Skip to content
COOEY
ADVISORIES
143 advisories

CISA cyber & ICS and DC3 (DoD Cyber Crime Center / DCISE) threat products relevant to the DIB — each read by dex into a categorized card: the gist, why it matters, who's affected, and what to do.

Vulnerability RCE CISA ICS 2026-08-27

Xiiaozet LK100W ↗

Xiiaozet LK100W devices below version 2.1.240 have critical OS command injection and authentication bypass flaws.

Successful exploitation of CVE-2026-78037, CVE-2026-78239, and CVE-2026-76943 allows an authenticated attacker to execute arbitrary OS commands with elevated privileges, leading to complete device compromise. DIBs using Xiiaozet LK100W in IT infrastructure must patch immediately to prevent unauthorized access and data theft.

AFFECTEDXiiaozet LK100W

▸ DO  Update Xiiaozet LK100W firmware to version 2.1.240 or later immediately.

#rce#vulnerability#patch-available#ot
Vulnerability CISA ICS 2026-08-27

Rockwell Automation OTTO Fleet Manager ↗

Rockwell Automation OTTO Fleet Manager <=V2.36.2 has a bcrypt password hashing flaw enabling easier offline brute-force attacks.

A vulnerability in Rockwell Automation OTTO Fleet Manager stems from insufficient computational effort in bcrypt password hashing, allowing attackers to reduce the cost of offline brute-force attacks on stored password hashes. If an attacker gains access to an unencrypted system backup, weakly hashed credentials could be more easily compromised.

AFFECTEDRockwell Automation OTTO Fleet Manager

▸ DO  Patch Rockwell Automation OTTO Fleet Manager to version >V2.36.2 immediately.

#vulnerability#patch-available#critical-infrastructure
Vulnerability CISA ICS 2026-08-27

Mitsubishi Electric Multiple FA Products (Update D) ↗

Mitsubishi Electric FA products have a DoS vulnerability exploitable via crafted UDP packets.

Successful exploitation of CVE-2025-3511 in Mitsubishi Electric CC-Link IE TSN Remote I/O modules can cause denial-of-service, timeouts, or communication delays. DIBs using these modules in OT environments must patch to prevent remote attackers from disrupting operations.

AFFECTEDMitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2SMitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B

▸ DO  Patch affected Mitsubishi Electric CC-Link IE TSN Remote I/O modules to version 09 or later.

#vulnerability#ot#patch-available
Vulnerability CISA ICS 2026-08-27

Mitsubishi Electric CNC Series (Update A) ↗

Mitsubishi Electric CNC Series products are vulnerable to a remote out-of-bounds read causing denial-of-service.

Successful exploitation of CVE-2025-2399 allows a remote attacker to trigger an out-of-bounds read, resulting in a denial-of-service condition. Affected Mitsubishi Electric CNC Series models include M800VW, M800VS, M80V, M800W, M800S, M80, E80, C80, M750VW, M730VW, M720VW, M750VS, M730VS, M720VS, M70V, and E70.

AFFECTEDMitsubishi Electric M800VWMitsubishi Electric M800VSMitsubishi Electric M80VMitsubishi Electric M800WMitsubishi Electric M800SMitsubishi Electric M80

▸ DO  Patch affected Mitsubishi Electric CNC Series products immediately to mitigate the out-of-bounds read vulnerability.

#vulnerability#patch-available#ot
Vulnerability CISA ICS 2026-08-27

Ebyte NA111-M ↗

Ebyte NA111-M firmware 9013-2-17 contains multiple critical vulnerabilities allowing full device compromise.

Successful exploitation of these vulnerabilities could allow an attacker to fully compromise the Ebyte NA111-M device. Affected firmware includes CVE-2026-73125, CVE-2026-76179, CVE-2026-75814, CVE-2026-76940, CVE-2026-77966, CVE-2026-73809, CVE-2026-71187, CVE-2026-75548, CVE-2026-69658, CVE-2026-76133, CVE-2026-73819, CVE-2026-77975, and CVE-2026-77977.

AFFECTEDEbyte NA111-M

▸ DO  Patch Ebyte NA111-M firmware to a version prior to 9013-2-17 or apply vendor mitigations immediately.

#vulnerability#patch-available#mitigations
Vulnerability CISA 2026-08-27

CISA Adds Three Known Exploited Vulnerabilities to Catalog ↗

CISA added three actively exploited vulnerabilities to its KEV Catalog, requiring federal agencies to prioritize rapid remediation.

CISA has added CVE-2023-49105 (ownCloud), CVE-2026-53362 (Linux Kernel), and CVE-2026-66384 (JFrog Artifactory) to the Known Exploited Vulnerabilities (KEV) Catalog. Under BOD 26-04, federal agencies must prioritize rapid remediation of high-risk KEV vulnerabilities on publicly exposed assets that grant total control post-exploitation.

AFFECTEDownCloudLinux KernelJFrog Artifactory

▸ DO  Prioritize patching ownCloud, Linux Kernel, and JFrog Artifactory on publicly exposed assets.

#vulnerability#patch-available#exploited-in-wild#mitigations
Vulnerability CISA ICS 2026-08-27

Applied Systems Engineering ASE2000 V2 Communications Test Set ↗

Critical XXE and certificate validation flaws in Applied Systems Engineering ASE2000 V2 allow attackers to read/write files, exfiltrate data, and impersonate peers.

Successful exploitation of CVE-2018-1285 and CVE-2026-18717 in Applied Systems Engineering ASE2000 V2 Communications Test Set versions 2.25 through 2.37 enables arbitrary file read/write, outbound network requests, and TLS interception. This impacts critical infrastructure sectors including Chemical, Critical Manufacturing, Energy, and Water and Wastewater.

AFFECTEDApplied Systems Engineering ASE2000 V2

▸ DO  Patch Applied Systems Engineering ASE2000 V2 to version 2.38 or later immediately.

#vulnerability#patch-available#critical-infrastructure#xxe#tls-interception
Vulnerability RCE CISA ICS 2026-08-27

All-Line Equipment Company Fuel-Boss ↗

All-Line Equipment Company Fuel-Boss systems have critical remote code execution vulnerabilities requiring immediate patching.

Successful exploitation of CVE-2018-19518 and CVE-2019-11043 in All-Line Equipment Company Fuel-Boss allows attackers to execute arbitrary commands remotely. These flaws affect V1 Standard, Portal, Master/Slave, and Backflush Systems versions running PHP 7.1.5 or earlier, posing a severe risk to critical manufacturing and defense industrial base operations.

AFFECTEDAll-Line Equipment Company Fuel-Boss

▸ DO  Patch All-Line Equipment Company Fuel-Boss systems to versions beyond PHP 7.1.5 immediately and verify no unpatched instances exist in the environment.

#rce#vulnerability#patch-available#critical-manufacturing#dib-sector
Guidance CISA 2026-08-26

CISA Vulnerability Review ↗

CISA's Vulnerability Review highlights common software weaknesses and provides steps to address them proactively.

Most compromises exploit basic security failures and well-known software vulnerabilities rather than advanced techniques. The CISA Vulnerability Review analyzes vulnerability data from fiscal years 2024 and 2025 to establish a baseline and promote Secure by Design principles, helping organizations reduce systemic vulnerabilities instead of just reacting to individual flaws.

▸ DO  Review the CISA Vulnerability Review to identify common software weaknesses and implement Secure by Design principles in your software development lifecycle.

#mitigations#guidance#vulnerability
Vulnerability RCE CISA 2026-08-26

CISA Adds Six Known Exploited Vulnerabilities to Catalog ↗

CISA added six actively exploited vulnerabilities to its KEV Catalog, requiring federal agencies to prioritize rapid remediation.

CISA has added six new vulnerabilities to the Known Exploited Vulnerabilities (KEV) Catalog, including CVE-2015-3246, CVE-2015-5287, CVE-2019-1068, CVE-2021-23758, CVE-2022-0995, and CVE-2026-8452. These vulnerabilities are actively exploited and pose significant risks to the federal enterprise, requiring prioritized remediation under BOD 26-04.

AFFECTEDRed Hat LibuserRed Hat Automatic Bug Reporting ToolMicrosoft SQL ServerAjax.NET ProfessionalLinux KernelCitrix NetScaler ADC

▸ DO  Prioritize rapid remediation of the six listed CVEs on publicly exposed assets.

#rce#vulnerability#patch-available#exploited-in-wild#mitigations
Vulnerability RCE CISA ICS 2026-08-25

Zoneminder ↗

Zoneminder 1.37.48 and 1.38.3 have an OS command injection flaw allowing authenticated users to execute arbitrary commands.

An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality, allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server. Successful exploitation could result in full Remote Code Execution as the web server user.

AFFECTEDZoneminder

▸ DO  Upgrade Zoneminder to version 1.38.3 or later immediately.

#rce#vulnerability#patch-available#remote-code-execution
Vulnerability RCE CISA ICS 2026-08-25

Siemens SIMATIC IoT2050 Advanced ↗

Siemens SIMATIC IoT2050 Advanced devices have a missing authentication vulnerability in the Node-RED HTTP interface allowing unauthenticated remote code execution.

Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface. An unauthenticated remote attacker could create malicious flows and execute arbitrary code on the underlying server with maximum privileges.

AFFECTEDSiemens SIMATIC IoT2050 Advanced

▸ DO  Update to the latest version of Siemens SIMATIC IoT2050 Advanced immediately.

#rce#vulnerability#patch-available#ot
Vulnerability CISA ICS 2026-08-25

Rently Smart Home ↗

Rently Smart Home <=20.1.0 has an insufficiently protected credentials flaw allowing attackers to retrieve master pins and override user permissions.

Rently Smart Home versions 20.1.0 and prior are vulnerable to CVE-2026-75960, an Insufficiently Protected Credentials vulnerability that could allow attackers to retrieve pins including the Master Pin and override standard user permissions. Rently has patched this vulnerability in late June and no user action is required.

AFFECTEDRently Smart Home

▸ DO  Verify Rently Smart Home is patched to a version greater than 20.1.0.

#vulnerability#patch-available#mitigations
Vulnerability CISA ICS 2026-08-25

PayRange API ↗

PayRange API lacks authorization on management endpoints, exposing device details publicly.

A critical vulnerability in PayRange API allows unauthenticated attackers to access verbose details of every device on the network. This could lead to information disclosure, device modification, or denial of service.

AFFECTEDPayRange API

▸ DO  Contact PayRange support at [email protected] for mitigation guidance.

#vulnerability#patch-available#commercial-facilities
Vulnerability CISA ICS 2026-08-25

FURUNO FA-50 Class B AIS Transponder ↗

FURUNO FA-50 AIS transponders have hard-coded credentials and missing authentication allowing settings alteration.

Successful exploitation of CVE-2026-59769 in FURUNO FA-50 Class B AIS Transponders allows attackers to alter device settings using known credentials on the in-vessel network. Production ended in 2020 with no further software updates, so organizations must rely on physical security and network isolation.

AFFECTEDFURUNO FA-50 Class B AIS Transponder

▸ DO  Ensure vessels with FURUNO FA-50 transponders are physically locked and not connected directly to the internet.

#vulnerability#ot#mitigations
Vulnerability CISA ICS 2026-08-25

Ebyte NE2-D11 ↗

Ebyte NE2-D11 firmware FW-9167-0-11 has critical web management interface flaws allowing unauthenticated administrative access and data disclosure.

Successful exploitation of CVE-2026-73125 in Ebyte NE2-D11 firmware FW-9167-0-11 allows attackers to gain unauthorized administrative access, modify device configuration, and hijack sessions. Affected devices are deployed worldwide in critical manufacturing and energy sectors.

AFFECTEDEbyte NE2-D11

▸ DO  Patch Ebyte NE2-D11 firmware FW-9167-0-11 immediately and review device access controls.

#vulnerability#patch-available#critical-infrastructure
Vulnerability CISA 2026-08-25

CISA Adds One Known Exploited Vulnerability to Catalog ↗

CISA added CVE-2026-60004, a Gitea code injection vulnerability, to the KEV Catalog due to active exploitation.

CISA has added CVE-2026-60004, a Gitea code injection vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. This vulnerability poses significant risks to the federal enterprise and is a frequent attack vector for malicious cyber actors.

AFFECTEDGitea

▸ DO  Prioritize rapid remediation of CVE-2026-60004 on publicly exposed assets per BOD 26-04.

#vulnerability#exploited-in-wild#patch-available
Vulnerability RCE CISA ICS 2026-08-25

Bendix EC80 Brake ECU ↗

Bendix EC80 Brake ECUs have critical vulnerabilities allowing attackers to disable ABS, steering assist, and other vehicle functions.

Successful exploitation of stack-based buffer overflow and out-of-bounds write vulnerabilities in Bendix EC80 Brake ECUs could allow remote code execution and arbitrary CAN bus traffic injection. This compromises critical vehicle safety systems including ABS, steering assist, speedometer, and traction control.

AFFECTEDBendix EC80 Brake ECU

▸ DO  Patch Bendix EC80 Brake ECUs immediately and monitor for related CVEs.

#rce#vulnerability#ot#patch-available
Guidance CISA 2026-08-25

A Tale of Two SOCs: Insights From Two Red Team Assessments ↗

CISA red team assessments reveal how detection tuning and response processes determine whether an organization can contain a breach.

CISA conducted red team assessments at two organizations, showing that Organization B's rapid detection and isolation contrasted with Organization A's failure to contain the attack. The advisory highlights lessons on detection tuning, response processes, and mitigations for IT, cloud, and OT environments.

▸ DO  Review detection tool baselines and alert filtering to reduce false positives, and establish clear incident response procedures and defender authority.

#mitigations#detection#incident-response#ot#cloud#it
Vulnerability CISA 2026-08-24

CISA Adds One Known Exploited Vulnerability to Catalog ↗

CISA added CVE-2026-21962 to the KEV Catalog for Oracle HTTP Server and Weblogic Server Proxy Plug-in improper access control.

CISA has added CVE-2026-21962 to the Known Exploited Vulnerabilities (KEV) Catalog due to active exploitation. This improper access control flaw in Oracle HTTP Server and Weblogic Server Proxy Plug-in allows total control of an asset post-exploitation, posing significant risks to federal and private sector organizations.

AFFECTEDOracle HTTP ServerOracle Weblogic Server Proxy Plug-in

▸ DO  Prioritize patching CVE-2026-21962 on Oracle HTTP Server and Weblogic Server Proxy Plug-in on publicly exposed assets.

#vulnerability#patch-available#exploited-in-wild
Vulnerability CISA ICS 2026-08-20

Johnson Controls Simplex Incident Manager ↗

Johnson Controls Simplex Incident Manager <=V2.01 stores credentials in unencrypted memory, risking local extraction and unauthorized access.

A vulnerability in Johnson Controls Simplex Incident Manager allows local attackers with low privileges to extract unencrypted user credentials from system memory. This could lead to unauthorized access to the application and connected systems, impacting critical infrastructure sectors like manufacturing and energy.

AFFECTEDJohnson Controls Simplex Incident Manager

▸ DO  Patch Johnson Controls Simplex Incident Manager to version >V2.01 immediately and review memory-dumping defenses.

#vulnerability#patch-available#critical-infrastructure
Vulnerability CISA 2026-08-20

CISA Adds Two Known Exploited Vulnerabilities to Catalog ↗

CISA added two TrueConf Server vulnerabilities to the KEV Catalog due to active exploitation.

CISA has added CVE-2026-72529 and CVE-2026-72530 to the Known Exploited Vulnerabilities (KEV) Catalog. These TrueConf Server flaws allow missing authentication for critical functions and code injection, granting attackers total control of the asset.

AFFECTEDTrueConf Server

▸ DO  Prioritize patching TrueConf Server on publicly exposed assets immediately.

#vulnerability#exploited-in-wild#patch-available
ICS / OT CISA 2026-08-19

Defending Against an Active Threat to Siemens S7 Series PLCs ↗

Active threat actors are using AI-generated scripts to target Siemens S7 Series PLCs; owners must patch, isolate, and harden these devices.

CISA, NSA, FBI, DOE, and EPA warn of an active cyber threat targeting Siemens S7 Series programmable logic controllers (PLCs) using AI-generated exploitation scripts. While the advisory focuses on Siemens, the broader PLC targeting landscape requires all ICS owners to apply relevant mitigations to reduce risk to their devices and systems.

AFFECTEDSiemens S7 Series PLCs

▸ DO  Inventory all Siemens S7 Series PLCs, apply critical security patches, and ensure they are not accessible from the Internet.

#ics-ot#ai-generated#patch-available#mitigations
Vulnerability CISA 2026-08-19

CISA Adds One Known Exploited Vulnerability to Catalog ↗

CISA added CVE-2026-64849, an MLflow Server-Side Request Forgery vulnerability, to the KEV Catalog due to active exploitation.

CISA has added CVE-2026-64849, an MLflow Server-Side Request Forgery vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. This vulnerability poses significant risks to the federal enterprise and is a frequent attack vector for malicious cyber actors.

AFFECTEDMLflow

▸ DO  Prioritize rapid remediation of CVE-2026-64849 on publicly exposed MLflow assets.

#vulnerability#exploited-in-wild#patch-available
Vulnerability RCE CISA ICS 2026-08-18

Siemens Simcenter Nastran ↗

Siemens Simcenter Nastran has a stack overflow vulnerability allowing remote code execution if a user runs the binary with a malicious string.

A stack-based buffer overflow in Siemens Simcenter Nastran (Femap and Nastran versions <2606) allows remote code execution when a user is tricked into running the application with a malicious string. This affects critical manufacturing, defense industrial base, energy, healthcare, and transportation sectors worldwide.

AFFECTEDSiemens Simcenter FemapSiemens Simcenter Nastran

▸ DO  Update Siemens Simcenter Femap and Nastran to version 2606 or later immediately.

#rce#vulnerability#patch-available#dib-sector
Vulnerability RCE CISA ICS 2026-08-18

CISA Malcolm ↗

CISA Malcolm versions before 26.07.0 have path traversal and data amplification flaws that can cause denial-of-service or arbitrary code execution.

CISA Malcolm, a network traffic analysis tool, is affected by multiple vulnerabilities including path traversal and improper handling of compressed data. Exploitation could lead to denial-of-service or arbitrary code execution, impacting critical infrastructure sectors like information technology.

AFFECTEDCISA Malcolm

▸ DO  Upgrade CISA Malcolm to version 26.07.0 or later immediately.

#rce#vulnerability#patch-available#critical-infrastructure
Vulnerability CISA 2026-08-18

CISA Adds Four Known Exploited Vulnerabilities to Catalog ↗

CISA added four actively exploited vulnerabilities to its KEV Catalog, requiring federal agencies to prioritize rapid remediation.

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, including CVE-2026-33824 (Microsoft IKE), CVE-2026-55040 (Microsoft SharePoint), CVE-2026-59310 (Broadcom VMware vCenter), and CVE-2026-65400 (Apple macOS). These vulnerabilities grant total control of assets post-exploitation and are frequent attack vectors for malicious cyber actors.

AFFECTEDMicrosoft Internet Key Exchange (IKE) ServiceMicrosoft SharePointBroadcom VMware vCenterApple macOS

▸ DO  Prioritize rapid remediation of these high-risk vulnerabilities on publicly exposed assets and check for compromise before patching.

#vulnerability#patch-available#exploited-in-wild#mitigations
Vulnerability CISA 2026-08-17

CISA Adds One Known Exploited Vulnerability to Catalog ↗

CISA added CVE-2025-62593, a Ray-Project Ray code injection flaw, to its KEV Catalog due to active exploitation.

CISA has added CVE-2025-62593, a Ray-Project Ray code injection vulnerability, to the Known Exploited Vulnerabilities (KEV) Catalog. This flaw allows attackers to gain total control of an asset post-exploitation and is a frequent attack vector for malicious cyber actors.

AFFECTEDRay-Project Ray

▸ DO  Prioritize patching CVE-2025-62593 on Ray-Project Ray systems and verify systems were not compromised before remediation.

#vulnerability#exploited-in-wild#patch-available#mitigations
Vulnerability RCE CISA ICS 2026-08-13

Siemens Solid Edge ↗

Siemens Solid Edge has critical file parsing flaws allowing code execution via crafted PAR, PSM, or DFT files.

Siemens Solid Edge is affected by multiple out-of-bounds read/write and use-after-free vulnerabilities triggered by specially crafted design files. These flaws could allow attackers to crash the application or execute arbitrary code, posing a risk to critical manufacturing environments.

AFFECTEDSiemens Solid Edge

▸ DO  Update Siemens Solid Edge to the latest versions immediately.

#rce#vulnerability#patch-available#critical-manufacturing
Vulnerability RCE CISA ICS 2026-08-13

Siemens Siveillance Video ↗

Siemens Siveillance Video servers have an OS command injection flaw allowing remote code execution.

Siemens Siveillance Video Management Servers contain a vulnerability (CVE-2026-3014) that permits users with edit permissions to execute arbitrary code. Siemens has released patched versions for V2023 R3, V2024 R1, and V2025, and recommends immediate updates.

AFFECTEDSiemens Siveillance Video V2023 R3Siemens Siveillance Video V2024 R1Siemens Siveillance Video V2025

▸ DO  Update all Siemens Siveillance Video servers to the latest patched versions immediately.

#rce#vulnerability#patch-available#remote-code-execution#os-command-injection
Vulnerability RCE CISA ICS 2026-08-13

Siemens Parasolid ↗

Siemens Parasolid has an out-of-bounds read vulnerability allowing code execution when parsing X_T files.

Siemens Parasolid V38.0 and V38.1 versions below specific patches contain an out-of-bounds read flaw exploitable via crafted X_T files. This could lead to application crashes or arbitrary code execution, posing a risk to critical manufacturing environments using the software.

AFFECTEDSiemens Parasolid V38.0Siemens Parasolid V38.1

▸ DO  Update Siemens Parasolid to V38.0.235 or V38.1.230 or later immediately.

#rce#vulnerability#patch-available#critical-manufacturing
Vulnerability RCE CISA ICS 2026-08-13

Siemens License Server (SLS) ↗

Siemens License Server (SLS) has critical privilege escalation and path traversal flaws requiring immediate patching.

Siemens License Server (SLS) versions below 5.1 and 5.3 are vulnerable to local privilege escalation and path traversal, allowing attackers to execute arbitrary commands and read arbitrary files. Siemens has released a new version and recommends updating to the latest version to mitigate these risks.

AFFECTEDSiemens License Server (SLS)

▸ DO  Update Siemens License Server (SLS) to version 5.1 or later immediately.

#rce#vulnerability#patch-available#privilege-escalation#path-traversal
Vulnerability CISA ICS 2026-08-13

Siemens LOGO! Soft Comfort ↗

Siemens LOGO! Soft Comfort contains critical encryption and password handling flaws allowing local attackers to extract master keys and decrypt project data.

Siemens LOGO! Soft Comfort versions prior to the latest release have hardcoded AES master keys and unsalted password hashes, enabling local attackers to extract keys, decrypt project files, and bypass password protections. Siemens has released a patched version and recommends immediate updates to prevent unauthorized access to sensitive project logic and configurations.

AFFECTEDSiemens LOGO! Soft Comfort

▸ DO  Update Siemens LOGO! Soft Comfort to the latest version immediately.

#vulnerability#patch-available#mitigations
Vulnerability CISA ICS 2026-08-13

Siemens Desigo DXR and PXC Controllers ↗

Siemens Desigo DXR and PXC controllers have a DoS vulnerability exploitable via malformed BACnet packets.

A vulnerability in Siemens Desigo DXR and PXC controllers allows attackers to cause denial of service by sending malformed BACnet packets. Recovery requires a device reset or reboot, and Siemens has released updated versions to patch the flaw.

AFFECTEDSiemens Desigo DXR2Siemens Desigo PXC3Siemens Desigo PXC4Siemens Desigo PXC5.E003Siemens Desigo PXC5.E24Siemens Desigo PXC7

▸ DO  Update Siemens Desigo DXR and PXC controllers to the latest versions immediately.

#vulnerability#ot#patch-available#dos
Vulnerability CISA ICS 2026-08-13

Johnson Controls Metasys ↗

Johnson Controls Metasys systems are vulnerable to a cross-site scripting flaw that allows session hijacking and unauthorized access.

A low-privilege user can inject a persistent malicious XSS payload via a crafted URL into Johnson Controls Metasys UI, executing in the context of other users' sessions including administrators. This could lead to session hijacking and unauthorized access, affecting Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, and Energy sectors.

AFFECTEDJohnson Controls Metasys

▸ DO  Patch Johnson Controls Metasys to version 14.1.5 or higher immediately.

#vulnerability#patch-available#cross-site-scripting#session-hijacking
Vulnerability RCE CISA ICS 2026-08-13

Johnson Controls Inc. Airwall ↗

Johnson Controls Airwall <=4.0.4 contains hardcoded cryptographic keys and authentication bypass flaws.

Successful exploitation of CVE-2026-64887 and CVE-2026-34492 in Johnson Controls Airwall allows attackers to decrypt sensitive data, bypass authentication, and read arbitrary files. The hardcoded keys are identical across all installations, meaning a single disclosure grants universal access.

AFFECTEDJohnson Controls Airwall

▸ DO  Patch Johnson Controls Airwall to version 4.0.5 or later immediately.

#rce#vulnerability#hardcoded-credentials#authentication-bypass#critical-infrastructure
Vulnerability CISA 2026-08-13

Flow Neuroscience FL-100 ↗

Flow Neuroscience FL-100 devices have a hard-coded credential allowing Bluetooth attackers to override safety limits and manipulate brain stimulation parameters.

An undocumented hard-coded credential in Flow Neuroscience FL-100 devices bypasses authentication, enabling attackers within Bluetooth range to manipulate brain stimulation parameters and override safety limits. Healthcare and public health sectors are impacted worldwide.

AFFECTEDFlow Neuroscience FL-100Flow Neuroscience Halo Neuroscience FL-100

▸ DO  Install the latest firmware updates provided by Flow Neuroscience via the Flow app.

#vulnerability#hard-coded-credentials#healthcare#bluetooth#mitigations
Vulnerability CISA ICS 2026-08-13

ANDRITZ HIPASE-250 and 250 SCALA ↗

ANDRITZ HIPASE-250 and 250 SCALA software versions <=7.20 have critical flaws allowing password recovery and unauthorized access.

Successful exploitation of these vulnerabilities allows attackers to read data from the device or gain access to affected workstations. The flaws include storing passwords in a recoverable format, missing authentication for critical functions, and use of hard-coded credentials.

AFFECTEDANDRITZ HIPASE-250ANDRITZ 250 SCALA

▸ DO  Upgrade ANDRITZ HIPASE-250 and 250 SCALA to version V8.00.00 or later immediately.

#vulnerability#patch-available#ot
Vulnerability CISA 2026-08-11

Pulsetto Vagus Nerve Stimulator ↗

Pulsetto Vagus Nerve Stimulator firmware accepts unauthenticated BLE commands that can disable safety mechanisms or alter stimulation settings.

A critical vulnerability (CVE-2026-18844) in the Pulsetto Vagus Nerve Stimulator allows attackers to send hidden commands over its unencrypted Bluetooth Low Energy interface. Exploitation could disable electrical safety mechanisms or modify stimulation output, posing a severe risk to healthcare patients.

AFFECTEDPulsetto Vagus Nerve Stimulator

▸ DO  Contact Pulsetto directly at [email protected] for remediation and monitor for firmware updates.

#vulnerability#healthcare#ble#critical-infrastructure
Vulnerability CISA 2026-08-11

Mira Hormone Monitor, Mira Android App ↗

Mira Hormone Monitor and Mira Android App have critical vulnerabilities allowing unauthorized access, data manipulation, and account takeover.

Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token information, and obtain control of user accounts. The affected versions are Mira Monitor Firmware 1.7.1.47 and Mira Android App 4.5.15.4.

AFFECTEDMira Monitor FirmwareMira Android App

▸ DO  Update Mira Monitor Firmware and Mira Android App to the latest patched versions immediately.

#vulnerability#healthcare#patch-available
◀ PREV PAGE 01 / 04 NEXT ▶