CVE-2026-27663Disclosure

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), RTUM85 RTU Base (All versions < V26.10). The affected application contains denial-of-service (DoS) vulnerability. The remote operation mode is susceptible to a resource exhaustion condition when subjected to a high volume of requests. Sending multiple requests can exhaust resources, preventing parameterization and requiring a reset or reboot to restore functionality.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-04-02); latest day: 1
  • 6 total mentions across 5 days

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-03-29: 1Mentions · 2026-04-02: 2Mentions · 2026-04-07: 1Mentions · 2026-04-13: 1Mentions · 2026-04-16: 1Patch / Workaround · 2026-04-02: 2Technical Details · 2026-04-02: 203-2904-0204-0704-1304-16
Signal classification3 categories
Disclosure
233.3%
Patch
233.3%
General
233.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-291
Disclosure1
2026-04-022
Patch2
2026-04-071
General1
2026-04-131
General1
2026-04-161
Disclosure1
Full discourse6 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Siemens ❗ CVE-2026-27664 ❗ CVE-2026-27663 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-siemens-4/ https://t.co/jZCIqOCGpF

    Post summary

    A brief notice lists two Siemens product vulnerabilities (CVE‑2026‑27664 and CVE‑2026‑27663) with links for additional information, but no further details are provided.

    0001083
    6.6K followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Disclosure

    🔒 #CyberSecurity Siemens SICAM 8: CVE-2026-27663 &amp; CVE-2026-27664 Detection and Remediation "CISA has released ICS Advisory ICSA-26-092-01 regarding critical vulnerabilities…" 🔗 https://securityarsenal.com/blog/siemens-sicam-8-cve-2026-27663-and-cve-2026-27664-detection-and-remediation #CyberSecurity #ThreatIntel #managedsoc #mdr #securitymonitoring

    Post summary

    The post announces a CISA advisory on Siemens SICAM 8 CVE‑2026‑27663 and CVE‑2026‑27664, linking to a blog for detection and remediation guidance.

    0000049
    10 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos WatchGuard ❗ CVE-2026-27664 ❗ CVE-2026-27663 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-watchguard-3/ https://t.co/I4LBCNdK6J

    Post summary

    The post lists two WatchGuard CVEs and links to a site for further details but offers no additional technical information, PoC, exploit, or patch details.

    0000094
    6.6K followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Multiple ICS Vulnerabilities: Hitachi Energy Ellipse JasperReports RCE; Siemens SICAM 8 DoS (XML parsing/resource exhaustion); Yokogawa CENTUM VP hard-coded PROG password 📅 **Timeline:** Disclosure: 2025-09-16, Patch: 2026-03-30 🆔 **CVE-2025-10492** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 59.43% 🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories 📂 **Affected Versions:** Hitachi Ellipse ≤9.0.50 🔧 **Fixed Versions:** Vendor guidance via Hitachi PSIRT/CISA (no fixed version listed) 🫨 **Attack Vectors:** - Java deserialization over network (remote code execution) 📝 **Summary:** A deserialization flaw in the JasperReports component used by Hitachi Ellipse allows remote code execution, risking full system compromise. Exploitation could disrupt ICS operations, impact safety, and enable lateral movement. 📈 **Impact Scope:** ICS/OT systems — remote code execution, potential operational disruption and safety risks. 🛡️ **Recommended Actions:** - Inventory Ellipse instances, isolate affected hosts, and follow Hitachi PSIRT/CISA guidance immediately - Block/validate untrusted deserialization inputs and apply vendor/third‑party library mitigations 🆔 **CVE-2026-27663** | 📊 CVSS: 6.5 (MEDIUM 🟡) | 📈 EPSS: 4.82% 🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories 📂 **Affected Versions:** Siemens CPCI85 <26.10, RTUM85 <26.10, SICORE <26.10.0 🔧 **Fixed Versions:** Siemens update ≥26.10 (SICORE 26.10.0+) 🫨 **Attack Vectors:** - High-volume request/resource exhaustion in remote operation mode (DoS) 📝 **Summary:** A resource-exhaustion vulnerability in Siemens SICAM 8 can cause service degradation or reboot via high-volume requests, impacting availability of control systems. Operational disruption risk is significant for exposed or poorly segmented deployments. 📈 **Impact Scope:** ICS/OT systems — denial-of-service affecting availability and operational continuity. 🛡️ **Recommended Actions:** - Apply Siemens security updates (≥26.10 / SICORE 26.10.0+) and isolate affected devices from untrusted networks - Implement rate-limiting, request validation, and monitoring for anomalous traffic volumes 🆔 **CVE-2026-27664** | 📊 CVSS: 7.5 (HIGH 🟠) | 📈 EPSS: 15.74% 🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories 📂 **Affected Versions:** Siemens CPCI85 <26.10, RTUM85 <26.10, SICORE <26.10.0 🔧 **Fixed Versions:** Siemens update ≥26.10 (SICORE 26.10.0+) 🫨 **Attack Vectors:** - Malformed XML over network leading to out-of-bounds write and service crash (DoS) 📝 **Summary:** A crafted XML input can trigger an out‑of‑bounds write in SICAM 8, causing service crashes and denial-of-service. This threatens availability of monitoring/control functions and may require manual recovery. 📈 **Impact Scope:** ICS/OT systems — denial-of-service and potential operational safety impacts. 🛡️ **Recommended Actions:** - Patch to Siemens 26.10+ (SICORE 26.10.0+) and restrict XML/protocol exposure via network controls - Add input validation, monitoring for crashes, and automated restart/detection safeguards 🆔 **CVE-2025-7741** | 📊 CVSS: 2.1 (LOW 🟢) | 📈 EPSS: 4.39% 🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories 📂 **Affected Versions:** CENTUM VP R5.01.00–<R5.04.20, R6.01.00–<R6.12.00, R7.01.00 🔧 **Fixed Versions:** CENTUM VP R7.01.10, use Windows Authentication for R5/R6 🫨 **Attack Vectors:** - Hard-coded PROG account password allowing authentication with HIS screen/local access 📝 **Summary:** A hard-coded PROG password in CENTUM VP permits authentication if an attacker can access HIS screens, enabling unauthorized actions and privilege misuse. Risk increases where PROG permissions were elevated or HIS access is insufficiently restricted. 📈 **Impact Scope:** ICS/OT systems — unauthorized access, privilege misuse, and potential operational impact. 🛡️ **Recommended Actions:** - Patch to R7.01.10 or switch affected R5/R6 branches to Windows Authentication; restrict HIS screen access - Rotate credentials where possible, enforce least privilege, and monitor PROG account usage 🪢 **Related Resources:** - https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-03 - https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-01 🏷 **Tags:** #Cybersecurity #ICS #OT

    Post summary

    The advisory announces several critical industrial control system vulnerabilities, outlines specific technical details and impact, and provides patch guidance, but no proof of concept or active exploitation is reported.

    00000159
    277 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Multiple ICS Vulnerabilities: Hitachi Ellipse JasperReports RCE; Siemens SICAM 8 DoS/Out-of-bounds; Yokogawa CENTUM VP Hard-coded Password 📅 **Timeline:** Disclosure: unknown, Patch: unknown 🆔 **CVE-2025-10492** | 📊 CVSS: 9.8 (Critical 🔴) | 📈 EPSS: 59.43% 🆔 **CVE-2026-27663** | 📊 CVSS: 6.5 (Medium 🟡) | 📈 EPSS: 4.82% 🆔 **CVE-2026-27664** | 📊 CVSS: 7.5 (High 🟠) | 📈 EPSS: 15.74% 🆔 **CVE-2025-7741** | 📊 CVSS: 4.0 (Low/Medium 🟢) | 📈 EPSS: 4.39% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Hitachi Ellipse ≤9.0.50, Siemens SICAM 8 family (CPCI85/RTUM85/SICORE) <26.10, Yokogawa CENTUM VP R5.x affected (>=R5.01.00 <R5.04.20), Yokogawa CENTUM VP R6.x affected (>=R6.01.00 <R6.12.00), Yokogawa CENTUM VP vR7.01.00 🔧 **Fixed Versions:** Yokogawa: CENTUM VP R7.01.10 (patch) or switch R5/R6 to Windows Auth, Siemens: apply latest SICAM 8 security updates, Hitachi: update Jaspersoft per PSIRT 🫨 **Attack Vectors:** - Java deserialization via Jaspersoft/JasperReports → remote code execution - High-volume remote requests causing resource exhaustion (DoS) - Malformed XML parsing → out-of-bounds write and service crash - Hard-coded PROG account password usable from HIS screen access (local/admin interface) 📝 **Summary:** Multiple high-impact ICS flaws affect Hitachi, Siemens and Yokogawa products: CVE-2025-10492 enables full RCE via a vulnerable Jaspersoft component in Hitachi Ellipse; CVE-2026-27663/27664 allow DoS and crashes in Siemens SICAM 8 components; CVE-2025-7741 is a hard-coded PROG password in Yokogawa CENTUM VP that can enable local privilege misuse. These issues threaten operational availability and can lead to full system compromise in critical manufacturing and energy environments. 📈 **Impact Scope:** Industrial control systems in critical manufacturing, energy, and related sectors; impacts include full RCE, denial-of-service/resource exhaustion and crashes, and local privilege misuse via hard-coded account. 🛡️ **Recommended Actions:** - Apply vendor-provided updates/patches immediately and follow PSIRT advisories - Isolate ICS/HMI networks, minimize exposure of management interfaces, and implement network-level filtering/throttling - Hitachi: remediate/upgrade vulnerable Jaspersoft per PSIRT; Siemens: deploy latest SICAM 8 security updates; Yokogawa: apply R7.01.10 patch or switch R5/R6 to Windows Authentication Mode and review PROG permissions - Monitor for abnormal requests, crashes, and unauthorized logins; test patches in lab before wide deployment 🪢 **Related Resources:** - https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-03 - https://www.cve.org/CVERecord?id=CVE-2025-10492 🏷 **Tags:** #Cybersecurity #ICS #OTsecurity (Remove commas and spaces between tags)

    Post summary

    This advisory details several critical Industrial Control System vulnerabilities, provides explicit patch information and remediation steps, and highlights the technical impact of each CVE, but it does not discuss exploitation or PoC availability.

    00000141
    277 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27663 A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions &lt; V26.10), RTUM85 RTU Base (All versions &lt; V26.10). The affected applicat… https://www.cve.org/CVERecord?id=CVE-2026-27663

    Post summary

    The text announces the identification of CVE‑2026‑27663 affecting older versions of CPCI85 and RTUM85, and provides a link to the official CVE record, with no exploit detail or mitigation information.

    00000184
    56.9K followersView on X

Explore more