PatchSiren cyber security CVE debrief
CVE-2026-21945 Siemens CVE debrief
CVE-2026-21945 is a network-reachable denial-of-service vulnerability affecting Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. The advisory says an unauthenticated attacker can trigger a hang or repeatable crash, resulting in availability loss. Oracle’s note also narrows the practical exposure: it is aimed at Java client deployments that load and execute untrusted code under the Java sandbox, such as Java Web Start applications or applets, and does not apply to typical trusted-code server deployments.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Teams responsible for Oracle Java SE, Oracle GraalVM for JDK, or Oracle GraalVM Enterprise Edition should care most, especially where affected runtimes are installed on client endpoints or legacy desktop environments that still use Java Web Start, applets, or other sandboxed code paths. Patch management, endpoint security, and vulnerability management teams should also prioritize it for internet-connected or user-facing fleets.
Technical summary
The advisory describes an unauthenticated, network-accessible availability issue with CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (7.5). Successful exploitation can cause a hang or repeatedly reproducible crash, but the provided source text does not indicate confidentiality or integrity impact. The advisory explicitly limits the affected usage model to Java deployments that rely on the sandbox for untrusted code; it states that deployments running only trusted code in server-style environments are not in scope.
Defensive priority
High for affected client or desktop Java deployments; lower for trusted-code server deployments that match the advisory’s exclusion language.
Recommended defensive actions
- Inventory Java SE and GraalVM versions across endpoints and client systems, with special attention to the versions named in the advisory.
- Upgrade to the vendor-fixed release described in the source remediation guidance: V5.0 or later.
- Prioritize systems that run Java Web Start, applets, or other sandboxed/untrusted-code workflows.
- Verify whether any business-critical applications still depend on affected legacy Java client behaviors and plan remediation windows accordingly.
- Monitor affected endpoints for repeated hangs or crashes and confirm that patching removes the vulnerable runtime version.
Evidence notes
Primary evidence comes from the CISA CSAF advisory ICSA-26-134-10, published 2026-05-12 and republished 2026-05-14. The advisory body describes Oracle Java SE / Oracle GraalVM for JDK / Oracle GraalVM Enterprise Edition, with a DoS impact and a remediation of V5.0 or later. The provided wrapper metadata contains a vendor/product mismatch ('Siemens SIMATIC CN 4100 vers:intdot/<5.0') that does not align with the advisory description, so vendor attribution in the wrapper should be treated as low confidence.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-21945 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-21945
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-21945 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-21945
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.