CVE-2026-54429
View CSAF Summary SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIMATIC S7-PLCSIM Advanced are affected: SIMATIC S7-PLCSIM Advanced vers:all/* (CVE-2026-54429) CVSS Vendor Equipment Vulnerabilities v3 7.4 Siemens Siemens SIMATIC S7-PLCSIM Advanced Allocation of Resources Without Limits or Throttling Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-54429 Affected devices do not properly handle high-volume multicast network traffic, which can exhaust available memory resources in the affected application. This could allow an unauthenticated attacker on the local network segment to cause a denial-of-service condition of the affected application. The affected application becomes inaccessible and requires a manual restart; no project data is lost. Successful exploitation requires a specific project configuration to be already active on the targeted instance. View CVE Details Affected Products Siemens SIMATIC S7-PLCSIM Advanced Vendor: Siemens Product Version: SIMATIC S7-PLCSIM Advanced Product Status: known_affected Remediations Mitigation Disable the S7-PLCSIM Virtual Switch binding on the network adapter used by the affected instance. This prevents the adapter from entering an external communication mode and removes the attack vector entirely. (see SIMATIC S7-PLCSIM Advanced Function Manual V8.0, 11/2025 Section 5.3 and Section 6.1.2.3; and SIMATIC S7-PLCSIM Advanced Function Manual API V8.0, 11/2025 Section 7.2) Mitigation Restrict multicast traffic on the network segment hosting the SIMATIC S7-PLCSIM Advanced host. Mitigation Use 'Softbus' / 'PLCSIM' network mode. This mode does not accept any packets fr
CSIRTS triage
- What
- A vulnerability could allow an attacker to cause a denial of service condition.
- Who is affected
- Users of all versions of SIMATIC S7-PLCSIM Advanced.
- Urgency
- Remediation is critical as the vulnerability could lead to service disruption.
- Action
- Siemens is preparing fix versions and recommends specific countermeasures.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-54429
Get an email if CVE-2026-54429 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
Advisory coverage (5)
- criticalSiemens SIMATIC S7-PLCSIM Advancedcisa · 2026-07-28
- medium[NEW] [medium] Siemens SIMATIC S7: Vulnerability allows denial of servicecert-bund · 2026-07-15
- unknownMultiple vulnerabilities in Siemens products (July 15, 2026)cert-fr-avis · 2026-07-15
- unknownNCSC-2026-0229 [1.00] [M/H] Vulnerabilities fixed in Siemens productsncsc-nl · 2026-07-14
- highCVE-2026-54429: A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected dev…nvd · 2026-07-14
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-54429)