Security Advisory

CVE-2026-27664

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-03-26 14:03:21
Last updated 2026-04-14 18:24:39
Assigner siemens
State PUBLISHED

Description

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), SICORE Base system (All versions < V26.10.0). The affected application contains an out-of-bounds write vulnerability while parsing specially crafted XML inputs. This could allow an unauthenticated attacker to exploit this issue by sending a malicious XML request, which may cause the service to crash, resulting in a denial-of-service condition.