
CVE-2026-54801coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from CISA Cybersecurity Advisories