CVE-2026-54799: Siemens CPCI85 Central Processing/communication

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains a vulnerability in its firmware update mechanism's signature validation process. This could allow an attacker to install malicious firmware, leading to persistent code execution and system compromise.

Affected products

  • Siemens CPCI85 Central Processing/communication: before V26.20 (fixed in V26.20)
  • Siemens Sicore Base System: before V26.20.0 (fixed in V26.20.0)

Published 2026-07-09. Last modified 2026-07-09.