Skip to content
COOEY
ADVISORIES
83 advisories

CISA cyber & ICS and DC3 (DoD Cyber Crime Center / DCISE) threat products relevant to the DIB — each read by dex into a categorized card: the gist, why it matters, who's affected, and what to do.

Vulnerability RCE CISA ICS 2026-08-27

Xiiaozet LK100W ↗

Xiiaozet LK100W devices below version 2.1.240 have critical OS command injection and authentication bypass flaws.

Successful exploitation of CVE-2026-78037, CVE-2026-78239, and CVE-2026-76943 allows an authenticated attacker to execute arbitrary OS commands with elevated privileges, leading to complete device compromise. DIBs using Xiiaozet LK100W in IT infrastructure must patch immediately to prevent unauthorized access and data theft.

AFFECTEDXiiaozet LK100W

▸ DO  Update Xiiaozet LK100W firmware to version 2.1.240 or later immediately.

#rce#vulnerability#patch-available#ot
Vulnerability CISA ICS 2026-08-27

Rockwell Automation OTTO Fleet Manager ↗

Rockwell Automation OTTO Fleet Manager <=V2.36.2 has a bcrypt password hashing flaw enabling easier offline brute-force attacks.

A vulnerability in Rockwell Automation OTTO Fleet Manager stems from insufficient computational effort in bcrypt password hashing, allowing attackers to reduce the cost of offline brute-force attacks on stored password hashes. If an attacker gains access to an unencrypted system backup, weakly hashed credentials could be more easily compromised.

AFFECTEDRockwell Automation OTTO Fleet Manager

▸ DO  Patch Rockwell Automation OTTO Fleet Manager to version >V2.36.2 immediately.

#vulnerability#patch-available#critical-infrastructure
Vulnerability CISA ICS 2026-08-27

Mitsubishi Electric Multiple FA Products (Update D) ↗

Mitsubishi Electric FA products have a DoS vulnerability exploitable via crafted UDP packets.

Successful exploitation of CVE-2025-3511 in Mitsubishi Electric CC-Link IE TSN Remote I/O modules can cause denial-of-service, timeouts, or communication delays. DIBs using these modules in OT environments must patch to prevent remote attackers from disrupting operations.

AFFECTEDMitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2SMitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B

▸ DO  Patch affected Mitsubishi Electric CC-Link IE TSN Remote I/O modules to version 09 or later.

#vulnerability#ot#patch-available
Vulnerability CISA ICS 2026-08-27

Mitsubishi Electric CNC Series (Update A) ↗

Mitsubishi Electric CNC Series products are vulnerable to a remote out-of-bounds read causing denial-of-service.

Successful exploitation of CVE-2025-2399 allows a remote attacker to trigger an out-of-bounds read, resulting in a denial-of-service condition. Affected Mitsubishi Electric CNC Series models include M800VW, M800VS, M80V, M800W, M800S, M80, E80, C80, M750VW, M730VW, M720VW, M750VS, M730VS, M720VS, M70V, and E70.

AFFECTEDMitsubishi Electric M800VWMitsubishi Electric M800VSMitsubishi Electric M80VMitsubishi Electric M800WMitsubishi Electric M800SMitsubishi Electric M80

▸ DO  Patch affected Mitsubishi Electric CNC Series products immediately to mitigate the out-of-bounds read vulnerability.

#vulnerability#patch-available#ot
Vulnerability CISA ICS 2026-08-27

Ebyte NA111-M ↗

Ebyte NA111-M firmware 9013-2-17 contains multiple critical vulnerabilities allowing full device compromise.

Successful exploitation of these vulnerabilities could allow an attacker to fully compromise the Ebyte NA111-M device. Affected firmware includes CVE-2026-73125, CVE-2026-76179, CVE-2026-75814, CVE-2026-76940, CVE-2026-77966, CVE-2026-73809, CVE-2026-71187, CVE-2026-75548, CVE-2026-69658, CVE-2026-76133, CVE-2026-73819, CVE-2026-77975, and CVE-2026-77977.

AFFECTEDEbyte NA111-M

▸ DO  Patch Ebyte NA111-M firmware to a version prior to 9013-2-17 or apply vendor mitigations immediately.

#vulnerability#patch-available#mitigations
Vulnerability CISA ICS 2026-08-27

Applied Systems Engineering ASE2000 V2 Communications Test Set ↗

Critical XXE and certificate validation flaws in Applied Systems Engineering ASE2000 V2 allow attackers to read/write files, exfiltrate data, and impersonate peers.

Successful exploitation of CVE-2018-1285 and CVE-2026-18717 in Applied Systems Engineering ASE2000 V2 Communications Test Set versions 2.25 through 2.37 enables arbitrary file read/write, outbound network requests, and TLS interception. This impacts critical infrastructure sectors including Chemical, Critical Manufacturing, Energy, and Water and Wastewater.

AFFECTEDApplied Systems Engineering ASE2000 V2

▸ DO  Patch Applied Systems Engineering ASE2000 V2 to version 2.38 or later immediately.

#vulnerability#patch-available#critical-infrastructure#xxe#tls-interception
Vulnerability RCE CISA ICS 2026-08-27

All-Line Equipment Company Fuel-Boss ↗

All-Line Equipment Company Fuel-Boss systems have critical remote code execution vulnerabilities requiring immediate patching.

Successful exploitation of CVE-2018-19518 and CVE-2019-11043 in All-Line Equipment Company Fuel-Boss allows attackers to execute arbitrary commands remotely. These flaws affect V1 Standard, Portal, Master/Slave, and Backflush Systems versions running PHP 7.1.5 or earlier, posing a severe risk to critical manufacturing and defense industrial base operations.

AFFECTEDAll-Line Equipment Company Fuel-Boss

▸ DO  Patch All-Line Equipment Company Fuel-Boss systems to versions beyond PHP 7.1.5 immediately and verify no unpatched instances exist in the environment.

#rce#vulnerability#patch-available#critical-manufacturing#dib-sector
Vulnerability RCE CISA ICS 2026-08-25

Zoneminder ↗

Zoneminder 1.37.48 and 1.38.3 have an OS command injection flaw allowing authenticated users to execute arbitrary commands.

An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality, allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server. Successful exploitation could result in full Remote Code Execution as the web server user.

AFFECTEDZoneminder

▸ DO  Upgrade Zoneminder to version 1.38.3 or later immediately.

#rce#vulnerability#patch-available#remote-code-execution
Vulnerability RCE CISA ICS 2026-08-25

Siemens SIMATIC IoT2050 Advanced ↗

Siemens SIMATIC IoT2050 Advanced devices have a missing authentication vulnerability in the Node-RED HTTP interface allowing unauthenticated remote code execution.

Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface. An unauthenticated remote attacker could create malicious flows and execute arbitrary code on the underlying server with maximum privileges.

AFFECTEDSiemens SIMATIC IoT2050 Advanced

▸ DO  Update to the latest version of Siemens SIMATIC IoT2050 Advanced immediately.

#rce#vulnerability#patch-available#ot
Vulnerability CISA ICS 2026-08-25

Rently Smart Home ↗

Rently Smart Home <=20.1.0 has an insufficiently protected credentials flaw allowing attackers to retrieve master pins and override user permissions.

Rently Smart Home versions 20.1.0 and prior are vulnerable to CVE-2026-75960, an Insufficiently Protected Credentials vulnerability that could allow attackers to retrieve pins including the Master Pin and override standard user permissions. Rently has patched this vulnerability in late June and no user action is required.

AFFECTEDRently Smart Home

▸ DO  Verify Rently Smart Home is patched to a version greater than 20.1.0.

#vulnerability#patch-available#mitigations
Vulnerability CISA ICS 2026-08-25

PayRange API ↗

PayRange API lacks authorization on management endpoints, exposing device details publicly.

A critical vulnerability in PayRange API allows unauthenticated attackers to access verbose details of every device on the network. This could lead to information disclosure, device modification, or denial of service.

AFFECTEDPayRange API

▸ DO  Contact PayRange support at [email protected] for mitigation guidance.

#vulnerability#patch-available#commercial-facilities
Vulnerability CISA ICS 2026-08-25

FURUNO FA-50 Class B AIS Transponder ↗

FURUNO FA-50 AIS transponders have hard-coded credentials and missing authentication allowing settings alteration.

Successful exploitation of CVE-2026-59769 in FURUNO FA-50 Class B AIS Transponders allows attackers to alter device settings using known credentials on the in-vessel network. Production ended in 2020 with no further software updates, so organizations must rely on physical security and network isolation.

AFFECTEDFURUNO FA-50 Class B AIS Transponder

▸ DO  Ensure vessels with FURUNO FA-50 transponders are physically locked and not connected directly to the internet.

#vulnerability#ot#mitigations
Vulnerability CISA ICS 2026-08-25

Ebyte NE2-D11 ↗

Ebyte NE2-D11 firmware FW-9167-0-11 has critical web management interface flaws allowing unauthenticated administrative access and data disclosure.

Successful exploitation of CVE-2026-73125 in Ebyte NE2-D11 firmware FW-9167-0-11 allows attackers to gain unauthorized administrative access, modify device configuration, and hijack sessions. Affected devices are deployed worldwide in critical manufacturing and energy sectors.

AFFECTEDEbyte NE2-D11

▸ DO  Patch Ebyte NE2-D11 firmware FW-9167-0-11 immediately and review device access controls.

#vulnerability#patch-available#critical-infrastructure
Vulnerability RCE CISA ICS 2026-08-25

Bendix EC80 Brake ECU ↗

Bendix EC80 Brake ECUs have critical vulnerabilities allowing attackers to disable ABS, steering assist, and other vehicle functions.

Successful exploitation of stack-based buffer overflow and out-of-bounds write vulnerabilities in Bendix EC80 Brake ECUs could allow remote code execution and arbitrary CAN bus traffic injection. This compromises critical vehicle safety systems including ABS, steering assist, speedometer, and traction control.

AFFECTEDBendix EC80 Brake ECU

▸ DO  Patch Bendix EC80 Brake ECUs immediately and monitor for related CVEs.

#rce#vulnerability#ot#patch-available
Vulnerability CISA ICS 2026-08-20

Johnson Controls Simplex Incident Manager ↗

Johnson Controls Simplex Incident Manager <=V2.01 stores credentials in unencrypted memory, risking local extraction and unauthorized access.

A vulnerability in Johnson Controls Simplex Incident Manager allows local attackers with low privileges to extract unencrypted user credentials from system memory. This could lead to unauthorized access to the application and connected systems, impacting critical infrastructure sectors like manufacturing and energy.

AFFECTEDJohnson Controls Simplex Incident Manager

▸ DO  Patch Johnson Controls Simplex Incident Manager to version >V2.01 immediately and review memory-dumping defenses.

#vulnerability#patch-available#critical-infrastructure
Vulnerability RCE CISA ICS 2026-08-18

Siemens Simcenter Nastran ↗

Siemens Simcenter Nastran has a stack overflow vulnerability allowing remote code execution if a user runs the binary with a malicious string.

A stack-based buffer overflow in Siemens Simcenter Nastran (Femap and Nastran versions <2606) allows remote code execution when a user is tricked into running the application with a malicious string. This affects critical manufacturing, defense industrial base, energy, healthcare, and transportation sectors worldwide.

AFFECTEDSiemens Simcenter FemapSiemens Simcenter Nastran

▸ DO  Update Siemens Simcenter Femap and Nastran to version 2606 or later immediately.

#rce#vulnerability#patch-available#dib-sector
Vulnerability RCE CISA ICS 2026-08-18

CISA Malcolm ↗

CISA Malcolm versions before 26.07.0 have path traversal and data amplification flaws that can cause denial-of-service or arbitrary code execution.

CISA Malcolm, a network traffic analysis tool, is affected by multiple vulnerabilities including path traversal and improper handling of compressed data. Exploitation could lead to denial-of-service or arbitrary code execution, impacting critical infrastructure sectors like information technology.

AFFECTEDCISA Malcolm

▸ DO  Upgrade CISA Malcolm to version 26.07.0 or later immediately.

#rce#vulnerability#patch-available#critical-infrastructure
Vulnerability RCE CISA ICS 2026-08-13

Siemens Solid Edge ↗

Siemens Solid Edge has critical file parsing flaws allowing code execution via crafted PAR, PSM, or DFT files.

Siemens Solid Edge is affected by multiple out-of-bounds read/write and use-after-free vulnerabilities triggered by specially crafted design files. These flaws could allow attackers to crash the application or execute arbitrary code, posing a risk to critical manufacturing environments.

AFFECTEDSiemens Solid Edge

▸ DO  Update Siemens Solid Edge to the latest versions immediately.

#rce#vulnerability#patch-available#critical-manufacturing
Vulnerability RCE CISA ICS 2026-08-13

Siemens Siveillance Video ↗

Siemens Siveillance Video servers have an OS command injection flaw allowing remote code execution.

Siemens Siveillance Video Management Servers contain a vulnerability (CVE-2026-3014) that permits users with edit permissions to execute arbitrary code. Siemens has released patched versions for V2023 R3, V2024 R1, and V2025, and recommends immediate updates.

AFFECTEDSiemens Siveillance Video V2023 R3Siemens Siveillance Video V2024 R1Siemens Siveillance Video V2025

▸ DO  Update all Siemens Siveillance Video servers to the latest patched versions immediately.

#rce#vulnerability#patch-available#remote-code-execution#os-command-injection
Vulnerability RCE CISA ICS 2026-08-13

Siemens Parasolid ↗

Siemens Parasolid has an out-of-bounds read vulnerability allowing code execution when parsing X_T files.

Siemens Parasolid V38.0 and V38.1 versions below specific patches contain an out-of-bounds read flaw exploitable via crafted X_T files. This could lead to application crashes or arbitrary code execution, posing a risk to critical manufacturing environments using the software.

AFFECTEDSiemens Parasolid V38.0Siemens Parasolid V38.1

▸ DO  Update Siemens Parasolid to V38.0.235 or V38.1.230 or later immediately.

#rce#vulnerability#patch-available#critical-manufacturing
Vulnerability RCE CISA ICS 2026-08-13

Siemens License Server (SLS) ↗

Siemens License Server (SLS) has critical privilege escalation and path traversal flaws requiring immediate patching.

Siemens License Server (SLS) versions below 5.1 and 5.3 are vulnerable to local privilege escalation and path traversal, allowing attackers to execute arbitrary commands and read arbitrary files. Siemens has released a new version and recommends updating to the latest version to mitigate these risks.

AFFECTEDSiemens License Server (SLS)

▸ DO  Update Siemens License Server (SLS) to version 5.1 or later immediately.

#rce#vulnerability#patch-available#privilege-escalation#path-traversal
Vulnerability CISA ICS 2026-08-13

Siemens LOGO! Soft Comfort ↗

Siemens LOGO! Soft Comfort contains critical encryption and password handling flaws allowing local attackers to extract master keys and decrypt project data.

Siemens LOGO! Soft Comfort versions prior to the latest release have hardcoded AES master keys and unsalted password hashes, enabling local attackers to extract keys, decrypt project files, and bypass password protections. Siemens has released a patched version and recommends immediate updates to prevent unauthorized access to sensitive project logic and configurations.

AFFECTEDSiemens LOGO! Soft Comfort

▸ DO  Update Siemens LOGO! Soft Comfort to the latest version immediately.

#vulnerability#patch-available#mitigations
Vulnerability CISA ICS 2026-08-13

Siemens Desigo DXR and PXC Controllers ↗

Siemens Desigo DXR and PXC controllers have a DoS vulnerability exploitable via malformed BACnet packets.

A vulnerability in Siemens Desigo DXR and PXC controllers allows attackers to cause denial of service by sending malformed BACnet packets. Recovery requires a device reset or reboot, and Siemens has released updated versions to patch the flaw.

AFFECTEDSiemens Desigo DXR2Siemens Desigo PXC3Siemens Desigo PXC4Siemens Desigo PXC5.E003Siemens Desigo PXC5.E24Siemens Desigo PXC7

▸ DO  Update Siemens Desigo DXR and PXC controllers to the latest versions immediately.

#vulnerability#ot#patch-available#dos
Vulnerability CISA ICS 2026-08-13

Johnson Controls Metasys ↗

Johnson Controls Metasys systems are vulnerable to a cross-site scripting flaw that allows session hijacking and unauthorized access.

A low-privilege user can inject a persistent malicious XSS payload via a crafted URL into Johnson Controls Metasys UI, executing in the context of other users' sessions including administrators. This could lead to session hijacking and unauthorized access, affecting Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, and Energy sectors.

AFFECTEDJohnson Controls Metasys

▸ DO  Patch Johnson Controls Metasys to version 14.1.5 or higher immediately.

#vulnerability#patch-available#cross-site-scripting#session-hijacking
Vulnerability RCE CISA ICS 2026-08-13

Johnson Controls Inc. Airwall ↗

Johnson Controls Airwall <=4.0.4 contains hardcoded cryptographic keys and authentication bypass flaws.

Successful exploitation of CVE-2026-64887 and CVE-2026-34492 in Johnson Controls Airwall allows attackers to decrypt sensitive data, bypass authentication, and read arbitrary files. The hardcoded keys are identical across all installations, meaning a single disclosure grants universal access.

AFFECTEDJohnson Controls Airwall

▸ DO  Patch Johnson Controls Airwall to version 4.0.5 or later immediately.

#rce#vulnerability#hardcoded-credentials#authentication-bypass#critical-infrastructure
Vulnerability CISA ICS 2026-08-13

ANDRITZ HIPASE-250 and 250 SCALA ↗

ANDRITZ HIPASE-250 and 250 SCALA software versions <=7.20 have critical flaws allowing password recovery and unauthorized access.

Successful exploitation of these vulnerabilities allows attackers to read data from the device or gain access to affected workstations. The flaws include storing passwords in a recoverable format, missing authentication for critical functions, and use of hard-coded credentials.

AFFECTEDANDRITZ HIPASE-250ANDRITZ 250 SCALA

▸ DO  Upgrade ANDRITZ HIPASE-250 and 250 SCALA to version V8.00.00 or later immediately.

#vulnerability#patch-available#ot
Vulnerability CISA ICS 2026-08-07

CPDLC over ATN-B1 Vulnerabilities ↗

CPDLC over ATN-B1 systems have multiple vulnerabilities allowing message injection and denial-of-service.

CPDLC over ATN-B1 relies on legacy clear text unauthenticated radio frequency links, enabling unauthorized message injection, denial-of-service, and forced session resets. These vulnerabilities can degrade operational safety margins by increasing workload and reducing situational awareness.

AFFECTEDATN-B1 CPDLC

▸ DO  Review CPDLC over ATN-B1 configurations and apply available mitigations or patches.

#vulnerability#ot#mitigations
Vulnerability CISA ICS 2026-08-06

Johnson Controls Inc. TL280 ↗

Johnson Controls TL280 devices running firmware below 5.63 contain hardcoded credentials and a broken cryptographic algorithm.

Successful exploitation of the TL280 vulnerability allows attackers to access sensitive information on the device. The affected firmware versions are TL280 <5.63, which includes CVE-2026-27871 involving hardcoded credentials and a risky cryptographic algorithm.

AFFECTEDJohnson Controls TL280

▸ DO  Apply firmware update 5.63 to Johnson Controls TL280 devices and restrict network access to trusted management VLANs only.

#vulnerability#patch-available#ot#mitigations
Vulnerability RCE CISA ICS 2026-08-06

ABB Ability Zenon ↗

ABB Ability Zenon systems with MongoDB 4.2 are vulnerable to multiple critical flaws including CVE-2025-14847.

Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data. The affected systems include ABB Ability Zenon with MongoDB 4.2 installed, impacting critical infrastructure sectors like Chemical, Energy, and Water and Wastewater.

AFFECTEDABB Ability ZenonMongoDB Server

▸ DO  Patch ABB Ability Zenon systems with MongoDB 4.2 to versions 7.0.28 or 8.0.17 or later immediately.

#rce#vulnerability#patch-available#critical-infrastructure#cve-2025-14847
Vulnerability CISA ICS 2026-08-04

Acrisure KARR BT and DR-100 ↗

Acrisure KARR BT and DR-100 firmware versions before July 20, 2026, contain a hard-coded cryptographic key flaw enabling unauthorized vehicle control.

Acrisure KARR BT and DR-100 anti-theft systems use a shared Bluetooth authentication key, allowing attackers within range to issue unauthorized commands like unlocking doors or immobilizing engines. A firmware update released on July 20, 2026, patches this vulnerability.

AFFECTEDAcrisure KARR BTAcrisure DR-100

▸ DO  Update Acrisure KARR BT and DR-100 firmware to version July 20, 2026, or later.

#vulnerability#patch-available#transportation
Vulnerability CISA ICS 2026-07-30

Watchfire Controller Software ↗

Watchfire Controller Software contains hard-coded RSA keys allowing firmware takeover via CVE-2026-5846.

Watchfire Controller Software versions BC550 12.30, BC750 11.33|12.35, BC760 12.38|13.00, and BC760DC 12.39 embed plaintext RSA private keys in firmware, enabling malicious firmware delivery and full controller control. This affects Commercial Facilities, Critical Manufacturing, Healthcare, Financial Services, and other sectors in the US and abroad.

AFFECTEDWatchfire Controller Software

▸ DO  Patch Watchfire Controller Software to versions that remove hard-coded keys and verify firmware integrity.

#vulnerability#patch-available#critical-infrastructure
Vulnerability CISA ICS 2026-07-30

Toptech Systems RCU II+ and Multiload II+ ↗

Toptech Systems RCU II+ and Multiload II+ devices have an unauthenticated debug interface allowing full system control.

Successful exploitation of CVE-2026-12562 grants attackers root-level access to the embedded Linux environment, enabling filesystem manipulation, process control, and network interface alteration. This affects Toptech Systems RCU II+ and Multiload II+ devices deployed worldwide, posing a critical risk to connected infrastructure.

AFFECTEDToptech Systems RCU II+Toptech Systems Multiload II+

▸ DO  Patch Toptech Systems RCU II+ and Multiload II+ devices to version 2025-11-24 or later immediately.

#vulnerability#patch-available#critical-infrastructure#energy
Vulnerability RCE CISA ICS 2026-07-30

Schneider Electric IGSS ↗

Schneider Electric IGSS Definition module has an out-of-bounds write vulnerability risking data loss or arbitrary code execution.

Schneider Electric has identified an out-of-bounds write vulnerability in the IGSS Definition module of its IGSS product. Importing a malicious CGF file could lead to data loss or arbitrary code execution, potentially resulting in loss of system control.

AFFECTEDSchneider Electric IGSS

▸ DO  Patch IGSS Definition module to version 18.0.0.26124 or higher immediately.

#rce#vulnerability#patch-available#critical-infrastructure
Vulnerability CISA ICS 2026-07-30

NASA Core Flight System (cFS) Health & Safety (HS) Application ↗

NASA cFS HS App <=v7.0.1 has a NULL pointer dereference causing denial-of-service.

An incomplete fix for CVE-2026-15352 leaves a separate NULL pointer dereference in the NASA Core Flight System (cFS) Health & Safety (HS) Application through version 7.0.1. Exploitation can crash the application, causing a denial-of-service condition and processor reset.

AFFECTEDNASA Core Flight System (cFS) Health & Safety (HS) Applicati

▸ DO  Upgrade NASA cFS HS Application to a patched version or apply vendor mitigation.

#vulnerability#patch-available#ot
Vulnerability CISA ICS 2026-07-30

Mitsubishi Electric CC-Link IE TSN Communication Protocol ↗

Mitsubishi Electric CC-Link IE TSN protocol flaw allows network attackers to tamper with data or cause DoS via crafted packets.

A vulnerability in Mitsubishi Electric CC-Link IE TSN Communication Protocol enables attackers on the same network segment to inject specially crafted packets under specific timing conditions, resulting in data tampering or denial-of-service. Affected Mitsubishi Electric MELSEC MX Controller and Master/local module models are at risk.

AFFECTEDMitsubishi Electric MELSEC MX Controller MX-R model MXR300-1Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-3Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-6Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-1Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-2Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8

▸ DO  Patch affected Mitsubishi Electric CC-Link IE TSN Communication Protocol versions immediately.

#vulnerability#patch-available#ot
Vulnerability CISA ICS 2026-07-30

MikroTik RouterOS ↗

MikroTik RouterOS API session-management flaw allows extraction of WireGuard private keys and full VPN impersonation.

A critical vulnerability (CVE-2026-14227) in MikroTik RouterOS enables attackers to extract WireGuard private keys in plaintext via low-privilege API access, leading to full VPN impersonation and traffic decryption. Affected versions include RouterOS vers:all/*, impacting critical infrastructure sectors like information technology worldwide.

AFFECTEDMikroTik RouterOS

▸ DO  Patch MikroTik RouterOS immediately and ensure users are fully logged out when permissions are downgraded.

#vulnerability#patch-available#ot#mitigations
Vulnerability CISA ICS 2026-07-30

MZ Automation lib60870 ↗

MZ Automation lib60870 2.4.0 has out-of-bounds read flaws exploitable via crafted IEC 60870-5-104 traffic.

Successful exploitation of CVE-2026-61893 and CVE-2026-63033 in MZ Automation lib60870 2.4.0 can crash critical infrastructure devices in energy, water, and manufacturing sectors. MZ Automation recommends updating to version 2.4.1 when available.

AFFECTEDMZ Automation lib60870

▸ DO  Update MZ Automation lib60870 to version 2.4.1 when available and monitor for similar IEC 60870-5-104 exploits.

#vulnerability#ot#patch-available#critical-infrastructure
Vulnerability CISA ICS 2026-07-30

MZ Automation GmbH libiec61850 ↗

MZ Automation GmbH libiec61850 versions before 1.6.2 have multiple out-of-bounds read flaws causing denial-of-service.

Successful exploitation of these vulnerabilities allows an attacker to cause a denial-of-service condition on MZ Automation GmbH libiec61850 devices. The flaws stem from improper validation of UTC timestamps in unauthenticated IEC 61850 GOOSE messages, leading to heap out-of-bounds reads and process crashes.

AFFECTEDMZ Automation GmbH libiec61850

▸ DO  Update MZ Automation GmbH libiec61850 to version 1.6.2 or later.

#vulnerability#ot#patch-available
Vulnerability CISA ICS 2026-07-30

Johnson Controls OpenBlue Employee ↗

Johnson Controls OpenBlue Employee has critical XSS and file upload flaws exploitable in critical infrastructure sectors.

Successful exploitation of CVE-2026-21662, CVE-2026-34495, and CVE-2026-34497 allows attackers to upload malicious files, execute cross-site scripting attacks, or inject arbitrary HTML. These vulnerabilities affect Johnson Controls OpenBlue Employee versions <=V2025.3.1 and impact critical manufacturing, commercial facilities, government services, transportation, and energy sectors.

AFFECTEDJohnson Controls OpenBlue Employee

▸ DO  Patch Johnson Controls OpenBlue Employee to version >V2025.3.1 immediately and restrict file upload types on affected systems.

#vulnerability#xss#file-upload#critical-infrastructure#patch-available
Vulnerability CISA ICS 2026-07-28

igloohome Smart Lock Mobile Application ↗

igloohome Smart Lock Mobile App 3.2.3 and prior has a source code exposure flaw allowing unauthorized backend access.

A critical vulnerability in the igloohome Smart Lock Mobile Application (Android) versions 3.2.3 and prior allows unauthorized actors to access backend services due to sensitive information inclusion in source code. igloohome has patched the issue by enhancing backend access controls to require proper authentication.

AFFECTEDigloohome Smart Lock Mobile Application

▸ DO  Update igloohome Smart Lock Mobile Application to version 3.2.4 or later immediately.

#vulnerability#patch-available#mitigations
◀ PREV PAGE 01 / 03 NEXT ▶