CYBERSECURITYTRACKER
TRACKING6,877 stories in this site build1,441 vulnerability news stories in this site build
Operational technology

ICS advisories

Cybersecurity and Infrastructure Security Agency (CISA) advisories for industrial control systems (ICS), the operational technology (OT) counterpart to the vulnerability feed. Each advisory shows the Common Vulnerability Scoring System (CVSS) score and version CISA publishes, the Common Weakness Enumeration (CWE) class, affected vendors and products, critical infrastructure sectors, vendor fixes and other mitigations, and every Common Vulnerabilities and Exposures (CVE) identifier it names. Industrial Control Systems Advisory (ICSA) and Industrial Control Systems Medical Advisory (ICSMA) records are included and marked. When CISA does not state a CVSS version, the page says so. The facts come from CISA's Common Security Advisory Framework (CSAF) documents. This page carries metadata and links only; each summary is CISA's own advisory summary, with link syntax shown as plain text.

364 CISA advisories: 349 ICS (ICSA) and 15 medical device (ICSMA), all numbered 202611 new since 2026-09-10Really Simple Syndication (RSS) feed

ICS advisory records

364 shown
About this data

Advisories come from the Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS) advisory program, covering operational technology (OT) across the critical infrastructure sectors. The CVSS score, weakness class (CWE), affected vendors and products, and mitigations are read directly from CISA's own Common Security Advisory Framework (CSAF) documents, and each summary is CISA's advisory summary text, verbatim. This page carries metadata and links only: it never reproduces exploit detail. When an advisory publishes no CVSS score the page reads "Not scored", never a zero. A named CVE this tracker follows links into the vulnerabilities table; a CVE it does not follow links to its National Vulnerability Database record. Each named CVE says whether exploitation is reported, not reported, or unknown.

Advisory documents areCISA ICS Advisories (CSAF), aU.S. Government Work (public domain). Advisory enumeration and the critical infrastructure sector column come from the ICS Advisory Project (ODbL v1.0).

Glossary