CYBERSECURITYTRACKER
TRACKING7,931 stories in this site build1,728 vulnerability news stories in this site build
Permanent story citation

Siemens SIPLUS and SIMATIC Products

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8189

As cited

Copy frozen at (site build).

ot ics

Siemens SIPLUS and SIMATIC Products

Siemens released security advisories for CVE-2026-31431, a Linux kernel vulnerability affecting numerous SIPLUS and SIMATIC product lines including runtime environments, human machine interface panels, and industrial edge devices. The vulnerability enables incorrect resource transfer between security spheres with a CVSS score of 7.8, and Siemens has released patched versions for most affected products while providing mitigation guidance for others.

Why it matters: Organizations running Siemens SIMATIC or SIPLUS industrial control systems and edge devices need to prioritize patching to version 21 Update 2 SR1 or later, as this actively exploited vulnerability allows local privilege escalation on affected Linux-based platforms.

VendorsVMwareLinux
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary