CVE-2026-22184
CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens CADRA are affected: CADRA vers:intdot/ CVSS Vendor Equipment Vulnerabilities v3 9.8 Siemens Siemens CADRA Improper Input Validation, Incorrect Bitwise Shift of Integer, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Integer Overflow or Wraparound, Access of Resource Using Incompatible Type ('Type Confusion') Background Critical Infrastructure Sectors: Chemical, Commercial Facilities, Communications, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany
EPSS 0.01% · 0.4th percentile
Risk Scores
Timeline
- Jan 7, 2026 CVE Published
- Jan 8, 2026 EPSS Score
- Jan 11, 2026 EPSS Score
- Jan 14, 2026 EPSS Score
- Jan 14, 2026 CVE Updated
- Jan 18, 2026 EPSS Score
- Jan 21, 2026 EPSS Score
- Jan 24, 2026 EPSS Score
- Jan 27, 2026 EPSS Score
- Jan 30, 2026 EPSS Score
- Feb 2, 2026 EPSS Score
- Feb 6, 2026 EPSS Score
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-06 advisory
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-06.json advisory
- https://www.cve.org/CVERecord?id=CVE-2005-2096 technical
- https://cwe.mitre.org/data/definitions/20.html technical
- https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L technical
- https://www.cve.org/CVERecord?id=CVE-2016-9840 technical
- https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H technical
- https://www.cve.org/CVERecord?id=CVE-2016-9841 technical
- https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H technical
- https://www.cve.org/CVERecord?id=CVE-2016-9842 technical
- https://cwe.mitre.org/data/definitions/1335.html technical
- https://www.cve.org/CVERecord?id=CVE-2017-14919 technical
- https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H technical
- https://www.cve.org/CVERecord?id=CVE-2018-25032 technical
- https://cwe.mitre.org/data/definitions/787.html technical
- https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H technical
- https://www.cve.org/CVERecord?id=CVE-2022-37434 technical
- https://cwe.mitre.org/data/definitions/120.html technical
- https://www.cve.org/CVERecord?id=CVE-2023-45853 technical
- https://cwe.mitre.org/data/definitions/190.html technical
…and 5 more