PatchSiren cyber security CVE debrief
CVE-2025-53066 Siemens CVE debrief
CVE-2025-53066 is a network-exploitable Oracle Java SE / GraalVM JAXP vulnerability with a CVSS v3.1 base score of 7.5. The advisory says an unauthenticated attacker can reach the issue over multiple protocols and may gain unauthorized access to critical data or all data accessible to the affected Java runtime, including sandboxed Java Web Start or applet deployments that process untrusted code.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Owners of Oracle Java SE and GraalVM JDK deployments on servers, middleware, web services, and client systems; teams that expose Java APIs to untrusted input; and security teams supporting sandboxed Java Web Start or applet environments.
Technical summary
The source advisory describes a JAXP component issue affecting Oracle Java SE 8u461, 8u461-perf, 11.0.28, 17.0.16, 21.0.8, and 25; Oracle GraalVM for JDK 17.0.16 and 21.0.8; and Oracle GraalVM Enterprise Edition 21.3.15. Exploitation does not require authentication or user interaction, and the attack surface includes APIs exposed by services that supply data to the component. The reported impact is confidentiality-only (C:H/I:N/A:N).
Defensive priority
High — prioritize inventorying and patching affected Java/GraalVM deployments, especially internet-facing services and any environment that processes untrusted input through JAXP.
Recommended defensive actions
- Inventory Oracle Java SE and GraalVM installations and compare them against the affected versions listed in the advisory.
- Prioritize patching or upgrading internet-facing systems and any Java services that accept untrusted data through JAXP.
- Review sandboxed Java Web Start and Java applet deployments that load untrusted code; reduce or remove those trust assumptions where possible.
- Restrict network exposure to affected Java services until remediation is complete, and monitor for unauthorized access to sensitive data.
Evidence notes
The advisory content is explicit about the affected Oracle Java/GraalVM versions, the JAXP component, the network/unauthenticated attack model, and the CVSS vector. The source item's vendor/product metadata is inconsistent with the advisory text (it references Siemens SIMATIC CN 4100 while the body describes Oracle Java SE/GraalVM), so the Oracle/JAXP description should be treated as authoritative for this CVE.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-53066 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-53066
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-53066 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-53066
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.