Technology · Siemens
Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 204 vulnerabilities in Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP: 0 in the last 7 days and 0 in the last 90 days, 10 of them critical and 1 exploited in the wild. The most recent, CVE-2026-43057, was published on 1 May 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 10
- Exploited in the wild
- 1
About Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP
A high-end industrial controller with integrated Multi-Functional Platform capabilities for complex automation tasks.
Latest Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP vulnerabilities
- CVE-2026-43057: Linux Kernel denial of service in IPv6 tunneled traffic handlinghighCVSS 7.5EPSS 0.4%
- CVE-2026-43040: Linux Kernel information leak in IPv6 ndisc nduseroptmsghighCVSS 7.1EPSS 0.1%
- CVE-2026-43035: Linux kernel information leak in tc_chain_fill_nodemediumCVSS 5.5EPSS 0.1%
- CVE-2026-43033: Linux Kernel memory corruption in crypto authencesn decryptionhighCVSS 7.8EPSS 0.1%
- CVE-2026-43030: Linux Kernel BPF verifier incorrect state pruning in regsafehighCVSS 7.8EPSS 0.1%
- CVE-2026-43028: Linux Kernel Netfilter missing null-termination in x_tableshighCVSS 7.1EPSS 0.1%
- CVE-2026-43027: Linux Kernel use-after-free in Netfilter nf_conntrack_helperhighCVSS 7.8EPSS 0.1%
- CVE-2026-43026: Linux Kernel Netfilter uninitialized memory use in ctnetlinkmediumCVSS 5.5EPSS 0.1%
- CVE-2026-43025: Linux Kernel Netfilter out-of-bounds read in ctnetlinkhighCVSS 7.3EPSS 0.1%
- CVE-2026-43024: Linux Kernel denial of service in netfilter nf_tablesmediumCVSS 5.5EPSS 0.1%
- CVE-2026-43011: Linux Kernel double free in net/x25 networking stackcriticalCVSS 9.8EPSS 0.5%
- CVE-2026-31768: Linux Kernel ti-adc161s626 DMA-safe memory corruptionhighCVSS 7.8EPSS 0.1%
- CVE-2026-31761: Linux Kernel race condition in MPU-3050 gyroscope driverhighCVSS 7.8EPSS 0.1%
- CVE-2026-31752: Linux Kernel out-of-bounds read in bridge ND option parsingmediumCVSS 5.5EPSS 0.1%
- CVE-2026-31737: Linux Kernel ftgmac100 resource leak in ring allocation failuremediumCVSS 5.5EPSS 0.1%
- CVE-2026-5435: GNU glibc out-of-bounds write in ns_printrrf TSIG handlinghighCVSS 7.3EPSS 0.2%
- CVE-2026-31682: Linux Kernel out-of-bounds read in bridge br_nd_sendcriticalCVSS 9.1EPSS 0.4%
- CVE-2026-31680: Linux Kernel use-after-free in IPv6 flowlabelhighCVSS 7.8EPSS 0.1%
- CVE-2026-31674: Linux Kernel out-of-bounds access in netfilter ip6t_rthighCVSS 7.1EPSS 0.1%
- CVE-2026-31671: Linux Kernel information leak in xfrm_user build_reportmediumCVSS 5.5EPSS 0.1%
- CVE-2026-31670: Linux Kernel memory exhaustion in rfkill subsystemmediumCVSS 5.5EPSS 0.1%
- CVE-2026-31669: Linux Kernel slab-use-after-free in MPTCP IPv6 subflowcriticalCVSS 9.8EPSS 0.4%
- CVE-2026-31665: Linux Kernel use-after-free in Netfilter nft_ct timeout objecthighCVSS 7.8EPSS 0.1%
- CVE-2026-31658: Linux Kernel memory leak in Altera TSE Ethernet drivermediumCVSS 5.5EPSS 0.1%
- CVE-2026-31651: Linux Kernel NULL pointer dereference in vub300 MMC drivermediumCVSS 5.5EPSS 0.1%
Most severe Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-39964: Linux Kernel race condition in af_alg_sendmsgcriticalexploited in the wildCVSS 3.3EPSS 1.0%
- CVE-2026-43011: Linux Kernel double free in net/x25 networking stackcriticalCVSS 9.8EPSS 0.5%
- CVE-2026-5450: GNU glibc heap buffer overflow in scanf %mc specifiercriticalCVSS 9.8EPSS 0.4%
- CVE-2026-31649: Linux Kernel stmmac integer underflow in jumbo_frmcriticalCVSS 9.8EPSS 0.4%
- CVE-2026-31669: Linux Kernel slab-use-after-free in MPTCP IPv6 subflowcriticalCVSS 9.8EPSS 0.4%
- CVE-2026-31533: Linux Kernel use-after-free in net/tls encryption error pathcriticalCVSS 9.8EPSS 0.3%
- CVE-2025-38724: Linux Kernel nfsd use-after-free in nfsd4_setclientid_confirmcriticalCVSS 9.8EPSS 0.2%
- CVE-2025-38708: Linux Kernel use after free in DRBD handle_write_conflictscriticalCVSS 9.8EPSS 0.2%
- CVE-2026-31448: Linux Kernel infinite loop in ext4 file system extent mappingcriticalCVSS 9.4EPSS 0.4%
- CVE-2026-31682: Linux Kernel out-of-bounds read in bridge br_nd_sendcriticalCVSS 9.1EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518-4-pn-dp-mfp.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP vulnerabilities", https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518-4-pn-dp-mfp, 26 September 2026.