Exploitation ongoing with high activity in latest observed window (1 mentions)
Immediate actions
Patch affected systems immediately
Assume compromise if assets are exposed
Recommended action window: Immediate (within 24h)
NVD description
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), SICORE Base system (All versions < V26.10.0). The affected application contains an out-of-bounds write vulnerability while parsing specially crafted XML inputs. This could allow an unauthenticated attacker to exploit this issue by sending a malicious XML request, which may cause the service to crash, resulting in a denial-of-service condition.
⚠️ Vulnerabilidades en productos Siemens
❗ CVE-2026-27664
❗ CVE-2026-27663
➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-siemens-4/ https://t.co/jZCIqOCGpF
Post summary
The tweet announces two new Siemens product vulnerabilities (CVE-2026-27664 and CVE-2026-27663) and directs readers to a link for additional information.
CVE-2026-27664 A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), SICORE Base system (All versions < V26.10.0). The affected app… https://www.cve.org/CVERecord?id=CVE-2026-27664
Post summary
The excerpt announces the identification of CVE-2026‑27664 affecting certain CPCI85 and SICORE Base system versions but provides no further exploitation, patch, or technical details.
🔒 #CyberSecurity
Siemens SICAM 8: CVE-2026-27663 & CVE-2026-27664 Detection and Remediation
"CISA has released ICS Advisory ICSA-26-092-01 regarding critical vulnerabilities…"
🔗 https://securityarsenal.com/blog/siemens-sicam-8-cve-2026-27663-and-cve-2026-27664-detection-and-remediation
#CyberSecurity#ThreatIntel#managedsoc#mdr#securitymonitoring
Post summary
An advisory (ICSA‑26‑092‑01) was issued for two Siemens SICAM 8 vulnerabilities (CVE‑2026‑27663 & 27664), providing detection and remediation guidance via the referenced blog.
⚠️ **Vulnerability Alert:** Multiple ICS Vulnerabilities: Hitachi Energy Ellipse JasperReports RCE; Siemens SICAM 8 DoS (XML parsing/resource exhaustion); Yokogawa CENTUM VP hard-coded PROG password
📅 **Timeline:** Disclosure: 2025-09-16, Patch: 2026-03-30
🆔 **CVE-2025-10492** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 59.43%
🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories
📂 **Affected Versions:** Hitachi Ellipse ≤9.0.50
🔧 **Fixed Versions:** Vendor guidance via Hitachi PSIRT/CISA (no fixed version listed)
🫨 **Attack Vectors:**
- Java deserialization over network (remote code execution)
📝 **Summary:**
A deserialization flaw in the JasperReports component used by Hitachi Ellipse allows remote code execution, risking full system compromise. Exploitation could disrupt ICS operations, impact safety, and enable lateral movement.
📈 **Impact Scope:** ICS/OT systems — remote code execution, potential operational disruption and safety risks.
🛡️ **Recommended Actions:**
- Inventory Ellipse instances, isolate affected hosts, and follow Hitachi PSIRT/CISA guidance immediately
- Block/validate untrusted deserialization inputs and apply vendor/third‑party library mitigations
🆔 **CVE-2026-27663** | 📊 CVSS: 6.5 (MEDIUM 🟡) | 📈 EPSS: 4.82%
🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories
📂 **Affected Versions:** Siemens CPCI85 <26.10, RTUM85 <26.10, SICORE <26.10.0
🔧 **Fixed Versions:** Siemens update ≥26.10 (SICORE 26.10.0+)
🫨 **Attack Vectors:**
- High-volume request/resource exhaustion in remote operation mode (DoS)
📝 **Summary:**
A resource-exhaustion vulnerability in Siemens SICAM 8 can cause service degradation or reboot via high-volume requests, impacting availability of control systems. Operational disruption risk is significant for exposed or poorly segmented deployments.
📈 **Impact Scope:** ICS/OT systems — denial-of-service affecting availability and operational continuity.
🛡️ **Recommended Actions:**
- Apply Siemens security updates (≥26.10 / SICORE 26.10.0+) and isolate affected devices from untrusted networks
- Implement rate-limiting, request validation, and monitoring for anomalous traffic volumes
🆔 **CVE-2026-27664** | 📊 CVSS: 7.5 (HIGH 🟠) | 📈 EPSS: 15.74%
🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories
📂 **Affected Versions:** Siemens CPCI85 <26.10, RTUM85 <26.10, SICORE <26.10.0
🔧 **Fixed Versions:** Siemens update ≥26.10 (SICORE 26.10.0+)
🫨 **Attack Vectors:**
- Malformed XML over network leading to out-of-bounds write and service crash (DoS)
📝 **Summary:**
A crafted XML input can trigger an out‑of‑bounds write in SICAM 8, causing service crashes and denial-of-service. This threatens availability of monitoring/control functions and may require manual recovery.
📈 **Impact Scope:** ICS/OT systems — denial-of-service and potential operational safety impacts.
🛡️ **Recommended Actions:**
- Patch to Siemens 26.10+ (SICORE 26.10.0+) and restrict XML/protocol exposure via network controls
- Add input validation, monitoring for crashes, and automated restart/detection safeguards
🆔 **CVE-2025-7741** | 📊 CVSS: 2.1 (LOW 🟢) | 📈 EPSS: 4.39%
🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories
📂 **Affected Versions:** CENTUM VP R5.01.00–<R5.04.20, R6.01.00–<R6.12.00, R7.01.00
🔧 **Fixed Versions:** CENTUM VP R7.01.10, use Windows Authentication for R5/R6
🫨 **Attack Vectors:**
- Hard-coded PROG account password allowing authentication with HIS screen/local access
📝 **Summary:**
A hard-coded PROG password in CENTUM VP permits authentication if an attacker can access HIS screens, enabling unauthorized actions and privilege misuse. Risk increases where PROG permissions were elevated or HIS access is insufficiently restricted.
📈 **Impact Scope:** ICS/OT systems — unauthorized access, privilege misuse, and potential operational impact.
🛡️ **Recommended Actions:**
- Patch to R7.01.10 or switch affected R5/R6 branches to Windows Authentication; restrict HIS screen access
- Rotate credentials where possible, enforce least privilege, and monitor PROG account usage
🪢 **Related Resources:**
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-03
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-01
🏷 **Tags:** #Cybersecurity#ICS#OT
Post summary
The bulletin announces several critical and moderate CVEs affecting Hitachi and Siemens. It provides technical details, patch information, and mitigation steps, but reports no active exploitation or proof-of-concept code.
A lot of offensive activities were identified targeting Siemens CPCI85 Central Processing Communication and SICORE Base system (CVE-2026-27664) https://vuldb.com/?ctiid.353636
Post summary
The statement indicates that CVE-2026-27664 is actively targeted by offensive actors against Siemens CPCI85 and SICORE systems, but no patch or detailed technical info is provided.
There is a new vulnerability with elevated criticality in Siemens CPCI85 Central Processing Communication and SICORE Base system (CVE-2026-27664) https://vuldb.com/?id.353636
Post summary
The post announces a newly disclosed high‑severity vulnerability (CVE‑2026‑27664) affecting Siemens CPCI85 and SICORE Base systems, with a reference link to VulDB for further details.