Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
industrial-control-system-vulnerabilitywidely-deployed-product-advisorycritical-infrastructure-threat

Siemens SICAM 8 Flaws Expose OT Devices to Denial-of-Service

Updated 3mo agoFirst seen Mar 27, 20262 sources

Siemens disclosed multiple vulnerabilities in SICAM 8 industrial control system products affecting CPCI85 Central Processing/Communication, RTUM85 RTU Base, and the SICORE Base system, with vulnerable versions identified as releases prior to V26.10 or V26.10.0 depending on the product. The issues are tracked as CVE-2026-27663 and CVE-2026-27664, and can allow denial-of-service conditions in operational technology environments. Siemens published advisory SSA-246443, while the Canadian Centre for Cyber Security and CISA both urged asset owners to review the vendor guidance and apply the recommended updates.

According to CISA, CVE-2026-27663 is a resource exhaustion flaw in remote operation mode that can block parameterization and may require a reset or reboot, while CVE-2026-27664 is an out-of-bounds write triggered by specially crafted XML input that can crash the affected service. Siemens has released fixed versions and advised organizations to validate patches before deployment and harden network access with segmentation, firewalls, and VPNs; CISA further recommended minimizing internet exposure of control systems and isolating OT networks from business networks to reduce the risk of disruption.

Share:
Siemens SICAM 8 Flaws Expose OT Devices to Denial-of-Service
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Apr 2, 20263mo ago

CISA republishes Siemens SICAM 8 advisory

On 2026-04-02, CISA republished the Siemens advisory to increase visibility, detailing the two denial-of-service vulnerabilities and their impact on SICAM 8 components. CISA also recommended minimizing internet exposure, isolating OT networks, and using segmentation, firewalls, and VPNs.

Mar 27, 20263mo ago

Canadian Centre for Cyber Security issues notice on Siemens advisory

On 2026-03-27, the Canadian Centre for Cyber Security published alert AV26-290 highlighting Siemens' advisory and the affected industrial control system products. It urged administrators to review Siemens' guidance, follow mitigations, and apply the necessary updates.

Mar 26, 20263mo ago

Siemens publishes advisory for SICAM 8 vulnerabilities

On 2026-03-26, Siemens published advisory SSA-246443 covering multiple vulnerabilities in SICAM 8 products affecting CPCI85 Central Processing/Communication, RTUM85 RTU Base, and SICORE Base system. The advisory identified denial-of-service issues tracked as CVE-2026-27663 and CVE-2026-27664 and provided updated versions and mitigation guidance.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

9 LINKEDOpen in app
Affected products
4 linked
Cpci85 Central Processing/CommunicationSicam S8000Sicore Base SystemRtum85 Rtu Base
Organizations
3 linked
SiemensCyberDanubeVERBUND Digital Power
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.