PatchSiren cyber security CVE debrief
CVE-2026-54800 Siemens CVE debrief
The CVE-2026-54800 vulnerability affects Siemens CPCI85 Central Processing/Communication and SICORE Base system. The vulnerability class involves a default configuration that disables all OPC UA security mechanisms, potentially allowing unauthorized access and control. Likely operational impact includes compromised system integrity and unauthorized access to critical system functions. Source-confidence limits are based on CVE description and source item metadata, which indicate limited information about affected scope and exploitability. Review context suggests that defenders should verify system configurations, review OPC UA security mechanism settings, and ensure proper security measures are in place. The CVE record was published on 2026-07-09T00:00:00.000Z and has not been modified since then. It is recommended that organizations using these systems review system configurations, implement compensating controls, and prioritize updating to the latest firmware versions.
- Vendor
- Siemens
- Product
- CPCI85 Central Processing/Communication
- CVSS
- MEDIUM 4.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-09
- Original CVE updated
- 2026-07-16
- Advisory published
- 2026-07-09
- Advisory updated
- 2026-07-16
Who should care
Organizations using Siemens CPCI85 Central Processing/Communication and SICORE Base system, especially those in industrial control systems (ICS) environments, should be aware of this vulnerability and take necessary actions to mitigate potential risks. Operators, platform administrators, and security teams should review system configurations, implement compensating controls, and prioritize updating to the latest firmware versions.
Technical summary
The Siemens CPCI85 Central Processing/Communication and SICORE Base system are affected by a vulnerability that allows unauthorized access and control due to a default configuration that disables all OPC UA security mechanisms. The vulnerability has a CVSS score of 4.8 and is classified as MEDIUM severity. Affected organizations should review system configurations, implement additional security measures, and update to the latest firmware versions to mitigate potential risks.
Defensive priority
Organizations using Siemens CPCI85 Central Processing/Communication and SICORE Base system should prioritize updating to the latest firmware versions to mitigate potential unauthorized access and control over critical system functions.
Recommended defensive actions
- Update to V26.20 or later version for CPCI85 Central Processing/Communication
- Update to V26.20.0 or later version for SICORE Base system
- Implement additional security measures to compensate for the default insecure configuration
- Monitor system logs for suspicious activity
- Perform regular security audits and vulnerability assessments
Evidence notes
The CVE description and source item metadata indicate that the affected application ships with a default configuration that disables all OPC UA security mechanisms, potentially allowing unauthorized access and control. However, detailed information about affected scope and exploitability is limited. Defenders should verify system configurations, review OPC UA security mechanism settings, and ensure proper security measures are in place.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-54800 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-54800
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-54800 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-54800
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-197-05.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-229470.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-229470.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-05
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.