CYBERSECURITYTRACKER
TRACKING7,789 stories in this site build1,682 vulnerability news stories in this site build
Vulnerabilities

OT and ICS advisories

Browse Cybersecurity and Infrastructure Security Agency (CISA) operational technology (OT) and industrial control systems (ICS) advisories, including scores, affected products, and mitigations.

Cybersecurity and Infrastructure Security Agency (CISA) advisories for industrial control systems (ICS), the operational technology (OT) counterpart to the vulnerability feed. Each advisory shows the Common Vulnerability Scoring System (CVSS) score and version CISA publishes, the Common Weakness Enumeration (CWE) class, affected vendors and products, critical infrastructure sectors, vendor fixes and other mitigations, and every Common Vulnerabilities and Exposures (CVE) identifier it names. Industrial Control Systems Advisory (ICSA) and Industrial Control Systems Medical Advisory (ICSMA) records are included and marked. When CISA does not state a CVSS version, the page says so. The facts come from CISA's Common Security Advisory Framework (CSAF) documents. This page carries metadata and links only; each summary is CISA's own advisory summary, with link syntax shown as plain text.

382 CISA advisories: 367 ICS (ICSA) and 15 medical device (ICSMA), all numbered 202611 new since 2026-09-18Really Simple Syndication (RSS) feed

ICS advisory records

382 shown

My Stack only keeps advisories that name a vendor you have pinned. Pins are the vendors you added to My Stack on the home page. Your pin list is saved only in this browser. Shared view and feed requests include the selected vendor names in their URLs. Pins never change what the tracker collects or scores.

About this data

Advisories come from the Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS) advisory program, covering operational technology (OT) across the critical infrastructure sectors. The CVSS score, weakness class (CWE), affected vendors and products, and mitigations are read directly from CISA's own Common Security Advisory Framework (CSAF) documents, and each summary is CISA's advisory summary text, verbatim. This page carries metadata and links only: it never reproduces exploit detail. When an advisory publishes no CVSS score the page reads "Not scored", never a zero. A named CVE this tracker follows links into the vulnerabilities table; a CVE it does not follow links to its National Vulnerability Database record. Each named CVE says whether exploitation is reported, not reported, or unknown.

Advisory documents areCISA ICS Advisories (CSAF), aU.S. Government Work (public domain). Advisory enumeration and the critical infrastructure sector column come from the ICS Advisory Project (ODbL v1.0).

Glossary