CVE-2026-31431

● KEV HIGH

View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS va...

Affects 49 products across 12 vendors.

BCS8.89
CVSS 3.17.8
EPSS94.5%
Percentile100th
PatchUnknown
KEV Added2026-05-01
CVSS Vector — Plain English Requires local access, low complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-669: CWE-669
CWE-1288: CWE-1288
◆ SAGE Intelligence — CITED Relevance Research Team

The Linux kernel's crypto module, specifically the algif_aead component, contains a vulnerability that has been addressed by reverting to out-of-place operations. This change simplifies the code and removes unnecessary complexity, reducing the risk of potential security issues. The vulnerability is rated as high severity with a CVSS score of 7.8, and it affects multiple vendors and distributions. While there is no known exploit, a public proof of concept exists, and the vulnerability is listed in the KEV catalog.

BSID: BS-2026-GLOBAL-271236-H • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-31431?
The Linux kernel's crypto module, specifically the algif_aead component, contains a vulnerability that has been addressed by reverting to out-of-place operations. This change simplifies the code and removes unnecessary complexity, reducing the risk of potential security issues. The vulnerability is rated as high severity with a CVSS score of 7.8, and it affects multiple vendors and distributions. While there is no known exploit, a public proof of concept exists, and the vulnerability is listed i
What is the CVSS score for CVE-2026-31431?
CVE-2026-31431 has CVSS 7.8 (High). Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. EPSS: 94.5%.
Is CVE-2026-31431 actively exploited?
Yes. CVE-2026-31431 is in the CISA KEV catalog (added 2026-05-01). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2026-31431?
Priority: MEDIUM.
What systems are affected by CVE-2026-31431?
CVE-2026-31431 affects: Amazon, Arista, Arista, Arista, Arista, Arista, Canonical, Debian.
What NERC-CIP standard applies to CVE-2026-31431?
NERC CIP CIP-007 CIP-007-R2: This CVE affects the integrity and availability of the system, which are critical for the secure operation of BES Cyber Systems. CIP-007-R2 requires the implementation of security controls to protect against unauthorized access and manipulation.
What IEC 62443 requirement maps to CVE-2026-31431?
IEC 62443 SR 7.6: This CVE impacts the security of the system by potentially allowing unauthorized access and data manipulation. SR 7.6 requires the implementation of security measures to protect against such vulnerabilities and ensure the integrity and availability of the system.
Vulnerability Details
CVE IDCVE-2026-31431
BSIDBS-2026-GLOBAL-271236-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Published2026-07-28
Last Modified2026-07-28
ICS Relevance85%
Weakness (CWE)
Verticals
ICS-OT
Domains
NETWORK-INFRACLOUD
SourceNVD
Official Description

View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP are affected: SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) vers:intdot/>=3.1.6

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability can be exploited locally by an attacker with low privileges. The attacker could potentially cause a denial of service, gain unauthorized access, or manipulate data. The attack does not require user interaction and can affect the confidentiality, integrity, and availability of the system.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Amazon Amazon Linux
Arista Velocloud Gateway
Arista Cloudvision Portal
Arista Cloudvision Agni
Arista Velocloud Edge
Arista Netvisor Os
Canonical Ubuntu Linux
Debian Debian Linux
Fortinet —
Linux Linux Kernel
Nixos Nixos
Opensuse Leap
Redhat Enterprise Linux
Redhat Openshift Container Platform
Siemens Simatic S7-1500 Tm Mfp Firmware
Siemens Simatic S7-1500 Cpu 1518-4 Pn\/Dp Mfp Firmware
Siemens Simatic S7-1500 Cpu 1518-4 Pn\/Dp Mfp
Siemens Simatic S7-1500 Cpu 1518F-4 Pn\/Dp Mfp Firmware
Siemens Simatic S7-1500 Cpu 1518F-4 Pn\/Dp Mfp
Siemens Siplus S7-1500 Cpu 1518-4 Pn\/Dp Mfp Firmware
Siemens Siplus S7-1500 Cpu 1518-4 Pn\/Dp Mfp
Siemens Simatic S7-1500 Tm Mfp
Siemens Simatic S7-1500 Cpu 1518-4 Pn/Dp Mfp
Siemens Simatic S7-1500 Cpu 1518-4 Pn/Dp Mfp Firmware
Siemens Simatic S7-1500 Cpu 1518F-4 Pn/Dp Mfp
Siemens Simatic S7-1500 Cpu 1518F-4 Pn/Dp Mfp Firmware
Siemens Siplus S7-1500 Cpu 1518-4 Pn/Dp Mfp
Siemens Siplus S7-1500 Cpu 1518-4 Pn/Dp Mfp Firmware
Suse Caas Platform
Suse Linux Enterprise Live Patching
Suse Openstack Cloud
Suse Linux Enterprise High Performance Computing
Suse Manager Proxy
Suse Manager Server
Suse Linux Enterprise Workstation Extension
Suse Linux Enterprise High Availability Extension
Suse Linux Enterprise Real Time
Suse Openstack Cloud Crowbar
Suse Enterprise Storage
Suse Manager Retail Branch Server
Suse Linux Enterprise Micro
Suse Basesystem Module
Suse Development Tools Module
Suse Legacy Module
Suse Linux Micro
Suse Public Cloud Module
Suse Realtime Module
Suse Linux Enterprise Server
Suse Linux Enterprise Desktop
Vmware Velocloud Orchestrator
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 0 Days
CISA KEV● Active Exploitation Confirmed (added 2026-05-01)
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement strict access controls and monitoring for the affected components to detect and prevent unauthorized access or manipulation.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE affects the integrity and availability of the system, which are critical for the secure operation of BES Cyber Systems. CIP-007-R2 requires the implementation of security controls to protect against unauthorized access and manipulation.
IEC 62443: SR 7.6
This CVE impacts the security of the system by potentially allowing unauthorized access and data manipulation. SR 7.6 requires the implementation of security measures to protect against such vulnerabilities and ensure the integrity and availability of the system.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash25d5e54cb997dbfd1b9f59bb96286839325bd60c4497864ee8c72486839f24561be4fcf02ffde288f70248be8ca7088e77c9a23bb0942a896b24b11d71c7b71e
Related CVEs affecting Amazon
CVE-2024-32888 10.0 The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides dat... CVE-2012-4249 10.0 The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle To... CVE-2019-3989 9.8 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to ex... CVE-2015-7292 9.8 Stack-based buffer overflow in the havok_write function in drivers/staging/ha... CVE-2019-18960 9.8 Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19....
View all Amazon CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2026-31431 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.

Start Free KEV Monitoring →