Skip to content
IACS RadarIndustrial Cyber Exposure & Intelligence

CISA + vendors

ICS Advisories

Advisories specifically aimed at industrial control systems — from CISA ICS-CERT and directly from vendors (Siemens ProductCERT, ABB PSIRT) — including revision history (initial publication, Update A, Update B) and linked CVEs.

132

Found

Advisory data: live connection— last retrieved: 24 September 2026 at 04:08.

Filters

132 advisories found

9AKK108473A3188

Mint Workbench I Path traversal Vulnerability

ABBMint Workbench I

ABB PSIRThigh

Published

22 September 2026

Last update

22 September 2026

Linked CVEs

Affected sectors

Risk evaluation

A local attacker who successfully exploited this vulnerability could gain elevated privileges by Path Traversal, arbitrarily reading files of system, to cause confidentiality impact of system files.

Mitigation summary

Mint Workbench I 5876 and the versions before, are impacted, customers who use these products, should: - Disable Service MWI http when it is not in active use. - Restrict physical machine access to authorized personnel only. - Avoid storing sensitive or confidential data on any hosts running service MWI http. - Enable User Account Control (UAC) to block unauthorized privilege escalation attempts. These actions above are the only measures available. No further patch will be released because this product reaches end-of-life globally (out of China) by the end of 2026 and in China by the end of 2027. To exploit the vulnerability the attacker needs to have local access to the machine beforehand and have file write access in the path. Please also refer to section “General security recommendations” for further advise on how to keep your system secure.

Revision history (1)
  1. Initial publication22 September 2026

    Initial version

Official source: ABB PSIRT

SSA-814963

SSA-814963: Insecure Inherited Permission in Mendix (Revoked)

SiemensMendix Runtime

Siemens ProductCERTlow

Published

14 July 2026

Last update

22 September 2026

Linked CVEs

Affected sectors

Risk evaluation

This advisory is revoked. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute.

Mitigation summary

See the official CISA advisory for mitigating measures.

Revision history (2)
  1. Initial publication14 July 2026

    Publication Date

  2. Update A22 September 2026

    Revoked advisory as the CVE is rejected

Official source: Siemens ProductCERT

7PAA010706

Freelance Missing Length Check

ABBSystem Version

ABB PSIRThigh

Published

18 September 2026

Last update

18 September 2026

Linked CVEs

Affected sectors

Risk evaluation

ABB is aware of a vulnerability in the product versions listed as affected in the advisory. An update is available that resolves the reported vulnerability in the product versions under maintenance. An attacker who successfully exploited this vulnerability could cause the product to stop or make the product inaccessible.

Mitigation summary

Refer to section “General security recommendations” for further advice on how to keep your system secure, as well checking the section “Workarounds”.

Revision history (1)
  1. Initial publication18 September 2026

    Initial version.

Official source: ABB PSIRT

ICSA-26-211-07

Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)

Mitsubishi ElectricMitsubishi Electric MELSEC MX Controller MX-R model MXR300-16

CISAhigh

Published

30 July 2026

Last update

17 September 2026

Linked CVEs

Affected sectors

Risk evaluation

Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly.

Mitigation summary

For customers using the affected products, please refer to Mitsubishi Electric's security advisory, "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-005_en.pdf" and take the measures described there.

Revision history (4)
  1. Initial publication30 July 2026

    Initial Publication

  2. Update A30 July 2026

    CISA Republication - Initial CISA Republication of Mitsubishi Electric 2026-005 advisory

  3. Update B17 September 2026

    MXF100S-N32, MXF100S-P32, MXF100S-8-N32, MXF100S-8-P32, MXF100S-16-N32, MXF100S-16-P32, LD78G4, and LD78G16 have been added as affected products and MI2532-W, MI2332-W, and NZ2GACP610-60 have been removed from affected products.

  4. Update C17 September 2026

    CISA Republication update based on Mitsubishi Electric 2026-005 advisory

Official source: CISA

4JDE002044

dynovaPRO™ Reset Credentials Vulnerability

ABBdynovaPRO™ cloud system < 2026-08-27 12:00 (CEST)

ABB PSIRTcritical

Published

17 September 2026

Last update

17 September 2026

Linked CVEs

Affected sectors

Risk evaluation

ABB is aware of public reports of a vulnerability in the product listed as affected in the advisory. An update has been deployed to the cloud system that resolves a publicly reported vulnerability in the product versions listed above. An attacker who successfully exploited this vulnerability could take remote control of the product. The vulnerability has been identified in the keycloak authentication component which is integrated into dynovaPRO™. The vulnerability exists in the 'Forgot Password' functionality and allows unauthenticated attackers to bypass authentication and hijack user accounts. Users who have received a password reset mail before the mentioned date, without having requested it, are thereby potentially attacked by exploiting this vulnerability. ABB investigated potentially malicious user reset activities and blocked those user access immediately to reduce the exploitation risk. The credentials of those users have been deleted after the software fix was deployed and the users were informed that they must reset their password to gain access to dynovaPRO™ again.

Mitigation summary

The following conditions reduce the risk of exploitation of this vulnerability: - Limited Attack Surface: The vulnerability is specific to the password reset functionality. Other authentication methods are not affected. - Email Notifications: Legitimate users receive email notifications during password reset attempts, which may alert them to unauthorized access attempts. Refer to section “General security recommendations” for further advise on how to keep your system secure.

Revision history (1)
  1. Initial publication17 September 2026

    Initial version

Official source: ABB PSIRT

SSA-823812

SSA-823812: Denial of Service Vulnerability in WTV676 and WTV776 devices

SiemensWTV676-HB6035 Web Interface

Siemens ProductCERTmiddel

Published

16 September 2026

Last update

16 September 2026

Linked CVEs

Affected sectors

Risk evaluation

The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigation summary

Update to V3.94 or later version

Revision history (1)
  1. Initial publication16 September 2026

    Publication Date

Official source: Siemens ProductCERT

3BHS973333

AC 800PEC, AC 800PEC ARM, AC 800PEC Tool, Control Terminal (xCT) and AC 800PEC Tool Cheetah Impacted by multiple vulnerabilities in Wibu CodeMeter

ABBAC 800PEC

ABB PSIRThigh

Published

10 September 2026

Last update

10 September 2026

Affected sectors

Risk evaluation

An update is available that resolves a publicly reported vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited these vulnerabilities could - Allow arbitrary files to be deleted with system privileges (CVE-2026-81572), - Read potentially sensitive configuration data and overwrite selected values in Server.ini (CVE-2026-81573) - Crash CodeMeter and disclose sensitive information such as process memory and stack canar-ies (CVE-2026-81574) - Crash CodeMeter (CVE-2026-81575), or - Read potentially sensitive license information (CVE-2026-81576)

Mitigation summary

For CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, and CVE-2026-81576: If you enabled the network server functionality at some point but no longer need it, disable it: - Open the Registry Editor and navigate to Computer\HKEY_LOCAL_MACHINE\SOFTWARE\ WIBUSYSTEMS\CodeMeter\Server\CurrentVersion\, then change the value of IsNetworkServerfrom 1 to 0. - Restart CodeMeter.

Revision history (1)
  1. Initial publication10 September 2026

    Initial version.

Official source: ABB PSIRT

2NGA003144

ABB AbilityTM zenon Security Risk Due to High-Severity Vulnerabilities in WIBU CodeMeter Runtime

ABBAbilityTM zenon

ABB PSIRThigh

Published

9 September 2026

Last update

9 September 2026

Affected sectors

Risk evaluation

ABB is aware of publicly disclosed security vulnerabilities affecting the WIBU-Systems CodeMeter Runtime for Windows, identified as CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575 and CVE-2026-81576. The CodeMeter Runtime component is used within affected ABB zenon Software Platform installations for software licensing and license server functionality. Successful exploitation of the reported vulnerabilities could enable local privilege escalation on Windows systems and impact systems configured as CodeMeter license servers, potentially leading to unauthorized access, service disruption, or loss of system integrity. Refer to the WIBU-Systems advisory for detailed technical information on each vulnerability. Please see the References section for the WIBU-Systems security advisory.

Mitigation summary

ABB recommends the following mitigation measures: - Update the WIBU-Systems CodeMeter Runtime to version 8.41a or later. - The latest CodeMeter Runtime software is available from the WIBU-Systems download page: User Software - Wibu-Systems, please see the References section for the corresponding link. - Where upgrading is not feasible, ABB recommends that asset owners perform a risk assessment and implement compensating controls such as network isolation, access restrictions, and enhanced monitoring of affected systems. ABB recommends that customers apply the update at earliest convenience. The vulnerabilities associated with CVE-2026-81573, CVE-2026-81574, CVE-2026-81575 and CVE-2026-81576 are exploitable only when the WIBU-Systems CodeMeter Runtime is configured as a network server, which is not the de-fault configuration. The CVE-2026-81572 vulnerability requires local access to the affected Windows system and execution by a low-privileged user. Consequently, systems with restricted local access, proper privilege management, and limited network exposure are less likely to be successfully compromised. Refer to section “General security recommendations” for further advise on how to keep your system secure.

Revision history (1)
  1. Initial publication9 September 2026

    Initial version.

Official source: ABB PSIRT

SSA-019113

SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6

SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)

Siemens ProductCERTcritical

Published

14 July 2026

Last update

8 September 2026

Linked CVEs

CVE-2021-41617CVE-2023-28531CVE-2023-51384CVE-2023-52927CVE-2023-53292CVE-2024-26783CVE-2024-27056CVE-2024-28956CVE-2024-36903CVE-2024-36927CVE-2024-42079CVE-2024-46786CVE-2024-47736CVE-2024-47809CVE-2024-49968CVE-2024-49994CVE-2024-49998CVE-2024-50014CVE-2024-50063CVE-2024-50164CVE-2024-50298CVE-2024-53124CVE-2024-53170CVE-2024-54458CVE-2024-56631CVE-2024-56703CVE-2024-56719CVE-2024-57917CVE-2024-57924CVE-2024-57973CVE-2024-57977CVE-2024-57979CVE-2024-58011CVE-2024-58016CVE-2024-58020CVE-2024-58056CVE-2024-58058CVE-2024-58061CVE-2024-58086CVE-2025-21645CVE-2025-21648CVE-2025-21655CVE-2025-21676CVE-2025-21682CVE-2025-21702CVE-2025-21705CVE-2025-21706CVE-2025-21707CVE-2025-21718CVE-2025-21731CVE-2025-21745CVE-2025-21758CVE-2025-21760CVE-2025-21764CVE-2025-21765CVE-2025-21780CVE-2025-21795CVE-2025-21796CVE-2025-21802CVE-2025-21814CVE-2025-21846CVE-2025-21853CVE-2025-21861CVE-2025-21863CVE-2025-21864CVE-2025-21867CVE-2025-21875CVE-2025-21887CVE-2025-21913CVE-2025-21919CVE-2025-21925CVE-2025-21926CVE-2025-21938CVE-2025-21959CVE-2025-21999CVE-2025-22005CVE-2025-22015CVE-2025-22055CVE-2025-22056CVE-2025-22060CVE-2025-22083CVE-2025-22090CVE-2025-22095CVE-2025-22107CVE-2025-22111CVE-2025-22121CVE-2025-23136CVE-2025-23143CVE-2025-37785CVE-2025-37909CVE-2025-37917CVE-2025-37945CVE-2025-37959CVE-2025-37964CVE-2025-37972CVE-2025-37980CVE-2025-38125CVE-2025-38162CVE-2025-38192CVE-2025-38201CVE-2025-38232CVE-2025-38322CVE-2025-38591CVE-2025-38614CVE-2025-38681CVE-2025-38704CVE-2025-38721CVE-2025-38725CVE-2025-38727CVE-2025-38732CVE-2025-38736CVE-2025-39681CVE-2025-39691CVE-2025-39721CVE-2025-39748CVE-2025-39756CVE-2025-39764CVE-2025-39770CVE-2025-39773CVE-2025-39782CVE-2025-39795CVE-2025-39826CVE-2025-39827CVE-2025-39845CVE-2025-39866CVE-2025-39871CVE-2025-39931CVE-2025-39953CVE-2025-39955CVE-2025-39964CVE-2025-39977CVE-2025-39978CVE-2025-39980CVE-2025-40022CVE-2025-40070CVE-2025-40078CVE-2025-40080CVE-2025-40105CVE-2025-40135CVE-2025-40149CVE-2025-40196CVE-2025-40219CVE-2025-40261CVE-2025-40300CVE-2025-61984CVE-2025-61985CVE-2025-68206CVE-2025-68261CVE-2025-68264CVE-2025-68265CVE-2025-68266CVE-2025-68291CVE-2025-68337CVE-2025-68349CVE-2025-68363CVE-2025-68371CVE-2025-68724CVE-2025-68725CVE-2025-68742CVE-2025-68764CVE-2025-68773CVE-2025-68776CVE-2025-68782CVE-2025-68787CVE-2025-68788CVE-2025-68798CVE-2025-68803CVE-2025-68814CVE-2025-68816CVE-2025-68818CVE-2025-68820CVE-2025-71064CVE-2025-71075CVE-2025-71079CVE-2025-71085CVE-2025-71086CVE-2025-71088CVE-2025-71095CVE-2025-71097CVE-2025-71098CVE-2025-71104CVE-2025-71112CVE-2025-71113CVE-2025-71114CVE-2025-71120CVE-2025-71123CVE-2025-71131CVE-2025-71161CVE-2025-71162CVE-2025-71163CVE-2025-71185CVE-2025-71186CVE-2025-71189CVE-2025-71190CVE-2025-71191CVE-2025-71197CVE-2025-71221CVE-2025-71265CVE-2025-71266CVE-2025-71267CVE-2026-3497CVE-2026-22977CVE-2026-22979CVE-2026-22980CVE-2026-22982CVE-2026-22992CVE-2026-22994CVE-2026-23003CVE-2026-23005CVE-2026-23010CVE-2026-23011CVE-2026-23019CVE-2026-23026CVE-2026-23038CVE-2026-23054CVE-2026-23060CVE-2026-23083CVE-2026-23084CVE-2026-23086CVE-2026-23087CVE-2026-23095CVE-2026-23100CVE-2026-23103CVE-2026-23110CVE-2026-23111CVE-2026-23113CVE-2026-23154CVE-2026-23204CVE-2026-23231CVE-2026-23242CVE-2026-23243CVE-2026-23245CVE-2026-23255CVE-2026-23270CVE-2026-23271CVE-2026-23273CVE-2026-23274CVE-2026-23277CVE-2026-23284CVE-2026-23287CVE-2026-23290CVE-2026-23293CVE-2026-23300CVE-2026-23304CVE-2026-23319CVE-2026-23321CVE-2026-23335CVE-2026-23340CVE-2026-23343CVE-2026-23351CVE-2026-23359CVE-2026-23365CVE-2026-23368CVE-2026-23370CVE-2026-23378CVE-2026-23379CVE-2026-23381CVE-2026-23391CVE-2026-23392CVE-2026-23397CVE-2026-23398CVE-2026-23399CVE-2026-23414CVE-2026-23422CVE-2026-23434CVE-2026-23438CVE-2026-23439CVE-2026-23446CVE-2026-23449CVE-2026-23450CVE-2026-23452CVE-2026-23454CVE-2026-23455CVE-2026-23456CVE-2026-23457CVE-2026-23458CVE-2026-23463CVE-2026-23474CVE-2026-23475CVE-2026-27135CVE-2026-31389CVE-2026-31391CVE-2026-31396CVE-2026-31402CVE-2026-31403CVE-2026-31411CVE-2026-31414CVE-2026-31415CVE-2026-31416CVE-2026-31417CVE-2026-31418CVE-2026-31421CVE-2026-31422CVE-2026-31423CVE-2026-31424CVE-2026-31427CVE-2026-31428CVE-2026-31431CVE-2026-31441CVE-2026-31446CVE-2026-31447CVE-2026-31448CVE-2026-31449CVE-2026-31450CVE-2026-31452CVE-2026-31466CVE-2026-31469CVE-2026-31485CVE-2026-31494CVE-2026-31495CVE-2026-31496CVE-2026-31503CVE-2026-31504CVE-2026-31507CVE-2026-31508CVE-2026-31515CVE-2026-31518CVE-2026-31521CVE-2026-31533CVE-2026-31546CVE-2026-31555CVE-2026-31563CVE-2026-31565CVE-2026-31628CVE-2026-31634CVE-2026-31649CVE-2026-31651CVE-2026-31658CVE-2026-31664CVE-2026-31665CVE-2026-31669CVE-2026-31670CVE-2026-31671CVE-2026-31674CVE-2026-31680CVE-2026-31681CVE-2026-31682CVE-2026-31700CVE-2026-31737CVE-2026-31752CVE-2026-31761CVE-2026-31768CVE-2026-40355CVE-2026-41989CVE-2026-43011CVE-2026-43024CVE-2026-43025CVE-2026-43026CVE-2026-43027CVE-2026-43028CVE-2026-43030CVE-2026-43033CVE-2026-43035CVE-2026-43038CVE-2026-43040CVE-2026-43057CVE-2026-43071CVE-2026-43085CVE-2026-43089CVE-2026-43116CVE-2026-43216CVE-2026-43284CVE-2026-43303CVE-2026-43492CVE-2026-43499CVE-2026-43501CVE-2026-45841CVE-2026-46015CVE-2026-46021CVE-2026-46033CVE-2026-46037CVE-2026-46040CVE-2026-46046CVE-2026-46086CVE-2026-46101CVE-2026-46116CVE-2026-46132CVE-2026-46172CVE-2026-46173CVE-2026-46174CVE-2026-46193CVE-2026-46300CVE-2026-46303CVE-2026-46306CVE-2026-46323CVE-2026-46333CVE-2026-52910CVE-2026-52912CVE-2026-52930CVE-2026-52933CVE-2026-52942CVE-2026-52943CVE-2026-52946CVE-2026-52970CVE-2026-52986CVE-2026-52998CVE-2026-52999CVE-2026-53001CVE-2026-53002CVE-2026-53006CVE-2026-53012CVE-2026-53050CVE-2026-53134CVE-2026-53218CVE-2026-53219CVE-2026-53223CVE-2026-53236CVE-2026-53239CVE-2026-53249CVE-2026-53268CVE-2026-53269CVE-2026-53275CVE-2026-53295CVE-2026-53352CVE-2026-53400CVE-2026-63810CVE-2026-64279CVE-2026-64317CVE-2026-64370CVE-2026-64371CVE-2026-64375CVE-2026-64411CVE-2026-64412CVE-2026-64413CVE-2026-64422CVE-2026-64423CVE-2026-64425CVE-2026-64538CVE-2026-64545CVE-2026-64552CVE-2026-64560

Affected sectors

Risk evaluation

Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigation summary

Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.

Revision history (2)
  1. Initial publication14 July 2026

    Publication Date

  2. Update A8 September 2026

    Added 79 CVEs; Added fix for CVE-2026-43284, CVE-2026-46300 and CVE-2026-31431

Official source: Siemens ProductCERT

SSA-142885

SSA-142885: Multiple Vulnerabilities in Reyrolle 7SR5 Before V2.70

SiemensReyrolle 7SR5

Siemens ProductCERTcritical

Risk evaluation

Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version.

Mitigation summary

Update to V2.70 or later version

Revision history (1)
  1. Initial publication8 September 2026

    Publication Date

Official source: Siemens ProductCERT

SSA-157465

SSA-157465: Reflected Cross-site scripting Vulnerability in Teamcenter

SiemensTeamcenter V2412

Siemens ProductCERTmiddel

Published

8 September 2026

Last update

8 September 2026

Linked CVEs

Affected sectors

Risk evaluation

A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user's session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim's Teamcenter session. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigation summary

Update to V2412.0013 or later version

Revision history (1)
  1. Initial publication8 September 2026

    Publication Date

Official source: Siemens ProductCERT

SSA-216014

SSA-216014: Vulnerabilities in EFI variable of SIMATIC IPCs, SIMATIC Tablet PCs, and SIMATIC Field PGs

SiemensSIMATIC Field PG M5

Siemens ProductCERThigh

Published

11 March 2025

Last update

8 September 2026

Affected sectors

Risk evaluation

Multiple vulnerabilities has been identified in Siemens SIMATIC IPCs, SIMATIC Tablet PCs, and SIMATIC Field PGs that can allow an authenticated attacker to alter the secure boot and password configurations. Siemens has released new versions of BIOS for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigation summary

Restrict access to root/administrator permission for the operating system

Revision history (4)
  1. Initial publication11 March 2025

    Publication Date

  2. Update A10 June 2025

    Added SIMATIC IPC RC-543A and RW-543B; Updated SIMATIC IPC3000 Smart V3, IPC 347G, IPC 527G

  3. Update B11 November 2025

    Added fix for SIMATIC IPC227G / IPC277G / IPC277G PRO / IPC327G / IPC377G

  4. Update C10 February 2026

    Added fix versions for IPC RW-543B and IPC RC-543B

Official source: Siemens ProductCERT

SSA-229470

SSA-229470: Multiple Vulnerabilities in SICAM 8 Products Before V26.20

SiemensCPCI85 Central Processing/Communication

Siemens ProductCERThigh

Published

9 July 2026

Last update

8 September 2026

Affected sectors

Risk evaluation

Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: - SICAM A8000 Device firmware - CPCI85 for CP-8031/CP-8050 - SICORE for CP-8010/CP-8012 - SICAM EGS Device firmware - CPCI85 - SICAM S8000 - SICORE Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigation summary

Update to V26.20 or later version The firmware CPCI85 V26.20 is present within “CP-8031/CP-8050 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109804985/ and also within “SICAM EGS Package” V26.20 https://support.industry.siemens.com/cs/document/109972536/

Revision history (2)
  1. Initial publication9 July 2026

    Publication Date

  2. Update A8 September 2026

    Added Acknowledgement

Official source: Siemens ProductCERT

SSA-254516

SSA-254516: Arbitrary File Upload in OIS Web Module

SiemensSiveillance Control Pro V3.0

Siemens ProductCERTcritical

Published

8 September 2026

Last update

8 September 2026

Linked CVEs

Affected sectors

Risk evaluation

A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server. Siemens has released patches and updates for Siveillance OIS to apply to the products that incorporate the OIS service, and recommends to update to the latest versions.

Mitigation summary

Update to V3.0.12.2173 or later version

Revision history (1)
  1. Initial publication8 September 2026

    Publication Date

Official source: Siemens ProductCERT

SSA-282044

SSA-282044: DLL Hijacking Vulnerability in Siemens Web Installer used by the Online Software Delivery

SiemensAutomation License Manager V6.0

Siemens ProductCERThigh

Published

12 August 2025

Last update

8 September 2026

Linked CVEs

Affected sectors

Risk evaluation

The installers used to install several Siemens products are affected by a DLL hijacking vulnerability. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected installer component. This vulnerability poses a risk only during setup and installation phase of the affected applications downloaded e.g. via OSD (Online Software Delivery). Siemens has released new versions for several affected products and recommends using the latest versions during setup and installation. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigation summary

Harden the application host to prevent local access by untrusted personnel

Revision history (4)
  1. Initial publication12 August 2025

    Publication Date

  2. Update A9 September 2025

    Added Sahil Shah to acknowledgment; Added fix for SIMATIC Energy Suite V19, SIMATIC Energy Suite V20, SIMATIC MTP CREATOR V4.x, SIMATIC Control Function Library (CFL) V3.x, TIA Portal Test Suite V19, TIA Portal Test Suite V20, SIMATIC WinCC Visualization Architect V19, SIMATIC WinCC Visualization Architect V20, SIMATIC S7-PCT; Updated No fix planned for SIMATIC ProSave V17,SIMATIC WinCC flexible ES, SIMATIC Control Function Library (CFL) V1.x, SIMATIC Control Function Library (CFL) V2.x

  3. Update B14 October 2025

    Added fix for MTP Creator V2.x, CFL V4.x, Simatic WinCC Unified Line Coordination and Simatic WinCC Unified Sequence

  4. Update C11 November 2025

    Added Fixes for PCS 7 Logic Matrix V9.1, PCS7 Advanced Process Faceplates V9.1, SIMATIC PCS 7 Basis Faceplates V9.1 PCS 7 Basis Library V9.1, SIMATIC Management Agent V9.1, SIMATIC Management Console V9.1, PCS 7 V9.1, PCS 7 V10.0

Official source: Siemens ProductCERT

SSA-327438

SSA-327438: Multiple Vulnerabilities in SCALANCE LPE9403

SiemensSCALANCE LPE9403 (6GK5998-3GS00-2AC2)

Siemens ProductCERThigh

Risk evaluation

SCALANCE LPE9403 is affected by multiple vulnerabilities which lead to a compromise in availability, integrity and confidentiality. Siemens has released a new version for SCALANCE LPE9403 and recommends to update to the latest version. Siemens recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigation summary

Restrict access to authorized and trusted personal only

Revision history (3)
  1. Initial publication13 May 2025

    Publication Date

  2. Update A8 July 2025

    Added fix for CVE-2025-40572, CVE-2025-40573, CVE-2025-40574, CVE-2025-40575, CVE-2025-40576, CVE-2025-40577, CVE-2025-40579, CVE-2025-40580

  3. Update B8 September 2026

    Added fix for devices with SINEMA Remote Connect Edge Client installed

Official source: Siemens ProductCERT

SSA-328642

SSA-328642: "Copy Fail" Vulnerability in Multiple Industrial Products

SiemensSIMATIC AX Runtime Core Linux Common Debian

Siemens ProductCERThigh

Published

8 September 2026

Last update

8 September 2026

Linked CVEs

Affected sectors

Risk evaluation

Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigation summary

Limit access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only.

Revision history (1)
  1. Initial publication8 September 2026

    Publication Date

Official source: Siemens ProductCERT

SSA-330084

SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family

SiemensDesigo CC ClickOnce Client V6

Siemens ProductCERThigh

Published

8 September 2026

Last update

8 September 2026

Linked CVEs

Affected sectors

Risk evaluation

A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization.

Mitigation summary

Evaluate authorization policy for Graphics application following Least Privilege principle, so only required users have access to the configuration.

Revision history (1)
  1. Initial publication8 September 2026

    Publication Date

Official source: Siemens ProductCERT

SSA-331739

SSA-331739: Privilege Escalation Vulnerability in WIBU CodeMeter Runtime Affecting Siemens Products

SiemensSIMATIC PDM Maintenance Station V5.0

Siemens ProductCERThigh

Published

12 August 2025

Last update

8 September 2026

Linked CVEs

Affected sectors

Risk evaluation

WIBU Systems published information about a privilege escalation vulnerability under a certain circumstances and associated fix releases of CodeMeter Runtime, a product provided by WIBU Systems and used in several Siemens industrial products. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigation summary

Update to V3.18 P032 or later version

Revision history (3)
  1. Initial publication12 August 2025

    Publication Date

  2. Update A9 September 2025

    Removed Simatic Information Server and Simatic Process Historian as they are not affected.

  3. Update B8 September 2026

    Added fix for SIMATIC PDM Maintenance Station V5.0

Official source: Siemens ProductCERT

SSA-434797

SSA-434797: Buffer Overflow Vulnerability in OpenSSL affecting Siemens Products

SiemensAI Lightweight Inference Server

Siemens ProductCERThigh

Published

9 June 2026

Last update

8 September 2026

Linked CVEs

Affected sectors

Risk evaluation

OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigation summary

As a defense-in-depth measure, organizations may review whether affected systems are exposed to untrusted CMS/PKCS#7 content from external sources.

Revision history (4)
  1. Initial publication9 June 2026

    Publication Date

  2. Update A14 July 2026

    Added SCALANCE X-200 family, X-200IRT family, X-200RNA family, X-300/408 family, SC-600 family to Known Not Affected and fix for SINUMERIK Access MyMachine /OPC UA , SIMOVE Fleetmanager. Updated remediation to No fix planned for SIMATIC Comfort/Mobile RT

  3. Update B11 August 2026

    Added RUGGEDCOM ROX II family and SIMATIC HMI Operator Device to Known Not Affected and removed SIMATIC Comfort/Mobile RT and updated SIMATIC Advanced HMI Panels and SIMATIC HMI Basic Panels to no fix available; Added fix for SIMATIC PDM V9.3 and added PCS neo V6.0 and Simatic Logon to affected products.

  4. Update C8 September 2026

    Updated remediation for AI Lightweight Inference Server to no fix planned.

Official source: Siemens ProductCERT

SSA-503852

SSA-503852: Authentication Bypass Vulnerability in Industrial Edge Management

SiemensIndustrial Edge Management Cloud

Siemens ProductCERTcritical

Published

8 September 2026

Last update

8 September 2026

Linked CVEs

Affected sectors

Risk evaluation

Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigation summary

Block direct internet access to IEM Pro / IEM Virtual The most effective immediate measure is to block direct internet access to your IEM Pro or IEM V instance. This ensures that no external attacks can occur via this vulnerability.

Revision history (1)
  1. Initial publication8 September 2026

    Publication Date

Official source: Siemens ProductCERT

SSA-517424

SSA-517424: Path Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT

SiemensSIMOVE Fleetmanager V3.1

Siemens ProductCERThigh

Published

8 September 2026

Last update

8 September 2026

Linked CVEs

Affected sectors

Risk evaluation

SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigation summary

Configure appropriate user management by restricting services' access rights to project files

Revision history (1)
  1. Initial publication8 September 2026

    Publication Date

Official source: Siemens ProductCERT

3ADR011572

Automation Builder, Drive Application Builder, Virtual Drive, Virtual DrivePlus Impacted by multiple vulnerabilities in Wibu CodeMeter

ABBAutomation Builder

ABB PSIRThigh

Published

3 September 2026

Last update

3 September 2026

Affected sectors

Risk evaluation

An update is available that resolves publicly reported vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited these vulnerabilities could - allow arbitrary files to be deleted with system privileges (CVE-2026-81572), - read potentially sensitive configuration data and overwrite selected values in Server.ini (CVE-2026-81573), - crash CodeMeter and disclose sensitive information such as process memory and stack canaries (CVE-2026-81574), - crash CodeMeter (CVE-2026-81575), or - read potentially sensitive license information (CVE-2026-81576)

Mitigation summary

For CVE-2026-81572 the exposure can be limited by auditing the list of local users and removing any unnecessary accounts. For CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, and CVE-2026-81576: If you enabled the network server functionality at some point but no longer need it, disable it: - Open the Registry Editor and navigate to Computer\HKEY_LOCAL_MACHINE\SOFTWARE\ WIBUSYSTEMS\CodeMeter\Server\CurrentVersion\, then change the value of IsNetworkServerfrom 1 to 0. - Restart CodeMeter.

Revision history (1)
  1. Initial publication3 September 2026

    Initial version.

Official source: ABB PSIRT

SA26P012

mapp Services Use of Weak Authenticators in mapp Audit

B&R Industrial Automation GmbHmapp Audit

ABB PSIRThigh

Published

3 September 2026

Last update

3 September 2026

Linked CVEs

Affected sectors

Risk evaluation

An update is available that resolves a vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploits this vulnerability could gain access to the OPC UA server component on affected devices due to insufficient entropy of authenticators used by mapp Audit.

Mitigation summary

The problem is corrected in the following product versions: mapp Services >= 6.8.0 B&R recommends that customers apply the update at earliest convenience when the vulnerable functionality mapp Audit is used. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revision history (1)
  1. Initial publication3 September 2026

    Initial version.

Official source: ABB PSIRT

ICSA-26-202-01

Tycon Systems TPDIN-Monitor-WEB2 (Update A)

Tycon SystemsTPDIN-Monitor-WEB2

CISAcritical

Published

21 July 2026

Last update

3 September 2026

Affected sectors

Risk evaluation

Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.

Mitigation summary

Tycon Systems has released firmware 2.4.5, which resolves this vulnerability by requiring an administrator username and password to be set before the web interface is served. Further inquiries can be directed to security@tyconsystems.com.

Revision history (2)
  1. Initial publication21 July 2026

    Initial Publication

  2. Update A3 September 2026

    Updated affected version range and vulnerability details based on vendor input.

Official source: CISA

SSA-887643

SSA-887643: Account Hijacking Vulnerability in Mendix SAML module

SiemensMendix SAML (Mendix 10 compatible)

Siemens ProductCERThigh

Published

3 September 2026

Last update

3 September 2026

Linked CVEs

Affected sectors

Risk evaluation

Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version.

Mitigation summary

Update to V3.6.27 or later version

Revision history (1)
  1. Initial publication3 September 2026

    Publication Date

Official source: Siemens ProductCERT

ICSA-26-202-09

Rockwell Automation 1734 POINT I/O (Update A)

Rockwell Automation1734 POINT I/O

CISAlow

Published

21 July 2026

Last update

1 September 2026

Linked CVEs

Affected sectors

Risk evaluation

Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product.

Mitigation summary

Rockwell Automation recommends users are to migrate to 5034-OB8.

Revision history (2)
  1. Initial publication21 July 2026

    Initial Republication of Rockwell Automation Security Advisory

  2. Update A1 September 2026

    Update A - Updated impact statement and CVSS scores.

Official source: CISA

SSA-682041

SSA-682041: Cross Site Scripting Vulnerability in Element Maps

SiemensElement maps-ng V47

Siemens ProductCERThigh

Published

27 August 2026

Last update

27 August 2026

Linked CVEs

Affected sectors

Risk evaluation

The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label of map pins. This could allow an attacker to craft a malicious URL that, when loaded by a victim and the map pin is hovered over, executes arbitrary script code within the victim's browser session. This vulnerability affects only the @siemens/maps-ng package. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigation summary

Deploy a strict Content Security Policy (CSP)

Revision history (1)
  1. Initial publication27 August 2026

    Publication Date

Official source: Siemens ProductCERT

ICSA-26-232-01

Johnson Controls Simplex Incident Manager

Johnson Controls Inc.Simplex Incident Manager

CISAmiddel

Published

20 August 2026

Last update

20 August 2026

Linked CVEs

Affected sectors

Risk evaluation

Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems.

Mitigation summary

Johnson Controls has released a patched version (v2.01.01) to address this vulnerability. To help reduce the risk of exploitation, Johnson Controls suggests considering the following defensive measures: Upgrade the Simplex Incident Manager to version v1.01.05 or later. Restrict local access to systems running the Simplex Incident Manager to authorized personnel only. Implement endpoint protection and monitoring to detect memory-dumping tools or suspicious processes. Enforce strong access control policies and the principle of least privilege on host systems. Utilize full-disk encryption and secure boot to reduce the risk of offline memory analysis. Monitor for unauthorized local access attempts and implement audit logging.

Revision history (1)
  1. Initial publication20 August 2026

    Initial Republication of Johnson Controls Product Security Advisory JCI-PSA-2026-28

Official source: CISA

ICSA-26-230-02

Siemens Simcenter Nastran

SiemensSimcenter Femap

CISAhigh

Published

11 August 2026

Last update

18 August 2026

Linked CVEs

Affected sectors

Risk evaluation

Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigation summary

Update to V2606 or later version

Revision history (3)
  1. Initial publication11 August 2026

    Publication Date

  2. Update A13 August 2026

    Added Simcenter Femap with fix

  3. Update B18 August 2026

    Initial CISA Republication of Siemens ProductCERT SSA-069220 advisory

Official source: CISA

ICSA-26-225-14

Johnson Controls Metasys

Johnson Controls Inc.Metasys 12

CISAhigh

Published

13 August 2026

Last update

13 August 2026

Linked CVEs

Affected sectors

Risk evaluation

Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access.

Mitigation summary

Johnson Controls recommends the following actions:

Revision history (1)
  1. Initial publication13 August 2026

    Initial Publication.

Official source: CISA

ICSA-26-225-13

Siemens LOGO! Soft Comfort

SiemensLOGO! Soft Comfort

CISAmiddel

Published

11 August 2026

Last update

13 August 2026

Affected sectors

Risk evaluation

Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt project data or remove project passwords. The lack of password salting enables offline dictionary or brute-force attacks against the password hashes. Successful exploitation could result in unauthorized access to, or modification of, sensitive project logic and configurations. Siemens has released a new version for LOGO! Soft Comfort and recommends to update to the latest version.

Mitigation summary

Update to V9 or later version Note: A hardware upgrade to LOGO! V9 BM or later is also required to avoid compatibility mode, in which the vulnerabilities addressed by this advisory remain present.

Revision history (2)
  1. Initial publication11 August 2026

    Publication Date

  2. Update A13 August 2026

    Initial CISA Republication of Siemens ProductCERT SSA-751328 advisory

Official source: CISA

ICSA-26-225-12

Siemens Solid Edge

SiemensSolid Edge SE2025

CISAhigh

Published

11 August 2026

Last update

13 August 2026

Affected sectors

Risk evaluation

Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigation summary

Update to V225.0 Update 15 or later version

Revision history (2)
  1. Initial publication11 August 2026

    Publication Date

  2. Update A13 August 2026

    Initial CISA Republication of Siemens ProductCERT SSA-621657 advisory

Official source: CISA

ICSA-26-225-11

Siemens Simcenter Femap

SiemensSimcenter Femap

CISAhigh

Published

11 August 2026

Last update

13 August 2026

Affected sectors

Risk evaluation

Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for Simcenter Femap and recommends to update to the latest version.

Mitigation summary

Update to V2606.0001 or later version

Revision history (2)
  1. Initial publication11 August 2026

    Publication Date

  2. Update A13 August 2026

    Initial CISA Republication of Siemens ProductCERT SSA-584312 advisory

Official source: CISA

ICSA-26-225-10

Siemens Parasolid

SiemensParasolid V38.0

CISAhigh

Published

11 August 2026

Last update

13 August 2026

Linked CVEs

Affected sectors

Risk evaluation

Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigation summary

Update to V38.0.235 or later version

Revision history (2)
  1. Initial publication11 August 2026

    Publication Date

  2. Update A13 August 2026

    Initial CISA Republication of Siemens ProductCERT SSA-138516 advisory

Official source: CISA

ICSA-26-225-09

Siemens Siveillance Video

SiemensSiveillance Video V2023 R3

CISAcritical

Published

11 August 2026

Last update

13 August 2026

Linked CVEs

Affected sectors

Risk evaluation

Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigation summary

Update to V23.3 HotfixRev27 or later version

Revision history (2)
  1. Initial publication11 August 2026

    Publication Date

  2. Update A13 August 2026

    Initial CISA Republication of Siemens SSA-825228 advisory

Official source: CISA

ICSA-26-225-08

Siemens Desigo DXR and PXC Controllers

SiemensDesigo DXR2

CISAmiddel

Published

11 August 2026

Last update

13 August 2026

Linked CVEs

Affected sectors

Risk evaluation

A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigation summary

Update to V01.21.233.16-7862 or later version Please contact your local Siemens office for additional support in obtaining the update.

Revision history (2)
  1. Initial publication11 August 2026

    Publication Date

  2. Update A13 August 2026

    Initial CISA Republication of Siemens SSA-781903 advisory

Official source: CISA

ICSA-26-225-05

ANDRITZ HIPASE-250 and 250 SCALA

ANDRITZHIPASE-250

CISAhigh

Published

13 August 2026

Last update

13 August 2026

Affected sectors

Risk evaluation

Successful exploitation of these vulnerabilities could allow an attacker to read data from the device or gain access to affected workstations.

Mitigation summary

ANDRITZ has addressed these issues in version V8.00.00 (released 2024-12) and in version V8.15.00 (released 2026-07) and encourages users to keep their systems updated to the latest version (currently HIPASE-250 Version V8.15.00). For more information, users can contact ANDRITZ at the following website: https://www.andritz.com/group-en/contact

Revision history (1)
  1. Initial publication13 August 2026

    Initial Publication

Official source: CISA

ICSA-26-225-04

Hitachi Energy APM Edge Product

Hitachi EnergyAPM Edge

CISAhigh

Published

28 July 2026

Last update

13 August 2026

Affected sectors

Risk evaluation

Hitachi Energy is aware of Dirty Frag vulnerabilities that affect APM Edge product versions listed in this document. Successful exploitation of these vulnerabilities could result in impact on confidentiality, integrity and availability of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.

Mitigation summary

Disable the esp4 and esp6 modules [2]

Revision history (2)
  1. Initial publication28 July 2026

    Initial public release

  2. Update A13 August 2026

    Initial CISA Republication of Hitachi Energy PSIRT 8DBD000256 advisory

Official source: CISA

ICSA-26-225-03

Johnson Controls Inc. Airwall

Johnson Controls Inc.Airwall

CISAmiddel

Published

13 August 2026

Last update

13 August 2026

Affected sectors

Risk evaluation

Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized access to protected system resources.

Mitigation summary

To help reduce risk of exploitation, Johnson Controls recommends the following defensive measures: Apply v4.1.0 or later patches for all Airwalls.

Revision history (1)
  1. Initial publication13 August 2026

    Initial Republication of Johnson Controls JCI-PSA-2026-18 and JCI-PSA-2026-25

Official source: CISA

ICSA-26-225-02

Haiwell IoT Cloud HMI Gateway

HaiwellHaiwell IoT Cloud HMI Gateway

CISAcritical

Published

13 August 2026

Last update

13 August 2026

Linked CVEs

Affected sectors

Risk evaluation

Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges.

Mitigation summary

Haiwell has addressed the issue in patch version number Scada-v3.50.1.19, which is available for download on their website: https://en.haiwell.com/app/system/entrance.php?m=include&c=access&a=dodown&lang=en&id=361

Revision history (1)
  1. Initial publication13 August 2026

    Initial Publication

Official source: CISA

ICSA-26-225-01

AVEVA Enterprise SCADA

AVEVAEnterprise SCADA

CISAhigh

Published

13 August 2026

Last update

13 August 2026

Linked CVEs

Affected sectors

Risk evaluation

Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization.

Mitigation summary

AVEVA recommends that customers using affected product versions should perform the following to mitigate the risk of exploit: 1. Evaluate the impact of these vulnerabilities based on your operational environment, architecture, and product implementation. 2. Plan an upgrade of Servers and Clients to one of the available fixed versions listed in this document. 3. Configure Servers and Clients as described in this document.

Revision history (1)
  1. Initial publication13 August 2026

    Initial Republication of AVEVA security bulletin AVEVA-2026-005

Official source: CISA

SSA-069220

SSA-069220: Stack Overflow Vulnerability in Simcenter Nastran Before V2606

SiemensSimcenter Femap

Siemens ProductCERThigh

Published

11 August 2026

Last update

13 August 2026

Linked CVEs

Affected sectors

Risk evaluation

Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigation summary

Update to V2606 or later version

Revision history (2)
  1. Initial publication11 August 2026

    Publication Date

  2. Update A13 August 2026

    Added Simcenter Femap with fix

Official source: Siemens ProductCERT

ICSA-26-225-07

Siemens License Server (SLS)

SiemensSiemens License Server (SLS)

CISAhigh

Published

11 August 2026

Last update

12 August 2026

Affected sectors

Risk evaluation

Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version.

Mitigation summary

Update to V5.1 or later version

Revision history (2)
  1. Initial publication11 August 2026

    Publication Date

  2. Update A12 August 2026

    Initial CISA Republication of Siemens ProductCERT SSA-077553 advisory

Official source: CISA

ICSA-26-225-06

Siemens RUGGEDCOM APE1808

SiemensRUGGEDCOM APE1808

CISAmiddel

Published

11 August 2026

Last update

12 August 2026

Affected sectors

Risk evaluation

Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens recommends to contact customer support for additional information, and follow Fortinet advisory for workarounds and mitigation measures.

Mitigation summary

Contact customer support to receive detailed information

Revision history (2)
  1. Initial publication11 August 2026

    Publication Date

  2. Update A12 August 2026

    Initial CISA Republication of Siemens ProductCERT SSA-127084 advisory

Official source: CISA

ICSA-26-204-01

Johnson Controls C-CURE 9000 and Victor application server (Update A)

Johnson ControlsC-CURE 9000

CISAcritical

Published

23 July 2026

Last update

11 August 2026

Affected sectors

Risk evaluation

Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution.

Mitigation summary

Johnson Controls recommends the following upgrades to address the vulnerable deserialization path: Upgrade to C-CURE 9000 v3.20 or later

Revision history (2)
  1. Initial publication23 July 2026

    Initial Republication of Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16.

  2. Update A11 August 2026

    Update A - Made changes to affected products and mitigations.

Official source: CISA

SSA-077553

SSA-077553: Multiple Vulnerabilities in Siemens License Server (SLS)

SiemensSiemens License Server (SLS)

Siemens ProductCERThigh

Published

11 August 2026

Last update

11 August 2026

Affected sectors

Risk evaluation

Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version.

Mitigation summary

Update to V5.1 or later version

Revision history (1)
  1. Initial publication11 August 2026

    Publication Date

Official source: Siemens ProductCERT

SSA-104023

SSA-104023: Multiple Vulnerabilities in Palo Alto Networks PAN-OS on RUGGEDCOM APE1808 Devices

SiemensRUGGEDCOM APE1808

Siemens ProductCERTcritical

Risk evaluation

Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/

Mitigation summary

Contact customer support to receive patch and update information

Revision history (2)
  1. Initial publication14 July 2026

    Publication Date

  2. Update A11 August 2026

    Added CVE-2026-0279, CVE-2026-0280, CVE-2026-0281, CVE-2026-0282, CVE-2026-0283, CVE-2026-0284, CVE-2026-0285, CVE-2026-0286, CVE-2026-0287 and CVE-2026-0288

Official source: Siemens ProductCERT

SSA-127084

SSA-127084: Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices

SiemensRUGGEDCOM APE1808

Siemens ProductCERTmiddel

Published

11 August 2026

Last update

11 August 2026

Affected sectors

Risk evaluation

Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens recommends to contact customer support for additional information, and follow Fortinet advisory for workarounds and mitigation measures.

Mitigation summary

Contact customer support to receive detailed information

Revision history (1)
  1. Initial publication11 August 2026

    Publication Date

Official source: Siemens ProductCERT

SSA-138516

SSA-138516: Out of Bounds Read Vulnerability in Parasolid X_T File Parsing

SiemensParasolid V38.0

Siemens ProductCERThigh

Published

11 August 2026

Last update

11 August 2026

Linked CVEs

Affected sectors

Risk evaluation

Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigation summary

Update to V38.0.235 or later version

Revision history (1)
  1. Initial publication11 August 2026

    Publication Date

Official source: Siemens ProductCERT

SSA-306654

SSA-306654: Insyde BIOS Vulnerabilities in Siemens Industrial Products

SiemensRUGGEDCOM APE1808 - BIOS

Siemens ProductCERThigh

Risk evaluation

Insyde has published information on vulnerabilities in Insyde BIOS in February 2022. This advisory lists the Siemens Industrial products affected by these vulnerabilities. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigation summary

As a prerequisite for an attack, an attacker must be able to run untrusted code on affected systems. Siemens recommends limiting the possibilities to run untrusted code

Revision history (4)
  1. Initial publication22 February 2022

    Publication Date

  2. Update A8 March 2022

    Corrected AV:L for all CVEs, added RUGGEDCOM APE1808 and SIMATIC IPC477E PRO

  3. Update B12 July 2022

    Added CVE-2021-43613, CVE-2021-43614 and CVE-2021-38489, add fix for SIMATIC Field PG M6, SIMATIC ITP1000 for all CVEs except CVE-2021-43613

  4. Update C9 August 2022

    Added fix for SIMATIC IPC227G, SIMATIC IPC277G, SIMATIC IPC327G, SIMATIC IPC377G, clarified affected versions for RUGGEDCOM APE1808

Official source: Siemens ProductCERT

SSA-392349

SSA-392349: Denial of Service Vulnerability in Industrial Devices

SiemensIE/PB LINK HA (6GK1411-5BB00)

Siemens ProductCERThigh

Published

12 May 2026

Last update

11 August 2026

Linked CVEs

Affected sectors

Risk evaluation

Multiple industrial devices contain a vulnerability that could allow an attacker to cause a denial of service condition. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigation summary

As a mitigation, disable the ethernet ports on the CPU and use a communication module (like CP) for communication instead

Revision history (3)
  1. Initial publication12 May 2026

    Publication Date

  2. Update A14 July 2026

    Added fix for SCALANCE SC-600 family

  3. Update B11 August 2026

    Added fix for IE/PB LINK HA

Official source: Siemens ProductCERT

SSA-584312

SSA-584312: File Parsing Vulnerabilities in Simcenter Femap Before V2606 MP1

SiemensSimcenter Femap

Siemens ProductCERThigh

Published

11 August 2026

Last update

11 August 2026

Affected sectors

Risk evaluation

Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for Simcenter Femap and recommends to update to the latest version.

Mitigation summary

Update to V2606.0001 or later version

Revision history (1)
  1. Initial publication11 August 2026

    Publication Date

Official source: Siemens ProductCERT

SSA-621657

SSA-621657: File Parsing Vulnerabilities in Solid Edge Before Version SE2026 Update 7

SiemensSolid Edge SE2025

Siemens ProductCERThigh

Published

11 August 2026

Last update

11 August 2026

Affected sectors

Risk evaluation

Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigation summary

Update to V225.0 Update 15 or later version

Revision history (1)
  1. Initial publication11 August 2026

    Publication Date

Official source: Siemens ProductCERT

SSA-628843

SSA-628843: Out of Bound Read Vulnerability in TPM 2.0

SiemensSIMATIC CN 4100

Siemens ProductCERTmiddel

Published

14 April 2026

Last update

11 August 2026

Linked CVEs

Affected sectors

Risk evaluation

The products listed below contain a vulnerability that could allow an attacker to perform an out-of-bound read, potentially leading to information disclosure or denial of service of the TPM. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.

Mitigation summary

Currently no fix is planned

Revision history (2)
  1. Initial publication14 April 2026

    Publication Date

  2. Update A11 August 2026

    Added no fix planned for SIMATIC ITP1000 and for SIMATIC Field PG M5. Added fix for SIMATIC Field PG M6

Official source: Siemens ProductCERT

SSA-686975

SSA-686975: IPU 2022.3 Vulnerabilities in Siemens Industrial Products using Intel CPUs

SiemensSIMATIC Field PG M5

Siemens ProductCERThigh

Published

14 February 2023

Last update

11 August 2026

Linked CVEs

Affected sectors

Risk evaluation

Intel has published information on vulnerabilities in Intel products in November 2022. This advisory lists the related Siemens Industrial products affected by these vulnerabilities that can be patched by applying the corresponding BIOS update ("2022.3 IPU – BIOS Advisory" Intel-SA-00688). Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigation summary

As a prerequisite for an attack, an attacker must be able to run untrusted code on affected systems. Siemens recommends limiting the possibilities to run untrusted code if possible.

Revision history (4)
  1. Initial publication14 February 2023

    Publication Date

  2. Update A9 May 2023

    Added affected products SIMATIC IPC PX-39A and SIMATIC IPC PX-39A pro

  3. Update B11 July 2023

    Added fix for SIMATIC Field PG M5

  4. Update C8 August 2023

    Added fix for SIMATIC IPC BX-39A, SIMATIC IPC PX-39A, and SIMATIC IPC PX-39A pro

Official source: Siemens ProductCERT

SSA-751328

SSA-751328: Recoverable Hardcoded AES Master Key in Siemens LOGO! Soft Comfort

SiemensLOGO! Soft Comfort

Siemens ProductCERTmiddel

Published

11 August 2026

Last update

11 August 2026

Affected sectors

Risk evaluation

Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt project data or remove project passwords. The lack of password salting enables offline dictionary or brute-force attacks against the password hashes. Successful exploitation could result in unauthorized access to, or modification of, sensitive project logic and configurations. Siemens has released a new version for LOGO! Soft Comfort and recommends to update to the latest version.

Mitigation summary

Update to V9 or later version Note: A hardware upgrade to LOGO! V9 BM or later is also required to avoid compatibility mode, in which the vulnerabilities addressed by this advisory remain present.

Revision history (1)
  1. Initial publication11 August 2026

    Publication Date

Official source: Siemens ProductCERT

SSA-781903

SSA-781903: Denial of Service Vulnerability in Desigo DXR and PXC Controllers

SiemensDesigo DXR2

Siemens ProductCERTmiddel

Published

11 August 2026

Last update

11 August 2026

Linked CVEs

Affected sectors

Risk evaluation

A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigation summary

Update to V01.21.233.16-7862 or later version Please contact your local Siemens office for additional support in obtaining the update.

Revision history (1)
  1. Initial publication11 August 2026

    Publication Date

Official source: Siemens ProductCERT

SSA-825228

SSA-825228: Potential Remote Code Execution in Siveillance Video Management Servers

SiemensSiveillance Video V2023 R3

Siemens ProductCERTcritical

Published

11 August 2026

Last update

11 August 2026

Linked CVEs

Affected sectors

Risk evaluation

Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigation summary

Update to V23.3 HotfixRev27 or later version

Revision history (1)
  1. Initial publication11 August 2026

    Publication Date

Official source: Siemens ProductCERT

SSA-827968

SSA-827968: Vulnerability in Nozomi Guardian/CMC Before V26.2.0 on RUGGEDCOM APE1808 Devices

SiemensRUGGEDCOM APE1808

Siemens ProductCERThigh

Risk evaluation

Nozomi Networks has published information on vulnerabilities in Nozomi Guardian/CMC. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Siemens has released a new version for RUGGEDCOM APE1808 and recommends to update to the latest version.

Mitigation summary

Upgrade Nozomi Guardian to v26.2.0. Contact customer support to receive patch and update information

Revision history (4)
  1. Initial publication13 January 2026

    Publication Date

  2. Update A14 April 2026

    Added CVE-2025-40894

  3. Update B12 May 2026

    Added CVE-2025-40897 and CVE-2025-40899

  4. Update C9 June 2026

    Added CVE-2025-40900, CVE-2025-40901, CVE-2025-40902, CVE--2025-40903 and CVE-2025-40904

Official source: Siemens ProductCERT

SSA-834709

SSA-834709: Missing Authentication Vulnerability in Node-RED on SIMATIC IoT2050 Advanced with Industrial OS

SiemensSIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2)

Siemens ProductCERTcritical

Published

11 August 2026

Last update

11 August 2026

Linked CVEs

Affected sectors

Risk evaluation

SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released a new version for SIMATIC IoT2050 Advanced and strongly recommends to update to the latest version.

Mitigation summary

Harden the Node-RED installation (see Node-RED User Guide)

Revision history (1)
  1. Initial publication11 August 2026

    Publication Date

Official source: Siemens ProductCERT

SSA-864900

SSA-864900: Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices

SiemensRUGGEDCOM APE1808

Siemens ProductCERTcritical

Risk evaluation

Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens has released a new version for RUGGEDCOM APE1808 and recommends to update to the latest version.

Mitigation summary

Update Fortigate NGFW to V7.4.9 or later following the secure update recommendation procedure. Contact customer support to receive detailed information

Revision history (4)
  1. Initial publication13 May 2025

    Publication Date

  2. Update A8 July 2025

    Added CVE-2025-24471, CVE-2025-22862, CVE-2024-50562 and CVE-2025-25250

  3. Update B12 August 2025

    Added CVE-2024-55599

  4. Update C9 September 2025

    Added CVE-2025-25248 and CVE-2025-53744

Official source: Siemens ProductCERT

ICSA-26-218-02

Johnson Controls Inc. TL280

Johnson Controls Inc.TL280

CISAmiddel

Published

6 August 2026

Last update

6 August 2026

Linked CVEs

Affected sectors

Risk evaluation

Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device.

Mitigation summary

To help reduce the risk of exploitation, Johnson Control suggests considering the following defensive measures: Apply firmware update 5.63.

Revision history (1)
  1. Initial publication6 August 2026

    Initial Republication of Johnson Controls Security Advisory JCI-PSA-2026-08

Official source: CISA

ICSA-26-218-01

ABB Ability Zenon

ABBAbility Zenon

CISAhigh

Risk evaluation

ABB is aware of publicly reported vulnerabilities affecting MongoDB 4.2, which is bundled within the IIoT Services of the affected product versions. MongoDB 4.2 has reached end-of-life and contains multiple known security vulnerabilities. An attacker who successfully exploits these vulnerabilities could potentially access sensitive information, cause denial of service, or disrupt system availability.

Mitigation summary

ABB recommends the following mitigation measures: - Replace bundled MongoDB with a supported version if IIoT services are required: - Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. - The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer - Uninstall IIoT Services wherever it’s not required: - If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section “General security recommendations” for further advise on how to keep your system secure.

Revision history (2)
  1. Initial publication30 July 2026

    Initial version

  2. Update A6 August 2026

    Initial CISA Republication of ABB PSIRT 9AKK108472A9037 advisory

Official source: CISA

ICSA-26-211-09

Watchfire Controller Software

WatchfireBC550

CISAmiddel

Published

30 July 2026

Last update

31 July 2026

Linked CVEs

Affected sectors

Risk evaluation

Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller.

Mitigation summary

Watchfire has applied the required security patch to all affected controllers under its management. Watchfire recommends users verify their controller software version and upgrade to one of the approved versions below, if they are not already on an approved patch level.

Revision history (2)
  1. Initial publication30 July 2026

    Initial Publication

  2. Update A31 July 2026

    Updated Product and Remediation details

Official source: CISA

ICSA-26-211-11

MZ Automation lib60870

MZ Automation GmbHlib60870

CISAmiddel

Published

30 July 2026

Last update

30 July 2026

Affected sectors

Risk evaluation

Successful exploitation of these vulnerabilities could crash the device being accessed.

Mitigation summary

MZ Automation recommends users update to version 2.4.1 when available.

Revision history (1)
  1. Initial publication30 July 2026

    Initial Publication

Official source: CISA

ICSA-26-211-10

MZ Automation GmbH libiec61850

MZ Automation GmbHlibiec61850

CISAhigh

Risk evaluation

Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device.

Mitigation summary

MZ Automation GmbH recommends that users update to version 1.6.2.

Revision history (1)
  1. Initial publication30 July 2026

    Initial Publication

Official source: CISA

ICSA-26-211-08

o6 Automation open62541

o6 Automation GmbHopen62541 on Windows and Linux

CISAhigh

Published

30 July 2026

Last update

30 July 2026

Affected sectors

Risk evaluation

Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code.

Mitigation summary

o6 Automation has prepared mitigations and fixes to address these issues and recommends that users update to the newest version. The new version can be obtained by contacting o6 Automation https://www.o6-automation.com/contact or by downloading from the following locations:

Revision history (1)
  1. Initial publication30 July 2026

    Initial Publication

Official source: CISA

ICSA-26-211-05

Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module

Rockwell AutomationControlLogix 5580

CISAmiddel

Published

30 July 2026

Last update

30 July 2026

Linked CVEs

Affected sectors

Risk evaluation

Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.

Mitigation summary

Rockwell Automation recommend users update to the following versions: ControlLogix 5580: Update to V38.011

Revision history (1)
  1. Initial publication30 July 2026

    Initial Publication

Official source: CISA

ICSA-26-211-04

Schneider Electric IGSS

Schneider ElectricIGSS

CISAhigh

Published

14 July 2026

Last update

30 July 2026

Linked CVEs

Affected sectors

Risk evaluation

Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. The IGSS Definition module is a design-time component used by system integrators to create mimic diagrams for plant personnel, enabling them to monitor and control the SCADA system. Failure to apply the remediation provided below may risk loss of data or arbitrary code execution, which could result in the loss of control of the system.

Mitigation summary

Version 18.0.0.26125 of the IGSS Definition module includes a fix for this vulnerability and is available for download through IGSS Master > Update IGSS Software or here: https://igss.schneider-electric.com/igss/igssupdates/v180/IGSSUPDATE.ZIP

Revision history (2)
  1. Initial publication14 July 2026

    Original Release

  2. Update A30 July 2026

    Initial CISA Republication of Schneider Electric SEVD-2026-195-01 advisory

Official source: CISA

ICSA-26-211-03

Toptech Systems RCU II+ and Multiload II+

Toptech SystemsRCU II+

CISAhigh

Published

30 July 2026

Last update

30 July 2026

Linked CVEs

Affected sectors

Risk evaluation

Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources.

Mitigation summary

Toptech Systems provides two methods for remediating affected RCU II+ and Multiload II+ units: First, move the device to a closed or segmented network without untrusted access.

Revision history (1)
  1. Initial publication30 July 2026

    Initial Publication

Official source: CISA

ICSA-26-211-02

Johnson Controls OpenBlue Employee

Johnson Controls Inc.OpenBlue Employee (FMS Employee)

CISAlow

Published

30 July 2026

Last update

30 July 2026

Affected sectors

Risk evaluation

Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content.

Mitigation summary

Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation: Apply the latest product update for OpenBlue Employee (FMS Employee). Customers running V2025.3.1 [LV1.1] or earlier should apply the latest available update.

Revision history (1)
  1. Initial publication30 July 2026

    Initial Republication of Johnson Controls Inc. Security Advisory JCI-PSA-2026-09

Official source: CISA

9AKK108472A9037

ABB AbilityTM zenon Security Risk Due to End-of-Life MongoDB Component

ABBAbility Zenon

ABB PSIRThigh

Risk evaluation

ABB is aware of publicly reported vulnerabilities affecting MongoDB 4.2, which is bundled within the IIoT Services of the affected product versions. MongoDB 4.2 has reached end-of-life and contains multiple known security vulnerabilities. An attacker who successfully exploits these vulnerabilities could potentially access sensitive information, cause denial of service, or disrupt system availability.

Mitigation summary

ABB recommends the following mitigation measures: - Replace bundled MongoDB with a supported version if IIoT services are required: - Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. - The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer - Uninstall IIoT Services wherever it’s not required: - If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section “General security recommendations” for further advise on how to keep your system secure.

Revision history (1)
  1. Initial publication30 July 2026

    Initial version

Official source: ABB PSIRT

ICSA-26-209-07

ABB KNX Update Tool

ABBKNX Update Tool (ABB)

CISAmiddel

Published

17 July 2026

Last update

28 July 2026

Linked CVEs

Affected sectors

Risk evaluation

ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The vulnerability report has been shared in responsible disclosure. An attacker who successfully exploited this vulnerability could cause the product to become unusable. ABB confirms the vulnerability but at the same time acknowledges that the issue affects exclusively classic KNX devices that are not supporting the latest KNX Secure standard. Due to a lack of security in legacy KNX devices, the issue cannot be resolved via a software change. In order to actively exploit this vulnerability, an attacker requires physical access to the bus, the affected device is connected to. ABB has no plans of corrective measures.

Mitigation summary

Due to the nature of the classic KNX protocol stack and security concept, there are no options to resolve the vulnerability with a software update on a technical level. ABB recommends to follow general security recommendations listed in the security guideline (see References and General security recommendations). In addition, it shall be avoided to control sensitive functionality by legacy KNX devices such as, but not limited to, access control to e.g. hotel rooms or other protected areas. Note: Legacy KNX standards were never designed to meet state of the art security standards like introduced with KNX Data Secure published in 2017.

Revision history (2)
  1. Initial publication17 July 2026

    Initial version

  2. Update A28 July 2026

    Initial CISA Republication of ABB PSIRT 9AKK108472A9270 advisory

Official source: CISA

ICSA-26-209-04

Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP

SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)

CISAcritical

Published

14 July 2026

Last update

28 July 2026

Linked CVEs

CVE-2021-41617CVE-2023-28531CVE-2023-51384CVE-2023-52927CVE-2024-26783CVE-2024-27056CVE-2024-28956CVE-2024-36903CVE-2024-36927CVE-2024-42079CVE-2024-46786CVE-2024-47736CVE-2024-47809CVE-2024-49968CVE-2024-49994CVE-2024-49998CVE-2024-50014CVE-2024-50063CVE-2024-50164CVE-2024-50298CVE-2024-53124CVE-2024-53170CVE-2024-54458CVE-2024-56631CVE-2024-56703CVE-2024-56719CVE-2024-57917CVE-2024-57924CVE-2024-57973CVE-2024-57977CVE-2024-57979CVE-2024-58011CVE-2024-58016CVE-2024-58020CVE-2024-58056CVE-2024-58058CVE-2024-58061CVE-2024-58086CVE-2025-21645CVE-2025-21648CVE-2025-21655CVE-2025-21676CVE-2025-21682CVE-2025-21702CVE-2025-21705CVE-2025-21706CVE-2025-21707CVE-2025-21718CVE-2025-21731CVE-2025-21745CVE-2025-21758CVE-2025-21760CVE-2025-21764CVE-2025-21765CVE-2025-21780CVE-2025-21795CVE-2025-21796CVE-2025-21802CVE-2025-21814CVE-2025-21846CVE-2025-21853CVE-2025-21861CVE-2025-21864CVE-2025-21867CVE-2025-21875CVE-2025-21887CVE-2025-21913CVE-2025-21919CVE-2025-21925CVE-2025-21926CVE-2025-21938CVE-2025-21959CVE-2025-21999CVE-2025-22005CVE-2025-22015CVE-2025-22055CVE-2025-22056CVE-2025-22060CVE-2025-22083CVE-2025-22090CVE-2025-22095CVE-2025-22107CVE-2025-22111CVE-2025-22121CVE-2025-23136CVE-2025-23143CVE-2025-37785CVE-2025-37909CVE-2025-37917CVE-2025-37945CVE-2025-37959CVE-2025-37964CVE-2025-37972CVE-2025-37980CVE-2025-38125CVE-2025-38162CVE-2025-38192CVE-2025-38201CVE-2025-38232CVE-2025-38322CVE-2025-38591CVE-2025-38614CVE-2025-38681CVE-2025-38704CVE-2025-38721CVE-2025-38725CVE-2025-38727CVE-2025-38732CVE-2025-38736CVE-2025-39681CVE-2025-39691CVE-2025-39721CVE-2025-39748CVE-2025-39756CVE-2025-39764CVE-2025-39770CVE-2025-39773CVE-2025-39782CVE-2025-39795CVE-2025-39826CVE-2025-39827CVE-2025-39845CVE-2025-39866CVE-2025-39871CVE-2025-39931CVE-2025-39953CVE-2025-39955CVE-2025-39964CVE-2025-39977CVE-2025-39978CVE-2025-39980CVE-2025-40022CVE-2025-40070CVE-2025-40078CVE-2025-40080CVE-2025-40105CVE-2025-40135CVE-2025-40149CVE-2025-40219CVE-2025-40261CVE-2025-40300CVE-2025-61984CVE-2025-61985CVE-2025-68206CVE-2025-68261CVE-2025-68264CVE-2025-68265CVE-2025-68266CVE-2025-68291CVE-2025-68337CVE-2025-68349CVE-2025-68363CVE-2025-68371CVE-2025-68724CVE-2025-68725CVE-2025-68742CVE-2025-68764CVE-2025-68773CVE-2025-68776CVE-2025-68782CVE-2025-68787CVE-2025-68788CVE-2025-68798CVE-2025-68803CVE-2025-68814CVE-2025-68816CVE-2025-68818CVE-2025-68820CVE-2025-71064CVE-2025-71075CVE-2025-71079CVE-2025-71085CVE-2025-71086CVE-2025-71088CVE-2025-71095CVE-2025-71097CVE-2025-71098CVE-2025-71104CVE-2025-71112CVE-2025-71113CVE-2025-71114CVE-2025-71120CVE-2025-71123CVE-2025-71131CVE-2025-71161CVE-2025-71162CVE-2025-71163CVE-2025-71185CVE-2025-71186CVE-2025-71189CVE-2025-71190CVE-2025-71191CVE-2025-71197CVE-2025-71221CVE-2025-71265CVE-2025-71266CVE-2025-71267CVE-2026-3497CVE-2026-22977CVE-2026-22979CVE-2026-22980CVE-2026-22982CVE-2026-22992CVE-2026-22994CVE-2026-23003CVE-2026-23005CVE-2026-23010CVE-2026-23011CVE-2026-23019CVE-2026-23026CVE-2026-23038CVE-2026-23054CVE-2026-23060CVE-2026-23083CVE-2026-23084CVE-2026-23086CVE-2026-23087CVE-2026-23095CVE-2026-23100CVE-2026-23103CVE-2026-23110CVE-2026-23111CVE-2026-23113CVE-2026-23154CVE-2026-23204CVE-2026-23231CVE-2026-23242CVE-2026-23243CVE-2026-23245CVE-2026-23270CVE-2026-23271CVE-2026-23273CVE-2026-23274CVE-2026-23277CVE-2026-23284CVE-2026-23287CVE-2026-23290CVE-2026-23293CVE-2026-23300CVE-2026-23304CVE-2026-23319CVE-2026-23321CVE-2026-23335CVE-2026-23340CVE-2026-23343CVE-2026-23351CVE-2026-23359CVE-2026-23365CVE-2026-23368CVE-2026-23370CVE-2026-23378CVE-2026-23379CVE-2026-23381CVE-2026-23391CVE-2026-23392CVE-2026-23397CVE-2026-23398CVE-2026-23414CVE-2026-23422CVE-2026-23434CVE-2026-23438CVE-2026-23439CVE-2026-23446CVE-2026-23449CVE-2026-23450CVE-2026-23452CVE-2026-23454CVE-2026-23455CVE-2026-23456CVE-2026-23457CVE-2026-23458CVE-2026-23463CVE-2026-23474CVE-2026-23475CVE-2026-27135CVE-2026-31389CVE-2026-31391CVE-2026-31396CVE-2026-31402CVE-2026-31403CVE-2026-31411CVE-2026-31414CVE-2026-31415CVE-2026-31416CVE-2026-31417CVE-2026-31418CVE-2026-31421CVE-2026-31422CVE-2026-31423CVE-2026-31424CVE-2026-31427CVE-2026-31428CVE-2026-31431CVE-2026-31441CVE-2026-31446CVE-2026-31447CVE-2026-31448CVE-2026-31450CVE-2026-31452CVE-2026-31466CVE-2026-31469CVE-2026-31485CVE-2026-31494CVE-2026-31495CVE-2026-31496CVE-2026-31503CVE-2026-31504CVE-2026-31507CVE-2026-31508CVE-2026-31515CVE-2026-31518CVE-2026-31521CVE-2026-31533CVE-2026-31546CVE-2026-31555CVE-2026-31563CVE-2026-31565CVE-2026-31628CVE-2026-31634CVE-2026-31649CVE-2026-31651CVE-2026-31658CVE-2026-31664CVE-2026-31665CVE-2026-31669CVE-2026-31670CVE-2026-31671CVE-2026-31674CVE-2026-31680CVE-2026-31682CVE-2026-31737CVE-2026-31752CVE-2026-31761CVE-2026-31768CVE-2026-40355CVE-2026-41989CVE-2026-43011CVE-2026-43024CVE-2026-43025CVE-2026-43026CVE-2026-43027CVE-2026-43028CVE-2026-43030CVE-2026-43033CVE-2026-43035CVE-2026-43038CVE-2026-43040CVE-2026-43057CVE-2026-43284CVE-2026-46174CVE-2026-46300CVE-2026-46333

Affected sectors

Risk evaluation

Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigation summary

Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.

Revision history (2)
  1. Initial publication14 July 2026

    Publication Date

  2. Update A28 July 2026

    Initial CISA Republication of Siemens ProductCERT SSA-019113 advisory

Official source: CISA

ICSA-26-209-03

Siemens SIMATIC S7-PLCSIM Advanced

SiemensSIMATIC S7-PLCSIM Advanced

CISAhigh

Published

14 July 2026

Last update

28 July 2026

Linked CVEs

Affected sectors

Risk evaluation

SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigation summary

Disable the S7-PLCSIM Virtual Switch binding on the network adapter used by the affected instance. This prevents the adapter from entering an external communication mode and removes the attack vector entirely. (see SIMATIC S7-PLCSIM Advanced Function Manual V8.0, 11/2025 Section 5.3 and Section 6.1.2.3; and SIMATIC S7-PLCSIM Advanced Function Manual API V8.0, 11/2025 Section 7.2)

Revision history (2)
  1. Initial publication14 July 2026

    Publication Date

  2. Update A28 July 2026

    Initial CISA Republication of Siemens ProductCERT SSA-828211 advisory

Official source: CISA

ICSA-26-209-02

Siemens Mendix Runtime

SiemensMendix Runtime

CISAcritical

Published

14 July 2026

Last update

28 July 2026

Linked CVEs

Affected sectors

Risk evaluation

Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely. This documentation gap may lead application developers to unknowingly apply overly permissive access rules to System.User, resulting in unintended exposure of sensitive user data or privilege escalation within deployed Mendix applications. A common misconfiguration identified is with the anonymous user role with a System.User entity to gain access to all stored records, even though no access rights are explicitly configured on that role. Siemens recommends Mendix developers to review their access rules based on updated documentation.

Mitigation summary

Any security model relying solely on XPath constraints on a System.User specialization to restrict access should be revised to enforce restrictions at the App Security role-management configuration level instead.

Revision history (2)
  1. Initial publication14 July 2026

    Publication Date

  2. Update A28 July 2026

    Initial CISA Republication of Siemens ProductCERT SSA-814963 advisory

Official source: CISA

ICSA-26-209-01

Siemens Desigo CC

SiemensDesigo CC family V7

CISAcritical

Published

14 July 2026

Last update

28 July 2026

Linked CVEs

Affected sectors

Risk evaluation

OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.

Mitigation summary

Currently no fix is available

Revision history (2)
  1. Initial publication14 July 2026

    Publication Date

  2. Update A28 July 2026

    Initial CISA Republication of Siemens ProductCERT SSA-734552 advisory

Official source: CISA

ICSA-26-204-07

MZ Automation lib60870

MZ Automationlib60870

CISAhigh

Published

23 July 2026

Last update

23 July 2026

Linked CVEs

Affected sectors

Risk evaluation

Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service.

Mitigation summary

MZ automation recommends users update to version 2.4.1 or later. Documentation can be found at https://github.com/mz-automation/lib60870/security/advisories/GHSA-f5xp-w6f3-vvrv.

Revision history (1)
  1. Initial publication23 July 2026

    Initial Publication

Official source: CISA

ICSA-26-204-06

MZ Automation libIEC61850

MZ AutomationlibIEC61850

CISAhigh

Published

23 July 2026

Last update

23 July 2026

Affected sectors

Risk evaluation

Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions.

Mitigation summary

MZ Automation recommends updating to the latest build of the libIEC61850 standard. Documentation can be found at https://github.com/mz-automation/libiec61850.

Revision history (1)
  1. Initial publication23 July 2026

    Initial Publication

Official source: CISA

ICSA-26-204-05

Rockwell Automation ThinManager

Rockwell AutomationThinManager

CISAhigh

Published

14 July 2026

Last update

23 July 2026

Linked CVEs

Affected sectors

Risk evaluation

Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory.

Mitigation summary

Users using the affected software, should upgrade to one of the corrected versions as follows:

Revision history (2)
  1. Initial publication14 July 2026

    Initial Publication by Rockwell Automation

  2. Update A23 July 2026

    Initial Republication of Rockwell Automation advisory

Official source: CISA

ICSA-26-204-04

Panduit IntraVUE

PronetiqsIntraVUE

CISAcritical

Published

23 July 2026

Last update

23 July 2026

Affected sectors

Risk evaluation

Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider knowledge, or advanced tooling.

Mitigation summary

Pronetiqs advises users to update to the latest version of the IntraVUE software, version 3.2.1a16 or later.

Revision history (1)
  1. Initial publication23 July 2026

    Initial Publication

Official source: CISA

ICSA-26-204-03

Weintek cMT3092X

WeintekcMT3092X firmware

CISAhigh

Published

23 July 2026

Last update

23 July 2026

Affected sectors

Risk evaluation

Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users.

Mitigation summary

Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors.

Revision history (1)
  1. Initial publication23 July 2026

    Initial Publication

Official source: CISA

ICSA-26-204-02

Johnson Controls XAAP Android

Johnson ControlsXAAP Android

CISAlow

Published

23 July 2026

Last update

23 July 2026

Linked CVEs

Affected sectors

Risk evaluation

Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device.

Mitigation summary

Johnson Controls recommends users update the XAAP Android application to version 1.53 or later, which contains the fix for this vulnerability.

Revision history (1)
  1. Initial publication23 July 2026

    Initial Republication of Johnson Controls JCI-PSA-2026-10

Official source: CISA

ICSA-26-202-10

Rockwell Automation Studio 5000 Logix Designer

Rockwell AutomationStudio 5000 Logix Designer

CISAhigh

Published

21 July 2026

Last update

21 July 2026

Affected sectors

Risk evaluation

Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code.

Mitigation summary

Rockwell Automation recommends users to upgrade to the following: Studio 5000 Logix Designer: V37.00, 36.01, 35.02, 34.04, 33.04, 32.05 (CVE-2026-9108)

Revision history (1)
  1. Initial publication21 July 2026

    Initial Republication of Rockwell Automation Security Advisory

Official source: CISA

ICSA-26-202-08

Rockwell Automation 1718-AENTR/1719-AENTR

Rockwell Automation1718/ 1719 Ex I/O

CISAhigh

Published

21 July 2026

Last update

21 July 2026

Linked CVEs

Affected sectors

Risk evaluation

Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product.

Mitigation summary

Rockwell Automation recommends users to upgrade to 1718/ 1719 Ex I/O version 3.012 or later.

Revision history (1)
  1. Initial publication21 July 2026

    Initial Republication of Rockwell Automation Security Advisory

Official source: CISA

ICSA-26-202-07

Rockwell Automation FactoryTalk Services Platform

Rockwell AutomationFactoryTalk Directory (FTSP)

CISAhigh

Published

21 July 2026

Last update

21 July 2026

Linked CVEs

Affected sectors

Risk evaluation

Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations.

Mitigation summary

Users using FactoryTalk Services Platform v6.60 should apply either the individual patch (RAID 1158263) or the February 2026 Patch Roll-up, or later update.

Revision history (1)
  1. Initial publication21 July 2026

    Initial Republication of Rockwell Automation SD1786

Official source: CISA

ICSA-26-202-06

Siemens CADRA

SiemensCADRA

CISAcritical

Risk evaluation

CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigation summary

Update to V2511 or later version

Revision history (2)
  1. Initial publication14 July 2026

    Publication Date

  2. Update A21 July 2026

    Initial CISA Republication of Siemens ProductCERT SSA-470355 advisory

Official source: CISA

ICSA-26-202-05

Siemens IAM Client

SiemensCOMOS V10.4.5

CISAmiddel

Published

14 July 2026

Last update

21 July 2026

Linked CVEs

Affected sectors

Risk evaluation

Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.

Mitigation summary

Update to V10.6.1 or later version

Revision history (2)
  1. Initial publication14 July 2026

    Publication Date

  2. Update A21 July 2026

    Initial CISA Republication of Siemens ProductCERT SSA-288252 advisory

Official source: CISA

ICSA-26-202-04

Siemens SIDIS Secured SmartPlug

SiemensSIDIS Secured SmartPlug

CISAcritical

Risk evaluation

SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version.

Mitigation summary

Update to V7.26.0310 or later version

Revision history (2)
  1. Initial publication14 July 2026

    Publication Date

  2. Update A21 July 2026

    Initial CISA Republication of Siemens ProductCERT SSA-585531 advisory

Official source: CISA

ICSA-26-202-03

Siemens Opcenter X

SiemensOpcenter X

CISAcritical

Published

14 July 2026

Last update

21 July 2026

Linked CVEs

Affected sectors

Risk evaluation

Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version.

Mitigation summary

Update to V2604 or later version

Revision history (2)
  1. Initial publication14 July 2026

    Publication Date

  2. Update A21 July 2026

    Initial CISA Republication of Siemens ProductCERT SSA-096828 advisory

Official source: CISA

ICSA-26-202-02

Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW

SiemensRUGGEDCOM APE1808

CISAhigh

Published

14 July 2026

Last update

21 July 2026

Affected sectors

Risk evaluation

Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/

Mitigation summary

Contact customer support to receive patch and update information

Revision history (2)
  1. Initial publication14 July 2026

    Publication Date

  2. Update A21 July 2026

    Initial CISA Republication of Siemens ProductCERT SSA-104023 advisory

Official source: CISA

9AKK108472A9270

ABB/EL/ELSB/Building Automation File integrity can be bypassed in KNX Update Tool for classic KNX products

ABBKNX Update Tool (ABB)

ABB PSIRTmiddel

Published

17 July 2026

Last update

17 July 2026

Linked CVEs

Affected sectors

Risk evaluation

ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The vulnerability report has been shared in responsible disclosure. An attacker who successfully exploited this vulnerability could cause the product to become unusable. ABB confirms the vulnerability but at the same time acknowledges that the issue affects exclusively classic KNX devices that are not supporting the latest KNX Secure standard. Due to a lack of security in legacy KNX devices, the issue cannot be resolved via a software change. In order to actively exploit this vulnerability, an attacker requires physical access to the bus, the affected device is connected to. ABB has no plans of corrective measures.

Mitigation summary

Due to the nature of the classic KNX protocol stack and security concept, there are no options to resolve the vulnerability with a software update on a technical level. ABB recommends to follow general security recommendations listed in the security guideline (see References and General security recommendations). In addition, it shall be avoided to control sensitive functionality by legacy KNX devices such as, but not limited to, access control to e.g. hotel rooms or other protected areas. Note: Legacy KNX standards were never designed to meet state of the art security standards like introduced with KNX Data Secure published in 2017.

Revision history (1)
  1. Initial publication17 July 2026

    Initial version

Official source: ABB PSIRT

ICSA-26-197-09

Rockwell Automation FactoryTalk DataMosaix

Rockwell AutomationDataMosaix Private Cloud

CISAmiddel

Published

16 July 2026

Last update

16 July 2026

Linked CVEs

Affected sectors

Risk evaluation

Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious scripts on the server.

Mitigation summary

Rockwell Automation recommends users to upgrade to the following: DataMosaix Private Cloud versions 8.03 or later.

Revision history (1)
  1. Initial publication16 July 2026

    Initial Republication of Rockwell Automation Security Advisory SD1787

Official source: CISA

ICSA-26-197-08

Rockwell Automation Flex 5000 Adapter

Rockwell AutomationFlex 5000 Adapter

CISAhigh

Published

16 July 2026

Last update

16 July 2026

Linked CVEs

Affected sectors

Risk evaluation

Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition on the affected product.

Mitigation summary

Rockwell Automation recommends users to upgrade to the following: Flex 5000 Adapter version 6.012.

Revision history (1)
  1. Initial publication16 July 2026

    Initial Republication of Rockwell Automation Security Advisory SD1789

Official source: CISA

ICSA-26-197-07

SALTO ProAccess Space

SALTOProAccess Space

CISAmiddel

Published

16 July 2026

Last update

16 July 2026

Linked CVEs

Affected sectors

Risk evaluation

Successful exploitation of this vulnerability allows an authenticated attacker to escalate privileges and access spaces outside their assigned partition, within the same Salto ProAccess Space installation or system. Exploitation requires valid authenticated operator credentials and the partition feature to be enabled; installations without partitioning are not affected.

Mitigation summary

Users of SALTO ProAccess using the tenancy feature should upgrade to version 6.13.

Revision history (1)
  1. Initial publication16 July 2026

    Initial Publication

Official source: CISA

SSA-082556

SSA-082556: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5

SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)

Siemens ProductCERTcritical

Published

10 June 2025

Last update

14 July 2026

Linked CVEs

CVE-2021-41617CVE-2023-4527CVE-2023-4806CVE-2023-4911CVE-2023-5363CVE-2023-6246CVE-2023-6779CVE-2023-6780CVE-2023-28531CVE-2023-38545CVE-2023-38546CVE-2023-44487CVE-2023-46218CVE-2023-46219CVE-2023-48795CVE-2023-51384CVE-2023-51385CVE-2023-52927CVE-2024-2961CVE-2024-6119CVE-2024-6387CVE-2024-12133CVE-2024-12243CVE-2024-24855CVE-2024-26596CVE-2024-28085CVE-2024-33599CVE-2024-33600CVE-2024-33601CVE-2024-33602CVE-2024-34397CVE-2024-37370CVE-2024-37371CVE-2024-45490CVE-2024-45491CVE-2024-45492CVE-2024-47736CVE-2024-47809CVE-2024-49998CVE-2024-50246CVE-2024-50298CVE-2024-53166CVE-2024-56719CVE-2024-57924CVE-2024-57977CVE-2024-57996CVE-2024-58005CVE-2025-3198CVE-2025-4373CVE-2025-4598CVE-2025-5244CVE-2025-5245CVE-2025-6395CVE-2025-7425CVE-2025-7545CVE-2025-7546CVE-2025-8224CVE-2025-9230CVE-2025-9232CVE-2025-11082CVE-2025-11083CVE-2025-11412CVE-2025-11413CVE-2025-11414CVE-2025-11494CVE-2025-11495CVE-2025-11839CVE-2025-11840CVE-2025-21676CVE-2025-21682CVE-2025-21701CVE-2025-21702CVE-2025-21712CVE-2025-21724CVE-2025-21728CVE-2025-21745CVE-2025-21756CVE-2025-21758CVE-2025-21765CVE-2025-21766CVE-2025-21767CVE-2025-21795CVE-2025-21796CVE-2025-21848CVE-2025-21862CVE-2025-21864CVE-2025-21865CVE-2025-26465CVE-2025-31115CVE-2025-32988CVE-2025-32989CVE-2025-37945CVE-2025-37980CVE-2025-38058CVE-2025-38063CVE-2025-38067CVE-2025-38071CVE-2025-38079CVE-2025-38083CVE-2025-38100CVE-2025-38111CVE-2025-38124CVE-2025-38162CVE-2025-38167CVE-2025-38192CVE-2025-38198CVE-2025-38201CVE-2025-38212CVE-2025-38214CVE-2025-38215CVE-2025-38222CVE-2025-38231CVE-2025-38236CVE-2025-38280CVE-2025-38285CVE-2025-38312CVE-2025-38342CVE-2025-38350CVE-2025-38364CVE-2025-38393CVE-2025-38400CVE-2025-38430CVE-2025-38451CVE-2025-38457CVE-2025-38465CVE-2025-38466CVE-2025-38468CVE-2025-38470CVE-2025-38471CVE-2025-38477CVE-2025-38498CVE-2025-38499CVE-2025-38614CVE-2025-38685CVE-2025-38691CVE-2025-38701CVE-2025-38702CVE-2025-38704CVE-2025-38708CVE-2025-38721CVE-2025-38724CVE-2025-38727CVE-2025-39683CVE-2025-39689CVE-2025-39697CVE-2025-39724CVE-2025-39748CVE-2025-39756CVE-2025-39764CVE-2025-39770CVE-2025-39773CVE-2025-39783CVE-2025-39787CVE-2025-39795CVE-2025-39798CVE-2025-39866CVE-2025-39929CVE-2025-39931CVE-2025-39977CVE-2025-40022CVE-2025-40135CVE-2025-40219CVE-2025-40261CVE-2025-46836CVE-2025-59375CVE-2025-66382CVE-2025-68206CVE-2025-68265CVE-2025-71161CVE-2025-71221CVE-2025-71265CVE-2025-71266CVE-2025-71267CVE-2026-3904CVE-2026-4046CVE-2026-4437CVE-2026-4438CVE-2026-5435CVE-2026-5450CVE-2026-5928CVE-2026-6238CVE-2026-23100CVE-2026-23111CVE-2026-23113CVE-2026-23154CVE-2026-23204CVE-2026-23231CVE-2026-23242CVE-2026-23243CVE-2026-23245CVE-2026-23270CVE-2026-23271CVE-2026-23273CVE-2026-23274CVE-2026-23277CVE-2026-23284CVE-2026-23287CVE-2026-23290CVE-2026-23293CVE-2026-23300CVE-2026-23304CVE-2026-23319CVE-2026-23321CVE-2026-23335CVE-2026-23340CVE-2026-23343CVE-2026-23351CVE-2026-23359CVE-2026-23365CVE-2026-23368CVE-2026-23370CVE-2026-23378CVE-2026-23379CVE-2026-23381CVE-2026-23391CVE-2026-23392CVE-2026-23397CVE-2026-23398CVE-2026-23414CVE-2026-23422CVE-2026-23434CVE-2026-23438CVE-2026-23439CVE-2026-23446CVE-2026-23449CVE-2026-23450CVE-2026-23452CVE-2026-23454CVE-2026-23455CVE-2026-23456CVE-2026-23457CVE-2026-23458CVE-2026-23463CVE-2026-23474CVE-2026-23475CVE-2026-31389CVE-2026-31391CVE-2026-31396CVE-2026-31402CVE-2026-31403CVE-2026-31411CVE-2026-31414CVE-2026-31415CVE-2026-31416CVE-2026-31417CVE-2026-31418CVE-2026-31421CVE-2026-31422CVE-2026-31423CVE-2026-31424CVE-2026-31427CVE-2026-31428CVE-2026-31431CVE-2026-31441CVE-2026-31446CVE-2026-31447CVE-2026-31448CVE-2026-31450CVE-2026-31452CVE-2026-31466CVE-2026-31469CVE-2026-31485CVE-2026-31494CVE-2026-31495CVE-2026-31496CVE-2026-31503CVE-2026-31504CVE-2026-31507CVE-2026-31508CVE-2026-31515CVE-2026-31518CVE-2026-31521CVE-2026-31533CVE-2026-31546CVE-2026-31555CVE-2026-31563CVE-2026-31565CVE-2026-31628CVE-2026-31634CVE-2026-31649CVE-2026-31651CVE-2026-31658CVE-2026-31664CVE-2026-31665CVE-2026-31669CVE-2026-31670CVE-2026-31671CVE-2026-31674CVE-2026-31680CVE-2026-31682CVE-2026-31737CVE-2026-31752CVE-2026-31761CVE-2026-31768CVE-2026-32776CVE-2026-32777CVE-2026-32778CVE-2026-40355CVE-2026-41080CVE-2026-41989CVE-2026-43011CVE-2026-43024CVE-2026-43025CVE-2026-43026CVE-2026-43027CVE-2026-43028CVE-2026-43030CVE-2026-43033CVE-2026-43035CVE-2026-43038CVE-2026-43040CVE-2026-43057CVE-2026-43284CVE-2026-45186CVE-2026-46174CVE-2026-46300

Affected sectors

Risk evaluation

Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.5 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. Note: This SSA advises vulnerabilities for firmware version V3.1.5 only; for version V3.1.6 refer to SSA-019113.

Mitigation summary

Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.

Revision history (4)
  1. Initial publication10 June 2025

    Publication Date

  2. Update A12 August 2025

    Added CVE-2025-6395, CVE-2025-32988, CVE-2025-32989, CVE-2025-32990

  3. Update B13 January 2026

    Added CVE-2025-66382, CVE-2025-39929, CVE-2025-39931, CVE-2025-39977, CVE-2025-40022, CVE-2025-11082, CVE-2025-11083, CVE-2025-11412, CVE-2025-11413, CVE-2025-11414, CVE-2025-11494, CVE-2025-11495, CVE-2025-11839, CVE-2025-11840, CVE-2025-9230, CVE-2025-9232, CVE-2025-3198, CVE-2025-5244, CVE-2025-5245, CVE-2025-7545, CVE-2025-7546, CVE-2025-8224, CVE-2025-7425, CVE-2025-59375

  4. Update C10 February 2026

    Added 22 CVEs

Official source: Siemens ProductCERT

SSA-096828

SSA-096828: Token Invalidation Vulnerability in Opcenter X Before V2604

SiemensOpcenter X

Siemens ProductCERTcritical

Published

14 July 2026

Last update

14 July 2026

Linked CVEs

Affected sectors

Risk evaluation

Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version.

Mitigation summary

Update to V2604 or later version

Revision history (1)
  1. Initial publication14 July 2026

    Publication Date

Official source: Siemens ProductCERT

SSA-288252

SSA-288252: Unquoted Search Path Vulnerability in IAM Client

SiemensCOMOS V10.4.5

Siemens ProductCERTmiddel

Published

14 July 2026

Last update

14 July 2026

Linked CVEs

Affected sectors

Risk evaluation

Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.

Mitigation summary

Update to V10.6.1 or later version

Revision history (1)
  1. Initial publication14 July 2026

    Publication Date

Official source: Siemens ProductCERT

SSA-470355

SSA-470355: Zlib and Foxit Vulnerabilities in CADRA

SiemensCADRA

Siemens ProductCERTcritical

Risk evaluation

CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigation summary

Update to V2511 or later version

Revision history (1)
  1. Initial publication14 July 2026

    Publication Date

Official source: Siemens ProductCERT

SSA-555707

SSA-555707: Information Disclosure Vulnerability in Simcenter STAR-CCM+

SiemensSimcenter STAR-CCM+

Siemens ProductCERTmiddel

Published

9 August 2022

Last update

14 July 2026

Linked CVEs

Affected sectors

Risk evaluation

Simcenter STAR-CCM+ contains an information disclosure vulnerability when using the Power-on-Demand public license server. An attacker could access a system's host, user, and display name. Siemens has updated the public Power-on-Demand public license server.

Mitigation summary

Avoid using sensitive or personal data in user, host and display names

Revision history (2)
  1. Initial publication9 August 2022

    Publication Date

  2. Update A14 July 2026

    Added fix for Simcenter STAR-CCM+

Official source: Siemens ProductCERT

SA26P011

Security Issues addressed in APROL R 4.4-01P5

B&R Industrial Automation GmbHAPROL

ABB PSIRTcritical

Published

6 July 2026

Last update

6 July 2026

Affected sectors

Risk evaluation

An update is available that resolves several vulnerabilities and updates one or more 3rd party components in the product versions listed as affected in the advisory. An attacker who successfully exploited these vulnerabilities could impact the availability of the product, spoof identities or elevate privileges.

Mitigation summary

The problem is corrected in the following product versions: - APROL >= R 4.4-01P5 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revision history (1)
  1. Initial publication6 July 2026

    Initial version.

Official source: ABB PSIRT

7PAA024620

ABB Ability Edgenius: Copy Fail

ABBUnknown product

ABB PSIRThigh

Published

25 June 2026

Last update

25 June 2026

Linked CVEs

Affected sectors

Risk evaluation

ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete control of the system

Mitigation summary

The problem is corrected in the following product versions: - Edgenius 3.2.4.1 ABB recommends that customers apply the update at earliest convenience.

Revision history (1)
  1. Initial publication25 June 2026

    Initial version.

Official source: ABB PSIRT

7PAA020047

Advant Master Online Builder DLL vulnerability

ABBControl Builder A

ABB PSIRTmiddel

Published

23 June 2026

Last update

23 June 2026

Linked CVEs

Affected sectors

Risk evaluation

ABB became aware of vulnerability in the products versions listed as affected in the advisory, where an incorrect version of Online Builder (ONB) was included in the media. An update is available that resolves the vulnerability, see details in Recommended immediate actions.

Mitigation summary

ABB has investigated the vulnerability and remediated it in the newly released versions. The vulnerability has been resolved in the product versions listed as fixed in the advisory. - Version 6.1.1-2 does not contain this vulnerability and therefore no update is required. The vulnerability was again introduced in 6.1.1-3 when an older ONB version was included in the release media. - Version 6.1.1-4 do not contain this vulnerability but present version 6.1.1-3 by 800xA System Installer and System Configuration Console (SCC). Version 6.1.1-4 is therefore withdrawn. - Version 6.2.0-2 do not contain this vulnerability but present version 6.2.0-1 by 800xA System Installer and System Configuration Console (SCC). Version 6.2.0-2 is therefore withdrawn. ABB recommends that customers apply the update at their earliest convenience. - Control Builder A: It is recommended to update Control Builder A to version 1.4/5 or later. - 800xA for Advant Master: - Versions 6.0.3-1 and earlier, - Versions 6.1.1-1 and earlier, - Versions 6.1.1-2, 6.1.1-3, and 6.1.1-4 should be updated to version 6.1.1-5 or later. - 800xA for Advant Master: - Versions 6.2.0-1 and 6.2.0-2 should be updated to version 6.2.0-3 or later.

Revision history (1)
  1. Initial publication23 June 2026

    Initial version.

Official source: ABB PSIRT

SA26P010

Impact of Linux Kernel vulnerabilities on B&R products

B&R Industrial Automation GmbHLinux for B&R

ABB PSIRThigh

Published

11 June 2026

Last update

18 June 2026

Affected sectors

Risk evaluation

B&R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory. Successful local exploitation of these vulnerabilities could allow an attacker to escalate privileges on the affected system. Public proof-of-concept exploits are available for the vulnerabilities described herein. At the time of publication of this advisory, B&R had no evidence of active exploitation targeting B&R products.

Mitigation summary

For affected products, software updates should be installed upon availability. Product Patch version - APROL : APROL-AutoYaST-DVD- V4.4-010.10.260602 Until remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.

Revision history (2)
  1. Initial publication11 June 2026

    Initial version.

  2. Update A18 June 2026

    Updating the CWE classification for CVE-2026-43494.

Official source: ABB PSIRT

7PAA020361

Freelance Security Lock - Access to Windows OS

ABBSystem Version

ABB PSIRTmiddel

Published

10 June 2026

Last update

17 June 2026

Linked CVEs

Affected sectors

Risk evaluation

ABB is aware of a vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the product to stop or make the product inaccessible.

Mitigation summary

ABB recommends using Freelance Extended User Management instead of Security Lock. Freelance Extended User Management is based on Windows user accounts and is available for Freelance 2019 or higher. For Freelance 2016 and earlier, please refer to chapter “General Security Information”. A fix for Freelance Security Lock is in preparation and will be announced in this updated document. Refer to section “General security recommendations” for further advise on how to keep your system secure. To reduce the likelihood of exploitation via keyboard shortcuts: - disable unnecessary accessibility features - use hardened OS configurations that suppress system-level shortcuts - implement BIOS/UEFI-level restrictions on keyboard input during runtime.

Revision history (2)
  1. Initial publication10 June 2026

    Initial version.

  2. Update A17 June 2026

    Correction on the product relationship

Official source: ABB PSIRT

SA26P009

XZ Utils vulnerability impacting B&R Products

B&R Industrial Automation GmbHPPC3100

ABB PSIRThigh

Published

10 June 2026

Last update

10 June 2026

Linked CVEs

Affected sectors

Risk evaluation

An update is available that resolves vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the product to stop or corrupt memory data.

Mitigation summary

The problem is corrected in the following product versions: Product Terminal OS Version - PPC3100 1.8.1 - C50 1.8.0 - C80 1.8.0 - FT50 1.8.1 - MT50 1.8.1 - T30 1.8.0 - T80 1.8.0 - T50 1.8.1 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revision history (1)
  1. Initial publication10 June 2026

    Initial version.

Official source: ABB PSIRT

9AKK108472A7840

Vulnerabilities in T-MAC Plus

ABBT-MAC Plus

ABB PSIRTcritical

Published

3 June 2026

Last update

3 June 2026

Affected sectors

Risk evaluation

ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. An attacker who successfully exploited any of these vulnerabilities could potentially compromise the system in different ways.

Mitigation summary

ABB has investigated these vulnerabilities to provide adequate protection to customers. The problem is corrected in the following product versions: T-MAC Plus version 4.0-25 ABB recommends that customers apply the update at earliest convenience.

Revision history (1)
  1. Initial publication3 June 2026

    Initial version.

Official source: ABB PSIRT

SA25P006

PPT30 OPC-UA Server has issues handling concurrent connections

B&R Industrial Automation GmbHPPT30 Operating System

ABB PSIRThigh

Published

26 May 2026

Last update

26 May 2026

Linked CVEs

Affected sectors

Risk evaluation

B&R is aware of a vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploits this vulnerability could make the OPC-UA server of the product inaccessible.

Mitigation summary

The problem is corrected in the following product versions: PPT30 Operating System 1.8.0 The OPC-UA server is not activated by default. B&R recommends that customers with the OPC-UA Server enabled to install the update at their earliest opportunity. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revision history (1)
  1. Initial publication26 May 2026

    Initial version.

Official source: ABB PSIRT

7PAA023732

System 800xA affected by 3rd party component vulnerabilities

ABB800xA History

ABB PSIRThigh

Risk evaluation

ABB is aware of public reports of vulnerabilities in 7-Zip version 18.5 and Microsoft Azure Data Studio version 1.32 included in the product versions listed as affected in the advisory. The vulnerability in 7-Zip can be exploited if attacker gains control over the system and extracts a malicious file using this version of 7-Zip. Otherwise, the attacker must force the user to visit malicious websites or click links and extract the package through 7-zip. Microsoft Azure Data Studio gets installed along with SQL Server Management Studio. An attacker who successfully exploits vulnerability in Microsoft Azure Data studio may compromise the security of the product by gaining privileges, reading sensitive information, executing commands, evading detection, etc. if the Authentication, Authorization and Accountability is not configured properly in the system. However, none of the products listed above uses Microsoft Azure Data Studio. Microsoft Azure Data Studio is automatically removed from the system from System 800xA 7.0 onwards. These vulnerabilities may appear when the product media is scanned. However, they can only be ex-ploited if the vulnerable software is installed on the system. For this reason, it is strongly advised to uninstall outdated or vulnerable versions of third-party software immediately.

Mitigation summary

Workarounds are specific measures that a user can take to help block an attack, for example, temporarily disabling the vulnerable feature may remove the exposure with well-known impact on functionality. There are no workarounds. Uninstalling the affected third-party software fully eliminates the risk of vulnerabilities. Refer to the section ‘Recommended immediate actions’.

Revision history (2)
  1. Initial publication31 March 2026

    Initial version.

  2. Update A22 May 2026

    Added missing CVE description for CVE-2024-26203.

Official source: ABB PSIRT

SA25P007

B&R Automation Studio Update of SQLite version

B&R Industrial Automation GmbHAutomation Studio

ABB PSIRTcritical

Risk evaluation

ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that replaces an outdated third-party component. Although no successful exploitation was observed during testing of the affected B&R products, the identified vulnerabilities could present potential attack vectors that might enable unauthorized access, data exposure, or remote code execution.

Mitigation summary

The problem is corrected in the following product versions: B&R Automation Studio 6.5 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revision history (2)
  1. Initial publication18 February 2026

    Initial version.

  2. Update A14 May 2026

    Corrected vendor name from 'ABB' to 'B&R Industrial Automation GmbH' to ensure accurate product matching.

Official source: ABB PSIRT

SA26P001

​​PVI​ ​​Insertion of Sensitive Information into Logfile

B&R Industrial Automation GmbH​​PVI​

ABB PSIRTmiddel

Published

29 January 2026

Last update

14 May 2026

Linked CVEs

Affected sectors

Risk evaluation

ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is now available that addresses and remediates the vulnerability. An attacker who successfully exploited this vulnerability could read sensitive information in the logging data of the PVI client application. Logging is deactivated by default in all PVI client versions.

Mitigation summary

The problem is corrected in the following product versions: - PVI 6.5.0 Please note that PVI is included in the Automation Studio installation package and shares the same version number as the corresponding Automation Studio release. B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revision history (2)
  1. Initial publication29 January 2026

    Initial version.

  2. Update A14 May 2026

    Corrected vendor name from 'ABB' to 'B&R Industrial Automation GmbH' to ensure accurate product matching.

Official source: ABB PSIRT

SA24P003

​B&R PCs vulnerable to PixieFail attack​

B&R Industrial Automation GmbHAPC4100

ABB PSIRThigh

Risk evaluation

ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is now available that addresses and remediates the vulnerability. A network attacker could exploit the vulnerabilities to execute remote code, initiate DoS attacks, conduct DNS cache poisoning, or extract sensitive information.

Mitigation summary

The problems are corrected in the following product versions: - APC4100 1.09 - APC910 No patch will be released (Please refer to the mitigation measures specified in this advisory). - C80 1.14 - MPC3100 1.24 - PPC1200 1.14 - PPC900 2.16 - APC2200 1.35 - PPC2200 1.35 - APC3100 1.45 - PPC3100 1.45 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revision history (2)
  1. Initial publication29 January 2026

    Initial version.

  2. Update A14 May 2026

    Corrected vendor name from 'ABB' to 'B&R Industrial Automation GmbH' to ensure accurate product matching.

Official source: ABB PSIRT

SA25P005

B&R Automation Runtime Improper Handling of Flooding conditions on ANSL Server

B&R Industrial Automation GmbHAutomation Runtime

ABB PSIRTmiddel

Published

19 January 2026

Last update

14 May 2026

Linked CVEs

Affected sectors

Risk evaluation

ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that resolves a vulnerability. An attacker who successfully exploited this vulnerability could cause the product to stop.

Mitigation summary

The problem is corrected in the following product versions: - Automation Runtime 6 versions >= 6.5 - Automation Runtime 4 versions >= R4.93 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revision history (2)
  1. Initial publication19 January 2026

    Initial version.

  2. Update A14 May 2026

    Corrected vendor name from 'ABB' to 'B&R Industrial Automation GmbH' to ensure accurate product matching.

Official source: ABB PSIRT

SA25P004

Automation Studio Insufficient Server Certificate Validation

B&R Industrial Automation GmbHAutomation Studio

ABB PSIRThigh

Published

19 January 2026

Last update

14 May 2026

Linked CVEs

Affected sectors

Risk evaluation

ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that resolves a vulnerability. Successful exploitation of this vulnerability may enable an attacker to masquerade as a trusted party when B&R Automation Studio establishes a connection with a server via the ANSL over TLS or OPC-UA protocol.

Mitigation summary

The problem is corrected in the following product versions: B&R Automation Studio version 6.5 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is de-scribed in the user manual.

Revision history (2)
  1. Initial publication19 January 2026

    Initial Version

  2. Update A14 May 2026

    Corrected vendor name from 'ABB' to 'B&R Industrial Automation GmbH' to ensure accurate product matching.

Official source: ABB PSIRT

7PAA020125

Denial of Service Vulnerabilities in System 800xA, Symphony® Plus IEC 61850 communication stack

ABBS+ Operations

ABB PSIRTmiddel

Published

13 April 2026

Last update

13 April 2026

Linked CVEs

Affected sectors

Risk evaluation

This vulnerability was privately reported relating to ABB’s implementation of the IEC 61850 communication stack for MMS client applications used in some Automation control system products. Note: IEC 61850 communication typically supports MMS and GOOSE protocols. Some ABB products support both, others only MMS (e.g. S+ Operations and PM 877). In any case, GOOSE communication is not impacted by this reported vulnerability. If an attacker gains access to a site’s IEC 61850 network, then exploiting this vulnerability will result in a device fault (PM 877, CI850 and CI868 modules) and will require a manual restart. If this attack is directed at a S+ Operations node running IEC 61850 connectivity, this will result in a crash in the IEC 61850 communication driver which, if continued a repeating basis, will also result in a denial-of-service situation. Note that this does not have an impact on the overall availability and functionality of the S+ Operations node, only the IEC 61850 communication function. The System 800xA IEC61850 Connect is not affected.

Mitigation summary

ABB advises all customers to review their installations to determine if they are using an impacted product as listed above, no further analysis or tools are needed to make this determination. The recommended immediate actions per product are listed below: - CI868 (for AC 800M) Devices with firmware versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected in 6.1.1 and 7.0 tracks for 800xA. AC 800M 6.1.1-3 is planned for Q2 2027, AC 800M 7.0 has been released in December 2025. - CI850 (for Symphony Plus SD Series) Devices with firmware versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected in version C_0 or later (planned Q2 2026). - PM 877 (Symphony Plus MR) Devices with firmware versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected with firmware version 3.53 or later (planned Q1 2026). - S+ Operations Versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected in version 3.4 or later (released in January 2026). ABB recommends customers apply updates, as they become available, at their earliest convenience. It is also advisable to review the Mitigating Factors, Workarounds and General security recommendations sections for additional actions which may help reduce overall risk.

Revision history (1)
  1. Initial publication13 April 2026

    Initial version.

Official source: ABB PSIRT

7PAA017341

PostgreSQL vulnerabilities in ABB Ability™ Symphony® Plus Engineering

ABBUnknown product

ABB PSIRThigh

Published

13 April 2026

Last update

13 April 2026

Affected sectors

Risk evaluation

ABB became aware of vulnerability in the products versions listed as affected in the advisory. The ABB S+ Engineering product versions are affected by vulnerabilities in PostgreSQL version 13.11 and earlier versions. If an attacker gains access to a site’s S+ Client Server network, they could exploit such vulnerabilities by executing arbitrary code and potentially compromising the entire system.

Mitigation summary

ABB advises all customers to review their installations to determine if they are using an impacted product as listed above, no further analysis or tools are needed to make this determination. The recommended immediate actions per product are listed below: - Systems using S+ Engineering 2.2 through 2.4 SP2 should upgrade to S+ Engineering 2.4 SP2 RU1 (re-leased in December 2024) or later. - End users who are unable to install one of these updates should immediately look to implement the Mitigation and Workarounds listed below as this will restrict or prevent an attacker’s ability to com-promise the system. ABB recommends that customers apply the update at the earliest convenience.

Revision history (1)
  1. Initial publication13 April 2026

    Initial version.

Official source: ABB PSIRT

4HZM000604

ABB Ability Camera Connect Vulnerabilities in outdated 3rd party component (SQLite 3.2.4)

ABBAbility Camera Connect

ABB PSIRTcritical

Risk evaluation

ABB is aware of public reports of vulnerabilities in a 3rd party dependency SQLite Version 3.2.4 which was delivered together with the installation package of Camera Connect Version 2.0.0.42 and below. An update is available that resolves a privately reported outdated 3rd party component with vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited any of these vulnerabilities in the 3rd party component could potentially compromise the system in different ways.

Mitigation summary

The problem is corrected in the following product versions: - ABB Ability Camera Connect 2.0.0.49. The easiest path to mitigate the problem is an update of ABB Ability Camera Connect system by the customer. ABB recommends that customers apply the update at earliest convenience.

Revision history (1)
  1. Initial publication26 March 2026

    Initial version.

Official source: ABB PSIRT

4JNO000329

AWIN Gateways Vulnerabilities in Embedded Webserver

ABBAWIN Firmware

ABB PSIRThigh

Published

13 March 2026

Last update

13 March 2026

Affected sectors

Risk evaluation

ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. AWIN gateways are not intended to be internet-facing. An attacker who successfully exploited this vulnerability could take remote control of the product and reboot the device, potentially causing a denial of service. It can also reveal system specific configuration. ABB requires, as noted in the User Manual, that AWIN gateways should not be exposed to the internet or any other insecure network. Note. To exploit this vulnerability the attacker needs access to the AWIN gateways. These gateways are installed on sites which often have perimeter security, and the gateways are installed behind firewalls.

Mitigation summary

Do the following actions: - Stop and disconnect any AWIN gateways that are exposed directly to the Internet. - Ensure that physical controls are in place, so no unauthorized personnel can access your devices, components, peripheral equipment, and networks. - Ensure that all AWIN gateways are upgraded to the latest firmware version. Please find the latest version of firmware on the respective product Release Notes. - When remote access is required, only use secure methods. The problem is corrected in the following product versions: - AWIN GW100 rev2: v2.1-0 - AWIN GW120: v2.0-0 ABB recommends that customers contact ABB to obtain the updated firmware as soon as possible. ABB Service Support engineer shall apply the firmware update at earliest convenience.

Revision history (1)
  1. Initial publication13 March 2026

    Initial version.

Official source: ABB PSIRT

3ADR011536

AC500 V3 Stack buffer overflow in Cryptographic Message Syntax

ABBAC500 V3 Firmware

ABB PSIRTcritical

Published

12 March 2026

Last update

12 March 2026

Linked CVEs

Affected sectors

Risk evaluation

ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves publicly reported vulnerability. An attacker who successfully exploited these vulnerabilities could cause a crash, denial-of-service (DoS), or potentially remote code execution.

Mitigation summary

The problem is corrected in the following product version: - AC500 V3 firmware version 3.9.0 HF1 ABB recommends that customers apply the update at earliest convenience. This firmware version is released for all AC500 V3 PLC types and available for download from the ABB library. https://search.abb.com/library/Download.aspx?DocumentID=3ADR011537&LanguageCode=en&DocumentPartId=&Action=Launch

Revision history (1)
  1. Initial publication12 March 2026

    Initial version.

Official source: ABB PSIRT

3ADR011525

ABB Automation Builder Gateway for Windows with insecure defaults

ABBAutomation Builder

ABB PSIRTmiddel

Published

24 February 2026

Last update

24 February 2026

Linked CVEs

Affected sectors

Risk evaluation

ABB became aware of severe vulnerability in the products versions listed as affected in the advisory. The Windows gateway is accessible remotely by default. Unauthenticated attackers can therefore search for PLCs, but the user management of the PLCs prevents the actual access to the PLCs – unless it is disabled

Mitigation summary

If remote access is not required, check the "LocalAddress" setting in the [CmpGwCommDrvTcp] section of the Gateway's configuration file as follows (restart of gateway required in case of changes): [CmpGwCommDrvTcp] LocalAddress=127.0.0.1 ; allow access only from the local computer The gateway configuration file can be located at (example for Automation Builder 2.8): %ProgramFiles%\ABB\AB2.8\AutomationBuilder\GatewayPLC\Gateway.cfg Starting with Automation Builder version 2.9.0 the vulnerability is closed by setting the default for the gateway to local access. Automation Builder 2.9.0 is available for download from the related download site. https://www.abb.com/global/en/areas/motion/digital-tools/automation-builder/software-download

Revision history (1)
  1. Initial publication24 February 2026

    Initial version.

Official source: ABB PSIRT

3ADR011524

AC500 V3 Multiple vulnerabilities

ABBAC500 V3

ABB PSIRThigh

Published

24 February 2026

Last update

24 February 2026

Affected sectors

Risk evaluation

ABB became aware of severe vulnerability in the products versions listed as affected in the advisory. An update is available that resolves these vulnerabilities. An attacker who successfully exploited these vulnerabilities could bypass the user management and read visualization files (CVE-2025-2595), read and write certificates and keys (CVE-2025-41659) or cause a denial-of-service (DoS) (CVE-2025-41691).

Mitigation summary

The problem is corrected in the following product versions: - AC500 V3 firmware version 3.9.0 ABB recommends that customers apply the update at earliest convenience. This firmware version is released for all AC500 V3 PLC types and available from Automation Builder 2.9.0. Automation Builder 2.9.0 is available for download from the related download site. https://www.abb.com/global/en/areas/motion/digital-tools/automation-builder/software-download

Revision history (1)
  1. Initial publication24 February 2026

    Initial version.

Official source: ABB PSIRT

7PAA013309

System 800xA SECURITY Advisory - ABB 800xA Base 6.0.x, 6.1.x CSLib communication DoS vulnerability

ABB800xA Base

ABB PSIRTmiddel

Published

5 June 2024

Last update

23 January 2026

Linked CVEs

Affected sectors

Risk evaluation

ABB is aware of a vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause services to crash and restart by sending specifically crafted messages. The vulnerability only affects 800xA services in PC based client/server nodes. Controllers are not affected by this vulnerability

Mitigation summary

The problem is corrected in the following product versions: - ABB 800xA Base 6.2.0-0 (part of System 800xA 6.2.0.0) - ABB 800xA Base 6.1.1-3 (part of System 800xA 6.1.1.2) - ABB 800xA Base 6.0.3-10 (RollUp released in September’2025. RollUp requires System 800xA 6.0.3.4 to be installed in the system. See References for more details.) It is recommended to update to an active product version to obtain the latest corrections.

Revision history (4)
  1. Initial publication5 June 2024

    Initial version

  2. Update A14 June 2024

    Included CVSS v4.0 score

  3. Update B22 January 2025

    Updated the planned release date for ABB 800xA Base 6.0.3-x

  4. Update C7 February 2025

    Updated Affected Products and Recommended immediate actions

Official source: ABB PSIRT

9AKK108472A1331

ABB Ability™ OPTIMAX® Authentication Bypass in Single-Sign On with Azure Active Directory

ABBUnknown product

ABB PSIRThigh

Published

16 January 2026

Last update

16 January 2026

Linked CVEs

Affected sectors

Risk evaluation

ABB became aware of severe vulnerability in the products versions listed as affected in the advisory, if the optional integration with Azure Active Directory for Single-Sign On is enabled. We have not received any reports of this vulnerability being exploited. An attacker who successfully exploits this vulnerability could bypass user authentication and potentially cause the product to: - Shutdown the system, - Modify the configuration of the system, - Install and run arbitrary code

Mitigation summary

The problem is corrected in the following product versions: - ABB Ability OPTIMAX v6.4.1-251120 (see References 9AKK108472A0435) or later - ABB Ability OPTIMAX v6.3.1-251120 (see References 9AKK108472A0437) or later ABB recommends that customers using earlier versions of OPTIMAX v6.4 and OPTIMAX v6.3 apply an update of the operating system at earliest convenience. Customers still using the meanwhile unsupported OPTIMAX v6.2 or v6.1 shall contact ABB to identify the right way forward.

Revision history (1)
  1. Initial publication16 January 2026

    Initial version.

Official source: ABB PSIRT

2CRT000009

WebPro SNMP Card PowerValue Multiple Vulnerabilities

ABBUnknown product

ABB PSIRThigh

Published

7 January 2026

Last update

7 January 2026

Affected sectors

Risk evaluation

ABB became aware of multiple internally discovered vulnerabilities in the WebPro SNMP card PowerValue for the product versions listed as affected in the advisory. Depending upon the vulnerability, an attacker with access to local network who successfully exploited this vulnerability could have - Unauthorized access - Insufficient Session Expiration leading to resource unavailability - Uncontrolled Resource Consumption leading to DOS attack ABB strongly advises customers to update the latest firmware of affected products.

Mitigation summary

The problem is corrected in the following product versions: WebPro SNMP card PowerValue version 1.1.8.p ABB advises users of the affected product versions to reach out to ABB Digital Service Support (ch.ups.digital@abb.com) for guidance and recommended actions. Additionally, ABB recommends implementing defensive measures to reduce the risk of vulnerability exploitation, as outlined in the product instruction manual. Please refer to the section “Mitigation factors” for more information.

Revision history (1)
  1. Initial publication7 January 2026

    Initial version.

Official source: ABB PSIRT

4HZM000603

ABB Ability Camera Connect Vulnerabilities in outdated 3rd party component (VLC)

ABBAbility Camera Connect

ABB PSIRTcritical

Risk evaluation

ABB is aware of public reports of vulnerabilities in a 3rd party component VLC media player Version 2.2.4 which was delivered together with the installation package of Camera Connect Version 1.5.0.14 and below. An update is available that resolves a privately reported outdated 3rd party component with vulnerabilities in the product versions listed as affected in this advisory. An attacker who successfully exploited any of these vulnerabilities in the 3rd party component could potentially compromise the system in different ways.

Mitigation summary

The VLC-based component operates solely within completely isolated environments without internet access or any connectivity to external networks. Consequently: • No exposure to untrusted MMS streams: The integer overflow vulnerability relies on handling a maliciously crafted external stream, which is not possible in isolated environments • No remote attacker access: Without network ingress, attackers cannot trigger the vulnerability remotely. • Drastically reduced attack surface: The absence of any external media inputs effectively neutralizes the exploit path, significantly lowering the risk of both denial of service and code execution.

Revision history (2)
  1. Initial publication27 November 2025

    Initial version.

  2. Update A28 November 2025

    Correction in References

Official source: ABB PSIRT

7PAA022088

Edgenius Management Portal Authentication Bypass

ABBAbility Edgenius

ABB PSIRTcritical

Published

20 November 2025

Last update

20 November 2025

Linked CVEs

Affected sectors

Risk evaluation

ABB identified a critical vulnerability present in ABB Ability Edgenius starting from version 3.2.0.0. We have not received any reports of this vulnerability being exploited. An unauthenticated attacker could exploit this vulnerability to: → install and run arbitrary code, → uninstall installed applications, → modify the configuration of installed applications, on systems running the vulnerable versions of ABB Ability Edgenius, including 3.2.0.0 through 3.2.1.1.

Mitigation summary

ABB has prepared an update to fix this vulnerability included in the latest Roll-Up, ABB Ability Edgenius version 3.2.2.0. ABB advises customers to upgrade as soon as possible. Until the upgrade is applied, ABB advises customers to disable the Edgenius Management Portal to mitigate the vulnerability.

Revision history (1)
  1. Initial publication20 November 2025

    Initial version.

Official source: ABB PSIRT

2NGA002813

PCM600 SharpZip library vulnerability

ABBUnknown product

ABB PSIRTmiddel

Published

3 November 2025

Last update

3 November 2025

Linked CVEs

Affected sectors

Risk evaluation

An update is available that resolves vulnerability in the product versions listed as affected in this advisory. An attacker who successfully exploited this vulnerability could insert and run arbitrary code in the system.

Mitigation summary

The problem is corrected in the following product version: ABB Protection and control IED manager PCM600 version 2.14. ABB recommends that customers apply the update at earliest convenience. Note: RE_630 protection relays are not compatible with PCM600 version 2.14. When using earlier PCM600 versions with RE_630, the known vulnerability must be mitigated through system-level defenses. For mitigation guidance, refer to the General Security Recommendations.

Revision history (1)
  1. Initial publication3 November 2025

    Initial version.

Official source: ABB PSIRT

4TZ00000006007

ALS-mini-S4/S8 IP Missing Authentication Vulnerability and its Mitigations

ABBALS-mini-s4 IP

ABB PSIRTcritical

Published

20 October 2025

Last update

23 October 2025

Linked CVEs

Affected sectors

Risk evaluation

ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the pollution of heap memory which potentially takes remote control of the product and performs a write operation to the flash memory to alter the firmware behavior.

Mitigation summary

ABB recommends that customers correctly configure the device in the network by referring to section Mitigating factors, or apply Workarounds to completely eliminate the attack vector.

Revision history (2)
  1. Initial publication20 October 2025

    Initial version.

  2. Update A23 October 2025

    Updated CVSS 3.1 score

Official source: ABB PSIRT

9AKK108471A8948

Terra AC wallbox Heap Memory Corruption Vulnerability

ABBTerra AC wallbox (UL40/80A)

ABB PSIRTmiddel

Published

20 October 2025

Last update

21 October 2025

Linked CVEs

Affected sectors

Risk evaluation

ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the pollution of heap memory which potentially takes remote control of the product and performs a write operation to the flash memory to alter the firmware behavior.

Mitigation summary

The problem is corrected in the product versions listed as fixed in the advisory. Terra AC wallbox (UL40/80A) 1.8.33 Terra AC wallbox (UL32A) 1.8.34 Terra AC MID 1.8.34 Terra AC Juno CE 1.8.34 Terra AC PTB 1.8.33 Terra AC wallbox (JP) 1.8.34 Additionally, we strongly recommend not use unsafe mode(http) to connect your charger to your backend even though OCPP is allowed to do in this way, which absolutely could be attacked by malicious man or organization as a common knowledge. ABB recommends that customers apply the update at earliest convenience.

Revision history (2)
  1. Initial publication20 October 2025

    Initial version.

  2. Update A21 October 2025

    Final version

Official source: ABB PSIRT

3KXG200000R4801

CoreSense™ HM and CoreSense™ M10 File Path Traversal Vulnerability

ABBUnknown product

ABB PSIRThigh

Published

16 April 2025

Last update

20 October 2025

Linked CVEs

Affected sectors

Risk evaluation

An update is available that resolves vulnerability in the product versions listed as affected in this advisory. A path traversal vulnerability in these products can allow unauthenticated users to gain access to restricted directories. Exploiting this vulnerability can lead to complete system compromise and exposure of sensitive information.

Mitigation summary

The vulnerabilities are corrected in the following version: CoreSense™ HM v2.3.4 & CoreSense™ M10 v1.4.1.31 ABB recommends that customers apply the update at the earliest convenience.

Revision history (4)
  1. Initial publication16 April 2025

    Initial version.

  2. Update A30 September 2025

    Addressed comments.

  3. Update B7 October 2025

    Fixed incorrect links.

  4. Update C20 October 2025

    Final version with corrected dates.

Official source: ABB PSIRT

4TZ00000006008

LVS MConfig Insecure memory handling

ABBUnknown product

ABB PSIRThigh

Published

8 October 2025

Last update

8 October 2025

Linked CVEs

Affected sectors

Risk evaluation

ABB became aware of an internally discovered vulnerability in the MConfig product versions listed as affected in the advisory. An attacker with access to local networks who successfully exploits vulnerability could have access to application’s sensitive information. ABB strongly advises customers to update MConfig with latest software version.

Mitigation summary

The vulnerability is resolved in the following product versions: MConfig version 1.4.9.22 ABB advises users to update their devices to the latest software version. Additionally, ABB recommends implementing defensive measures to reduce the risk of vulnerability exploitation, as outlined in the product instruction manual. Please refer to the section “Mitigation factors” for more information

Revision history (1)
  1. Initial publication8 October 2025

    Initial version.

Official source: ABB PSIRT