CVE-2026-27664Disclosure

MEDIUMCVSS 8.7 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), SICORE Base system (All versions < V26.10.0). The affected application contains an out-of-bounds write vulnerability while parsing specially crafted XML inputs. This could allow an unauthenticated attacker to exploit this issue by sending a malicious XML request, which may cause the service to crash, resulting in a denial-of-service condition.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 2 mentions (2026-03-26); latest day: 1
  • 8 total mentions across 6 days

Deep dive

Activity timeline8 mentions / 6d
01122Mentions · 2026-03-26: 2Mentions · 2026-03-29: 1Mentions · 2026-04-02: 2Mentions · 2026-04-07: 1Mentions · 2026-04-13: 1Mentions · 2026-04-16: 1Active Exploitation · 2026-03-26: 1Patch / Workaround · 2026-04-02: 2Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-02: 203-2603-2904-0204-0704-1304-16
Signal classification4 categories
Disclosure
337.5%
General
225.0%
Patch
225.0%
Active Exploitation
112.5%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-262
Active Exploitation1Disclosure1
2026-03-291
General1
2026-04-022
Disclosure1Patch1
2026-04-071
General1
2026-04-131
Disclosure1
2026-04-161
Patch1
Full discourse8 posts
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Siemens ❗ CVE-2026-27664 ❗ CVE-2026-27663 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-siemens-4/ https://t.co/jZCIqOCGpF

    Post summary

    The tweet announces two new Siemens product vulnerabilities (CVE-2026-27664 and CVE-2026-27663) and directs readers to a link for additional information.

    0001083
    6.6K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27664 A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions &lt; V26.10), SICORE Base system (All versions &lt; V26.10.0). The affected app… https://www.cve.org/CVERecord?id=CVE-2026-27664

    Post summary

    The excerpt announces the identification of CVE-2026‑27664 affecting certain CPCI85 and SICORE Base system versions but provides no further exploitation, patch, or technical details.

    00010112
    56.9K followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity Siemens SICAM 8: CVE-2026-27663 &amp; CVE-2026-27664 Detection and Remediation "CISA has released ICS Advisory ICSA-26-092-01 regarding critical vulnerabilities…" 🔗 https://securityarsenal.com/blog/siemens-sicam-8-cve-2026-27663-and-cve-2026-27664-detection-and-remediation #CyberSecurity #ThreatIntel #managedsoc #mdr #securitymonitoring

    Post summary

    An advisory (ICSA‑26‑092‑01) was issued for two Siemens SICAM 8 vulnerabilities (CVE‑2026‑27663 & 27664), providing detection and remediation guidance via the referenced blog.

    0000049
    10 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos WatchGuard ❗ CVE-2026-27664 ❗ CVE-2026-27663 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-watchguard-3/ https://t.co/I4LBCNdK6J

    Post summary

    The post lists two WatchGuard CVEs with links for further info but provides no concrete details on exploits, patches, or vulnerability specifics.

    0000094
    6.6K followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Multiple ICS Vulnerabilities: Hitachi Ellipse JasperReports RCE; Siemens SICAM 8 DoS/Out-of-bounds; Yokogawa CENTUM VP Hard-coded Password 📅 **Timeline:** Disclosure: unknown, Patch: unknown 🆔 **CVE-2025-10492** | 📊 CVSS: 9.8 (Critical 🔴) | 📈 EPSS: 59.43% 🆔 **CVE-2026-27663** | 📊 CVSS: 6.5 (Medium 🟡) | 📈 EPSS: 4.82% 🆔 **CVE-2026-27664** | 📊 CVSS: 7.5 (High 🟠) | 📈 EPSS: 15.74% 🆔 **CVE-2025-7741** | 📊 CVSS: 4.0 (Low/Medium 🟢) | 📈 EPSS: 4.39% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Hitachi Ellipse ≤9.0.50, Siemens SICAM 8 family (CPCI85/RTUM85/SICORE) <26.10, Yokogawa CENTUM VP R5.x affected (>=R5.01.00 <R5.04.20), Yokogawa CENTUM VP R6.x affected (>=R6.01.00 <R6.12.00), Yokogawa CENTUM VP vR7.01.00 🔧 **Fixed Versions:** Yokogawa: CENTUM VP R7.01.10 (patch) or switch R5/R6 to Windows Auth, Siemens: apply latest SICAM 8 security updates, Hitachi: update Jaspersoft per PSIRT 🫨 **Attack Vectors:** - Java deserialization via Jaspersoft/JasperReports → remote code execution - High-volume remote requests causing resource exhaustion (DoS) - Malformed XML parsing → out-of-bounds write and service crash - Hard-coded PROG account password usable from HIS screen access (local/admin interface) 📝 **Summary:** Multiple high-impact ICS flaws affect Hitachi, Siemens and Yokogawa products: CVE-2025-10492 enables full RCE via a vulnerable Jaspersoft component in Hitachi Ellipse; CVE-2026-27663/27664 allow DoS and crashes in Siemens SICAM 8 components; CVE-2025-7741 is a hard-coded PROG password in Yokogawa CENTUM VP that can enable local privilege misuse. These issues threaten operational availability and can lead to full system compromise in critical manufacturing and energy environments. 📈 **Impact Scope:** Industrial control systems in critical manufacturing, energy, and related sectors; impacts include full RCE, denial-of-service/resource exhaustion and crashes, and local privilege misuse via hard-coded account. 🛡️ **Recommended Actions:** - Apply vendor-provided updates/patches immediately and follow PSIRT advisories - Isolate ICS/HMI networks, minimize exposure of management interfaces, and implement network-level filtering/throttling - Hitachi: remediate/upgrade vulnerable Jaspersoft per PSIRT; Siemens: deploy latest SICAM 8 security updates; Yokogawa: apply R7.01.10 patch or switch R5/R6 to Windows Authentication Mode and review PROG permissions - Monitor for abnormal requests, crashes, and unauthorized logins; test patches in lab before wide deployment 🪢 **Related Resources:** - https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-03 - https://www.cve.org/CVERecord?id=CVE-2025-10492 🏷 **Tags:** #Cybersecurity #ICS #OTsecurity (Remove commas and spaces between tags)

    Post summary

    The notice outlines several critical industrial control system vulnerabilities and emphasizes immediate vendor patches and mitigation steps.

    00000141
    277 followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Multiple ICS Vulnerabilities: Hitachi Energy Ellipse JasperReports RCE; Siemens SICAM 8 DoS (XML parsing/resource exhaustion); Yokogawa CENTUM VP hard-coded PROG password 📅 **Timeline:** Disclosure: 2025-09-16, Patch: 2026-03-30 🆔 **CVE-2025-10492** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 59.43% 🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories 📂 **Affected Versions:** Hitachi Ellipse ≤9.0.50 🔧 **Fixed Versions:** Vendor guidance via Hitachi PSIRT/CISA (no fixed version listed) 🫨 **Attack Vectors:** - Java deserialization over network (remote code execution) 📝 **Summary:** A deserialization flaw in the JasperReports component used by Hitachi Ellipse allows remote code execution, risking full system compromise. Exploitation could disrupt ICS operations, impact safety, and enable lateral movement. 📈 **Impact Scope:** ICS/OT systems — remote code execution, potential operational disruption and safety risks. 🛡️ **Recommended Actions:** - Inventory Ellipse instances, isolate affected hosts, and follow Hitachi PSIRT/CISA guidance immediately - Block/validate untrusted deserialization inputs and apply vendor/third‑party library mitigations 🆔 **CVE-2026-27663** | 📊 CVSS: 6.5 (MEDIUM 🟡) | 📈 EPSS: 4.82% 🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories 📂 **Affected Versions:** Siemens CPCI85 <26.10, RTUM85 <26.10, SICORE <26.10.0 🔧 **Fixed Versions:** Siemens update ≥26.10 (SICORE 26.10.0+) 🫨 **Attack Vectors:** - High-volume request/resource exhaustion in remote operation mode (DoS) 📝 **Summary:** A resource-exhaustion vulnerability in Siemens SICAM 8 can cause service degradation or reboot via high-volume requests, impacting availability of control systems. Operational disruption risk is significant for exposed or poorly segmented deployments. 📈 **Impact Scope:** ICS/OT systems — denial-of-service affecting availability and operational continuity. 🛡️ **Recommended Actions:** - Apply Siemens security updates (≥26.10 / SICORE 26.10.0+) and isolate affected devices from untrusted networks - Implement rate-limiting, request validation, and monitoring for anomalous traffic volumes 🆔 **CVE-2026-27664** | 📊 CVSS: 7.5 (HIGH 🟠) | 📈 EPSS: 15.74% 🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories 📂 **Affected Versions:** Siemens CPCI85 <26.10, RTUM85 <26.10, SICORE <26.10.0 🔧 **Fixed Versions:** Siemens update ≥26.10 (SICORE 26.10.0+) 🫨 **Attack Vectors:** - Malformed XML over network leading to out-of-bounds write and service crash (DoS) 📝 **Summary:** A crafted XML input can trigger an out‑of‑bounds write in SICAM 8, causing service crashes and denial-of-service. This threatens availability of monitoring/control functions and may require manual recovery. 📈 **Impact Scope:** ICS/OT systems — denial-of-service and potential operational safety impacts. 🛡️ **Recommended Actions:** - Patch to Siemens 26.10+ (SICORE 26.10.0+) and restrict XML/protocol exposure via network controls - Add input validation, monitoring for crashes, and automated restart/detection safeguards 🆔 **CVE-2025-7741** | 📊 CVSS: 2.1 (LOW 🟢) | 📈 EPSS: 4.39% 🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories 📂 **Affected Versions:** CENTUM VP R5.01.00–<R5.04.20, R6.01.00–<R6.12.00, R7.01.00 🔧 **Fixed Versions:** CENTUM VP R7.01.10, use Windows Authentication for R5/R6 🫨 **Attack Vectors:** - Hard-coded PROG account password allowing authentication with HIS screen/local access 📝 **Summary:** A hard-coded PROG password in CENTUM VP permits authentication if an attacker can access HIS screens, enabling unauthorized actions and privilege misuse. Risk increases where PROG permissions were elevated or HIS access is insufficiently restricted. 📈 **Impact Scope:** ICS/OT systems — unauthorized access, privilege misuse, and potential operational impact. 🛡️ **Recommended Actions:** - Patch to R7.01.10 or switch affected R5/R6 branches to Windows Authentication; restrict HIS screen access - Rotate credentials where possible, enforce least privilege, and monitor PROG account usage 🪢 **Related Resources:** - https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-03 - https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-01 🏷 **Tags:** #Cybersecurity #ICS #OT

    Post summary

    The bulletin announces several critical and moderate CVEs affecting Hitachi and Siemens. It provides technical details, patch information, and mitigation steps, but reports no active exploitation or proof-of-concept code.

    00000159
    277 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting Siemens CPCI85 Central Processing Communication and SICORE Base system (CVE-2026-27664) https://vuldb.com/?ctiid.353636

    Post summary

    The statement indicates that CVE-2026-27664 is actively targeted by offensive actors against Siemens CPCI85 and SICORE systems, but no patch or detailed technical info is provided.

    0000070
    2.1K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Siemens CPCI85 Central Processing Communication and SICORE Base system (CVE-2026-27664) https://vuldb.com/?id.353636

    Post summary

    The post announces a newly disclosed high‑severity vulnerability (CVE‑2026‑27664) affecting Siemens CPCI85 and SICORE Base systems, with a reference link to VulDB for further details.

    0000067
    2.1K followersView on X

Explore more