CVE-2026-54798: Siemens CPCI85 Central Processing/communication

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application includes a debugging interface that is accessible through HTTP endpoints. This could allow an authenticated attacker to disrupt the system by crashing the web process causing denial of service conditions.

Affected products

  • Siemens CPCI85 Central Processing/communication: before V26.20 (fixed in V26.20)
  • Siemens Sicore Base System: before V26.20.0 (fixed in V26.20.0)

Published 2026-07-09. Last modified 2026-07-09.