CISA has published an ICS advisory for Siemens SICAM 8 products (including CPCI85 and SICORE base systems used in energy and critical manufacturing). The flaws (CVE-2026-54798 through CVE-2026-54801) span active debug code exposed via HTTP endpoints, initialization of a resource with an insecure default, and — notably from an identity perspective — an unverified password change weakness. These could enable authenticated attackers to disrupt operation or manipulate credential controls.
While the primary impact described is denial of service, the unverified password change and insecure default initialization issues touch directly on access-control integrity in OT environments. Siemens has released fixed versions (26.20 and later) and recommends updating.
What to take away: even in industrial systems, weaknesses in password-change verification and default credential handling can undermine identity assurance; organizations running SICAM 8 should patch and audit access controls promptly.