Skip to content
COOEY
ADVISORIES
11 advisories

CISA cyber & ICS and DC3 (DoD Cyber Crime Center / DCISE) threat products relevant to the DIB — each read by dex into a categorized card: the gist, why it matters, who's affected, and what to do.

Vulnerability CISA 2026-07-10

CISA Adds Two Known Exploited Vulnerabilities to Catalog ↗

CISA added two new CVEs to the KEV Catalog requiring urgent patching on exposed assets.

CVE-2026-48939 (iCagenda) and CVE-2026-56291 (Balbooa) allow unrestricted file uploads with dangerous types, enabling remote code execution. BOD 26-04 mandates prioritizing remediation of these KEV vulnerabilities on publicly exposed assets.

AFFECTEDiCagendaBalbooa

▸ DO  Prioritize patching iCagenda and Balbooa on exposed assets per BOD 26-04.

#patch-available#exploited-in-wild#vulnerability#federal-enterprise
Vulnerability CISA ICS 2026-07-09

Schneider Electric PowerChute Serial Shutdown ↗

Schneider Electric PowerChute Serial Shutdown <=1.4 has critical path traversal and injection flaws enabling file overwrite and credential reset.

Successful exploitation could allow attackers to overwrite critical files, forge logs, gain unauthorized access, or trigger DoS. This affects Schneider Electric PowerChute Serial Shutdown <=1.4 and impacts sectors including Communications, Critical Manufacturing, Energy, Healthcare, IT, and Transportation.

AFFECTEDSchneider Electric PowerChute Serial ShutdownPowerChute Serial Shutdown <=1.4

▸ DO  Patch Schneider Electric PowerChute Serial Shutdown to version >1.4 immediately.

#patch-available#vulnerability#critical-infrastructure#file-overwrite#credential-theft
Vulnerability CISA ICS 2026-07-09

Schneider Electric Easergy MiCOM Px40 Series ↗

Schneider Electric Easergy MiCOM Px40 Series protection relays are vulnerable to unauthorized SNMP exposure of device identification.

Schneider Electric has identified a vulnerability in its Easergy MiCOM Px40 Series products that allows unauthorized exposure of basic device identification through the SNMP protocol. Failure to apply mitigations may risk unauthorized exposure of basic device identification through the SNMP protocol.

AFFECTEDSchneider ElectricEasergy MiCOM Px40 SeriesEasergy MiCOM P14xEasergy MiCOM P24xEasergy MiCOM P341Easergy MiCOM P342

▸ DO  Apply the Schneider Electric mitigations for the affected Easergy MiCOM Px40 Series versions immediately.

#vulnerability#snmp#iot#ot#patch-available#dib-sector
Vulnerability RCE CISA ICS 2026-07-09

OpenPLC v3 ↗

Authenticated attackers can write arbitrary files and execute code via OpenPLC v3's unvalidated file upload workflow.

OpenPLC v3 contains a critical vulnerability (CVE-2026-14480) allowing authenticated users to write arbitrary files and escalate to code execution via the legacy web UI. This affects critical infrastructure sectors including manufacturing, energy, and water utilities worldwide.

AFFECTEDOpenPLC v3

▸ DO  Patch OpenPLC v3 immediately and review file upload controls in legacy web UI.

#rce#patch-available#exploited-in-wild#critical-infrastructure#code-execution
Vulnerability RCE CISA ICS 2026-07-07

Siemens SINEC OS ↗

Siemens SINEC OS before V4.0 contains multiple critical vulnerabilities affecting RuggedCom RST2428P devices.

This advisory highlights multiple vulnerabilities in Siemens SINEC OS prior to version 4.0, including buffer overflows and authentication bypasses. DIB organizations should update affected RuggedCom RST2428P devices to the latest version immediately.

AFFECTEDSiemens SINEC OSRuggedCom RST2428P

▸ DO  Update Siemens SINEC OS to version 4.0 or later on affected RuggedCom RST2428P devices.

#rce#vulnerability#patch-available#ics-ot#dib-sector
Vulnerability RCE CISA ICS 2026-07-07

Siemens Mendix Studio Pro ↗

Siemens Mendix Studio Pro versions prior to 11.12 have a file parsing vulnerability enabling arbitrary code execution during build pipelines.

This advisory details a critical vulnerability in Siemens Mendix Studio Pro where specially crafted malicious projects can trigger arbitrary code execution in the context of the user. Siemens has released patches for several affected versions and recommends immediate updates, while also advising countermeasures for products where fixes are not yet available.

AFFECTEDSiemens Mendix Studio Pro 10.11Siemens Mendix Studio Pro 10.12Siemens Mendix Studio Pro 10.13Siemens Mendix Studio Pro 10.14Siemens Mendix Studio Pro 10.15Siemens Mendix Studio Pro 10.16

▸ DO  Update Siemens Mendix Studio Pro to the latest patched version or implement compensating controls.

#rce#patch-available#exploited-in-wild#dib-sector#siemens#file-parsing
Vulnerability RCE CISA ICS 2026-07-07

Labcenter Proteus 9 ↗

Labcenter Proteus 9.1_SP4_Build_42914 has critical out-of-bounds write and buffer overflow flaws enabling arbitrary code execution.

Exploitation could disclose information or allow arbitrary code execution on affected Labcenter Proteus 9 installations. DIB organizations must patch immediately to prevent remote code execution.

AFFECTEDLabcenter Proteus 9.1_SP4_Build_42914

▸ DO  Upgrade to Labcenter Proteus 9.2 SPO immediately.

#rce#patch-available#exploited-in-wild#vulnerability
Vulnerability CISA ICS 2026-07-07

Hydro-Québec Le Circuit Electrique charging station backend ↗

Hydro-Québec charging station backend vulnerabilities allow unauthenticated websocket access and privilege escalation.

Exploitation of these flaws in Hydro-Québec Le Circuit Electrique charging station backend could lead to privilege escalation or denial-of-service attacks. Hydro-Québec has updated most stations to disable OCPP and implemented authentication for remaining systems.

AFFECTEDHydro-Québec Le Circuit Electrique charging station backend

▸ DO  Review and patch Hydro-Québec Le Circuit Electrique charging station backend systems to disable OCPP or implement authentication.

#vulnerability#patch-available#ics-ot#critical-infrastructure
Vulnerability CISA ICS 2026-07-07

Hitachi Energy PROMOD V ↗

Hitachi Energy PROMOD V versions <=1.0.10 use insecure HTTP, enabling interception of credentials and session data.

Hitachi Energy disclosed a critical vulnerability in PROMOD V where insecure HTTP communication allows attackers to intercept or manipulate sensitive data in transit. Affected versions are 1.0.10 and prior; vendors must upgrade to version 1.0.11 and enable HTTPS on the Digipede server.

AFFECTEDHitachi Energy PROMOD V

▸ DO  Patch Hitachi Energy PROMOD V to version 1.0.11 and enable HTTPS on the Digipede server.

#vulnerability#patch-available#credential-theft#http-insecure#energy-sector
Vulnerability CISA 2026-07-07

CISA Adds Three Known Exploited Vulnerabilities to Catalog ↗

CISA added three new CVEs to the KEV Catalog, including JoomShaper and Langflow flaws exploited in the wild.

Three vulnerabilities affecting JoomShaper, Langflow, and Joomlack have been added to CISA's KEV Catalog due to evidence of active exploitation. DIB organizations should prioritize patching these components to prevent unauthorized access and file upload attacks.

AFFECTEDJoomShaperLangflowJoomlack

▸ DO  Prioritize patching JoomShaper, Langflow, and Joomlack components per BOD 26-04.

#exploited-in-wild#patch-available#vulnerability#access-control#authorization-bypass#unrestricted-upload
Vulnerability CISA 2026-07-07

CISA Adds One Known Exploited Vulnerability to Catalog ↗

CISA added CVE-2026-48282 (Adobe ColdFusion path traversal) to the KEV Catalog due to active exploitation.

This vulnerability allows attackers to traverse paths in Adobe ColdFusion, granting full control of the asset. Federal agencies must prioritize rapid remediation per BOD 26-04, and CISA encourages all organizations to adopt risk-based vulnerability management.

AFFECTEDAdobe ColdFusion

▸ DO  Patch Adobe ColdFusion immediately.

#exploited-in-wild#patch-available#vulnerability#dib-sector