PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-21945 Siemens CVE debrief

CVE-2026-21945 is a network-reachable denial-of-service vulnerability affecting Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. The advisory says an unauthenticated attacker can trigger a hang or repeatable crash, resulting in availability loss. Oracle’s note also narrows the practical exposure: it is aimed at Java client deployments that load and execute untrusted code under the Java sandbox, such as Java Web Start applications or applets, and does not apply to typical trusted-code server deployments.

Vendor
Siemens
Product
SIMATIC CN 4100
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

Teams responsible for Oracle Java SE, Oracle GraalVM for JDK, or Oracle GraalVM Enterprise Edition should care most, especially where affected runtimes are installed on client endpoints or legacy desktop environments that still use Java Web Start, applets, or other sandboxed code paths. Patch management, endpoint security, and vulnerability management teams should also prioritize it for internet-connected or user-facing fleets.

Technical summary

The advisory describes an unauthenticated, network-accessible availability issue with CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (7.5). Successful exploitation can cause a hang or repeatedly reproducible crash, but the provided source text does not indicate confidentiality or integrity impact. The advisory explicitly limits the affected usage model to Java deployments that rely on the sandbox for untrusted code; it states that deployments running only trusted code in server-style environments are not in scope.

Defensive priority

High for affected client or desktop Java deployments; lower for trusted-code server deployments that match the advisory’s exclusion language.

Recommended defensive actions

  • Inventory Java SE and GraalVM versions across endpoints and client systems, with special attention to the versions named in the advisory.
  • Upgrade to the vendor-fixed release described in the source remediation guidance: V5.0 or later.
  • Prioritize systems that run Java Web Start, applets, or other sandboxed/untrusted-code workflows.
  • Verify whether any business-critical applications still depend on affected legacy Java client behaviors and plan remediation windows accordingly.
  • Monitor affected endpoints for repeated hangs or crashes and confirm that patching removes the vulnerable runtime version.

Evidence notes

Primary evidence comes from the CISA CSAF advisory ICSA-26-134-10, published 2026-05-12 and republished 2026-05-14. The advisory body describes Oracle Java SE / Oracle GraalVM for JDK / Oracle GraalVM Enterprise Edition, with a DoS impact and a remediation of V5.0 or later. The provided wrapper metadata contains a vendor/product mismatch ('Siemens SIMATIC CN 4100 vers:intdot/<5.0') that does not align with the advisory description, so vendor attribution in the wrapper should be treated as low confidence.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-21945 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-21945

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-21945 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-21945

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.