Fourteen CVEs in Siemens Reyrolle 7SR5 Protection Relays
ICSA-26-258-05 aggregates five 2024 identifiers and nine new ones into a single advisory, top score 9.8, with V2.70 as the remedy.

CISA published ICSA-26-258-05 on 15 September for Siemens Reyrolle 7SR5 protection relays, all versions before V2.70. It aggregates fourteen CVEs with CVSS v3.1 base scores from 4.0 to 9.8. No v4.0 scores are given.
Five of the identifiers date from 2024 — CVE-2024-42384, CVE-2024-42385, CVE-2024-42386, CVE-2024-42391 and CVE-2024-42392. Nine are new: CVE-2026-62645 through CVE-2026-62650, plus CVE-2026-62652, CVE-2026-62653 and CVE-2026-62654. The highest, CVE-2026-62645, is rated 9.8 critical. The remedy is a single one: update to V2.70 or later, available through Siemens' support portal.
The two-year-old identifiers are the part that says something about this equipment class. Those CVEs were assigned in 2024 and only now roll into a fixed version, which is a fair indication of how long firmware remediation cycles run in protection equipment — and why. A protection relay is not a device you patch on a Tuesday. It sits at the boundary between the substation network and the primary plant, its settings are the reason a fault clears safely, and updating it means an outage, a test plan and a re-verification of the protection scheme.
Which is the practical reading for an asset owner: V2.70 belongs on the outage schedule, not the patch list. A 9.8 in a widely deployed relay line is a grid-reliability item rather than an IT one, and anyone running substation edge gateways alongside these relays should be planning the window now rather than discovering the dependency during the next audit.