Executive Summary
In March 2026, Siemens identified two critical vulnerabilities in its SICAM 8 industrial control products: CVE-2026-27663 and CVE-2026-27664. CVE-2026-27663 is a denial-of-service vulnerability in CPCI85 and RTUM85 devices, where high-volume requests can exhaust system resources, leading to operational disruptions. CVE-2026-27664 is an out-of-bounds write vulnerability in CPCI85 and SICORE systems, exploitable through specially crafted XML inputs, potentially causing service crashes. Siemens has released firmware updates (V26.10 and V26.10.0) to address these issues. (sentinelone.com)
These vulnerabilities highlight the ongoing risks in industrial control systems, emphasizing the need for timely patch management and robust network security measures to protect critical infrastructure from potential cyber threats.
Why This Matters Now
The discovery of these vulnerabilities underscores the critical importance of securing industrial control systems against cyber threats, as exploitation could lead to significant operational disruptions in critical infrastructure sectors.
Attack Path Analysis
An attacker exploited vulnerabilities in Siemens SICAM 8 products by sending specially crafted XML requests, leading to denial-of-service conditions. The attack did not involve privilege escalation, lateral movement, command and control, or data exfiltration, but resulted in significant operational disruption.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited vulnerabilities in Siemens SICAM 8 products by sending specially crafted XML requests, leading to denial-of-service conditions.
Related CVEs
CVE-2026-27663
CVSS 6.5A denial-of-service vulnerability in Siemens SICAM 8 products allows remote attackers to exhaust resources by sending multiple requests, preventing parameterization and requiring a reset or reboot to restore functionality.
Affected Products:
Siemens CPCI85 Central Processing/Communication – < 26.10
Siemens RTUM85 RTU Base – < 26.10
Exploit Status:
no public exploitCVE-2026-27664
CVSS 7.5An out-of-bounds write vulnerability in Siemens SICAM 8 products allows unauthenticated attackers to send specially crafted XML inputs, potentially causing the service to crash and resulting in a denial-of-service condition.
Affected Products:
Siemens CPCI85 Central Processing/Communication – < 26.10
Siemens SICORE Base system – < 26.10.0
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Endpoint Denial of Service
Exploitation for Client Execution
Valid Accounts
External Remote Services
Exfiltration Over Alternative Protocol
Network Denial of Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 – Flaw Remediation
Control ID: SI-2
PCI DSS 4.0 – System and Application Security
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Data
Control ID: Pillar 3
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Critical power grid infrastructure faces denial-of-service vulnerabilities in SICAM systems, requiring immediate firmware updates to prevent operational disruptions and maintain grid reliability.
Oil/Energy/Solar/Greentech
Energy control systems vulnerable to resource exhaustion and XML parsing attacks, threatening SCADA operations and requiring enhanced network segmentation and monitoring capabilities.
Critical Manufacturing
Industrial control systems using Siemens SICAM products exposed to out-of-bounds write vulnerabilities, demanding immediate patching and improved east-west traffic security implementations.
Government Administration
Critical infrastructure protection mandates require addressing SICAM vulnerabilities through zero trust segmentation and enhanced threat detection to prevent cascading operational failures.
Sources
- Siemens SICAM 8 Productshttps://www.cisa.gov/news-events/ics-advisories/icsa-26-092-01Verified
- Siemens ProductCERT Security Advisory SSA-246443https://cert-portal.siemens.com/productcert/html/ssa-246443.htmlVerified
- NVD - CVE-2026-27663https://nvd.nist.gov/vuln/detail/CVE-2026-27663Verified
- NVD - CVE-2026-27664https://nvd.nist.gov/vuln/detail/CVE-2026-27664Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to exploit vulnerabilities in Siemens SICAM 8 products, thereby reducing the operational disruption caused by the denial-of-service conditions.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit vulnerabilities in Siemens SICAM 8 products would likely have been constrained, reducing the potential for denial-of-service conditions.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely have been constrained, reducing the potential for further exploitation.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the network would likely have been constrained, reducing the potential for further exploitation.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control infrastructure would likely have been constrained, reducing the potential for persistent access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate data would likely have been constrained, reducing the potential for data loss.
The operational disruption caused by the denial-of-service conditions would likely have been constrained, reducing the potential for prolonged downtime.
Impact at a Glance
Affected Business Functions
- Substation Automation
- Grid Monitoring
- Energy Management
Estimated downtime: 2 days
Estimated loss: $50,000
n/a
Recommended Actions
Key Takeaways & Next Steps
- • Implement network segmentation to restrict access to critical systems.
- • Deploy intrusion prevention systems (IPS) to detect and block malicious traffic patterns.
- • Regularly update and patch systems to address known vulnerabilities.
- • Conduct thorough input validation to prevent exploitation of parsing vulnerabilities.
- • Establish robust monitoring to detect and respond to denial-of-service attacks promptly.



