PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-54800 Siemens CVE debrief

The CVE-2026-54800 vulnerability affects Siemens CPCI85 Central Processing/Communication and SICORE Base system. The vulnerability class involves a default configuration that disables all OPC UA security mechanisms, potentially allowing unauthorized access and control. Likely operational impact includes compromised system integrity and unauthorized access to critical system functions. Source-confidence limits are based on CVE description and source item metadata, which indicate limited information about affected scope and exploitability. Review context suggests that defenders should verify system configurations, review OPC UA security mechanism settings, and ensure proper security measures are in place. The CVE record was published on 2026-07-09T00:00:00.000Z and has not been modified since then. It is recommended that organizations using these systems review system configurations, implement compensating controls, and prioritize updating to the latest firmware versions.

Vendor
Siemens
Product
CPCI85 Central Processing/Communication
CVSS
MEDIUM 4.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-09
Original CVE updated
2026-07-16
Advisory published
2026-07-09
Advisory updated
2026-07-16

Who should care

Organizations using Siemens CPCI85 Central Processing/Communication and SICORE Base system, especially those in industrial control systems (ICS) environments, should be aware of this vulnerability and take necessary actions to mitigate potential risks. Operators, platform administrators, and security teams should review system configurations, implement compensating controls, and prioritize updating to the latest firmware versions.

Technical summary

The Siemens CPCI85 Central Processing/Communication and SICORE Base system are affected by a vulnerability that allows unauthorized access and control due to a default configuration that disables all OPC UA security mechanisms. The vulnerability has a CVSS score of 4.8 and is classified as MEDIUM severity. Affected organizations should review system configurations, implement additional security measures, and update to the latest firmware versions to mitigate potential risks.

Defensive priority

Organizations using Siemens CPCI85 Central Processing/Communication and SICORE Base system should prioritize updating to the latest firmware versions to mitigate potential unauthorized access and control over critical system functions.

Recommended defensive actions

  • Update to V26.20 or later version for CPCI85 Central Processing/Communication
  • Update to V26.20.0 or later version for SICORE Base system
  • Implement additional security measures to compensate for the default insecure configuration
  • Monitor system logs for suspicious activity
  • Perform regular security audits and vulnerability assessments

Evidence notes

The CVE description and source item metadata indicate that the affected application ships with a default configuration that disables all OPC UA security mechanisms, potentially allowing unauthorized access and control. However, detailed information about affected scope and exploitability is limited. Defenders should verify system configurations, review OPC UA security mechanism settings, and ensure proper security measures are in place.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-54800 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-54800

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-54800 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-54800

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-197-05.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-229470.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-229470.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-05

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.