VDB

CVE-2026-22184

CVE-2026-22184 PUBLISHED CVSS 9.800000190734863 CRITICAL

CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens CADRA are affected: CADRA vers:intdot/ CVSS Vendor Equipment Vulnerabilities v3 9.8 Siemens Siemens CADRA Improper Input Validation, Incorrect Bitwise Shift of Integer, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Integer Overflow or Wraparound, Access of Resource Using Incompatible Type ('Type Confusion') Background Critical Infrastructure Sectors: Chemical, Commercial Facilities, Communications, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany

EPSS 0.01% · 0.4th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score
0.01%
0.4th percentile

Timeline

  • Jan 7, 2026 CVE Published
  • Jan 8, 2026 EPSS Score
  • Jan 11, 2026 EPSS Score
  • Jan 14, 2026 EPSS Score
  • Jan 14, 2026 CVE Updated
  • Jan 18, 2026 EPSS Score
  • Jan 21, 2026 EPSS Score
  • Jan 24, 2026 EPSS Score
  • Jan 27, 2026 EPSS Score
  • Jan 30, 2026 EPSS Score
  • Feb 2, 2026 EPSS Score
  • Feb 6, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›