{"schema_version":1,"title":"Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 83 vulnerabilities in Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP: 0 in the last 7 days and 0 in the last 90 days, 5 of them critical and 1 exploited in the wild. The most recent, CVE-2026-43040, was published on 1 May 2026.","url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518f-4-pn-dp-mfp","json_url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518f-4-pn-dp-mfp.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518f-4-pn-dp-mfp","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":33,"all_time":83,"critical":5,"exploited":1,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":78},"latest":[{"cve":"CVE-2026-43040","cvss":7.1,"epss":0.0012,"slug":"cve-2026-43040-linux-kernel-information-leak-in-ipv6-ndisc-nduseroptmsg","title":"Linux Kernel information leak in IPv6 ndisc nduseroptmsg","severity":"high","exploited":false,"published_at":"2026-05-01T15:16:50.13+00:00","url":"https://junglewise.ai/threats/cve-2026-43040-linux-kernel-information-leak-in-ipv6-ndisc-nduseroptmsg"},{"cve":"CVE-2026-43035","cvss":5.5,"epss":0.0012,"slug":"cve-2026-43035-linux-kernel-information-leak-in-tc-chain-fill-node","title":"Linux kernel information leak in tc_chain_fill_node","severity":"medium","exploited":false,"published_at":"2026-05-01T15:16:48.147+00:00","url":"https://junglewise.ai/threats/cve-2026-43035-linux-kernel-information-leak-in-tc-chain-fill-node"},{"cve":"CVE-2026-43033","cvss":7.8,"epss":0.0013,"slug":"cve-2026-43033-linux-kernel-memory-corruption-in-crypto-authencesn-decryption","title":"Linux Kernel memory corruption in crypto authencesn decryption","severity":"high","exploited":false,"published_at":"2026-05-01T15:16:47.91+00:00","url":"https://junglewise.ai/threats/cve-2026-43033-linux-kernel-memory-corruption-in-crypto-authencesn-decryption"},{"cve":"CVE-2026-43030","cvss":7.8,"epss":0.0013,"slug":"cve-2026-43030-linux-kernel-bpf-verifier-incorrect-state-pruning-in-regsafe","title":"Linux Kernel BPF verifier incorrect state pruning in regsafe","severity":"high","exploited":false,"published_at":"2026-05-01T15:16:47.557+00:00","url":"https://junglewise.ai/threats/cve-2026-43030-linux-kernel-bpf-verifier-incorrect-state-pruning-in-regsafe"},{"cve":"CVE-2026-43028","cvss":7.1,"epss":0.0013,"slug":"cve-2026-43028-linux-kernel-netfilter-missing-null-termination-in-x-tables","title":"Linux Kernel Netfilter missing null-termination in x_tables","severity":"high","exploited":false,"published_at":"2026-05-01T15:16:47.297+00:00","url":"https://junglewise.ai/threats/cve-2026-43028-linux-kernel-netfilter-missing-null-termination-in-x-tables"},{"cve":"CVE-2026-43027","cvss":7.8,"epss":0.0013,"slug":"cve-2026-43027-linux-kernel-use-after-free-in-netfilter-nf-conntrack-helper","title":"Linux Kernel use-after-free in Netfilter nf_conntrack_helper","severity":"high","exploited":false,"published_at":"2026-05-01T15:16:47.167+00:00","url":"https://junglewise.ai/threats/cve-2026-43027-linux-kernel-use-after-free-in-netfilter-nf-conntrack-helper"},{"cve":"CVE-2026-43026","cvss":5.5,"epss":0.0012,"slug":"cve-2026-43026-linux-kernel-netfilter-uninitialized-memory-use-in-ctnetlink","title":"Linux Kernel Netfilter uninitialized memory use in ctnetlink","severity":"medium","exploited":false,"published_at":"2026-05-01T15:16:47.033+00:00","url":"https://junglewise.ai/threats/cve-2026-43026-linux-kernel-netfilter-uninitialized-memory-use-in-ctnetlink"},{"cve":"CVE-2026-43025","cvss":7.3,"epss":0.0013,"slug":"cve-2026-43025-linux-kernel-netfilter-out-of-bounds-read-in-ctnetlink","title":"Linux Kernel Netfilter out-of-bounds read in ctnetlink","severity":"high","exploited":false,"published_at":"2026-05-01T15:16:46.903+00:00","url":"https://junglewise.ai/threats/cve-2026-43025-linux-kernel-netfilter-out-of-bounds-read-in-ctnetlink"},{"cve":"CVE-2026-43011","cvss":9.8,"epss":0.0051,"slug":"cve-2026-43011-linux-kernel-double-free-in-net-x25-networking-stack","title":"Linux Kernel double free in net/x25 networking stack","severity":"critical","exploited":false,"published_at":"2026-05-01T15:16:44.993+00:00","url":"https://junglewise.ai/threats/cve-2026-43011-linux-kernel-double-free-in-net-x25-networking-stack"},{"cve":"CVE-2026-31768","cvss":7.8,"epss":0.0013,"slug":"cve-2026-31768-linux-kernel-ti-adc161s626-dma-safe-memory-corruption","title":"Linux Kernel ti-adc161s626 DMA-safe memory corruption","severity":"high","exploited":false,"published_at":"2026-05-01T15:16:39.977+00:00","url":"https://junglewise.ai/threats/cve-2026-31768-linux-kernel-ti-adc161s626-dma-safe-memory-corruption"},{"cve":"CVE-2026-31752","cvss":5.5,"epss":0.0012,"slug":"cve-2026-31752-linux-kernel-out-of-bounds-read-in-bridge-nd-option-parsing","title":"Linux Kernel out-of-bounds read in bridge ND option parsing","severity":"medium","exploited":false,"published_at":"2026-05-01T15:16:38.09+00:00","url":"https://junglewise.ai/threats/cve-2026-31752-linux-kernel-out-of-bounds-read-in-bridge-nd-option-parsing"},{"cve":"CVE-2026-31737","cvss":5.5,"epss":0.0012,"slug":"cve-2026-31737-linux-kernel-ftgmac100-resource-leak-in-ring-allocation-failure","title":"Linux Kernel ftgmac100 resource leak in ring allocation failure","severity":"medium","exploited":false,"published_at":"2026-05-01T15:16:36.347+00:00","url":"https://junglewise.ai/threats/cve-2026-31737-linux-kernel-ftgmac100-resource-leak-in-ring-allocation-failure"},{"cve":"CVE-2026-5435","cvss":7.3,"epss":0.002,"slug":"cve-2026-5435-gnu-glibc-out-of-bounds-write-in-ns-printrrf-tsig-handling","title":"GNU glibc out-of-bounds write in ns_printrrf TSIG handling","severity":"high","exploited":false,"published_at":"2026-04-28T13:19:22.29+00:00","url":"https://junglewise.ai/threats/cve-2026-5435-gnu-glibc-out-of-bounds-write-in-ns-printrrf-tsig-handling"},{"cve":"CVE-2026-31682","cvss":9.1,"epss":0.0042,"slug":"cve-2026-31682-linux-kernel-out-of-bounds-read-in-bridge-br-nd-send","title":"Linux Kernel out-of-bounds read in bridge br_nd_send","severity":"critical","exploited":false,"published_at":"2026-04-25T09:16:01.913+00:00","url":"https://junglewise.ai/threats/cve-2026-31682-linux-kernel-out-of-bounds-read-in-bridge-br-nd-send"},{"cve":"CVE-2026-31680","cvss":7.8,"epss":0.0012,"slug":"cve-2026-31680-linux-kernel-use-after-free-in-ipv6-flowlabel","title":"Linux Kernel use-after-free in IPv6 flowlabel","severity":"high","exploited":false,"published_at":"2026-04-25T09:16:01.673+00:00","url":"https://junglewise.ai/threats/cve-2026-31680-linux-kernel-use-after-free-in-ipv6-flowlabel"},{"cve":"CVE-2026-31674","cvss":7.1,"epss":0.0012,"slug":"cve-2026-31674-linux-kernel-out-of-bounds-access-in-netfilter-ip6t-rt","title":"Linux Kernel out-of-bounds access in netfilter ip6t_rt","severity":"high","exploited":false,"published_at":"2026-04-25T09:16:00.963+00:00","url":"https://junglewise.ai/threats/cve-2026-31674-linux-kernel-out-of-bounds-access-in-netfilter-ip6t-rt"},{"cve":"CVE-2026-31671","cvss":5.5,"epss":0.0011,"slug":"cve-2026-31671-linux-kernel-information-leak-in-xfrm-user-build-report","title":"Linux Kernel information leak in xfrm_user build_report","severity":"medium","exploited":false,"published_at":"2026-04-24T15:16:46.903+00:00","url":"https://junglewise.ai/threats/cve-2026-31671-linux-kernel-information-leak-in-xfrm-user-build-report"},{"cve":"CVE-2026-31670","cvss":5.5,"epss":0.0011,"slug":"cve-2026-31670-linux-kernel-memory-exhaustion-in-rfkill-subsystem","title":"Linux Kernel memory exhaustion in rfkill subsystem","severity":"medium","exploited":false,"published_at":"2026-04-24T15:16:46.79+00:00","url":"https://junglewise.ai/threats/cve-2026-31670-linux-kernel-memory-exhaustion-in-rfkill-subsystem"},{"cve":"CVE-2026-31628","cvss":5.5,"epss":0.0013,"slug":"cve-2026-31628-linux-kernel-information-disclosure-in-amd-zen1-hardware-divider","title":"Linux Kernel information disclosure in AMD Zen1 hardware divider","severity":"medium","exploited":false,"published_at":"2026-04-24T15:16:42.103+00:00","url":"https://junglewise.ai/threats/cve-2026-31628-linux-kernel-information-disclosure-in-amd-zen1-hardware-divider"},{"cve":"CVE-2026-31563","cvss":7.5,"epss":0.0048,"slug":"cve-2026-31563-linux-kernel-dos-in-macb-network-driver-via-invalid-irq-context","title":"Linux Kernel DoS in macb network driver via invalid IRQ context","severity":"high","exploited":false,"published_at":"2026-04-24T15:16:30.72+00:00","url":"https://junglewise.ai/threats/cve-2026-31563-linux-kernel-dos-in-macb-network-driver-via-invalid-irq-context"},{"cve":"CVE-2026-31555","cvss":5.5,"epss":0.0012,"slug":"cve-2026-31555-linux-kernel-stale-pointer-in-futex-lock-pi-retry-path","title":"Linux Kernel stale pointer in futex_lock_pi retry path","severity":"medium","exploited":false,"published_at":"2026-04-24T15:16:29.837+00:00","url":"https://junglewise.ai/threats/cve-2026-31555-linux-kernel-stale-pointer-in-futex-lock-pi-retry-path"},{"cve":"CVE-2026-31546","cvss":5.5,"epss":0.0012,"slug":"cve-2026-31546-linux-kernel-null-pointer-dereference-in-bonding-debugfs","title":"Linux Kernel NULL pointer dereference in bonding debugfs","severity":"medium","exploited":false,"published_at":"2026-04-24T15:16:28.69+00:00","url":"https://junglewise.ai/threats/cve-2026-31546-linux-kernel-null-pointer-dereference-in-bonding-debugfs"},{"cve":"CVE-2026-31533","cvss":9.8,"epss":0.0026,"slug":"cve-2026-31533-linux-kernel-use-after-free-in-net-tls-encryption-error-path","title":"Linux Kernel use-after-free in net/tls encryption error path","severity":"critical","exploited":false,"published_at":"2026-04-23T18:16:26.857+00:00","url":"https://junglewise.ai/threats/cve-2026-31533-linux-kernel-use-after-free-in-net-tls-encryption-error-path"},{"cve":"CVE-2026-41989","cvss":6.7,"epss":0.0018,"slug":"cve-2026-41989-gnupg-libgcrypt-heap-buffer-overflow-in-ecdh-decryption","title":"GnuPG Libgcrypt heap buffer overflow in ECDH decryption","severity":"medium","exploited":false,"published_at":"2026-04-23T05:16:05.75+00:00","url":"https://junglewise.ai/threats/cve-2026-41989-gnupg-libgcrypt-heap-buffer-overflow-in-ecdh-decryption"},{"cve":"CVE-2026-31521","cvss":5.5,"epss":0.0012,"slug":"cve-2026-31521-linux-kernel-out-of-bounds-read-in-module-loader-simplify-symbols","title":"Linux Kernel out-of-bounds read in module loader simplify_symbols","severity":"medium","exploited":false,"published_at":"2026-04-22T14:16:51.93+00:00","url":"https://junglewise.ai/threats/cve-2026-31521-linux-kernel-out-of-bounds-read-in-module-loader-simplify-symbols"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","slug":"simatic-s7-1500-cpu-1518-4-pn-dp-mfp","vulnerabilities":204,"url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518-4-pn-dp-mfp"},{"name":"Siemens SIMATIC CN 4100","slug":"simatic-cn-4100","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/simatic-cn-4100"},{"name":"Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP","slug":"siplus-s7-1500-cpu-1518-4-pn-dp-mfp","vulnerabilities":70,"url":"https://junglewise.ai/threats/technologies/siplus-s7-1500-cpu-1518-4-pn-dp-mfp"},{"name":"Siemens RUGGEDCOM APE1808","slug":"ruggedcom-ape1808","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/ruggedcom-ape1808"},{"name":"Siemens RUGGEDCOM RST2428P","slug":"ruggedcom-rst2428p","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/ruggedcom-rst2428p"},{"name":"Siemens ROX II","slug":"rox-ii","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/rox-ii"},{"name":"Siemens SINEC OS","slug":"sinec-os","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/sinec-os"},{"name":"Siemens Solid Edge","slug":"solid-edge","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/solid-edge"},{"name":"Siemens SIMATIC S7-1500 TM MFP GNU/Linux subsystem","slug":"simatic-s7-1500-tm-mfp-gnu-linux-subsystem","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-tm-mfp-gnu-linux-subsystem"},{"name":"Siemens Ruggedcom Rox II","slug":"ruggedcom-rox-ii","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/ruggedcom-rox-ii"},{"name":"Siemens Reyrolle 7SR5","slug":"reyrolle-7sr5","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/reyrolle-7sr5"},{"name":"Siemens Simcenter Femap","slug":"simcenter-femap","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/simcenter-femap"}],"technology":{"hub":true,"name":"Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","slug":"simatic-s7-1500-cpu-1518f-4-pn-dp-mfp","vendor":{"name":"Siemens","slug":"siemens","url":"https://junglewise.ai/threats/vendors/siemens"},"aliases":[],"category":"industrial-control-system-hardware","homepage":"https://www.siemens.com/global/en/products/automation/systems/industrial/simatic-s7-1500.html","description":"A high-performance fail-safe central processing unit for the SIMATIC S7-1500 controller family with multifunctional platform capabilities.","url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518f-4-pn-dp-mfp"},"most_severe":[{"cve":"CVE-2025-39964","cvss":3.3,"epss":0.01,"slug":"cve-2025-39964-linux-kernel-race-condition-in-af-alg-sendmsg","title":"Linux Kernel race condition in af_alg_sendmsg","severity":"critical","exploited":true,"published_at":"2025-10-13T14:15:34.737+00:00","url":"https://junglewise.ai/threats/cve-2025-39964-linux-kernel-race-condition-in-af-alg-sendmsg"},{"cve":"CVE-2026-43011","cvss":9.8,"epss":0.0051,"slug":"cve-2026-43011-linux-kernel-double-free-in-net-x25-networking-stack","title":"Linux Kernel double free in net/x25 networking stack","severity":"critical","exploited":false,"published_at":"2026-05-01T15:16:44.993+00:00","url":"https://junglewise.ai/threats/cve-2026-43011-linux-kernel-double-free-in-net-x25-networking-stack"},{"cve":"CVE-2026-5450","cvss":9.8,"epss":0.0045,"slug":"cve-2026-5450-gnu-glibc-heap-buffer-overflow-in-scanf-mc-specifier","title":"GNU glibc heap buffer overflow in scanf %mc specifier","severity":"critical","exploited":false,"published_at":"2026-04-20T21:16:36.85+00:00","url":"https://junglewise.ai/threats/cve-2026-5450-gnu-glibc-heap-buffer-overflow-in-scanf-mc-specifier"},{"cve":"CVE-2026-31533","cvss":9.8,"epss":0.0026,"slug":"cve-2026-31533-linux-kernel-use-after-free-in-net-tls-encryption-error-path","title":"Linux Kernel use-after-free in net/tls encryption error path","severity":"critical","exploited":false,"published_at":"2026-04-23T18:16:26.857+00:00","url":"https://junglewise.ai/threats/cve-2026-31533-linux-kernel-use-after-free-in-net-tls-encryption-error-path"},{"cve":"CVE-2026-31682","cvss":9.1,"epss":0.0042,"slug":"cve-2026-31682-linux-kernel-out-of-bounds-read-in-bridge-br-nd-send","title":"Linux Kernel out-of-bounds read in bridge br_nd_send","severity":"critical","exploited":false,"published_at":"2026-04-25T09:16:01.913+00:00","url":"https://junglewise.ai/threats/cve-2026-31682-linux-kernel-out-of-bounds-read-in-bridge-br-nd-send"},{"cve":"CVE-2025-71162","cvss":7.8,"epss":0.0019,"slug":"cve-2025-71162-linux-kernel-tegra-adma-use-after-free-in-audio-termination","title":"Linux Kernel Tegra ADMA use-after-free in audio termination","severity":"high","exploited":false,"published_at":"2026-01-25T15:15:53.947+00:00","url":"https://junglewise.ai/threats/cve-2025-71162-linux-kernel-tegra-adma-use-after-free-in-audio-termination"},{"cve":"CVE-2025-39683","cvss":7.8,"epss":0.0016,"slug":"cve-2025-39683-linux-kernel-slab-out-of-bounds-read-in-ftrace-tracing-subsystem","title":"Linux Kernel slab-out-of-bounds read in ftrace tracing subsystem","severity":"high","exploited":false,"published_at":"2025-09-05T18:15:44.81+00:00","url":"https://junglewise.ai/threats/cve-2025-39683-linux-kernel-slab-out-of-bounds-read-in-ftrace-tracing-subsystem"},{"cve":"CVE-2025-38704","cvss":7.8,"epss":0.0016,"slug":"cve-2025-38704-linux-kernel-invalid-pointer-access-in-rcu-nocb-offload","title":"Linux Kernel invalid pointer access in RCU NOCB offload","severity":"high","exploited":false,"published_at":"2025-09-04T16:15:39.263+00:00","url":"https://junglewise.ai/threats/cve-2025-38704-linux-kernel-invalid-pointer-access-in-rcu-nocb-offload"},{"cve":"CVE-2025-39787","cvss":7.8,"epss":0.0015,"slug":"cve-2025-39787-linux-kernel-qualcomm-mdt-loader-buffer-over-read","title":"Linux Kernel Qualcomm MDT loader buffer over-read","severity":"high","exploited":false,"published_at":"2025-09-11T17:15:44.907+00:00","url":"https://junglewise.ai/threats/cve-2025-39787-linux-kernel-qualcomm-mdt-loader-buffer-over-read"},{"cve":"CVE-2025-38499","cvss":7.8,"epss":0.0015,"slug":"cve-2025-38499-linux-kernel-missing-cap-sys-admin-check-in-clone-private-mnt","title":"Linux Kernel missing CAP_SYS_ADMIN check in clone_private_mnt","severity":"high","exploited":false,"published_at":"2025-08-11T16:15:30.057+00:00","url":"https://junglewise.ai/threats/cve-2025-38499-linux-kernel-missing-cap-sys-admin-check-in-clone-private-mnt"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}