Siemens SIMATIC S7-PLCSIM Advanced
View CSAF Summary SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIMATIC S7-PLCSIM Advanced are affected: SIMATIC S7-PLCSIM Advanced vers:all/* (CVE-2026-54429) CVSS Vendor Equipment Vulnerabilities v3 7.4 Siemens Siemens SIMATIC S7-PLCSIM Advanced Allocation of Resources Without Limits or Throttling Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-54429 Affected devices do not properly handle high-volume multicast network traffic, which can exhaust available memory resources in the affected application. This could allow an unauthenticated attacker on the local network segment to cause a denial-of-service condition of the affected application. The affected application becomes inaccessible and requires a manual restart; no project data is lost. Successful exploitation requires a specific project configuration to be already active on the targeted instance. View CVE Details Affected Products Siemens SIMATIC S7-PLCSIM Advanced Vendor: Siemens Product Version: SIMATIC S7-PLCSIM Advanced Product Status: known_affected Remediations Mitigation Disable the S7-PLCSIM Virtual Switch binding on the network adapter used by the affected instance. This prevents the adapter from entering an external communication mode and removes the attack vector entirely. (see SIMATIC S7-PLCSIM Advanced Function Manual V8.0, 11/2025 Section 5.3 and Section 6.1.2.3; and SIMATIC S7-PLCSIM Advanced Function Manual API V8.0, 11/2025 Section 7.2) Mitigation Restrict multicast traffic on the network segment hosting the SIMATIC S7-PLCSIM Advanced host. Mitigation Use 'Softbus' / 'PLCSIM' network mode. This mode does not accept any packets fr
CSIRTS triage
- What
- A vulnerability could allow an attacker to cause a denial of service condition.
- Who is affected
- Users of all versions of SIMATIC S7-PLCSIM Advanced.
- Urgency
- Remediation is critical as the vulnerability could lead to service disruption.
- Action
- Siemens is preparing fix versions and recommends specific countermeasures.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch SIMATIC S7-PLCSIM Advanced
Get an email when a new SIMATIC S7-PLCSIM Advanced advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-03
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-544290.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-54429 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Siemens SIMATIC S7: Vulnerability allows denial of servicecert-bund
- unknownMultiple vulnerabilities in Siemens products (July 15, 2026)cert-fr-avis
- unknownNCSC-2026-0229 [1.00] [M/H] Vulnerabilities fixed in Siemens productsncsc-nl
- highCVE-2026-54429: A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected dev…nvd
More from CISA Cybersecurity Advisories
- criticalOpen Source Software: Security Principles and Practices2026-07-30
- criticalSchneider Electric IGSS2026-07-30
- criticalToptech Systems RCU II+ and Multiload II+2026-07-30
- criticalNASA Core Flight System (cFS) Health & Safety (HS) Application2026-07-30
- criticalMikroTik RouterOS2026-07-30