Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
High

Remote Operation DoS in Siemens SICAM A8000 CPCI85/RTUM85

IdentifiersCVE-2026-27663CWE-770· Allocation of Resources Without…

CVE-2026-27663 is a denial-of-service vulnerability in the remote operation mode of Siemens SICAM A8000 components CPCI85 Central Processing/Communication and RTUM85 RTU Base affecting all versions prior to V26.10. The flaw is caused by uncontrolled resource exhaustion/allocation without limits or throttling in the remote operation service. An attacker can trigger the condition by sending a high volume of requests; reporting indicates the issue can be induced with fewer than 100 crafted requests to the remote operation endpoint. Successful exploitation stalls the service so that the affected PLC can no longer be parameterized via Toolbox II, while the service may remain running but unusable until restarted or the device is rebooted.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation causes a denial-of-service condition in the affected remote operation functionality. The device can no longer be parameterized, interrupting operational management of the PLC. Recovery may require restarting the affected service through the web interface or rebooting/resetting the device, resulting in loss of availability of the parameterization function and operational disruption. Available information indicates no direct confidentiality or integrity impact, but availability impact is high.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, disable remote operation where it is not required, restrict network access to the device and remote operation service, and place affected systems behind firewalls with appropriate segmentation or VPN-controlled access. Minimize exposure of control-system devices, ensure they are not reachable from the internet, isolate OT networks from business networks, and enable the web interface if operationally appropriate so the stalled service can be restarted without a full reboot.

Remediation

Patch, then assume compromise.

Upgrade affected Siemens SICAM A8000 products using CPCI85 Central Processing/Communication or RTUM85 RTU Base to version V26.10 or later. Siemens has released fixes in V26.10 and recommends applying the provided security updates using the corresponding tooling and documented procedures, validating updates before deployment, and supervising the update process with trained staff.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
SiemensCpci85 Central Processing/Communicationapplication
SiemensRtum85 Rtu Basehardware

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

ACTIVITY FEED

Recent activity

4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.

No news coverage yet. Advisories and community discussion only.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity3

Community discussion across Reddit, Mastodon, and other social sources.