Technology · Siemens
Siemens SIMATIC CN 4100 vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 74 vulnerabilities in Siemens SIMATIC CN 4100: 0 in the last 7 days and 0 in the last 90 days, 11 of them critical and 2 exploited in the wild. The most recent, CVE-2026-22925, was published on 12 May 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 11
- Exploited in the wild
- 2
Latest Siemens SIMATIC CN 4100 vulnerabilities
- CVE-2026-22925: Siemens SIMATIC CN 4100 resource exhaustion via TCP SYN floodhighCVSS 7.5EPSS 0.3%
- CVE-2026-22924: Siemens SIMATIC CN 4100 missing authentication and resource exhaustioncriticalCVSS 9.1EPSS 0.3%
- CVE-2026-31431: Linux Kernel crypto algif_aead improper memory handlingcriticalexploited in the wildCVSS 7.8EPSS 2.6%
- CVE-2026-31790: OpenSSL uninitialized memory disclosure in RSASVE key encapsulationhighCVSS 7.5EPSS 1.2%
- CVE-2026-31789: OpenSSL heap buffer overflow in buf2hex conversioncriticalCVSS 9.8EPSS 0.2%
- CVE-2026-28390: OpenSSL NULL pointer dereference in CMS EnvelopedData processinghighCVSS 7.5EPSS 1.0%
- CVE-2026-28389: OpenSSL NULL pointer dereference in CMS EnvelopedData processinghighCVSS 7.5EPSS 1.0%
- CVE-2026-28388: OpenSSL NULL pointer dereference in delta CRL processinghighCVSS 7.5EPSS 1.1%
- CVE-2026-28387: OpenSSL use-after-free in DANE TLSA-based authenticationhighCVSS 8.1EPSS 0.8%
- CVE-2026-21947: Oracle Java SE XSS in JavaFXlowCVSS 3.1
- CVE-2026-21945: Oracle Java SE and GraalVM denial of service in Security componenthighCVSS 7.5EPSS 0.5%
- CVE-2026-21933: Oracle Java SE and GraalVM networking data manipulationmediumCVSS 6.1
- CVE-2026-21932: Oracle Java SE improper URI handling in AWT and JavaFXhighCVSS 7.4EPSS 0.3%
- CVE-2026-21925: Oracle Java SE and GraalVM data manipulation in RMImediumCVSS 4.8
- CVE-2025-61795: Apache Tomcat DoS via delayed cleanup of multipart temporary filesmediumCVSS 5.3EPSS 1.2%
- CVE-2025-55752: Apache Tomcat relative path traversal in URL rewrite normalizationhighCVSS 7.5
- CVE-2025-61748: Oracle Java SE and GraalVM improper access control in LibrarieslowCVSS 3.7
- CVE-2025-39866: Linux Kernel use-after-free in __mark_inode_dirtyhighCVSS 7.8EPSS 0.3%
- CVE-2025-39857: Linux Kernel NULL pointer dereference in net/smchighCVSS 7.5EPSS 0.1%
- CVE-2025-39849: Linux Kernel out-of-bounds write in cfg80211 SME SSID handlinghighCVSS 8.8EPSS 0.1%
- CVE-2025-39848: Linux Kernel memory corruption in ax25_kiss_rcvhighCVSS 8.8EPSS 0.1%
- CVE-2025-39845: Linux Kernel x86_64 page table synchronization failuremediumCVSS 5.5EPSS 0.1%
- CVE-2025-39827: Linux Kernel slab-use-after-free in ROSE network protocolmediumCVSS 5.5EPSS 0.1%
- CVE-2025-39826: Linux Kernel use-after-free in ROSE networking protocolhighCVSS 7EPSS 0.1%
- CVE-2025-39825: Linux Kernel SMB client race condition in rename operationhighCVSS 7.8EPSS 0.1%
Most severe Siemens SIMATIC CN 4100 vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-39682: Linux Kernel memory corruption in TLS zero-length record handlingcriticalexploited in the wildCVSS 9.8EPSS 2.9%
- CVE-2026-31431: Linux Kernel crypto algif_aead improper memory handlingcriticalexploited in the wildCVSS 7.8EPSS 2.6%
- CVE-2026-31789: OpenSSL heap buffer overflow in buf2hex conversioncriticalCVSS 9.8EPSS 0.2%
- CVE-2025-38724: Linux Kernel nfsd use-after-free in nfsd4_setclientid_confirmcriticalCVSS 9.8EPSS 0.2%
- CVE-2025-38708: Linux Kernel use after free in DRBD handle_write_conflictscriticalCVSS 9.8EPSS 0.2%
- CVE-2025-39703: Linux kernel denial of service in HSR frame processingcriticalCVSS 9.8EPSS 0.1%
- CVE-2025-39702: Linux Kernel timing attack in IPv6 Segment Routing HMAC validationcriticalCVSS 9.8EPSS 0.1%
- CVE-2025-39673: Linux Kernel race condition in ppp_fill_forward_pathcriticalCVSS 9.8EPSS 0.1%
- CVE-2025-38552: Linux Kernel race condition in MPTCP subflow creationcriticalCVSS 9.4EPSS 0.2%
- CVE-2026-22924: Siemens SIMATIC CN 4100 missing authentication and resource exhaustioncriticalCVSS 9.1EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/simatic-cn-4100.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Siemens SIMATIC CN 4100 vulnerabilities", https://junglewise.ai/threats/technologies/simatic-cn-4100, 26 September 2026.