How can operators check whether their Siemens SIPLUS or SIMATIC product is affected by CVE-2026-31431?

Operators should start with the CISA ICS advisory released on September 22, 2026 and compare their Siemens product name and version against the affected list.
What to check first
The advisory says multiple Siemens SIPLUS and SIMATIC products are affected by the Copy Fail vulnerability associated with CVE-2026-31431.
The affected list includes:
- SIMATIC AX Runtime Core Linux components
- SIMATIC CN 4100
- multiple SIMATIC HMI MTP1000 Unified panel variants
How to use that information
Check the exact product family first, then compare the installed release against the advisory and Siemens’ update guidance.
If your product appears in the affected list and an updated version exists, Siemens advises moving to the latest release. If a fix is not available yet, or is still being prepared, Siemens recommends specific countermeasures.
Keep the advisory close
The context does not include every affected version or every countermeasure. For an operational check, use CISA’s advisory and Siemens’ latest release information before deciding whether a system is clear.
What should users do if an updated Siemens SIPLUS or SIMATIC release is available?

If an updated Siemens SIPLUS or SIMATIC release is available for an affected product, Siemens’ guidance is to move to the latest release.
The practical step
For products affected by the Copy Fail vulnerability, the confirmed recommendation is straightforward: update to the latest available version when Siemens has issued one.
CISA’s September 22, 2026 advisory says Siemens has released updated versions for several affected products.
If no fix is available yet
Not every product may have an available fix at the same time. The advisory says that for products without an available fix, or where fixes are still being prepared, Siemens recommends specific countermeasures.
The context does not list those countermeasures in detail, so users should follow the official advisory rather than guessing.
What to verify before acting
Confirm that your product is on the affected list, then check whether Siemens has an updated release for that product. Because advisories can be revised, review the CISA page and Siemens guidance before scheduling changes.
What changed after CISA’s September 22, 2026 advisory for Siemens SIPLUS and SIMATIC products?

CISA’s September 22, 2026 advisory changed the public status of the issue by identifying affected Siemens SIPLUS and SIMATIC products tied to the Copy Fail vulnerability.
What became clear after the advisory
The advisory confirmed that multiple Siemens products are affected by CVE-2026-31431.
It also identified examples from the affected list, including SIMATIC AX Runtime Core Linux components, SIMATIC CN 4100, and multiple SIMATIC HMI MTP1000 Unified panel variants.
What Siemens had already provided
The advisory says Siemens issued updated versions for several affected products and advises users to move to the latest releases.
For products that do not yet have a fix, or where fixes are still being prepared, Siemens recommends specific countermeasures.
What remains product-specific
The exact next step depends on the specific Siemens product and version in use. The context does not include the full version table or the countermeasure details, so teams should use the CISA advisory as the current reference point.
Sources / Learn more
Related reading
- What should NetScaler ADC and Gateway administrators do first after CISA added CVE-2026-88771 and CVE-2026-88772 to the KEV Catalog?; Which Citrix products are affected by CVE-2026-88771 and CVE-2026-88772?; How are CVE-2026-88771 and CVE-2026-88772 different?; When did CISA add the two Citrix NetScaler vulnerabilities to the Known Exploited Vulnerabilities Catalog?
- What should Siemens Mendix Runtime users do after CISA revoked the advisory and CVE-2026-7891 was retracted?; What changed in CISA’s September 24, 2026 Siemens Mendix Runtime Update A?; Does the Siemens Mendix Runtime issue expose the protected application-specific attribute?
- How do I update a Eufy Omni C20 or Omni X10 Pro to firmware version 1.6.4 or later?; Which Eufy Omni C20 and Omni X10 Pro firmware versions are affected by the September 24, 2026 CISA advisory?; What should I do if my Eufy Omni C20 or Omni X10 Pro was paired while running firmware before 1.6.4?; What changed in the CISA advisory for Eufy Omni C20 and Omni X10 Pro released on September 24, 2026?

Leave a Reply