ICS advisories
Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS) advisories, the operational technology (OT) counterpart to the vulnerability feed. Each advisory carries the authoritative Common Vulnerability Scoring System (CVSS) score, weakness class, affected vendors and products, critical infrastructure sectors, and vendor mitigations taken directly from CISA's Common Security Advisory Framework (CSAF) documents, and links every Common Vulnerabilities and Exposures (CVE) identifier it names. This page carries metadata and links only; each summary is CISA's own advisory summary, verbatim.
- ICSA-26-204-07OTCVSS 8.2 HighReleased 2026-07-23
MZ Automation lib60870
Vendor: MZ AutomationProduct: lib60870
Critical infrastructure sectorsChemicalEnergyWater and Wastewater SystemsSuccessful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service.
Named CVEsCVE-2026-16002Weakness classesView CISA CSAF advisory ↗Mitigations- MZ automation recommends users update to version 2.4.1 or later. Documentation can be found at https://github.com/mz-automation/lib60870/security/advisories/GHSA-f5xp-w6f3-vvrv.Vendor reference ↗
- ICSA-26-204-06OTCVSS 8.1 HighReleased 2026-07-23
MZ Automation libIEC61850
Vendor: MZ AutomationProduct: libIEC61850
Critical infrastructure sectorsCritical ManufacturingEnergyTransportation SystemsSuccessful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions.
View CISA CSAF advisory ↗Mitigations- MZ Automation recommends updating to the latest build of the libIEC61850 standard. Documentation can be found at https://github.com/mz-automation/libiec61850.Vendor reference ↗
- ICSA-26-204-04OTCVSS 10 CriticalReleased 2026-07-23
Panduit IntraVUE
Vendor: PronetiqsProduct: IntraVUE
Critical infrastructure sectorsCritical ManufacturingEnergyInformation TechnologyWater and Wastewater SystemsSuccessful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider knowledge, or advanced tooling.
Named CVEsView CISA CSAF advisory ↗Mitigations- Pronetiqs advises users to update to the latest version of the IntraVUE software, version 3.2.1a16 or later.
- For further questions, please contact Pronetiqs at info@pronetiqs.com.Vendor reference ↗
- ICSA-26-204-03OTCVSS 8.8 HighReleased 2026-07-23
Weintek cMT3092X
Vendor: WeintekProducts: cMT3092X firmware, EasyWeb
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users.
View CISA CSAF advisory ↗Mitigations- Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors.Vendor reference ↗
- Weintek has published a document with more details about this issue at https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf.Vendor reference ↗
- ICSA-26-204-02OTCVSS 3.3 LowReleased 2026-07-23
Johnson Controls XAAP Android
Vendor: Johnson ControlsProduct: XAAP Android
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device.
Named CVEsCVE-2026-34490Weakness classesView CISA CSAF advisory ↗Mitigations- Johnson Controls recommends users update the XAAP Android application to version 1.53 or later, which contains the fix for this vulnerability.
- Johnson Controls recommends users restrict physical access to devices running the XAAP Android application.
- Johnson Controls recommends users ensure devices are hardened with up-to-date Android OS versions, device encryption enabled, and screen lock protections in place.
- Johnson Controls recommends users implement a Mobile Device Management (MDM) solution to enforce security policies, including encryption requirements, application whitelisting, and remote wipe capabilities.
- Johnson Controls recommends users Avoid rooting or jailbreaking devices used in production environments, as this weakens OS-level security controls that help protect local application data.
- For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-10.
- ICSA-26-204-01OTCVSS 9.6 CriticalReleased 2026-07-23
Johnson Controls C-CURE 9000 and Victor application server
Vendor: Johnson ControlsProducts: C-CURE 9000 and victor, victor Web
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution.
View CISA CSAF advisory ↗Mitigations- Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation: (CVE-2026-21655) Upgrade to C-CURE 9000 / victor version 3.20 or later, which addresses the vulnerable deserialization path (LV1.1).
- Network segmentation - Isolate the C-CURE 9000 and victor application servers on a dedicated network segment and restrict access to port 8999 to only authorized systems that require connectivity.
- Firewall / access control lists - Implement strict firewall rules to block all unnecessary inbound connections to port 8999 from untrusted network segments.
- Intrusion detection / prevention - Deploy IDS/IPS signatures tuned to detect known .NET deserialization exploit payloads (e.g., ysoserial.net patterns) targeting port 8999.
- Application whitelisting - Enforce application whitelisting on application server hosts to prevent unauthorized executables from being launched by the server process.
- Least privilege - Ensure the application server process runs with the minimum privileges necessary, reducing the impact of successful exploitation.
- Monitor and audit - Enable detailed logging on application server hosts and monitor for anomalous process creation by SoftwareHouse.CrossFire.Server.exe.
- Disable unnecessary services - If the ClientConnectionManager_NF.SynchronousServerNotification callback interface is not required, disable or restrict it to reduce attack surface.
- For more detailed mitigation instructions, please see Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisoriesVendor reference ↗
- (CVE-2026-21653, CVE-2026-34496) Update all victor Web installations to version 7.0 or later, which contains the fix for this vulnerability. The fix has been validated through independent retest.
- ICSA-26-202-10OTCVSS 7.5 HighReleased 2026-07-21
Rockwell Automation Studio 5000 Logix Designer
Vendor: Rockwell AutomationProduct: Studio 5000 Logix Designer
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code.
Named CVEsCVE-2026-9108CVE-2026-9127CVE-2026-9128View CISA CSAF advisory ↗Mitigations- Rockwell Automation recommends users to upgrade to the following: Studio 5000 Logix Designer: V37.00, 36.01, 35.02, 34.04, 33.04, 32.05 (CVE-2026-9108)
- Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight).Vendor reference ↗
- For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html.Vendor reference ↗
- Studio 5000 Logix Designer: V36.00, 35.01, 34.02, 33.02, 32.05 (CVE-2026-9127)
- Studio 5000 Logix Designer: V36.00, 35.01, 34.03, 33.03, 32.05 (CVE-2026-9128)
- ICSA-26-202-09OTCVSS 7.5 HighReleased 2026-07-21
Rockwell Automation 1734 POINT I/O
Vendor: Rockwell AutomationProduct: 1734 POINT I/O
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product.
Named CVEsWeakness classesView CISA CSAF advisory ↗Mitigations- Rockwell Automation recommends users are to migrate to 5034-OB8.
- Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight).Vendor reference ↗
- For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html.Vendor reference ↗
- ICSA-26-202-08OTCVSS 7.5 HighReleased 2026-07-21
Rockwell Automation 1718-AENTR/1719-AENTR
Vendor: Rockwell AutomationProduct: 1718/ 1719 Ex I/O
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product.
Named CVEsWeakness classesView CISA CSAF advisory ↗Mitigations- Rockwell Automation recommends users to upgrade to 1718/ 1719 Ex I/O version 3.012 or later.
- Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight).Vendor reference ↗
- For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html.Vendor reference ↗
- ICSA-26-202-07OTCVSS 7.8 HighReleased 2026-07-21
Rockwell Automation FactoryTalk Services Platform
Vendor: Rockwell AutomationProduct: FactoryTalk Directory (FTSP)
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations.
Named CVEsWeakness classesView CISA CSAF advisory ↗Mitigations- Users using FactoryTalk Services Platform v6.60 should apply either the individual patch (RAID 1158263) or the February 2026 Patch Roll-up, or later update.
- Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell's security best practices.Vendor reference ↗
- For more information, refer to Rockwell Automation's security advisory SD1786 page.Vendor reference ↗
- ICSA-26-202-01OTCVSS 9.8 CriticalReleased 2026-07-21
Tycon Systems TPDIN-Monitor-WEB2
Vendor: Tycon SystemsProduct: TPDIN-Monitor-WEB2
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.
Named CVEsCVE-2026-61884CVE-2026-55985View CISA CSAF advisory ↗Mitigations- Tycon Systems did not respond to CISA's attempts at coordination. Users of Tycon Systems TPDIN-Monitor-WEB2 are encouraged to contact Tycon Systems and keep their systems up to date.Vendor reference ↗
- ICSA-26-197-09OTCVSS 6.1 MediumReleased 2026-07-16
Rockwell Automation FactoryTalk DataMosaix
Vendor: Rockwell AutomationProduct: DataMosaix Private Cloud
Critical infrastructure sectorsCritical ManufacturingInformation TechnologySuccessful exploitation of this vulnerability could allow an authenticated attacker to inject malicious scripts on the server.
Named CVEsCVE-2026-9292Weakness classesView CISA CSAF advisory ↗Mitigations- Rockwell Automation recommends users to upgrade to the following: DataMosaix Private Cloud versions 8.03 or later.
- Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight).Vendor reference ↗
- For more information, see Rockwell Automation Security Advisory SD1787 (https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1787.html).Vendor reference ↗
- ICSA-26-197-08OTCVSS 7.5 HighReleased 2026-07-16
Rockwell Automation Flex 5000 Adapter
Vendor: Rockwell AutomationProduct: Flex 5000 Adapter
Critical infrastructure sectorsCritical ManufacturingInformation TechnologySuccessful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition on the affected product.
Named CVEsCVE-2026-12659Weakness classesView CISA CSAF advisory ↗Mitigations- Rockwell Automation recommends users to upgrade to the following: Flex 5000 Adapter version 6.012.
- Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight).Vendor reference ↗
- For more information, see Rockwell Automation Security Advisory SD1789 (https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1789.html).Vendor reference ↗
- ICSA-26-197-07OTCVSS 6.5 MediumReleased 2026-07-16
SALTO ProAccess Space
Vendor: SALTOProduct: ProAccess Space
Critical infrastructure sectorsCommercial FacilitiesCritical ManufacturingSuccessful exploitation of this vulnerability allows an authenticated attacker to escalate privileges and access spaces outside their assigned partition, within the same Salto ProAccess Space installation or system. Exploitation requires valid authenticated operator credentials and the partition feature to be enabled; installations without partitioning are not affected.
Named CVEsWeakness classesView CISA CSAF advisory ↗Mitigations- Users of SALTO ProAccess using the tenancy feature should upgrade to version 6.13.
- To further enhance security after applying the update: 1. Operate ProAccess Space on a protected internal network and avoid exposing it directly to the Internet. 2. Restrict operator-level accounts to the minimum required and apply least-privilege principles. 3. If feasible, disable the partitioning feature and operate under a single partition. 4. When strong tenant separation is required, consider running separate Space instances (isolated environments) rather than relying solely on logical partitioning.
- ICSA-26-197-06OTCVSS 8.6 HighReleased 2026-07-16
Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix
Vendor: Rockwell AutomationProducts: CompactLogix 5370, Compact GuardLogix 5370, ControlLogix 5570, GuardLogix 5570, CompactLogix 5380, Compact GuardLogix 5380, CompactLogix 5480, ControlLogix 5580, GuardLogix 5580, CompactLogix 5380 Recovery Image, Compact GuardLogix 5380 Recovery Image, CompactLogix 5480 Recovery Image, ControlLogix 5580 Recovery Image, GuardLogix 5580 Recovery Image
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition.
Weakness classesView CISA CSAF advisory ↗Mitigations- Rockwell Automation recommend updating to the following: CompactLogix 5370: Update to V35.016, V36.011 and later
- Compact GuardLogix 5370: Update to V35.016, V36.011 and later
- ControlLogix 5570: Update to V35.016, V36.011 and later
- GuardLogix 5570: Update to V35.016, V36.011 and later
- CompactLogix 5380: Update to V34.014, V35.013, V36.011 and later
- Compact GuardLogix 5380: Update to V34.014, V35.013, V36.011 and later
- CompactLogix 5480: Update to V34.014, V35.013, V36.011 and later
- ControlLogix 5580: Update to V34.014, V35.013, V36.011 and later
- GuardLogix 5580: Update to V34.014, V35.013, V36.011 and later
- CompactLogix 5380 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed
- Compact GuardLogix 5380 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed
- CompactLogix 5480 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed
- ControlLogix 5580 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed
- GuardLogix 5580 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed
- ICSA-26-197-04OTCVSS 7 HighReleased 2026-07-16
AutomationDirect Productivity Suite
Vendor: AutomationDirectProduct: Productivity Suite
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of these vulnerabilities could allow an attacker with local or physical access to cause memory corruption, unintended information disclosure, application instability, or a denial-of-service condition in the affected product.
Named CVEsView CISA CSAF advisory ↗Mitigations- AutomationDirect recommends that users update Productivity suite to v4.7.0.47 and above https://www.automationdirect.com/support/software-downloads.Vendor reference ↗
- If the update cannot be applied right away, the following compensating controls are recommended until the upgrade can be performed.
- Disconnect the engineering workstation from external networks (e.g., the internet or corporate LAN) to reduce exposure.
- Use only trusted, dedicated internal networks or air-gapped systems for device communication.
- Restrict both physical and logical access to authorized personnel only.
- Configure whitelisting so that only trusted, pre-approved applications are allowed to run. Block any unauthorized software.
- Use antivirus or EDR tools and configure host-based firewalls to block unauthorized access attempts.
- Enable and regularly review system logs to detect suspicious or unauthorized activity.
- Maintain secure, tested backups of the PLC and its configurations to minimize downtime in case of an incident.
- Continuously evaluate risks associated with running outdated firmware and adjust compensating measures accordingly.
- ICSA-26-197-03OTCVSS 7.5 HighReleased 2026-07-16
NASA Core Flight System (cFS) Health & Safety (HS) Application
Vendor: NASAProduct: Core Flight System (cFS) Health & Safety (HS) Application
Critical infrastructure sectorsTransportation SystemsSuccessful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.
Named CVEsWeakness classesView CISA CSAF advisory ↗Mitigations- NASA recommends users update to v7.0.1 (https://github.com/nasa/HS/releases/tag/v7.0.1)Vendor reference ↗
- ICSA-26-197-02OTCVSS 7.5 HighReleased 2026-07-16
Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT
Vendor: Rockwell AutomationProducts: 1756-EN3, 1756-EN2, 1756-ENBT
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.
Named CVEsWeakness classesView CISA CSAF advisory ↗Mitigations- Rockwell Automation recommends users take the following actions: 1756-EN3: Update to V12.002
- 1756-EN2: Update to V12.002
- 1756-ENBT: Product is discontinued, fix is unavailable
- ICSA-26-197-01OTCVSS 7.8 HighReleased 2026-07-16
Rockwell Automation Arena
Vendor: Rockwell AutomationProduct: Arena
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation these vulnerabilities could allow an attacker to execute arbitrary code in the context of the current process.
Weakness classesView CISA CSAF advisory ↗Mitigations- Rockwell Automation recommends users to update to V17.00.01
- ICSA-26-204-05OTCVSS 8.1 HighReleased 2026-07-14 · Updated 2026-07-23
Rockwell Automation ThinManager
Vendor: Rockwell AutomationProduct: ThinManager
Critical infrastructure sectorsChemicalCritical ManufacturingEnergyFood and AgricultureWater and Wastewater SystemsSuccessful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory.
Named CVEsCVE-2026-11917Weakness classesView CISA CSAF advisory ↗Mitigations- Users using the affected software, should upgrade to one of the corrected versions as follows:
- ThinManager Versions 13.0.0 - 13.0.7 --> 13.0.8
- ThinManager Versions 13.1.0 - 13.1.5 --> 13.1.6
- ThinManager Versions 13.2.0 - 13.2.4 --> 13.2.5
- ThinManager Versions 14.0.0 - 14.0.2 --> 14.0.3
- Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices.Vendor reference ↗
- For more information, refer to Rockwell Automation's Securitry Advisory page.Vendor reference ↗
- ICSA-26-202-06OTCVSS 9.8 CriticalReleased 2026-07-14 · Updated 2026-07-21
Siemens CADRA
Vendor: SiemensProduct: CADRA
Critical infrastructure sectorsChemicalCommercial FacilitiesCommunicationsEnergyCADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
Named CVEsCVE-2005-2096CVE-2016-9840CVE-2016-9841CVE-2016-9842CVE-2017-14919CVE-2018-25032CVE-2022-37434CVE-2023-45853CVE-2025-10585CVE-2025-13223CVE-2026-22184View CISA CSAF advisory ↗Mitigations- Update to V2511 or later version
- Block access to untrusted or external web content from sensitive systems
- Currently no fix is available
- ICSA-26-202-05OTCVSS 6.7 MediumReleased 2026-07-14 · Updated 2026-07-21
Siemens IAM Client
Vendor: SiemensProducts: COMOS V10.4.5, COMOS V10.6, Designcenter NX, Simcenter 3D, Simcenter Femap V2506, Simcenter Femap V2512, Simcenter Nastran, Simcenter STAR-CCM+, Solid Edge SE2025, Solid Edge SE2026, Teamcenter Visualization V2412, Teamcenter Visualization V2506, Teamcenter Visualization V2512, Tecnomatix Plant Simulation V2404, Tecnomatix Plant Simulation V2504, Tecnomatix Process Simulate
Critical infrastructure sectorsChemicalCritical ManufacturingEnergyMultiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.
Named CVEsWeakness classesView CISA CSAF advisory ↗Mitigations- Update to V10.6.1 or later versionVendor reference ↗
- Update to V225.0 Update 13 or later versionVendor reference ↗
- Update to V226.0 Update 04 or later versionVendor reference ↗
- Update to V2404.0022 or later versionVendor reference ↗
- Update to V2412.0012 or later versionVendor reference ↗
- Update to V2504.0010 or later versionVendor reference ↗
- Update to V2506.0003 or later versionVendor reference ↗
- Update to V2506.0009 or later versionVendor reference ↗
- Update to V2512.0002 or later versionVendor reference ↗
- Update to V2512.2605 or later versionVendor reference ↗
- Update to V2512.7000 or later versionVendor reference ↗
- Update to V2606 or later versionVendor reference ↗
- Update to V10.4.5.0.2 or later version. Contact customer support to receive patch and update information
- ICSA-26-202-04OTCVSS 9.8 CriticalReleased 2026-07-14 · Updated 2026-07-21
Siemens SIDIS Secured SmartPlug
Vendor: SiemensProduct: SIDIS Secured SmartPlug
Critical infrastructure sectorsCritical ManufacturingSIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version.
Named CVEsCVE-2022-23303CVE-2022-23304CVE-2022-37660CVE-2022-48174CVE-2025-5222CVE-2025-5914CVE-2025-9230CVE-2025-9231CVE-2025-9232CVE-2025-26465CVE-2025-32462CVE-2026-5121View CISA CSAF advisory ↗Mitigations- Update to V7.26.0310 or later version
- ICSA-26-202-03OTCVSS 10 CriticalReleased 2026-07-14 · Updated 2026-07-21
Siemens Opcenter X
Vendor: SiemensProduct: Opcenter X
Critical infrastructure sectorsCritical ManufacturingOpcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version.
Named CVEsWeakness classesView CISA CSAF advisory ↗Mitigations- Update to V2604 or later versionVendor reference ↗
- ICSA-26-202-02OTCVSS 7.2 HighReleased 2026-07-14 · Updated 2026-07-21
Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW
Vendor: SiemensProduct: RUGGEDCOM APE1808
Critical infrastructure sectorsCritical ManufacturingPalo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/
Named CVEsCVE-2026-0266CVE-2026-0272CVE-2026-0273View CISA CSAF advisory ↗Mitigations- Contact customer support to receive patch and update information
- ICSA-26-195-04OTCVSS 10 CriticalReleased 2026-07-14
Rockwell Automation 1715-AENTR EtherNet/IP Adapter
Vendor: Rockwell AutomationProduct: 1715-AENTR EtherNet/IP Adapter
Critical infrastructure sectorsEnergyWater and Wastewater SystemsCritical ManufacturingSuccessful exploitation of this vulnerability could allow an attacker to read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device.
Named CVEsWeakness classesView CISA CSAF advisory ↗Mitigations- Rockwell Automation recommends that users update to 1715-AENTR EtherNet/IP Adapter version 3.011 and later.
- Rockwell Automation recommends users of the affected software who are not able to upgrade to one of the corrected versions should use their security best practices.Vendor reference ↗
- For more information, see the Rockwell Automation security advisory SD1785Vendor reference ↗
- If you have any questions regarding this security issue and how to mitigate it,contact Rockwell Automation for help.Vendor reference ↗
- ICSA-26-197-05OTCVSS 7.2 HighReleased 2026-07-09 · Updated 2026-07-16
Siemens SICAM 8
Vendor: SiemensProducts: CPCI85 Central Processing/Communication, SICORE Base system
Critical infrastructure sectorsCritical ManufacturingEnergyMultiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: - SICAM A8000 Device firmware - CPCI85 for CP-8031/CP-8050 - SICORE for CP-8010/CP-8012 - SICAM EGS Device firmware - CPCI85 - SICAM S8000 - SICORE Siemens has released new versions for the affected products and recommends to update to the latest versions.
Named CVEsView CISA CSAF advisory ↗Mitigations- Update to V26.20 or later version The firmware CPCI85 V26.20 is present within “CP-8031/CP-8050 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109804985/ and also within “SICAM EGS Package” V26.20 https://support.industry.siemens.com/cs/document/109972536/
- Update to V26.20.0 or later version The firmware SICORE V26.20.0 is present within “CP-8010/CP-8012 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109972894/ and also within “SICAM S8000 Package” V26.20 https://support.industry.siemens.com/cs/document/109818240
- ICSA-26-190-01OTCVSS 9.9 CriticalReleased 2026-07-09
OpenPLC v3
Vendor: OpenPLCProduct: OpenPLC
Critical infrastructure sectorsCritical ManufacturingEnergyTransportation SystemsWater and WastewaterSuccessful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to the filesystem and escalate this into arbitrary native code execution through the normal OpenPLC program compilation process, potentially resulting in code execution as the OpenPLC runtime user.
Named CVEsWeakness classesView CISA CSAF advisory ↗Mitigations- OpenPLC recommends users upgrade to OpenPLC v4 as OpenPLC v3 is end-of-life and is no longer receiving patches, bug fixes, or security updates.
- ICSA-26-188-07OTCVSS 5.9 MediumReleased 2026-07-07
Digi International PortServer TS, Digi One SP IA
Vendor: Digi InternationalProducts: PortServer TS, Digi One SP, Digi One SP IA, Digi One IA
Critical infrastructure sectorsCritical ManufacturingCommunicationsInformation TechnologyTransportation SystemsSuccessful exploitation of these vulnerabilities could allow an attacker to bypass authentication and gain access to restricted resources, obtain credentials, and inject malicious scripts.
Named CVEsCVE-2026-12352CVE-2026-12948View CISA CSAF advisory ↗Mitigations- Digi International recommends users upgrade to Digi Connect EZ or Digi Connect EZ TS as a long term solution. If users are not able to upgrade at this time, the following actions should be taken:
- For Digi PortServer TS: Enable HTTPS on the web server.
- Alternatively, disable the web server when it is not actively being used for configuration.
- Compensating control: If you cannot apply the HTTPS configuration, restrict access via firewall or VPN.
- For Digi One SP / Digi One SP IA / Digi One IA: Disable the web server. If you cannot apply the HTTPS configuration, restrict access via firewall or VPN.
- The following deployment practices are the recommended means of reducing exposure: Deploy the device on a trusted network segment, not exposed to untrusted or public networks.
- Place the device behind a firewall or VPN and restrict access to the web management interface to trusted administrative hosts only.
- Safeguard administrator credentials, since exploitation requires authenticated administrator access to write the affected fields.
- For assistance users should contact Digi International's support team https://www.digi.com/support.Vendor reference ↗
- Digi International recommends users perform the following actions regarding XSS: Digi International will not provide a firmware fix for products affected by CVE-2026-12948, which are approaching end-of-life. Digi International recommends users upgrade to the Digi Connect EZ or Digi Connect EZ TS as a long-term solution.
- ICSA-26-188-06OTCVSS 7.8 HighReleased 2026-07-07
Labcenter Proteus 9
Vendor: Labcenter ElectronicsProduct: Proteus
Critical infrastructure sectorsCommunicationsCritical ManufacturingDefense Industrial BaseEnergyHealthcare and Public HealthTransportation SystemsWater and Wastewater SystemsSuccessful exploitation of these vulnerabilities could disclose information and allow a malicious user to execute arbitrary code on affected installations.
View CISA CSAF advisory ↗Mitigations- Labcenter recommends ensuring you are using the latest version (9.2 SPO) of the software. Version can be found by looking at the bottom left of the Proteus home page (Version 8 or higher) or by selecting the About ISIS or About ARES option from the Help menu. Update notifications appear in the new and information section of the home page where you can activate the download and installation directly.
- If you have questions or need help please contact Labcenter or your local distributor.
- ICSA-26-188-01OTCVSS 9.8 CriticalReleased 2026-07-07
Hydro-Québec Le Circuit Electrique charging station backend
Vendor: Hydro-QuébecProduct: Le Circuit Electrique charging station backend
Critical infrastructure sectorsTransportation SystemsSuccessful exploitation of these vulnerabilities could lead to privilege escalation, or result in a denial-of-service attack.
View CISA CSAF advisory ↗Mitigations- Hydro-Québec has updated the majority of charging stations to disable OCPP, mitigating the risk of exploitation. Hydro-Québec has also implemented authentication systems to mitigate the issue for certain charging stations which are still reliant on OCPP. Contact Hydro-Québec with any additional questions.
- ICSA-26-183-03OTCVSS 10 CriticalReleased 2026-07-02
Gardyn IoT Hub
Vendor: GardynProducts: Home Firmware, Studio Firmware, Cloud API
Critical infrastructure sectorsFood and AgricultureSuccessful exploitation of these vulnerabilities could allow unauthenticated users to access and control IoT Hub managed devices.
Named CVEsView CISA CSAF advisory ↗Mitigations- Gardyn states that IoT Hub deployed infrastructure has been updated to fix the listed vulnerabilities.
- Gardyn requests that users ensure their devices have Internet connectivity in order to automatically download needed firmware updates. Unconnected devices will automatically update when configured with a working Internet connection. Gardyn also recommends that users update their mobile application to the most recent version. The current versions of the Gardyn App and the Gardyn Home firmware can be checked in the Gardyn App.
- Further information on Gardyn security can be found here: https://mygardyn.com/security/Vendor reference ↗
- Further customer support can be obtained from Gardyn at: support@mygardyn.comVendor reference ↗
- ICSA-26-183-02OTCVSS 6.1 MediumReleased 2026-07-02
CubeSpace CW0057 Reaction Wheel
Vendor: CubeSpaceProduct: CW0057 Reaction Wheel
Critical infrastructure sectorsCommunicationsSuccessful exploitation of this vulnerability could allow an attacker to upload arbitrary malicious firmware to the device.
Named CVEsCVE-2026-13743Weakness classesView CISA CSAF advisory ↗Mitigations- CubeSpace has released the following firmware versions for users to enable: Firmware version 5.0.20. Firmware version 5.0.20 introduces the capability for cryptographically verified secure boot; however, this protection is not enabled by default. Users must activate signed‑boot functionality, particularly the fully immutable mode, to achieve full security.
- CubeSpace acknowledges the finding. The CW0057 reaction wheel authenticates firmware updates with a CRC-32 integrity check, which confirms image integrity but does not verify the source of an image. Exploitation requires direct physical access to the device and is not exploitable remotely. A device affected by this method remains recoverable: the bootloader operates independently of the application firmware and can reload known-good, CubeSpace-supplied images, so an affected unit cannot be permanently disabled by this method. Starting with firmware version 5.0.20, CubeSpace offers optional cryptographic secure boot of varying security levels which customers can enable. Given the physical-access prerequisite and the availability of recovery, CubeSpace assesses the practical risk as low.
- ICSA-26-183-01OTCVSS 8.1 HighReleased 2026-07-02
ST Engineering iDirect iQ-Series Terminals
Vendor: ST Engineering iDirectProducts: Evolution iQ‑Series terminals, 3315‑Series terminals, 9‑Series terminals
Critical infrastructure sectorsCommunicationsDefense Industrial BaseEnergyGovernment FacilitiesTransportation SystemsSuccessful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition.
Named CVEsView CISA CSAF advisory ↗Mitigations- ST Engineering iDirect has fixed the vulnerabilities and recommend users update the software to version 4.5.2.2 or newer.
- Registered users are able to download patches from the iDirect Support Portal https://support.idirect.net/s/login.Vendor reference ↗
- Restrict management interfaces to trusted networks (e.g., VPN, ACLs).
- Avoid exposing administrative APIs to the public internet.
- Enforce strong authentication practices.
- Monitor for anomalous API activity and unexpected device reboots.
- ICSMA-26-181-01OTCVSS 9.8 CriticalReleased 2026-06-30
OFFIS DCMTK Toolkit
Vendor: OFFISProduct: DCMTK
Critical infrastructure sectorsHealthcare and Public HealthSuccessful exploitation of these vulnerabilities could allow an attacker to write files, access unauthorized information, exhaust memory, or crash affected DCMTK client or server processes.
Named CVEsCVE-2026-50003CVE-2026-50254CVE-2026-35505CVE-2026-52868CVE-2026-44628View CISA CSAF advisory ↗Mitigations- The maintainer was notified of these vulnerabilities and has provided a fix. The fix is included in the latest commits and can be obtained in the following snapshot:
- https://github.com/DCMTK/dcmtk/releases/tag/latest.Vendor reference ↗
- Users are recommended to download the latest GitHub release once it becomes available.
- ICSA-26-188-04OTCVSS 5.4 MediumReleased 2026-06-30 · Updated 2026-07-07
Siemens Mendix Studio Pro
Vendor: SiemensProducts: Mendix Studio Pro 10.11, Mendix Studio Pro 10.12, Mendix Studio Pro 10.13, Mendix Studio Pro 10.14, Mendix Studio Pro 10.15, Mendix Studio Pro 10.16, Mendix Studio Pro 10.17, Mendix Studio Pro 10.18, Mendix Studio Pro 10.19, Mendix Studio Pro 10.20, Mendix Studio Pro 10.21, Mendix Studio Pro 10.22, Mendix Studio Pro 10.23, Mendix Studio Pro 10.24, Mendix Studio Pro 11.0, Mendix Studio Pro 11.1, Mendix Studio Pro 11.10, Mendix Studio Pro 11.11, Mendix Studio Pro 11.2, Mendix Studio Pro 11.3, Mendix Studio Pro 11.4, Mendix Studio Pro 11.5, Mendix Studio Pro 11.6, Mendix Studio Pro 11.7, Mendix Studio Pro 11.8, Mendix Studio Pro 11.9
Critical infrastructure sectorsCritical ManufacturingEnergyMendix Studio Pro versions before V11.12 are affected by a file parsing vulnerability that could be triggered when the application reads specially crafted malicious project during the build pipeline. This could allow an attacker to execute arbitrary code in the context of that user. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.
Named CVEsCVE-2026-48192Weakness classesView CISA CSAF advisory ↗Mitigations- Currently no fix is planned
- Update to V10.24.21 or later versionVendor reference ↗
- Update to V11.6.7 or later versionVendor reference ↗
- ICSA-26-188-03OTCVSS 8.1 HighReleased 2026-06-30 · Updated 2026-07-07
Hitachi Energy e-mesh EMS
Vendor: Hitachi EnergyProduct: Hitachi Energy e-mesh EMS
Critical infrastructure sectorsEnergyHitachi Energy is aware of a buffer overflow vulnerability that affects e-mesh EMS product versions listed in this document. Successful exploitation of this vulnerability could lead to a buffer overflow condition, potentially resulting in application outages (denial of service) and possible arbitrary code execution. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.
Named CVEsWeakness classesView CISA CSAF advisory ↗Mitigations- Apply hotfix for respective e-mesh EMS versions to update NGINX to either v1.30.2 or latest
- Ensure rewrite configuration does not contain "?" to replace unnamed captures, and ensure ASLR is set to active (value=2) across all deployment targets covering all 3 versions.
- Underlying Ubuntu Server 20.04 LTS is End of Life. For e-mesh EMS versions 4.1.6/4.4.2 using Ubuntu 20.04 LTS, upgrade to Ubuntu Server 22.04, or 24.04, or activate Ubuntu Pro/ESM as an interim measure.
- ICSA-26-188-02OTCVSS 7.1 HighReleased 2026-06-30 · Updated 2026-07-07
Hitachi Energy PROMOD V
Vendor: Hitachi EnergyProduct: PROMOD V
Critical infrastructure sectorsEnergyHitachi Energy is aware of insecure HTTP transmission vulnerability in PROMOD V product versions listed in this document. This vulnerability could allow attackers to intercept or manipulate sensitive data in transit, potentially leading to credential theft, session hijacking, or unauthorized access.
Named CVEsCVE-2026-10763Weakness classesView CISA CSAF advisory ↗Mitigations- Upgrade to version 1.0.11 and enable HTTPS on Digipede server. [2] Refer to “1.0.11 PROMOD V User Guide”, Section 2 Essential Skills->Running PROMOD V->Digipede Grid. Alternatively, refer to the same section in the online help contained in the application.
- Apply general mitigation factors
- ICSA-26-181-07OTCVSS 9.8 CriticalReleased 2026-06-30
Delta Electronics DVP12SE PLC
Vendor: Delta ElectronicsProduct: DVP12SE PLC
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of these vulnerabilities could allow an attacker to remotely issue commands, modify operational values, interfere with control logic, and alter device behavior without authentication or privilege enforcement.
Named CVEsCVE-2026-12819CVE-2026-12818View CISA CSAF advisory ↗Mitigations- Delta Electronics is aware of these vulnerabilities and is currently working on a fix.
- Delta Electronics recommends users apply the following workarounds:
- Enable the IP Filter feature: Configure and enable the PLC's built-in IP Filter function via the programming software. Restrict access exclusively to the IP addresses of trusted devices (such as designated HMI panels or SCADA hosts) to block unauthorized network access.Set up PLC password protection: Enable password protection for the PLC within the programming software to ensure the device's core control logic and parameters cannot be easily downloaded, overwritten, or tampered with.Implement network isolation and firewall protection: Deploy the PLC within an independent local area network (OT control network) secured by a firewall. Never connect the device directly to the office network or the Internet. If remote access is required, enforce the use of a secure, authorized VPN tunnel.
- For more information refer to Delta Electronic's advisory page https://www.deltaww.com/en-US/service-support/product-cybersecurity/advisory.Vendor reference ↗
- ICSA-26-181-06OTCVSS 10 CriticalReleased 2026-06-30
StoneFly Storage Concentrator
Vendor: StoneFlyProducts: Storage Concentrator, Storage Concentrator Virtual Machine
Critical infrastructure sectorsDefense Industrial BaseEnergyFinancial ServicesHealthcare and Public HealthInformation TechnologySuccessful exploitation of these vulnerabilities could allow attackers to gain broad unauthorized access, execute arbitrary commands with root privileges, steal sensitive data, and perform actions on behalf of legitimate users across interconnected systems.
Named CVEsCVE-2026-50110CVE-2026-56413CVE-2026-56415CVE-2026-55721CVE-2026-50040View CISA CSAF advisory ↗Mitigations- StoneFly recommends that users upgrade to Storage Concentrator version 8.0.4.29 or later to remediate these vulnerabilities.
- For additional questions or support, users may contact StoneFly at https://stonefly.com/contact-us/.Vendor reference ↗
- ICSA-26-181-02OTCVSS 7.5 HighReleased 2026-06-30
Frangoteam FUXA SCADA/HMI
Vendor: FrangoteamProduct: FUXA SCADA/HMI
Critical infrastructure sectorsCritical ManufacturingEnergyWater and Wastewater SystemsSuccessful exploitation of this vulnerability could allow an unauthenticated remote attacker to enumerate all user accounts and role assignments on a FUXA SCADA/HMI instance.
Named CVEsCVE-2026-13207Weakness classesView CISA CSAF advisory ↗Mitigations- Frangoteam recommends users apply the latest version of FUXA 1.3.2 or later https://github.com/frangoteam/FUXA/releases.Vendor reference ↗
- ICSA-26-181-01OTCVSS 8.8 HighReleased 2026-06-30
Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M
Vendor: Mitsubishi ElectricProduct: MELSOFT Update Manager SW1DND-UDM-M
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of these vulnerabilities could allow a local attacker to tamper with or destroy information in the affected product, cause a denial-of-service condition in the affected product, or execute arbitrary code when a specially crafted archive file is decompressed by the 7-Zip component included in MELSOFT Update Manager.
Named CVEsView CISA CSAF advisory ↗Mitigations- Mitsubishi Electric has identified the following specific workarounds and mitigations users can apply to reduce risk:
- Mitsubishi Electric is releasing fixed version 1.015R or later for MELSOFT Update Manager SW1DND-UDM-M. Please download the update file for the fixed version from the link "https://www.mitsubishielectric.co.jp/fa/download/index.html" (This site is in Japanese) and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-004_en.pdf".Vendor reference ↗
- For users who cannot immediately update the product, Mitsubishi Electric recommends using the PC with the affected product within a LAN and blocking remote logins from untrusted networks, hosts, and users, to minimize the risk of exploitation of this vulnerability.
- For users who cannot immediately update the product, Mitsubishi Electric recommends using a firewall, virtual private network (VPN), or similar network security controls to prevent unauthorized access and allow only trusted users to remote login when internet access is required, to minimize the risk of exploitation of this vulnerability.
- For users who cannot immediately update the product, Mitsubishi Electric recommends restricting physical access to the PC with the affected product and the network to which the PC is connected, to minimize the risk of exploitation of this vulnerability.
- For users who cannot immediately update the product, Mitsubishi Electric recommends preventing users from clicking on web links in emails from untrusted sources, or from opening attachments in untrusted emails, to minimize the risk of exploitation of this vulnerability.
- For users who cannot immediately update the product, Mitsubishi Electric recommends installing anti-virus software on the PC with the affected product, to minimize the risk of exploitation of this vulnerability.
- For more information see the associated Mitsubishi Electric security advisory 2026-004: https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-004_en.pdf.Vendor reference ↗
- ICSMA-26-176-02OTCVSS 8.2 HighReleased 2026-06-25
OHIF Viewers DICOM
Vendor: Open Health Imaging Foundation (OHIF)Product: OHIF DICOM Web Viewer Framework
Critical infrastructure sectorsHealthcare and Public HealthSuccessful exploitation of this vulnerability in a custom integration version could allow an attacker to steal an authenticated clinician's token via a crafted link.
Named CVEsCVE-2026-12473Weakness classesView CISA CSAF advisory ↗Mitigations- The maintainer has fixed the reported vulnerability and released version 3.12.2 (2026-05-18). The fix is located at OHIF/Viewers#5985 (master), OHIF/Viewers#5978 (release/3.12).
- Users are recommended to upgrade to v3.12.2 or later. Operators who need dicomwebproxy or dicomjson in authenticated deployments must additionally configure the new dangerouslyAllowedOriginsForAuthenticatedEnvironments allowlist in app-config.js.
- Users running OHIF with authentication should remove ALL unused DicomWebProxyDataSource and DicomJSONDataSource configurations from the configuration file they are deploying with.
- ICSMA-26-176-01OTCVSS 9.1 CriticalReleased 2026-06-25
pydicom pynetdicom Library
Vendor: pydicomProduct: pynetdicom
Critical infrastructure sectorsHealthcare and Public HealthSuccessful exploitation of this vulnerability could allow an unauthenticated attacker to write to arbitrary file paths.
Named CVEsCVE-2026-56445Weakness classesView CISA CSAF advisory ↗Mitigations- The maintainer of pynetdicom has not responded to requests to work with CISA to mitigate this vulnerability. For update information, refer to the github page https://github.com/pydicom/pynetdicom.Vendor reference ↗
- ICSA-26-195-02OTCVSS 7.8 HighReleased 2026-06-25 · Updated 2026-07-14
ABB Ability Edgenius
Vendor: ABBProducts: Gateway - bE100, Gateway - E3100C, Server - vE1000
Critical infrastructure sectorsCritical ManufacturingABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete control of the system
Named CVEsWeakness classesView CISA CSAF advisory ↗Mitigations- The problem is corrected in the following product versions: - Edgenius 3.2.4.1 ABB recommends that customers apply the update at earliest convenience.
- Mitigating factors describe conditions and circumstances that make an attack that exploits the vulnerability difficult or less likely to succeed. Refer to section General security recommendations for further advise on how to keep your system secure. Recommended mitigation factors - Limit access to ssh or cockpit - By default, no additional lower privilege users are present on Edgenius installations
- ICSA-26-176-06OTCVSS 7.8 HighReleased 2026-06-25
Delta Electronics DTM Soft
Vendor: Delta ElectronicsProduct: DTMSoft
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code.
Named CVEsCVE-2026-12578Weakness classesView CISA CSAF advisory ↗Mitigations- Delta Electronics is aware of the vulnerability and is currently working on a fix.
- Delta Electronics recommends users apply the following workarounds:
- Do not open unsolicited project files: Do not open or import unsolicited project files, untrusted Internet links, or unexpected attachments from emails, network shares, or USB drives. Always verify the source of the file before opening it.
- Avoid running as administrator: Do not use the "Run as Administrator" option when launching the software. Running the software with standard user privileges effectively limits the damage of potential malicious code.
- For more information refer to Delta Electronic's advisory page https://www.deltaww.com/en-US/service-support/product-cybersecurity/advisory.Vendor reference ↗
- ICSA-26-176-05OTCVSS 7.2 HighReleased 2026-06-25
H.VIEW HV-500S6 IP Camera
Vendor: H.VIEWProduct: HV-500S6 IP Camera
Critical infrastructure sectorsCommercial FacilitiesSuccessful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code and upload malicious files to the affected device.
Named CVEsCVE-2026-55975CVE-2026-56414View CISA CSAF advisory ↗Mitigations- H.View did not respond to CISA's request to coordinate. Users are encouraged to reach out to H.View for support. https://hviewsmart.com/pages/contact-usVendor reference ↗
- ICSA-26-176-04OTCVSS 8.1 HighReleased 2026-06-25
Daktronics Controller Firmware
Vendor: DaktronicsProducts: VFC-DMP-5000, DMP-5000, DMP-8000
Critical infrastructure sectorsCommercial FacilitiesInformation TechnologyEmergency ServicesHealthcare and Public HealthSuccessful exploitation of these vulnerabilities could could provide an unauthenticated user with complete root-level access and control of the system.
Named CVEsCVE-2026-28701CVE-2026-33560CVE-2026-31928View CISA CSAF advisory ↗Mitigations- Daktronics recommends users update their device software to one of the following versions (based on product configuration in use): 8.117.0.x, 9.43.0.x, or 10.34.0.x
- Daktronics recommends updating the default passwords and encourages using strong, unique credentials per device.
- ICSA-26-176-03OTCVSS 7.8 HighReleased 2026-06-25
Horner Automation Cscape
Vendor: Horner AutomationProduct: Cscape
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could allow a local attacker to disclose information and execute arbitrary code.
Named CVEsCVE-2026-12897Weakness classesView CISA CSAF advisory ↗Mitigations- Horner Automation has released Cscape 10.2 SP3 for users to download.
- For more information, see the Cscape 10.2 SP3 release notes (https://hornerautomation.com/cscape-software-free/cscape-software/).Vendor reference ↗
- ICSA-26-176-02OTCVSS 9.4 CriticalReleased 2026-06-25
EVoke Systems Charging Station Management System
Vendor: EVoke SystemsProduct: EVoke CSMS
Critical infrastructure sectorsEnergyTransportation SystemsSuccessful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.
Named CVEsCVE-2026-40702CVE-2026-50176CVE-2026-54479CVE-2026-44622View CISA CSAF advisory ↗Mitigations- EVoke states that as a hardware-agnostic platform supporting multiple charger Original Equipment Manufacturers OEMs, EVoke must interoperate with EVSE devices that support different OCPP security profiles depending on the firmware capabilities of the charger. EVoke CSMS currently supports all OCPP security profiles (0–3). However, the effective security configuration for a charger connection is determined by the security profile implemented in the EVSE firmware. Some legacy chargers deployed in the network support only Security Profile 0 or 1. These chargers were installed prior to the broader industry adoption of stronger authentication mechanisms defined in OCPP Security Profiles 2 and 3. EVoke is actively working with charger OEM partners to migrate supported devices to Security Profile 2 (TLS encryption with basic authentication) or Security Profile 3 (Mutual TLS authentication using client certificates). For OEMs that continue to support firmware updates, EVoke will prioritize upgrades to enable Security Profiles 2 or 3.
- EVoke states that certain legacy charger models deployed on the network are no longer supported by the manufacturer (for example, chargers originally produced by EVBox). These devices cannot be upgraded to support stronger security profiles. For chargers limited to Security Profiles 0 or 1, EVoke is implementing additional server-side protections to mitigate spoofing risks. Allow-listed chargers will only be accepted from chargers whose IDs are registered in the EVoke CSMS inventory database. Unknown charger identifiers will be rejected.
- EVoke states that to reduce the risk of duplicate sessions, only a single active connection per charger ID will be permitted. If a second connection using the same charger ID is detected, the new connection will be rejected or the previous session will be terminated. This prevents unauthorized actors from establishing parallel sessions using spoofed charger identifiers.
- EVoke states that the platform will monitor session anomalies including repeated connection attempts, unexpected IP address changes, and abnormal message patterns. Security events will be logged and flagged for operational review.
- EVoke states that to address the risk of denial-of-service via repeated authentication attempts, EVoke will implement connection rate limiting at the WebSocket gateway layer. These controls will restrict excessive connection attempts from the same source and temporarily block abusive traffic patterns.
- EVoke states they are developing a lifecycle policy for legacy chargers that cannot support modern OCPP security profiles. This policy will include identification of unsupported EVSE models and risk classification Migration planning with site operators where possible
- Contact EVoke using their contact page: https://evokesystems.com/contact-us/ for more information.Vendor reference ↗
- ICSA-26-176-01OTCVSS 7.5 HighReleased 2026-06-25
Yokogawa FAST/TOOLS and CI Server
Vendor: YokogawaProducts: FAST/TOOLS, Collaborative Information Server (CI Server)
Critical infrastructure sectorsCritical ManufacturingEnergyFood and AgricultureSuccessful exploitation of this vulnerability may return a response containing the CI Server setting information.
Named CVEsCVE-2026-11833Weakness classesView CISA CSAF advisory ↗Mitigations- Yokogawa recommends users update FAST/TOOLS up to R10.04 and apply patch software (R10.04 SP4).
- Yokogawa recommends users update Collaborative Information Server (CI Server) up to R1.05.
- For more information and details on implementing these mitigations, users should see the Yokogawa security advisory report YSAR-26-0004 at https://web-material3.yokogawa.com/1/39777/files/YSAR-26-0004-E.pdfVendor reference ↗
- For questions related to this report, please contact the below.https://contact.yokogawa.com/cs/gw?c-id=000498Vendor reference ↗
- ICSA-26-195-01OTCVSS 4.4 MediumReleased 2026-06-23 · Updated 2026-07-14
ABB Advant Master Online Builder
Vendor: ABBProducts: Control Builder A, 800xA for Advant Master
Critical infrastructure sectorsCritical ManufacturingABB became aware of vulnerability in the products versions listed as affected in the advisory, where an incorrect version of Online Builder (ONB) was included in the media. An update is available that resolves the vulnerability, see details in Recommended immediate actions.
Named CVEsCVE-2025-13162Weakness classesView CISA CSAF advisory ↗Mitigations- ABB has investigated the vulnerability and remediated it in the newly released versions. The vulnerability has been resolved in the product versions listed as fixed in the advisory. - Version 6.1.1-2 does not contain this vulnerability and therefore no update is required. The vulnerability was again introduced in 6.1.1-3 when an older ONB version was included in the release media. - Version 6.1.1-4 do not contain this vulnerability but present version 6.1.1-3 by 800xA System Installer and System Configuration Console (SCC). Version 6.1.1-4 is therefore withdrawn. - Version 6.2.0-2 do not contain this vulnerability but present version 6.2.0-1 by 800xA System Installer and System Configuration Console (SCC). Version 6.2.0-2 is therefore withdrawn. ABB recommends that customers apply the update at their earliest convenience. - Control Builder A: It is recommended to update Control Builder A to version 1.4/5 or later. - 800xA for Advant Master: - Versions 6.0.3-1 and earlier, - Versions 6.1.1-1 and earlier, - Versions 6.1.1-2, 6.1.1-3, and 6.1.1-4 should be updated to version 6.1.1-5 or later. - 800xA for Advant Master: - Versions 6.2.0-1 and 6.2.0-2 should be updated to version 6.2.0-3 or later.
- Since it is required that the attacker has access to the system, it is important that all users that have access to the system are managed as recommended by ABB guidelines. - Allow only authorized users to log on to the system and enforce strong passwords that are changed regularly. - Restrict temporary connection of portable computers, USB memory devices and other removable data carriers. Computers that can be physically accessed by regular users should have ports for removable data carriers disabled or at least managed to only allow intended device types. For more information on recommended practices, see [1].
- The recommendation is to upgrade to a version where the vulnerability is corrected. If an upgrade Is not possible and a workaround is needed, contact ABB Support.
- ICSA-26-174-07OTCVSS 7.5 HighReleased 2026-06-23
Hubbell Aclara Metrum Cellular Web Interface
Vendor: HubbellProduct: Aclara Metrum Cellular Web Interface
Critical infrastructure sectorsEnergySuccessful exploitation of this vulnerability could allow attackers to manipulate critical device settings and repeatedly disrupt operations, potentially causing a loss of communications to the device.
Named CVEsCVE-2026-1840Weakness classesView CISA CSAF advisory ↗Mitigations- Hubbell encourages users to update their firmware to v2.1.0.105 in order to minimize network exposure and ensure that devices are not accessible from the Internet. Users can download version 2.1.0.105 from AclaraConnect https://aclara.my.site.com/AclaraConnect/s/.Vendor reference ↗
- ICSMA-26-169-01OTCVSS 6.5 MediumReleased 2026-06-18
Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT
Vendor: Apollo PharmacyProduct: Blood Glucose Monitoring System (Model No. APG-01 BT)
Critical infrastructure sectorsHealthcare and Public HealthSuccessful exploitation of these vulnerabilities could allow an attacker to obtain sensitive health-related information and prevent legitimate users from establishing a connection with the device.
Named CVEsCVE-2026-50034CVE-2026-52866View CISA CSAF advisory ↗Mitigations- Apollo Pharmacy did not respond to CISA's requests to coordinate. Users are encouraged to reach out to Apollo Pharmacy directly for more information:https://www.apollopharmacy.in/contact-us.Vendor reference ↗
- CISA recommends users follow the guidance in the Understanding Bluetooth Technology blog https://www.cisa.gov/news-events/news/understanding-bluetooth-technology.Vendor reference ↗
- ICSA-26-169-06OTCVSS 7.5 HighReleased 2026-06-18
Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module
Vendor: Mitsubishi ElectricProduct: Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition in the affected product by continuously sending a large number of communication packets to the Ethernet port of the product in a short period of time, increasing the processing load of the product, preventing the internal anomaly-detection processing from being performed, and causing the communication function to stop.
Named CVEsCVE-2026-8806Weakness classesView CISA CSAF advisory ↗Mitigations- There are no plans to release fixed version for MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP. For customers of MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP, refer to the Mitsubishi Electric security advisory "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-003_en.pdf", and take the actions described there.Vendor reference ↗
- For customers, Mitsubishi Electric recommends using a firewall, virtual private network (VPN), etc. to prevent unauthorized access when internet access is required, to minimize the risk of exploiting this vulnerability.
- For customers, Mitsubishi Electric recommends using the affected product within a LAN and blocking access from untrusted networks and hosts through firewalls, to minimize the risk of exploiting this vulnerability.
- For customers, Mitsubishi Electric recommends using the IP filter function of the affected product to block access from untrusted hosts and minimize the risk of exploiting this vulnerability. For details on the IP filter function, refer to "13.1 IP Filter Function" in the MELSEC iQ-F FX5 User's Manual (Communication) which can be downloaded from the link "https://www.mitsubishielectric.com/fa/download/index.html."Vendor reference ↗
- For customers, Mitsubishi Electric recommends restricting physical access to the affected product, as well as to PCs and network devices to which it is connected, to minimize the risk of exploiting this vulnerability.
- For customers, Mitsubishi Electric recommends installing anti-virus software on PCs that can access the affected product, to minimize the risk of exploiting this vulnerability.
- ICSA-26-169-05OTCVSS 7.5 HighReleased 2026-06-18
Mitsubishi Electric MELSEC iQ-F Series
Vendor: Mitsubishi ElectricProduct: MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition in the affected product by rapidly establishing a large number of TCP connections to it, resulting in an inconsistency in the product's internal connection management process and triggering improper memory access.
Named CVEsCVE-2026-8805Weakness classesView CISA CSAF advisory ↗Mitigations- Mitsubishi Electric is releasing fixed version 1.001 or later for MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP. Download the update file for the fixed version from the link "https://www.mitsubishielectric.com/fa/download/index.html" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-002_en.pdf".Vendor reference ↗
- For users who cannot immediately update the product, Mitsubishi Electric recommends using a firewall, virtual private network (VPN), etc. to prevent unauthorized access when internet access is required, to minimize the risk of exploiting this vulnerability.
- For users who cannot immediately update the product, Mitsubishi Electric recommends using the affected product within a LAN and blocking access from untrusted networks and hosts through firewalls, to minimize the risk of exploiting this vulnerability.
- For users who cannot immediately update the product, Mitsubishi Electric recommends using the IP filter function of the affected product to block access from untrusted hosts and minimize the risk of exploiting this vulnerability. For details on the IP filter function, refer to "13.1 IP Filter Function" in the MELSEC iQ-F FX5 User's Manual (Communication) which can be downloaded from the link "https://www.mitsubishielectric.com/fa/download/index.html."Vendor reference ↗
- For users who cannot immediately update the product, Mitsubishi Electric recommends restricting physical access to the affected product, as well as to PCs and network devices to which it is connected, to minimize the risk of exploiting this vulnerability.
- For users who cannot immediately update the product, Mitsubishi Electric recommends installing anti-virus software on PCs that can access the affected product, to minimize the risk of exploiting this vulnerability.
- ICSA-26-169-03OTCVSS 7.7 HighReleased 2026-06-18
Rockwell Automation FactoryTalk Historian Site Edition
Vendor: Rockwell AutomationProduct: FactoryTalk Historian SE
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of these vulnerabilities could allow an attacker to obtain a valid authentication token, perform a denial of service, or crash the system.
Named CVEsCVE-2025-13036CVE-2025-44019CVE-2025-36539View CISA CSAF advisory ↗Mitigations- Rockwell Automation recommends the following: Mitigations and Workarounds for CVE-2025-13036: Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use our security best practices and consider applying the available patch (BF32850) for their current version (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1157978/loc/en_US).Vendor reference ↗
- For more information, see Rockwell Automation Security Advisory SD1773 (https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1773.html)Vendor reference ↗
- Mitigations and Workarounds for CVE-2025-36539 & CVE-2025-44109: Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use our security best practices and also consider the following: Monitor liveness of PI Network Manager and PI Archive Subsystem services. Set the PI Network Manager and PI Archive Subsystem services to automatically restart. Limit port 5450 access to trusted workstations and software. For a list of PI System firewall port requirements, see knowledge base article KB01162 - Firewall Port Requirements. For a starting point on PI system security best practices, see knowledge base article KB00833 - Best practices for securing your PI Server.
- ICSA-26-169-02OTCVSS 7.8 HighReleased 2026-06-18 · Updated 2026-06-25
AzeoTech DAQFactory (Update A)
Vendor: AzeoTechProduct: DAQFactory
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of these vulnerabilities could allow an attacker to upload malicious .ctl files that may lead to arbitrary code execution.
Named CVEsCVE-2026-12390CVE-2026-12921View CISA CSAF advisory ↗Mitigations- Users are discouraged from using documents from unknown/untrusted sources.
- Users are encouraged to store .ctl files in a folder only writeable by admin-level users.
- Users are encouraged to operate in "Safe Mode" when loading documents that have been out of their control.
- Users are encouraged to apply a document editing password to their documents.
- ICSA-26-169-01OTCVSS 9.8 CriticalReleased 2026-06-18
AVer PTC cameras
Vendor: AVerProducts: PTC500S, PTC115, PTC500+, PTC115+
Critical infrastructure sectorsGovernment FacilitiesCommercial FacilitiesHealthcare and Public HealthSuccessful exploitation of this vulnerability could allow arbitrary code execution.
Named CVEsCVE-2026-40624Weakness classesView CISA CSAF advisory ↗Mitigations- AVer has provided a firmware fix to address this vulnerability; users can find it at the following location: (https://presentation.aver.com/DownloadFile.aspx?n=6617|1C01A887-7CDC-4C96-AD9A-11D53DE1AD71&t=ServiceDownload).Vendor reference ↗
- ICSA-26-167-05OTCVSS 9.4 CriticalReleased 2026-06-16
Rockwell Automation FLEX I/O EtherNet/IP Adapters
Vendor: Rockwell AutomationProducts: 1794-AENTR, 1794-AENTRXT
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access, account takeover, and cause loss of availability.
Named CVEsCVE-2026-0646CVE-2026-0647View CISA CSAF advisory ↗Mitigations- Rockwell Automation recommends users update to 2.013 to resolve these vulnerabilities.
- For more information, please visit Rockwell Automation's SD1775 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1775.htmlVendor reference ↗
- ICSA-26-167-04OTCVSS 7.5 HighReleased 2026-06-16
Rockwell Automation CompactLogix
Vendor: Rockwell AutomationProducts: CompactLogix 5370 L1, CompactLogix 5370 L2, CompactLogix 5370 L3
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition.
Named CVEsCVE-2025-11694CVE-2026-9307View CISA CSAF advisory ↗Mitigations- Rockwell Automation recommends users update to V38.011 https://compatibility.rockwellautomation.com/Pages/MultiProductFindDownloads.aspx?crumb=112&mode=3&refSoft=1&versions=55023,55024,55025,55026,55027,55061Vendor reference ↗
- For more information, please visit Rockwell Automations SD1776 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1776.htmlVendor reference ↗
- ICSA-26-167-03OTCVSS 7.5 HighReleased 2026-06-16
Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP
Vendor: Rockwell AutomationProducts: CompactLogix 5370, Compact GuardLogix 5370, ControlLogix 5570, GuardLogix 5570
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could cause a denial-of-service condition that may result in a major nonrecoverable fault (MNRF).
Named CVEsCVE-2026-11317Weakness classesView CISA CSAF advisory ↗Mitigations- Rockwell Automation recommends users to update to the following versions: CompactLogix 5370: Versions 34.016 and later
- Compact GuardLogix 5370: Versions 35.015 and later
- ControlLogix 5570: Versions 36.012 and later
- GuardLogix 5570: Versions 37.011 and later
- For more information, see Rockwell Automation Security Advisory SD1772 (https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1772.html)Vendor reference ↗
- ICSA-26-167-02OTCVSS 7.5 HighReleased 2026-06-16
RSLinx Classic Third-Party Vulnerability
Vendor: Rockwell AutomationProduct: RSLinx Classic
Critical infrastructure sectorsCritical ManufacturingEnergyFood and AgricultureWater and Wastewater SystemsSuccessful exploitation of this vulnerability can lead to a denial of service, where the application will become unresponsive and will not recover on its own.
Named CVEsCVE-2020-13573Weakness classesView CISA CSAF advisory ↗Mitigations- Rockwell Automation recommends that customers using the affected software should upgrade to version 4.60.00 or later. Customers who are not able to upgrade to one of the corrected versions, should consider applying the available patch (BF31213) for their current version or applying the recommended security best practices.Vendor reference ↗
- ICSA-26-167-01OTCVSS 7 HighReleased 2026-06-16
Rockwell Automation FactoryTalk Analytics PavilionX
Vendor: Rockwell AutomationProduct: FactoryTalk Analytics PavilionX
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could result in an attacker executing privileged operations.
Named CVEsCVE-2025-14272Weakness classesView CISA CSAF advisory ↗Mitigations- Rockwell Automation recommends users update FactoryTalk Analytics PavilionX software to version 7.01 or later. The upgrade can be downloaded from the Rockwell Automation Download Center: https://www.rockwellautomation.com/en-us/support/product/product-downloads.htmlVendor reference ↗
- See Rockwell Automation's SD1777 advisory for more information: https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1777.htmlVendor reference ↗
- ICSA-26-174-06OTCVSS 7.8 HighReleased 2026-06-11 · Updated 2026-06-23
Impact of Linux Kernel vulnerabilities on B&R products
Vendor: B&R Industrial Automation GmbHProducts: Linux for B&R, APROL, X20EDS410
Critical infrastructure sectorsCritical ManufacturingB&R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory. Successful local exploitation of these vulnerabilities could allow an attacker to escalate privileges on the affected system. Public proof-of-concept exploits are available for the vulnerabilities described herein. At the time of publication of this advisory, B&R had no evidence of active exploitation targeting B&R products.
Named CVEsView CISA CSAF advisory ↗Mitigations- For affected products, software updates should be installed upon availability. Product Patch version - APROL : APROL-AutoYaST-DVD- V4.4-010.10.260602 Until remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.
- Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts. Refer to section “General security recommendations” for further advise on how to keep your system secure.
- Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed. Important: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer's responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments. For Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command: sudo apt update && sudo apt upgrade A system reboot is required after the upgrade for the updated kernel to take effect. Temporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431. Execute the following commands as root: echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf rmmod algif_aead 2>/dev/null || true Impact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run: lsof | grep AF_ALG
- ICSA-26-162-03OTCVSS 7.7 HighReleased 2026-06-11
Brickcom Cameras
Vendor: BrickcomProducts: Brickcom Cube, Brickcom Dome, Brickcom Bullet, Brickcom Box
Critical infrastructure sectorsCommercial FacilitiesCritical ManufacturingFinancial ServicesHealthcare and Public HealthSuccessful exploitation of these vulnerabilities could allow a remote unauthenticated attacker to gain unauthorized access to live video feeds, retrieve sensitive visual information from affected premises, and obtain administrative control of the device.
Named CVEsCVE-2026-50245CVE-2026-50005View CISA CSAF advisory ↗Mitigations- Brickcom did not respond to CISAs request for coordination. Users are encouraged to reach out to Brickcom for support https://www.brickcom.com/case/Vendor reference ↗
- ICSA-26-162-02OTCVSS 9.8 CriticalReleased 2026-06-11
Naxclow IoT Platform
Vendor: NaxclowProducts: Smart Doorbell X3, X Smart Home, V720, ix cam
Critical infrastructure sectorsCommercial FacilitiesSuccessful exploitation of these vulnerabilities could allow an attacker to impersonate devices, intercept or manipulate communications, harvest sensitive credentials at scale, or gain unauthorized access.
Named CVEsCVE-2026-42947CVE-2026-50108CVE-2026-50101CVE-2026-28742CVE-2026-42932CVE-2026-50244CVE-2026-50099View CISA CSAF advisory ↗Mitigations- Naxclow did not respond to CISA's attempts to coordinate these vulnerabilities. Users should contact Naxclow for more information.
- ICSA-26-162-01OTCVSS 9.8 CriticalReleased 2026-06-11
Yarbo Android/iOS Mobile Application and Cloud Infrastructure
Vendor: YarboProducts: Yarbo Android/IOS mobile application, Cloud MQTT infrastructure
Critical infrastructure sectorsCommercial FacilitiesSuccessful exploitation of these vulnerabilities could allow an attacker to obtain hard-coded credentials, gain access to telemetry data, and potentially send operational commands to the robot fleet.
Named CVEsCVE-2026-10557CVE-2026-7368View CISA CSAF advisory ↗Mitigations- Yarbo recommends users update the Yarbo mobile app to 3.17.4 or later. Server-side broker authorization will be enforced automatically upon deployment of the May 2026 update. No user action is required.
- ICSA-26-181-05OTCVSS 7.5 HighReleased 2026-06-10 · Updated 2026-06-30
XZ Utils vulnerability impacting B&R Products
Vendor: B&R Industrial Automation GmbHProducts: PPC3100, C50, C80, FT50, MT50, T30, T80, T50
Critical infrastructure sectorsCritical ManufacturingAn update is available that resolves vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the product to stop or corrupt memory data.
Named CVEsCVE-2025-31115Weakness classesView CISA CSAF advisory ↗Mitigations- The problem is corrected in the following product versions: Product Terminal OS Version - PPC3100 1.8.1 - C50 1.8.0 - C80 1.8.0 - FT50 1.8.1 - MT50 1.8.1 - T30 1.8.0 - T80 1.8.0 - T50 1.8.1 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.
- Refer to section “General security recommendations” for further advise on how to keep your system secure
- ICSA-26-174-05OTCVSS 6.6 MediumReleased 2026-06-10 · Updated 2026-06-23
ABB Freelance Security Lock
Vendor: ABBProducts: System Version, Freelance Security Lock
Critical infrastructure sectorsCritical ManufacturingABB is aware of a vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the product to stop or make the product inaccessible.
Named CVEsCVE-2025-7064Weakness classesView CISA CSAF advisory ↗Mitigations- ABB recommends using Freelance Extended User Management instead of Security Lock. Freelance Extended User Management is based on Windows user accounts and is available for Freelance 2019 or higher. For Freelance 2016 and earlier, please refer to chapter “General Security Information”. A fix for Freelance Security Lock is in preparation and will be announced in this updated document. Refer to section “General security recommendations” for further advise on how to keep your system secure. To reduce the likelihood of exploitation via keyboard shortcuts: - disable unnecessary accessibility features - use hardened OS configurations that suppress system-level shortcuts - implement BIOS/UEFI-level restrictions on keyboard input during runtime.
- Workarounds are specific measures that a user can take to help block an attack, for example, temporarily disabling the vulnerable feature may remove the exposure with well-known impact on functionality. ABB has tested the following workaround. Although this workaround will not correct the underlying vulnerability, it can help block known attack vectors. When a workaround reduces functionality, this is identified below as “Impact of workaround”. For Freelance 2019 and higher, ABB recommends using Freelance Extended User Management instead of Security Lock. For Freelance 2016 SP1 and older, no workaround is available.
- ICSA-26-181-04OTCVSS 7.5 HighReleased 2026-06-09 · Updated 2026-06-25
Schneider Electric EasyLogic T150 and Saitel DP RTU
Vendor: Schneider ElectricProducts: EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller, EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller Firmware, Saitel DP Remote Terminal Unit & Controller, Saitel DP Remote Terminal Unit & Controller Firmware
Critical infrastructure sectorsCritical ManufacturingEnergySchneider Electric is aware of a vulnerability in its EasyLogic T150 (formerly known as Saitel DR) and Saitel DP Remote Terminal Unit & Controller products. The [EasyLogic T150 (formerly known as Saitel DR RTU)](https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=62685#overview) is a field device, offering a solid and powerful modular platform for data acquisition, communication, automation and IED integration for distribution and transmission networks, generation sector and railway. The [Saitel DP RTU](https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=61747) is a modular platform for medium voltage and high voltage public distribution and transmission substation control. Failure to apply the mitigations provided below may risk credential harvesting and unauthorized access attacks, which could result in exposure of sensitive information and compromise of device integrity and operations when an attacker has subsequent physical access to the device.
Named CVEsCVE-2026-9650CVE-2026-9651View CISA CSAF advisory ↗Mitigations- Version 11.06.32 of EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller includes a fix for these vulnerabilities and is available:• Contact Schneider Electric’s Customer Care Center to download this firmware.• Reboot needed: Yes.
- Version 11.06.38 of SAITEL DP Remote Terminal Unit & Controller includes a fix for these vulnerabilities and is available:• Contact Schneider Electric’s Customer Care Center to download this firmware.• Reboot needed: Yes.
- ICSA-26-181-03OTCVSS 6.5 MediumReleased 2026-06-09 · Updated 2026-06-30
Schneider Electric EcoStruxure IT Data Center Expert
Vendor: Schneider ElectricProduct: EcoStruxure IT Data Center Expert
Critical infrastructure sectorsInformation TechnologyCritical ManufacturingEnergySchneider Electric is aware of a vulnerability in its EcoStruxure™ IT Data Center Expert. The EcoStruxure™ IT Data Center Expert product is a scalable monitoring software that collects, organizes, and distributes critical device information providing a comprehensive view of equipment. Failure to apply the remediation provided below may risk information disclosure.
Named CVEsCVE-2026-8045Weakness classesView CISA CSAF advisory ↗Mitigations- v9.1.2 of EcoStruxure™ IT Data Center Expert includes a fix for this vulnerability and is available for download here: https://www.se.com/en/product-range/61851-ecostruxure-it-data- center-expert/#software-and-firmwareVendor reference ↗
- ICSA-26-176-07OTCVSS 7.5 HighReleased 2026-06-09 · Updated 2026-06-25
Schneider Electric PowerLogic P7
Vendor: Schneider ElectricProduct: PowerLogic™ P7
Critical infrastructure sectorsCommercial FacilitiesCritical ManufacturingEnergySchneider Electric is aware of a vulnerability in its PowerLogic™ P7 product. The PowerLogic™ P7 is a protection and control platform designed for complex and advanced electrical network applications. Failure to apply the remediation provided below may risk unauthorized execution of privileged commands or loss of HMI operability and configuration functionality, which could result in loss of control over system operations and disruption of critical services.
Named CVEsCVE-2026-9716CVE-2026-9717CVE-2026-9718View CISA CSAF advisory ↗Mitigations- Version V02.004.001 of PowerLogicTM P7 includes a fix for this vulnerability and is available for download here: • Contact Schneider Electric’s Customer Care Center to download this firmware. • Reboot needed: Yes
- If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Restrict network access to P7 service endpoints (ports 8080 and 3702) • Monitor and alert on anomalous SOAP requests targeting wsApp • Limit administrative access and apply least privilege principles for all users interacting with P7.
- ICSA-26-174-04OTCVSS 8.8 HighReleased 2026-06-09 · Updated 2026-06-23
Siemens SINEC INS
Vendor: SiemensProduct: SINEC INS
Critical infrastructure sectorsCritical ManufacturingTransportation SystemsEnergyHealthcare and Public HealthFinancial ServicesGovernment FacilitiesSINEC INS before V1.0 SP2 Update 6 is affected by multiple vulnerabilities. Siemens has released a new version for SINEC INS and recommends to update to the latest version.
Named CVEsCVE-2026-46746CVE-2026-46747CVE-2026-46748CVE-2026-46749View CISA CSAF advisory ↗Mitigations- Update to V1.0 SP2 Update 6 or later versionVendor reference ↗
- ICSA-26-174-03OTCVSS 9.8 CriticalReleased 2026-06-09 · Updated 2026-06-23
Siemens Products using OpenSSL
Vendor: SiemensProducts: AI Lightweight Inference Server, Connector for Azure, Databus, HiMed Cockpit, RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2), SCALANCE LPE9403 (6GK5998-3GS00-2AC2), SCALANCE LPE9413 (6GK5998-3GS01-2AC2), SCALANCE LPE9433 (6GK5998-3GS11-2AC2), SCALANCE M804PB (6GK5804-0AP00-2AA2), SCALANCE M812-1 ADSL-Router family, SCALANCE M816-1 ADSL-Router family, SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2), SCALANCE M874-2 (6GK5874-2AA00-2AA2), SCALANCE M874-3 (6GK5874-3AA00-2AA2), SCALANCE M874-3 3G-Router (CN) (6GK5874-3AA00-2FA2), SCALANCE M876-3 (6GK5876-3AA02-2BA2), SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2), SCALANCE M876-4 (6GK5876-4AA10-2BA2), SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2), SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2), SCALANCE MUB852-1 (A1) (6GK5852-1EA10-1AA1), SCALANCE MUB852-1 (B1) (6GK5852-1EA10-1BA1), SCALANCE MUM853-1 (A1) (6GK5853-2EA10-2AA1), SCALANCE MUM853-1 (B1) (6GK5853-2EA10-2BA1), SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1), SCALANCE MUM856-1 (A1) (6GK5856-2EA10-3AA1), SCALANCE MUM856-1 (B1) (6GK5856-2EA10-3BA1), SCALANCE MUM856-1 (CN) (6GK5856-2EA00-3FA1), SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1), SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1), SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2), SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2), SCALANCE SC622-2C (6GK5622-2GS00-2AC2), SCALANCE SC626-2C (6GK5626-2GS00-2AC2), SCALANCE SC632-2C (6GK5632-2GS00-2AC2), SCALANCE SC636-2C (6GK5636-2GS00-2AC2), SCALANCE SC642-2C (6GK5642-2GS00-2AC2), SCALANCE SC646-2C (6GK5646-2GS00-2AC2), SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0), SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0), SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0), SCALANCE WAM766-1 (6GK5766-1GE00-7DA0), SCALANCE WAM766-1 (ME) (6GK5766-1GE00-7DC0), SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0), SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0), SCALANCE WAM766-1 EEC (ME) (6GK5766-1GE00-7TC0), SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0), SCALANCE WUB762-1 (6GK5762-1AJ00-1AA0), SCALANCE WUB762-1 iFeatures (6GK5762-1AJ00-2AA0), SCALANCE WUM763-1 (6GK5763-1AL00-3AA0), SCALANCE WUM763-1 (6GK5763-1AL00-3DA0), SCALANCE WUM763-1 (US) (6GK5763-1AL00-3AB0), SCALANCE WUM763-1 (US) (6GK5763-1AL00-3DB0), SCALANCE WUM766-1 (6GK5766-1GE00-3DA0), SCALANCE WUM766-1 (ME) (6GK5766-1GE00-3DC0), SCALANCE WUM766-1 (USA) (6GK5766-1GE00-3DB0), SCALANCE XC316-8 (6GK5324-8TS00-2AC2), SCALANCE XC324-4 (6GK5328-4TS00-2AC2), SCALANCE XC324-4 EEC (6GK5328-4TS00-2EC2), SCALANCE XC332 (6GK5332-0GA00-2AC2), SCALANCE XC416-8 (6GK5424-8TR00-2AC2), SCALANCE XC424-4 (6GK5428-4TR00-2AC2), SCALANCE XC432 (6GK5432-0GR00-2AC2), SCALANCE XR302-32 (6GK5334-5TS00-2AR3), SCALANCE XR302-32 (6GK5334-5TS00-3AR3), SCALANCE XR302-32 (6GK5334-5TS00-4AR3), SCALANCE XR322-12 (6GK5334-3TS00-2AR3), SCALANCE XR322-12 (6GK5334-3TS00-3AR3), SCALANCE XR322-12 (6GK5334-3TS00-4AR3), SCALANCE XR326-8 (6GK5334-2TS00-2AR3), SCALANCE XR326-8 (6GK5334-2TS00-3AR3), SCALANCE XR326-8 (6GK5334-2TS00-4AR3), SCALANCE XR326-8 EEC (6GK5334-2TS00-2ER3), SCALANCE XR502-32 (6GK5534-5TR00-2AR3), SCALANCE XR502-32 (6GK5534-5TR00-3AR3), SCALANCE XR502-32 (6GK5534-5TR00-4AR3), SCALANCE XR522-12 (6GK5534-3TR00-2AR3), SCALANCE XR522-12 (6GK5534-3TR00-3AR3), SCALANCE XR522-12 (6GK5534-3TR00-4AR3), SCALANCE XR524-8WG (6GK5532-2SR00-2AR3), SCALANCE XR524-8WG (6GK5532-2SR00-2RR3), SCALANCE XR524-8WG (6GK5532-2SR00-3AR3), SCALANCE XR524-8WG (6GK5532-2SR00-3RR3), SCALANCE XR526-8 (6GK5534-2TR00-2AR3), SCALANCE XR526-8 (6GK5534-2TR00-3AR3), SCALANCE XR526-8 (6GK5534-2TR00-4AR3), Shopfloor IT Suite, SIDIS Prime, Siemens OPC UA Modelling Editor (SiOME), SIMATIC Comfort/Mobile RT, SIMATIC eaSie Core Package (6DL5424-0AX00-0AV8), SIMATIC eaSie PCS 7 Skill Package (6DL5424-0BX00-0AV8), SIMATIC HMI Basic Panels, SIMATIC HMI Comfort Panels, SIMATIC HMI Mobile Panels, SIMATIC IOT2050 (6ES7647-0BA00-1YA2), SIMATIC IPC BX-21A, SIMATIC IPC MD-57A, SIMATIC IPC ORCLA, SIMATIC PDM V9.3, SIMATIC RTLS Locating Manager (6GT2780-0DA00), SIMATIC RTLS Locating Manager (6GT2780-0DA10), SIMATIC RTLS Locating Manager (6GT2780-0DA20), SIMATIC RTLS Locating Manager (6GT2780-0DA30), SIMATIC RTLS Locating Manager (6GT2780-1EA10), SIMATIC RTLS Locating Manager (6GT2780-1EA20), SIMATIC RTLS Locating Manager (6GT2780-1EA30), SIMATIC STEP 7 V5, SIMATIC Target, SIMATIC WinCC OA V3.19, SIMATIC WinCC OA V3.20, SIMATIC WinCC OA V3.21, SIMATIC WinCC Runtime Advanced V17, SIMATIC WinCC Unified Sequence, SIMATIC WinCC V7.5, SIMATIC WinCC V8.0, SIMATIC WinCC V8.1, SIMOTION OACAMGEN (6AU1820-3EA20-0AB0), SIMOVE Fleetmanager V3.1, SIMOVE Fleetmanager V3.2, SIMOVE Fleetmanager V3.3, SINAMICS G200, SINAMICS G220, SINAMICS S200, SINAMICS S210, SINAMICS S220, SINEC INS, SINEC NMS, SINEC Security Monitor, SINUMERIK Access MyMachine /OPC UA, SIPLANT, SITRANS ASM IQ, SITRANS Soft Sensor Engine IQ (SITRANS SSE IQ), User Management Component (UMC), Visual Inspection Cockpit
Critical infrastructure sectorsCritical ManufacturingTransportation SystemsEnergyHealthcare and Public HealthFinancial ServicesGovernment FacilitiesOpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
Named CVEsCVE-2025-15467Weakness classesView CISA CSAF advisory ↗Mitigations- As a defense-in-depth measure, organizations may review whether affected systems are exposed to untrusted CMS/PKCS#7 content from external sources.
- Do not accept files from untrusted and unvalidated sources in the affected applications
- Restrict the port at the host with the DeviceConnectionProxy to secure destinations
- Securing the connected email server as follows: • Configure the email server to enforce encrypted communication (TLS/SSL) for all SMTP connections. • Restrict access to the email server to trusted systems only (e.g., by using firewall rules or IP allowlists). • Ensure strong authentication to access the email server. • Keep the email server software and underlying operating system up to date with the latest security patches.
- Securing the connected email server as follows: • Configure the email server to enforce encrypted communication (TLS/SSL) for all SMTP connections. • Restrict access to the email server to trusted systems only (e.g., by using firewall rules or IP allowlists). • Ensure strong authentication to access the email server. • Keep the email server software and underlying operating system up to date with the latest security patches.
- The hardening instructions mentioned in the products security concept should be followed
- Currently no fix is planned
- Currently no fix is available
- Update to V1.0 SP2 Update 5 or later versionVendor reference ↗
- Update to V1.8.0 or later versionVendor reference ↗
- Update to V17 Update 9 or later versionVendor reference ↗
- Update to V17.9 or later versionVendor reference ↗
- Update to V2.15.3.0 or later versionVendor reference ↗
- Update to V21 or later versionVendor reference ↗
- Update to V3.19 P024 or later versionVendor reference ↗
- Update to V3.20 P012 or later versionVendor reference ↗
- Update to V3.21 P02 or later versionVendor reference ↗
- Update to V3.3.2 or later versionVendor reference ↗
- Update to V5.7 SP4 or later versionVendor reference ↗
- Contact customer support siplant-support.de@siemens.com
- ICSA-26-174-02OTCVSS 6.1 MediumReleased 2026-06-09 · Updated 2026-06-23
Siemens SIPROTEC 5 Using DIGSI5 Protocol
Vendor: SiemensProducts: SIPROTEC 5 6MD84 (CP300), SIPROTEC 5 6MD85 (CP200), SIPROTEC 5 6MD85 (CP300), SIPROTEC 5 6MD86 (CP200), SIPROTEC 5 6MD86 (CP300), SIPROTEC 5 6MD89 (CP300), SIPROTEC 5 6MU85 (CP300), SIPROTEC 5 7KE85 (CP200), SIPROTEC 5 7KE85 (CP300), SIPROTEC 5 7SA82 (CP100), SIPROTEC 5 7SA82 (CP150), SIPROTEC 5 7SA86 (CP200), SIPROTEC 5 7SA86 (CP300), SIPROTEC 5 7SA87 (CP200), SIPROTEC 5 7SA87 (CP300), SIPROTEC 5 7SD82 (CP100), SIPROTEC 5 7SD82 (CP150), SIPROTEC 5 7SD86 (CP200), SIPROTEC 5 7SD86 (CP300), SIPROTEC 5 7SD87 (CP200), SIPROTEC 5 7SD87 (CP300), SIPROTEC 5 7SJ81 (CP100), SIPROTEC 5 7SJ81 (CP150), SIPROTEC 5 7SJ82 (CP100), SIPROTEC 5 7SJ82 (CP150), SIPROTEC 5 7SJ85 (CP200), SIPROTEC 5 7SJ85 (CP300), SIPROTEC 5 7SJ86 (CP200), SIPROTEC 5 7SJ86 (CP300), SIPROTEC 5 7SK82 (CP100), SIPROTEC 5 7SK82 (CP150), SIPROTEC 5 7SK85 (CP200), SIPROTEC 5 7SK85 (CP300), SIPROTEC 5 7SL82 (CP100), SIPROTEC 5 7SL82 (CP150), SIPROTEC 5 7SL86 (CP200), SIPROTEC 5 7SL86 (CP300), SIPROTEC 5 7SL87 (CP200), SIPROTEC 5 7SL87 (CP300), SIPROTEC 5 7SS85 (CP200), SIPROTEC 5 7SS85 (CP300), SIPROTEC 5 7ST85 (CP200), SIPROTEC 5 7ST85 (CP300), SIPROTEC 5 7ST86 (CP300), SIPROTEC 5 7SX82 (CP150), SIPROTEC 5 7SX85 (CP300), SIPROTEC 5 7SY82 (CP150), SIPROTEC 5 7UM85 (CP300), SIPROTEC 5 7UT82 (CP100), SIPROTEC 5 7UT82 (CP150), SIPROTEC 5 7UT85 (CP200), SIPROTEC 5 7UT85 (CP300), SIPROTEC 5 7UT86 (CP200), SIPROTEC 5 7UT86 (CP300), SIPROTEC 5 7UT87 (CP200), SIPROTEC 5 7UT87 (CP300), SIPROTEC 5 7VE85 (CP300), SIPROTEC 5 7VK87 (CP200), SIPROTEC 5 7VK87 (CP300), SIPROTEC 5 7VU85 (CP300), SIPROTEC 5 Compact 7SX800 (CP050)
Critical infrastructure sectorsCritical ManufacturingTransportation SystemsEnergyHealthcare and Public HealthFinancial ServicesGovernment FacilitiesSIPROTEC 5 is vulnerable to arbitrary file uploads by authenticated users using the DIGSI 5 protocol. This could allow an attacker to upload malicious configuration files, potentially causing a permanent denial of service condition. As a mitigation measure, users of the CP050 and CP150 device models are advised to upgrade to version 9.90 or later. For CP300 device models, devices 7ST85 and 7ST86 are advised to upgrade to version 10.00 or later, while the remaining models should upgrade to version 9.90 or later. These versions introduce an allow-list feature that restricts arbitrary file uploads and reduces the risk associated with this vulnerability. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
Named CVEsCVE-2025-40808Weakness classesView CISA CSAF advisory ↗Mitigations- <br> Users are advised to upgrade to V9.90 or later, which introduces an allow-list feature that restricts arbitrary file uploads
- Apply password protection to all DIGSI connections to ensure secure communication
- For DIGSI access provision your own certificates signed by your customer PKI as described in https://support.industry.siemens.com/cs/document/109768375
- For the available devices [CP050, CP100, CP150 and CP300] , activate role based access control (RBAC) in the device (supported in SIPROTEC 5 firmware versions V7.80 and higher)
- Users are advised to upgrade to V10.00 or later, which introduces an allow-list feature that restricts arbitrary file uploads
- Currently no fix is planned
- Currently no fix is available
- ICSA-26-174-01OTCVSS 7.1 HighReleased 2026-06-09 · Updated 2026-06-23
Siemens WinCC Certificate Manager
Vendor: SiemensProducts: SIMATIC WinCC Unified PC Runtime V16, SIMATIC WinCC Unified PC Runtime V17, SIMATIC WinCC Unified PC Runtime V18, SIMATIC WinCC Unified PC Runtime V19, SIMATIC WinCC Unified PC Runtime V20, SIMATIC WinCC Unified PC Runtime V21
Critical infrastructure sectorsCritical ManufacturingTransportation SystemsEnergyHealthcare and Public HealthFinancial ServicesGovernment FacilitiesWinCC Certificate Manager insufficiently protects key material that could allow an attacker to extract sensitive information. Siemens has released a new version for SIMATIC WinCC Unified PC Runtime V21 and recommends to update to the latest version. Siemens recommends specific countermeasures for products where fixes are not, or not yet available.
Named CVEsCVE-2026-24349Weakness classesView CISA CSAF advisory ↗Mitigations- The affected product may be operated only by personnel qualified for the specific task in accordance with the relevant documentation, in particular its warning notices and safety instructions. Qualified personnel are those who, based on their training and experience, are capable of identifying risks and avoiding potential hazards when working with the affected product.
- Currently no fix is planned
- Update to V21 Update 2 or later versionVendor reference ↗
- ICSA-26-155-01OTCVSS 6.3 MediumReleased 2026-06-04
NAVTOR NavBox
Vendor: NAVTORProduct: NavBox
Critical infrastructure sectorsInformation TechnologySuccessful exploitation of this vulnerability could allow a local attacker to gain unauthorized access to SOAP methods, resulting in a disruption of operations.
Named CVEsCVE-2026-21404Weakness classesView CISA CSAF advisory ↗Mitigations- NAVTOR has released a patch for NavBox in April 2026. Version 4.17.2.6 and later includes the fix. Users that have an active NavBox connection will automatically be kept up to date with the latest version. No user action required.
- ICSA-26-195-03OTCVSS 9.9 CriticalReleased 2026-06-03 · Updated 2026-07-14
ABB T-MAC Plus
Vendor: ABBProduct: T-MAC Plus
Critical infrastructure sectorsCritical ManufacturingABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. An attacker who successfully exploited any of these vulnerabilities could potentially compromise the system in different ways.
Named CVEsCVE-2025-14771CVE-2025-14772CVE-2025-14773CVE-2025-14774View CISA CSAF advisory ↗Mitigations- ABB has investigated these vulnerabilities to provide adequate protection to customers. The problem is corrected in the following product versions: T-MAC Plus version 4.0-25 ABB recommends that customers apply the update at earliest convenience.
- The misconfigurations on the IIS server, which were reported to security auditing, have been corrected. File Browsing Feature was enabled on that IIS server. That feature along with the default IIS site has been removed.
- Workarounds are specific measures that a user can take to help block an attack, for example, temporarily disabling the vulnerable feature may remove the exposure with well-known impact on functionality. ABB has tested the following workarounds. Although these workarounds will not correct the underlying vulnerability, they can help block known attack vectors. When a workaround reduces functionality, this is identified below as “Impact of workaround”.
- ABB T-MAC Plus web application supports several classes of users (e.g., Admin, Customer, Operator, etc.) with different roles. An authenticated user with low privileges (e.g., Customer) can execute administrative operations. The privileges associated to the different users have been revised and applied correctly.
- A DOM-based XSS vulnerability is present. If a malicious actor gains access to the operations network and can create or edit an existing entity, they could insert malicious JavaScript code to be executed in the web forms. New T-MAC Plus version 4.0-25 will correct the vulnerability.
- If a malicious actor gains physical access to a serial device, disables it, connects a malicious device with same IP address, and sends a specially crafted message, the service responsible for communicating with the device will be blocked until a manual restart is performed. New T-MAC Plus version 4.0-25 will correct the vulnerability.
- ICSA-26-188-05OTCVSS 9.8 CriticalReleased 2026-06-02 · Updated 2026-07-07
Siemens SINEC OS
Vendor: SiemensProduct: RUGGEDCOM RST2428P (6GK6242-6PA00)
Critical infrastructure sectorsCritical ManufacturingTransportation SystemsEnergyHealthcare and Public HealthFinancial ServicesGovernment Services and FacilitiesSINEC OS before V4.0 contains multiple vulnerabilities. Siemens has released a new version for RUGGEDCOM RST2428P and recommends to update to the latest version.
Named CVEsCVE-2025-1352CVE-2025-1376CVE-2025-6052CVE-2025-6141CVE-2025-6170CVE-2025-7039CVE-2025-8732CVE-2025-9086CVE-2025-9230CVE-2025-9231CVE-2025-9232CVE-2025-10966CVE-2025-13465CVE-2025-13601CVE-2025-39913CVE-2025-40214CVE-2025-40248CVE-2025-40250CVE-2025-40251CVE-2025-40252CVE-2025-40254CVE-2025-40257CVE-2025-40258CVE-2025-40261CVE-2025-40262CVE-2025-40263CVE-2025-40264CVE-2025-40271CVE-2025-40278CVE-2025-40280CVE-2025-40281CVE-2025-40345CVE-2025-46394CVE-2025-49794CVE-2025-49795CVE-2025-49796CVE-2025-60876CVE-2025-66035CVE-2025-66382CVE-2025-66412CVE-2025-69720CVE-2025-71185CVE-2025-71186CVE-2025-71188CVE-2025-71189CVE-2025-71190CVE-2025-71191CVE-2026-1484CVE-2026-1489CVE-2026-3784CVE-2026-22610CVE-2026-22976CVE-2026-22977CVE-2026-23025CVE-2026-23026CVE-2026-23030CVE-2026-23031CVE-2026-23032CVE-2026-23033CVE-2026-23037CVE-2026-23038CVE-2026-23111CVE-2026-23112CVE-2026-23220CVE-2026-23222CVE-2026-23228CVE-2026-23229CVE-2026-23230CVE-2026-23231CVE-2026-23236CVE-2026-23238CVE-2026-24515CVE-2026-25210CVE-2026-26157CVE-2026-26158CVE-2026-35535CVE-2026-41918Weakness classesView CISA CSAF advisory ↗Mitigations- Update to V4.0 or later versionVendor reference ↗
- ICSMA-26-148-01OTCVSS 8.8 HighReleased 2026-05-28
Fourth Frontier Frontier X Mobile Application, Frontier X2
Vendor: Fourth FrontierProducts: Frontier X Android application, Frontier X IOS application, Frontier X2
Critical infrastructure sectorsHealthcare and Public HealthSuccessful exploitation of this vulnerability could allow an attacker to read and write arbitrary handle values and change clinical readings, which could result in taking control of the device and lead to patient harm.
Named CVEsCVE-2026-5768Weakness classesView CISA CSAF advisory ↗Mitigations- Fourth Frontier is aware of the vulnerability and is working on a fix. Users are encouraged to reach out to Fourth Frontier directly for assistance. https://fourthfrontier.com/pages/contact-usl.Vendor reference ↗
- Frontier X/X2 devices can connect to only one app at a time; users should first connect the Frontier X/X2 device using the Frontier X app and then start the activity.
- ICSA-26-148-08OTCVSS 9.8 CriticalReleased 2026-05-28
XCharge C6
Vendor: XChargeProduct: C6
Critical infrastructure sectorsTransportation SystemsSuccessful exploitation of these vulnerabilities could allow an attacker to gain administrator rights or execute code on the affected device.
Named CVEsCVE-2026-9037CVE-2026-9038CVE-2026-9039View CISA CSAF advisory ↗Mitigations- XCharge has confirmed that the update has been deployed for all affected chargers. Users with questions can reach out to XCharge Support for further details if needed. https://www.xcharge.com/contactVendor reference ↗
- ICSA-26-148-06OTCVSS 9.1 CriticalReleased 2026-05-28
KMW CCTV Security Cameras
Vendor: KMWProducts: KM-IP521, KM-IP421
Critical infrastructure sectorsCommercial FacilitiesGovernment FacilitiesCritical ManufacturingFinancial ServicesTransportation SystemsSuccessful exploitation of this vulnerability may grant full unauthorized access to camera feeds and settings.
Named CVEsCVE-2026-5386Weakness classesView CISA CSAF advisory ↗Mitigations- KMW has issued a firmware update to address this vulnerability. The firmware update can be found at https://main.kmw.ro/pub/Firmware/521_421.zip.Vendor reference ↗
- KM-IP421 - will lose the cloud authorization after this update so users will need to contact customer support to re-authorize the P2P connection.
- KMW recommends connecting surveillance equipment on a separate network, allow only specific devices access to the internet, check for firmware updates regularly, and use cloud connections responsibly.
- If there are any issues customers are encouraged to contact KMW directly.
- ICSA-26-148-05OTCVSS 8.4 HighReleased 2026-05-28
CP Plus 8 Ch. Network Video Recorder
Vendor: CP PlusProducts: CP-UNR-108F1 Hardware, CP-UNR-108F1 Web, CP-UNR-108F1 System
Critical infrastructure sectorsCommercial FacilitiesCritical ManufacturingEmergency ServicesSuccessful exploitation of this vulnerability allows an attacker's malicious script to execute in the browser of any authenticated user or administrator who accesses the affected interface. This could lead to compromise of user sessions, execution of unauthorized actions with the victim's privileges, exposure or manipulation of sensitive data, and degradation of overall system integrity.
Named CVEsCVE-2026-6824Weakness classesView CISA CSAF advisory ↗Mitigations- CP Plus recommends updating the firmware on the device to the latest firmware version.
- CP-UNR-AxxxMars_PN_15_Q_00_V1.00.14.01.T.260326 which can be downloaded at https://drive.google.com/file/d/1Ctxdp55UtlrQY7CSepkImM9zFgdcuCyL/viewVendor reference ↗
- For firmware access and upgrade instructions, please contact support at:
- Phone: +91-8800952952
- Email: support@cpplusworld.comVendor reference ↗
- ICSA-26-148-02OTCVSS 9.8 CriticalReleased 2026-05-28
Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter
Vendor: Jinan USR IOT Technology Limited (PUSR)Product: USR-W610 RS232/485 to Wi-Fi/Ethernet Converter
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could result in an attacker gaining administrator access to the device.
Named CVEsCVE-2026-7786Weakness classesView CISA CSAF advisory ↗Mitigations- Jinan USR IOT Technology Limited (PUSR) did not respond to CISA's attempts at coordination. Users of PUSR USR-W610 devices are encouraged to contact PUSR and keep their systems up to date.
- ICSA-26-148-01OTCVSS 8.3 HighReleased 2026-05-28
MacGregor Voyage Data Recorder (VDR) G4e
Vendor: DanelecProduct: MacGregor Voyage Data Recorder (VDR) G4e
Critical infrastructure sectorsTransportation SystemsSuccessful exploitation of these vulnerabilities could result in an attacker gaining administrator access to the device.
Named CVEsCVE-2026-42941CVE-2026-42951CVE-2026-44611CVE-2026-42929CVE-2026-40425View CISA CSAF advisory ↗Mitigations- Danelec has released firmware version V5.250 to resolve these vulnerabilities. Users of MacGregor Voyage Data Recorder (VDR) G4e devices are encouraged to update the firmware at the earliest service attendance rather than waiting for an annual performance test. Contact Danelec with additional questions: https://www.danelec.com/contactVendor reference ↗
- ICSMA-26-146-01OTCVSS 9.8 CriticalReleased 2026-05-26
Eppendorf BioFlo 320
Vendor: EppendorfProduct: BioFlo 320 Bioreactor
Critical infrastructure sectorsHealthcare and Public HealthSuccessful exploitation of this vulnerability could allow an attacker to gain full access to functionality and data with the bioreactor.
Named CVEsCVE-2026-7251Weakness classesView CISA CSAF advisory ↗Mitigations- Eppendorf has released a software update that permanently removes VNC access from the controller. Users should download and apply this update from: https://www.eppendorf.com/software-downloads.Vendor reference ↗
- All affected BioFlo 320 systems always shipped with Virtual Network Computing (VNC) disabled by default, and VNC can only be enabled locally at the tower. Eppendorf has removed VNC configuration information from all current documentation, so it no longer appears in BioFlo 320 Operating Manuals.
- Eppendorf recommends user do the following:
- Verify that VNC is disabled on the controller
- Enable security so that only Admin and Supervisor roles can change VNC settings.
- Install Version 5.0 Software as soon as possible
- ICSA-26-155-05OTCVSS 5.5 MediumReleased 2026-05-26 · Updated 2026-06-04
Hitachi Energy MACH HiDraw
Vendor: Hitachi EnergyProduct: MACH HiDraw
Critical infrastructure sectorsDamsEnergyTransportation SystemsHitachi Energy is aware of a buffer overflow vulnerability that affects MACH HiDraw product versions listed in this document. Successful exploitation of this vulnerability could lead to a buffer overflow condition, potentially resulting in application outages (denial of service) and possible arbitrary code execution. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.
Named CVEsCVE-2026-7310Weakness classesView CISA CSAF advisory ↗Mitigations- Fixed in version 9.23. Due to the complexity of individual implementation of the project, contact local account team for further information on possible upgrades.
- Hitachi's General Mitigation Factors/Workarounds: Recommended security practices and firewall configurations can help protect a process control network from attacks that originate from outside the network. Such practices include that process control systems are physically protected from direct access by unauthorized personnel, have no direct connections to the Internet, and are separated from other networks by means of a firewall system that has a minimal number of ports exposed, and others that have to be evaluated case by case. Process control systems should not be used for Internet surfing, instant messaging, or receiving e-mails. Portable computers and removable storage media should be carefully scanned for viruses before they are connected to a control system. Proper password policies and processes should be followed.
- ICSA-26-155-04OTCVSS 7.8 HighReleased 2026-05-26 · Updated 2026-06-04
Hitachi Energy RTU500
Vendor: Hitachi EnergyProduct: RTU500 series CMU Firmware
Critical infrastructure sectorsDamsEnergyWater and Wastewater SystemsHitachi Energy is aware of vulnerabilities that affect RTU500 product versions listed in this document. If exploited, these vulnerabilities primarily impact product availability, with potential secondary impacts on confidentiality and integrity. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.
Named CVEsCVE-2025-69421CVE-2026-24515CVE-2026-25210CVE-2026-32776CVE-2026-32777CVE-2026-32778CVE-2026-8479View CISA CSAF advisory ↗Mitigations- Update to CMU Firmware version 13.8.2
- Follow general mitigation factors/workarounds
- Update to CMU Firmware version 13.7.9 (when available) or 13.8.2
- Update to CMU Firmware version 13.7.8
- ICSA-26-155-03OTCVSS 7.5 HighReleased 2026-05-26 · Updated 2026-06-04
B&R PPT30 Operating System
Vendor: B&R Industrial Automation GmbHProduct: PPT30 Operating System
Critical infrastructure sectorsCommercial FacilitiesCritical ManufacturingEnergyTransportation SystemsWater and Wastewater SystemsB&R is aware of a vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploits this vulnerability could make the OPC-UA server of the product inaccessible.
Named CVEsCVE-2025-11482Weakness classesView CISA CSAF advisory ↗Mitigations- The problem is corrected in the following product versions: PPT30 Operating System 1.8.0. The OPC-UA server is not activated by default. B&R recommends that customers with the OPC-UA Server enabled to install the update at their earliest opportunity. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.
- The optional OPC-UA server is not activated by default. The OPC-UA server shall only be activated, if required. PPT30 products are intended to operate at Levels 1 and 2 of the ABB ICS Cyber Security Reference Architecture. To restrict access to the OPC-UA server exclusively to trusted IP addresses, configure the South Firewall and/or the Control Network Firewall accordingly, and properly segment the network where the PPT30 operates. Additionally, ensure that the physical network interfaces assigned to the same logical network as the PPT30 are accessible only to authorized personnel. Refer to section “General security recommendations” for further advise on how to keep your system secure.
- ICSA-26-155-02OTCVSS 7.5 HighReleased 2026-05-26 · Updated 2026-06-04
Hitachi Energy ITT600 Explorer
Vendor: Hitachi EnergyProduct: ITT600 Explorer
Critical infrastructure sectorsEnergyHitachi Energy is aware of vulnerabilities that affect ITT600 Explorer product versions listed in this document. These vulnerabilities can be exploited to carry out Denial of Service (DoS) attack on the product. The vulnerabilities only affect Hitachi Energy Integrated Testing Tool ITT600 SA Explorer without affecting IEC 61850 system endpoints. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.
Named CVEsCVE-2024-8176CVE-2025-59375View CISA CSAF advisory ↗Mitigations- Update to version 2.1 SP6 HF1
- Upgrade to version 2.2 when available
- ICSA-26-139-05OTCVSS 5.3 MediumReleased 2026-05-19
Kieback & Peter DDC Building Controllers
Vendor: Kieback & PeterProducts: DDC4002, DDC4100, DDC4200, DDC4200-L, DDC4400, DDC4002e, DDC4200e, DDC4400e, DDC4020e, DDC4040e, DDC520
Critical infrastructure sectorsCommercial FacilitiesCommunicationsFinancial ServicesFood and AgricultureGovernment FacilitiesHealthcare and Public HealthInformation TechnologySuccessful exploitation of this vulnerability could allow an attacker to take control of the victim's browser.
Named CVEsCVE-2026-4293Weakness classesView CISA CSAF advisory ↗Mitigations- Kieback & Peter DDC Building Controllers are developed and designed for use in closed building automation networks. The system is protected by a multi-level perimeter against attacks, especially from outside, by dividing it into operational technology (OT) zones with firewalls. Building automation systems (BA systems) in general should not be directly accessible from untrusted networks, especially from the Internet, but should be protected by consistently applying the defense-in-depth strategy. This concept is supported by organizational measures in the building as part of a safety management system. In order to achieve safety, measures are required at all levels.
- The DDC4002, DDC4100, DDC4200, DDC4200-L and DDC4400 controllers are end-of-maintenance, therefore the recommendations for these devices are as follows: These devices must be operated in a strictly separate OT environment.
- The DDC4002, DDC4100, DDC4200, DDC4200-L and DDC4400 controllers are end-of-maintenance, therefore the recommendations for these devices are as follows: Only trusted individuals should be granted network access to the DDC web portal.
- The DDC4002, DDC4100, DDC4200, DDC4200-L and DDC4400 controllers are end-of-maintenance, therefore the recommendations for these devices are as follows: Access to the web portal should be disabled in the device configuration if not required.
- The DDC4002, DDC4100, DDC4200, DDC4200-L and DDC4400 controllers are end-of-maintenance, therefore the recommendations for these devices are as follows: Users should be informed that only links from trusted sources should be used to access the web service.
- For the DDC520, DDC4002e, DDC4200e, DDC4400e, DDC4020e, and DDC4040e controllers, Kieback & Peter recommends the following safety measure: Restrict network access to the device
- For the DDC520, DDC4002e, DDC4200e, DDC4400e, DDC4020e, and DDC4040e controllers, Kieback & Peter recommends the following safety measure: Do not directly connect the device to the Internet
- Update the firmware to the latest available version: DDC4002e -> Update to version 1.23.5 or newer
- Update the firmware to the latest available version: DDC4200e -> Update to version 1.23.5 or newer
- Update the firmware to the latest available version: DDC4400e -> Update to version 1.23.5 or newer
- Update the firmware to the latest available version: DDC4020e -> Update to version 1.23.5 or newer
- Update the firmware to the latest available version: DDC4040e -> Update to version 1.23.5 or newer
- Update the firmware to the latest available version: DDC520 -> Update to version 1.24.2 or newer
- ICSA-26-139-04OTCVSS 9.1 CriticalReleased 2026-05-19
ZKTeco CCTV Cameras
Vendor: ZKTecoProduct: SSC335-GC2063-Face-0b77 Solution
Critical infrastructure sectorsCommercial FacilitiesSuccessful exploitation of this vulnerability could result in information disclosure, including capture of camera account credentials.
Named CVEsCVE-2026-8598Weakness classesView CISA CSAF advisory ↗Mitigations- ZKTeco has patched this vulnerability in firmware version V5.0.1.2.20260421. ZKTeco recommends that users upgrade to firmware version V5.0.1.2.20260421 or later at their earliest opportunity.
- Please see the security advisory from ZKTeco here: https://www.zkteco.com/en/announcement/23 for further information.Vendor reference ↗
- ICSA-26-139-03OTCVSS 9.1 CriticalReleased 2026-05-19
ScadaBR
Vendor: ScadaBRProduct: ScadaBR
Critical infrastructure sectorsCritical ManufacturingDamsChemicalEnergyWater and Wastewater SystemsSuccessful exploitation of these vulnerabilities could allow an attacker to perform unauthenticated remote code execution.
Named CVEsCVE-2026-8602CVE-2026-8603CVE-2026-8604CVE-2026-8605View CISA CSAF advisory ↗Mitigations- ScadaBR has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of ScadaBR are invited to contact ScadaBR customer support for additional information https://github.com/ScadaBR.Vendor reference ↗
- ICSA-26-134-17OTCVSS 9.8 CriticalReleased 2026-05-14
Universal Robots Polyscope 5
Vendor: Universal RobotsProduct: Polyscope 5
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of these vulnerabilities could allow an attacker to bypass authentication and execute code.
Named CVEsCVE-2026-8153Weakness classesView CISA CSAF advisory ↗Mitigations- Universal Robots has released Polyscope 5 version 5.25.1.For more information, see Universal Robots article: https://www.universal-robots.com/articles/ur/cybersecurity/cve-2026-8153-command-injection-in-the-polyscope-5-dashboard-server/.Vendor reference ↗
- ICSA-26-169-07OTCVSS 8.3 HighReleased 2026-05-12 · Updated 2026-06-18
Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products
Vendor: Schneider ElectricProducts: Easergy MiCOM C264, Easergy MiCOM P139, Easergy MiCOM P437, Easergy MiCOM P439, Easergy MiCOM P532, Easergy MiCOM P539, Easergy MiCOM P631, Easergy MiCOM P632, Easergy MiCOM P633, Easergy MiCOM P634, Easergy MiCOM P138, Easergy MiCOM P436, Easergy MiCOM P438, Easergy MiCOM P638, Easergy MiCOM C434, EcoStruxure Power Automation System Gateway (EPAS-GTW), EcoStruxure Power Automation System User Interface (EPAS-UI), EcoStruxure Power Operation, iPMFLS, PowerLogic P5 Protection Relay, PowerLogic P7 Protection and Control Platform, PowerLogic T300, PowerLogic T500, Saitel DP, EasyLogic T150 (formerly Saitel DR), Easergy C5, Easergy MiCOM P139 version, Saitel DR, EcoStruxure Power Automation Automation System User Interface (EPAS-UI), EcoStruxure Power Operation (EPO), Easergy MiCOM P40 Series
Critical infrastructure sectorsChemicalCritical ManufacturingEnergyWater and Wastewater SystemsSchneider Electric is aware of vulnerabilities in its PowerChute™ Serial Shutdown product. The [PowerChute Serial Shutdown](https://www.se.com/ww/en/product-range/137943580-powerchute-serial-shutdown/#products) product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktop, servers and workstations. Failure to apply the remediation provided below may risk improper input validation which could result in disruption of operations and access to system data.
Named CVEsCVE-2026-4827Weakness classesView CISA CSAF advisory ↗Mitigations- Version D7.34 of MiCOM C264 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device. Reboot is required
- Version 1.1.18 of Easergy C5 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device. Reboot is required
- Version P139.678.700 Easergy MiCOM P139 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.
- Version P439.678.700 Easergy MiCOM P439 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.
- Version P539.678.700 Easergy MiCOM P539 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.
- Version P632.678.700 Easergy MiCOM P632 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.
- Version P633.678.700 Easergy MiCOM P633 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.
- Version P634.680.701 Easergy MiCOM P634 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.
- Version P633.680.701 Easergy MiCOM P633 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.
- Version P138.677.701 Easergy MiCOM P138 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.
- Version C434.679.700 Easergy MiCOM C434 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.
- HUe Firmware version 11.06.31 includes a fix for this vulnerability and is available for download here: . Contact Schneider Electric’s Customer Care Center to download this software. A reboot is needed to complete the firmware upgrade
- Version 6.4.610.500.101 of EPAS Gateway includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this software
- Version 3.0.4 of EPAS-UI includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this software.
- EPO 2022 CU 7 of EcoStruxure™ Power Operation includes a fix for this vulnerability and is available for download here: • https://community.se.com/t5/EcoStruxure-PowerOperation/Power-Operation-2022-CU7-is-Now-Available/tdp/524787 Reboot needed: yesVendor reference ↗
- EPO 2024 CU 3 of EcoStruxure™ Power Operation includes a fix for this vulnerability and is available for download here: • https://community.se.com/t5/EcoStruxure-PowerOperation/Power-Operation-2024-CU3-is-HERE/td-p/534769 Reboot needed: yesVendor reference ↗
- Version 64.2025.0.14 of iPMFLS includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.
- Version V02.503.101 of PowerLogic™ P5 includes a fix for this vulnerability Contact Schneider Electric’s Customer Care Center to download this firmware.
- Version V02.003.001 of PowerLogic™ P7 includes a fix for this vulnerability Contact Schneider Electric’s Customer Care Center to download this firmware.
- Version 2.9.5 of PowerLogic™ T300 includes a fix for this vulnerability Contact Schneider Electric’s Customer Care Center to download this firmware. A reboot is needed to complete the firmware upgrade
- ICSA-26-169-04OTCVSS 7.1 HighReleased 2026-05-12 · Updated 2026-06-18
Schneider Electric EasyLogic T150 and Saitel DP
Vendor: Schneider ElectricProducts: EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller, EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller Firmware, Saitel DP Remote Terminal Unit & Controller, Saitel DP Remote Terminal Unit & Controller Firmware
Critical infrastructure sectorsEnergyCritical ManufacturingSchneider Electric is aware of a vulnerability in its EasyLogic T150 (formerly known as Saitel DR) and Saitel DP Remote Terminal Unit & Controller products. The [EasyLogic T150 (formerly known as Saitel DR RTU)](https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=62685#overview) is a field device, offering a solid and powerful modular platform for data acquisition, communication, automation and IED integration for distribution and transmission networks, generation sector and railway. The [Saitel DP RTU](https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=61747) is a modular platform for medium voltage and high voltage public distribution and transmission substation control. Failure to apply the fix provided below may risk a path traversal–based attack in which an authenticated user could gain unauthorized file access.
Named CVEsCVE-2026-6865Weakness classesView CISA CSAF advisory ↗Mitigations- Version 11.06.32 of EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller includes a fix for this vulnerability and is available for download here: • Contact Schneider Electric’s Customer Care Center to download this firmware. • Reboot needed: Yes
- Version 11.06.37 of Saitel DP Remote Terminal Unit & Controller includes a fix for this vulnerability and is available for download here: • Contact Schneider Electric’s Customer Care Center to download this firmware. • Reboot needed: Yes
- If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Ensure strict credential controls, even for low privilege users. • Ensure isolation and credentials are in place, as per the product’s security recommendations.
- ICSA-26-160-03OTCVSS 7.5 HighReleased 2026-05-12 · Updated 2026-06-09
Schneider Electric EcoStruxure Panel Server
Vendor: Schneider ElectricProducts: EcoStruxure Panel Server PAS800, EcoStruxure Panel Server PAS800V2, EcoStruxure Panel Server PAS600, EcoStruxure Panel Server PAS600V2, EcoStruxure Panel Server PAS400
Critical infrastructure sectorsCommercial FacilitiesCritical ManufacturingEnergySchneider Electric is aware of its vulnerability in its EcoStruxure Panel Server offer. The EcoStruxure Panel Server is a high performance, modular gateway with enhanced cybersecurity that provides easy and fast connections to multiple concurrent edge control or cloud applications. Failure to apply the remediations provided below may risk unauthorized authentication, which could lead to access to sensitive information.
Named CVEsCVE-2026-6866Weakness classesView CISA CSAF advisory ↗Mitigations- Version 002.006.000 of EcoStruxure Panel Server includes a fix for this vulnerability and is available for download here: • https://www.se.com/ww/en/download/document/PAS800_Fir mware_Package/ • Reboot needed: YesVendor reference ↗
- Version 002.006.000 of EcoStruxure Panel Server includes a fix for this vulnerability and is available for download here: • https://www.se.com/ww/en/download/document/PAS800V2_F irmware_Package/ • Reboot needed: YesVendor reference ↗
- Version 002.006.000 of EcoStruxure Panel Server includes a fix for this vulnerability and is available for download here: • https://www.se.com/ww/en/download/document/PAS600_Fir mware_Package/ • Reboot needed: YesVendor reference ↗
- Version 002.006.000 of EcoStruxure Panel Server includes a fix for this vulnerability and is available for download here: • https://www.se.com/ww/en/download/document/PAS600V2_ Firmware_Package/ • Reboot needed: YesVendor reference ↗
- Version 002.006.000 of EcoStruxure Panel Server includes a fix for this vulnerability and is available for download here: • https://www.se.com/ww/en/download/document/PAS400_Fir mware_Package/ • Reboot needed: YesVendor reference ↗
- ICSA-26-160-02OTCVSS 8.3 HighReleased 2026-05-12 · Updated 2026-06-09
Siemens KACO Blueplanet Inverters
Vendor: SiemensProducts: blueplanet 100 NX3 M8, blueplanet 100 TL3 GEN2, blueplanet 105 TL3, blueplanet 105 TL3 GEN2, blueplanet 110 TL3, blueplanet 125 NX3 M11, blueplanet 125 TL3, blueplanet 125 TL3 GEN2, blueplanet 137 TL3, blueplanet 150 TL3, blueplanet 150 TL3 GEN2, blueplanet 155 TL3, blueplanet 155 TL3 GEN2, blueplanet 165 TL3, blueplanet 165 TL3 GEN2, blueplanet 25.0 NX3-33.0 NX3, blueplanet 3.0 NX3-20.0 NX3, blueplanet 3.0 TL3-60.0 TL3, blueplanet 3.0-5.0 NX1, blueplanet 360 NX3 M6, blueplanet 50.0 NX3-60.0 NX3, blueplanet 87.0 TL3, blueplanet 87.0 TL3 GEN2, blueplanet 92.0 TL3, blueplanet 92.0 TL3 GEN2, blueplanet gridsafe 110 TL3-S, blueplanet gridsafe 137 TL3-S, blueplanet gridsafe 92.0 TL3-S, blueplanet hybrid 10.0 TL3, blueplanet hybrid 6.0 NH3-12.0 NH3
Critical infrastructure sectorsEnergyKACO blueplanet Inverters contain multiple vulnerabilities that could allow an attacker to derive the credentials from the devices serial number and misuse them to gain unauthorized access. KACO new energy GmbH has released new versions for several affected products and recommends to update to the latest versions. KACO new energy GmbH is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.
Named CVEsCVE-2025-40946CVE-2026-41125View CISA CSAF advisory ↗Mitigations- Currently no fix is planned
- Currently no fix is available
- Update to V3.91 or later versionVendor reference ↗
- Update to V6.1.4.9 or later versionVendor reference ↗
- ICSA-26-148-07OTCVSS 5.5 MediumReleased 2026-05-12 · Updated 2026-05-20
Schnieider Electric EcoStruxure Machine Expert HVAC (SEVD-2026-132-01)
Vendor: Schneider ElectricProduct: Ecostruxure™ Machine Expert HVAC
Critical infrastructure sectorsChemicalCritical ManufacturingEnergyWater and Wastewater SystemsSchneider Electric is aware of a vulnerability in its EcostruxureTM Machine Expert HVAC product. The [EcostruxureTM Machine Expert HVAC](https://www.se.com/ww/en/download/document/EcoStruxureME_HVAC/) product is a programming software for Modicon M171-M172 logic controllers. Failure to apply the remediation provided below may risk in revealing sensitive information, which could result in disclosing protected source code, leading to loss of confidentiality.
Named CVEsCVE-2026-6332Weakness classesView CISA CSAF advisory ↗Mitigations- Version 1.10.0 of Ecostruxure™ Machine Expert HVAC includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/download/document/EcoStruxureME_HVAC_1_10_0/Vendor reference ↗
- ICSA-26-139-02OTCVSS 10 CriticalReleased 2026-05-12 · Updated 2026-07-02
Siemens RUGGEDCOM APE1808 Devices
Vendor: SiemensProduct: RUGGEDCOM APE1808
Critical infrastructure sectorsCritical ManufacturingPalo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Siemens is preparing fix versions and recommends countermeasures for products where fixes are not, or not yet available. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/
Named CVEsCVE-2026-0256CVE-2026-0257CVE-2026-0258CVE-2026-0261CVE-2026-0262CVE-2026-0264CVE-2026-0265CVE-2026-0300View CISA CSAF advisory ↗Mitigations- Contact customer support to receive patch and update information
- Disable Authentication Override options (for generating and accepting cookies) in the GlobalProtect portal and gateway configuration
- Use a dedicated certificate for Authentication Override cookies
- Disable the DNS Proxy feature (Network > DNS Proxy) if it is not being used and configure DNS server with a RFC1918 or a public trusted IP address
- Disassociate DNS Proxy from externally accessible interfaces and configure DNS server with a RFC1918 or a public trusted IP address
- Disable Response Pages in the Interface Management Profile attached to every L3 interface in any zone where untrusted/internet traffic can ingress. Keep Response Pages enabled only on interfaces in trust/internal zones where legitimate users' browsers ingress
- Disable User-ID™ Authentication Portal if not required
- Restrict access to the User-ID Authentication Portal to trusted internal IP addresses only
- ICSA-26-134-16OTCVSS 9.8 CriticalReleased 2026-05-12 · Updated 2026-05-14
Siemens Ruggedcom Rox
Vendor: SiemensProducts: RUGGEDCOM ROX MX5000, RUGGEDCOM ROX MX5000RE, RUGGEDCOM ROX RX1400, RUGGEDCOM ROX RX1500, RUGGEDCOM ROX RX1501, RUGGEDCOM ROX RX1510, RUGGEDCOM ROX RX1511, RUGGEDCOM ROX RX1512, RUGGEDCOM ROX RX1524, RUGGEDCOM ROX RX1536, RUGGEDCOM ROX RX5000
Critical infrastructure sectorsCritical ManufacturingRuggedcom Rox before v2.17.1 contain multiple third-party vulnerabilities. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Named CVEsCVE-2019-13103CVE-2019-13104CVE-2019-13106CVE-2019-14192CVE-2019-14193CVE-2019-14194CVE-2019-14195CVE-2019-14196CVE-2019-14197CVE-2019-14198CVE-2019-14199CVE-2019-14200CVE-2019-14201CVE-2019-14202CVE-2019-14203CVE-2019-14204CVE-2020-10648CVE-2022-2347CVE-2022-30552CVE-2022-30790CVE-2022-34835CVE-2023-3019CVE-2023-27043CVE-2024-3447CVE-2024-22365CVE-2024-57256CVE-2024-57258CVE-2025-0395CVE-2025-3576CVE-2025-6020CVE-2025-7425CVE-2025-9714CVE-2025-46836CVE-2025-49794CVE-2025-49796Weakness classesView CISA CSAF advisory ↗Mitigations- Update to V2.17.1 or later versionVendor reference ↗
- ICSA-26-134-15OTCVSS 9.1 CriticalReleased 2026-05-12 · Updated 2026-05-14
Siemens SIMATIC S7 PLC Web Server
Vendor: SiemensProducts: SIMATIC Drive Controller CPU 1504D TF (6ES7615-4DF10-0AB0), SIMATIC Drive Controller CPU 1507D TF (6ES7615-7DF10-0AB0), SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SJ00-0AB0), SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SJ01-0AB0), SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SK03-0AB0), SIMATIC ET 200SP CPU 1510SP-1 PN (6ES7510-1DJ00-0AB0), SIMATIC ET 200SP CPU 1510SP-1 PN (6ES7510-1DJ01-0AB0), SIMATIC ET 200SP CPU 1510SP-1 PN (6ES7510-1DK03-0AB0), SIMATIC ET 200SP CPU 1512SP F-1 PN (6ES7512-1SK00-0AB0), SIMATIC ET 200SP CPU 1512SP F-1 PN (6ES7512-1SK01-0AB0), SIMATIC ET 200SP CPU 1512SP F-1 PN (6ES7512-1SM03-0AB0), SIMATIC ET 200SP CPU 1512SP-1 PN (6ES7512-1DK00-0AB0), SIMATIC ET 200SP CPU 1512SP-1 PN (6ES7512-1DK01-0AB0), SIMATIC ET 200SP CPU 1512SP-1 PN (6ES7512-1DM03-0AB0), SIMATIC ET 200SP CPU 1514SP F-2 PN (6ES7514-2SN03-0AB0), SIMATIC ET 200SP CPU 1514SP-2 PN (6ES7514-2DN03-0AB0), SIMATIC ET 200SP CPU 1514SPT F-2 PN (6ES7514-2WN03-0AB0), SIMATIC ET 200SP CPU 1514SPT-2 PN (6ES7514-2VN03-0AB0), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V2 CPUs, SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V3 CPUs, SIMATIC ET 200SP Open Controller CPU 1515SP PC3 V4 CPUs, SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK00-0AB0), SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK01-0AB0), SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK02-0AB0), SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AL03-0AB0), SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK00-0AB0), SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK01-0AB0), SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CL03-0AB0), SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK00-0AB0), SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK01-0AB0), SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK02-0AB0), SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FL03-0AB0), SIMATIC S7-1500 CPU 1511T-1 PN (6ES7511-1TK01-0AB0), SIMATIC S7-1500 CPU 1511T-1 PN (6ES7511-1TL03-0AB0), SIMATIC S7-1500 CPU 1511TF-1 PN (6ES7511-1UK01-0AB0), SIMATIC S7-1500 CPU 1511TF-1 PN (6ES7511-1UL03-0AB0), SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK00-0AB0), SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK01-0AB0), SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CM03-0AB0), SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL00-0AB0), SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL01-0AB0), SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL02-0AB0), SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AM03-0AB0), SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL00-0AB0), SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL01-0AB0), SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL02-0AB0), SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FM03-0AB0), SIMATIC S7-1500 CPU 1513pro F-2 PN (6ES7513-2GM03-0AB0), SIMATIC S7-1500 CPU 1513pro-2 PN (6ES7513-2PM03-0AB0), SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM00-0AB0), SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM01-0AB0), SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM02-0AB0), SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AN03-0AB0), SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM00-0AB0), SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM01-0AB0), SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM02-0AB0), SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FN03-0AB0), SIMATIC S7-1500 CPU 1515T-2 PN (6ES7515-2TM01-0AB0), SIMATIC S7-1500 CPU 1515T-2 PN (6ES7515-2TN03-0AB0), SIMATIC S7-1500 CPU 1515TF-2 PN (6ES7515-2UM01-0AB0), SIMATIC S7-1500 CPU 1515TF-2 PN (6ES7515-2UN03-0AB0), SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN00-0AB0), SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN01-0AB0), SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN02-0AB0), SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AP03-0AB0), SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN00-0AB0), SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN01-0AB0), SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN02-0AB0), SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FP03-0AB0), SIMATIC S7-1500 CPU 1516pro F-2 PN (6ES7516-2GP03-0AB0), SIMATIC S7-1500 CPU 1516pro-2 PN (6ES7516-2PP03-0AB0), SIMATIC S7-1500 CPU 1516T-3 PN (6ES7516-3TP10-0AB0), SIMATIC S7-1500 CPU 1516T-3 PN/DP (6ES7516-3TN00-0AB0), SIMATIC S7-1500 CPU 1516TF-3 PN (6ES7516-3UP10-0AB0), SIMATIC S7-1500 CPU 1516TF-3 PN/DP (6ES7516-3UN00-0AB0), SIMATIC S7-1500 CPU 1517-3 PN (6ES7517-3AQ10-0AB0), SIMATIC S7-1500 CPU 1517-3 PN/DP (6ES7517-3AP00-0AB0), SIMATIC S7-1500 CPU 1517F-3 PN (6ES7517-3FQ10-0AB0), SIMATIC S7-1500 CPU 1517F-3 PN/DP (6ES7517-3FP00-0AB0), SIMATIC S7-1500 CPU 1517F-3 PN/DP (6ES7517-3FP01-0AB0), SIMATIC S7-1500 CPU 1517T-3 PN (6ES7517-3TQ10-0AB0), SIMATIC S7-1500 CPU 1517T-3 PN/DP (6ES7517-3TP00-0AB0), SIMATIC S7-1500 CPU 1517TF-3 PN (6ES7517-3UQ10-0AB0), SIMATIC S7-1500 CPU 1517TF-3 PN/DP (6ES7517-3UP00-0AB0), SIMATIC S7-1500 CPU 1518-3 PN (6ES7518-3AT10-0AB0), SIMATIC S7-1500 CPU 1518-4 PN/DP (6ES7518-4AP00-0AB0), SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0), SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0), SIMATIC S7-1500 CPU 1518F-3 PN (6ES7518-3FT10-0AB0), SIMATIC S7-1500 CPU 1518F-4 PN/DP (6ES7518-4FP00-0AB0), SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0), SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0), SIMATIC S7-1500 CPU 1518T-3 PN (6ES7518-3TT10-0AB0), SIMATIC S7-1500 CPU 1518T-4 PN/DP (6ES7518-4TP00-0AB0), SIMATIC S7-1500 CPU 1518TF-3 PN (6ES7518-3UT10-0AB0), SIMATIC S7-1500 CPU 1518TF-4 PN/DP (6ES7518-4UP00-0AB0), SIMATIC S7-1500 CPU S7-1518-4 PN/DP ODK (6ES7518-4AP00-3AB0), SIMATIC S7-1500 CPU S7-1518F-4 PN/DP ODK (6ES7518-4FP00-3AB0), SIMATIC S7-1500 ET 200pro: CPU 1513PRO F-2 PN (6ES7513-2GL00-0AB0), SIMATIC S7-1500 ET 200pro: CPU 1513PRO-2 PN (6ES7513-2PL00-0AB0), SIMATIC S7-1500 ET 200pro: CPU 1516PRO F-2 PN (6ES7516-2GN00-0AB0), SIMATIC S7-1500 ET 200pro: CPU 1516PRO-2 PN (6ES7516-2PN00-0AB0), SIMATIC S7-1500 Software Controller CPU 1507S F V2, SIMATIC S7-1500 Software Controller CPU 1507S F V3, SIMATIC S7-1500 Software Controller CPU 1507S F V4, SIMATIC S7-1500 Software Controller CPU 1507S V2, SIMATIC S7-1500 Software Controller CPU 1507S V3, SIMATIC S7-1500 Software Controller CPU 1507S V4, SIMATIC S7-1500 Software Controller CPU 1508S F V2, SIMATIC S7-1500 Software Controller CPU 1508S F V3, SIMATIC S7-1500 Software Controller CPU 1508S F V4, SIMATIC S7-1500 Software Controller CPU 1508S T V3, SIMATIC S7-1500 Software Controller CPU 1508S TF V3, SIMATIC S7-1500 Software Controller CPU 1508S V2, SIMATIC S7-1500 Software Controller CPU 1508S V3, SIMATIC S7-1500 Software Controller CPU 1508S V4, SIMATIC S7-1500 Software Controller Linux V2, SIMATIC S7-1500 Software Controller Linux V3, SIMATIC S7-PLCSIM Advanced, SIPLUS ET 200SP CPU 1510SP F-1 PN (6AG1510-1SJ01-2AB0), SIPLUS ET 200SP CPU 1510SP F-1 PN RAIL (6AG2510-1SJ01-1AB0), SIPLUS ET 200SP CPU 1510SP-1 PN (6AG1510-1DJ01-2AB0), SIPLUS ET 200SP CPU 1510SP-1 PN (6AG1510-1DJ01-7AB0), SIPLUS ET 200SP CPU 1510SP-1 PN RAIL (6AG2510-1DJ01-1AB0), SIPLUS ET 200SP CPU 1510SP-1 PN RAIL (6AG2510-1DJ01-4AB0), SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK00-2AB0), SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK01-2AB0), SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK01-7AB0), SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL (6AG2512-1SK01-1AB0), SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL (6AG2512-1SK01-4AB0), SIPLUS ET 200SP CPU 1512SP-1 PN (6AG1512-1DK01-2AB0), SIPLUS ET 200SP CPU 1512SP-1 PN (6AG1512-1DK01-7AB0), SIPLUS ET 200SP CPU 1512SP-1 PN RAIL (6AG2512-1DK01-1AB0), SIPLUS ET 200SP CPU 1512SP-1 PN RAIL (6AG2512-1DK01-4AB0), SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK00-2AB0), SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK01-2AB0), SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK01-7AB0), SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK02-2AB0), SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK02-7AB0), SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL (6AG2511-1AK01-1AB0), SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL (6AG2511-1AK02-1AB0), SIPLUS S7-1500 CPU 1511-1 PN TX RAIL (6AG2511-1AK01-4AB0), SIPLUS S7-1500 CPU 1511-1 PN TX RAIL (6AG2511-1AK02-4AB0), SIPLUS S7-1500 CPU 1511F-1 PN (6AG1511-1FK00-2AB0), SIPLUS S7-1500 CPU 1511F-1 PN (6AG1511-1FK01-2AB0), SIPLUS S7-1500 CPU 1511F-1 PN (6AG1511-1FK02-2AB0), SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL00-2AB0), SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL01-2AB0), SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL01-7AB0), SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL02-2AB0), SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL02-7AB0), SIPLUS S7-1500 CPU 1513F-1 PN (6AG1513-1FL00-2AB0), SIPLUS S7-1500 CPU 1513F-1 PN (6AG1513-1FL01-2AB0), SIPLUS S7-1500 CPU 1513F-1 PN (6AG1513-1FL02-2AB0), SIPLUS S7-1500 CPU 1515F-2 PN (6AG1515-2FM01-2AB0), SIPLUS S7-1500 CPU 1515F-2 PN (6AG1515-2FM02-2AB0), SIPLUS S7-1500 CPU 1515F-2 PN RAIL (6AG2515-2FM02-4AB0), SIPLUS S7-1500 CPU 1515F-2 PN T2 RAIL (6AG2515-2FM01-2AB0), SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN00-2AB0), SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN00-7AB0), SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN01-2AB0), SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN01-7AB0), SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN02-2AB0), SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN02-7AB0), SIPLUS S7-1500 CPU 1516-3 PN/DP RAIL (6AG2516-3AN02-4AB0), SIPLUS S7-1500 CPU 1516-3 PN/DP TX RAIL (6AG2516-3AN01-4AB0), SIPLUS S7-1500 CPU 1516F-3 PN/DP (6AG1516-3FN00-2AB0), SIPLUS S7-1500 CPU 1516F-3 PN/DP (6AG1516-3FN01-2AB0), SIPLUS S7-1500 CPU 1516F-3 PN/DP (6AG1516-3FN02-2AB0), SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL (6AG2516-3FN02-2AB0), SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL (6AG2516-3FN02-4AB0), SIPLUS S7-1500 CPU 1518-4 PN/DP (6AG1518-4AP00-4AB0), SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0), SIPLUS S7-1500 CPU 1518F-4 PN/DP (6AG1518-4FP00-4AB0)
Critical infrastructure sectorsChemicalEnergyFood and AgricultureWater and Wastewater SystemsSIMATIC S7 PLCs contain multiple vulnerabilities in the web server that could allow an attacker to perform cross-site scripting attacks. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
Named CVEsCVE-2026-25786CVE-2026-25787CVE-2026-25789Weakness classesView CISA CSAF advisory ↗Mitigations- Restrict TIA project download to trusted personnel only.
- Currently no fix is planned
- Currently no fix is available
- Update to V2.9.9 or later versionVendor reference ↗
- Update to V3.1.6 or later versionVendor reference ↗
- Restrict access to the function right "firmware update" to instructed personnel.
- ICSA-26-134-14OTCVSS 9.1 CriticalReleased 2026-05-12 · Updated 2026-05-14
Siemens SENTRON 7KT PAC1261 Data Manager
Vendor: SiemensProduct: SENTRON 7KT PAC1261 Data Manager
Critical infrastructure sectorsEnergyThe web server in SENTRON 7KT PAC1261 Data Manager Before V2.1.0 contains a request smuggling vulnerability in the Go Project's net/http package that could allow an attacker to retrieve authorization tokens that can be used to gain administrative control over the device. Siemens has released a new version for SENTRON 7KT PAC1261 Data Manager and recommends to update to the latest version.
Named CVEsCVE-2025-22871Weakness classesView CISA CSAF advisory ↗Mitigations- Use encrypted protocols
- Update to V2.1.0 or later versionVendor reference ↗
- ICSA-26-134-13OTCVSS 5.3 MediumReleased 2026-05-12 · Updated 2026-05-14
Siemens SIPROTEC 5
Vendor: SiemensProducts: SIPROTEC 5 6MD84 (CP300), SIPROTEC 5 6MD85 (CP200), SIPROTEC 5 6MD85 (CP300), SIPROTEC 5 6MD86 (CP200), SIPROTEC 5 6MD86 (CP300), SIPROTEC 5 6MD89 (CP300), SIPROTEC 5 6MU85 (CP300), SIPROTEC 5 7KE85 (CP200), SIPROTEC 5 7KE85 (CP300), SIPROTEC 5 7SA82 (CP100), SIPROTEC 5 7SA82 (CP150), SIPROTEC 5 7SA84 (CP200), SIPROTEC 5 7SA86 (CP200), SIPROTEC 5 7SA86 (CP300), SIPROTEC 5 7SA87 (CP200), SIPROTEC 5 7SA87 (CP300), SIPROTEC 5 7SD82 (CP100), SIPROTEC 5 7SD82 (CP150), SIPROTEC 5 7SD84 (CP200), SIPROTEC 5 7SD86 (CP200), SIPROTEC 5 7SD86 (CP300), SIPROTEC 5 7SD87 (CP200), SIPROTEC 5 7SD87 (CP300), SIPROTEC 5 7SJ81 (CP100), SIPROTEC 5 7SJ81 (CP150), SIPROTEC 5 7SJ82 (CP100), SIPROTEC 5 7SJ82 (CP150), SIPROTEC 5 7SJ85 (CP200), SIPROTEC 5 7SJ85 (CP300), SIPROTEC 5 7SJ86 (CP200), SIPROTEC 5 7SJ86 (CP300), SIPROTEC 5 7SK82 (CP100), SIPROTEC 5 7SK82 (CP150), SIPROTEC 5 7SK85 (CP200), SIPROTEC 5 7SK85 (CP300), SIPROTEC 5 7SL82 (CP100), SIPROTEC 5 7SL82 (CP150), SIPROTEC 5 7SL86 (CP200), SIPROTEC 5 7SL86 (CP300), SIPROTEC 5 7SL87 (CP200), SIPROTEC 5 7SL87 (CP300), SIPROTEC 5 7SS85 (CP200), SIPROTEC 5 7SS85 (CP300), SIPROTEC 5 7ST85 (CP200), SIPROTEC 5 7ST85 (CP300), SIPROTEC 5 7ST86 (CP300), SIPROTEC 5 7SX82 (CP150), SIPROTEC 5 7SX85 (CP300), SIPROTEC 5 7SY82 (CP150), SIPROTEC 5 7UM85 (CP300), SIPROTEC 5 7UT82 (CP100), SIPROTEC 5 7UT82 (CP150), SIPROTEC 5 7UT85 (CP200), SIPROTEC 5 7UT85 (CP300), SIPROTEC 5 7UT86 (CP200), SIPROTEC 5 7UT86 (CP300), SIPROTEC 5 7UT87 (CP200), SIPROTEC 5 7UT87 (CP300), SIPROTEC 5 7VE85 (CP300), SIPROTEC 5 7VK87 (CP200), SIPROTEC 5 7VK87 (CP300), SIPROTEC 5 7VU85 (CP300), SIPROTEC 5 Compact 7SX800 (CP050)
Critical infrastructure sectorsCritical ManufacturingThe SIPROTEC 5 devices do not use sufficiently random numbers to generate session identifiers. This could facilitate a brute-force attack against a valid session identifier which could allow an unauthenticated remote attacker to hijack a valid user session. The affected session identifiers are only used in a subset of the endpoints that are provided by the affected products. Siemens is preparing fix versions and recommends countermeasures for products where fixes are not, or not yet available.
Named CVEsCVE-2024-54017Weakness classesView CISA CSAF advisory ↗Mitigations- Currently no fix is available
- Update to V11.0 or later versionVendor reference ↗
- ICSA-26-134-12OTCVSS 9.1 CriticalReleased 2026-05-12 · Updated 2026-05-14
Siemens Ruggedcom Rox
Vendor: SiemensProducts: RUGGEDCOM ROX MX5000, RUGGEDCOM ROX MX5000RE, RUGGEDCOM ROX RX1400, RUGGEDCOM ROX RX1500, RUGGEDCOM ROX RX1501, RUGGEDCOM ROX RX1510, RUGGEDCOM ROX RX1511, RUGGEDCOM ROX RX1512, RUGGEDCOM ROX RX1524, RUGGEDCOM ROX RX1536, RUGGEDCOM ROX RX5000
Critical infrastructure sectorsCritical ManufacturingRuggedcom Rox contains an input validation vulnerability in the Scheduler functionality that could allow an authenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Named CVEsCVE-2025-40949Weakness classesView CISA CSAF advisory ↗Mitigations- Update to V2.17.1 or later versionVendor reference ↗
- ICSA-26-134-11OTCVSS 7.5 HighReleased 2026-05-12 · Updated 2026-05-14
Siemens Ruggedcom Rox
Vendor: SiemensProducts: RUGGEDCOM ROX MX5000, RUGGEDCOM ROX MX5000RE, RUGGEDCOM ROX RX1400, RUGGEDCOM ROX RX1500, RUGGEDCOM ROX RX1501, RUGGEDCOM ROX RX1510, RUGGEDCOM ROX RX1511, RUGGEDCOM ROX RX1512, RUGGEDCOM ROX RX1524, RUGGEDCOM ROX RX1536, RUGGEDCOM ROX RX5000
Critical infrastructure sectorsCritical ManufacturingRuggedcom Rox contains an input validation vulnerability in the feature key installation process that could allow an authenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Named CVEsCVE-2025-40947Weakness classesView CISA CSAF advisory ↗Mitigations- Update to V2.17.1 or later versionVendor reference ↗
- ICSA-26-134-10OTCVSS 9.6 CriticalReleased 2026-05-12 · Updated 2026-05-14
Siemens SIMATIC
Vendor: SiemensProduct: SIMATIC CN 4100
Critical infrastructure sectorsCritical ManufacturingSIMATIC CN 4100 contains multiple vulnerabilities which could potentially lead to a compromise in availability, integrity and confidentiality. Siemens has released a new version for SIMATIC CN 4100 and recommends to update to the latest version.
Named CVEsCVE-2024-47704CVE-2024-57924CVE-2024-58240CVE-2025-6021CVE-2025-6052CVE-2025-7425CVE-2025-8916CVE-2025-9230CVE-2025-9231CVE-2025-9232CVE-2025-9820CVE-2025-14831CVE-2025-23143CVE-2025-23160CVE-2025-31257CVE-2025-37931CVE-2025-37968CVE-2025-38322CVE-2025-38347CVE-2025-38491CVE-2025-38502CVE-2025-38552CVE-2025-38614CVE-2025-38670CVE-2025-38676CVE-2025-38677CVE-2025-38679CVE-2025-38680CVE-2025-38681CVE-2025-38683CVE-2025-38684CVE-2025-38685CVE-2025-38687CVE-2025-38691CVE-2025-38693CVE-2025-38694CVE-2025-38695CVE-2025-38696CVE-2025-38697CVE-2025-38698CVE-2025-38699CVE-2025-38700CVE-2025-38701CVE-2025-38702CVE-2025-38706CVE-2025-38707CVE-2025-38708CVE-2025-38711CVE-2025-38712CVE-2025-38713CVE-2025-38714CVE-2025-38715CVE-2025-38721CVE-2025-38723CVE-2025-38724CVE-2025-38725CVE-2025-38727CVE-2025-38728CVE-2025-38729CVE-2025-38732CVE-2025-38735CVE-2025-38736CVE-2025-39673CVE-2025-39675CVE-2025-39676CVE-2025-39681CVE-2025-39682CVE-2025-39683CVE-2025-39684CVE-2025-39685CVE-2025-39686CVE-2025-39687CVE-2025-39689CVE-2025-39691CVE-2025-39692CVE-2025-39693CVE-2025-39694CVE-2025-39697CVE-2025-39701CVE-2025-39702CVE-2025-39703CVE-2025-39706CVE-2025-39709CVE-2025-39710CVE-2025-39713CVE-2025-39714CVE-2025-39715CVE-2025-39716CVE-2025-39718CVE-2025-39719CVE-2025-39724CVE-2025-39736CVE-2025-39737CVE-2025-39738CVE-2025-39742CVE-2025-39743CVE-2025-39749CVE-2025-39752CVE-2025-39756CVE-2025-39757CVE-2025-39759CVE-2025-39760CVE-2025-39766CVE-2025-39770CVE-2025-39772CVE-2025-39773CVE-2025-39776CVE-2025-39782CVE-2025-39783CVE-2025-39787CVE-2025-39788CVE-2025-39790CVE-2025-39794CVE-2025-39795CVE-2025-39798CVE-2025-39800CVE-2025-39801CVE-2025-39806CVE-2025-39808CVE-2025-39812CVE-2025-39813CVE-2025-39817CVE-2025-39819CVE-2025-39823CVE-2025-39824CVE-2025-39825CVE-2025-39826CVE-2025-39827CVE-2025-39828CVE-2025-39835CVE-2025-39838CVE-2025-39839CVE-2025-39841CVE-2025-39842CVE-2025-39843CVE-2025-39844CVE-2025-39845CVE-2025-39846CVE-2025-39847CVE-2025-39848CVE-2025-39849CVE-2025-39853CVE-2025-39857CVE-2025-39860CVE-2025-39864CVE-2025-39865CVE-2025-39866CVE-2025-40300CVE-2025-43368CVE-2025-47219CVE-2025-48989CVE-2025-53057CVE-2025-53066CVE-2025-55752CVE-2025-55754CVE-2025-61748CVE-2025-61795CVE-2026-2673CVE-2026-21925CVE-2026-21932CVE-2026-21933CVE-2026-21945CVE-2026-21947CVE-2026-22924CVE-2026-22925CVE-2026-28387CVE-2026-28388CVE-2026-28389CVE-2026-28390CVE-2026-31789CVE-2026-31790Weakness classesCWE-476CWE-617CWE-416CWE-787CWE-190CWE-770CWE-125CWE-385CWE-121CWE-407CWE-401CWE-119CWE-20CWE-667CWE-674CWE-805CWE-366CWE-820CWE-908CWE-415CWE-772CWE-835CWE-911CWE-664CWE-362CWE-394CWE-369CWE-1285CWE-1025CWE-208CWE-1286CWE-833CWE-364CWE-573CWE-273CWE-402CWE-404CWE-284CWE-200CWE-23CWE-150CWE-757CWE-400CWE-79CWE-306CWE-754View CISA CSAF advisory ↗Mitigations- Update to V5.0 or later versionVendor reference ↗
- ICSA-26-134-09OTCVSS 7.1 HighReleased 2026-05-12 · Updated 2026-05-14
Siemens Opcenter RDnL
Vendor: SiemensProduct: Opcenter RDnL
Critical infrastructure sectorsCritical ManufacturingOpcenter RDnL is affected by missing authentication in critical function in ‘ActiveMQ Artemis’. An unauthenticated attacker within the adjacent network could use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker. This could potentially result in availability impacts or message injection into any queue via the rogue broker. Breaking the integrity of a message has a low impact due to missing auto refresh functionality and it does not contain any confidential information. ActiveMQ Artemis has released a new version and Siemens recommends to update to the latest version.
Named CVEsCVE-2026-27446Weakness classesView CISA CSAF advisory ↗Mitigations- Implement and deploy a Core interceptor to deny all Core downstream federation connect packets. Such packets have a type of (int) -16 or (byte) 0xfffffff0. Documentation for interceptors is available at https://artemis.apache.org/components/artemis/documentation/latest/intercepting-operations.html .
- Remove Core protocol support from any acceptor receiving connections from untrusted sources. Incoming Core protocol connections are supported by default via the "artemis" acceptor listening on port 61616. See the "protocols" URL parameter configured for the acceptor. An acceptor URL without this parameter supports all protocols by default, including Core
- Use two-way SSL (i.e. certificate-based authentication) in order to force every client to present the proper SSL certificate when establishing a connection before any message protocol handshake is attempted. This will prevent unauthenticated exploitation of this vulnerability
- Update to Apache Artemis version 2.52.0 or later version
- ICSA-26-134-08OTCVSS 9.1 CriticalReleased 2026-05-12 · Updated 2026-05-14
Siemens Siemens ROS#
Vendor: SiemensProduct: ROS#
Critical infrastructure sectorsCritical ManufacturingROS# contains a ROS service file_server, that before version 2.2.2 contains a path traversal vulnerability which could allow an attacker to access, i.e. read and write, arbitrary files, which are accessible with the user rights of the user that runs the service, on the system that hosts service. Siemens has released a new version for ROS# and recommends to update to the latest version.
Named CVEsCVE-2026-41551Weakness classesView CISA CSAF advisory ↗Mitigations- For versions before 2.2.2: - run file_server on a trusted network only. - run file_server with appropriate user rights. - run file_server only for tasks it was designed for, transferring URDF files from ROS host to target system, not as a service that runs continuously in the background. - run file_server only if manually transferring files is not possible.
- Update to V2.2.2 or later versionVendor reference ↗
- ICSA-26-134-07OTCVSS 7.7 HighReleased 2026-05-12 · Updated 2026-05-14
Siemens SIMATIC
Vendor: SiemensProducts: SIMATIC HMI MTP1000 Unified Comfort Panel (6AV2128-3KB06-0AX1), SIMATIC HMI MTP1000 Unified Comfort Panel hygienic (6AV2128-3KB40-0AX0), SIMATIC HMI MTP1000 Unified Comfort Panel hygienic neutral design (6AV2128-3KB70-0AX0), SIMATIC HMI MTP1000, Unified Comfort Panel neutral (6AV2128-3KB36-0AX1), SIMATIC HMI MTP1200 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3MB27-1BX0), SIMATIC HMI MTP1200 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3MB27-0BX0), SIMATIC HMI MTP1200 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3MB27-0AX0), SIMATIC HMI MTP1200 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3MB57-1BX0), SIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (expandable, round tube) and extensio (6AV2128-3MB57-0BX0), SIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3MB57-0AX0), SIMATIC HMI MTP1200 Unified Comfort Panel (6AV2128-3MB06-0AX1), SIMATIC HMI MTP1200 Unified Comfort Panel hygienic (6AV2128-3MB40-0AX0), SIMATIC HMI MTP1200 Unified Comfort Panel hygienic neutral design (6AV2128-3MB70-0AX0), SIMATIC HMI MTP1200 Unified Comfort Panel neutral design (6AV2128-3MB36-0AX1), SIMATIC HMI MTP1500 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3QB27-1BX0), SIMATIC HMI MTP1500 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3QB27-0BX0), SIMATIC HMI MTP1500 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3QB27-0AX0), SIMATIC HMI MTP1500 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3QB57-1BX0), SIMATIC HMI MTP1500 Comfort Pro neutral design for support arm (expandable, round tube) and extensio (6AV2128-3QB57-0BX0), SIMATIC HMI MTP1500 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3QB57-0AX0), SIMATIC HMI MTP1500 Unified Comfort Panel (6AV2128-3QB06-0AX1), SIMATIC HMI MTP1500 Unified Comfort Panel hygienic (6AV2128-3QB40-0AX0), SIMATIC HMI MTP1500 Unified Comfort Panel hygienic neutral design (6AV2128-3QB70-0AX0), SIMATIC HMI MTP1500 Unified Comfort Panel neutral design (6AV2128-3QB36-0AX1), SIMATIC HMI MTP1900 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3UB27-1BX0), SIMATIC HMI MTP1900 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3UB27-0BX0), SIMATIC HMI MTP1900 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3UB27-0AX0), SIMATIC HMI MTP1900 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3UB57-1BX0), SIMATIC HMI MTP1900 Comfort Pro neutral design for support arm (expandable, round tube) and extensio (6AV2128-3UB57-0BX0), SIMATIC HMI MTP1900 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3UB57-0AX0), SIMATIC HMI MTP1900 Unified Comfort Panel (6AV2128-3UB06-0AX1), SIMATIC HMI MTP1900 Unified Comfort Panel hygienic (6AV2128-3UB40-0AX0), SIMATIC HMI MTP1900 Unified Comfort Panel hygienic neutral design (6AV2128-3UB70-0AX0), SIMATIC HMI MTP1900 Unified Comfort Panel neutral design (6AV2128-3UB36-0AX1), SIMATIC HMI MTP2200 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3XB27-1BX0), SIMATIC HMI MTP2200 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3XB27-0BX0), SIMATIC HMI MTP2200 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3XB27-0AX0), SIMATIC HMI MTP2200 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3XB57-1BX0), SIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (expandable, round tube) and extensio (6AV2128-3XB57-0BX0), SIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3XB57-0AX0), SIMATIC HMI MTP2200 Unified Comfort Hygienic (6AV2128-3XB40-0AX0), SIMATIC HMI MTP2200 Unified Comfort Hygienic neutral design (6AV2128-3XB70-0AX0), SIMATIC HMI MTP2200 Unified Comfort Panel (6AV2128-3XB06-0AX1), SIMATIC HMI MTP2200 Unified Comfort Panel neutral design (6AV2128-3XB36-0AX1), SIMATIC HMI MTP700 Unified Comfort Panel (6AV2128-3GB06-0AX1), SIMATIC HMI MTP700 Unified Comfort Panel hygienic neutral design (6AV2128-3GB40-0AX0), SIMATIC HMI MTP700 Unified Comfort Panel hygienic neutral design (6AV2128-3GB70-0AX0), SIMATIC HMI MTP700, Unified Comfort Panel neutral design (6AV2128-3GB36-0AX1), SIPLUS HMI MTP1000 Unified Comfort (6AG1128-3KB06-4AX1), SIPLUS HMI MTP1200 Unified Comfort (6AG1128-3MB06-4AX1), SIPLUS HMI MTP700 Unified Comfort (6AG1128-3GB06-4AX1)
Critical infrastructure sectorsCritical ManufacturingSIMATIC HMI Unified Comfort Panels before V21.0 are affected by a vulnerability that allows an unauthenticated attacker to access the web browser via the help link. This vulnerability allows an attacker to access the web browser through the Control Panel if it is not protected by the corresponding security mechanisms. This opens the possibility for the attacker to find backdoors, which might lead to unwanted misconfigurations. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Named CVEsCVE-2026-27662Weakness classesView CISA CSAF advisory ↗Mitigations- Compliance with the security guidelines is strongly recommended (specially chapter “3.2 Ending HMI runtime”, “3.4.1 Enable access protection for the Control Panel” and “3.4.2 Changing runtime autostart) https://support.industry.siemens.com/cs/ww/en/view/109481300
- Disable the taskbar which can be configured in the Control Panel > System Properties > Taskbar.
- Update to V21 or later versionVendor reference ↗
- ICSA-26-134-06OTCVSS 7.5 HighReleased 2026-05-12 · Updated 2026-05-14
Siemens Industrial Devices
Vendor: SiemensProducts: IE/PB LINK HA (6GK1411-5BB00), IE/PB link PN IO (6GK1411-5AB10), RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2), SCALANCE M804PB (6GK5804-0AP00-2AA2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2), SCALANCE M812-1 ADSL-Router (6GK5812-1BA00-2AA2), SCALANCE M816-1 ADSL-Router (6GK5816-1AA00-2AA2), SCALANCE M816-1 ADSL-Router (6GK5816-1BA00-2AA2), SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2), SCALANCE M874-2 (6GK5874-2AA00-2AA2), SCALANCE M874-3 (6GK5874-3AA00-2AA2), SCALANCE M874-3 3G-Router (CN) (6GK5874-3AA00-2FA2), SCALANCE M876-3 (6GK5876-3AA02-2BA2), SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2), SCALANCE M876-4 (6GK5876-4AA10-2BA2), SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2), SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2), SCALANCE MUB852-1 (A1) (6GK5852-1EA10-1AA1), SCALANCE MUB852-1 (B1) (6GK5852-1EA10-1BA1), SCALANCE MUM853-1 (A1) (6GK5853-2EA10-2AA1), SCALANCE MUM853-1 (B1) (6GK5853-2EA10-2BA1), SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1), SCALANCE MUM856-1 (A1) (6GK5856-2EA10-3AA1), SCALANCE MUM856-1 (B1) (6GK5856-2EA10-3BA1), SCALANCE MUM856-1 (CN) (6GK5856-2EA00-3FA1), SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1), SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1), SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2), SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2), SCALANCE SC622-2C (6GK5622-2GS00-2AC2), SCALANCE SC626-2C (6GK5626-2GS00-2AC2), SCALANCE SC632-2C (6GK5632-2GS00-2AC2), SCALANCE SC636-2C (6GK5636-2GS00-2AC2), SCALANCE SC642-2C (6GK5642-2GS00-2AC2), SCALANCE SC646-2C (6GK5646-2GS00-2AC2), SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0), SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0), SCALANCE W1788-2 EEC M12 (6GK5788-2GY01-0TA0), SCALANCE W1788-2 M12 (6GK5788-2GY01-0AA0), SCALANCE W1788-2IA M12 (6GK5788-2HY01-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0), SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0), SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0), SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0), SCALANCE WAM766-1 (6GK5766-1GE00-7DA0), SCALANCE WAM766-1 (ME) (6GK5766-1GE00-7DC0), SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0), SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0), SCALANCE WAM766-1 EEC (ME) (6GK5766-1GE00-7TC0), SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0), SCALANCE WUB762-1 (6GK5762-1AJ00-1AA0), SCALANCE WUB762-1 iFeatures (6GK5762-1AJ00-2AA0), SCALANCE WUM763-1 (6GK5763-1AL00-3AA0), SCALANCE WUM763-1 (6GK5763-1AL00-3DA0), SCALANCE WUM763-1 (US) (6GK5763-1AL00-3AB0), SCALANCE WUM763-1 (US) (6GK5763-1AL00-3DB0), SCALANCE WUM766-1 (6GK5766-1GE00-3DA0), SCALANCE WUM766-1 (ME) (6GK5766-1GE00-3DC0), SCALANCE WUM766-1 (USA) (6GK5766-1GE00-3DB0), SCALANCE X204-2 (6GK5204-2BB10-2AA3), SCALANCE X204-2FM (6GK5204-2BB11-2AA3), SCALANCE X204-2LD (6GK5204-2BC10-2AA3), SCALANCE X204-2LD TS (6GK5204-2BC10-2CA2), SCALANCE X204-2TS (6GK5204-2BB10-2CA2), SCALANCE X206-1 (6GK5206-1BB10-2AA3), SCALANCE X206-1LD (6GK5206-1BC10-2AA3), SCALANCE X208 (6GK5208-0BA10-2AA3), SCALANCE X208PRO (6GK5208-0HA10-2AA6), SCALANCE X212-2 (6GK5212-2BB00-2AA3), SCALANCE X212-2LD (6GK5212-2BC00-2AA3), SCALANCE X216 (6GK5216-0BA00-2AA3), SCALANCE X224 (6GK5224-0BA00-2AA3), SCALANCE X302-7 EEC (230V, coated) (6GK5302-7GD00-3GA3), SCALANCE X302-7 EEC (230V) (6GK5302-7GD00-3EA3), SCALANCE X302-7 EEC (24V, coated) (6GK5302-7GD00-1GA3), SCALANCE X302-7 EEC (24V) (6GK5302-7GD00-1EA3), SCALANCE X302-7 EEC (2x 230V, coated) (6GK5302-7GD00-4GA3), SCALANCE X302-7 EEC (2x 230V) (6GK5302-7GD00-4EA3), SCALANCE X302-7 EEC (2x 24V, coated) (6GK5302-7GD00-2GA3), SCALANCE X302-7 EEC (2x 24V) (6GK5302-7GD00-2EA3), SCALANCE X304-2FE (6GK5304-2BD00-2AA3), SCALANCE X306-1LD FE (6GK5306-1BF00-2AA3), SCALANCE X307-2 EEC (230V, coated) (6GK5307-2FD00-3GA3), SCALANCE X307-2 EEC (230V) (6GK5307-2FD00-3EA3), SCALANCE X307-2 EEC (24V, coated) (6GK5307-2FD00-1GA3), SCALANCE X307-2 EEC (24V) (6GK5307-2FD00-1EA3), SCALANCE X307-2 EEC (2x 230V, coated) (6GK5307-2FD00-4GA3), SCALANCE X307-2 EEC (2x 230V) (6GK5307-2FD00-4EA3), SCALANCE X307-2 EEC (2x 24V, coated) (6GK5307-2FD00-2GA3), SCALANCE X307-2 EEC (2x 24V) (6GK5307-2FD00-2EA3), SCALANCE X307-3 (6GK5307-3BL00-2AA3), SCALANCE X307-3 (6GK5307-3BL10-2AA3), SCALANCE X307-3LD (6GK5307-3BM00-2AA3), SCALANCE X307-3LD (6GK5307-3BM10-2AA3), SCALANCE X308-2 (6GK5308-2FL00-2AA3), SCALANCE X308-2 RD (inkl. SIPLUS variants), SCALANCE X308-2LD (6GK5308-2FM00-2AA3), SCALANCE X308-2LD (6GK5308-2FM10-2AA3), SCALANCE X308-2LH (6GK5308-2FN00-2AA3), SCALANCE X308-2LH (6GK5308-2FN10-2AA3), SCALANCE X308-2LH+ (6GK5308-2FP00-2AA3), SCALANCE X308-2LH+ (6GK5308-2FP10-2AA3), SCALANCE X308-2M (6GK5308-2GG00-2AA2), SCALANCE X308-2M (6GK5308-2GG10-2AA2), SCALANCE X308-2M PoE (6GK5308-2QG00-2AA2), SCALANCE X308-2M PoE (6GK5308-2QG10-2AA2), SCALANCE X308-2M TS (6GK5308-2GG00-2CA2), SCALANCE X308-2M TS (6GK5308-2GG10-2CA2), SCALANCE X310 (6GK5310-0FA00-2AA3), SCALANCE X310 (6GK5310-0FA10-2AA3), SCALANCE X310FE (6GK5310-0BA00-2AA3), SCALANCE X310FE (6GK5310-0BA10-2AA3), SCALANCE X320-1 FE (6GK5320-1BD00-2AA3), SCALANCE X320-1-2LD FE (6GK5320-3BF00-2AA3), SCALANCE X408-2 (6GK5408-2FD00-2AA2), SCALANCE XF204 (6GK5204-0BA00-2AF2), SCALANCE XF204-2 (6GK5204-2BC00-2AF2), SCALANCE XF206-1 (6GK5206-1BC00-2AF2), SCALANCE XF208 (6GK5208-0BA00-2AF2), SCALANCE XM408-4C (6GK5408-4GP00-2AM2), SCALANCE XM408-4C (L3 int.) (6GK5408-4GQ00-2AM2), SCALANCE XM408-8C (6GK5408-8GS00-2AM2), SCALANCE XM408-8C (L3 int.) (6GK5408-8GR00-2AM2), SCALANCE XM416-4C (6GK5416-4GS00-2AM2), SCALANCE XM416-4C (L3 int.) (6GK5416-4GR00-2AM2), SCALANCE XR324-12M (230V, ports on front) (6GK5324-0GG00-3AR2), SCALANCE XR324-12M (230V, ports on front) (6GK5324-0GG10-3AR2), SCALANCE XR324-12M (230V, ports on rear) (6GK5324-0GG00-3HR2), SCALANCE XR324-12M (230V, ports on rear) (6GK5324-0GG10-3HR2), SCALANCE XR324-12M (24V, ports on front) (6GK5324-0GG00-1AR2), SCALANCE XR324-12M (24V, ports on front) (6GK5324-0GG10-1AR2), SCALANCE XR324-12M (24V, ports on rear) (6GK5324-0GG00-1HR2), SCALANCE XR324-12M (24V, ports on rear) (6GK5324-0GG10-1HR2), SCALANCE XR324-12M TS (24V) (6GK5324-0GG00-1CR2), SCALANCE XR324-12M TS (24V) (6GK5324-0GG10-1CR2), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front) (6GK5324-4GG00-3ER2), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front) (6GK5324-4GG10-3ER2), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG00-3JR2), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG10-3JR2), SCALANCE XR324-4M EEC (24V, ports on front) (6GK5324-4GG00-1ER2), SCALANCE XR324-4M EEC (24V, ports on front) (6GK5324-4GG10-1ER2), SCALANCE XR324-4M EEC (24V, ports on rear) (6GK5324-4GG00-1JR2), SCALANCE XR324-4M EEC (24V, ports on rear) (6GK5324-4GG10-1JR2), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front) (6GK5324-4GG00-4ER2), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front) (6GK5324-4GG10-4ER2), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG00-4JR2), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG10-4JR2), SCALANCE XR324-4M EEC (2x 24V, ports on front) (6GK5324-4GG00-2ER2), SCALANCE XR324-4M EEC (2x 24V, ports on front) (6GK5324-4GG10-2ER2), SCALANCE XR324-4M EEC (2x 24V, ports on rear) (6GK5324-4GG00-2JR2), SCALANCE XR324-4M EEC (2x 24V, ports on rear) (6GK5324-4GG10-2JR2), SCALANCE XR324-4M PoE (230V, ports on front) (6GK5324-4QG00-3AR2), SCALANCE XR324-4M PoE (230V, ports on front) (6GK5324-4QG10-3AR2), SCALANCE XR324-4M PoE (230V, ports on rear) (6GK5324-4QG00-3HR2), SCALANCE XR324-4M PoE (230V, ports on rear) (6GK5324-4QG10-3HR2), SCALANCE XR324-4M PoE (24V, ports on front) (6GK5324-4QG00-1AR2), SCALANCE XR324-4M PoE (24V, ports on front) (6GK5324-4QG10-1AR2), SCALANCE XR324-4M PoE (24V, ports on rear) (6GK5324-4QG00-1HR2), SCALANCE XR324-4M PoE (24V, ports on rear) (6GK5324-4QG10-1HR2), SCALANCE XR324-4M PoE TS (24V, ports on front) (6GK5324-4QG00-1CR2), SCALANCE XR324-4M PoE TS (24V, ports on front) (6GK5324-4QG10-1CR2), SCALANCE XR524-8C, 1x230V (6GK5524-8GS00-3AR2), SCALANCE XR524-8C, 1x230V (L3 int.) (6GK5524-8GR00-3AR2), SCALANCE XR524-8C, 24V (6GK5524-8GS00-2AR2), SCALANCE XR524-8C, 24V (L3 int.) (6GK5524-8GR00-2AR2), SCALANCE XR524-8C, 2x230V (6GK5524-8GS00-4AR2), SCALANCE XR524-8C, 2x230V (L3 int.) (6GK5524-8GR00-4AR2), SCALANCE XR526-8C, 1x230V (6GK5526-8GS00-3AR2), SCALANCE XR526-8C, 1x230V (L3 int.) (6GK5526-8GR00-3AR2), SCALANCE XR526-8C, 24V (6GK5526-8GS00-2AR2), SCALANCE XR526-8C, 24V (L3 int.) (6GK5526-8GR00-2AR2), SCALANCE XR526-8C, 2x230V (6GK5526-8GS00-4AR2), SCALANCE XR526-8C, 2x230V (L3 int.) (6GK5526-8GR00-4AR2), SCALANCE XR528-6M (6GK5528-0AA00-2AR2), SCALANCE XR528-6M (2HR2, L3 int.) (6GK5528-0AR00-2HR2), SCALANCE XR528-6M (2HR2) (6GK5528-0AA00-2HR2), SCALANCE XR528-6M (L3 int.) (6GK5528-0AR00-2AR2), SCALANCE XR552-12M (6GK5552-0AA00-2AR2), SCALANCE XR552-12M (2HR2, L3 int.) (6GK5552-0AR00-2AR2), SCALANCE XR552-12M (2HR2) (6GK5552-0AA00-2HR2), SCALANCE XR552-12M (2HR2) (6GK5552-0AR00-2HR2), SIMATIC CFU DIQ (6ES7655-5PX31-1XX0), SIMATIC CFU PA (6ES7655-5PX11-0XX0), SIMATIC CFU PA (6ES7655-5PX11-1XX0), SIMATIC ET 200pro IM 154-8 PN/DP CPU (6ES7154-8AB01-0AB0), SIMATIC ET 200pro IM 154-8F PN/DP CPU (6ES7154-8FB01-0AB0), SIMATIC ET 200pro IM 154-8FX PN/DP CPU (6ES7154-8FX00-0AB0), SIMATIC ET 200S IM 151-8 PN/DP CPU (6ES7151-8AB01-0AB0), SIMATIC ET 200S IM 151-8F PN/DP CPU (6ES7151-8FB01-0AB0), SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SJ00-0AB0), SIMATIC ET 200SP CPU 1510SP-1 PN (6ES7510-1DJ00-0AB0), SIMATIC ET 200SP CPU 1512SP F-1 PN (6ES7512-1SK00-0AB0), SIMATIC ET 200SP CPU 1512SP-1 PN (6ES7512-1DK00-0AB0), SIMATIC ET 200SP HA IM155-6 PN, SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK00-0AB0), SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK00-0AB0), SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL00-0AB0), SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM00-0AB0), SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM00-0AB0), SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN00-0AB0), SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN00-0AB0), SIMATIC S7-300 CPU 314C-2 PN/DP (6ES7314-6EH04-0AB0), SIMATIC S7-300 CPU 315-2 PN/DP (6ES7315-2EH14-0AB0), SIMATIC S7-300 CPU 315F-2 PN/DP (6ES7315-2FJ14-0AB0), SIMATIC S7-300 CPU 315T-3 PN/DP (6ES7315-7TJ10-0AB0), SIMATIC S7-300 CPU 317-2 PN/DP (6ES7317-2EK14-0AB0), SIMATIC S7-300 CPU 317F-2 PN/DP (6ES7317-2FK14-0AB0), SIMATIC S7-300 CPU 317T-3 PN/DP (6ES7317-7TK10-0AB0), SIMATIC S7-300 CPU 317TF-3 PN/DP (6ES7317-7UL10-0AB0), SIMATIC S7-300 CPU 319-3 PN/DP (6ES7318-3EL01-0AB0), SIMATIC S7-300 CPU 319F-3 PN/DP (6ES7318-3FL01-0AB0), SIMATIC S7-400 CPU 412-2 PN V7 (6ES7412-2EK07-0AB0), SIMATIC S7-400 CPU 414-3 PN/DP V7 (6ES7414-3EM07-0AB0), SIMATIC S7-400 CPU 414F-3 PN/DP V7 (6ES7414-3FM07-0AB0), SIMATIC S7-400 CPU 416-3 PN/DP V7 (6ES7416-3ES07-0AB0), SIMATIC S7-400 CPU 416F-3 PN/DP V7 (6ES7416-3FS07-0AB0), SIMATIC S7-400 H V6 CPU family (incl. SIPLUS variants), SIMATIC S7-410 V10 CPU family (incl. SIPLUS variants), SIMATIC S7-410 V8 CPU family (incl. SIPLUS variants), SIMIT UNIT V10, SIMIT UNIT V11, SINAMICS CBE20, SINAMICS G115D, SINAMICS G120 (incl. SIPLUS variants), SINAMICS G120C, SINAMICS G120D, SINAMICS G120X, SINAMICS G120XA, SINAMICS G130, SINAMICS G150, SINAMICS S110, SINAMICS S120 (incl. SIPLUS variants), SINAMICS S150, SINUMERIK 840D sl, SIPLUS ET 200S IM 151-8 PN/DP CPU (6AG1151-8AB01-7AB0), SIPLUS ET 200S IM 151-8F PN/DP CPU (6AG1151-8FB01-2AB0), SIPLUS NET IE/PB link PN IO (6AG1411-5AB10-2AA0), SIPLUS S7-300 CPU 314C-2 PN/DP (6AG1314-6EH04-7AB0), SIPLUS S7-300 CPU 315-2 PN/DP (6AG1315-2EH14-7AB0), SIPLUS S7-300 CPU 315F-2 PN/DP (6AG1315-2FJ14-2AB0), SIPLUS S7-300 CPU 317-2 PN/DP (6AG1317-2EK14-7AB0), SIPLUS S7-300 CPU 317F-2 PN/DP (6AG1317-2FK14-2AB0), SIPLUS S7-400 CPU 414-3 PN/DP V7 (6AG1414-3EM07-7AB0), SIPLUS S7-400 CPU 416-3 PN/DP V7 (6AG1416-3ES07-7AB0), SITOP PSU8600 1AC 20 A/4x5 A PN (6EP3336-8MB00-2CY0), SITOP PSU8600 3AC 20 A PN (6EP3436-8SB00-2AY0), SITOP PSU8600 3AC 20 A/4x5 A PN (6EP3436-8MB00-2CY0), SITOP PSU8600 3AC 40 A PN (6EP3437-8SB00-2AY0), SITOP PSU8600 3AC 40 A/4x10 A PN (6EP3437-8MB00-2CY0), SITOP PSU8600 3AC 40 A/4x10A EIP (6EP3437-8MB10-2CY0), SITOP UPS1600 10 A Ethernet/ PROFINET (6EP4134-3AB00-2AY0), SITOP UPS1600 20 A Ethernet/ PROFINET (6EP4136-3AB00-2AY0), SITOP UPS1600 40 A Ethernet/ PROFINET (6EP4137-3AB00-2AY0), SITOP UPS1600 EX 20 A Ethernet PROFINET (6EP4136-3AC00-2AY0)
Critical infrastructure sectorsCritical ManufacturingMultiple industrial devices contain a vulnerability that could allow an attacker to cause a denial of service condition. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
Named CVEsCVE-2025-40833Weakness classesView CISA CSAF advisory ↗Mitigations- As a mitigation, disable the ethernet ports on the CPU and use a communication module (like CP) for communication instead
- Restrict access to the affected systems to trusted IP addresses only
- Currently no fix is planned
- Currently no fix is available
- Update to V10.2 or later versionVendor reference ↗
- Update to V2.0.0 or later versionVendor reference ↗
- Update to V3.2.0 or later versionVendor reference ↗
- Update to V6.6.0 or later versionVendor reference ↗
- Update to V8.3 or later versionVendor reference ↗
- Update to V1.3 or later version
- https://support.industry.siemens.com/cs/ww/en/view/1029552/
- ICSA-26-134-05OTCVSS 7.8 HighReleased 2026-05-12 · Updated 2026-07-02
Siemens Simcenter Femap
Vendor: SiemensProduct: Simcenter Femap
Critical infrastructure sectorsCritical ManufacturingSimcenter Femap is affected by file parsing vulnerabilities in Datakit library and Parasolid Translator Component that could be triggered when the application reads files in IPT or IGS format. If a user is tricked to open a malicious file with the affected application, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released a new version for Simcenter Femap and recommends to update to the latest version.
Named CVEsCVE-2025-12659CVE-2025-40936View CISA CSAF advisory ↗Mitigations- Update to V2512.0003 or later versionVendor reference ↗
- ICSA-26-134-04OTCVSS 7.5 HighReleased 2026-05-12 · Updated 2026-05-14
Siemens Teamcenter
Vendor: SiemensProducts: Teamcenter V2312, Teamcenter V2406, Teamcenter V2412, Teamcenter V2506, Teamcenter V2512
Critical infrastructure sectorsCritical ManufacturingSiemens Teamcenter is affected by multiple vulnerabilities which could potentially lead to a compromise in availability, integrity and confidentiality. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Named CVEsCVE-2024-4367CVE-2026-33862CVE-2026-33893View CISA CSAF advisory ↗Mitigations- Update to V2312.0009 or later versionVendor reference ↗
- Update to V2406.0006 or later versionVendor reference ↗
- Update to V2312.0014 or later versionVendor reference ↗
- Update to V2406.0012 or later versionVendor reference ↗
- Update to V2412.0009 or later versionVendor reference ↗
- Update to V2506.0005 or later versionVendor reference ↗
- ICSA-26-134-03OTCVSS 7.8 HighReleased 2026-05-12 · Updated 2026-05-14
Siemens Solid Edge
Vendor: SiemensProduct: Solid Edge
Critical infrastructure sectorsCritical ManufacturingSolid Edge SE2026 before Update 5 is affected by two file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released a new version for Solid Edge SE2026 and recommends to update to the latest version.
Named CVEsCVE-2026-44411CVE-2026-44412View CISA CSAF advisory ↗Mitigations- Update to V226.0 Update 5 or later versionVendor reference ↗
- ICSA-26-134-02OTCVSS 6.8 MediumReleased 2026-05-12 · Updated 2026-05-14
Siemens Ruggedcom Rox
Vendor: SiemensProducts: RUGGEDCOM ROX MX5000, RUGGEDCOM ROX MX5000RE, RUGGEDCOM ROX RX1400, RUGGEDCOM ROX RX1500, RUGGEDCOM ROX RX1501, RUGGEDCOM ROX RX1510, RUGGEDCOM ROX RX1511, RUGGEDCOM ROX RX1512, RUGGEDCOM ROX RX1524, RUGGEDCOM ROX RX1536, RUGGEDCOM ROX RX5000
Critical infrastructure sectorsCritical ManufacturingRuggedcom Rox contains an improper access control vulnerability that could allow an authenticated remote attacker to read arbitrary files with root privileges from the underlying operating system's filesystem. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Named CVEsCVE-2025-40948Weakness classesView CISA CSAF advisory ↗Mitigations- Update to V2.17.1 or later versionVendor reference ↗
- ICSA-26-134-01OTCVSS 8 HighReleased 2026-05-12 · Updated 2026-05-14
Siemens gWAP
Vendor: SiemensProduct: gWAP
Critical infrastructure sectorsCritical ManufacturingSiemens gPROMS Web Applications Publisher (gWAP) is affected by a remote code execution vulnerability introduced through a third-party component, namely the Axios HTTP client library. The vulnerability stems from a specific "Gadget" attack chain that allows prototype pollution in other third-party libraries, potentially allowing an attacker to execute arbitrary code. Siemens has released a new version for gWAP and recommends to update to the latest version.
Named CVEsCVE-2026-40175Weakness classesView CISA CSAF advisory ↗Mitigations- Update to V3.1.1 or later versionVendor reference ↗
- ICSA-26-132-02OTCVSS 8.2 HighReleased 2026-05-12
Subnet Solutions PowerSYSTEM Center
Vendor: Subnet Solutions Inc.Products: PowerSYSTEM Center 2020, PowerSYSTEM Center 2024, PowerSYSTEM Center 2026
Critical infrastructure sectorsCritical ManufacturingEnergySuccessful exploitation of these vulnerabilities could allow an authenticated attacker to expose sensitive information or cause a CRLF injection.
Named CVEsCVE-2026-26289CVE-2026-33570CVE-2026-35555CVE-2026-35504View CISA CSAF advisory ↗Mitigations- Subnet Solutions recommends users update to the latest version of PowerSYSTEM Center PSC 2020 Update 29, PSC 2024 Update 2, and PSC 2026 GA Hotfix.
- For assistance in upgrading, users should contact a Subnet Solutions System Integration team member or customer support team at (403) 270-8885 or by email at support@subnet.com.Vendor reference ↗
- Subnet Solutions recommends users do the following in order to reduce risk:
- Monitor user activity records to ensure users are following acceptable usage policies of the application.
- Restrict access to Notification Settings to trusted Administrators Monitor "Send from Address" in settings and Activity Records.
- Configure a notification rule that triggers in any bulk account export activity.
- ICSA-26-132-01OTCVSS 7.8 HighReleased 2026-05-12
Fuji Electric Tellus
Vendor: Fuji ElectricProduct: Tellus
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could allow an attacker to elevate privileges from user to system, which may then enable the attacker to cause a temporary denial of service, open files, or delete files.
Named CVEsCVE-2026-8108Weakness classesView CISA CSAF advisory ↗Mitigations- Fuji Electric recommends that Tellus be installed only with administrator privileges.
- ICSA-26-127-01OTCVSS 7.3 HighReleased 2026-05-07
MAXHUB Pivot client application
Vendor: MAXHUBProduct: MAXHUB Pivot client application
Critical infrastructure sectorsInformation TechnologySuccessful exploitation of this vulnerability may enable an attacker to access tenant email addresses and associated information in cleartext or cause a denial-of-service condition.
Named CVEsCVE-2026-6411Weakness classesView CISA CSAF advisory ↗Mitigations- MAXHUB recommends users upgrade the Pivot client application to v1.36.2 or newer. The remediation has been made available through an OTA update. Users running v1.36.2 or later are not affected and need only ensure they continue to maintain the latest version. At this time, MAXHUB is not aware of any public exploitation of this issue. For more information, see the MAXHUB support page.Vendor reference ↗
- ICSA-26-125-05OTCVSS 8.7 HighReleased 2026-05-05
Johnson Controls CEM AC2000
Vendor: Johnson Controls Inc.Product: CEM AC2000
Critical infrastructure sectorsCritical ManufacturingCommercial FacilitiesGovernment FacilitiesTransportation SystemsEnergySuccessful exploitation of this vulnerability could allow a standard user to escalate privileges on the host machine.
Named CVEsCVE-2026-21661Weakness classesView CISA CSAF advisory ↗Mitigations- Johnson Controls recommends users apply the following mitigations:
- Upgrade CEM AC 2000 12.0 to 12.0 Release 10.
- Upgrade CEM AC 2000 11.0 to 11.0 Release 9.
- Upgrade CEM AC 2000 10.6 to 10.6 Release 3.
- For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory.Vendor reference ↗
- ICSA-26-125-01OTCVSS 4.4 MediumReleased 2026-04-28 · Updated 2026-05-05
Hitachi Energy PCM600
Vendor: Hitachi EnergyProducts: PCM600 Legacy, PCM600
Critical infrastructure sectorsEnergyHitachi Energy is aware of a vulnerability that affects the Hitachi Energy PCM600 product versions listed in this document. An attacker successfully exploiting this vulnerability can impact integrity of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.
Named CVEsCVE-2018-1002208Weakness classesView CISA CSAF advisory ↗Mitigations- Prior to acquisition, PCM600 product versions 2.11 and earlier were distributed under ABB’s organization. Some Hitachi Energy users may still be operating these legacy versions. While ABB continues to maintain the PCM600 2.x product line, Hitachi Energy now exclusively maintains and distributes the PCM600 3.x product line. ABB has recently published a cybersecurity advisory [2NGA002813] (https://library.e.abb.com/public/ec33308ad2c34f92bab09df09c66954d/2NGA002813_PCM600_Sharpziplib_Vulnerability.pdf) with their recommended actions for this same vulnerability. However, because Hitachi Energy does not maintain or validate the PCM600 2.x releases, they cannot assess or guarantee the compatibility of ABB’s recommended updates with other Hitachi Energy IEDs (Relion 670 series, 650 series, SAM600, PWC600). PCM600 versions 3.0, and later are the Hitachi Energy maintained and validated versions, Hitachi Energy strongly recommends users to migrate to these versions. Additionally, please follow Hitachi Energy's [Industrial Control Systems Best Practices,](https://publisher.hitachienergy.com/preview?DocumentID=8DBD000235&LanguageCode=en&DocumentPartId=&Action=Launch) until the planned remediation is released. Contact your support representative for more detailed guidance tailored to your deployment.
- Ensure that Chapter 4 of Cyber Security Deployment Guideline - 1MRK505410 has been followed during the deployment. Ensure that no default credentials are in use. In case of exceptions, please ensure they have been mitigated with adequate countermeasures.
- Update to PCM600 3.1 SP4 (Update Planned)
- ICSA-26-118-01OTCVSS 5.5 MediumReleased 2026-04-28
NSA GRASSMARLIN
Vendor: NSAProduct: GRASSMARLIN
Critical infrastructure sectorsInformation TechnologySuccessful exploitation of this vulnerability could allow an attacker to disclose sensitive information.
Named CVEsCVE-2026-6807Weakness classesView CISA CSAF advisory ↗Mitigations- NSA has indicated that the GRASSMARLIN project has reached end-of-life status as of 2017 and is no longer supported. The project is archived, and no patches or further updates are planned or expected.
- ICSA-26-113-06OTCVSS 9.8 CriticalReleased 2026-04-23
Intrado 911 Emergency Gateway (EGW)
Vendor: IntradoProduct: Emergency Gateway
Critical infrastructure sectorsEmergency ServicesSuccessful exploitation of this vulnerability could allow an attacker to read, modify, or delete files.
Named CVEsCVE-2026-6074Weakness classesView CISA CSAF advisory ↗Mitigations- Intrado developed and released a software update on March 2nd, 2026, that addresses this issue and has contacted customers to coordinate applying the patch.
- If you have questions, contact Intrado E911 Support: E911Support@intrado.comVendor reference ↗
- ICSA-26-113-05OTCVSS 9.8 CriticalReleased 2026-04-23
Hangzhou Xiongmai Technology Co., Ltd XM530 IP Camera
Vendor: Hangzhou Xiongmai Technology Co., LtdProduct: IP Camera XM530V200_X6-WEQ_8M firmware
Critical infrastructure sectorsCommercial FacilitiesSuccessful exploitation of this vulnerability could allow an attacker to bypass authentication and have remote access to sensitive information on the device.
Named CVEsCVE-2025-65856Weakness classesView CISA CSAF advisory ↗Mitigations- Hangzhou Xiongmai Technology Co., Ltd has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of XM530 IP cameras are invited to contact Xiongmai Technology customer support for additional information (https://www.xiongmaitech.com/en/index.php/about/contact/42).Vendor reference ↗
- ICSA-26-113-04OTCVSS 7.5 HighReleased 2026-04-23
SpiceJet Online Booking System
Vendor: SpiceJetProduct: Online Booking System
Critical infrastructure sectorsTransportation SystemsSuccessful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information.
Named CVEsCVE-2026-6375CVE-2026-6376View CISA CSAF advisory ↗Mitigations- SpiceJet did not respond to CISA's requests to coordinate. Users are encouraged to reach out to SpiceJet for more information: https://corporate.spicejet.com/contactus.aspxVendor reference ↗
- ICSA-26-113-03OTCVSS 9.8 CriticalReleased 2026-04-23
Milesight Cameras
Vendor: MilesightProducts: MS-Cxx63-PD, MS-Cxx64-xPD, MS-Cxx73-xPD, MS-Cxx75-xxPD, MS-Cxx83-xPD, MS-Cxx74-PA, MS-C8477-HPG1, MS-C8477-PC, MS-C5321-FPE, MS-Cxx72-xxxPE, MS-Cxx62-xxxPE, MS-Cxx52-xxxPE, MS-Cxx66-xxxPE, MS-Cxx66-xxxGPE, MS-Cxx61-xxxPE, MS-Cxx67-xxxPE, MS-Cxx71-xxxPE, MS-Cxx41-xxxPE, MS-Cxx76-PE, MS-Cxx65-PE, MS-Cxx66-xxxG1, MS-Cxx62-xxxG1, MS-Cxx72-xxxG1, MS-CQxx31-xxxG1, MS-CQxx68-xxxG1, MS-CQxx72-xxxG1, MS-Nxxxx-NxE, MS-Nxxxx-xxC, MS-Nxxxx-xxE, MS-Nxxxx-xxG, MS-Nxxxx-xxH, MS-Nxxxx-xxT, PMC8266-FPE, PMC8266-FGPE, PM3322-E, TS4466-X4RIPG1, TS5366-X12RIPG1, TS8266-X4RIPG1, TS4466-X4RIVPG1, TS4466-RFIVPG1, TS8266-X4RIVPG1, TS8266-RFIVPG1, TS4466-X4RIWG1, TS8266-X4RIWG1, TS5510-GVH, TS5510-GH, TS5511-GVH, TS2966-X12TPE, TS4466-X4RPE, TS5366-X12PE, TS8266-X4PE, TS2966-X12TVPE, TS4466-X4RVPE, TS5366-X12VPE, TS8266-X4VPE, TS4441-X36RPE, TS4441-X36RE, TS4466-X4RWE, TS8266-X4WE, MS-C2964-RFLPC, MS-C2972-RFLPC, MS-C2966-RFLWPC, TS2866-X4TPC, TS2866-X4TVPC, TS2866-X4TGPC, TS2841-X36TPC, TS2841-X36TPC/W, TS2867-X5TPC, TS2961-X12TPC, TS8266-FPC/P, MS-C2966-X12RLPC, MS-C2966-X12RLVPC, MS-C5366-X12LPC, MS-C5366-X12LVPC, MS-C5361-X12LPC, MS-Cxx66-xxxxGOPC, SC211, SP111, MS-Cxx66-RFIPKG1, MS-Cxx72-RFIPKG1, MS-Cxx66-FIPKG1, MS-Cxx72-FIPKG1
Critical infrastructure sectorsCommercial FacilitiesSuccessful exploitation of these vulnerabilities could crash the device being accessed or allow remote code execution.
Named CVEsCVE-2026-28747CVE-2026-27785CVE-2026-32644CVE-2026-32649CVE-2026-20766View CISA CSAF advisory ↗Mitigations- Milesight advises all users to update their device to the latest firmware versions of PE/PC/PA found at https://www.milesight.com/support/download/firmware.Vendor reference ↗
- MS-Cxx63-PD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13
- MS-Cxx64-xPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13
- MS-Cxx73-xPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13
- MS-Cxx75-xxPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13
- MS-Cxx83-xPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13
- MS-Cxx74-PA: 3x.8.0.3-r11 and prior versions: Update to 3x.8.0.3-r13
- MS-C8477-HPG1: 63.8.0.4-r3 and prior versions: Update to 63.8.0.4-r4
- MS-C8477-PC: 48.8.0.4-r3 and prior versions: Update to 48.8.0.4-r4
- MS-C5321-FPE: 62.8.0.4-r5 and prior versions: Update to 62.8.0.4-r6
- MS-Cxx72-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2
- MS-Cxx62-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2
- MS-Cxx52-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2
- MS-Cxx66-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2
- MS-Cxx66-xxxGPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2
- MS-Cxx61-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2
- MS-Cxx67-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2
- MS-Cxx71-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2
- MS-Cxx41-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2
- MS-Cxx76-PE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2
- ICSA-26-113-02OTCVSS 9.4 CriticalReleased 2026-04-23
Carlson Software VASCO-B GNSS Receiver
Vendor: Carlson SoftwareProduct: VASCO-B GNSS Receiver
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could enable a remote attacker to alter critical system functions or disrupt device operation.
Named CVEsCVE-2026-3893Weakness classesView CISA CSAF advisory ↗Mitigations- Carlson Software recommends users update to Version 1.4.0 or greater. For more information contact Carlson Software https://www.carlsonsw.com/support-and-training/Vendor reference ↗
- ICSA-26-113-01OTCVSS 7.3 HighReleased 2026-04-23
Yadea T5 Electric Bicycle
Vendor: YadeaProduct: T5 Electric Bicycle
Critical infrastructure sectorsTransportation SystemsSuccessful exploitation of this vulnerability could result in an attacker being able to unlock and start the bicycle, leading to vehicle theft.
Named CVEsCVE-2025-70994Weakness classesView CISA CSAF advisory ↗Mitigations- Yadea did not respond to CISA's attempts at coordination. Users of Yadea T5 Electric Bicycles are encouraged to keep their systems up to date and lock their property securely with external mechanisms. Users can contact Yadea at https://yadea.com/contact-us.Vendor reference ↗
- ICSA-26-111-12OTCVSS 9.8 CriticalReleased 2026-04-21
SenseLive X3050
Vendor: SenseLiveProduct: X3050
Critical infrastructure sectorsCritical ManufacturingWater and Wastewater SystemsEnergyInformation TechnologySuccessful exploitation of these vulnerabilities could allow an attacker to take complete control of the device.
Named CVEsCVE-2026-40630CVE-2026-25720CVE-2026-35503CVE-2026-39462CVE-2026-27843CVE-2026-40431CVE-2026-40623CVE-2026-27841CVE-2026-40620CVE-2026-35064CVE-2026-25775View CISA CSAF advisory ↗Mitigations- SenseLive did not respond to CISA's requests to coordinate. Affected users are encouraged to reach out to SenseLive for more information. https://senselive.io/contactVendor reference ↗
- ICSA-26-111-10OTCVSS 9.8 CriticalReleased 2026-04-21
Silex Technology SD-330AC and AMC Manager
Vendor: Silex TechnologyProducts: SD-330AC, AMC Manager
Critical infrastructure sectorsInformation TechnologySuccessful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code, cause a denial-of-service, or configuration information may be altered without authentication.
Named CVEsCVE-2026-32955CVE-2026-32956CVE-2026-32957CVE-2026-32958CVE-2015-5621CVE-2026-32959CVE-2026-32960CVE-2026-32961CVE-2026-32962CVE-2024-24487CVE-2026-32963CVE-2026-32964CVE-2026-32965View CISA CSAF advisory ↗Mitigations- The developer has released the following versions to address this vulnerability: SD-330AC firmware Ver 1.50 or later
- AMC Manager Ver.5.1.0 or later
- CVE-2026-32955, CVE-2026-32956, CVE-2026-32957, and CVE-2026-32963: Disable HTTP/HTTPS service.
- For more information, see Silex Technology's security advisory in English (https://www.silex.jp/support/security-advisories/en/2026-001) or in Japanese (https://www.silex.jp/support/security-advisories/2026-001).Vendor reference ↗
- For more information, see JPCERT/CC vulnerability notes in English (https://jvn.jp/en/vu/JVNVU94271449/) or in Japanese (https://jvn.jp/vu/JVNVU94271449/).Vendor reference ↗
- CVE-2026-32958 and CVE-2026-32965: Set a password for the settings web interface.
- CVE-2015-5621: Disable SNMP service.
- ICSA-26-111-06OTCVSS 6.4 MediumReleased 2026-04-21 · Updated 2026-06-23
Zero Motorcycles Firmware (Update A)
Vendor: Zero MotorcyclesProduct: Zero Motorcycles firmware
Critical infrastructure sectorsTransportation SystemsSuccessful exploitation of this vulnerability could allow an attacker to pair via Bluetooth with a motorcycle, gaining unauthorized access to all Bluetooth functions, including changing the firmware.
Named CVEsCVE-2026-1354Weakness classesView CISA CSAF advisory ↗Mitigations- Zero Motorcycles has investigated this report and cautions users to pair their mobile device to their vehicle in a safe location where they can be sure no one else will try to pair at the same time. Once initiated, complete the full pairing process and confirm it is successful. Store physical keys in a secure location and do not leave the bike unattended with the key in the "ON" position. Zero Motorcycles has addressed this issue in a firmware update that is available on their FOTA platform and can be obtained by using the mobile app or by visiting an authorized Zero Motorcycles dealership. Zero Motorcycles recommends all users update the firmware to the latest available version.
- ICSA-26-111-05OTCVSS 7.3 HighReleased 2026-04-21
Hardy Barth Salia EV Charge Controller
Vendor: Hardy BarthProduct: Salia Board Firmware
Critical infrastructure sectorsEnergyTransportation SystemsSuccessful exploitation of these vulnerabilities could crash the device being accessed; a buffer overflow condition may allow remote code execution.
Named CVEsCVE-2025-5873CVE-2025-10371Weakness classesView CISA CSAF advisory ↗Mitigations- Hardy Barth did not respond to CISA's request for coordination.
- Contact Hardy Barth using their contact page here: https://www.hardy-barth.de/de/kontakt for more information.Vendor reference ↗
- Alternatively, Hardy Barth can also be contacted through their eCharge brand here: https://www.echarge.de/en/contact_companyVendor reference ↗
- ICSA-26-106-04OTCVSS 9.1 CriticalReleased 2026-04-16
AVEVA Pipeline Simulation
Vendor: AVEVAProduct: Pipeline Simulation
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could allow an unauthenticated attacker to modify simulation parameters, training configuration and training records.
Named CVEsCVE-2026-5387Weakness classesView CISA CSAF advisory ↗Mitigations- All affected versions can be fixed by upgrading to AVEVA Pipeline Simulation 2025 SP1 P01 (build 7.1.9580.8513) or higher. (https://softwaresupportsp.aveva.com/en-US/downloads/products/details/57b79fdb-7b5f-4125-8a44-833b6b5c6d6f)Vendor reference ↗
- For more information, please see AVEVA's security bulletin AVEVA-2026-004 (https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-004.pdf).Vendor reference ↗
- Restrict Network Access: Implement host-based and/or network firewall controls on all nodes hosting the Pipeline Simulation Server API to ensure that only trusted Pipeline Simulation client systems are permitted to establish connections.
- Enforce Secure Communication: Enable TLS for all API communications and ensure that server certificates are properly managed and protected to reduce the risk of manipulator-in-the-middle(MitM) attacks and tampering with data in transit.
- ICSA-26-106-03OTCVSS 9.8 CriticalReleased 2026-04-16
Anviz Multiple Products
Vendor: AnvizProducts: CX2 Lite Firmware, CX7 Firmware, CrossChex Standard
Critical infrastructure sectorsCommercial FacilitiesCritical ManufacturingDefense Industrial BaseEnergyFinancial ServicesFood and AgricultureGovernment FacilitiesHealthcare and Public HealthInformation TechnologyTransportation SystemsSuccessful exploitation of these vulnerabilities could allow attackers to conduct reconnaissance, capture or decrypt sensitive data, alter device configurations, gain unauthorized administrative or root‑level access, execute arbitrary code, compromise credentials or communications, and ultimately obtain full control over affected devices.
Named CVEsCVE-2026-33093CVE-2026-35061CVE-2026-32648CVE-2026-40461CVE-2026-35682CVE-2026-35546CVE-2026-40066CVE-2026-32324CVE-2026-31927CVE-2026-33569CVE-2026-40434CVE-2026-32650View CISA CSAF advisory ↗Mitigations- Anviz did not respond to CISA's attempts to coordinate these vulnerabilities. Users should contact Anviz for more information at https://www.anviz.com/contact-us.html.Vendor reference ↗
- ICSA-26-106-02OTCVSS 9.1 CriticalReleased 2026-04-16
Horner Automation Cscape and XL4, XL7 PLC
Vendor: Horner AutomationProducts: Cscape, XL7 PLC, XL4 PLC
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could allow an attacker to gain unauthorized access to systems and services.
Named CVEsCVE-2026-6284Weakness classesView CISA CSAF advisory ↗Mitigations- Horner Automation recommends users update to Cscape v10.2 SP2 or later. Horner Automation has also released the latest firmware for both XL4 and XL7 PLCs. Horner recommends users update to the latest version of the firmware. https://hornerautomation.com/cscape-software-free/cscape-software/.Vendor reference ↗
- For more information, see Horner Automation's release notes.
- ICSA-26-106-01OTCVSS 7.8 HighReleased 2026-04-16
Delta Electronics ASDA-Soft
Vendor: Delta ElectronicsProduct: ASDA-Soft
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code.
Named CVEsCVE-2026-5726Weakness classesView CISA CSAF advisory ↗Mitigations- Delta Electronics recommends users download and upgrade ASDA-Soft to v7.2.6.0 or later. If you have any product-related support concerns, contact Delta via the portal page at https://www.deltaww.com/en-US/service-support/contact-us?type=1 for any information or materials you may require.Vendor reference ↗
- Delta Electronics provides the following general recommendations: Do not click on untrusted internet links or open unsolicited attachments in emails. Avoid exposing control systems and equipment to the Internet. Place control system networks and remote devices behind firewalls, and isolate them from the business network. When remote access is required, use a secure access method, such as a virtual private network (VPN).
- For more information, see Delta Electronics advisory Delta-PCSA-2026-00007 athttps://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2026-00007_ASDA-Soft%20Stack-based%20Buffer%20Overflow%20Vulnerability%20(CVE-2026-5726).pdfVendor reference ↗
- ICSA-26-190-03OTCVSS 5.3 MediumReleased 2026-04-14 · Updated 2026-07-09
Schneider Electric Easergy MiCOM Px40 Series
Vendor: Schneider ElectricProducts: Easergy MiCOM P14x, Easergy MiCOM P24x, Easergy MiCOM P341, Easergy MiCOM P342, P343, P344, P345, Easergy MiCOM P442, P444, Easergy MiCOM P443, P445, P446, P543, P544, P545, P546, Easergy MiCOM P841, Easergy MiCOM P643, Easergy MiCOM P642, P645, Easergy MiCOM P741, P742, P743, Easergy MiCOM P746, Easergy MiCOM P849
Critical infrastructure sectorsCritical ManufacturingEnergyTransportation SystemsSchneider Electric is aware of a vulnerability in its Easergy MiCOM Px40 Series products. The [Easergy MiCOM Px40](https://www.se.com/ww/en/product-subcategory/4725-easergy-micom-px40-series/?filter=business-6-medium-voltage-distribution-and-grid-automation) is a protection relay series for Medium Voltage, High Voltage and Extra High Voltage protection. Failure to apply the mitigations provided below may risk unauthorized exposure of basic device identification through the SNMP protocol.
Named CVEsCVE-2026-4832Weakness classesView CISA CSAF advisory ↗Mitigations- For customers who do not require SNMP Contact Schneider Electric's [Customer Care Center](https://www.se.com/ww/en/work/support/contacts.jsp) to upgrade the Firmware to a version without SNMP functionality. If customers choose not to apply the upgrade provided above, they should immediately apply the following mitigations to reduce the risk of exploit: * Use relays only in a protected network environment, * Use firewalls to protect and separate the control system network from other networks, * Use VPN (Virtual Private Networks) tunnels if remote access is required. For customers who require SNMP Please immediately apply the following mitigations to reduce the risk of exploit: * Use relays only in a protected network environment, * Use firewalls to protect and separate the control system network from other networks, * Use VPN (Virtual Private Networks) tunnels if remote access is required.
- ICSA-26-190-02OTCVSS 6.1 MediumReleased 2026-04-14 · Updated 2026-07-09
Schneider Electric PowerChute Serial Shutdown
Vendors: Schneider Electric, Microsoft, Red Hat, SuSEProducts: PowerChute™ Serial Shutdown, Windows, Enterprise Linux, Linux
Critical infrastructure sectorsCommunicationsCritical ManufacturingEnergyHealthcare and Public HealthInformation TechnologyTransportation SystemsSchneider Electric is aware of vulnerabilities in its PowerChute™ Serial Shutdown product. The [PowerChute Serial Shutdown](https://www.se.com/ww/en/product-range/137943580-powerchute-serial-shutdown/#products) product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktop, servers and workstations. Failure to apply the remediation provided below may risk improper input validation which could result in disruption of operations and access to system data.
Named CVEsCVE-2026-2399CVE-2026-2404CVE-2026-2402CVE-2026-2405CVE-2026-2403CVE-2026-2400CVE-2026-2401View CISA CSAF advisory ↗Mitigations- Version v1.5 of PowerChute™ Serial Shutdown includes a fix for this vulnerability and is available for download here: • Windows: https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/ Specific instructions and hardening guidelines for these mitigations can be found in the [Security Handbook](https://download.schneider-electric.com/files?p_Doc_Ref=SPD_CCON-PCSSSH_EN).Vendor reference ↗
- Version v1.5 of PowerChute™ Serial Shutdown includes a fix for this vulnerability and is available for download here: • Linux: https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/ Specific instructions and hardening guidelines for these mitigations can be found in the [Security Handbook](https://download.schneider-electric.com/files?p_Doc_Ref=SPD_CCON-PCSSSH_EN).Vendor reference ↗
- Version v1.5 of PowerChute™ Serial Shutdown includes a fix for this vulnerability and is available for download here: • Windows: https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/ Specific instructions and hardening guidelines for these mitigations can be found in the [Security Handbook](https://download.schneider-electric.com/files?p_Doc_Ref=SPD_CCON-PCSSSH_EN).Vendor reference ↗
- Version v1.5 of PowerChute™ Serial Shutdown includes a fix for this vulnerability and is available for download here: • Linux: https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/ Specific instructions and hardening guidelines for these mitigations can be found in the [Security Handbook](https://download.schneider-electric.com/files?p_Doc_Ref=SPD_CCON-PCSSSH_EN).Vendor reference ↗
- ICSA-26-160-01OTCVSS 9 CriticalReleased 2026-04-14 · Updated 2026-06-09
Schneider Electric Modicon Network Managed Switches
Vendor: Schneider ElectricProducts: Connexium Managed Switches, Modicon Managed Switches, Modicon Redundancy Switches
Critical infrastructure sectorsCommercial FacilitiesEnergyFood and AgricultureGovernment Services and FacilitiesTransportation SystemsWater and WastewaterSchneider Electric is aware of a RADIUS protocol vulnerability affecting its Modicon Network Managed Switch product. The Modicon Network Managed Switch product provides connectivity for multiple Ethernet devices, network management, enhanced cyber security and more advanced switching features. Failure to apply the mitigation provided below may risk forgery attacks in RADIUS Protocol, which could result in modification of any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response which could result in the possibility of denial of service and loss of confidentiality, integrity of the devices connected to the switch.
Named CVEsCVE-2024-3596Weakness classesView CISA CSAF advisory ↗Mitigations- The default RADIUS configuration is not vulnerable. However, if the RADIUS Server Message Authenticator option is disabled, the product becomes vulnerable.We advise keeping this parameter in its default (enabled) state.This parameter can be configured via CLI and SNMP:TCSESM* CLI: radius server msgauthMIB: hmAgentRadiusServerMsgAuth
- The default RADIUS configuration is not vulnerable. However, if the RADIUS Server Message Authenticator option is disabled, the product becomes vulnerable.We advise keeping this parameter in its default (enabled) state.This parameter can be configured via CLI and SNMP:MCSESM*, MCSESP* CLI: radius server auth modify <index> msgauth MIB: hm2AgentRadiusServerMsgAuth
- The default RADIUS configuration is not vulnerable. However, if the RADIUS Server Message Authenticator option is disabled, the product becomes vulnerable.We advise keeping this parameter in its default (enabled) state.This parameter can be configured via CLI and SNMP:MCSESR* CLI: radius server auth modify <index> msgauth MIB: hm2AgentRadiusServerMsgAuth
- ICSA-26-111-11OTCVSS 7.1 HighReleased 2026-04-14 · Updated 2026-04-21
Siemens Industrial Edge Management
Vendor: SiemensProducts: Industrial Edge Management Pro V1, Industrial Edge Management Pro V2, Industrial Edge Management Virtual
Critical infrastructure sectorsCritical ManufacturingIndustrial Edge Management contains an authorization bypass vulnerability that could be exploited by an unauthenticated remote attacker to circumvent authentication and to access connected Industrial Edge Devices through the remote connection feature. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Named CVEsCVE-2026-33892Weakness classesView CISA CSAF advisory ↗Mitigations- Ensure network access to affected products is limited to trusted parties only
- Update to V1.15.17 or later versionVendor reference ↗
- Update to V2.1.1 or later versionVendor reference ↗
- Update to V2.8.0 or later versionVendor reference ↗
- ICSA-26-111-09OTCVSS 8.8 HighReleased 2026-04-14 · Updated 2026-04-21
Siemens SINEC NMS
Vendor: SiemensProduct: SINEC NMS
Critical infrastructure sectorsCritical ManufacturingSINEC NMS before V4.0 SP3 contains an Authorization Bypass vulnerability that could allow an attacker to bypass authorization checks, leading to the ability to reset the password of any arbitrary user account. Siemens has released a new version for SINEC NMS and recommends to update to the latest version.
Named CVEsCVE-2026-25654Weakness classesView CISA CSAF advisory ↗Mitigations- Limit network access to trusted users and systems only
- Update to V4.0 SP3 or later versionVendor reference ↗
- ICSA-26-111-08OTCVSS 7.7 HighReleased 2026-04-14 · Updated 2026-04-21
Siemens RUGGEDCOM CROSSBOW Station Access Controller (SAC)
Vendor: SiemensProduct: RUGGEDCOM CROSSBOW Station Access Controller (SAC)
Critical infrastructure sectorsCritical ManufacturingRUGGEDCOM CROSSBOW Station Access Controller (SAC) contains a vulnerability that could allow an attacker to achieve arbitrary code execution and to create a denial of service condition. Siemens has released a new version for RUGGEDCOM CROSSBOW Station Access Controller (SAC) and recommends to update to the latest version.
Named CVEsCVE-2025-6965Weakness classesView CISA CSAF advisory ↗Mitigations- Update to V5.8 or later versionVendor reference ↗
- ICSA-26-111-07OTCVSS 9.1 CriticalReleased 2026-04-14 · Updated 2026-04-21
Siemens SCALANCE
Vendor: SiemensProducts: SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0)
Critical infrastructure sectorsCommunicationsInformation TechnologyCritical ManufacturingSCALANCE W-700 IEEE 802.11n family before V6.6.0 are affected by multiple vulnerabilities. Siemens has released a new version for SCALANCE W-700 IEEE 802.11n family and recommends to update to the latest version.
Named CVEsCVE-2020-24588CVE-2020-26139CVE-2020-26140CVE-2020-26141CVE-2020-26143CVE-2020-26144CVE-2020-26146CVE-2020-26147CVE-2021-3712CVE-2022-0778CVE-2022-31765CVE-2022-36323CVE-2022-36324CVE-2022-36325CVE-2023-44373View CISA CSAF advisory ↗Mitigations- As these vulnerabilities can only be exploited within Wi-Fi range, when possible reduce Wi-Fi transmission power or make sure to have the devices in private areas with physical access controls
- Disable A-MSDU, if possible
- Update to V6.6.0 or later versionVendor reference ↗
- ICSA-26-111-04OTCVSS 3.7 LowReleased 2026-04-14 · Updated 2026-04-21
Siemens Analytics Toolkit
Vendor: SiemensProducts: Siemens Software Center, Simcenter 3D, Simcenter Femap, Simcenter STAR-CCM+, Solid Edge SE2025, Solid Edge SE2026, Tecnomatix Plant Simulation
Critical infrastructure sectorsCritical ManufacturingMultiple Siemens applications are affected by improper certificate validation in Siemens Analytics Toolkit. This could allow an unauthenticated remote attacker to perform man in the middle attacks. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Named CVEsCVE-2025-40745Weakness classesView CISA CSAF advisory ↗Mitigations- Update to V225.0 Update 13 or later versionVendor reference ↗
- Update to V226.0 Update 04 or later versionVendor reference ↗
- Update to V2504.0008 or later versionVendor reference ↗
- Update to V2506.0002 or later versionVendor reference ↗
- Update to V2506.6000 or later versionVendor reference ↗
- Update to V2602 or later versionVendor reference ↗
- Update to V3.5.8.2 or later versionVendor reference ↗
- ICSA-26-111-03OTCVSS 7.3 HighReleased 2026-04-14 · Updated 2026-04-21
Siemens SINEC NMS
Vendor: SiemensProduct: SINEC NMS
Critical infrastructure sectorsCritical ManufacturingSiemens SINEC NMS when used with User Management Component (UMC) contains an authentication bypass vulnerability due to insufficient validation of user identity. This could allow an unauthenticated remote attacker to bypass authentication and gain unauthorized access to the application. Siemens has released a new version for SINEC NMS and recommends to update to the latest version.
Named CVEsCVE-2026-24032Weakness classesView CISA CSAF advisory ↗Mitigations- Update to V4.0 SP3 or later versionVendor reference ↗
- ICSA-26-111-02OTCVSS 8.8 HighReleased 2026-04-14 · Updated 2026-04-21
Siemens RUGGEDCOM CROSSBOW Secure Access Manager Primary
Vendor: SiemensProduct: RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P)
Critical infrastructure sectorsCritical ManufacturingRUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) contains a vulnerability that could allow an attacker to escalate their own privileges. Siemens has released a new version for RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) and recommends to update to the latest version.
Named CVEsCVE-2026-27668Weakness classesView CISA CSAF advisory ↗Mitigations- Update to V5.8 or later versionVendor reference ↗
- ICSA-26-111-01OTCVSS 6.6 MediumReleased 2026-04-14 · Updated 2026-04-21
Siemens TPM 2.0
Vendor: SiemensProducts: SIMATIC CN 4100, SIMATIC Field PG M5, SIMATIC Field PG M6, SIMATIC IPC BX-32A, SIMATIC IPC BX-39A, SIMATIC IPC BX-56A, SIMATIC IPC BX-59A, SIMATIC IPC MD-57A, SIMATIC IPC PX-32A, SIMATIC IPC PX-39A, SIMATIC IPC PX-39A PRO, SIMATIC IPC RW-528A, SIMATIC IPC RW-548A, SIMATIC IPC227E, SIMATIC IPC277E, SIMATIC IPC427E, SIMATIC IPC477E, SIMATIC IPC477E PRO, SIMATIC IPC627E, SIMATIC IPC647E, SIMATIC IPC677E, SIMATIC IPC847E, SIMATIC ITP1000, SIPLUS IPC427E
Critical infrastructure sectorsCritical ManufacturingThe products listed below contain a vulnerability that could allow an attacker to perform an out-of-bound read, potentially leading to information disclosure or denial of service of the TPM. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.
Named CVEsWeakness classesView CISA CSAF advisory ↗Mitigations- Currently no fix is planned
- Currently no fix is available
- Update to V21.01.20 or later versionVendor reference ↗
- Update to V29.01.09 or later versionVendor reference ↗
- Update to V30.01.10 or later versionVendor reference ↗
- Update to V32.01.09 or later versionVendor reference ↗
- Update to V34.01.02 or later versionVendor reference ↗
- ICSA-26-120-06OTCVSS 8.8 HighReleased 2026-04-13 · Updated 2026-04-30
ABB Ability Symphony Plus Engineering
Vendor: ABBProduct: S+ Engineering
Critical infrastructure sectorsChemicalCritical ManufacturingEnergyWater and Wastewater SystemsABB became aware of vulnerability in the products versions listed as affected in the advisory. The ABB S+ Engineering product versions are affected by vulnerabilities in PostgreSQL version 13.11 and earlier versions. If an attacker gains access to a site’s S+ Client Server network, they could exploit such vulnerabilities by executing arbitrary code and potentially compromising the entire system.
Named CVEsCVE-2023-5869CVE-2023-39417CVE-2024-7348CVE-2024-0985View CISA CSAF advisory ↗Mitigations- ABB advises all customers to review their installations to determine if they are using an impacted product as listed above, no further analysis or tools are needed to make this determination. The recommended immediate actions per product are listed below: - Systems using S+ Engineering 2.2 through 2.4 SP2 should upgrade to S+ Engineering 2.4 SP2 RU1 (re-leased in December 2024) or later. - End users who are unable to install one of these updates should immediately look to implement the Mitigation and Workarounds listed below as this will restrict or prevent an attacker’s ability to com-promise the system. ABB recommends that customers apply the update at the earliest convenience.
- Any exploit of these vulnerabilities would require that the attacker has access to the site’s S+ client/server network. Following ABB’s recommended security practices, including network architecture and perimeter firewall, are mitigating factors in preventing external access to the S+ client/server net-work. Refer to section “General security recommendations” for further advise on how to keep your system secure.
- No workarounds are available. Assess the installation specific risk based on this advisory. Use the recommendations described under “Mitigating factors” or “Recommended immediate actions”.
- ICSA-26-120-01OTCVSS 6.5 MediumReleased 2026-04-13 · Updated 2026-04-30
ABB System 800xA, Symphony Plus IEC 61850
Vendor: ABBProducts: CI868, CI850, PM 877, S+ Operations, <=6.0.0303.0, <=6.1.0031.0, <=6.1.1004.0, <=6.1.1202.0, <=6.2.0006.0, 6.1.1-3
Critical infrastructure sectorsChemicalCritical ManufacturingEnergyWater and Wastewater SystemsThis vulnerability was privately reported relating to ABB’s implementation of the IEC 61850 communication stack for MMS client applications used in some Automation control system products. Note: IEC 61850 communication typically supports MMS and GOOSE protocols. Some ABB products support both, others only MMS (e.g. S+ Operations and PM 877). In any case, GOOSE communication is not impacted by this reported vulnerability. If an attacker gains access to a site’s IEC 61850 network, then exploiting this vulnerability will result in a device fault (PM 877, CI850 and CI868 modules) and will require a manual restart. If this attack is directed at a S+ Operations node running IEC 61850 connectivity, this will result in a crash in the IEC 61850 communication driver which, if continued a repeating basis, will also result in a denial-of-service situation. Note that this does not have an impact on the overall availability and functionality of the S+ Operations node, only the IEC 61850 communication function. The System 800xA IEC61850 Connect is not affected.
Named CVEsCVE-2025-3756Weakness classesView CISA CSAF advisory ↗Mitigations- ABB advises all customers to review their installations to determine if they are using an impacted product as listed above, no further analysis or tools are needed to make this determination. The recommended immediate actions per product are listed below: - CI868 (for AC 800M) Devices with firmware versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected in 6.1.1 and 7.0 tracks for 800xA. AC 800M 6.1.1-3 is planned for Q2 2027, AC 800M 7.0 has been released in December 2025. - CI850 (for Symphony Plus SD Series) Devices with firmware versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected in version C_0 or later (planned Q2 2026). - PM 877 (Symphony Plus MR) Devices with firmware versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected with firmware version 3.53 or later (planned Q1 2026). - S+ Operations Versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected in version 3.4 or later (released in January 2026). ABB recommends customers apply updates, as they become available, at their earliest convenience. It is also advisable to review the Mitigating Factors, Workarounds and General security recommendations sections for additional actions which may help reduce overall risk.
- The vulnerabilities announced in this Advisory for ABB Process Automation products require that an attacker has access to the system network and hosts which are generally expected to be protected. Process Control and IEC 61850 networks are NOT recommended to be exposed directly to Internet connections. If these networks are not properly isolated, then connected components may be remotely exploitable as described in this advisory. To exploit the vulnerability, an attacker with remote network access can send a specially crafted packet to the PM 877, CI850 and CI868 modules which causes the fault of these devices. S+ Operations only implements 61850 client services and therefore are not intended to listen to in-coming connection requests. However, if a specially crafted message is sent anyway, it can still cause the 61850-communication driver to crash. The usage of a perimeter firewall to allow legitimate client communications is an effective mitigation. Refer to section “General security recommendations” for further advise on how to keep your system secure.
- No workarounds are available. Assess the installation specific risk based on this advisory. Use the recommendations described under “Mitigating factors” or “Recommended immediate actions”.
- ICSA-26-099-02OTCVSS 8.6 HighReleased 2026-04-09
GPL Odorizers GPL750
Vendor: GPL OdorizersProducts: GPL750 (XL4), GPL750 (XL4 Prime), GPL750 (XL7), GPL750 (XL7 Prime)
Critical infrastructure sectorsCritical ManufacturingChemicalEnergySuccessful exploitation of this vulnerability could allow a low privileged remote attacker to manipulate register values, which would result in too much or too little odorant being injected into a gas line.
Named CVEsCVE-2026-4436Weakness classesView CISA CSAF advisory ↗Mitigations- GPL Odorizers recommends users update to the latest software version of the GPL750 in connection with the latest firmware from Horner Automation for the XL4, XL4 Prime, XL7, and XL7 Prime devices.https://lincenergysystems-my.sharepoint.com/:f:/p/h_baer/IgDYaHIhXpyLQJvnKPd6b80TAUgV7Lp8qmVYBFUb0lmr7ak?e=JLeADm.Vendor reference ↗
- GPL Odorizers recommends users clear the old files from their microSD cards, keeping only the LOGS folder and the FIRMWARE.LIC file if they have a WebMI license. The compressed folder downloaded from the link above can then be extracted to the root directory of the microSD card. These files already include the corresponding firmware update. If users do not have IT permissions to access their microSD cards, GPL Odorizers can provide preconfigured SD cards that technicians can simply swap into their odorizers prior to installation.
- For assistance in updating GPL Odorizers to the latest version, users should reach out to GPL Odorizers directly via phone number (303) 697-6701 during the hours of 8:00 a.m. to 4:00 p.m. MST.
- Horner Automation offers firmware version 15.76 for their XL Series and version 17.30 for their XL Prime Series controllers https://hornerautomation.com/controller-firmware/. An installation guide is available for both the XL series and the XL Prime series.Vendor reference ↗
- ICSA-26-099-01OTCVSS 9.8 CriticalReleased 2026-04-09
Contemporary Controls BASC 20T
Vendor: Contemporary Controls Sedona AllianceProduct: BASControl20
Critical infrastructure sectorsCommercial FacilitiesCritical ManufacturingEnergySuccessful exploitation of this vulnerability could allow an attacker to enumerate the functionality of each component associated with the PLC, reconfigure, rename, delete, perform file transfers, and make remote procedure calls.
Named CVEsCVE-2025-13926Weakness classesView CISA CSAF advisory ↗Mitigations- According to Contemporary Controls, the BASC-20T is an obsolete product. It is recommended that users of the affected product contact Contemporary Controls for additional information.Vendor reference ↗
- ICSA-26-097-01OTCVSS 8.8 HighReleased 2026-04-07
Mitsubishi Electric GENESIS64 and ICONICS Suite products
Vendors: Mitsubishi Electric, Mitsubishi Electric Iconics Digital SolutionsProducts: GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, MC Works 64, GENESIS
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of these vulnerabilities could allow a local attacker to disclose SQL Server credentials used by the affected products and use them to disclose, tamper with, or destroy data, or to cause a denial-of-service (DoS) condition on the system.
Named CVEsCVE-2025-14815CVE-2025-14816View CISA CSAF advisory ↗Mitigations- Mitsubishi Electric is releasing fixed version 10.98 or later for GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian and AnalytiX. Please download the fixed version from the link "https://iconicsinc.my.site.com/community/s/resource-center/product-downloads" and install it. After installation, perform the following step (1) and (2). (1) In Workbench, open the “Configure Application(s) Settings” dialog. In the “Available Applications” list, uncheck the “Local Cache” column for applications. (2) Delete the files created by the local cache functionality from "C:\ProgramData\ICONICS\Cache\*.sdf". For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2025-023.pdf".Vendor reference ↗
- Mitsubishi Electric Iconics Digital Solutions is releasing fixed version 10.98 or later for GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian and AnalytiX. Please download the fixed version from the link "https://iconicsinc.my.site.com/community/s/resource-center/product-downloads" and install it. After installation, perform the following step (1) and (2). (1) In Workbench, open the “Configure Application(s) Settings” dialog. In the “Available Applications” list, uncheck the “Local Cache” column for applications. (2) Delete the files created by the local cache functionality from "C:\ProgramData\ICONICS\Cache\*.sdf". For more information on the fixed version, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities which can be found at "https://iconics.com/about/security/cert".Vendor reference ↗
- Mitsubishi Electric is releasing fixed version 11.03 or later for GENESIS. Please download the fixed version from the link "https://iconicsinc.my.site.com/community/s/resource-center/product-downloads" and install it. After installation, perform the following step (1) and (2). (1) In Workbench, open the “Configure Application(s) Settings” dialog. In the “Available Applications” list, uncheck the “Local Cache” column for applications. (2) Delete the files created by the local cache functionality from "C:\ProgramData\ICONICS\11\Cache\*.sqlite3". For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2025-023.pdf".Vendor reference ↗
- Mitsubishi Electric Iconics Digital Solutions is releasing fixed version 11.03 or later for GENESIS. Please download the fixed version from the link "https://iconicsinc.my.site.com/community/s/resource-center/product-downloads" and install it. After installation, perform the following step (1) and (2). (1) In Workbench, open the “Configure Application(s) Settings” dialog. In the “Available Applications” list, uncheck the “Local Cache” column for applications. (2) Delete the files created by the local cache functionality from "C:\ProgramData\ICONICS\11\Cache\*.sqlite3". For more information on the fixed version, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities which can be found at "https://iconics.com/about/security/cert".Vendor reference ↗
- There are no plans to release fixed version for MC Works64. For users of MC Works64, refer to the Mitsubishi Electric security advisory "https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2025-023.pdf", and take the actions described there.Vendor reference ↗
- For customer of GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, and AnalytiX that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions recommend performing the following step (1) and (2). (1) In Workbench, open the “Configure Application(s) Settings” dialog. In the “Available Applications” list, uncheck the “Local Cache” column for applications. (2) Delete the files created by the local cache functionality from "C:\ProgramData\ICONICS\Cache\*.sdf".
- For customer of GENESIS that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions recommend performing the following step (1) and (2). (1) In Workbench, open the “Configure Application(s) Settings” dialog. In the “Available Applications” list, uncheck the “Local Cache” column for applications. (2) Delete the files created by the local cache functionality from "C:\ProgramData\ICONICS\11\Cache\*.sqlite3".
- For customer of MC Works 64, Mitsubishi Electric recommends performing the following step (1) and (2). (1)In Workbench, open the “Configure Application(s) Settings” dialog. In the “Available Applications” list, uncheck the “Local Cache” column for applications. (2) Delete the files created by the local cache functionality from "C:\ProgramData\ICONICS\Cache\*.sdf".
- For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions recommend using Windows authentication instead of SQL authentication for the SQL server authentication method, to minimize the risk of exploiting this vulnerability.
- For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions recommend configuring the PCs with the affected product installed so that only an administrator can log in, to minimize the risk of exploiting this vulnerability.
- For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions recommend using the PCs with the affected product installed in the LAN and blocking remote login from untrusted networks and hosts, and from non-administrator users, to minimize the risk of exploiting this vulnerability.
- For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions recommend blocking unauthorized access by using a firewall, virtual private network (VPN), etc. and allowing remote login only to administrator when internet access is required, to minimize the risk of exploiting this vulnerability.
- For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions recommend restricting physical access to the PC with the affected product installed and to the network to which the PC is connected, to minimize the risk of exploiting this vulnerability.
- For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions recommend preventing the user from clicking on web links in emails from untrusted sources, or from opening attachments in untrusted emails, to minimize the risk of exploiting this vulnerability.
- Mitsubishi Electric is releasing fixed version 10.98 or later for GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian and AnalytiX. Please download the fixed version from the link "https://iconicsinc.my.site.com/community/s/resource-center/product-downloads" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2025-023.pdf".Vendor reference ↗
- Mitsubishi Electric Iconics Digital Solutions is releasing fixed version 10.98 or later for GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian and AnalytiX. Please download the fixed version from the link "https://iconicsinc.my.site.com/community/s/resource-center/product-downloads" and install it. For more information on the fixed version, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities which can be found at "https://iconics.com/about/security/cert".Vendor reference ↗
- Mitsubishi Electric is releasing fixed version 11.03 or later for GENESIS. Please download the fixed version from the link "https://iconicsinc.my.site.com/community/s/resource-center/product-downloads" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2025-023.pdf".Vendor reference ↗
- Mitsubishi Electric Iconics Digital Solutions is releasing fixed version 11.03 or later for GENESIS. Please download the fixed version from the link "https://iconicsinc.my.site.com/community/s/resource-center/product-downloads" and install it. For more information on the fixed version, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities which can be found at "https://iconics.com/about/security/cert".Vendor reference ↗
- For customer of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions recommend performing the following steps (1) and (2). (1) Change the permissions of HHSplitter.exe so that only trusted administrators can execute it. (2) Delete HHSplitter.exe from the system if it is unnecessary.
- For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions recommend blocking unauthorized access by using a firewall, virtual private network (VPN), etc. and allowing remote login only to administrator when internet access is required, and from non-administrator users, to minimize the risk of exploiting this vulnerability.
- ICSA-26-092-02OTCVSS 4 MediumReleased 2026-04-02
Yokogawa CENTUM VP
Vendor: YokogawaProduct: CENTUM VP
Critical infrastructure sectorsCritical ManufacturingEnergyFood and AgricultureSuccessful exploitation of this vulnerability could allow an attacker to login as the PROG user and modify permissions.
Named CVEsCVE-2025-7741Weakness classesView CISA CSAF advisory ↗Mitigations- Yokogawa recommends users applying the following mitigations to affected versions:
- CENTUM VP R5.01.00 to R5.04.20: Change the user authentication mode to Windows Authentication Mode.
- CENTUM VP R6.01.00 to R6.12.00: Change the user authentication mode to Windows Authentication Mode.
- CENTUM VP R7.01.00: Apply patch software R7.01.10.
- NOTE:Changing to Windows Authentication Mode requires engineering work. If users wish to make this change, please contact Yokogawa directly https://contact.yokogawa.com/cs/gw?c-id=000498.Vendor reference ↗
- For more information and details on implementing these mitigations, users should see the Yokogawa advisory YSAR-26-0003 at https://web-material3.yokogawa.com/1/39281/files/YSAR-26-0003-E.pdfVendor reference ↗
- ICSA-26-090-02OTCVSS 9.8 CriticalReleased 2026-03-31
PX4 Autopilot
Vendor: PX4Product: Autopilot
Critical infrastructure sectorsTransportation SystemsEmergency ServicesDefense Industrial BaseSuccessful exploitation of this vulnerability could allow an attacker with access to the MAVLink interface to execute arbitrary shell commands without cryptographic authentication.
Named CVEsCVE-2026-1579Weakness classesView CISA CSAF advisory ↗Mitigations- PX4 recommends enabling MAVLink 2.0 message signing as the authentication mechanism for all non‑USB communication links. PX4 has published a security hardening guide for integrators and manufacturers at https://docs.px4.io/main/en/mavlink/security_hardening.Vendor reference ↗
- Message signing configuration documentation can be found at https://docs.px4.io/main/en/mavlink/message_signing.Vendor reference ↗
- ICSA-26-090-01OTCVSS 9.8 CriticalReleased 2026-03-31
Anritsu Remote Spectrum Monitor
Vendor: AnritsuProducts: Remote Spectrum Monitor MS27100A, Remote Spectrum Monitor MS27101A, Remote Spectrum Monitor MS27102A, Remote Spectrum Monitor MS27103A
Critical infrastructure sectorsCommunicationsDefense Industrial BaseEmergency ServicesTransportation SystemsSuccessful exploitation of this vulnerability could allow attackers with network access to alter operational settings, obtain sensitive signal data, or disrupt device availability.
Named CVEsCVE-2026-3356Weakness classesView CISA CSAF advisory ↗Mitigations- Anritsu has no plans to fix this issue. Anritsu recommends that users deploy Remote Spectrum Monitor within secure network environments to mitigate potential risks.
- Users can contact Anritsu Technical Support (1-800-267-4878) for more information.
- ICSA-26-092-01OTCVSS 7.5 HighReleased 2026-03-26 · Updated 2026-04-02
Siemens SICAM 8 Products
Vendor: SiemensProducts: CPCI85 Central Processing/Communication, RTUM85 RTU Base, SICORE Base system
Critical infrastructure sectorsCritical ManufacturingMultiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: - SICAM A8000 Device firmware - CPCI85 for CP-8031/CP-8050 - SICORE for CP-8010/CP-8012 - RTUM85 for CP-8010/CP-8012 - SICAM EGS Device firmware - CPCI85 - SICAM S8000 - SICORE - RTUM85 Siemens has released new versions for the affected products and recommends to update to the latest versions.
Named CVEsCVE-2026-27663CVE-2026-27664View CISA CSAF advisory ↗Mitigations- Update to V26.10 or later version The firmware RTUM85 V26.10 is present within “CP-8010/CP-8012 Package” V26.10 https://support.industry.siemens.com/cs/ww/en/view/109972894/ and also within “SICAM S8000 Package” V26.10 https://support.industry.siemens.com/cs/document/109818240
- Update to V26.10 or later version The firmware CPCI85 V26.10 is present within “CP-8031/CP-8050 Package” V26.10 https://support.industry.siemens.com/cs/ww/en/view/109804985/ and also within “SICAM EGS Package” V26.10 https://support.industry.siemens.com/cs/document/109972536/
- Update to V26.10.0 or later version The firmware SICORE V26.10.0 is present within “CP-8010/CP-8012 Package” V26.10 https://support.industry.siemens.com/cs/ww/en/view/109972894/ and also within “SICAM S8000 Package” V26.10 https://support.industry.siemens.com/cs/document/109818240
- ICSA-26-085-03OTCVSS 10 CriticalReleased 2026-03-26
PTC Windchill Product Lifecycle Management
Vendor: PTCProducts: Windchill PDMLink, FlexPLM
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could allow an attacker to achieve remote code execution.
Named CVEsCVE-2026-4681Weakness classesView CISA CSAF advisory ↗Mitigations- PTC is aware of the issue and is actively developing a fix. In the meantime, PTC recommends applying the recommended workaround. Until official patches are available, customers must take urgent steps to safeguard their environments. Specifically: Protect any publicly accessible Windchill systems
- While publicly accessible Windchill and FlexPLM systems are at higher risk and require immediate attention, PTC strongly recommends applying the mitigation steps to all deployments, regardless of Internet exposure
- Apply the same precautions to FlexPLM deployments
- The following Apache and IIS HTTP Server configuration update should be IMMEDIATELY applied to every Windchill or FlexPLM system: Customers using Apache HTTP Server should only follow "Apache HTTP Server Configuration – Workaround Steps" section steps
- Customers using Microsoft IIS should only follow "IIS Configuration - Workaround Steps" section steps
- Please explicitly note that the same mitigation steps must also be applied on File Server / Replica Server configurations where applicable
- For Windchill releases prior to 11.0 M030, workarounds may need to be altered to apply to unsupported previous releases
- For Apache HTTP Server and IIS configuration workaround steps, please refer to the official advisory at:https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-critical-vulnerability.Vendor reference ↗
- If immediate remediation is not feasible, additional guidance and remediation options are available:https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-critical-vulnerability.Vendor reference ↗
- ICSA-26-085-02OTCVSS 8.1 HighReleased 2026-03-26 · Updated 2026-04-16
OC Messaging and Custom Messaging Gateway
Vendor: OpenCode SystemsProducts: OC Messaging, Custom Messaging Gateway
Critical infrastructure sectorsCommunicationsSuccessful exploitation of this vulnerability could allow an authenticated low-privileged user to gain access to SMS messages outside of their authorized tenant scope via a crafted company or tenant identifier parameter.
Named CVEsCVE-2025-70614Weakness classesView CISA CSAF advisory ↗Mitigations- The vulnerability was identified by OpenCode Systems on January 5, 2026 and remediated on January 6, 2026 with the release of version 6.33.11.
- For more information, contact OpenCode: https://opencode.com/about/contact-usVendor reference ↗
- ICSMA-26-083-01OTCVSS 7.5 HighReleased 2026-03-24
Grassroots DICOM (GDCM)
Vendor: GrassrootsProduct: Grassroots DICOM (GDCM)
Critical infrastructure sectorsHealthcare and Public HealthSuccessful exploitation of this vulnerability could allow an attacker to send a specially crafted file, and when parsed, could result in a denial-of-service condition.
Named CVEsCVE-2026-3650Weakness classesView CISA CSAF advisory ↗Mitigations- The maintainer of Grassroots DICOM (GDCM) has not responded to requests to work with CISA to mitigate this vulnerability. For update information refer to the software page on SourceForge.
- https://sourceforge.net/projects/gdcm/.Vendor reference ↗
- ICSA-26-083-01OTCVSS 9.8 CriticalReleased 2026-03-24
Pharos Controls Mosaic Show Controller
Vendor: Pharos ControlsProduct: Mosaic Show Controller Firmware
Critical infrastructure sectorsCommercial FacilitiesSuccessful exploitation of this vulnerability could allow an unauthenticated attacker to execute arbitrary commands with root privileges.
Named CVEsCVE-2026-2417Weakness classesView CISA CSAF advisory ↗Mitigations- Pharos Controls recommends that users upgrade Mosaic Show Controller to version 2.16 or later.
- ICSA-26-085-01OTCVSS 10 CriticalReleased 2026-03-23 · Updated 2026-03-26
WAGO GmbH & Co. KG Industrial Managed Switches
Vendor: WAGOProducts: 852-1812, 852-1813, 852-1813/000-001, 852-1816, 852-303, 852-1305, 852-1305/000-001, 852-1505/000-001, 852-1505, 852-602, 852-603, 852-1605, 852-1812/010-000, 852-1813/010-000, 852-1816/010-000, 852-1813/010-001
Critical infrastructure sectorsCommercial FacilitiesCritical ManufacturingEnergyTransportation SystemsA vulnerability has been found affecting the Managed Switches of WAGO. An unauthenticated attacker can fully compromise the device via an undocumented function.
Named CVEsCVE-2026-3587Weakness classesView CISA CSAF advisory ↗Mitigations- Please update your devices to the specified fixed firmware version. | Product | Fixed Version | |-------------------------------------------|---------------| | Lean Managed Switch 852-1812 | V1.2.1.S1 | | Lean Managed Switch 852-1813 | V1.2.1.S1 | | Lean Managed Switch 852-1813/000-001| V1.2.3.S1 | | Lean Managed Switch 852-1816 | V1.2.1.S1 | | Industrial Managed Switch 852-303 | V1.2.8.S1 | | Industrial Managed Switch 852-1305 | V1.2.0.S1 | | Industrial Managed Switch 852-1305/000-001| V1.2.0.S1 | | Industrial Managed Switch 852-1505/000-001| V1.2.0.S1 | | Industrial Managed Switch 852-1505 | V1.1.9.S1 | | Industrial Managed Switch 852-602 | V1.0.6.S1 | | Industrial Managed Switch 852-603 | V1.0.6.S1 | | Industrial Managed Switch 852-1605 | V1.2.5.S1 | | Lean Managed Switch 852-1812/010-000| V1.2.1.S1 | | Lean Managed Switch 852-1813/010-000| V1.2.1.S1 | | Lean Managed Switch 852-1813/010-001| V1.2.1.S1 | | Lean Managed Switch 852-1816/010-000| V1.2.1.S1 |
- To eliminate the attack vector deactivate ssh and telnet on the device.
- To reduce the attack vector deactivate ssh and telnet on the devices. This ensures that the CLI is only accessible locally via RS232.
- ICSA-26-078-08OTCVSS 9.1 CriticalReleased 2026-03-19
Automated Logic WebCTRL Premium Server
Vendor: Automated LogicProduct: WebCTRL Premium Server
Critical infrastructure sectorsCommercial FacilitiesSuccessful exploitation of these vulnerabilities could allow an attacker to read, intercept, or modify communications.
Named CVEsCVE-2026-25086CVE-2026-32666CVE-2026-24060View CISA CSAF advisory ↗Mitigations- Automated Logic notes that WebCTRL 7 is End of Life (EOL) and has been out of support since January 27, 2023. Users are advised to upgrade to the latest version of the WebCTRL server application, which supports the more secure BACnet/SC.
- For customers using supported versions of WebCTRL (WebCTRL 8.5 cumulative releases and later), Automated Logic provides secure configuration guidance for hardware and software deployments; BACnet Secure Connect (BACnet/SC) support, which introduces TLS encryption and mutual authentication; and published best practices for network segmentation, access control, and secure protocol implementation. Additional information is available at: https://www.automatedlogic.com/en/company/security-commitment/.Vendor reference ↗
- ICSA-26-078-07OTCVSS 9.4 CriticalReleased 2026-03-19
IGL-Technologies eParking.fi
Vendor: IGL-TechnologiesProduct: eParking.fi
Critical infrastructure sectorsEnergyTransportation SystemsSuccessful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.
Named CVEsCVE-2026-29796CVE-2026-31903CVE-2026-32663CVE-2026-31926View CISA CSAF advisory ↗Mitigations- IGL-Technologies has updated eParking's OCPP servers to reduce the risks posed by the vulnerability. These updates implemented the following security controls:
- 1) Enforce modern security profiles and stronger authentication.
- 2) Device‑level whitelisting was implemented to ensure that only authorized charging units can connect.
- 3) Rate‑limiting controls prevent excessive requests and reduces DoS risk.
- 4) Enhanced automated monitoring and alerting to detection abnormal network activity.
- Devices using the encrypted deployment of eParking's OCPP servers or IGL-Technologies proprietary eTolppa protocol are not impacted by these vulnerabilities.
- To prevent this in the future IGL-Technologies will continue vulnerability monitoring under their ISO 27001:2022 security program and tighten security requirements for future third‑party OCPP hardware approvals.
- For more information please contact the IGL-Technologies security team at this email address: security@igl.fi.Vendor reference ↗
- ICSA-26-078-06OTCVSS 9.4 CriticalReleased 2026-03-19
CTEK Chargeportal
Vendor: CTEKProduct: Chargeportal
Critical infrastructure sectorsEnergyTransportation SystemsSuccessful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.
Named CVEsCVE-2026-25192CVE-2026-31904CVE-2026-27649CVE-2026-28204View CISA CSAF advisory ↗Mitigations- CTEK will be sunsetting this product in April 2026. Please contact CTEK for more information https://www.ctek.com/support.Vendor reference ↗
- ICSA-26-120-05OTCVSS 8.3 HighReleased 2026-03-13 · Updated 2026-04-30
ABB AWIN Gateways
Vendor: ABBProducts: GW100 rev. 2, AWIN Firmware, GW100 rev.2, GW120
Critical infrastructure sectorsCritical ManufacturingABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. AWIN gateways are not intended to be internet-facing. An attacker who successfully exploited this vulnerability could take remote control of the product and reboot the device, potentially causing a denial of service. It can also reveal system specific configuration. ABB requires, as noted in the User Manual, that AWIN gateways should not be exposed to the internet or any other insecure network. Note. To exploit this vulnerability the attacker needs access to the AWIN gateways. These gateways are installed on sites which often have perimeter security, and the gateways are installed behind firewalls.
Named CVEsCVE-2025-13777CVE-2025-13778CVE-2025-13779View CISA CSAF advisory ↗Mitigations- Do the following actions: - Stop and disconnect any AWIN gateways that are exposed directly to the Internet. - Ensure that physical controls are in place, so no unauthorized personnel can access your devices, components, peripheral equipment, and networks. - Ensure that all AWIN gateways are upgraded to the latest firmware version. Please find the latest version of firmware on the respective product Release Notes. - When remote access is required, only use secure methods. The problem is corrected in the following product versions: - AWIN GW100 rev2: v2.1-0 - AWIN GW120: v2.0-0 ABB recommends that customers contact ABB to obtain the updated firmware as soon as possible. ABB Service Support engineer shall apply the firmware update at earliest convenience.
- AWIN gateways are NOT internet facing devices and should be installed behind firewalls. These gateways are intended to be located between level 0 (process) and level 1 (basic control) hierarchy of the IEC 62443 reference model. Ensure that physical controls are in place, so no unauthorized personnel can access your devices, components, peripheral equipment, and networks. Update the firmware on the gateways with the newer versions with the fix. At the time of writing the following versions are latest: - AWIN GW100 rev2: v2.1-0 - AWIN GW120: v2.0-0 Refer to the Release Notes and Product Bulletins for up-to-date information on the latest firmware re-leases.
- ICSA-26-132-05OTCVSS 9.8 CriticalReleased 2026-03-12 · Updated 2026-05-12
ABB AC500 V3 Stack Buffer Overflow in Cryptographic Message Syntax
Vendor: ABBProducts: PM5xxx, AC500 V3 Firmware
Critical infrastructure sectorsChemicalCritical ManufacturingEnergyWater and Wastewater SystemsABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves publicly reported vulnerability. An attacker who successfully exploited these vulnerabilities could cause a crash, denial-of-service (DoS), or potentially remote code execution.
Named CVEsCVE-2025-15467Weakness classesView CISA CSAF advisory ↗Mitigations- The problem is corrected in the following product version: - AC500 V3 firmware version 3.9.0 HF1 ABB recommends that customers apply the update at earliest convenience. This firmware version is released for all AC500 V3 PLC types and available for download from the ABB library. https://search.abb.com/library/Download.aspx?DocumentID=3ADR011537&LanguageCode=en&DocumentPartId=&Action=Launch
- Refer to section “General security recommendations” for further advise on how to keep your system secure.
- No workarounds are available
- ICSA-26-071-06OTCVSS 6.3 MediumReleased 2026-03-12 · Updated 2026-03-13
Inductive Automation Ignition Software
Vendor: Inductive AutomationProduct: Ignition Software
Critical infrastructure sectorsInformation TechnologySuccessful exploitation of this vulnerability could allow an attacker to execute malicious code with OS application service account permissions that the authenticated, privileged application user did not intend on running.
Named CVEsCVE-2025-13913Weakness classesView CISA CSAF advisory ↗Mitigations- Fix - upgrade Ignition software from 8.1.x to 8.3.0 or greater.
- MITIGATION (8.1.x Linux). Implement Ignition Security Hardening Guide Appendix A. https://inductiveautomation.com/resources/article/ignition-security-hardening-guideVendor reference ↗
- MITIGATION (8.1.x Windows). Covered in Ignition Security Hardening Guide Appendix A. 1. Create a new dedicated local Windows account that will be used exclusively for the Ignition service (e.g. svc-ign). a. The best security practice is that the Ignition service should not be a domain account (unless otherwise needed). b. Remove all group memberships from the service account (including Users and Administrators). c. Add to security policy to log in as a service. d. Add to "Deny log on locally" security policy. 2. Provide full read/write access only to the Ignition installation directory for the service account created in #1. a. Add read/write permissions to other directories in the local filesystem as needed (e.g.: if configured to use optional Enterprise Administration Module to write automated backups to the file system). 3. Set deny access settings for service account on other directories not needed by the Ignition service. a. Specifically the C:\Windows, C:\Users, and directories for any other applications in the Program Files or Program Files(x86) directories. b. Use java param to change temp directory to a location within the Ignition install directory so the Users folder can be denied access to the Ignition service account.
- BEST PRACTICES (8.1.x and 8.3.x)4. Restrict project imports to verified and trusted sources only, ideally using checksums or digital signatures.5. Use multiple environments (e.g. Dev, Test, Prod) with a staging workflow so that new data is never introduced directly to Production environments. See Ignition Deployment Best Practices.6. When feasible, segment or isolate Ignition gateways from corporate resources and Windows Domains.a. The Ignition service account or AD server object should never need Windows Domain or Windows Active Directory privileges. This would only be needed if an Asset Owners IT or OT department uses this for management outside Ignition.b. Ignition may be federated with Active Directory environments (e.g. OT domains) by entering "Authentication Profile" credentials within the Ignition gateway itself. This could use secure LDAP, SAML, or OpenID Connect.7. When feasible, enforce strong credential management and MFA for all users with Designer permissions (8.1.x and 8.3.x), Config Page permissions (8.1.x), and Config Write permissions (8.3.x).8. When feasible, deploy Ignition within hardened or containerized environments.Vendor reference ↗
- ICSA-26-071-01OTCVSS 8.1 HighReleased 2026-03-12
Trane Tracer SC, Tracer SC+, and Tracer Concierge
Vendor: TraneProducts: Tracer SC, Tracer SC+, Tracer Concierge
Critical infrastructure sectorsCritical ManufacturingCommercial FacilitiesGovernment FacilitiesSuccessful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, execute arbitrary commands, or perform a denial-of-service on the product.
Named CVEsCVE-2026-28252CVE-2026-28253CVE-2026-28254CVE-2026-28255CVE-2026-28256View CISA CSAF advisory ↗Mitigations- Trane has released the following versions of Tracer SC+ for users to upgrade to:
- CVE-2026-28252, CVE-2026-28253, CVE-2026-28254: Tracer SC+ version v6.30.2313
- CVE-2026-28255: Trane has implemented enhanced cloud security controls to mitigate this vulnerability.
- CVE-2026-28256: Trane has implemented enhanced security controls which have been communicated to their customers. For more information, contact Trane.
- ICSA-26-083-02OTCVSS 6.5 MediumReleased 2026-03-10 · Updated 2026-03-24
Schneider Electric EcoStruxure Foxboro DCS
Vendor: Schneider ElectricProduct: EcoStruxure Foxboro DCS
Critical infrastructure sectorsCommercial FacilitiesCritical ManufacturingEnergySchneider Electric is aware of a vulnerability in its EcoStruxure Foxboro DCS Control Software on Foxboro DCS workstations and servers. Control Core Services and all runtime software, like FCPs, FDCs, and FBMs, are not affected. The EcoStruxure Foxboro DCS ([https://www.se.com/ww/en/product-range/63680-ecostruxure-foxboro-dcs/](https://www.se.com/ww/en/product-range/63680-ecostruxure-foxboro-dcs/)) product is an innovative family of fault-tolerant, highly available control components, which consolidates critical information and elevates staff capabilities to ensure flawless, continuous plant operation. Failure to apply the remediation provided below may risk deserialization of untrusted data, which could result in loss of confidentiality, integrity and potential remote code execution on the compromised workstation.
Named CVEsCVE-2026-1286Weakness classesView CISA CSAF advisory ↗Mitigations- Version CS 8.1 of EcoStruxure Foxboro DCS includes a fix for this vulnerability and is available through [https://buyautomation.se.com/](https://buyautomation.se.com/) CS 8.1 requires FX-V3 licenses, standard upgrade procedures apply. A reboot is required for workstations and servers. Depending on the existing system version, online upgrade without production interruption might be possible. Schneider Electric recommends you work with your local field service representative or technical service consultant for further information.Vendor reference ↗
- If users choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: The vulnerability is attacked with manipulated data from external sources to the DCS computers. Examples for these are: * Configuration taglists * DirectAccess Scripts * Any partial or full Galaxy backups * Library files * Code snippets * ASCII files of any sort * Generally, any file getting from outside the DCS computer on a DCS computer. Only use data from trusted sources, check for correct file name endings on data files, check for reasonable file sizes for any files coming to the system, and check structured data for any fields or columns which might be unexpected. Check for unusual manipulations of data within data files and reject files containing unexpected data or structures. Use secure communication channels and encrypt communications when communicating outside the site network. Avoid and ban removable media (e.g. USB sticks or drives) Minimize count of users with engineering or administrative rights to DCS computers and ensure all interactions on DCS computers are executed with minimal user access rights. Consequently, isolating Foxboro DCS computers will help minimizing the risk of this vulnerability being exploited.
- ICSA-26-078-05OTCVSS 5.9 MediumReleased 2026-03-10 · Updated 2026-03-19
Mitsubishi Electric CNC Series
Vendor: Mitsubishi ElectricProducts: M800VW (BND-2051W000), M800VS (BND-2052W000), M80V (BND-2053W000), M80VW (BND-2054W000), M800W (BND-2005W000), M800S (BND-2006W000), M80 (BND-2007W000), M80W (BND-2008W000), E80 (BND-2009W000), C80 (BND-2036W000), M750VW (BND-1015W002), M730VW (BND-1015W000), M720VW (BND-1015W000), M750VS (BND-1012W002), M730VS (BND-1012W000-**), M720VS (BND-1012W000), M70V (BND-1018W000), E70 (BND-1022W000), NC Trainer2 (BND-1802W000), NC Trainer2 plus (BND-1803W000)
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products.
Named CVEsCVE-2025-2399Weakness classesView CISA CSAF advisory ↗Mitigations- Please apply the fixed version (BC or later) for Mitsubishi Electric M800VW(BND-2051W000), M800VS(BND-2052W000), M80V(BND-2053W000), and M80VW(BND-2054W000). For instructions on how to apply it, please consult your Mitsubishi Electric representative.
- Please apply the fixed version (FN or later) for Mitsubishi Electric M800W(BND-2005W000), M800S(BND-2006W000), M80(BND-2007W000), M80W(BND-2008W000), and E80(BND-2009W000). For instructions on how to apply it, please consult your Mitsubishi Electric representative.
- For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric recommends using a firewall or virtual private network (VPN) to prevent unauthorized access, when internet access is required, to minimize the risk of exploiting this vulnerability.
- For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric recommends using the product within a LAN and blocking access from untrusted networks and hosts through a firewall, to minimize the risk of exploiting this vulnerability.
- For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric recommends using IP filters to prevent unauthorized access, when internet access is required, to minimize the risk of exploiting this vulnerability. IP filter function is available for M800V/M80V Series and M800/M80/E80 Series. For details about the IP filter function, refer to the following manual for each product: M800V/M80V Series Instruction Manual "16. Appendix 3 IP Address Filter Setting Function", M800/M80/E80 Series Instruction Manual "15. Appendix 2 IP Address Filter Setting Function"
- For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric recommends restricting physical access to the affected product and to all computers and network devices to which the products are connected, to minimize the risk of exploiting this vulnerability.
- For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric recommends installing anti-virus software on PCs that can access the affected product, to minimize the risk of exploiting this vulnerability.
- For more information, see Mitsubishi Electric 2025-022. https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-022_en.pdfVendor reference ↗
- ICSA-26-078-04OTCVSS 7.8 HighReleased 2026-03-10 · Updated 2026-03-19
Schneider Electric EcoStruxure PME and EPO
Vendor: Schneider ElectricProducts: EcoStruxure Power Monitoring Expert (PME) 2022, EcoStruxure Power Monitoring Expert (PME), EcoStruxure Power Operation (EPO) 2022 Advanced Reporting and Dashboards Module, EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module
Critical infrastructure sectorsHealthcare and Public HealthInformation TechnologyCritical ManufacturingCommercial FacilitiesEnergyTransportation SystemsGovernment FacilitiesWater and Wastewater SystemsSchneider Electric is aware of a vulnerability in its EcoStruxure Power Monitoring Expert (PME) and EcoStruxure Power Operation (EPO) products. EcoStruxure Power Monitoring Expert (PME) is an on-premises software used to help power critical and energy-intensive facilities maximize uptime and operational efficiency. EcoStruxure Power Operation (EPO) are on-premises software offers that provides a single platform to monitor and control medium and lower power systems.Failure to apply the fix provided below may risk local arbitrary code execution, which could result in the local system being compromised, a disruption of operations, and/or unauthorized administrative control of the system.
Named CVEsCVE-2025-11739Weakness classesView CISA CSAF advisory ↗Mitigations- Hotfix_279338_Release_2024R2 is available for EcoStruxure Power Monitoring Expert (PME) that includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this hotfix. No reboot required.
- Customers should upgrade to EcoStruxure Power Monitoring Expert (PME) 2024 R3. Contact Schneider Electric’s Customer Care Center for assistance.
- Hotfix_282807 - for 2023R2 is available for EcoStruxure Power Monitoring Expert (PME) that includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this hotfix. No reboot required.
- Customers should upgrade to EcoStruxure Power Monitoring Expert (PME) 2023 R2. Once upgraded, Hotfix_282807 - for 2023R2 is available for EcoStruxure Power Monitoring Expert (PME) that includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for assistance.
- EcoStruxure Power Monitoring Expert (PME) 2022 version has reached its end of life and is no longer supported. • Ensure your deployment of PME has followed the cybersecurity hardening guidelines provided with the product. https://product-help.schneider-electric.com/EcoStruxure/Power-Monitoring-Expert-2024/content/2_planning/cybersecurity/cyber-planningrecactions.htm • Ensure PME is running in an isolated network • Deploy and configure the Windows firewall to limit access to appropriate network segments• Enforce complex password policies.o Review Server Access Permissions o Conduct an audit of all Windows-authenticated users who currently have access to PME. Repeat this audit of your system periodically. o Identify all accounts with access rights, especially those with elevated privileges or remote access. o Limit access to essential users only.o Revoke access for any user accounts that are not critical for system functionality or daily operations.o Apply the principle of least privilege to ensure users have only the access necessary for their role(s). Customers should also consider upgrading to the latest product offering EcoStruxure Power Monitoring Expert (PME) 2024 R3 to resolve this issue.Vendor reference ↗
- EcoStruxure Power Operation (EPO) 2022 version and EcoStruxure Power Monitoring Expert (PME) 2022 has reached its end of life and is no longer supported. • Ensure your deployment of PME has followed the cybersecurity hardening guidelines provided with the product. https://product-help.schneider-electric.com/EcoStruxure/Power-Monitoring-Expert-2024/content/2_planning/cybersecurity/cyber-planningrecactions.htm • Ensure PME is running in an isolated network • Deploy and configure the Windows firewall to limit access to appropriate network segments• Enforce complex password policies.o Review Server Access Permissions o Conduct an audit of all Windows-authenticated users who currently have access to PME. Repeat this audit of your system periodically. o Identify all accounts with access rights, especially those with elevated privileges or remote access. o Limit access to essential users only.o Revoke access for any user accounts that are not critical for system functionality or daily operations.o Apply the principle of least privilege to ensure users have only the access necessary for their role(s). Customers should also consider upgrading to the latest product offering EcoStruxure Power Monitoring Expert (PME) 2024 R3 to resolve this issue.Vendor reference ↗
- ICSA-26-078-03OTCVSS 8.2 HighReleased 2026-03-10 · Updated 2026-03-19
Schneider Electric EcoStruxure Automation Expert
Vendor: Schneider ElectricProduct: EcoStruxure™ Automation Expert
Critical infrastructure sectorsCommercial FacilitiesCritical ManufacturingEnergySchneider Electric is aware of a vulnerability in its EcoStruxure™ Automation Expert product. The EcoStruxure™ Automation Expert product is plant automation software designed for digital control systems in discrete, hybrid and continuous industrial processes. A totally integrated automation solution designed to enhance your flexibility, efficiency and scalability. Failure to apply the remediation provided below may risk execution of arbitrary commands on the engineering workstation, which could result in a potential compromise of full system.
Named CVEsCVE-2026-2273Weakness classesView CISA CSAF advisory ↗Mitigations- Version v25.0.1 of EcoStruxure™ Automation Expert includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/23643079-ecostruxure-automation-expert/Vendor reference ↗
- If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: Solution and archive files must be stored within the user’s home directory or in any location protected by appropriate Windows file‑system access controls to prevent unauthorized access in multi‑user environments. Users who choose to store files outside their home directory are responsible for applying restrictive Windows permissions to secure those locations. Before opening any solution or archive file, users are required to verify its authenticity and ensure that it has not been modified by unauthorized users. For detailed mitigation steps, refer to the User Manual - https://product-help.se.com/EcoStruxure%20Automation%20Expert/25.0/Offer%20Guides/en-US/EAE_UM?t=EAE_UM%2FSolutionIntegrity-FE037ED3.html%3Frhhlterm%3Dundefined%253Frhsearch%253Dundefined&theme=HelpVendor reference ↗
- ICSA-26-078-02OTCVSS 5.4 MediumReleased 2026-03-10 · Updated 2026-03-19
Schneider Electric Modicon Controllers M241, M251, M258, and LMC058
Vendor: Schneider ElectricProducts: Modicon Controllers M241, Modicon Controller M241 Firmware, Modicon Controllers M251, Modicon Controller M251, Modicon Controller M251 Firmware, Modicon Controllers M258, Modicon Controllers M258 Firmware, Modicon Controllers LMC058, Modicon Controllers LMC058 Firmware
Critical infrastructure sectorsCommercial FacilitiesCritical ManufacturingEnergySchneider Electric is aware of a vulnerability in its Modicon Controllers M241 / M251, M258, and LMC058 products. The [Modicon Controllers M241 / M251 / M258](https://www.se.com/ww/en/product-category/3900-plc-pac-and-dedicated-controllers/) and [Modicon LMC058](https://www.se.com/ww/en/product-range/7744-modicon-lmc058/) are Programmable Logic Controllers for performance-demanding applications. Failure to apply the remediation or mitigations provided below may risk a Cross-site Scripting or an open redirect attack which could result in an account takeover scenario or the execution of code in the user browser.
Named CVEsCVE-2025-13902Weakness classesView CISA CSAF advisory ↗Mitigations- Modicon Controller M241 Firmware version 5.4.13.12 delivered with EcoStruxure™ Machine Expert v2.5.0.1 includes a fix for this vulnerability and can be installed through Schneider Electric Software Installer available here: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER/ On the engineering workstation install v2.5.0.1 of EcoStruxure™ Machine Expert. For help refer to Schneider Electric Software Installer User Guide available here: https://www.se.com/ww/en/download/document/EIO0000005500/ Update Modicon Controller M241 to the latest Firmware and perform reboot. For instructions refer to Modicon M241 Logic Controller, Programming Guide: https://www.se.com/ww/en/download/document/EIO0000003059/Vendor reference ↗
- Modicon Controller M251 Firmware version 5.4.13.12 delivered with EcoStruxure™ Machine Expert v2.5.0.1 includes a fix for this vulnerability and can be installed through Schneider Electric Software Installer available here: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER/ On the engineering workstation install v2.5.0.1 of EcoStruxure™ Machine Expert. For help refer to Schneider Electric Software Installer User Guide available here: https://www.se.com/ww/en/download/document/EIO0000005500/ Update Modicon Controller M251 to the latest Firmware and perform reboot. For instructions refer to Modicon M251 Logic Controller, Programming Guide: https://www.se.com/us/en/download/document/EIO0000003089/Vendor reference ↗
- If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from public internet or untrusted networks. • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Deactivate the Webserver after use when not needed. • Use encrypted communication links. • Setup network segmentation and implement a firewall to block all unauthorized access to ports 80/HTTP and 443/HTTPS. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide product specific hardening guidelines.Vendor reference ↗
- • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from public internet or untrusted networks. • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Deactivate the Webserver after use when not needed. • Use encrypted communication links. • Setup network segmentation and implement a firewall to block all unauthorized access to ports 80/HTTP and 443/HTTPS. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide product specific hardening guidelines.Vendor reference ↗
- ICSA-26-078-01OTCVSS 5.3 MediumReleased 2026-03-10 · Updated 2026-03-19
Schneider Electric Modicon M241, M251, and M262
Vendor: Schneider ElectricProducts: Modicon M241, Modicon M251, Modicon M262, Modicon Controller M241, Modicon Controller M251, Modicon Controller M262
Critical infrastructure sectorsCommercial FacilitiesCritical ManufacturingEnergySchneider Electric is aware of a vulnerability in its Modicon Controllers M241 / M251, and M262 products. The Modicon Controllers M241 / M251 / M262 are Programmable Logic Controllers for performancedemanding applications. Failure to apply the remediation provided below may risk Denial of Service attack which could result in loss of availability of the controller
Named CVEsCVE-2025-13901Weakness classesView CISA CSAF advisory ↗Mitigations- Modicon Controller M241 Firmware version 5.4.13.12 delivered with EcoStruxure™ Machine Expert v2.5.0.1 includes a fix for this vulnerability and can be installed through Schneider Electric Software Installer available here: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER/ On the engineering workstation install v2.5.0.1 of EcoStruxure™ Machine Expert. For help refer to Schneider Electric Software Installer User Guide available here: https://www.se.com/ww/en/download/document/EIO0000005500/ Update Modicon Controller M241 to the latest Firmware and perform reboot. For instructions refer to Modicon M241 Logic Controller, Programming Guide: https://www.se.com/ww/en/download/document/EIO0000003059/Vendor reference ↗
- Modicon Controller M251 Firmware version 5.4.13.12 delivered with EcoStruxure™ Machine Expert v2.5.0.1 includes a fix for this vulnerability and can be installed through Schneider Electric Software Installer available here: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER/ On the engineering workstation install v2.5.0.1 of EcoStruxure™ Machine Expert. For help refer to Schneider Electric Software Installer User Guide available here: https://www.se.com/ww/en/download/document/EIO0000005500/ Update Modicon Controller M251 to the latest Firmware and perform reboot. For instructions refer to Modicon M251 Logic Controller, Programming Guide: https://www.se.com/ww/en/download/document/EIO0000003089/Vendor reference ↗
- Modicon Controller M262 Firmware version 5.4.10.12 delivered with EcoStruxure™ Machine Expert v2.5 includes a fix for this vulnerability and can be installed through Schneider Electric Software Installer available here: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER/ On the engineering workstation install v2.5.0.1 of EcoStruxure™ Machine Expert. For help refer to Schneider Electric Software Installer User Guide available here: https://www.se.com/ww/en/download/document/EIO0000005500/ Update Modicon Controller M262 to the latest Firmware and perform reboot. For instructions refer to Modicon M262 Logic/Motion Controller, Programming Guide: https://www.se.com/ww/en/download/document/EIO0000003651/Vendor reference ↗
- If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from public internet or untrusted networks. • Filter ports and IP through the embedded firewall. • Use encrypted communication links. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide product specific hardening guidelinesVendor reference ↗
- ICSA-26-076-04OTCVSS 7.4 HighReleased 2026-03-10 · Updated 2026-03-17
Siemens SICAM SIAPP SDK
Vendor: SiemensProduct: SICAM SIAPP SDK
Critical infrastructure sectorsCritical ManufacturingThe SICAM SIAPP SDK contains multiple vulnerabilities that could allow an attacker to disrupt the customer-developed SIAPP or its simulation environment. Potential impacts include denial of service within the SIAPP, corruption of SIAPP data, or exploit the simulation environment. These vulnerabilities are only exploitable if the API is used improperly or hardening measures are not applied. Siemens has released a new version for SICAM SIAPP SDK and recommends to update to the latest version.
Named CVEsCVE-2026-25569CVE-2026-25570CVE-2026-25571CVE-2026-25572CVE-2026-25573CVE-2026-25605View CISA CSAF advisory ↗Mitigations- Update to V2.1.7 or later
- ICSA-26-076-03OTCVSS 7.2 HighReleased 2026-03-10 · Updated 2026-03-17
Schneider Electric EcoStruxure Data Center Expert
Vendor: Schneider ElectricProduct: EcoStruxure IT Data Center Expert
Critical infrastructure sectorsCommercial FacilitiesEnergyFood and AgricultureGovernment FacilitiesTransportation SystemsSchneider Electric is aware of a hard-coded credentials vulnerability in its EcoStruxure IT Data Center Expert (DCE) product that requires administrator credentials and enabling a feature (SOCKS Proxy) that is off by default. The EcoStruxure IT Data Center Expert product is a scalable monitoring software that collects, organizes, and distributes critical device information providing a comprehensive view of equipment. Failure to apply the remediation provided below may risk information disclosure, and remote compromise of the offer which could result in disruption of operations and access to system data.
Named CVEsCVE-2025-13957Weakness classesView CISA CSAF advisory ↗Mitigations- v9.1 of EcoStruxure IT Data Center Expert includes a fix for this vulnerability and is available for download here: https://www.se.com/en/product-range/61851-ecostruxure-it-data-center-expert/#software-and-firmwareVendor reference ↗
- If users choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Harden the DCE instance according to the cybersecurity best practices documented in the EcoStruxure IT Data Center Expert Security Handbook • Ensure the SOCKS Proxy is disabled as in the default configuration.Vendor reference ↗
- For more information see the associated Schneider Electric CPCERT security advisory SEVD-2026-069-05 Use of Hard-coded Credentials vulnerability in EcoStruxure IT Data Center Expert PDF Version https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-069-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-069-05.pdfVendor reference ↗
- For more information see the associated Schneider Electric CPCERT security advisory SEVD-2026-069-05 Use of Hard-coded Credentials vulnerability in EcoStruxure IT Data Center Expert CSAF Version https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-069-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-069-05.jsonVendor reference ↗
- ICSA-26-071-05OTCVSS 2.6 LowReleased 2026-03-10 · Updated 2026-03-12
Siemens Heliox EV Chargers
Vendor: SiemensProducts: Heliox Flex 180 kW EV Charging Station, Heliox Mobile DC 40 kW EV Charging Station
Critical infrastructure sectorsCritical ManufacturingHeliox EV Chargers listed below contain improper access control vulnerability that could allow an attacker to reach unauthorized services via the charging cable. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Named CVEsCVE-2025-27769Weakness classesView CISA CSAF advisory ↗Mitigations- Contact customer support for patch information via OTA update
- ICSA-26-071-04OTCVSS 9.6 CriticalReleased 2026-03-10 · Updated 2026-05-14
Siemens SIMATIC
Vendor: SiemensProducts: SIMATIC Drive Controller CPU 1504D TF (6ES7615-4DF10-0AB0), SIMATIC Drive Controller CPU 1507D TF (6ES7615-7DF10-0AB0), SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SJ01-0AB0), SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SK03-0AB0), SIMATIC ET 200SP CPU 1510SP-1 PN (6ES7510-1DJ01-0AB0), SIMATIC ET 200SP CPU 1510SP-1 PN (6ES7510-1DK03-0AB0), SIMATIC ET 200SP CPU 1512SP F-1 PN (6ES7512-1SK01-0AB0), SIMATIC ET 200SP CPU 1512SP F-1 PN (6ES7512-1SM03-0AB0), SIMATIC ET 200SP CPU 1512SP-1 PN (6ES7512-1DK01-0AB0), SIMATIC ET 200SP CPU 1512SP-1 PN (6ES7512-1DM03-0AB0), SIMATIC ET 200SP CPU 1514SP F-2 PN (6ES7514-2SN03-0AB0), SIMATIC ET 200SP CPU 1514SP-2 PN (6ES7514-2DN03-0AB0), SIMATIC ET 200SP CPU 1514SPT F-2 PN (6ES7514-2WN03-0AB0), SIMATIC ET 200SP CPU 1514SPT-2 PN (6ES7514-2VN03-0AB0), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V2 CPUs - Windows OS, SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V3 CPUs - Industrial OS, SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V3 CPUs - Windows OS, SIMATIC ET 200SP Open Controller CPU 1515SP PC3 V4 CPUs, SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK00-0AB0), SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK01-0AB0), SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK02-0AB0), SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AL03-0AB0), SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK00-0AB0), SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK01-0AB0), SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CL03-0AB0), SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK01-0AB0), SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK02-0AB0), SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FL03-0AB0), SIMATIC S7-1500 CPU 1511T-1 PN (6ES7511-1TK01-0AB0), SIMATIC S7-1500 CPU 1511T-1 PN (6ES7511-1TL03-0AB0), SIMATIC S7-1500 CPU 1511TF-1 PN (6ES7511-1UK01-0AB0), SIMATIC S7-1500 CPU 1511TF-1 PN (6ES7511-1UL03-0AB0), SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK00-0AB0), SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK01-0AB0), SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CM03-0AB0), SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL01-0AB0), SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL02-0AB0), SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AM03-0AB0), SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL01-0AB0), SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL02-0AB0), SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FM03-0AB0), SIMATIC S7-1500 CPU 1513pro F-2 PN (6ES7513-2GM03-0AB0), SIMATIC S7-1500 CPU 1513pro-2 PN (6ES7513-2PM03-0AB0), SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM01-0AB0), SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM02-0AB0), SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AN03-0AB0), SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM01-0AB0), SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM02-0AB0), SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FN03-0AB0), SIMATIC S7-1500 CPU 1515T-2 PN (6ES7515-2TM01-0AB0), SIMATIC S7-1500 CPU 1515T-2 PN (6ES7515-2TN03-0AB0), SIMATIC S7-1500 CPU 1515TF-2 PN (6ES7515-2UM01-0AB0), SIMATIC S7-1500 CPU 1515TF-2 PN (6ES7515-2UN03-0AB0), SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN01-0AB0), SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN02-0AB0), SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AP03-0AB0), SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN01-0AB0), SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN02-0AB0), SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FP03-0AB0), SIMATIC S7-1500 CPU 1516pro F-2 PN (6ES7516-2GP03-0AB0), SIMATIC S7-1500 CPU 1516pro-2 PN (6ES7516-2PP03-0AB0), SIMATIC S7-1500 CPU 1516T-3 PN (6ES7516-3TP10-0AB0), SIMATIC S7-1500 CPU 1516T-3 PN/DP (6ES7516-3TN00-0AB0), SIMATIC S7-1500 CPU 1516TF-3 PN (6ES7516-3UP10-0AB0), SIMATIC S7-1500 CPU 1516TF-3 PN/DP (6ES7516-3UN00-0AB0), SIMATIC S7-1500 CPU 1517-3 PN (6ES7517-3AQ10-0AB0), SIMATIC S7-1500 CPU 1517-3 PN/DP (6ES7517-3AP00-0AB0), SIMATIC S7-1500 CPU 1517F-3 PN (6ES7517-3FQ10-0AB0), SIMATIC S7-1500 CPU 1517F-3 PN/DP (6ES7517-3FP00-0AB0), SIMATIC S7-1500 CPU 1517F-3 PN/DP (6ES7517-3FP01-0AB0), SIMATIC S7-1500 CPU 1517T-3 PN (6ES7517-3TQ10-0AB0), SIMATIC S7-1500 CPU 1517T-3 PN/DP (6ES7517-3TP00-0AB0), SIMATIC S7-1500 CPU 1517TF-3 PN (6ES7517-3UQ10-0AB0), SIMATIC S7-1500 CPU 1517TF-3 PN/DP (6ES7517-3UP00-0AB0), SIMATIC S7-1500 CPU 1518-3 PN (6ES7518-3AT10-0AB0), SIMATIC S7-1500 CPU 1518-4 PN/DP (6ES7518-4AP00-0AB0), SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0), SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0), SIMATIC S7-1500 CPU 1518F-3 PN (6ES7518-3FT10-0AB0), SIMATIC S7-1500 CPU 1518F-4 PN/DP (6ES7518-4FP00-0AB0), SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0), SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0), SIMATIC S7-1500 CPU 1518T-3 PN (6ES7518-3TT10-0AB0), SIMATIC S7-1500 CPU 1518T-4 PN/DP (6ES7518-4TP00-0AB0), SIMATIC S7-1500 CPU 1518TF-3 PN (6ES7518-3UT10-0AB0), SIMATIC S7-1500 CPU 1518TF-4 PN/DP (6ES7518-4UP00-0AB0), SIMATIC S7-1500 CPU S7-1518-4 PN/DP ODK (6ES7518-4AP00-3AB0), SIMATIC S7-1500 CPU S7-1518F-4 PN/DP ODK (6ES7518-4FP00-3AB0), SIMATIC S7-1500 ET 200pro: CPU 1513PRO F-2 PN (6ES7513-2GL00-0AB0), SIMATIC S7-1500 ET 200pro: CPU 1513PRO-2 PN (6ES7513-2PL00-0AB0), SIMATIC S7-1500 ET 200pro: CPU 1516PRO F-2 PN (6ES7516-2GN00-0AB0), SIMATIC S7-1500 ET 200pro: CPU 1516PRO-2 PN (6ES7516-2PN00-0AB0), SIMATIC S7-1500 Software Controller CPU 1507S F V2, SIMATIC S7-1500 Software Controller CPU 1507S F V3, SIMATIC S7-1500 Software Controller CPU 1507S F V4, SIMATIC S7-1500 Software Controller CPU 1507S V2, SIMATIC S7-1500 Software Controller CPU 1507S V3, SIMATIC S7-1500 Software Controller CPU 1507S V4, SIMATIC S7-1500 Software Controller CPU 1508S F V2, SIMATIC S7-1500 Software Controller CPU 1508S F V3, SIMATIC S7-1500 Software Controller CPU 1508S F V4, SIMATIC S7-1500 Software Controller CPU 1508S T V3, SIMATIC S7-1500 Software Controller CPU 1508S TF V3, SIMATIC S7-1500 Software Controller CPU 1508S V2, SIMATIC S7-1500 Software Controller CPU 1508S V3, SIMATIC S7-1500 Software Controller CPU 1508S V4, SIMATIC S7-1500 Software Controller Linux V2, SIMATIC S7-1500 Software Controller Linux V3, SIMATIC S7-PLCSIM Advanced, SIPLUS ET 200SP CPU 1510SP F-1 PN (6AG1510-1SJ01-2AB0), SIPLUS ET 200SP CPU 1510SP F-1 PN RAIL (6AG2510-1SJ01-1AB0), SIPLUS ET 200SP CPU 1510SP-1 PN (6AG1510-1DJ01-2AB0), SIPLUS ET 200SP CPU 1510SP-1 PN (6AG1510-1DJ01-7AB0), SIPLUS ET 200SP CPU 1510SP-1 PN RAIL (6AG2510-1DJ01-1AB0), SIPLUS ET 200SP CPU 1510SP-1 PN RAIL (6AG2510-1DJ01-4AB0), SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK01-2AB0), SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK01-7AB0), SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL (6AG2512-1SK01-1AB0), SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL (6AG2512-1SK01-4AB0), SIPLUS ET 200SP CPU 1512SP-1 PN (6AG1512-1DK01-2AB0), SIPLUS ET 200SP CPU 1512SP-1 PN (6AG1512-1DK01-7AB0), SIPLUS ET 200SP CPU 1512SP-1 PN RAIL (6AG2512-1DK01-1AB0), SIPLUS ET 200SP CPU 1512SP-1 PN RAIL (6AG2512-1DK01-4AB0), SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK01-2AB0), SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK01-7AB0), SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK02-2AB0), SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK02-7AB0), SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL (6AG2511-1AK01-1AB0), SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL (6AG2511-1AK02-1AB0), SIPLUS S7-1500 CPU 1511-1 PN TX RAIL (6AG2511-1AK01-4AB0), SIPLUS S7-1500 CPU 1511-1 PN TX RAIL (6AG2511-1AK02-4AB0), SIPLUS S7-1500 CPU 1511F-1 PN (6AG1511-1FK01-2AB0), SIPLUS S7-1500 CPU 1511F-1 PN (6AG1511-1FK02-2AB0), SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL01-2AB0), SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL01-7AB0), SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL02-2AB0), SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL02-7AB0), SIPLUS S7-1500 CPU 1513F-1 PN (6AG1513-1FL01-2AB0), SIPLUS S7-1500 CPU 1513F-1 PN (6AG1513-1FL02-2AB0), SIPLUS S7-1500 CPU 1515F-2 PN (6AG1515-2FM01-2AB0), SIPLUS S7-1500 CPU 1515F-2 PN (6AG1515-2FM02-2AB0), SIPLUS S7-1500 CPU 1515F-2 PN RAIL (6AG2515-2FM02-4AB0), SIPLUS S7-1500 CPU 1515F-2 PN T2 RAIL (6AG2515-2FM01-2AB0), SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN01-2AB0), SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN01-7AB0), SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN02-2AB0), SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN02-7AB0), SIPLUS S7-1500 CPU 1516-3 PN/DP RAIL (6AG2516-3AN02-4AB0), SIPLUS S7-1500 CPU 1516-3 PN/DP TX RAIL (6AG2516-3AN01-4AB0), SIPLUS S7-1500 CPU 1516F-3 PN/DP (6AG1516-3FN01-2AB0), SIPLUS S7-1500 CPU 1516F-3 PN/DP (6AG1516-3FN02-2AB0), SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL (6AG2516-3FN02-2AB0), SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL (6AG2516-3FN02-4AB0), SIPLUS S7-1500 CPU 1518-4 PN/DP (6AG1518-4AP00-4AB0), SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0), SIPLUS S7-1500 CPU 1518F-4 PN/DP (6AG1518-4FP00-4AB0)
Critical infrastructure sectorsCritical ManufacturingSIMATIC S7-1500 devices contain a vulnerability that could allow an attacker to inject code by tricking a legitimate user into importing a specially crafted trace file in the web interface. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
Named CVEsCVE-2025-40943Weakness classesView CISA CSAF advisory ↗Mitigations- Disable the webserver if not required on the affected systems. Restrict the access to Port 80/tcp and 443/tcp to trusted IP address only
- Only upload trusted trace files
- Currently no fix is available
- Update to V2.9.9 or later versionVendor reference ↗
- Update to V3.1.6 or later versionVendor reference ↗
- Update to V4.1.2 or later versionVendor reference ↗
- ICSA-26-071-03OTCVSS 8.7 HighReleased 2026-03-10 · Updated 2026-03-12
Siemens SIDIS Prime
Vendor: SiemensProduct: SIDIS Prime
Critical infrastructure sectorsCritical ManufacturingSIDIS Prime before V4.0.800 is affected by multiple vulnerabilities in the components OpenSSL, SQLite, and several Node.js packages as described below. Siemens has released a new version of SIDIS Prime and recommends to update to the latest version.
Named CVEsCVE-2024-29857CVE-2024-30171CVE-2024-30172CVE-2024-41996CVE-2025-6965CVE-2025-7783CVE-2025-9230CVE-2025-9232CVE-2025-9670CVE-2025-12816CVE-2025-15284CVE-2025-58751CVE-2025-58752CVE-2025-58754CVE-2025-62522CVE-2025-64718CVE-2025-64756CVE-2025-66030CVE-2025-66031CVE-2025-66035CVE-2025-66412CVE-2025-69277CVE-2026-22610Weakness classesView CISA CSAF advisory ↗Mitigations- Update to V4.0.800 or later version
- ICSA-26-071-02OTCVSS 9.8 CriticalReleased 2026-03-10 · Updated 2026-05-14
Siemens RUGGEDCOM APE1808 Devices
Vendor: SiemensProduct: RUGGEDCOM APE1808
Critical infrastructure sectorsCritical ManufacturingEnergyTransportation SystemsFortinet has published information on vulnerabilities in FORTIOS. This advisory lists the related Siemens Industrial products. Siemens has released a new version for RUGGEDCOM APE1808 and recommends to update to the latest version.
Named CVEsView CISA CSAF advisory ↗Mitigations- Update Fortigate NGFW to V7.4.9 or later version. Contact customer support to receive patch and update information
- Update Fortigate NGFW to V7.4.10 or later version. Contact customer support to receive patch and update information
- Update Fortigate NGFW to V7.4.10 or later version with FSSO TS Agent version 5.0 build 0324 or later version. Contact customer support to receive patch and update information
- Update Fortigate NGFW to V7.4.11 or later version. Contact customer support to receive patch and update information
- ICSA-26-069-03OTCVSS 9.8 CriticalReleased 2026-03-10 · Updated 2026-03-26
Honeywell IQ4 Series BMS Controller (Update A)
Vendor: HoneywellProducts: IQ4E Firmware, IQ412 Firmware, IQ422 Firmware, IQ4NC Firmware, IQ41x Firmware
Critical infrastructure sectorsCommercial FacilitiesCritical ManufacturingGovernment FacilitiesHealthcare and Public HealthSuccessful exploitation of this vulnerability could allow an unauthorized attacker to access controller management settings, control components, disclose information, or cause a denial-of-service condition.
Named CVEsCVE-2026-3611Weakness classesView CISA CSAF advisory ↗Mitigations- Version 3.30, released June 2015, and later force users to install a user module upon the commissioning of the device. This user module enables authentication and other security features for the web interface. When updating previously commissioned devices to firmware versions 3.30 or later (current version is 4.3x), users are not forced to install a user module unless they have changed their device configuration files after updating the firmware version. Honeywell recommends that users check their firmware versions and ensure that a user module has been set up to enable device security features, even if they are running firmware version 3.30 or later.
- Honeywell recommends that users with affected products take the following steps:
- Apply product updates as available.
- Follow guidance in the product security manual to ensure isolation of network segments hosting building automation controllers.
- Ensure adequate security controls are in place between OT and IT segments.
- Disable unnecessary accounts and services.
- Restrict system access to authorized personnel only and follow a least privilege approach.
- Apply defense-in-depth strategies.
- Log and monitor network traffic for suspicious activity.
- For IQ4 Series controllers, ensure the latest available firmware version is utilized. The latest firmware may be obtained from a dealer or the Trend Partner Network https://partners.trendcontrols.com/signin (login required).Vendor reference ↗
- Follow the Security Best Practice for Trend Products included with product documentation. Additional copies may be obtained from a dealer or the Trend Partner Network https://partners.trendcontrols.com/signin (login required).Vendor reference ↗
- ICSA-26-069-02OTCVSS 9.8 CriticalReleased 2026-03-10
Lantronix EDS3000PS and EDS5000
Vendor: LantronixProducts: EDS3000PS, EDS5000
Critical infrastructure sectorsCommunicationsInformation TechnologyCritical ManufacturingSuccessful exploitation of these vulnerabilities could allow an attacker to bypass authentication and execute code with root-level privileges.
Named CVEsCVE-2025-67034CVE-2025-67035CVE-2025-67036CVE-2025-67037CVE-2025-67038CVE-2025-67039CVE-2025-70082CVE-2025-67041View CISA CSAF advisory ↗Mitigations- For vulnerabilities CVE-2025-67034, CVE-2025-67035, CVE-2025-67036, CVE-2025-67037, CVE-2025-67038 Lantronix recommends users upgrade to EDS5000 version 2.2.0.0R1. The patch can be found here: https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/2538438657/Latest+Firmware+for+the+EDS5000+series+EDS5008+EDS5016+EDS5032.Vendor reference ↗
- For vulnerabilities CVE-2025-67039, CVE-2025-70082, and CVE-2025-67041, Lantronix recommends users upgrade to EDS3000PS version 3.2.0.0R2. The patch can be found here: https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1349189633/Latest+Firmware+for+the+EDS3000PS+series.Vendor reference ↗
- ICSA-26-069-01OTCVSS 9.8 CriticalReleased 2026-03-10
Apeman Cameras
Vendor: ApemanProduct: ID71
Critical infrastructure sectorsCommercial FacilitiesSuccessful exploitation of these vulnerabilities could allow an attacker to take control of the device or view camera feeds.
Named CVEsCVE-2025-11126CVE-2025-11851CVE-2025-11852View CISA CSAF advisory ↗Mitigations- Apeman did not respond to CISAs request for coordination. Users are encouraged to reach out to Apeman for support https://apemans.com/pages/contactusVendor reference ↗
- ICSA-26-064-01OTCVSS 7.8 HighReleased 2026-03-05
Delta Electronics CNCSoft-G2
Vendor: Delta ElectronicsProduct: CNCSoft-G2
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could result in an attacker achieving remote code execution on the device.
Named CVEsCVE-2026-3094Weakness classesView CISA CSAF advisory ↗Mitigations- Delta Electronics recommends users update to Version 2.1.0.39, which has resolved this vulnerability. The update can be obtained from the Delta Electronics download center at https://downloadcenter.deltaww.com/en-US/DownloadCenter?v=1&q=cncsoft&sort_expr=cdate&sort_dir=DESC.Vendor reference ↗
- For more information, see the associated Delta Electronics security advisory Delta-PCSA-2026-00004 which can be downloaded in PDF format here: https://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2026-00004_CNCSoft-G2_File%20Parsing%20Out-Of-Bounds%20Write.pdfVendor reference ↗
- ICSA-26-062-08OTCVSS 9.4 CriticalReleased 2026-03-03
Everon OCPP Backends
Vendor: EveronProduct: api.everon.io
Critical infrastructure sectorsEnergyTransportation SystemsSuccessful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.
Named CVEsCVE-2026-26288CVE-2026-24696CVE-2026-20748CVE-2026-27027View CISA CSAF advisory ↗Mitigations- Everon has shut down their platform on December 1st, 2025.
- ICSA-26-062-07OTCVSS 9.4 CriticalReleased 2026-03-03
ePower epower.ie
Vendor: ePowerProduct: epower.ie
Critical infrastructure sectorsEnergyTransportation SystemsSuccessful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.
Named CVEsCVE-2026-22552CVE-2026-27778CVE-2026-24912CVE-2026-27770View CISA CSAF advisory ↗Mitigations- ePower did not respond to CISA's request for coordination. Contact ePower using their contact page here: https://www.epower.ie/support/ for more information.Vendor reference ↗
- ICSA-26-062-06OTCVSS 9.4 CriticalReleased 2026-03-03
Mobiliti e-mobi.hu
Vendor: MobilitiProduct: e-mobi.hu
Critical infrastructure sectorsEnergyTransportation SystemsSuccessful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.
Named CVEsCVE-2026-26051CVE-2026-20882CVE-2026-27764CVE-2026-27777View CISA CSAF advisory ↗Mitigations- Mobiliti did not respond to CISA's request for coordination. Contact Mobiliti using their contact page here: https://www.mobiliti.hu/emobilitas/ugyfeltamogatas/ugyfelszolgalat for more information.Vendor reference ↗
- ICSA-26-062-05OTCVSS 9.4 CriticalReleased 2026-03-03
Labkotec LID-3300IP
Vendor: LabkotecProducts: LID-3300IP, LID-3300IP Type 2
Critical infrastructure sectorsCommunicationsEnergySuccessful exploitation of this vulnerability could allow attackers to gain unauthorized control over system operations, leading to disruption of normal functionality and potential safety hazards.
Named CVEsCVE-2026-1775Weakness classesView CISA CSAF advisory ↗Mitigations- Labkotec reports that it is not possible to implement secure and encrypted network traffic on the LID-3300IP. For this reason, Labkotec recommends updating ice detectors to the LID-3300IP Type 2 model and installing the latest firmware version V2.40. It is also highly recommended to activate HTTPS for network traffic. The device type and software version can be verified in the web interface.
- Devices not connected to an Ethernet network are not susceptible to this attack. Ice detectors operating on secure internal networks that adhere to modern security standards, where only authorized devices and users have access, are protected against external threats.
- Labkotec recommends implementing the following additional security controls:
- Do not connect the device to the public Internet
- Follow good security practices
- Change Default Credentials
- Enable Secure Management Access
- Network Segmentation
- Implement Firewall and Access Controls
- Restrict Protocols
- Monitor and Alert
- Avoid Direct Internet Exposure
- Keep Firmware Updated
- Control Physical Access
- Maintain Inventory and Access Reviews
- Users can find more information in Labkotec's security advisory (https://labkotec.fi/wp-content/uploads/CA-000001-Cybersecurity-Advisory.pdf).Vendor reference ↗
- ICSA-26-062-04OTCVSS 8.8 HighReleased 2026-03-03
Portwell Engineering Toolkits
Vendor: PortwellProduct: Portwell Engineering Toolkits
Critical infrastructure sectorsCritical ManufacturingEnergySuccessful exploitation of this vulnerability could allow a local attacker to escalate privileges or cause a denial-of-service condition.
Named CVEsCVE-2026-3437Weakness classesView CISA CSAF advisory ↗Mitigations- Portwell has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of Portwell Engineering Toolkits are invited to contact Portwell customer support (https://portwell.com/support.php) for additional information.Vendor reference ↗
- ICSA-26-062-01OTCVSS 7.5 HighReleased 2026-03-03 · Updated 2026-05-07
Mitsubishi Electric MELSEC iQ-F Series EtherNet/IP module and Ethernet Module (Update A)
Vendor: Mitsubishi ElectricProducts: MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP, MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP
Critical infrastructure sectorsCommercial FacilitiesSuccessful exploitation of these vulnerabilities could allow a remote attacker to cause a denial-of-service condition on the affected products by continuously sending UDP packets to the products.
Named CVEsCVE-2026-1874CVE-2026-1875CVE-2026-1876View CISA CSAF advisory ↗Mitigations- Mitsubishi Electric is releasing fixed version 1.107 or later for Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP. Download the fixed version from the link "https://www.mitsubishielectric.com/fa/download/index.html" and install it. For the update procedure, refer to "9.2 Update Using the Engineering Tool Updating the firmware for the intelligent function module" in the MELSEC iQ-F FX5 User's Manual (Application) which can be downloaded from the link "https://www.mitsubishielectric.com/fa/download/index.html." For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-021_en.pdf."Vendor reference ↗
- Mitsubishi Electric is releasing fixed version 1.001 or later for Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP. Download the fixed version from the link "https://www.mitsubishielectric.com/fa/download/index.html" and install it. For the update procedure, refer to "9.2 Update Using the Engineering Tool Updating the firmware for the intelligent function module" in the MELSEC iQ-F FX5 User's Manual (Application) which can be downloaded from the link "https://www.mitsubishielectric.com/fa/download/index.html." For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-021_en.pdf".Vendor reference ↗
- For users who cannot immediately update the product, Mitsubishi Electric recommends using a firewall, virtual private network (VPN), etc. to prevent unauthorized access when internet access is required, to minimize the risk of exploiting this vulnerability.
- For users who cannot immediately update the product, Mitsubishi Electric recommends using the affected product within a LAN and blocking access from untrusted networks and hosts through firewalls, to minimize the risk of exploiting this vulnerability.
- For users who cannot immediately update the product, Mitsubishi Electric recommends using the IP filter function of the affected product to block access from untrusted hosts and minimize the risk of exploiting this vulnerability. For details on the IP filter function, refer to "13.1 IP Filter Function" in the MELSEC iQ-F FX5 User's Manual (Communication) which can be downloaded from the link "https://www.mitsubishielectric.com/fa/download/index.html."
- For users who cannot immediately update the product, Mitsubishi Electric recommends restricting physical access to the affected product, as well as to PCs and network devices to which it is connected, to minimize the risk of exploiting this vulnerability.
- For users who cannot immediately update the product, Mitsubishi Electric recommends installing anti-virus software on PCs that can access the affected product, to minimize the risk of exploiting this vulnerability.
- There are no plans to release a fixed version. Please take the mitigations.
- Mitsubishi Electric recommends using a firewall, virtual private network (VPN), etc. to prevent unauthorized access when internet access is required, to minimize the risk of exploiting this vulnerability.
- Mitsubishi Electric recommends using the affected product within a LAN and blocking access from untrusted networks and hosts through firewalls, to minimize the risk of exploiting this vulnerability.
- Mitsubishi Electric recommends using the IP filter function of the affected product to block access from untrusted hosts and minimize the risk of exploiting this vulnerability. For details on the IP filter function, refer to "13.1 IP Filter Function" in the MELSEC iQ-F FX5 User's Manual (Communication) which can be downloaded from the link "https://www.mitsubishielectric.com/fa/download/index.html."
- Mitsubishi Electric recommends restricting physical access to the affected product, as well as to PCs and network devices to which it is connected, to minimize the risk of exploiting this vulnerability.
- Mitsubishi Electric recommends installing anti-virus software on PCs that can access the affected product, to minimize the risk of exploiting this vulnerability.
- ICSA-26-076-01OTCVSS 9.8 CriticalReleased 2026-02-26 · Updated 2026-03-17
CODESYS in Festo Automation Suite
Vendors: FESTO, CODESYSProducts: Festo Automation Suite, CODESYS Development System
Critical infrastructure sectorsCritical ManufacturingStarting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled within the FAS installation. From version 2.8.0.138 onwards, customers are required to download and install Codesys independently. This change impacts the handling of security vulnerabilities (CVEs) related to Codesys. Any Codesys-related security issues must now be addressed by the customer through their separate Codesys installation. The FAS itself includes only the connector component, which is maintained and updated within the suite. Please ensure that Codesys is kept up to date independently to mitigate any potential security risks associated with the Codesys software.
Named CVEsCVE-2025-2595CVE-2010-5250CVE-2017-3735CVE-2018-0739CVE-2018-10612CVE-2018-20025CVE-2018-20026CVE-2019-13532CVE-2019-13538CVE-2019-13542CVE-2019-13548CVE-2019-18858CVE-2019-19789CVE-2019-5105CVE-2019-9008CVE-2019-9009CVE-2019-9010CVE-2019-9011CVE-2019-9012CVE-2019-9013CVE-2020-10245CVE-2020-12067CVE-2020-12068CVE-2020-12069CVE-2020-14509CVE-2020-14513CVE-2020-14515CVE-2020-14517CVE-2020-14519CVE-2020-15806CVE-2020-16233CVE-2020-7052CVE-2021-21863CVE-2021-21864CVE-2021-21865CVE-2021-21866CVE-2021-21867CVE-2021-21868CVE-2021-21869CVE-2021-29239CVE-2021-29240CVE-2021-29241CVE-2021-29242CVE-2021-30186CVE-2021-30187CVE-2021-30188CVE-2021-30190CVE-2021-30195CVE-2021-33485CVE-2021-33486CVE-2021-34593CVE-2021-34595CVE-2021-34596CVE-2021-36763CVE-2021-36764CVE-2021-36765CVE-2022-1965CVE-2022-1989CVE-2022-22508CVE-2022-22513CVE-2022-22514CVE-2022-22515CVE-2022-22516CVE-2022-22517CVE-2022-22519CVE-2022-30791CVE-2022-30792CVE-2022-31805CVE-2022-31806CVE-2022-32136CVE-2022-32137CVE-2022-32138CVE-2022-32139CVE-2022-32140CVE-2022-32141CVE-2022-32142CVE-2022-32143CVE-2022-4046CVE-2022-4048CVE-2022-4224CVE-2022-47378CVE-2022-47379CVE-2022-47380CVE-2022-47381CVE-2022-47383CVE-2022-47384CVE-2022-47385CVE-2022-47386CVE-2022-47387CVE-2022-47388CVE-2022-47389CVE-2022-47390CVE-2022-47391CVE-2022-47392CVE-2022-47393CVE-2023-3662CVE-2023-3663CVE-2023-3669CVE-2023-3670CVE-2023-37545CVE-2023-37546CVE-2023-37547CVE-2023-37548CVE-2023-37549CVE-2023-37550CVE-2023-37551CVE-2023-37552CVE-2023-37553CVE-2023-37554CVE-2023-37555CVE-2023-37556CVE-2023-37557CVE-2023-37558CVE-2023-37559CVE-2023-3935CVE-2023-49675CVE-2023-49676CVE-2023-6357CVE-2024-5000CVE-2024-8175CVE-2025-0694CVE-2025-1468CVE-2025-41658CVE-2025-41659CVE-2020-11023CVE-2022-47382Weakness classesCWE-425CWE-426CWE-119CWE-674CWE-284CWE-330CWE-923CWE-22CWE-79CWE-476CWE-121CWE-120CWE-732CWE-755CWE-668CWE-770CWE-327CWE-787CWE-640CWE-269CWE-916CWE-805CWE-20CWE-347CWE-326CWE-346CWE-401CWE-404CWE-502CWE-50CWE-345CWE-78CWE-306CWE-125CWE-75CWE-823CWE-82CWE-552CWE-822CWE-33CWE-12CWE-400CWE-523CWE-1188CWE-122CWE-194CWE-126CWE-427CWE-940CWE-307CWE-416CWE-13CWE-754CWE-203CWE-276View CISA CSAF advisory ↗Mitigations- Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.
- Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.
- ICSA-26-057-10OTCVSS 10 CriticalReleased 2026-02-26
Copeland XWEB and XWEB Pro
Vendor: CopelandProducts: XWEB 300D PRO, XWEB 500D PRO, XWEB 500B PRO
Critical infrastructure sectorsCommercial FacilitiesSuccessful exploitation of these vulnerabilities could allow an attacker to bypass authentication, cause a denial-of-service condition, cause memory corruption, and execute arbitrary code.
Named CVEsCVE-2026-25085CVE-2026-21718CVE-2026-24663CVE-2026-21389CVE-2026-25111CVE-2026-20742CVE-2026-24517CVE-2026-25195CVE-2026-20910CVE-2026-24689CVE-2026-25109CVE-2026-20902CVE-2026-24695CVE-2026-25105CVE-2026-24452CVE-2026-23702CVE-2026-25721CVE-2026-20764CVE-2026-25196CVE-2026-25037CVE-2026-22877CVE-2026-20797CVE-2026-3037View CISA CSAF advisory ↗Mitigations- Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.Vendor reference ↗
- Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.
- ICSA-26-057-08OTCVSS 9.4 CriticalReleased 2026-02-26
Mobility46 mobility46.se
Vendor: Mobility46Product: mobility46.se
Critical infrastructure sectorsEnergyTransportation SystemsSuccessful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.
Named CVEsCVE-2026-27028CVE-2026-26305CVE-2026-27647CVE-2026-22878View CISA CSAF advisory ↗Mitigations- Mobility46 did not respond to CISA's request for coordination. Contact Mobility46 using their contact page here: https://www.mobility46.se/en/contact-us for more information.Vendor reference ↗
- ICSA-26-057-07OTCVSS 9.4 CriticalReleased 2026-02-26
EV Energy ev.energy
Vendor: EV EnergyProduct: ev.energy
Critical infrastructure sectorsEnergyTransportation SystemsSuccessful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.
Named CVEsCVE-2026-27772CVE-2026-24445CVE-2026-26290CVE-2026-25774View CISA CSAF advisory ↗Mitigations- EV Energy did not respond to CISA's request for coordination. Contact EV Energy using their contact page here: https://www.ev.energy/en-us for more information.Vendor reference ↗
- ICSA-26-057-06OTCVSS 9.4 CriticalReleased 2026-02-26 · Updated 2026-05-14
SWTCH EV swtchenergy.com (Update A)
Vendor: SWTCH EVProduct: swtchenergy.com
Critical infrastructure sectorsEnergyTransportation SystemsSuccessful exploitation of these vulnerabilities could allow attackers to impersonate charging stations, hijack sessions, suppress or misroute legitimate traffic to cause large-scale denial-of-service, and manipulate data sent to the backend.
Named CVEsCVE-2026-27767CVE-2026-25113CVE-2026-25778CVE-2026-27773View CISA CSAF advisory ↗Mitigations- SWTCH Energy has applied configuration changes to enforce security checks for initial connections from untrusted chargers. All initially onboarded devices and newly established connections are subject to the additional scrutiny related to authentication, connection-control, and ingress-protection requirements.
- For some existing chargers in the field, full enforcement remains dependent on device-specific constraints, including legacy firmware limitations and SSL/TLS compatibility issues. Where technically supported, affected chargers will be upgraded to align fully with the updated security policy.
- SWTCH applies compensating controls to all connection attempts, including monitoring and targeted network-level restrictions such as IP-based access controls, to reduce exposure while upgrade or retirement activities are completed.
- Refer to the SWTCH Security portal for additional information here: https://swtchenergy.com/security/.Vendor reference ↗
- Contact SWTCH EV using their contact page for further assistance here: https://swtchenergy.com/contact/.Vendor reference ↗
- ICSA-26-057-05OTCVSS 9.4 CriticalReleased 2026-02-26
Chargemap chargemap.com
Vendor: ChargemapProduct: chargemap.com
Critical infrastructure sectorsEnergyTransportation SystemsSuccessful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.
Named CVEsCVE-2026-25851CVE-2026-20792CVE-2026-25711CVE-2026-20791View CISA CSAF advisory ↗Mitigations- Chargemap did not respond to CISA's request for coordination. Contact Chargemap using their contact page here: https://chargemap.com/en-us/support for more information.Vendor reference ↗
- ICSA-26-057-04OTCVSS 9.4 CriticalReleased 2026-02-26
EV2GO ev2go.io
Vendor: EV2GOProduct: ev2go.io
Critical infrastructure sectorsEnergyTransportation SystemsSuccessful exploitation of these vulnerabilities could allow attackers to impersonate charging stations, hijack sessions, suppress or misroute legitimate traffic to cause large-scale denial of service, and manipulate data sent to the backend.
Named CVEsCVE-2026-24731CVE-2026-25945CVE-2026-20895CVE-2026-22890View CISA CSAF advisory ↗Mitigations- EV2GO did not respond to CISA's request for coordination. Contact EV2GO using their contact page here: https://ev2go.io/ for more information.Vendor reference ↗
- ICSA-26-057-03OTCVSS 9.4 CriticalReleased 2026-02-26
CloudCharge cloudcharge.se
Vendor: CloudChargeProduct: cloudcharge.se
Critical infrastructure sectorsEnergyTransportation SystemsSuccessful exploitation of these vulnerabilities could allow attackers to impersonate charging stations, hijack sessions, suppress or misroute legitimate traffic to cause large-scale denial of service, and manipulate data sent to the backend.
Named CVEsCVE-2026-20781CVE-2026-25114CVE-2026-27652CVE-2026-20733View CISA CSAF advisory ↗Mitigations- CloudCharge did not respond to CISA's request for coordination. Contact CloudCharge using their contact page here: https://cloudcharge.tech/support/contact/ for more information.Vendor reference ↗
- ICSA-26-057-02OTCVSS 7.5 HighReleased 2026-02-26
Pelco, Inc. Sarix Pro 3 Series IP Cameras
Vendor: Pelco, Inc.Products: Sarix Professional IMP 3 Series, Sarix Professional IXP 3 Series, Sarix Professional IBP 3 Series, Sarix Professional IWP 3 Series
Critical infrastructure sectorsCommercial FacilitiesDefense Industrial BaseEnergyGovernment FacilitiesHealthcare and Public HealthTransportation SystemsSuccessful exploitation of this vulnerability could allow attackers to gain unauthorized access to sensitive device data, bypass surveillance controls, and expose facilities to privacy breaches, operational risks, and regulatory compliance issues.
Named CVEsCVE-2026-1241Weakness classesView CISA CSAF advisory ↗Mitigations- Pelco, Inc. recommends that all Sarix Professional 3 Series Camera users update their camera firmware to version 02.53 or later. Installing the latest firmware ensures your device receives the most up-to-date bug fixes and critical security enhancements.
- More information can be found by visiting Pelco, Inc's technical support page (https://www.pelco.com/support) for assistance.Vendor reference ↗
- ICSA-26-057-01OTCVSS 9.1 CriticalReleased 2026-02-26
Johnson Controls, Inc. Frick Controls Quantum HD
Vendor: Johnson Controls, Inc.Product: Frick Controls Quantum HD
Critical infrastructure sectorsFood and AgricultureSuccessful exploitation of these vulnerabilities can lead to pre-authentication remote code execution, information leak or denial of service.
Named CVEsCVE-2026-21654CVE-2026-21656CVE-2026-21657CVE-2026-21658CVE-2026-21659CVE-2026-21660View CISA CSAF advisory ↗Mitigations- The Frick Controls Quantum HD, versions 10.22 through 11, are legacy platforms that have reached end of support. Johnson Controls, Inc. recommends upgrading to the latest platform, Quantum HD Unity, version 12 or higher. The update procedure can be found here (https://frickcontrolsblob.file.core.windows.net/frickweb1/Quantum-HD-Unity/Quantum_HD_Unity_Software_Update_Procedure.pdf?sv=2018-03-28&si=frickweb1-174C1294FA7&sr=f&sig=us0dhk6IWmCvmDvBs02yJvC%2BjnzbxqZmb4QEpVVDkxY%3D).Vendor reference ↗
- After completing the upgrade to version 12, verify full compliance with the hardening guide and apply all recommended security configurations.
- For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-05 at https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories.Vendor reference ↗
- ICSA-26-132-04OTCVSS 5.3 MediumReleased 2026-02-24 · Updated 2026-05-12
ABB Automation Builder Gateway for Windows
Vendor: ABBProduct: Automation Builder
Critical infrastructure sectorsChemicalCritical ManufacturingEnergyWater and Wastewater SystemsABB became aware of severe vulnerability in the products versions listed as affected in the advisory. The Windows gateway is accessible remotely by default. Unauthenticated attackers can therefore search for PLCs, but the user management of the PLCs prevents the actual access to the PLCs – unless it is disabled
Named CVEsCVE-2024-41975Weakness classesView CISA CSAF advisory ↗Mitigations- If remote access is not required, check the "LocalAddress" setting in the [CmpGwCommDrvTcp] section of the Gateway's configuration file as follows (restart of gateway required in case of changes): [CmpGwCommDrvTcp] LocalAddress=127.0.0.1 ; allow access only from the local computer The gateway configuration file can be located at (example for Automation Builder 2.8): %ProgramFiles%\ABB\AB2.8\AutomationBuilder\GatewayPLC\Gateway.cfg Starting with Automation Builder version 2.9.0 the vulnerability is closed by setting the default for the gateway to local access. Automation Builder 2.9.0 is available for download from the related download site. https://www.abb.com/global/en/areas/motion/digital-tools/automation-builder/software-download
- Workarounds are specific measures that a user can take to help block an attack, for example, temporarily disabling the vulnerable feature may remove the exposure with well-known impact on functionality. ABB has tested the following workarounds. Although these workarounds will not correct the underlying vulnerability, they can help block known attack vectors. When a workaround reduces functionality, this is identified below as “Impact of workaround”. The vulnerability can be closed by enabling local access only. See chapter “Recommended immediate actions” for details.
- ICSA-26-132-03OTCVSS 8.3 HighReleased 2026-02-24 · Updated 2026-05-12
ABB AC500 V3 Multiple Vulnerabilities
Vendor: ABBProduct: AC500 V3
Critical infrastructure sectorsChemicalCritical ManufacturingEnergyWater and Wastewater SystemsABB became aware of severe vulnerability in the products versions listed as affected in the advisory. An update is available that resolves these vulnerabilities. An attacker who successfully exploited these vulnerabilities could bypass the user management and read visualization files (CVE-2025-2595), read and write certificates and keys (CVE-2025-41659) or cause a denial-of-service (DoS) (CVE-2025-41691).
Named CVEsCVE-2025-2595CVE-2025-41659CVE-2025-41691View CISA CSAF advisory ↗Mitigations- The problem is corrected in the following product versions: - AC500 V3 firmware version 3.9.0 ABB recommends that customers apply the update at earliest convenience. This firmware version is released for all AC500 V3 PLC types and available from Automation Builder 2.9.0. Automation Builder 2.9.0 is available for download from the related download site. https://www.abb.com/global/en/areas/motion/digital-tools/automation-builder/software-download
- Refer to section “General security recommendations” for further advise on how to keep your system secure.
- No workarounds are available
- ICSA-26-092-03OTCVSS 9.8 CriticalReleased 2026-02-24 · Updated 2026-04-02
Hitachi Energy Ellipse
Vendor: Hitachi EnergyProduct: Ellipse
Critical infrastructure sectorsCritical ManufacturingHitachi Energy is aware of a Jasper Report vulnerability that affects the Ellipse product versions mentioned in this document below. This vulnerability can be exploited to carry out remote code execution (RCE) attack on the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.
Named CVEsCVE-2025-10492Weakness classesView CISA CSAF advisory ↗Mitigations- Since the vulnerability exists in Jasper Report component that is external to Ellipse application, restrict the loading of external custom reports created by end users by allowing only trusted Jasper reports generated by the system administrator.
- ICSA-26-062-03OTCVSS 7.5 HighReleased 2026-02-24 · Updated 2026-03-03
Hitachi Energy RTU500 Product
Vendor: Hitachi EnergyProduct: RTU500 series CMU Firmware
Critical infrastructure sectorsCritical ManufacturingHitachi Energy is aware of vulnerabilities that affect RTU500 product versions listed in this document. Successful exploitation of these vulnerabilities can result in the exposure of low-value user management information and device outage. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.
Named CVEsCVE-2026-1772CVE-2026-1773CVE-2024-8176CVE-2025-59375View CISA CSAF advisory ↗Mitigations- Update to CMU Firmware version 12.7.8
- Follow general mitigation factors/workarounds
- Update to CMU Firmware version 13.7.8 or latest
- Update to CMU Firmware version 13.8.2
- ICSA-26-062-02OTCVSS 6.8 MediumReleased 2026-02-24 · Updated 2026-03-03
Hitachi Energy Relion REB500 Product
Vendor: Hitachi EnergyProduct: Relion REB500
Critical infrastructure sectorsEnergyHitachi Energy is aware of vulnerabilities that affect the Relion REB500 product versions listed in this document. Authenticated users with certain roles can exploit the vulnerabilities to access and modify the directory contents they are not authorized to do so. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.
Named CVEsCVE-2026-2459CVE-2026-2460Weakness classesView CISA CSAF advisory ↗Mitigations- Hitachi Energy recommends that users update to version 8.3.3.1.
- For CVE-2026-2459, as a mitigation strategy, users may also disable the Installer role and enable it only during the firmware update process.
- Update to version 8.3.3.1
- Apply general mitigation factors
- ICSA-26-055-03OTCVSS 9.3 CriticalReleased 2026-02-24 · Updated 2026-07-02
Gardyn Home Kit (Update B)
Vendor: GardynProducts: Gardyn Home Firmware, Gardyn Studio Firmware, Gardyn Mobile Application, Gardyn Cloud API
Critical infrastructure sectorsFood and AgricultureSuccessful exploitation of these vulnerabilities could allow unauthenticated users to access and control edge devices, access cloud-based devices and user information without authentication, and pivot to other edge devices managed in the Gardyn cloud environment.
Named CVEsCVE-2025-29628CVE-2025-29629CVE-2025-29631CVE-2025-1242CVE-2025-10681CVE-2026-28766CVE-2026-25197CVE-2026-32646CVE-2026-28767CVE-2026-32662View CISA CSAF advisory ↗Mitigations- Gardyn states that the relevant fixes are included in the latest version of the Gardyn mobile application. Users are required to run a supported version of the Gardyn App on their phone in order to access Gardyn services and devices.
- The current versions of the Gardyn App and the Gardyn Home firmware can be checked in the Gardyn App.
- Gardyn requests that users ensure their devices have Internet connectivity in order to automatically download needed firmware updates. Unconnected devices will automatically update when configured with a working Internet connection. Gardyn also recommends that users update their mobile application to the most recent version.
- Further information on Gardyn security can be found here: https://mygardyn.com/security/Vendor reference ↗
- Further customer support can be obtained from Gardyn at: support@mygardyn.comVendor reference ↗
- ICSA-26-055-01OTCVSS 9.8 CriticalReleased 2026-02-24
InSAT MasterSCADA BUK-TS
Vendor: InSATProduct: MasterSCADA BUK-TS
Critical infrastructure sectorsCritical ManufacturingEnergyWater and Wastewater SystemSuccessful exploitation of these vulnerabilities may allow remote code execution.
Named CVEsCVE-2026-21410CVE-2026-22553View CISA CSAF advisory ↗Mitigations- InSAT has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of the affected products are encouraged to contact info@insat.ru or scada@insat.ru for additional information.Vendor reference ↗
- ICSA-26-050-04OTCVSS 8.2 HighReleased 2026-02-19
Welker OdorEyes EcoSystem Pulse Bypass System with XL4 Controller
Vendor: WelkerProduct: OdorEyes EcoSystem Pulse Bypass System with XL4 Controller
Critical infrastructure sectorsChemicalCritical ManufacturingEnergyFood and AgricultureSuccessful exploitation of this vulnerability could result in an over- or under-odorization event.
Named CVEsCVE-2026-24790Weakness classesView CISA CSAF advisory ↗Mitigations- Welker did not respond to CISA's attempts at coordination. Users of Welker OdorEyes devices are encouraged to contact Welker and keep their systems up to date.Vendor reference ↗
- ICSA-26-050-03OTCVSS 9.8 CriticalReleased 2026-02-19
Jinan USR IOT Technology Limited (PUSR) USR-W610
Vendor: Jinan USR IOT Technology Limited (PUSR)Product: USR-W610
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of these vulnerabilities could result in authentication being disabled, a denial-of-service condition, or an attacker stealing valid user credentials, including administrator credentials.
Named CVEsCVE-2026-25715CVE-2026-24455CVE-2026-26049CVE-2026-26048View CISA CSAF advisory ↗Mitigations- Jinan USR IOT Technology Limited (PUSR) has stated that the product is end-of-life, and there are no plans to patch. Users of PUSR USR-W610 devices are encouraged to contact PUSR and keep their systems up to date.Vendor reference ↗
- ICSA-26-050-02OTCVSS 8.6 HighReleased 2026-02-19
Valmet DNA Engineering Web Tools
Vendor: ValmetProduct: Valmet DNA Engineering Web Tools
Critical infrastructure sectorsCritical ManufacturingEnergySuccessful exploitation of this vulnerability could allow an unauthenticated attacker to manipulate the web maintenance services URL to achieve arbitrary file read access.
Named CVEsCVE-2025-15577Weakness classesView CISA CSAF advisory ↗Mitigations- Valmet has issued a fix for the reported vulnerability. Valmet recommends users reach out directly to their automation customer service group to obtain assistance with the fix: https://www.valmet.com/contact/.Vendor reference ↗
- For additional information, refer to Valmet's security advisory regarding this issue: https://www.valmet.com/company/innovation/advisories/CVE-2025-15577/.Vendor reference ↗
- ICSA-26-050-01OTCVSS 8.1 HighReleased 2026-02-19
EnOcean SmartServer IoT
Vendor: EnOcean Edge IncProduct: SmartServer IoT
Critical infrastructure sectorsInformation TechnologySuccessful exploitation of these vulnerabilities could allow an attacker to remotely execute arbitrary code and bypass ASLR.
Named CVEsCVE-2026-20761CVE-2026-22885View CISA CSAF advisory ↗Mitigations- EnOcean recommends users update the SmartServer platform software to SmartServer 4.6 Update 2 (v4.60.023) or a later release at https://enoceanwiki.atlassian.net/wiki/spaces/DrftSSIoT/pages/1475410/SmartServer+IoT+Release+Notes#Current-Stable-Release.Vendor reference ↗
- For additional mitigations and workarounds, refer to EnOcean's hardening guide at https://enoceanwiki.atlassian.net/wiki/spaces/IEC/pages/288063529/Enhancing+Security.Vendor reference ↗
- ICSA-26-141-03OTCVSS 9.8 CriticalReleased 2026-02-18 · Updated 2026-05-21
ABB B&R Automation Studio
Vendor: ABBProduct: B&R Automation Studio
Critical infrastructure sectorsEnergyABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that replaces an outdated third-party component. Although no successful exploitation was observed during testing of the affected B&R products, the identified vulnerabilities could present potential attack vectors that might enable unauthorized access, data exposure, or remote code execution.
Named CVEsCVE-2025-6965CVE-2025-3277CVE-2023-7104CVE-2022-35737CVE-2020-15358CVE-2020-13632CVE-2020-13631CVE-2020-13630CVE-2020-13435CVE-2020-13434CVE-2020-11656CVE-2020-11655CVE-2019-19646CVE-2019-19645CVE-2019-8457CVE-2018-20506CVE-2018-20505CVE-2018-20346CVE-2018-8740CVE-2017-10989CVE-2016-6153CVE-2015-6607CVE-2015-5895CVE-2015-3717CVE-2015-3416Weakness classesView CISA CSAF advisory ↗Mitigations- The problem is corrected in the following product versions: B&R Automation Studio 6.5 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.
- Refer to section “General security recommendations” for advice on how to keep your system secure.
- ICSA-26-048-04OTCVSS 9.8 CriticalReleased 2026-02-17 · Updated 2026-03-12
Honeywell HIB2PI CCTV Camera (Update B)
Vendor: HoneywellProduct: I-HIB2PI-UL
Critical infrastructure sectorsCommercial FacilitiesSuccessful exploitation of this vulnerability could lead to account takeover and unauthorized access to camera feeds.
Named CVEsCVE-2026-1670Weakness classesView CISA CSAF advisory ↗Mitigations- The affected product has been discontinued since April 2025. Honeywell recommends users contact Honeywell customer service and technical support at https://www.honeywell.com/us/en/contact/support for patch information.Vendor reference ↗
- Honeywell recommends that users follow the guidance in product manuals and configure devices in a protected IT environment, behind a firewall that is not accessible from untrusted networks. Users are advised to update to the current version through Honeywell customer service and technical support at https://www.honeywell.com/us/en/contact/support.Vendor reference ↗
- ICSA-26-048-03OTCVSS 7.8 HighReleased 2026-02-17
GE Vernova Enervista UR Setup
Vendor: GE VernovaProduct: Enervista UR Setup
Critical infrastructure sectorsCritical ManufacturingEnergyWater and Wastewater SystemsSuccessful exploitation of these vulnerabilities may allow code execution with elevated privileges.
Named CVEsCVE-2026-1762CVE-2026-1763View CISA CSAF advisory ↗Mitigations- GE Vernova recommends affected users to use patched versions of Enervista UR Setup: Versions 8.70 or later (https://www.gevernova.com/grid-solutions/resources?prod=urfamily&type=7).Vendor reference ↗
- ICSA-26-048-02OTCVSS 7.8 HighReleased 2026-02-17
Delta Electronics ASDA-Soft
Vendor: Delta ElectronicsProduct: ASDA-Soft
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability may allow an attacker to write arbitrary data beyond the bounds of a stack-allocated buffer, leading to the corruption of a structured exception handler (SEH).
Named CVEsCVE-2026-1361Weakness classesView CISA CSAF advisory ↗Mitigations- Delta has fixed this vulnerability and released a new version v7.2.2.0 at Delta Download Center (https://downloadcenter.deltaww.com/en-US/DownloadCenter?v=1&q=asda-soft&sort_expr=cdate&sort_dir=DESC).Vendor reference ↗
- For more information, see Delta Electronics advisory Delta-PCSA-2026-00003 at https://www.deltaww.com/en-US/service-support/product-cybersecurity/advisoryVendor reference ↗
- Delta Electronics provides the following general recommendations: Do not click on untrusted internet links or open unsolicited attachments in emails. Avoid exposing control systems and equipment to the Internet. Place control system networks and remote devices behind firewalls, and isolate them from the business network. When remote access is required, use a secure access method, such as a virtual private network (VPN).
- If you have any product-related support concerns, contact Delta via the portal page(https://www.deltaww.com/en-US/service-support/contact-us?type=1) for any information or materials you may require.Vendor reference ↗
- ICSA-26-043-10OTCVSS 9.8 CriticalReleased 2026-02-12
Airleader Master
Vendor: Airleader GmbHProduct: Airleader Master
Critical infrastructure sectorsChemicalCritical ManufacturingEnergyFood and AgricultureHealthcare and Public HealthTransportation SystemsWater and Wastewater SystemsSuccessful exploitation of this vulnerability could allow an attacker to obtain remote code execution.
Named CVEsCVE-2026-1358Weakness classesView CISA CSAF advisory ↗Mitigations- Airleader recommends that users upgrade Airleader Master to version 6.386 or later.
- Users of Airleader Master are encouraged to reach out to Airleader via email or submit a web form for more information and mitigation assistance.Vendor reference ↗
- ICSMA-26-041-01OTCVSS 5.5 MediumReleased 2026-02-10
ZOLL ePCR IOS Mobile Application
Vendor: ZOLLProduct: ePCR IOS Mobile Application
Critical infrastructure sectorsHealthcare and Public HealthSuccessful exploitation of this vulnerability could allow an attacker to gain unauthorized access to protected health information (PHI) or device telemetry.
Named CVEsCVE-2025-12699Weakness classesView CISA CSAF advisory ↗Mitigations- ZOLL ePCR IOS application was decommissioned in May 2025. ZOLL has no current plans to provide a replacement application. If users have questions or concerns, they are encouraged to reach out directly to ZOLL Support. https://www.zolldata.com/contact-us.Vendor reference ↗
- ICSA-26-076-02OTCVSS 9.8 CriticalReleased 2026-02-10 · Updated 2026-03-17
Schneider Electric SCADAPack and RemoteConnect
Vendor: Schneider ElectricProducts: SCADAPack™, SCADAPack™ firmware, RemoteConnect
Critical infrastructure sectorsEnergySchneider Electric is aware of a vulnerability in its SCADAPack™ x70 RTU products. The SCADAPack™ 47xi, SCADAPack™ 47x and SCADAPack™ 57x product are Remote Terminal Units that provide communication capabilities for remote monitoring and control. Failure to apply the remediations provided below may risk unauthorized access to your RTU, which could result in the possibility of denial of service and loss of confidentiality, integrity of the controller.
Named CVEsCVE-2026-0667Weakness classesView CISA CSAF advisory ↗Mitigations- Version R3.4.2 (Firmware version 9.12.2) of SCADAPack™ 47x and SCADAPack™ 47xi includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/download/document/RemoteConnect/Vendor reference ↗
- Version R3.4.2 of RemoteConnect includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/download/document/RemoteConnect/Vendor reference ↗
- If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: Follow the information according to SCADAPack™ Security Guidelines in section 8.3 Secured Communication. Also, apply the following standard practices to reduce the risk of exploit: • Setup network segmentation and implement the RTU firewall service to block all unauthorized access to services • Disable the logic debug service.Vendor reference ↗
- Follow the information according to SCADAPack™ Security Guidelines in section 8.3 Secured Communication. Also, apply the following standard practices to reduce the risk of exploit • Setup network segmentation and implement the RTU firewall service to block all unauthorized access to services. • Disable the logic debug service.Vendor reference ↗
- ICSA-26-055-02OTCVSS 7.3 HighReleased 2026-02-10 · Updated 2026-02-24
Schneider Electric EcoStruxure Building Operation Workstation
Vendor: Schneider ElectricProducts: EcoStruxure Building Operation Workstation, EcoStruxure Building Operation WebStation
Critical infrastructure sectorsCommercial FacilitiesEnergyGovernment FacilitiesHealthcare and Public HealthInformation TechnologyTransportation SystemsFinancial ServicesDefense Industrial BaseCritical ManufacturingSchneider Electric is aware of a vulnerability in EcoStruxure Building Operation Workstation and EcoStruxure Building Operation WebStation. [EcoStruxure Building Operation (EBO)](https://www.se.com/ww/en/product-range/62111-ecostruxure-building-operation-software/#overview) is an open and scalable software platform providing insight, control and management of multiple building systems and devices in one mobile-enabled convenient view. It delivers valuable data for decision-making to improve energy management and increase efficiency for better building performance and comfort, reduced carbon, and more sustainable building environments. Failure to apply the remediations below may risk exposure of local files or denial of service, which could result in data breaches, and operational disruptions.
Named CVEsCVE-2026-1227CVE-2026-1226View CISA CSAF advisory ↗Mitigations- The following versions of EcoStruxure Building Operation Workstation and EcoStruxure Building Operation WebStation include a fix for CVE-2026-1227: • 7.0.3.2000 (CP1) Step 1: Navigate to this link: https://www.se.com/myschneider/documentsDownloadCenter/detail?id=EBO-Patch-v7-0 Step 2: Download 'EcoStruxure Building Operation Patch v7.0' Step 3: Follow the installation instructions provided in the accompanying readme file. Additionally, ensure you are following the [EBO hardening guidelines](https://ecostruxure-building-help.se.com/bms/Topics/show.castle?id=14923&productversion=7.1&locale=en-US).Vendor reference ↗
- The following versions of EcoStruxure Building Operation Workstation and EcoStruxure Building Operation WebStation includes a fix for CVE-2026-1227: • 6.0.4.14001 (CP10) Step 1: Locate the appropriate version for your system here: https://www.se.com/myschneider/documentsDownloadCenter/detail?id=EBO-Patch-v6-0 Step 2: Download ‘EcoStruxure Building Operation Patch v6.0‘ Step 3: Follow the installation instructions provided in the accompanying readme file. Additionally, ensure you are following the [EBO hardening guidelines](https://ecostruxure-building-help.se.com/bms/Topics/show.castle?id=14923&productversion=7.1&locale=en-US).Vendor reference ↗
- If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Implement strong access controls to limit system access to authorized personnel. • Use multi factor authentication if using EBO version 7.0 or later. • Use firewalls to segregate networks and protect the building management system. • Regularly monitor system activity. • Ensure you are following [EBO hardening guidelines](https://ecostruxure-building-help.se.com/bms/Topics/show.castle?id=14923&productversion=7.1&locale=en-US).Vendor reference ↗
- For more information see the associated Schneider Electric security advisory SEVD-2026-041-02, titled ‘Multiple Vulnerabilities on EcoStruxure Building Operation Workstation and EcoStruxure Building Operation WebStation‘. • PDF Version: [https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-041-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-041-02.pdf](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-041-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-041-02.pdf) • CSAF Version: [https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-041-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-041-02.json](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-041-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-041-02.json).Vendor reference ↗
- The following versions of EcoStruxure Building Operation Workstation and EcoStruxure Building Operation WebStation include a fix for CVE-2026-1226: • 7.0.2 Step 1: Navigate to this link: https://www.se.com/myschneider/documentsDownloadCenter/detail?id=EBO-Patch-v7-0 Step 2: Download 'EcoStruxure Building Operation Patch v7.0' Step 3: Follow the installation instructions provided in the accompanying readme file. Additionally, ensure you are following the [EBO hardening guidelines](https://ecostruxure-building-help.se.com/bms/Topics/show.castle?id=14923&productversion=7.1&locale=en-US).Vendor reference ↗
- The following versions of EcoStruxure Building Operation Workstation and EcoStruxure Building Operation WebStation includes a fix for CVE-2026-1226: • 6.0.4.7000 (CP5) Step 1: Locate the appropriate version for your system here: https://www.se.com/myschneider/documentsDownloadCenter/detail?id=EBO-Patch-v6-0 Step 2: Download ‘EcoStruxure Building Operation Patch v6.0‘ Step 3: Follow the installation instructions provided in the accompanying readme file. Additionally, ensure you are following the [EBO hardening guidelines](https://ecostruxure-building-help.se.com/bms/Topics/show.castle?id=14923&productversion=7.1&locale=en-US).Vendor reference ↗
- For more information see the associated Schneider Electric security advisory SEVD-2026-041-02, titled "Multiple Vulnerabilities on EcoStruxure Building Operation Workstation and EcoStruxure Building Operation WebStation". • PDF Version: [https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-041-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-041-02.pdf](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-041-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-041-02.pdf) • CSAF Version: [https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-041-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-041-02.json](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-041-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-041-02.json).Vendor reference ↗
- ICSA-26-048-01OTCVSS 7.8 HighReleased 2026-02-10 · Updated 2026-02-17
Siemens Simcenter Femap and Nastran
Vendor: SiemensProducts: Simcenter Femap, Simcenter Nastran
Critical infrastructure sectorsCritical ManufacturingSiemens Simcenter Femap and Nastran is affected by multiple file parsing vulnerabilities that could be triggered when the application reads files in NDB and XDB formats. If a user is tricked to open a malicious file with any of the affected products, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Named CVEsCVE-2026-23715CVE-2026-23716CVE-2026-23717CVE-2026-23718CVE-2026-23719CVE-2026-23720View CISA CSAF advisory ↗Mitigations- Do not open untrusted XDB files in affected applications
- Update to V2512 or later versionVendor reference ↗
- Do not open untrusted NDB files in affected applications
- ICSA-26-043-08OTCVSS 7.8 HighReleased 2026-02-10 · Updated 2026-03-12
Siemens NX
Vendor: SiemensProducts: NX, NX (Managed Mode)
Critical infrastructure sectorsCritical ManufacturingSiemens NX is affected by missing data validation vulnerability that could allow an attacker with local access on a compromised system to interfere with internal data during the PDF export process that could potentially lead to arbitrary code execution. Siemens has released a new version of NX which resolves the data tampering vulnerability.
Named CVEsCVE-2026-22923Weakness classesView CISA CSAF advisory ↗Mitigations- Prioritize strong overall system hygiene to prevent initial system infection which includes maintaining fully patched systems, robust endpoint security, and continuous monitoring for signs of compromise
- Update to V2512 or later versionVendor reference ↗
- ICSA-26-043-07OTCVSS 6.3 MediumReleased 2026-02-10 · Updated 2026-02-12
Siemens Siveillance Video Management Servers
Vendor: SiemensProducts: Siveillance Video V2022 R3, Siveillance Video V2023 R1, Siveillance Video V2023 R2, Siveillance Video V2023 R3, Siveillance Video V2024 R1, Siveillance Video V2025
Critical infrastructure sectorsCritical ManufacturingThe Webhooks implementation of Siveillance Video Management Servers contains a vulnerability that could allow an authenticated remote attacker with read-only privileges to achieve full access to Webhooks API. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Named CVEsCVE-2025-0836Weakness classesView CISA CSAF advisory ↗Mitigations- If, for any reason it is not possible to install the latest patch, we recommend auditing your role security settings and consider everyone with read-only access to the Management Server as having a full access to Webhooks configuration.
- Update to V23.1 HotfixRev18 or later versionVendor reference ↗
- Update to V23.2 HotfixRev18 or later versionVendor reference ↗
- Update to V23.3 HotfixRev23 or later versionVendor reference ↗
- Update to V24.1 HotfixRev14 or later versionVendor reference ↗
- Update to V25.1 HotfixRev8 or later versionVendor reference ↗
- ICSA-26-043-05OTCVSS 7.8 HighReleased 2026-02-10 · Updated 2026-02-12
Siemens Solid Edge
Vendor: SiemensProduct: Solid Edge
Critical infrastructure sectorsCritical ManufacturingSolid Edge uses PS/IGES Parasolid Translator Component that contains an out of bounds read that could be triggered when the application reads files in IGS file formats. If a user is tricked to open a malicious file with any of the affected products, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for Solid Edge and recommends to update to the latest version.
Named CVEsCVE-2025-40936Weakness classesView CISA CSAF advisory ↗Mitigations- Update to V226.00 Update 03 or later versionVendor reference ↗
- ICSA-26-043-04OTCVSS 8.8 HighReleased 2026-02-10 · Updated 2026-02-12
Siemens Desigo CC Product Family and SENTRON Powermanager
Vendor: SiemensProducts: Desigo CC family V6, Desigo CC family V7, Desigo CC family V8, Desigo CC family V9, SENTRON Powermanager V6, SENTRON Powermanager V7, SENTRON Powermanager V8, SENTRON Powermanager V9
Critical infrastructure sectorsCritical ManufacturingVersions V6.0 through V8 QU1 of the Desigo CC product family (Desigo CC, Desigo CC Compact, Desigo CC Connect, Cerberus DMS), as well as the Desigo CC-based SENTRON Powermanager, are affected by a vulnerability in the underlying third-party component WIBU Systems CodeMeter Runtime. Successful exploitation of this vulnerability could lead to code execution in the context of the current process. Siemens has released instructions how to update the CodeMeter Runtime component and recommends to apply the update on affected systems.
Named CVEsCVE-2023-38545Weakness classesView CISA CSAF advisory ↗Mitigations- Update to V8.0 QU2 or later versionVendor reference ↗
- Apply patch as documented in section 'Additional Information'
- ICSA-26-043-02OTCVSS 7.6 HighReleased 2026-02-10 · Updated 2026-02-12
Siemens Polarion
Vendor: SiemensProducts: Polarion V2404, Polarion V2410
Critical infrastructure sectorsEnergyCritical ManufacturingPolarion before V2506 contains a vulnerability that could allow authenticated remote attackers to conduct cross-site scripting attacks. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Named CVEsCVE-2025-40587Weakness classesView CISA CSAF advisory ↗Mitigations- Update to V2404.5 or later versionVendor reference ↗
- Update to V2410.2 or later versionVendor reference ↗
- ICSA-26-043-01OTCVSS 7.8 HighReleased 2026-02-10 · Updated 2026-04-16
Siemens SINEC NMS
Vendor: SiemensProducts: SINEC NMS, User Management Component (UMC)
Critical infrastructure sectorsInformation TechnologyEnergyCritical ManufacturingMultiple Siemens products are affected by two local privilege escalation vulnerabilities which could allow an low privileged attacker to load malicious DLLs, potentially leading to arbitrary code execution with elevated privileges. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Named CVEsCVE-2026-25655CVE-2026-25656Weakness classesView CISA CSAF advisory ↗Mitigations- Update to V4.0 SP2 or later versionVendor reference ↗
- Update to V2.15.2.1 or later versionVendor reference ↗
- Update to V4.0 SP3 or later versionVendor reference ↗
- ICSA-26-041-04OTCVSS 6.5 MediumReleased 2026-02-10
AVEVA PI to CONNECT Agent
Vendor: AVEVAProduct: PI to CONNECT Agent
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could result in an unauthorized access to the proxy server.
Named CVEsCVE-2026-1495Weakness classesView CISA CSAF advisory ↗Mitigations- AVEVA recommends that organizations evaluate the impact of this vulnerability based on their operational environment, architecture, and product implementation.
- Users of affected product versions should apply security updates to mitigate the risk of proxy details exposure in newly generated PI to CONNECT Agent event logs.
- Users who have used affected product versions, should review existing PI to CONNECT Agent event logs (live/backups/copies) for exposed proxy connection details and consider purging the sensitive data from logs and/or configuring new credentials for access to the proxy service.
- The following general defensive measures are recommended:
- Remove use of plain text passwords in proxy URLs. Alternatively, if passwords are required by the proxy, then use least-privilege credentials.
- Ensure only trusted users are given Event Log Reader (S-1-5-32-573) privileges on hosts where PI to CONNECT is installed.
- Review existing PI to CONNECT event logs (live/backups/copies) for exposed proxy connection details and consider purging the sensitive data from logs and/or configuring new credentials for access to the proxy service.
- All affected versions can be fixed by upgrading to PI to CONNECT Agent v2.5.2790 or higher. The latestversion of the agent can be downloaded from the CONNECT Data Services Portal here: https://datahub.connect.aveva.com/.Vendor reference ↗
- For additional information please refer to AVEVA-2026-003 https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-003.pdf.Vendor reference ↗
- ICSA-26-041-03OTCVSS 7.5 HighReleased 2026-02-10
AVEVA PI Data Archive
Vendor: AVEVAProduct: PI Data Archive PI Server
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could result in a denial-of-service condition.
Named CVEsCVE-2026-1507Weakness classesView CISA CSAF advisory ↗Mitigations- AVEVA recommends that organizations evaluate the impact of this vulnerability based on their operational environment, architecture, and product implementation. Users of affected product versions should apply security updates to mitigate the risk of exploit.
- All impacted versions of PI Data Archive can be fixed by upgrading to PI Server 2024 R2 or later available here: https://softwaresupportsp.aveva.com/en-US/downloads/products/details/8c9b0e8c-eb68-481f-b420-c87a253a4172.Vendor reference ↗
- PI Data Archive delivered by PI Server 2018 SP3 Patch 7 and prior can be fixed by upgrading to PI Server 2018 SP3 Patch 8 or higher available here: https://softwaresupportsp.aveva.com/en-US/downloads/products/details/79492560-7e4c-4800-8bd7-40cce61a17d2.Vendor reference ↗
- The following general defensive measures are recommended:
- Monitor liveness of services listed in your installation's "\PI\adm\pisrvstart.bat".
- Set the PI Data Archive Subsystem services to automatically restart.
- PI Data Archive nodes should limit port 5450 inbound access to trusted workstations, users, and software.
- For additional information please refer to AVEVA-2026-002(https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-002.pdf).Vendor reference ↗
- ICSA-26-041-02OTCVSS 9.8 CriticalReleased 2026-02-10
ZLAN Information Technology Co. ZLAN5143D
Vendor: ZLAN Information Technology Co.Product: ZLAN5143D
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of these vulnerabilities could result in an attacker bypassing authentication, or resetting the device password.
Named CVEsCVE-2026-25084CVE-2026-24789Weakness classesView CISA CSAF advisory ↗Mitigations- ZLAN Information Technology Co. did not respond to CISA's attempts at coordination. Users of ZLAN5143D devices are encouraged to contact ZLAN and keep their systems up to date. https://www.zlmcu.com/en/contatct_us.htmVendor reference ↗
- ICSA-26-041-01OTCVSS 8.2 HighReleased 2026-02-10
Yokogawa FAST/TOOLS
Vendor: YokogawaProduct: FAST/TOOLS
Critical infrastructure sectorsCritical ManufacturingEnergyFood and AgricultureSuccessful exploitation of these vulnerabilities could allow an attacker to redirected users to malicious sites, decrypt communications, perform a man-in-the-middle (MITM) attack, execute malicious scripts, steal files, and perform other various attacks.
Named CVEsCVE-2025-66594CVE-2025-66595CVE-2025-66597CVE-2025-66598CVE-2025-66599CVE-2025-66600CVE-2025-66601CVE-2025-66602CVE-2025-66603CVE-2025-66604CVE-2025-66605CVE-2025-66606CVE-2025-66607CVE-2025-66608View CISA CSAF advisory ↗Mitigations- Yokogawa recommends users update to revision R10.04 and apply patch software (CS_e12787). After the patch is applied, users should apply R10.04 SP3.
- Yokogawa strongly recommends that all users establish and maintain a comprehensive security program, not just for addressing the vulnerability identified in this YSAR. Security program components include patch updates, antivirus software, backup and recovery solutions, zoning, hardening, whitelisting, firewalls, and other related measures. Yokogawa can assist organizations in setting up and continuously maintaining a security program. As a starting point for developing the most effective risk mitigation plan, Yokogawa offers security risk assessment services.
- For questions related to this report, please contact Yokogawa https://contact.yokogawa.com/cs/gw?c-id=000498.Vendor reference ↗
- ICSA-26-036-04OTCVSS 9.8 CriticalReleased 2026-02-05
Ilevia EVE X1 Server
Vendor: IleviaProduct: EVE X1
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of these vulnerabilities could allow an attacker to execute arbitrary shell commands and the disclosure of sensitive system information.
Named CVEsCVE-2025-34185CVE-2025-34184CVE-2025-34183CVE-2025-34186CVE-2025-34187CVE-2025-34517CVE-2025-34518CVE-2025-34512CVE-2025-34513View CISA CSAF advisory ↗Mitigations- Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces.
- ICSA-26-036-03OTCVSS 5.7 MediumReleased 2026-02-05
o6 Automation GmbH Open62541
Vendor: o6 Automation GmbHProduct: Open62541
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition and memory corruption.
Named CVEsCVE-2026-1301Weakness classesView CISA CSAF advisory ↗Mitigations- o6 Automation GmbH recommends users upgrade to the stable release of v1.5.0.
- ICSA-26-036-02OTCVSS 9.4 CriticalReleased 2026-02-05
Mitsubishi Electric MELSEC iQ-R Series
Vendor: Mitsubishi ElectricProduct: MELSEC iQ-R Series R08/16/32/120PCPU firmware
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability may allow an attacker to read device data or part of a control program from the affected product, write device data in the affected product, or cause a denial-of-service condition on the affected product.
Named CVEsCVE-2025-15080Weakness classesView CISA CSAF advisory ↗Mitigations- Mitsubishi Electric recommends users of the affected products follow the procedure below to update firmware version 49 or later. Download the update file for the fixed version, the engineering software for firmware upgrade, and the manual from the download website at https://www.mitsubishielectric.com/fa/download/index.html . For details on updating the firmware, see MELSEC iQ-R Module Configuration Manual "Appendix 2 Firmware Update Function".Vendor reference ↗
- Mitsubishi Electric recommends the following mitigations to reduce the risk of exploiting this vulnerability: Use a firewall or virtual private network (VPN) block access from untrusted networks and hosts using a firewall. Use the product within a LAN and block access from untrusted networks and hosts through a firewall. Use firewalls, IP filters, and similar controls to minimize connections to the product and prevent access from untrusted networks and hosts. For details on the IP filter function, refer to "IP Filter" in section 1.13, Security, of the MELSEC iQ-R Ethernet User's Manual (Application). Restrict physical access to the affected product and its connected LAN.
- For specific update instructions and additional details see the Mitsubishi Electric advisory at https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-020_en.pdf .Vendor reference ↗
- For further information, contact your local Mitsubishi Electric representative at https://www.mitsubishielectric.com/fa/service-support/index.html .Vendor reference ↗
- ICSA-26-036-01OTCVSS 8.8 HighReleased 2026-02-05 · Updated 2026-02-11
TP-Link Systems Inc. VIGI Series IP Camera
Vendor: TP-Link Systems Inc.Products: VIGI Cx45 Series Models C345, C445, VIGI Cx55 Series Models C355, C455, VIGI Cx85 Series Models C385, C485, VIGI C340S Series, VIGI C540S Series Models C540S, EasyCam C540S, VIGI C540V Series, VIGI C250 Series, VIGI Cx50 Series Models C350, C450, VIGI Cx20I (1.0) Series Models C220I 1.0, C320I 1.0, C420I 1.0, VIGI Cx20I (1.20) Series Models C220I 1.20, C320I 1.20, C420I 1.20, VIGI Cx30I (1.0) Series Models C230I 1.0, C330I 1.0, C430I 1.0, VIGI Cx30I (1.20) Series Models C230I 1.20, C330I 1.20, C430I 1.20, VIGI Cx30 (1.0) Series Models C230 1.0, C330 1.0, C430 1.0, VIGI Cx30 (1.20) Series Models C230 1.20, C330 1.20, C430 1.20, VIGI Cx40I (1.0) Series Models C240I 1.0, C340I 1.0, C440I 1.0, VIGI Cx40I (1.20) Series Models C240I 1.20, C340I 1.20, C440I 1.20, VIGI C230I Mini Series, VIGI C240 1.0 Series, VIGI C340 2.0 Series, VIGI C440 2.0 Series, VIGI C540 2.0 Series, VIGI C540‑4G Series, VIGI Cx40‑W Series Models C340‑W 2.0/2.20, C440‑W 2.0, C540‑W 2.0, VIGI Cx20 Series Models C320, C420, VIGI InSight Sx45 Series Models S245, S345, S445, VIGI InSight Sx55 Series Models S355, S455, VIGI InSight Sx85 Series Models S285, S385, VIGI InSight Sx45ZI Series Models S245ZI, S345ZI, S445ZI, VIGI InSight Sx85PI Series Models S385PI, S485PI, VIGI InSight S655I Series, VIGI InSight S345‑4G Series, VIGI InSight Sx25 Series Models S225, S325, S425
Critical infrastructure sectorsCommercial FacilitiesSuccessful exploitation of this vulnerability could result in unauthorized users gaining administrative access to affected closed circuit television cameras.
Named CVEsCVE-2026-0629Weakness classesView CISA CSAF advisory ↗Mitigations- TP-Link Systems Inc. strongly recommends that users with affected devices take the following actions:
- Download and update to the latest firmware version to fix the vulnerability from the following links.
- United States users should visit the TP-Link US Download Center here: https://www.vigi.com/us/support/download/.Vendor reference ↗
- Global English users should visit the TP-Link EN Download Center:https://www.vigi.com/es/support/download/.Vendor reference ↗
- India users should visit the TP-Link India Download Center:https://www.vigi.com/in/support/download/.Vendor reference ↗
- Please visit https://www.tp-link.com/us/support/faq/4906/ for the TP-Link advisory.Vendor reference ↗
- ICSA-26-034-04OTCVSS 10 CriticalReleased 2026-02-03
Synectix LAN 232 TRIO
Vendor: SynectixProduct: LAN 232 TRIO
Critical infrastructure sectorsCritical ManufacturingEmergency ServicesEnergyInformation TechnologyTransportation SystemsWater and Wastewater SystemsSuccessful exploitation of this vulnerability could result in an unauthenticated attacker modifying critical device settings or factory resetting the device.
Named CVEsCVE-2026-1633Weakness classesView CISA CSAF advisory ↗Mitigations- The affected products should be considered end-of-life, as Synectix is no longer in business and therefore firmware fixes, mitigations and updates will be unavailable.
- ICSA-26-034-03OTCVSS 9.1 CriticalReleased 2026-02-03
RISS SRL MOMA Seismic Station
Vendor: RISS SRLProduct: MOMA Seismic Station
Critical infrastructure sectorsCritical ManufacturingDamsEnergyWater and Wastewater SystemsTransportation SystemsSuccessful exploitation of this vulnerability could result in an unauthenticated attacker creating a denial-of-service condition.
Named CVEsCVE-2026-1632Weakness classesView CISA CSAF advisory ↗Mitigations- RISS SRL did not respond to CISA's request for coordination. Users of RISS MOMA Seismic Station are encouraged to contact RISS SRL (info@riss-srl.com) for more information.Vendor reference ↗
- ICSA-26-034-02OTCVSS 9.8 CriticalReleased 2026-02-03
*Avation Light Engine Pro *
Vendor: AvationProduct: Light Engine Pro
Critical infrastructure sectorsCommercial FacilitiesSuccessful exploitation of this vulnerability could allow an attacker to take full control of the device.
Named CVEsCVE-2026-1341Weakness classesView CISA CSAF advisory ↗Mitigations- Avation has not responded to CISA's request to coordinate. Users of Avation Light Engine Pro are encouraged to contact Avation for more information.
- ICSA-26-034-01OTCVSS 8.8 HighReleased 2026-02-03
Mitsubishi Electric FREQSHIP-mini for Windows
Vendor: Mitsubishi ElectricProduct: FREQSHIP-mini for Windows
Critical infrastructure sectorsCritical ManufacturingEnergyInformation TechnologyHealthcare and Public HealthGovernment FacilitiesSuccessful exploitation of this vulnerability could allow an attacker to gain unauthorized access to, modify, delete, or destroy information stored on the system where the affected product is installed, or cause a denial-of-service condition on the affected system.
Named CVEsCVE-2025-10314Weakness classesView CISA CSAF advisory ↗Mitigations- The vulnerability has been addressed in FREQSHIP-mini for Windows version 8.1.0 or later. Download and install the updated version from the Mitsubishi Electric download site at https://www.mitsubishielectric.co.jp/fa/download/index.html .Vendor reference ↗
- Mitsubishi Electric recommends that customers take the following mitigation measures to minimize the risk of this vulnerability being exploited: Use the PCs with the affected product installed only within a LAN, and block remote logins from untrusted networks, hosts, and non-administrator users. Block unauthorized access by using a firewall or virtual private network (VPN), etc., and allow remote login only for administrators when connecting the PCs with the affected product installed to the internet. Restrict physical access to the PC and its connected network to prevent unauthorized access. Do not click on links or open attachments in emails from untrusted sources. Install and regularly update antivirus software.
- Mitsubishi Electric Corporation recommends users contact their local Mitsubishi Electric representative at https://www.mitsubishielectric.co.jp/fa/support/purchase/index.html with questions.Vendor reference ↗
- For additional details, refer to Mitsubishi Electric's security advisory at https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2025-019_en.pdf .Vendor reference ↗
- ICSA-26-141-02OTCVSS 8.3 HighReleased 2026-01-29 · Updated 2026-05-21
ABB B&R PCs
Vendor: ABBProducts: APC4100, APC910, C80, MPC3100, PPC1200, PPC900, APC2200, PPC2200, APC3100, PPC3100
Critical infrastructure sectorsEnergyABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is now available that addresses and remediates the vulnerability. A network attacker could exploit the vulnerabilities to execute remote code, initiate DoS attacks, conduct DNS cache poisoning, or extract sensitive information.
Named CVEsCVE-2023-45229CVE-2023-45230CVE-2023-45231CVE-2023-45232CVE-2023-45233CVE-2023-45234CVE-2023-45235CVE-2023-45236CVE-2023-45237View CISA CSAF advisory ↗Mitigations- The problems are corrected in the following product versions: - APC4100 1.09 - APC910 No patch will be released (Please refer to the mitigation measures specified in this advisory). - C80 1.14 - MPC3100 1.24 - PPC1200 1.14 - PPC900 2.16 - APC2200 1.35 - PPC2200 1.35 - APC3100 1.45 - PPC3100 1.45 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.
- Deactivate the vulnerable component - The vulnerabilities exist in the Preboot eXecution Environment (PXE) of the UEFI firmware. If this functionality is not needed, it is recommended to disable it in the UEFI settings, thus making the vulnerabilities not exploitable. Limit accessibility - If PXE functionality is required, users should tightly restrict network traffic to legitimate users and block illegitimate PXE traffic, specifically related to IPv6. For instance, by blocking IPv6 network traffic on the control network firewall. https://help.br-automation.com/#/en/6/cyber-security/defense-in-depth-for-br-products/reference_architecture.html Refer to section “General security recommendations” for further advise on how to keep your system secure.
- The problems are corrected in the following product versions: - APC4100 1.09 - APC910 No patch will be released (Please refer to the mitigation measures specified in this advisory). - C80 1.14 - MPC3100 1.24 - PPC1200 1.14 - PPC900 2.16 - APC2200 1.35 - PPC2200 1.35 - APC3100 1.45 - PPC3100 1.45 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.
- ICSA-26-125-02OTCVSS 5 MediumReleased 2026-01-29 · Updated 2026-05-05
ABB B&R PVI
Vendor: ABBProduct: PVI
Critical infrastructure sectorsEnergyABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is now available that addresses and remediates the vulnerability. An attacker who successfully exploited this vulnerability could read sensitive information in the logging data of the PVI client application. Logging is deactivated by default in all PVI client versions.
Named CVEsCVE-2026-0936Weakness classesView CISA CSAF advisory ↗Mitigations- The problem is corrected in the following product versions: - PVI 6.5.0 Please note that PVI is included in the Automation Studio installation package and shares the same version number as the corresponding Automation Studio release. B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.
- This vulnerability is limited to the PVI client side application logging and does not impact any security related logging of the PVI server component. Logging is not enabled by default for PVI client applications. Activate logging on the client system only when it is required for troubleshooting, debugging or analysis. Ensure that all client side logging information is securely deleted after it is no longer needed. When enabling logging in PVI client applications, the storage path for the log files must be specified. Make sure that only the respective user has access to the directories where the logging information is stored. Refer to section “General security recommendations” for further advise on how to keep your system secure.
- ICSA-26-029-03OTCVSS 7.5 HighReleased 2026-01-29
Rockwell Automation ControlLogix
Vendor: Rockwell AutomationProducts: ControlLogix Redundancy Enhanced Module Catalog 1756-RM2 Firmware, ControlLogix Redundancy Enhanced Module Catalog 1756-RM2XT Firmware
Critical infrastructure sectorsChemicalEnergyCritical ManufacturingFood and AgricultureTransportation SystemsWater and Wastewater SystemsSuccessful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.
Named CVEsCVE-2025-14027Weakness classesView CISA CSAF advisory ↗Mitigations- Rockwell Automation recommends that users upgrade from the 1756-RM2 to 1756-RM3.Vendor reference ↗
- If users are unable to upgrade to the 1756-RM3, security best practices should be applied.Vendor reference ↗
- See Rockwell Automation's SD1769 advisory for more information.Vendor reference ↗
- ICSA-26-029-02OTCVSS 7.5 HighReleased 2026-01-29
Rockwell Automation ArmorStart LT
Vendor: Rockwell AutomationProducts: ArmorStart LT 290D, ArmorStart LT 291D, ArmorStart LT 294D
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition.
Named CVEsCVE-2025-9464CVE-2025-9465CVE-2025-9466CVE-2025-9278CVE-2025-9279CVE-2025-9280CVE-2025-9281CVE-2025-9282CVE-2025-9283Weakness classesView CISA CSAF advisory ↗Mitigations- There is no patch or upgrade at this time. Rockwell Automation recommends users apply security best practices to mitigate the risk of these vulnerabilities.Vendor reference ↗
- See Rockwell Automation's SD1768 advisory for more information.Vendor reference ↗
- ICSA-26-029-01OTCVSS 9.8 CriticalReleased 2026-01-29 · Updated 2026-02-05
KiloView Encoder Series (Update A)
Vendor: KiloViewProducts: Encoder Series E1 hardware Version 1.4, Encoder Series E1 hardware Version 1.6.20, Encoder Series E1-s hardware Version 1.4, Encoder Series E2 hardware Version 1.7.20, Encoder Series E2 hardware Version 1.8.20, Encoder Series G1 hardware Version 1.6.20, Encoder Series P1 hardware Version 1.3.20, Encoder Series P2 hardware Version 1.8.20, Encoder Series RE1 hardware Version 2.0.00, Encoder Series RE1 hardware Version 3.0.00
Critical infrastructure sectorsCommunicationsInformation TechnologySuccessful exploitation of this vulnerability could allow an unauthenticated attacker to create or delete administrator accounts, granting full administrative control.
Named CVEsCVE-2026-1453Weakness classesView CISA CSAF advisory ↗Mitigations- KiloView states that these specific hardware versions are end-of-life; therefore, no patches will be released due to hardware limitations. KiloView recommends that users implement mitigation measures such as network isolation or upgrade to newer hardware generations.
- Users of affected versions of KiloView Encoder Series are invited to contact KiloView customer support at https://www.kiloview.com/contact/ for additional information.Vendor reference ↗
- ICSA-26-043-06OTCVSS 10 CriticalReleased 2026-01-28 · Updated 2026-02-25
Siemens SINEC OS
Vendor: SiemensProducts: RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)
Critical infrastructure sectorsEnergyCritical ManufacturingTransportation SystemsWater and Wastewater SystemsSINEC OS before V3.3 contains third-party components with multiple vulnerabilities. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Named CVEsCVE-2022-48174CVE-2023-7256CVE-2023-39810CVE-2023-42363CVE-2023-42364CVE-2023-42365CVE-2023-42366CVE-2024-6197CVE-2024-6874CVE-2024-7264CVE-2024-8006CVE-2024-8096CVE-2024-9681CVE-2024-11053CVE-2024-12718CVE-2024-41996CVE-2024-47619CVE-2024-52533CVE-2025-0167CVE-2025-0665CVE-2025-0725CVE-2025-1390CVE-2025-3360CVE-2025-4138CVE-2025-4330CVE-2025-4373CVE-2025-4435CVE-2025-4516CVE-2025-4517CVE-2025-6141CVE-2025-9086CVE-2025-9230CVE-2025-9231CVE-2025-9232CVE-2025-10148CVE-2025-27587CVE-2025-32433CVE-2025-38084CVE-2025-38085CVE-2025-38086CVE-2025-38345CVE-2025-38350CVE-2025-38498CVE-2025-39839CVE-2025-39841CVE-2025-39846CVE-2025-39853CVE-2025-39860CVE-2025-39864CVE-2025-39865CVE-2025-59375Weakness classesView CISA CSAF advisory ↗Mitigations- Update to V3.3 or later versionVendor reference ↗
- See Section Additional Information.
- ICSA-26-043-09OTCVSS 8.8 HighReleased 2026-01-27 · Updated 2026-02-12
Hitachi Energy SuprOS
Vendor: Hitachi EnergyProduct: SuprOS
Critical infrastructure sectorsEnergyTransportation SystemsGovernment FacilitiesHitachi Energy is aware of a vulnerability that affects the SuprOS product versions listed in this document. An attacker successfully exploiting this vulnerability can cause confidentiality, integrity and availability impacts. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.
Named CVEsCVE-2025-7740Weakness classesView CISA CSAF advisory ↗Mitigations- Remove unwanted accounts and/or change the default passwords. Refer to the Secure Deployment Guidelines document as described in chapter 4.3
- Upon clean install, change the root password
- If updated from previous version, remove unwanted accounts and/or change the default passwords. Refer to the Secure Deployment Guidelines document as described in chapter 4.3
- Hitachi Energy recommends that customers apply the update and take recommended actions at the earliest convenience
- While reviewing the recommended immediate actions, assess the risk exposure of affected products within the operational environment and update or upgrade if necessary
- ICSA-26-036-06OTCVSS 9 CriticalReleased 2026-01-27 · Updated 2026-02-05
Hitachi Energy FOX61x
Vendor: Hitachi EnergyProduct: FOX61x
Critical infrastructure sectorsEnergyTransportation SystemsHitachi Energy is aware of a vulnerability that affects FOX61x product versions listed in this document. Successful exploitation of this vulnerability can lead to forgery attacks potentially causing impact on confidentiality, integrity and availability for the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. Note: This is applicable only if FOX61x devices are configured to use remote RADIUS authentication.
Named CVEsCVE-2024-3596Weakness classesView CISA CSAF advisory ↗Mitigations- Enable the RADIUS Message-Authenticator option in both the FOX61x and RADIUS Server configurations. Refer to the Technical User Documentation at https://publisher.hitachienergy.com/preview?DocumentID=1KHW029042&LanguageCode=en&DocumentPartId=R18&Action=launch.
- Update to FOX61x R18, then enable the RADIUS Message-Authenticator option in both the FOX61x and RADIUS Server configurations. Refer to the Technical User Documentation at https://publisher.hitachienergy.com/preview?DocumentID=1KHW029042&LanguageCode=en&DocumentPartId=R18&Action=launch.
- If the upgrade is not possible, apply general mitigation factors with segmentation of FOX management traffic to minimize the risk.
- For more information, see the associated Hitachi Energy cybersecurity advisory 8DBD000225 Radius MD5 Vulnerability in Hitachi Energy FOX61x product at https://publisher.hitachienergy.com/preview?DocumentID=8DBD000225&LanguageCode=en or https://publisher.hitachienergy.com/preview?DocumentID=8DBD000225-CSAF&LanguageCode=en&DocumentPartId=&Action=Launch .
- Hitachi Energy recommends implementing security practices and firewall configurations to help protect process control networks from external attacks. Such practices include ensuring that process control systems are physically protected from unauthorized access, have no direct Internet connections, and are separated from other networks by a firewall system that minimizes exposed ports, and any additional ports should be evaluated on a case-by-case basis. Process control systems should not be used for web browsing, instant messaging, or email. Portable computers and removable storage media should be thoroughly scanned for malware before being connected to a control system. Organizations should enforce proper password policies and procedures.
- ICSA-26-036-05OTCVSS 9 CriticalReleased 2026-01-27 · Updated 2026-02-05
Hitachi Energy XMC20
Vendor: Hitachi EnergyProduct: XMC20
Critical infrastructure sectorsEnergyTransportation SystemsHitachi Energy is aware of a vulnerability that affects XMC20 product versions listed in this document. Successful exploitation of this vulnerability can lead to forgery attacks potentially causing impact on confidentiality, integrity and availability for the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. Note: This is applicable only if XMC20 devices are configured to use remote RADIUS authentication.
Named CVEsCVE-2024-3596Weakness classesView CISA CSAF advisory ↗Mitigations- Enable the RADIUS Message-Authenticator option in both the XMC20 and RADIUS server configurations. Refer to the Technical User Documentation at https://publisher.hitachienergy.com/preview?DocumentID=1KHW029001&LanguageCode=en&DocumentPartId=R18&Action=launch.
- Update to XMC20 R18 and then enable the RADIUS Message-Authenticator option in both the XMC20 and RADIUS server configurations. Refer to the Technical User Documentation at https://publisher.hitachienergy.com/preview?DocumentID=1KHW029001&LanguageCode=en&DocumentPartId=R18&Action=launch.
- If the upgrade is not possible, apply general mitigation factors with segmentation of FOX management traffic to minimize the risk.
- For more information, see the associated Hitachi Energy cybersecurity advisory 8DBD000233 RADIUS MD5 Vulnerability in Hitachi Energy XMC20 product available in PDF format here https://publisher.hitachienergy.com/preview?DocumentID=8DBD000233&LanguageCode=en&DocumentPartId=&Action=launch or JSON format here https://publisher.hitachienergy.com/preview?DocumentID=8DBD000233-CSAF&LanguageCode=en&DocumentPartId=&Action=Launch.
- Hitachi Energy recommends implementing security practices and firewall configurations to help protect process control networks from external attacks. Such practices include ensuring that process control systems are physically protected from unauthorized access, have no direct Internet connections, and are separated from other networks by a firewall system that minimizes exposed ports, and any additional ports should be evaluated on a case-by-case basis. Process control systems should not be used for web browsing, instant messaging, or email. Portable computers and removable storage media should be thoroughly scanned for malware before being connected to a control system. Organizations should enforce proper password policies and procedures.
- ICSA-26-027-04OTCVSS 10 CriticalReleased 2026-01-27
Johnson Controls Metasys Products
Vendor: Johnson ControlsProducts: Metasys Application and Data Server (ADS), Metasys Extended Application and Data Server (ADX), Metasys LCS8500, Metasys NAE8500, Metasys System Configuration Tool (SCT), Metasys Controller Configuration Tool (CCT)
Critical infrastructure sectorsCommercial FacilitiesCritical ManufacturingEnergyGovernment FacilitiesTransportation SystemsSuccessful exploitation of this vulnerability could result in remote SQL execution, leading to alteration or loss of data.
Named CVEsCVE-2025-26385Weakness classesView CISA CSAF advisory ↗Mitigations- Johnson Controls recommends downloading and executing the Metasys patch for GIV-165989 from the License Portal. Login credentials are required.Vendor reference ↗
- Johnson Controls advises following the Metasys Release 14 Hardening Guide to ensure each Metasys installation is on a segmented network and not exposed to untrusted networks such as the internet.Vendor reference ↗
- Additionally, closing incoming TCP port 1433 can protect against exploitation of this vulnerability.
- For more detailed mitigation instructions, visit Johnson Controls Product Security Advisory JCI-PSA-2026-02.Vendor reference ↗
- ICSA-26-027-01OTCVSS 9.8 CriticalReleased 2026-01-27 · Updated 2026-02-25
iba Systems ibaPDA
Vendor: iba SystemsProduct: ibaPDA
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could allow an attacker to perform unauthorized actions on the file system.
Named CVEsCVE-2025-14988Weakness classesView CISA CSAF advisory ↗Mitigations- iba Systems recommends users update to ibaPDA v8.12.1 or a later version.
- If Installing the update is not possible, iba Systems recommends users: Enable User Management:To activate user management, navigate to User Management settings under the Configure option. Set a password for the admin user to enable user management.
- Configure Server Access: To configure, open Server Access Manager (found under Configure in the ibaPDA Client). Set the configuration to restrict access. For example, only 127.0.0.1 (localhost) or specific system IP addresses to communicate with ibaPDA can connect to the ibaPDA Server. (In this example, only connections from localhost are permitted to access ibaPDA.)
- Restrict Connections to Localhost (if ibaPDA is only accessed from the system where it runs): 1) Go to I/O Manager, then General, and deactivate the option /"Automatically open necessary ports in Windows Firewall./" (If this option remains active, after a restart of ibaPDA or a restart for data acquisition, the firewall will be reconfigured automatically.) 2) Then, go to Advanced Windows Firewall settings and delete or deactivate all incoming rules for the ibaPDA Client and Server. 3) Manually create firewall rules for the connection used for ibaPDA and verify that the correct ports are configured. For assistance with identifying the ports used by the ibaPDA service can be found in the iba Help Center. 4) Note: After making the changes, verify that all ibaPDA services are operating as expected and that the data acquisition is functioning correctly.
- For more information you can view iba Systems advisory at https://www.iba-ag.com/de/security/iba-2025-04Vendor reference ↗
- ICSA-26-022-08OTCVSS 9.4 CriticalReleased 2026-01-22
EVMAPA
Vendor: EVMAPAProduct: EVMAPA
Critical infrastructure sectorsTransportation SystemsSuccessful exploitation of these vulnerabilities could lead to degraded service, a denial-of-service, or unauthorized remote command execution, which could lead to spoofing or a manipulation of charging station statuses.
Named CVEsCVE-2025-54816CVE-2025-53968CVE-2025-55705View CISA CSAF advisory ↗Mitigations- CVE-2025-54816: EVMAPA informed CISA some of their charging stations do not allow changes to the authorization key using the Open Charge Point Protocol (OCPP). Currently, charge point operators have the option to connect stations using WebSocket Secure (WSS), and EVMAPA connects stations they supply via their own VPN. For OCPP 2.x and newer stations, EVMAPA plans to implement BASIC authorization control.
- CVE-2025-53968: EVMAPA did not release a statement regarding this vulnerability. Contact EVMAPA directly for more information.Vendor reference ↗
- CVE-2025-55705: EVMAPA informed CISA they have resolved this issue and do not allow simultaneous connection of charging stations with the same CBID.
- ICSA-26-022-07OTCVSS 7.8 HighReleased 2026-01-22
Delta Electronics DIAView
Vendor: Delta ElectronicsProduct: DIAView
Critical infrastructure sectorsChemicalCommercial FacilitiesCritical ManufacturingEnergyTransportation SystemsWater and Wastewater SystemsSuccessful exploitation of this vulnerability could enable an attacker to execute arbitrary code.
Named CVEsCVE-2026-0975Weakness classesView CISA CSAF advisory ↗Mitigations- Delta Electronics recommends users update to DIAView v4.4 or later.Vendor reference ↗
- For more information, see Delta Electronics advisory Delta-PCSA-2026-00002.Vendor reference ↗
- Delta Electronics offers users the following general recommendations:
- Do not click on untrusted Internet links or open unsolicited attachments in emails.
- Avoid exposing control systems and equipment to the Internet.
- Place control system networks and remote devices behind firewalls, and isolate them from the business network.
- When remote access is required, use a secure access method, such as a virtual private network (VPN).
- If you have any product-related support concerns, contact Delta via the portal page for any information or materials you may require.Vendor reference ↗
- ICSA-26-022-06OTCVSS 9.1 CriticalReleased 2026-01-22
Hubitat Elevation Hubs
Vendor: HubitatProducts: Elevation C3, Elevation C4, Elevation C5, Elevation C7, Elevation C8, Elevation C8 pro
Critical infrastructure sectorsEnergyCommunicationsSuccessful exploitation of this vulnerability could allow an authenticated attacker to escalate their privileges and control devices outside of their authorized scope.
Named CVEsCVE-2026-1201Weakness classesView CISA CSAF advisory ↗Mitigations- Hubitat has released the following for users to implement:
- Firmware version 2.4.2.157Vendor reference ↗
- ICSA-26-022-05OTCVSS 8.3 HighReleased 2026-01-22
Weintek cMT X Series HMI EasyWeb Service
Vendor: WeintekProducts: cMT3072XH, cMT3072XH(T), cMT-SVRX-820, cMT-CTRL01
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of these vulnerabilities could allow a low-level user to alter privileges and gain full control to the device.
Named CVEsCVE-2025-14750CVE-2025-14751View CISA CSAF advisory ↗Mitigations- Weintek recommends users implement the following mitigation techniques:
- cMT3072XH: Version 20241112
- cMT3072XH(T): Version 20241112
- cMT-SVRX-820: Version 20240919
- cMT-CTRL01: Version 20250827
- For more information, see Weintek's planned notice: https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdfVendor reference ↗
- ICSA-26-022-04OTCVSS 7.1 HighReleased 2026-01-22
Johnson Controls Inc. iSTAR Configuration Utility (ICU) tool
Vendor: Johnson Controls Inc.Product: iSTAR Configuration Utility (ICU) tool
Critical infrastructure sectorsCommercial FacilitiesCritical ManufacturingEnergyGovernment FacilitiesTransportation SystemsSuccessful exploitation of this vulnerability could allow an attacker to cause a failure within the operating system of the machine hosting the ICU tool.
Named CVEsCVE-2025-26386Weakness classesView CISA CSAF advisory ↗Mitigations- Johnson Controls Inc. recommends the following:
- Update the iSTAR Configuration Utility (ICU) tool to version 6.9.8
- For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2025-08 v1 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisoriesVendor reference ↗
- ICSA-26-022-03OTCVSS 6.5 MediumReleased 2026-01-22
Rockwell Automation CompactLogix 5370
Vendor: Rockwell AutomationProduct: CompactLogix 5370
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.
Named CVEsCVE-2025-11743Weakness classesView CISA CSAF advisory ↗Mitigations- Rockwell Automation reports that the following versions are fixed:
- Versions 37.011 and later
- Version 34.016
- Version 35.015
- Version 36.012
- Users using the affected software, who are not able to upgrade to one of the corrected versions, should use our security best practices.Vendor reference ↗
- For additional details, refer to advisory SD1770 on the Rockwell Automation security page.Vendor reference ↗
- ICSA-26-022-02OTCVSS 6.1 MediumReleased 2026-01-22
AutomationDirect CLICK Programmable Logic Controller
Vendor: AutomationDirectProduct: CLICK Programmable Logic Controller
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of these vulnerabilities could allow an attacker to impersonate users, escalate privileges, gain unauthorized access to systems and services, and decrypt sensitive data.
Named CVEsCVE-2025-67652CVE-2025-25051View CISA CSAF advisory ↗Mitigations- AutomationDirect recommends that users update CLICK PLUS and firmware to V3.90.Vendor reference ↗
- If the update cannot be applied right away, the following compensating controls are recommended until the upgrade can be performed:
- Network Isolation – Disconnect the CLICK PLUS PLC from external networks (e.g., the internet or corporate LAN) to reduce exposure.
- Secure Communications – Use only trusted, dedicated internal networks or air-gapped systems for device communication.
- Access Control – Restrict both physical and logical access to authorized personnel only.
- Application Whitelisting – Configure whitelisting so that only trusted, pre-approved applications are allowed to run. Block any unauthorized software.
- Endpoint Protection – Use antivirus or EDR tools and configure host-based firewalls to block unauthorized access attempts.
- Logging & Monitoring – Enable and regularly review system logs to detect suspicious or unauthorized activity.
- Backup & Recovery – Maintain secure, tested backups of the PLC and its configurations to minimize downtime in case of an incident.
- Ongoing Risk Assessment – Continuously evaluate risks associated with running outdated firmware and adjust compensating measures accordingly.
- ICSA-26-020-03OTCVSS 7.9 HighReleased 2026-01-20
Rockwell Automation Verve Asset Manager
Vendor: Rockwell AutomationProduct: Verve Asset Manager
Critical infrastructure sectorsCritical ManufacturingSuccessful exploitation of these vulnerabilities may allow an attacker to access sensitive information stored in variables within the ADI server.
Named CVEsCVE-2025-14376CVE-2025-14377View CISA CSAF advisory ↗Mitigations- Rockwell Automation reports that the issue was resolved in version 1.42, and the component has been optional since version 1.36. Rockwell Automation recommends updating to the latest available version.
- For additional details, refer to the advisory on the Rockwell Automation security page.Vendor reference ↗
- For further assistance, contact Rockwell Automation TechConnect for help.Vendor reference ↗
- ICSA-26-125-04OTCVSS 7.4 HighReleased 2026-01-19 · Updated 2026-05-05
ABB B&R Automation Studio
Vendor: ABBProduct: Automation Studio
Critical infrastructure sectorsCritical ManufacturingABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that resolves a vulnerability. Successful exploitation of this vulnerability may enable an attacker to masquerade as a trusted party when B&R Automation Studio establishes a connection with a server via the ANSL over TLS or OPC-UA protocol.
Named CVEsCVE-2025-11043Weakness classesView CISA CSAF advisory ↗Mitigations- The problem is corrected in the following product versions: B&R Automation Studio version 6.5 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is de-scribed in the user manual.
- To exploit this vulnerability, an attacker would need to intercept and redirect the communication between B&R Automation Studio and the target server, as well as present manipulated certificates that pass validation checks. B&R recommends operating B&R Automation Studio within Level 2 of the ABB ICS Cyber Security Reference Architecture when connecting to Level 1 devices via ANSL over TLS or OPC-UA. Operating in this trusted environment reduces the risk of successful exploitation drastically. Refer to section “General security recommendations” for further advise on how to keep your system secure.
- ICSA-26-125-03OTCVSS 6.8 MediumReleased 2026-01-19 · Updated 2026-05-05
ABB B&R Automation Runtime
Vendor: ABBProduct: Automation Runtime
Critical infrastructure sectorsCritical ManufacturingABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that resolves a vulnerability. An attacker who successfully exploited this vulnerability could cause the product to stop.
Named CVEsCVE-2025-11044Weakness classesView CISA CSAF advisory ↗Mitigations- The problem is corrected in the following product versions: - Automation Runtime 6 versions >= 6.5 - Automation Runtime 4 versions >= R4.93 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.
- The vulnerability cannot be exploited on all devices or across all customer applications. Extensive investigations by B&R have determined that shorter cycle times in customer projects increase the likelihood of potential exploitation. For customers unable to transition to a patched version, adjusting their application configuration to longer cycle times may therefore be considered as a mitigating measure. B&R Automation Runtime is designed to be operated on Level 1 of the ABB ICS Cyber Security Reference Architecture. Exploitation of the vulnerability from outside Level 1 would require an attacker to bypass the Control Network Firewall. Limiting the maximum data traffic and the maximum number of concurrent connections to the ANSL server of Automation Runtime on the Control Network Firewall, shall be considered to mitigate this vulnerability. B&R further recommends, in alignment with its Defense in Depth for B&R Products guidelines, that customers: - Test the maximum load capacity of their application under Automation Runtime before commissioning. - Restrict the permitted data traffic to the device via the Control Network Firewall to no more than 80% of the measured peak traffic value. Refer to section “General security recommendations” for further advise on how to keep your system secure.
- ICSA-26-120-04OTCVSS 8.1 HighReleased 2026-01-16 · Updated 2026-04-30
ABB Ability OPTIMAX
Vendor: ABBProducts: 6.1, 6.2, 6.3, 6.4
Critical infrastructure sectorsEnergyWater and WastewaterABB became aware of severe vulnerability in the products versions listed as affected in the advisory, if the optional integration with Azure Active Directory for Single-Sign On is enabled. We have not received any reports of this vulnerability being exploited. An attacker who successfully exploits this vulnerability could bypass user authentication and potentially cause the product to: - Shutdown the system, - Modify the configuration of the system, - Install and run arbitrary code
Named CVEsCVE-2025-14510Weakness classesView CISA CSAF advisory ↗Mitigations- The problem is corrected in the following product versions: - ABB Ability OPTIMAX v6.4.1-251120 (see References 9AKK108472A0435) or later - ABB Ability OPTIMAX v6.3.1-251120 (see References 9AKK108472A0437) or later ABB recommends that customers using earlier versions of OPTIMAX v6.4 and OPTIMAX v6.3 apply an update of the operating system at earliest convenience. Customers still using the meanwhile unsupported OPTIMAX v6.2 or v6.1 shall contact ABB to identify the right way forward.
- Exploitation requires three preconditions: - OPTIMAX is configured to integrate with Azure Active Directory, - An attacker has a network communication channel with OPTIMAX, - An attacker knows a valid username on the OPTIMAX system other than the default username. Refer to section “General security recommendations” for further advise on how to keep your system secure.
- ICSA-26-083-03OTCVSS 10 CriticalReleased 2026-01-13 · Updated 2026-03-24
"Schneider Electric Plant iT/Brewmaxx"
Vendor: Schneider ElectricProduct: Plant iT/Brewmaxx
Critical infrastructure sectorsEnergyCritical ManufacturingCommercial FacilitiesSchneider Electric is aware of multiple vulnerabilities in Redis open-source database, affecting its Plant iT product. The [Plant iT/Brewmaxx](https://www.proleit.com/plant-it/) product is an object-oriented and PLC-based process control system with integrated Manufacturing Execution System functionality. The integrated and modular software platform consists of basic systems, modules and add-ons that can be flexibly combined. Failure to apply the remediations provided below may risk privilege escalation, which could result in remote code execution.
Named CVEsView CISA CSAF advisory ↗Mitigations- Patch ProLeiT-2025-001 includes a fix to reduce the risk of exploit: • Install the patch to disable the eval commands in Redis on: o Application Server o VisuHub o Engineering Workstations o Workstation with emergency mode functionality • The patch ProLeiT-2025-001 is available via ProLeiT Support: https://www.proleit.com/support/ • Force usage of secure Redis configuration templates in system settings as documented in the patch manual. • Restart all patched Servers and WorkstationsVendor reference ↗
- ICSA-26-027-03OTCVSS 6.5 MediumReleased 2026-01-13 · Updated 2026-01-27
Schneider Electric Zigbee Products
Vendor: Schneider ElectricProducts: Wiser iTRV2, Wiser iTRV3, Wiser RTR2, Wiser UFH, Wiser 16A Electrical Heat Switch, Wiser Boiler Relay, Exxact cFMT 16a, Elko cFMT 16a, Odace cFMT 2a, Merten cFMT 16a, Merten cFMT 2a, Wiser Power Micromodule, Wiser FIP Micromodule, Iconic, Wiser Connected Smart Dimmer, Iconic, Wiser Connected Smart Switch, 2AX, Iconic, Wiser Connected Smart Switch, 10AX, Iconic, Connected AC Fan Controller, Iconic, Connected Smart Socket, Wiser Connected Application Module 1-Gang, Wiser Connected Application Module 2-Gang, Wiser Connected Push Button Dimmer, Wiser Connected Push Button Switch, Wiser Connected Push Button Shutter, Wiser Connected Motion Dimmer, Wiser Connected Motion Switch, Wiser Connected Rotary Dimmer, Connected Wireless Switch, Micromodule Switch, Micromodule Dimmer, Micromodule Shutter, Connected Single Socket Outlet, Connected Double Socket Outlet, Fuga Connected Socket Outlet, Mureva EV Link
Critical infrastructure sectorsCommercial FacilitiesCritical ManufacturingEnergyInformation TechnologyTransportation SystemsSchneider Electric is aware of multiple vulnerabilities with EmberZNet disclosed by Silicon Labs. Many vendors, including Schneider Electric, use Silicon Labs’ Zigbee processors in their offers. The following have denial of service vulnerabilities: Wiser iTRV, Wiser RTR, Wiser UFH, Wiser Heat Switch, Wiser Boiler Relay, cFMT (Exaact, Elko, Odace, Merten), Wiser Micromodule, Iconic Wiser Connected Smart Dimmer, Iconic Zigbee devices, Wiser Application Modules, Wiser Connected Pushbutton Switch/Dimmer/Shutter controller, Rotary Dimmer, Motion Sensor Dimmer/Switch, Smart socket outlets, and EV socket outlet. See the following table. Failure to apply the mitigations provided below may risk denial of service, which could result in products being unavailable.
Named CVEsCVE-2024-6350CVE-2024-6351CVE-2024-6352CVE-2024-10106CVE-2024-7322View CISA CSAF advisory ↗Mitigations- Customers should immediately apply the following mitigations to reduce the risk of exploit: To keep your Zigbee network safe and prevent unauthorized access: • Restrict device access: Do not allow unknown devices to join your network. • Review hub settings: Check how your Zigbee hub manages device pairing. • Control network availability: Only open the network when adding new devices and close it immediately after. • Use install codes and avoid the well-known key: Whenever possible, use unique install codes for added security. Replace default keys with secure, unique keys.
- ICSA-26-132-06OTCVSS 8.8 HighReleased 2026-01-07 · Updated 2026-05-12
ABB WebPro SNMP Card PowerValue Multiple Vulnerabilities
Vendor: ABBProducts: PowerValue, PowerValue UL
Critical infrastructure sectorsChemicalCommunicationsCritical ManufacturingDamsEnergyHealthcare and Public HealthInformation TechnologyWater and Wastewater SystemsABB became aware of multiple internally discovered vulnerabilities in the WebPro SNMP card PowerValue for the product versions listed as affected in the advisory. Depending upon the vulnerability, an attacker with access to local network who successfully exploited this vulnerability could have - Unauthorized access - Insufficient Session Expiration leading to resource unavailability - Uncontrolled Resource Consumption leading to DOS attack ABB strongly advises customers to update the latest firmware of affected products.
Named CVEsCVE-2025-4675CVE-2025-4676CVE-2025-4677View CISA CSAF advisory ↗Mitigations- The problem is corrected in the following product versions: WebPro SNMP card PowerValue version 1.1.8.p ABB advises users of the affected product versions to reach out to ABB Digital Service Support (ch.ups.digital@abb.com) for guidance and recommended actions. Additionally, ABB recommends implementing defensive measures to reduce the risk of vulnerability exploitation, as outlined in the product instruction manual. Please refer to the section “Mitigation factors” for more information.
- Mitigating factors describe conditions and circumstances that make an attack that exploits the vulnerability difficult or less likely to succeed. In case customer cannot opt for not to upgrade the firmware or it is not feasible then please immediately apply mitigating factors mentioned in “General security recommendations”.
- ICSA-26-043-03OTCVSS 10 CriticalReleased 2025-12-09 · Updated 2026-03-12
Siemens COMOS
Vendor: SiemensProducts: COMOS V10.4, COMOS V10.4.5, COMOS V10.5, COMOS V10.6
Critical infrastructure sectorsCritical ManufacturingCOMOS is affected by multiple vulnerabilities that could allow an attacker to execute arbitrary code or cause denial of service condition, data infiltration or perform access control violations. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Named CVEsView CISA CSAF advisory ↗Mitigations- Update to V10.6.1 or later versionVendor reference ↗
- Contact customer support to receive patch and update information
- Update to V10.4.5 or later versionVendor reference ↗
- Update to V10.5.2 or later versionVendor reference ↗
- ICSA-26-020-01OTCVSS 6.5 MediumReleased 2025-12-09 · Updated 2026-02-24
Schneider Electric EcoStruxure Foxboro DCS (Update A)
Vendors: Schneider Electric, IntelProducts: EcoStruxure™ Foxboro DCS Virtualization Server, EcoStruxure™ Foxboro DCS Standard Workstation, EcoStruxure™ Foxboro DCS Server, Xeon Silver, Xeon
Critical infrastructure sectorsCommercial FacilitiesCritical ManufacturingEnergySchneider Electric is aware of a vulnerability disclosed by INTEL used in the EcoStruxure™ Foxboro DCS product formerly known as Foxboro Evo Process Automation System and I/A Series. The [EcoStruxure™ Foxboro DCS product](https://www.se.com/ww/en/product-range/63680-ecostruxure-foxboro-dcs/#overview) is an innovative family of fault-tolerant, highly available control components, which consolidates critical information and elevates staff capabilities to ensure flawless, continuous plant operation. Failure to apply the remediations provided below may risk allowing an authenticated user to potentially enable information disclosure via a side channel with local access, which could result in loss of system functionality or unauthorized access to system functions.
Named CVEsCVE-2018-12130Weakness classesView CISA CSAF advisory ↗Mitigations- The recommendation is to upgrade to latest Foxboro server (V95, H94) and workstations (Dell D96): Please contact your local Service Representative or Schneider Electric Process Automation Global Customer Support Center for information on how to migrate to new hardware.https://pasupport.schneider-electric.com/home2020.asp?code=i1swrtYD1O7YcWYkLo5iZJHxEEY9U-agDBBtcLSP7EXksVendor reference ↗
- If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: The BIOS, OS security patches are applied to significantly reduce the exploit possibility. Additional information is available here: https://se.my.site.com/PAkb/s/article/KA000127385 Several layers of defense-in-depth mechanisms available in the recommended security architecture of DCS system, including the computers themselves, and by following the General Security Recommendations specified below mitigate this vulnerability. https://pasupport.schneider-electric.com/Content/Documents/IASeries/b0700_lastrev/b0700hz_f.pdfVendor reference ↗
- ICSA-26-146-05OTCVSS 9.8 CriticalReleased 2025-11-27 · Updated 2026-05-26
ABB Ability Camera Connect
Vendor: ABBProduct: Ability Camera Connect
Critical infrastructure sectorsChemicalCommercial FacilitiesCommunicationsCritical ManufacturingEnergyTransportation SystemsABB is aware of public reports of vulnerabilities in a 3rd party component VLC media player Version 2.2.4 which was delivered together with the installation package of Camera Connect Version 1.5.0.14 and below. An update is available that resolves a privately reported outdated 3rd party component with vulnerabilities in the product versions listed as affected in this advisory. An attacker who successfully exploited any of these vulnerabilities in the 3rd party component could potentially compromise the system in different ways.
Named CVEsCVE-2024-46461CVE-2023-47360CVE-2023-47359CVE-2023-46814CVE-2022-41325CVE-2020-26664CVE-2019-19721CVE-2019-13962CVE-2019-13615CVE-2019-13602CVE-2019-5460CVE-2019-5459CVE-2019-5439CVE-2018-11529CVE-2017-17670CVE-2017-10699CVE-2017-9301CVE-2017-9300CVE-2017-8313CVE-2017-8312CVE-2017-8311CVE-2017-8310View CISA CSAF advisory ↗Mitigations- The VLC-based component operates solely within completely isolated environments without internet access or any connectivity to external networks. Consequently: • No exposure to untrusted MMS streams: The integer overflow vulnerability relies on handling a maliciously crafted external stream, which is not possible in isolated environments • No remote attacker access: Without network ingress, attackers cannot trigger the vulnerability remotely. • Drastically reduced attack surface: The absence of any external media inputs effectively neutralizes the exploit path, significantly lowering the risk of both denial of service and code execution.
- The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect.
- • Air-gapped environments only: Camera Connect is deployed in completely isolated environments lacking any network connectivity or internet access. • No exposure to MMS streams: The vulnerability depends on processing crafted MMS streams, which cannot originate from external or internal network sources when the system is air-gapped. • Elimination of remote attack surface: Without any method for an attacker to deliver malicious media inputs, the vulnerability cannot be triggered remotely. • Strong reduction in exploitation risk: The combined absence of external media ingestion and unavailable network paths effectively neutralizes the integer underflow exploit, significantly reducing the likelihood of both denial-of-service and memory corruption scenarios.
- Given that Camera Connect is deployed exclusively in fully isolated, air-gapped environments with no internet access or external network connectivity, the following risk-reduction factors apply: • No exposure to crafted MMS streams: The exploit requires the receipt of specially crafted packets via the MMS protocol, which cannot occur without network connectivity. • Network attack vector eliminated: As the vulnerability’s CVSS vector highlights a network-based attack (AV:N), the lack of any ingress network path nullifies the attack surface. • Low likelihood of exploitation: Without access to malicious media input, there is effectively no practical method for an attacker to trigger memory corruption, making the likelihood of denial of service or arbitrary code execution negligible.
- Given that the VLC-based component is installed exclusively within air-gapped environments under strict administrative control, the following factors substantially reduce risk: • Restricted user access: Only trusted, privileged users perform installations and modifications. Standard users have no write permissions to the uninstaller directory. • No internet or network access: The exploit requires local manipulation of VLC’s uninstaller files; without external connectivity, remote coercion or manipulation is impossible. • Elimination of attacker vector: In air gapped deployments with administrative controls, un-privileged users cannot place malicious DLLs or executables in the uninstaller’s search path. • Minimized privilege escalation risk: The combination of controlled write access, absence of network exposure, and trusted user roles effectively neutralizes the binary hijacking threat, rendering successful exploitation highly unlikely.
- Camera Connect is deployed exclusively in air-gapped environments with no internet connectivity or external network access, which significantly reduces the risk: • No exposure to malicious MKV files: The exploit requires a specially crafted Matroska file. In controlled environments without external media sources, such files cannot be introduced. • Remote attack vector eliminated: The vulnerability’s CVSS vector indicates a network-based attack scenario, which is impossible without connectivity. • Strict operational controls: Media ingestion is limited to trusted sources under administrative supervision, further minimizing the likelihood of malicious file introduction. • Effective risk reduction: These combined factors render exploitation highly improbable, neutralizing the buffer overflow threat.
- • No exposure to malicious ASF files: The exploit requires a specially crafted ASF file. In con-trolled environments without external media sources, such files cannot be introduced. • Remote attack vector eliminated: The vulnerability’s CVSS vector indicates a network-based attack scenario, which is impossible without connectivity. • Strict operational controls: Media ingestion is limited to trusted sources under administrative supervision, further minimizing the likelihood of malicious file introduction. • Effective risk reduction: These combined factors render exploitation highly improbable, neutralizing the buffer overflow threat.
- • No exposure to malicious MKV files: The exploit requires a specially crafted MKV file. In con-trolled environments without external media sources, such files cannot be introduced. • Remote attack vector eliminated: The vulnerability’s CVSS vector indicates a network-based attack scenario, which is impossible without connectivity. • Strict operational controls: Media ingestion is limited to trusted sources under administrative supervision, further minimizing the likelihood of malicious file introduction. • Effective risk reduction: These combined factors render exploitation highly improbable, neutralizing the buffer overflow threat.
- • No exposure to malicious ASF files: The exploit requires a specially crafted ASF file. In con-trolled environments without external media sources, such files cannot be introduced. • Remote attack vector eliminated: The vulnerability’s CVSS vector indicates a network-based attack scenario, which is impossible without connectivity. • Strict operational controls: Media ingestion is limited to trusted sources under administrative supervision, further minimizing the likelihood of malicious file introduction. • Effective risk reduction: These combined factors render exploitation highly improbable, neutralizing the buffer overflow threat.
- The affected software is deployed exclusively in isolated environments with no internet connectivity and restricted external access. Exploitation of this vulnerability requires a user to open a specially crafted MKV file provided by an attacker. Since the system operates in a controlled network without exposure to untrusted sources, the likelihood of receiving and executing malicious media files is significantly reduced. Additionally, operational procedures can enforce the use of trusted media files only, further minimizing the risk.
- The affected VLC component is deployed exclusively in fully isolated, air gapped environments with no internet connectivity and tightly controlled external sources. Exploitation of CVE 2017 17670 re-quires a user to open a specifically crafted MP4 file containing a type conversion error in the demuxer. Since the system only processes trusted media files—validated through internal procedures and se-cured media channels—the probability of exposure to hostile MP4 content is minimal. Therefore, the risk of successful exploitation is significantly mitigated by the restricted deployment context.
- No network-based exposure: The vulnerability requires an external actor to supply malicious media content. With no Internet connectivity and presumably controlled file sources, the risk of loading un-trusted files is minimal.
- This vulnerability affects the libmpgatofixed32_plugin.dll module in VLC 2.2.4, which is responsible for decoding MPEG audio streams. The software in question does not process audio files or use any functionality related to audio decoding, meaning the vulnerable component is never invoked during normal operation. Additionally, the deployment environment is fully offline with no internet connectivity, and media ingestion is restricted to trusted internal sources. As a result, the attack surface for this vulnerability is effectively nonexistent, and the risk of exploitation is negligible under these conditions.
- This vulnerability affects VLC’s FLAC audio processing component. Camera Connect does not handle or process audio files, meaning the vulnerable code path is never executed during normal operation. Combined with the fact that the deployment environment is fully isolated (air gapped) and does not allow external file transfers from untrusted sources, the likelihood of exploitation is effectively eliminated.
- Even though the affected VLC version (2.2.4) contains this vulnerability, the software is deployed in fully air-gapped environments with no external or internet-facing connectivity. As a result, the likeli-hood of exploiting this vulnerability is extremely low.
- Because the affected VLC version (2.2.4) suffers from a heap out of bound read in the ParseJSS function—allowing an attacker to read uninitialized heap data via a crafted subtitles file—the risk of external exploitation is significantly reduced in your environment. Since the software is installed in strictly isolated systems with no internet access, no external attacker can deliver malicious subtitle files re-motely. Consequently, the only remaining exposure is local: an insider would need to intentionally load a crafted subtitle file to trigger the issue—a scenario considered highly unlikely under current governance and usage controls.
- Since the application is deployed exclusively in isolated, air-gapped environments with no external network connectivity, the attack vector—specifically, the ability for an attacker to deliver a crafted subtitle file—is significantly constrained.
- Because your team’s VLC based software is deployed only in isolated environments without internet access, the risk of malicious delivery of crafted subtitle files is greatly diminished. This significantly reduces exploitation likelihood.
- ICSA-26-120-03OTCVSS 9.6 CriticalReleased 2025-11-20 · Updated 2026-04-30
ABB Edgenius Management Portal
Vendor: ABBProduct: Ability Edgenius
Critical infrastructure sectorsCritical ManufacturingInformation TechnologyABB identified a critical vulnerability present in ABB Ability Edgenius starting from version 3.2.0.0. We have not received any reports of this vulnerability being exploited. An unauthenticated attacker could exploit this vulnerability to: → install and run arbitrary code, → uninstall installed applications, → modify the configuration of installed applications, on systems running the vulnerable versions of ABB Ability Edgenius, including 3.2.0.0 through 3.2.1.1.
Named CVEsCVE-2025-10571Weakness classesView CISA CSAF advisory ↗Mitigations- ABB has prepared an update to fix this vulnerability included in the latest Roll-Up, ABB Ability Edgenius version 3.2.2.0. ABB advises customers to upgrade as soon as possible. Until the upgrade is applied, ABB advises customers to disable the Edgenius Management Portal to mitigate the vulnerability.
- Exploitation requires an attacker to have gained access to the network where Edgenius has been deployed, and while the Edgenius Management Portal is running. Refer to section “General security recommendations” for further advise on how to keep your system secure.
- Workarounds are specific measures that a user can take to help block an attack, for example, temporarily disabling the vulnerable feature may remove the exposure with well-known impact on functionality. ABB has tested the following workaround.
- ICSA-26-120-02OTCVSS 4.4 MediumReleased 2025-11-03 · Updated 2026-05-13
ABB PCM600
Vendor: ABBProduct: PCM600
Critical infrastructure sectorsCritical ManufacturingAn update is available that resolves vulnerability in the product versions listed as affected in this advisory. An attacker who successfully exploited this vulnerability could insert and run arbitrary code in the system.
Named CVEsCVE-2018-1002208Weakness classesView CISA CSAF advisory ↗Mitigations- The problem is corrected in the following product version: ABB Protection and control IED manager PCM600 version 2.14. ABB recommends that customers apply the update at earliest convenience. Note: RE_630 protection relays are not compatible with PCM600 version 2.14. When using earlier PCM600 versions with RE_630, the known vulnerability must be mitigated through system-level defenses. For mitigation guidance, refer to the General Security Recommendations.
- ICSA-26-146-01OTCVSS 6.8 MediumReleased 2025-10-20 · Updated 2026-05-26
ABB Terra AC
Vendor: ABBProducts: Terra AC wallbox (UL40/80A), Terra AC wallbox (UL32A), Terra AC MID, Terra AC Juno CE, Terra AC PTB, Terra AC wallbox (JP)
Critical infrastructure sectorsCommercial FacilitiesCritical ManufacturingEnergyTransportation SystemsABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the pollution of heap memory which potentially takes remote control of the product and performs a write operation to the flash memory to alter the firmware behavior.
Named CVEsCVE-2025-5517Weakness classesView CISA CSAF advisory ↗Mitigations- The problem is corrected in the product versions listed as fixed in the advisory. Terra AC wallbox (UL40/80A) 1.8.33 Terra AC wallbox (UL32A) 1.8.34 Terra AC MID 1.8.34 Terra AC Juno CE 1.8.34 Terra AC PTB 1.8.33 Terra AC wallbox (JP) 1.8.34 Additionally, we strongly recommend not use unsafe mode(http) to connect your charger to your backend even though OCPP is allowed to do in this way, which absolutely could be attacked by malicious man or organization as a common knowledge. ABB recommends that customers apply the update at earliest convenience.
- ICSA-26-146-06OTCVSS 7.4 HighReleased 2025-10-08 · Updated 2026-05-26
ABB LVS MConfig
Vendor: ABBProduct: MConfig
Critical infrastructure sectorsChemicalCritical ManufacturingEnergyFood and AgricultureTransportation SystemsWater and Wastewater SystemsABB became aware of an internally discovered vulnerability in the MConfig product versions listed as affected in the advisory. An attacker with access to local networks who successfully exploits vulnerability could have access to application’s sensitive information. ABB strongly advises customers to update MConfig with latest software version.
Named CVEsCVE-2025-9970Weakness classesView CISA CSAF advisory ↗Mitigations- The vulnerability is resolved in the following product versions: MConfig version 1.4.9.22 ABB advises users to update their devices to the latest software version. Additionally, ABB recommends implementing defensive measures to reduce the risk of vulnerability exploitation, as outlined in the product instruction manual. Please refer to the section “Mitigation factors” for more information
- ICSA-26-148-03OTCVSS 8 HighReleased 2025-10-07 · Updated 2026-05-28
ABB EIBPORT
Vendor: ABBProducts: EIBPORT V3 KNX, EIBPORT V3 KNX GSM
Critical infrastructure sectorsCritical ManufacturingInformation TechnologyABB is aware of vulnerabilities in the product versions listed as affected in the advisory. A firmware update is available that resolves these privately reported vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited these vulnerabilities could access sensitive information stored inside the device and can change the configuration of the device .
Named CVEsCVE-2021-22291Weakness classesView CISA CSAF advisory ↗Mitigations- ABB recommends that customers apply the update at the earliest convenience.
- ICSA-26-146-04OTCVSS 10 CriticalReleased 2025-10-07 · Updated 2026-05-26
ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM)
Vendor: B&RProduct: Automation Runtime
Critical infrastructure sectorsChemicalCommunicationsCritical ManufacturingDamsEnergyHealthcare and Public HealthInformation TechnologyWater and Wastewater SystemsAn update is available that resolves a vulnerability identified by B&Rs internal security analysis in the product versions listed as affected in this advisory. An attacker who successfully exploited this vulnerability could cause the product to stop.
Named CVEsCVE-2025-3450Weakness classesView CISA CSAF advisory ↗Mitigations- The problem is corrected in Automation Runtime versions 6.3 and Q4.93. The System Diagnostic Manager (SDM) is disabled by default in Automation Runtime 6 and is not in-tended be enabled on active systems located outside properly secured production networks or in facilities lacking adequate physical and logical access controls to prevent any form of unauthorized interaction. For customers who use SDM on their systems, B&R recommends applying the update at the earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.
- ICSA-26-141-04OTCVSS 6.1 MediumReleased 2025-10-07 · Updated 2026-05-21
ABB B&R Automation Runtime
Vendor: B&RProduct: Automation Runtime
Critical infrastructure sectorsEnergyAn update is available that resolves a vulnerability identified by B&Rs internal security analysis in the product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could take over a remote session or execute code in the context of the user’s browser session.
Named CVEsCVE-2025-3449CVE-2025-3448CVE-2025-11498View CISA CSAF advisory ↗Mitigations- The problem is corrected in Automation Runtime 6.4. The System Diagnostic Manager (SDM) is disabled by default in Automation Runtime 6 and is not intended be enabled on active systems located outside properly secured production networks or in facilities lacking adequate physical and logical access controls to prevent any form of unauthorized interaction. For customers who use SDM on their systems, B&R recommends applying the update based on risk assessment at the earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.
- ICSA-26-141-05OTCVSS 6.1 MediumReleased 2025-09-16 · Updated 2026-05-21
ABB Terra AC Wallbox
Vendor: ABBProduct: Terra AC wallbox (JP)
Critical infrastructure sectorsEnergyABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the pollution of heap memory which potentially takes remote control of the product and performs a write operation to the flash memory to alter the firmware behavior.
Named CVEsCVE-2025-10504CVE-2025-12142CVE-2025-12143View CISA CSAF advisory ↗Mitigations- The problem is corrected in the following product version; apply the following update depending on product variant: Terra AC wallbox (JP) 1.8.36 ABB recommends that customers apply the update at earliest convenience.
- To attack with this kind of message, hackers must hijack Bluetooth first and then can send messages. Because the communication messages between BLE and charger have been encrypted. In theory, there is no way to attack the charger.
- The problem is corrected in the following product version; apply the following update depending on product variant: Terra AC wallbox (JP) 1.8.36 ABB recommends that customers apply the update at earliest convenience.
- ICSA-26-146-03OTCVSS 7.5 HighReleased 2025-08-12 · Updated 2026-05-28
ABB Ability Zenon Remote Transport Vulnerability (Update A)
Vendor: ABBProduct: Ability Zenon
Critical infrastructure sectorsChemicalCommunicationsCritical ManufacturingDamsEnergyHealthcare and Public HealthInformation TechnologyWater and Wastewater SystemsABB is aware of vulnerabilities in the product versions listed as affected in the advisory. The vulnerability enables unauthorized access to the Reboot OS function within the Remote Transport Service, allowing an attacker to trigger a system reboot without the required authentication. This functionality initiates a system reboot on the target machine. However, remote exploitation of this vulnerability is not feasible unless the attacker has already gained access to the network where the affected ABB Ability Zenon system is deployed. At the time of writing, there is no evidence that this vulnerability is being actively exploited in the wild.
Named CVEsCVE-2025-8754Weakness classesView CISA CSAF advisory ↗Mitigations- • Restrict network access to systems with the ABB Zenon Software Platform installed. - Ensure that access to a system is restricted by implementing access controls to minimize the risk of unauthorized access. • Assess the necessity of the ABB Zenon Remote Transport functionality. - Ensure that if the Remote Transport functionality is not used, the zensyssrv.exe (ABB Zenon System Service) is stopped or terminated. The zensyssrv.exe can also be stopped or terminated after authorized use to prevent this vulnerability.
- ICSA-26-146-02OTCVSS 5.8 MediumReleased 2025-07-23 · Updated 2026-05-26
ABB AC500 V2
Vendor: ABBProduct: AC500 V2
Critical infrastructure sectorsCritical ManufacturingEnergyWater and Wastewater SystemsABB became aware of vulnerabilities in AC500 V2 listed as affected in the advisory. An attacker who successfully exploited this vulnerability could access fragments of Modbus telegrams that have been sent earlier by that PLC
Named CVEsCVE-2025-7745Weakness classesView CISA CSAF advisory ↗Mitigations- The vulnerabilities have been resolved in the following product versions: AC500 V2 firmware version 2.5.3 (released in 2016) and later
- ICSA-26-148-04OTCVSS 6.8 MediumReleased 2025-07-21 · Updated 2026-05-28
ABB Busch-Welcome 2 Wire Door Opener Actuator
Vendor: ABBProducts: Switch Actuator 4 DU, Switch actuator, door/light 4 DU
Critical infrastructure sectorsCommercial FacilitiesABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could gain physical, unauthorized access to a Building where the product is installed
Named CVEsCVE-2025-7705Weakness classesView CISA CSAF advisory ↗Mitigations- The following actions need to be executed on premise where the respective Busch-Welcome® System is installed: • While the Busch-Welcome® System is in operation, toggle the mode switch on the product from “Door-Open” - to “Light” – Mode, wait one second and switch back to “Door-Open” - Mode. • Restart the Busch-Welcome® System with a Power reset (mains power off and on again). By executing the above steps, the system will recalibrate itself during boot up and will correct the misconfiguration automatically. ABB recommends that customers apply the above listed actions at the earliest convenience.
- ICSA-26-139-01OTCVSS 7.1 HighReleased 2025-04-16 · Updated 2026-05-19
ABB CoreSense HM and CoreSense M10
Vendor: ABBProduct: CoreSense HM <=2.3.1, 2.3.4 | CoreSense M10 <=1.4.1.12, 1.4.1.31
Critical infrastructure sectorsFood and AgricultureCommercial FacilitiesCritical ManufacturingAn update is available that resolves vulnerability in the product versions listed as affected in this advisory. A path traversal vulnerability in these products can allow unauthenticated users to gain access to restricted directories. Exploiting this vulnerability can lead to complete system compromise and exposure of sensitive information.
Named CVEsCVE-2025-3465Weakness classesView CISA CSAF advisory ↗Mitigations- The vulnerabilities are corrected in the following version: CoreSense™ HM v2.3.4 & CoreSense™ M10 v1.4.1.31 ABB recommends that customers apply the update at the earliest convenience.
- ICSA-26-027-02OTCVSS 9.8 CriticalReleased 2024-02-27 · Updated 2026-01-27
Festo Didactic SE MES PC
Vendor: Festo Didactic SEProduct: MES PC
Critical infrastructure sectorsCommercial FacilitiesCommunicationsCritical ManufacturingEnergyMES PCs shipped with Windows 10 come pre-installed with XAMPP. XAMPP is a bundle of third-party open-source applications including the Apache HTTP Server, the MariaDB database and more. From time to time, vulnerabilities in these applications are discovered. These are fixed in newer versions of XAMPP by updating the bundled applications. MES PCs shipped with Windows 10 include a copy of XAMPP which contains around 140 such vulnerabilities listed in this advisory. They can be fixed by replacing XAMPP with Festo Didactic's Factory Control Panel application.
Named CVEsCVE-2019-11036CVE-2023-25727CVE-2021-2011CVE-2022-32083CVE-2021-46668CVE-2018-19518CVE-2021-2194CVE-2019-11049CVE-2022-31626CVE-2022-32084CVE-2022-32088CVE-2022-27377CVE-2020-2922CVE-2019-9638CVE-2019-11044CVE-2020-7068CVE-2020-7069CVE-2015-2301CVE-2023-0568CVE-2022-27458CVE-2021-21706CVE-2022-27452CVE-2020-7071CVE-2022-27387CVE-2022-27376CVE-2019-11043CVE-2021-2032CVE-2021-2007CVE-2019-11045CVE-2022-27445CVE-2022-27457CVE-2022-27384CVE-2022-23808CVE-2023-0567CVE-2019-9025CVE-2022-27379CVE-2019-9637CVE-2021-27928CVE-2021-21703CVE-2020-2760CVE-2021-2166CVE-2015-2787CVE-2022-23807CVE-2020-2752CVE-2021-46666CVE-2020-2814CVE-2020-7065CVE-2021-21705CVE-2020-7062CVE-2019-11039CVE-2019-11035CVE-2022-27447CVE-2019-11046CVE-2022-27446CVE-2022-27386CVE-2019-9639CVE-2019-11042CVE-2022-27385CVE-2020-7059CVE-2020-7070CVE-2022-32091CVE-2015-2348CVE-2019-9020CVE-2021-35604CVE-2022-27444CVE-2018-14883CVE-2014-9705CVE-2020-7064CVE-2022-27382CVE-2020-7063CVE-2021-2372CVE-2019-9021CVE-2018-14851CVE-2022-27448CVE-2021-46663CVE-2021-2180CVE-2014-9709CVE-2023-25690CVE-2022-32082CVE-2022-31629CVE-2019-9022CVE-2016-3078CVE-2023-0662CVE-2021-2022CVE-2022-32089CVE-2019-11048CVE-2021-46669CVE-2019-11047CVE-2022-27383CVE-2021-46667CVE-2022-32087CVE-2022-36760CVE-2020-7060CVE-2018-17082CVE-2019-9640CVE-2021-46661CVE-2019-11034CVE-2022-27456CVE-2020-7061CVE-2022-27455CVE-2021-2144CVE-2021-2154CVE-2022-21595CVE-2019-11040CVE-2021-2389CVE-2023-27522CVE-2020-2812CVE-2021-46665CVE-2022-32086CVE-2022-32085CVE-2021-21704CVE-2020-7066CVE-2022-31628CVE-2021-46662CVE-2016-5385CVE-2022-37436CVE-2013-6501CVE-2021-21702CVE-2019-9024CVE-2019-9023CVE-2022-27449CVE-2021-46664CVE-2019-11050CVE-2021-21708CVE-2022-31625CVE-2022-32081CVE-2022-27378CVE-2006-20001CVE-2018-19935CVE-2022-4900CVE-2018-12882CVE-2019-9641CVE-2022-27380CVE-2022-27381CVE-2021-21707CVE-2022-27451CVE-2020-2780CVE-2019-11041CVE-2021-2174Weakness classesView CISA CSAF advisory ↗Mitigations- Festo Didactic has released Factory Control Panel as a replacement for XAMPP on its MES PCs. Contact technical support at services.didactic@festo.com to obtain the current version of Factory Control Panel which includes fixes for these vulnerabilities.
- ICSA-26-020-02OTCVSS 8.8 HighReleased 2023-07-11 · Updated 2026-01-20
Schneider Electric devices using CODESYS Runtime
Vendor: Schneider ElectricProducts: HMISCU Controller, Modicon Controller LMC078, Modicon Controller M241, Modicon Controller M251, Modicon Controller M262, Modicon Controller M258, Modicon Controller LMC058, Modicon Controller M218, PacDrive 3 Controllers: LMC Eco/Pro/Pro2, SoftSPS embedded in EcoStruxure Machine Expert, Vijeo Designer embedded in EcoStruxure Machine Expert, Harmony (Formerly Magelis) HMIGK/HMIGTO/HMIGTU/HMIGTUX/HMISTU series, Easy Harmony HMIET6/HMIFT6 Magelis HMIGXU series, Harmony (Formerly Magelis) HMIGK/HMIGTO/HMIGTU/HMIGTUX/HMISTU series iPC series with Vijeo Designer runtime, Vijeo Designer Basic, Harmony iPC series, Magelis XBT series, Easy Modicon M310, Harmony P6 series, Vijeo Designer runtime
Critical infrastructure sectorsCommercial FacilitiesCritical ManufacturingEnergySchneider Electric is aware of multiple vulnerabilities disclosed on CODESYS runtime system V3 communication server. Many vendors, including Schneider Electric, embed CODESYS in their offers. If successfully exploited, these vulnerabilities could result in a denial of service or, in some cases, in remote code execution on PacDrive controllers, Modicon Controllers M241 / M251 / M262 / M258 / LMC058 / LMC078 / M218 , HMISCU, the Simulation Runtime SoftSPS from EcoStruxure Machine Expert and EcoStruxure Microgrid Operation products. Failure to apply the mitigations provided below may result in denial of service and/or arbitrary remote code execution.
Named CVEsCVE-2022-4046CVE-2023-28355CVE-2022-47378CVE-2022-47379CVE-2022-47380CVE-2022-47381CVE-2022-47382CVE-2022-47383CVE-2022-47384CVE-2022-47386CVE-2022-47387CVE-2022-47388CVE-2022-47389CVE-2022-47390CVE-2022-47385CVE-2022-47392CVE-2022-47393CVE-2022-47391CVE-2023-37545CVE-2023-37546CVE-2023-37547CVE-2023-37548CVE-2023-37549CVE-2023-37550CVE-2023-37551CVE-2023-37552CVE-2023-37553CVE-2023-37554CVE-2023-37555CVE-2023-37556CVE-2023-37557CVE-2023-37558CVE-2023-37559CVE-2023-3662CVE-2023-3663CVE-2023-3669CVE-2023-3670Weakness classesView CISA CSAF advisory ↗Mitigations- Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.Vendor reference ↗
- Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.Vendor reference ↗
- Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.
- Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.Vendor reference ↗
- Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.Vendor reference ↗
- PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.Vendor reference ↗
- Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.Vendor reference ↗
- SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application.Vendor reference ↗
- Schneider Electric´s Modicon LMC078 controllers have reached end of their life and are no longer commercially available. They have been replaced by the Modicon M262 controllers. We recommend our customers to migrate to the latest offer. Please contact your local Schneider Electric technical support for more information.
- Schneider Electric’s Modicon M218 controllers have reached their end of life and are no longer commercially available. They have been replaced by the Modicon Easy M200 and Modicon M241 controllers. We recommend our customers to migrate to the latest offer. Please contact your local Schneider Electric technical support for more information.
- • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.
- • Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp
- Version 6.3 HF3 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. As an alternative, please contact your Schneider Electric Customer Care Center to obtain the Hot Fix. For additional detail please refer to the supplied help file in Hot Fix. On the engineering workstation, update to v6.3 HF3 of Vijeo Designer.
- Vijeo Designer Basic v2.0 HotFix 2 includes a fix for this vulnerability. Please contact your Schneider Electric Customer Care Center to obtain the installer. To complete the update, connect to Harmony HMI and download the firmware using Vijeo Designer Basic.Vendor reference ↗
- Version 6.3 SP2 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware As an alternative, please contact your Schneider Electric Customer Care Center to obtain the Fix. For additional details, please refer to the supplied help file in Hot Fix. On the engineering workstation, update to v6.3 SP2 of Vijeo Designer.Vendor reference ↗
- Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.
- Version 3.1.5.82 includes a fix for this vulnerability and can be download here: https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 As an alternative, contact your Schneider Electric Customer Care Center to obtain the firmware. To complete the update, connect to M310 and download the firmware using EcoStruxureTM Motion Expert.Vendor reference ↗
- ICSA-26-141-01OTCVSS 5.9 MediumReleased 2023-06-27 · Updated 2026-05-21
Hitachi Energy GMS600
Vendor: Hitachi EnergyProduct: GMS600
Critical infrastructure sectorsCritical ManufacturingHitachi Energy is aware of the vulnerability, CVE-2022-4304 in the OSS component OpenSSL, that affects the GMS600 versions that are listed below. An attacker successfully exploiting this vulnerability could send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection. For immediate mitigation /workaround information, please refer to the General Mitigation Factors/Workarounds
Named CVEsCVE-2022-4304Weakness classesView CISA CSAF advisory ↗Mitigations- Upgrade to version 1.3.2
About this data
Advisories come from the Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS) advisory program, covering operational technology (OT) across the critical infrastructure sectors. The CVSS score, weakness class (CWE), affected vendors and products, and mitigations are read directly from CISA's own Common Security Advisory Framework (CSAF) documents, and each summary is CISA's advisory summary text, verbatim. This page carries metadata and links only: it never reproduces exploit detail. When an advisory publishes no CVSS score the page reads "Not scored", never a zero. A named CVE this tracker follows links into the vulnerabilities table; a CVE it does not follow is shown as plain text.
Advisory documents areCISA ICS Advisories (CSAF), aU.S. Government Work (public domain). Advisory enumeration and the critical infrastructure sector column come from the ICS Advisory Project (ODbL v1.0).