CVE-2026-54800: Siemens CPCI85 Central Processing/communication

Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an attacker to gain unauthorized access and control over critical system functions.

Affected products

  • Siemens CPCI85 Central Processing/communication: before V26.20 (fixed in V26.20)
  • Siemens Sicore Base System: before V26.20.0 (fixed in V26.20.0)

Published 2026-07-09. Last modified 2026-07-09.