CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP

unknownknown exploitedpublic exploitCVE-2021-41617CVE-2023-28531CVE-2023-51384CVE-2023-52927CVE-2024-26783CVE-2024-27056
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP are affected: SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) vers:intdot/>=3.1.6 (CVE-2021-41617, CVE-2023-28531, CVE-2023-51384, CVE-2023-52927, CVE-2024-26783, CVE-2024-27056, CVE-2024-28956, CVE-2024-36903, CVE-2024-36927, CVE-2024-42079, CVE-2024-46786, CVE-2024-47736, CVE-2024-47809, CVE-2024-49968, CVE-2024-49994, CVE-2024-49998, CVE-2024-50014, CVE-2024-50063, CVE-2024-50164, CVE-2024-50298, CVE-2024-53124, CVE-2024-53170, CVE-2024-54458, CVE-2024-56631, CVE-2024-56703, CVE-2024-56719, CVE-2024-57917, CVE-2024-57924, CVE-2024-57973, CVE-2024-57977, CVE-2024-57979, CVE-2024-58011, CVE-2024-58016, CVE-2024-58020, CVE-2024-58056, CVE-2024-58058, CVE-2024-58061, CVE-2024-58086, CVE-2025-21645, CVE-2025-21648, CVE-2025-21655, CVE-2025-21676, CVE-2025-21682, CVE-2025-21702, CVE-2025-21705, CVE-2025-21706, CVE-2025-21707, CVE-2025-21718, CVE-2025-21731, CVE-2025-21745, CVE-2025-21758, CVE-2025-21760, CVE-2025-21764, CVE-2025-21765, CVE-2025-21780, CVE-2025-21795, CVE-2025-21796, CVE-2025-21802, CVE-2025-21814, CVE-2025-21846, CVE-2025-21853, CVE-2025-21861, CVE-2025-21864, CVE-2025-21867, CVE-2025-21875, CVE-2025-21887, CVE-2025-21913, CVE-2025-21919, CVE-2025-21925, CVE-2025-21926, CVE-2025-21938, CVE-2025-21959, CVE-2025-21999, CVE-2025-22005, CVE-2025-22015, CVE-2025-22055, CVE-2025-22056, CVE-2025-22060, CVE-2025-22083, CVE-2025-22090, CVE-2025-22095, CVE-2025-22107, CVE-2025-22111, CVE-2025-22121, CVE-2025-23136, CVE-2025-23143, CVE-2025-37785, CVE-2025-37909, CVE-2025-37917, CVE-2025-37945, CVE-2025-37959, CVE-2025-37964, CVE-2025-37972, CVE-2025-3

CSIRTS triage

What
Multiple vulnerabilities have been identified in the firmware of the product.
Who is affected
Users of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP with firmware version 3.1.6 or higher.
Urgency
Remediation is urgent as the vulnerabilities are actively exploited.
Action
Siemens is preparing fix versions and recommends specific countermeasures.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP

Get an email when a new SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
unknown
Published
2026-07-28
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-04

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2021-41617coverage & exploitation statusNVD · CVE.org
CVE-2023-28531coverage & exploitation statusNVD · CVE.org
CVE-2023-51384coverage & exploitation statusNVD · CVE.org
CVE-2023-52927coverage & exploitation statusNVD · CVE.org
CVE-2024-26783coverage & exploitation statusNVD · CVE.org
CVE-2024-27056coverage & exploitation statusNVD · CVE.org
CVE-2024-28956coverage & exploitation statusNVD · CVE.org
CVE-2024-36903coverage & exploitation statusNVD · CVE.org
CVE-2024-36927coverage & exploitation statusNVD · CVE.org
CVE-2024-42079coverage & exploitation statusNVD · CVE.org
CVE-2024-46786coverage & exploitation statusNVD · CVE.org
CVE-2024-47736coverage & exploitation statusNVD · CVE.org
CVE-2024-47809coverage & exploitation statusNVD · CVE.org
CVE-2024-49968coverage & exploitation statusNVD · CVE.org
CVE-2024-49994coverage & exploitation statusNVD · CVE.org
CVE-2024-49998coverage & exploitation statusNVD · CVE.org
CVE-2024-50014coverage & exploitation statusNVD · CVE.org
CVE-2024-50063coverage & exploitation statusNVD · CVE.org
CVE-2024-50164coverage & exploitation statusNVD · CVE.org
CVE-2024-50298coverage & exploitation statusNVD · CVE.org
CVE-2024-53124coverage & exploitation statusNVD · CVE.org
CVE-2024-53170coverage & exploitation statusNVD · CVE.org
CVE-2024-54458coverage & exploitation statusNVD · CVE.org
CVE-2024-56631coverage & exploitation statusNVD · CVE.org
CVE-2024-56703coverage & exploitation statusNVD · CVE.org
CVE-2024-56719coverage & exploitation statusNVD · CVE.org
CVE-2024-57917coverage & exploitation statusNVD · CVE.org
CVE-2024-57924coverage & exploitation statusNVD · CVE.org
CVE-2024-57973coverage & exploitation statusNVD · CVE.org
CVE-2024-57977coverage & exploitation statusNVD · CVE.org
CVE-2024-57979coverage & exploitation statusNVD · CVE.org
CVE-2024-58011coverage & exploitation statusNVD · CVE.org
CVE-2024-58016coverage & exploitation statusNVD · CVE.org
CVE-2024-58020coverage & exploitation statusNVD · CVE.org
CVE-2024-58056coverage & exploitation statusNVD · CVE.org
CVE-2024-58058coverage & exploitation statusNVD · CVE.org
CVE-2024-58061coverage & exploitation statusNVD · CVE.org
CVE-2024-58086coverage & exploitation statusNVD · CVE.org
CVE-2025-21645coverage & exploitation statusNVD · CVE.org
CVE-2025-21648coverage & exploitation statusNVD · CVE.org
CVE-2025-21655coverage & exploitation statusNVD · CVE.org
CVE-2025-21676coverage & exploitation statusNVD · CVE.org
CVE-2025-21682coverage & exploitation statusNVD · CVE.org
CVE-2025-21702coverage & exploitation statusNVD · CVE.org
CVE-2025-21705coverage & exploitation statusNVD · CVE.org
CVE-2025-21706coverage & exploitation statusNVD · CVE.org
CVE-2025-21707coverage & exploitation statusNVD · CVE.org
CVE-2025-21718coverage & exploitation statusNVD · CVE.org

+305 more CVEs referenced in this advisory.

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from CISA Cybersecurity Advisories