CVE-2026-54799: Siemens CPCI85 Central Processing/communication
Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains a vulnerability in its firmware update mechanism's signature validation process. This could allow an attacker to install malicious firmware, leading to persistent code execution and system compromise.
Affected products
- Siemens CPCI85 Central Processing/communication: before V26.20 (fixed in V26.20)
- Siemens Sicore Base System: before V26.20.0 (fixed in V26.20.0)
Published 2026-07-09. Last modified 2026-07-09.