CYBERSECURITYTRACKER
TRACKING7,045 stories in this site build1,486 vulnerability news stories in this site build
Vulnerabilities

OT and ICS advisories

Browse Cybersecurity and Infrastructure Security Agency (CISA) operational technology (OT) and industrial control systems (ICS) advisories, including scores, affected products, and mitigations.

Cybersecurity and Infrastructure Security Agency (CISA) advisories for industrial control systems (ICS), the operational technology (OT) counterpart to the vulnerability feed. Each advisory shows the Common Vulnerability Scoring System (CVSS) score and version CISA publishes, the Common Weakness Enumeration (CWE) class, affected vendors and products, critical infrastructure sectors, vendor fixes and other mitigations, and every Common Vulnerabilities and Exposures (CVE) identifier it names. Industrial Control Systems Advisory (ICSA) and Industrial Control Systems Medical Advisory (ICSMA) records are included and marked. When CISA does not state a CVSS version, the page says so. The facts come from CISA's Common Security Advisory Framework (CSAF) documents. This page carries metadata and links only; each summary is CISA's own advisory summary, with link syntax shown as plain text.

371 CISA advisories: 356 ICS (ICSA) and 15 medical device (ICSMA), all numbered 202615 new since 2026-09-11Really Simple Syndication (RSS) feed

ICS advisory records

371 shown
About this data

Advisories come from the Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS) advisory program, covering operational technology (OT) across the critical infrastructure sectors. The CVSS score, weakness class (CWE), affected vendors and products, and mitigations are read directly from CISA's own Common Security Advisory Framework (CSAF) documents, and each summary is CISA's advisory summary text, verbatim. This page carries metadata and links only: it never reproduces exploit detail. When an advisory publishes no CVSS score the page reads "Not scored", never a zero. A named CVE this tracker follows links into the vulnerabilities table; a CVE it does not follow links to its National Vulnerability Database record. Each named CVE says whether exploitation is reported, not reported, or unknown.

Advisory documents areCISA ICS Advisories (CSAF), aU.S. Government Work (public domain). Advisory enumeration and the critical infrastructure sector column come from the ICS Advisory Project (ODbL v1.0).

Glossary