Technology · Siemens
Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 83 vulnerabilities in Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP: 0 in the last 7 days and 0 in the last 90 days, 5 of them critical and 1 exploited in the wild. The most recent, CVE-2026-43040, was published on 1 May 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 5
- Exploited in the wild
- 1
About Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
A high-performance fail-safe central processing unit for the SIMATIC S7-1500 controller family with multifunctional platform capabilities.
Latest Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP vulnerabilities
- CVE-2026-43040: Linux Kernel information leak in IPv6 ndisc nduseroptmsghighCVSS 7.1EPSS 0.1%
- CVE-2026-43035: Linux kernel information leak in tc_chain_fill_nodemediumCVSS 5.5EPSS 0.1%
- CVE-2026-43033: Linux Kernel memory corruption in crypto authencesn decryptionhighCVSS 7.8EPSS 0.1%
- CVE-2026-43030: Linux Kernel BPF verifier incorrect state pruning in regsafehighCVSS 7.8EPSS 0.1%
- CVE-2026-43028: Linux Kernel Netfilter missing null-termination in x_tableshighCVSS 7.1EPSS 0.1%
- CVE-2026-43027: Linux Kernel use-after-free in Netfilter nf_conntrack_helperhighCVSS 7.8EPSS 0.1%
- CVE-2026-43026: Linux Kernel Netfilter uninitialized memory use in ctnetlinkmediumCVSS 5.5EPSS 0.1%
- CVE-2026-43025: Linux Kernel Netfilter out-of-bounds read in ctnetlinkhighCVSS 7.3EPSS 0.1%
- CVE-2026-43011: Linux Kernel double free in net/x25 networking stackcriticalCVSS 9.8EPSS 0.5%
- CVE-2026-31768: Linux Kernel ti-adc161s626 DMA-safe memory corruptionhighCVSS 7.8EPSS 0.1%
- CVE-2026-31752: Linux Kernel out-of-bounds read in bridge ND option parsingmediumCVSS 5.5EPSS 0.1%
- CVE-2026-31737: Linux Kernel ftgmac100 resource leak in ring allocation failuremediumCVSS 5.5EPSS 0.1%
- CVE-2026-5435: GNU glibc out-of-bounds write in ns_printrrf TSIG handlinghighCVSS 7.3EPSS 0.2%
- CVE-2026-31682: Linux Kernel out-of-bounds read in bridge br_nd_sendcriticalCVSS 9.1EPSS 0.4%
- CVE-2026-31680: Linux Kernel use-after-free in IPv6 flowlabelhighCVSS 7.8EPSS 0.1%
- CVE-2026-31674: Linux Kernel out-of-bounds access in netfilter ip6t_rthighCVSS 7.1EPSS 0.1%
- CVE-2026-31671: Linux Kernel information leak in xfrm_user build_reportmediumCVSS 5.5EPSS 0.1%
- CVE-2026-31670: Linux Kernel memory exhaustion in rfkill subsystemmediumCVSS 5.5EPSS 0.1%
- CVE-2026-31628: Linux Kernel information disclosure in AMD Zen1 hardware dividermediumCVSS 5.5EPSS 0.1%
- CVE-2026-31563: Linux Kernel DoS in macb network driver via invalid IRQ contexthighCVSS 7.5EPSS 0.5%
- CVE-2026-31555: Linux Kernel stale pointer in futex_lock_pi retry pathmediumCVSS 5.5EPSS 0.1%
- CVE-2026-31546: Linux Kernel NULL pointer dereference in bonding debugfsmediumCVSS 5.5EPSS 0.1%
- CVE-2026-31533: Linux Kernel use-after-free in net/tls encryption error pathcriticalCVSS 9.8EPSS 0.3%
- CVE-2026-41989: GnuPG Libgcrypt heap buffer overflow in ECDH decryptionmediumCVSS 6.7EPSS 0.2%
- CVE-2026-31521: Linux Kernel out-of-bounds read in module loader simplify_symbolsmediumCVSS 5.5EPSS 0.1%
Most severe Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-39964: Linux Kernel race condition in af_alg_sendmsgcriticalexploited in the wildCVSS 3.3EPSS 1.0%
- CVE-2026-43011: Linux Kernel double free in net/x25 networking stackcriticalCVSS 9.8EPSS 0.5%
- CVE-2026-5450: GNU glibc heap buffer overflow in scanf %mc specifiercriticalCVSS 9.8EPSS 0.4%
- CVE-2026-31533: Linux Kernel use-after-free in net/tls encryption error pathcriticalCVSS 9.8EPSS 0.3%
- CVE-2026-31682: Linux Kernel out-of-bounds read in bridge br_nd_sendcriticalCVSS 9.1EPSS 0.4%
- CVE-2025-71162: Linux Kernel Tegra ADMA use-after-free in audio terminationhighCVSS 7.8EPSS 0.2%
- CVE-2025-39683: Linux Kernel slab-out-of-bounds read in ftrace tracing subsystemhighCVSS 7.8EPSS 0.2%
- CVE-2025-38704: Linux Kernel invalid pointer access in RCU NOCB offloadhighCVSS 7.8EPSS 0.2%
- CVE-2025-39787: Linux Kernel Qualcomm MDT loader buffer over-readhighCVSS 7.8EPSS 0.1%
- CVE-2025-38499: Linux Kernel missing CAP_SYS_ADMIN check in clone_private_mnthighCVSS 7.8EPSS 0.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518f-4-pn-dp-mfp.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP vulnerabilities", https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518f-4-pn-dp-mfp, 26 September 2026.