CVE-2026-27663: Siemens CPCI85 Central Processing/communication
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), RTUM85 RTU Base (All versions < V26.10). The affected application contains denial-of-service (DoS) vulnerability. The remote operation mode is susceptible to a resource exhaustion condition when subjected to a high volume of requests. Sending multiple requests can exhaust resources, preventing parameterization and requiring a reset or reboot to restore functionality.
Affected products
- Siemens CPCI85 Central Processing/communication: before V26.10 (fixed in V26.10)
- Siemens RTUM85 Rtu Base: before V26.10 (fixed in V26.10)
Published 2026-03-26. Last modified 2026-06-17.