CVE-2026-54800: Siemens CPCI85 Central Processing/communication
Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an attacker to gain unauthorized access and control over critical system functions.
Affected products
- Siemens CPCI85 Central Processing/communication: before V26.20 (fixed in V26.20)
- Siemens Sicore Base System: before V26.20.0 (fixed in V26.20.0)
Published 2026-07-09. Last modified 2026-07-09.