CISA ICS Advisories
ICS Advisories
Advisories specifiek gericht op industriële besturingssystemen, inclusief revisiegeschiedenis (initiële publicatie, Update A, Update B) en gekoppelde CVE's.
60
Advisories
Advisorydata: live koppeling — laatst opgehaald: 25 juli 2026 om 00:17.
60 advisories
ICSA-26-204-07
MZ Automation lib60870
MZ Automation — lib60870
Risk evaluation
Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service.
Mitigatiesamenvatting
MZ automation recommends users update to version 2.4.1 or later. Documentation can be found at https://github.com/mz-automation/lib60870/security/advisories/GHSA-f5xp-w6f3-vvrv.
Revisiegeschiedenis (1)
Initiële publicatie — 23 juli 2026
Initial Publication
ICSA-26-204-06
MZ Automation libIEC61850
MZ Automation — libIEC61850
Gepubliceerd
23 juli 2026
Laatste update
23 juli 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions.
Mitigatiesamenvatting
MZ Automation recommends updating to the latest build of the libIEC61850 standard. Documentation can be found at https://github.com/mz-automation/libiec61850.
Revisiegeschiedenis (1)
Initiële publicatie — 23 juli 2026
Initial Publication
ICSA-26-204-05
Rockwell Automation ThinManager
Rockwell Automation — ThinManager
Risk evaluation
Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory.
Mitigatiesamenvatting
Users using the affected software, should upgrade to one of the corrected versions as follows:
Revisiegeschiedenis (2)
Initiële publicatie — 14 juli 2026
Initial Publication by Rockwell Automation
Update A — 23 juli 2026
Initial Republication of Rockwell Automation advisory
ICSA-26-204-04
Panduit IntraVUE
Pronetiqs — IntraVUE
Gepubliceerd
23 juli 2026
Laatste update
23 juli 2026
Getroffen sectoren
Risk evaluation
Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider knowledge, or advanced tooling.
Mitigatiesamenvatting
Pronetiqs advises users to update to the latest version of the IntraVUE software, version 3.2.1a16 or later.
Revisiegeschiedenis (1)
Initiële publicatie — 23 juli 2026
Initial Publication
ICSA-26-204-03
Weintek cMT3092X
Weintek — cMT3092X firmware
Gepubliceerd
23 juli 2026
Laatste update
23 juli 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users.
Mitigatiesamenvatting
Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors.
Revisiegeschiedenis (1)
Initiële publicatie — 23 juli 2026
Initial Publication
ICSA-26-204-02
Johnson Controls XAAP Android
Johnson Controls — XAAP Android
Risk evaluation
Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device.
Mitigatiesamenvatting
Johnson Controls recommends users update the XAAP Android application to version 1.53 or later, which contains the fix for this vulnerability.
Revisiegeschiedenis (1)
Initiële publicatie — 23 juli 2026
Initial Republication of Johnson Controls JCI-PSA-2026-10
ICSA-26-204-01
Johnson Controls C-CURE 9000 and Victor application server
Johnson Controls — C-CURE 9000 and victor
Gepubliceerd
23 juli 2026
Laatste update
23 juli 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution.
Mitigatiesamenvatting
Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation: (CVE-2026-21655) Upgrade to C-CURE 9000 / victor version 3.20 or later, which addresses the vulnerable deserialization path (LV1.1).
Revisiegeschiedenis (1)
Initiële publicatie — 23 juli 2026
Initial Republication of Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16
ICSA-26-202-10
Rockwell Automation Studio 5000 Logix Designer
Rockwell Automation — Studio 5000 Logix Designer
Gepubliceerd
21 juli 2026
Laatste update
21 juli 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code.
Mitigatiesamenvatting
Rockwell Automation recommends users to upgrade to the following: Studio 5000 Logix Designer: V37.00, 36.01, 35.02, 34.04, 33.04, 32.05 (CVE-2026-9108)
Revisiegeschiedenis (1)
Initiële publicatie — 21 juli 2026
Initial Republication of Rockwell Automation Security Advisory
ICSA-26-202-09
Rockwell Automation 1734 POINT I/O
Rockwell Automation — 1734 POINT I/O
Risk evaluation
Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product.
Mitigatiesamenvatting
Rockwell Automation recommends users are to migrate to 5034-OB8.
Revisiegeschiedenis (1)
Initiële publicatie — 21 juli 2026
Initial Republication of Rockwell Automation Security Advisory
ICSA-26-202-08
Rockwell Automation 1718-AENTR/1719-AENTR
Rockwell Automation — 1718/ 1719 Ex I/O
Risk evaluation
Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product.
Mitigatiesamenvatting
Rockwell Automation recommends users to upgrade to 1718/ 1719 Ex I/O version 3.012 or later.
Revisiegeschiedenis (1)
Initiële publicatie — 21 juli 2026
Initial Republication of Rockwell Automation Security Advisory
ICSA-26-202-07
Rockwell Automation FactoryTalk Services Platform
Rockwell Automation — FactoryTalk Directory (FTSP)
Risk evaluation
Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations.
Mitigatiesamenvatting
Users using FactoryTalk Services Platform v6.60 should apply either the individual patch (RAID 1158263) or the February 2026 Patch Roll-up, or later update.
Revisiegeschiedenis (1)
Initiële publicatie — 21 juli 2026
Initial Republication of Rockwell Automation SD1786
ICSA-26-202-06
Siemens CADRA
Siemens — CADRA
Gepubliceerd
14 juli 2026
Laatste update
21 juli 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
Mitigatiesamenvatting
Update to V2511 or later version
Revisiegeschiedenis (2)
Initiële publicatie — 14 juli 2026
Publication Date
Update A — 21 juli 2026
Initial CISA Republication of Siemens ProductCERT SSA-470355 advisory
ICSA-26-202-05
Siemens IAM Client
Siemens — COMOS V10.4.5
Risk evaluation
Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.
Mitigatiesamenvatting
Update to V10.6.1 or later version
Revisiegeschiedenis (2)
Initiële publicatie — 14 juli 2026
Publication Date
Update A — 21 juli 2026
Initial CISA Republication of Siemens ProductCERT SSA-288252 advisory
ICSA-26-202-04
Siemens SIDIS Secured SmartPlug
Siemens — SIDIS Secured SmartPlug
Gepubliceerd
14 juli 2026
Laatste update
21 juli 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version.
Mitigatiesamenvatting
Update to V7.26.0310 or later version
Revisiegeschiedenis (2)
Initiële publicatie — 14 juli 2026
Publication Date
Update A — 21 juli 2026
Initial CISA Republication of Siemens ProductCERT SSA-585531 advisory
ICSA-26-202-03
Siemens Opcenter X
Siemens — Opcenter X
Risk evaluation
Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version.
Mitigatiesamenvatting
Update to V2604 or later version
Revisiegeschiedenis (2)
Initiële publicatie — 14 juli 2026
Publication Date
Update A — 21 juli 2026
Initial CISA Republication of Siemens ProductCERT SSA-096828 advisory
ICSA-26-202-02
Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW
Siemens — RUGGEDCOM APE1808
Gepubliceerd
14 juli 2026
Laatste update
21 juli 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/
Mitigatiesamenvatting
Contact customer support to receive patch and update information
Revisiegeschiedenis (2)
Initiële publicatie — 14 juli 2026
Publication Date
Update A — 21 juli 2026
Initial CISA Republication of Siemens ProductCERT SSA-104023 advisory
ICSA-26-202-01
Tycon Systems TPDIN-Monitor-WEB2
Tycon Systems — TPDIN-Monitor-WEB2
Gepubliceerd
21 juli 2026
Laatste update
21 juli 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.
Mitigatiesamenvatting
Tycon Systems did not respond to CISA's attempts at coordination. Users of Tycon Systems TPDIN-Monitor-WEB2 are encouraged to contact Tycon Systems and keep their systems up to date.
Revisiegeschiedenis (1)
Initiële publicatie — 21 juli 2026
Initial Publication
ICSA-26-197-09
Rockwell Automation FactoryTalk DataMosaix
Rockwell Automation — DataMosaix Private Cloud
Risk evaluation
Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious scripts on the server.
Mitigatiesamenvatting
Rockwell Automation recommends users to upgrade to the following: DataMosaix Private Cloud versions 8.03 or later.
Revisiegeschiedenis (1)
Initiële publicatie — 16 juli 2026
Initial Republication of Rockwell Automation Security Advisory SD1787
ICSA-26-197-08
Rockwell Automation Flex 5000 Adapter
Rockwell Automation — Flex 5000 Adapter
Risk evaluation
Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition on the affected product.
Mitigatiesamenvatting
Rockwell Automation recommends users to upgrade to the following: Flex 5000 Adapter version 6.012.
Revisiegeschiedenis (1)
Initiële publicatie — 16 juli 2026
Initial Republication of Rockwell Automation Security Advisory SD1789
ICSA-26-197-07
SALTO ProAccess Space
SALTO — ProAccess Space
Risk evaluation
Successful exploitation of this vulnerability allows an authenticated attacker to escalate privileges and access spaces outside their assigned partition, within the same Salto ProAccess Space installation or system. Exploitation requires valid authenticated operator credentials and the partition feature to be enabled; installations without partitioning are not affected.
Mitigatiesamenvatting
Users of SALTO ProAccess using the tenancy feature should upgrade to version 6.13.
Revisiegeschiedenis (1)
Initiële publicatie — 16 juli 2026
Initial Publication
ICSA-26-197-06
Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix
Rockwell Automation — CompactLogix 5370
Gepubliceerd
16 juli 2026
Laatste update
16 juli 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition.
Mitigatiesamenvatting
Rockwell Automation recommend updating to the following: CompactLogix 5370: Update to V35.016, V36.011 and later
Revisiegeschiedenis (1)
Initiële publicatie — 16 juli 2026
Initial Publication
ICSA-26-197-05
Siemens SICAM 8
Siemens — CPCI85 Central Processing/Communication
Gepubliceerd
9 juli 2026
Laatste update
16 juli 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: - SICAM A8000 Device firmware - CPCI85 for CP-8031/CP-8050 - SICORE for CP-8010/CP-8012 - SICAM EGS Device firmware - CPCI85 - SICAM S8000 - SICORE Siemens has released new versions for the affected products and recommends to update to the latest versions.
Mitigatiesamenvatting
Update to V26.20 or later version The firmware CPCI85 V26.20 is present within “CP-8031/CP-8050 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109804985/ and also within “SICAM EGS Package” V26.20 https://support.industry.siemens.com/cs/document/109972536/
Revisiegeschiedenis (2)
Initiële publicatie — 9 juli 2026
Publication Date
Update A — 16 juli 2026
Initial CISA Republication of Siemens SSA-229470 advisory
ICSA-26-197-04
AutomationDirect Productivity Suite
AutomationDirect — Productivity Suite
Gepubliceerd
16 juli 2026
Laatste update
16 juli 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
Successful exploitation of these vulnerabilities could allow an attacker with local or physical access to cause memory corruption, unintended information disclosure, application instability, or a denial-of-service condition in the affected product.
Mitigatiesamenvatting
AutomationDirect recommends that users update Productivity suite to v4.7.0.47 and above https://www.automationdirect.com/support/software-downloads.
Revisiegeschiedenis (1)
Initiële publicatie — 16 juli 2026
Initial Publication
ICSA-26-197-03
NASA Core Flight System (cFS) Health & Safety (HS) Application
NASA — Core Flight System (cFS) Health & Safety (HS) Application
Risk evaluation
Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.
Mitigatiesamenvatting
NASA recommends users update to v7.0.1 (https://github.com/nasa/HS/releases/tag/v7.0.1)
Revisiegeschiedenis (1)
Initiële publicatie — 16 juli 2026
Initial Publication
ICSA-26-197-02
Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT
Rockwell Automation — 1756-EN3
Risk evaluation
Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.
Mitigatiesamenvatting
Rockwell Automation recommends users take the following actions: 1756-EN3: Update to V12.002
Revisiegeschiedenis (1)
Initiële publicatie — 16 juli 2026
Initial Publication
ICSA-26-197-01
Rockwell Automation Arena
Rockwell Automation — Arena
Gepubliceerd
16 juli 2026
Laatste update
16 juli 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
Successful exploitation these vulnerabilities could allow an attacker to execute arbitrary code in the context of the current process.
Mitigatiesamenvatting
Rockwell Automation recommends users to update to V17.00.01
Revisiegeschiedenis (1)
Initiële publicatie — 16 juli 2026
Initial Publication
ICSA-26-195-04
Rockwell Automation 1715-AENTR EtherNet/IP Adapter
Rockwell Automation — 1715-AENTR EtherNet/IP Adapter
Risk evaluation
Successful exploitation of this vulnerability could allow an attacker to read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device.
Mitigatiesamenvatting
Rockwell Automation recommends that users update to 1715-AENTR EtherNet/IP Adapter version 3.011 and later.
Revisiegeschiedenis (1)
Initiële publicatie — 14 juli 2026
Initial Republication of Rockwell Automation security advisory SD1785.
ICSA-26-195-03
ABB T-MAC Plus
ABB — T-MAC Plus
Gepubliceerd
3 juni 2026
Laatste update
14 juli 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. An attacker who successfully exploited any of these vulnerabilities could potentially compromise the system in different ways.
Mitigatiesamenvatting
ABB has investigated these vulnerabilities to provide adequate protection to customers. The problem is corrected in the following product versions: T-MAC Plus version 4.0-25 ABB recommends that customers apply the update at earliest convenience.
Revisiegeschiedenis (2)
Initiële publicatie — 3 juni 2026
Initial version.
Update A — 14 juli 2026
Initial CISA Republication of ABB PSIRT 9AKK108472A7840 advisory
ICSA-26-195-02
ABB Ability Edgenius
ABB — Onbekend product
Risk evaluation
ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete control of the system
Mitigatiesamenvatting
The problem is corrected in the following product versions: - Edgenius 3.2.4.1 ABB recommends that customers apply the update at earliest convenience.
Revisiegeschiedenis (2)
Initiële publicatie — 25 juni 2026
Initial version.
Update A — 14 juli 2026
Initial CISA Republication of ABB PSIRT 7PAA024620 advisory
ICSA-26-195-01
ABB Advant Master Online Builder
ABB — Control Builder A
Risk evaluation
ABB became aware of vulnerability in the products versions listed as affected in the advisory, where an incorrect version of Online Builder (ONB) was included in the media. An update is available that resolves the vulnerability, see details in Recommended immediate actions.
Mitigatiesamenvatting
ABB has investigated the vulnerability and remediated it in the newly released versions. The vulnerability has been resolved in the product versions listed as fixed in the advisory. - Version 6.1.1-2 does not contain this vulnerability and therefore no update is required. The vulnerability was again introduced in 6.1.1-3 when an older ONB version was included in the release media. - Version 6.1.1-4 do not contain this vulnerability but present version 6.1.1-3 by 800xA System Installer and System Configuration Console (SCC). Version 6.1.1-4 is therefore withdrawn. - Version 6.2.0-2 do not contain this vulnerability but present version 6.2.0-1 by 800xA System Installer and System Configuration Console (SCC). Version 6.2.0-2 is therefore withdrawn. ABB recommends that customers apply the update at their earliest convenience. - Control Builder A: It is recommended to update Control Builder A to version 1.4/5 or later. - 800xA for Advant Master: - Versions 6.0.3-1 and earlier, - Versions 6.1.1-1 and earlier, - Versions 6.1.1-2, 6.1.1-3, and 6.1.1-4 should be updated to version 6.1.1-5 or later. - 800xA for Advant Master: - Versions 6.2.0-1 and 6.2.0-2 should be updated to version 6.2.0-3 or later.
Revisiegeschiedenis (2)
Initiële publicatie — 23 juni 2026
Initial version.
Update A — 14 juli 2026
Initial CISA Republication of ABB PSIRT 7PAA020047 advisory
ICSA-26-190-03
Schneider Electric Easergy MiCOM Px40 Series
Schneider Electric — Easergy MiCOM P14x
Risk evaluation
Schneider Electric is aware of a vulnerability in its Easergy MiCOM Px40 Series products. The [Easergy MiCOM Px40](https://www.se.com/ww/en/product-subcategory/4725-easergy-micom-px40-series/?filter=business-6-medium-voltage-distribution-and-grid-automation) is a protection relay series for Medium Voltage, High Voltage and Extra High Voltage protection. Failure to apply the mitigations provided below may risk unauthorized exposure of basic device identification through the SNMP protocol.
Mitigatiesamenvatting
For customers who do not require SNMP Contact Schneider Electric's [Customer Care Center](https://www.se.com/ww/en/work/support/contacts.jsp) to upgrade the Firmware to a version without SNMP functionality. If customers choose not to apply the upgrade provided above, they should immediately apply the following mitigations to reduce the risk of exploit: * Use relays only in a protected network environment, * Use firewalls to protect and separate the control system network from other networks, * Use VPN (Virtual Private Networks) tunnels if remote access is required. For customers who require SNMP Please immediately apply the following mitigations to reduce the risk of exploit: * Use relays only in a protected network environment, * Use firewalls to protect and separate the control system network from other networks, * Use VPN (Virtual Private Networks) tunnels if remote access is required.
Revisiegeschiedenis (3)
Initiële publicatie — 14 april 2026
Original Release
Update A — 12 mei 2026
Updated the risk associated with successful exploitation of this vulnerability and revised the remediation table to a mitigation table to emphasize that multiple mitigation options are available.
Update B — 9 juli 2026
Initial CISA Republication of Schneider Electric CPCERT SEVD-2026-104-03 advisory
ICSA-26-190-02
Schneider Electric PowerChute Serial Shutdown
Schneider Electric — PowerChute™ Serial Shutdown
Gepubliceerd
14 april 2026
Laatste update
9 juli 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
Schneider Electric is aware of vulnerabilities in its PowerChute™ Serial Shutdown product. The [PowerChute Serial Shutdown](https://www.se.com/ww/en/product-range/137943580-powerchute-serial-shutdown/#products) product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktop, servers and workstations. Failure to apply the remediation provided below may risk improper input validation which could result in disruption of operations and access to system data.
Mitigatiesamenvatting
Version v1.5 of PowerChute™ Serial Shutdown includes a fix for this vulnerability and is available for download here: • Windows: https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/ Specific instructions and hardening guidelines for these mitigations can be found in the [Security Handbook](https://download.schneider-electric.com/files?p_Doc_Ref=SPD_CCON-PCSSSH_EN).
Revisiegeschiedenis (2)
Initiële publicatie — 14 april 2026
Original Release
Update A — 9 juli 2026
Initial CISA Republication of Schneider Electric CPCERT SEVD-2026-104-01 advisory
ICSA-26-190-01
OpenPLC v3
OpenPLC — OpenPLC
Risk evaluation
Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to the filesystem and escalate this into arbitrary native code execution through the normal OpenPLC program compilation process, potentially resulting in code execution as the OpenPLC runtime user.
Mitigatiesamenvatting
OpenPLC recommends users upgrade to OpenPLC v4 as OpenPLC v3 is end-of-life and is no longer receiving patches, bug fixes, or security updates.
Revisiegeschiedenis (1)
Initiële publicatie — 9 juli 2026
Initial Publication
ICSA-26-188-07
Digi International PortServer TS, Digi One SP IA
Digi International — PortServer TS
Gepubliceerd
7 juli 2026
Laatste update
7 juli 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication and gain access to restricted resources, obtain credentials, and inject malicious scripts.
Mitigatiesamenvatting
Digi International recommends users upgrade to Digi Connect EZ or Digi Connect EZ TS as a long term solution. If users are not able to upgrade at this time, the following actions should be taken:
Revisiegeschiedenis (1)
Initiële publicatie — 7 juli 2026
Initial Publication
ICSA-26-188-06
Labcenter Proteus 9
Labcenter Electronics — Proteus
Gepubliceerd
7 juli 2026
Laatste update
7 juli 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
Successful exploitation of these vulnerabilities could disclose information and allow a malicious user to execute arbitrary code on affected installations.
Mitigatiesamenvatting
Labcenter recommends ensuring you are using the latest version (9.2 SPO) of the software. Version can be found by looking at the bottom left of the Proteus home page (Version 8 or higher) or by selecting the About ISIS or About ARES option from the Help menu. Update notifications appear in the new and information section of the home page where you can activate the download and installation directly.
Revisiegeschiedenis (1)
Initiële publicatie — 7 juli 2026
Initial Publication
ICSA-26-188-05
Siemens SINEC OS
Siemens — RUGGEDCOM RST2428P (6GK6242-6PA00)
Gepubliceerd
2 juni 2026
Laatste update
7 juli 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
SINEC OS before V4.0 contains multiple vulnerabilities. Siemens has released a new version for RUGGEDCOM RST2428P and recommends to update to the latest version.
Mitigatiesamenvatting
Update to V4.0 or later version
Revisiegeschiedenis (2)
Initiële publicatie — 2 juni 2026
Publication Date
Update A — 7 juli 2026
Initial CISA Republication of Siemens ProductCERT SSA-253495 advisory
ICSA-26-188-04
Siemens Mendix Studio Pro
Siemens — Mendix Studio Pro 10.11
Risk evaluation
Mendix Studio Pro versions before V11.12 are affected by a file parsing vulnerability that could be triggered when the application reads specially crafted malicious project during the build pipeline. This could allow an attacker to execute arbitrary code in the context of that user. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.
Mitigatiesamenvatting
Currently no fix is planned
Revisiegeschiedenis (2)
Initiële publicatie — 30 juni 2026
Publication Date
Update A — 7 juli 2026
Initial CISA Republication of Siemens ProductCERT SSA-779310 advisory
ICSA-26-188-03
Hitachi Energy e-mesh EMS
Hitachi Energy — Hitachi Energy e-mesh EMS
Risk evaluation
Hitachi Energy is aware of a buffer overflow vulnerability that affects e-mesh EMS product versions listed in this document. Successful exploitation of this vulnerability could lead to a buffer overflow condition, potentially resulting in application outages (denial of service) and possible arbitrary code execution. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.
Mitigatiesamenvatting
Apply hotfix for respective e-mesh EMS versions to update NGINX to either v1.30.2 or latest
Revisiegeschiedenis (2)
Initiële publicatie — 30 juni 2026
Initial public release
Update A — 7 juli 2026
Initial CISA Republication of Hitachi Energy PSIRT 8DBD000253 advisory
ICSA-26-188-02
Hitachi Energy PROMOD V
Hitachi Energy — PROMOD V
Risk evaluation
Hitachi Energy is aware of insecure HTTP transmission vulnerability in PROMOD V product versions listed in this document. This vulnerability could allow attackers to intercept or manipulate sensitive data in transit, potentially leading to credential theft, session hijacking, or unauthorized access.
Mitigatiesamenvatting
Upgrade to version 1.0.11 and enable HTTPS on Digipede server. [2] Refer to “1.0.11 PROMOD V User Guide”, Section 2 Essential Skills->Running PROMOD V->Digipede Grid. Alternatively, refer to the same section in the online help contained in the application.
Revisiegeschiedenis (2)
Initiële publicatie — 30 juni 2026
Initial public release
Update A — 7 juli 2026
Initial CISA Republication of Hitachi Energy PSIRT 8DBD000250 advisory
ICSA-26-188-01
Hydro-Québec Le Circuit Electrique charging station backend
Hydro-Québec — Le Circuit Electrique charging station backend
Gepubliceerd
7 juli 2026
Laatste update
7 juli 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
Successful exploitation of these vulnerabilities could lead to privilege escalation, or result in a denial-of-service attack.
Mitigatiesamenvatting
Hydro-Québec has updated the majority of charging stations to disable OCPP, mitigating the risk of exploitation. Hydro-Québec has also implemented authentication systems to mitigate the issue for certain charging stations which are still reliant on OCPP. Contact Hydro-Québec with any additional questions.
Revisiegeschiedenis (1)
Initiële publicatie — 7 juli 2026
Initial Publication
ICSA-26-183-02
CubeSpace CW0057 Reaction Wheel
CubeSpace — CW0057 Reaction Wheel
Risk evaluation
Successful exploitation of this vulnerability could allow an attacker to upload arbitrary malicious firmware to the device.
Mitigatiesamenvatting
CubeSpace has released the following firmware versions for users to enable: Firmware version 5.0.20. Firmware version 5.0.20 introduces the capability for cryptographically verified secure boot; however, this protection is not enabled by default. Users must activate signed‑boot functionality, particularly the fully immutable mode, to achieve full security.
Revisiegeschiedenis (1)
Initiële publicatie — 2 juli 2026
Initial Publication
ICSA-26-183-01
ST Engineering iDirect iQ-Series Terminals
ST Engineering iDirect — Evolution iQ‑Series terminals
Gepubliceerd
2 juli 2026
Laatste update
2 juli 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition.
Mitigatiesamenvatting
ST Engineering iDirect has fixed the vulnerabilities and recommend users update the software to version 4.5.2.2 or newer.
Revisiegeschiedenis (1)
Initiële publicatie — 2 juli 2026
Initial Publication
ICSA-26-183-03
Gardyn IoT Hub
Gardyn — Home Firmware
Gepubliceerd
2 juli 2026
Laatste update
2 juli 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
Successful exploitation of these vulnerabilities could allow unauthenticated users to access and control IoT Hub managed devices.
Mitigatiesamenvatting
Gardyn states that IoT Hub deployed infrastructure has been updated to fix the listed vulnerabilities.
Revisiegeschiedenis (1)
Initiële publicatie — 2 juli 2026
Initial Publication
ICSMA-26-181-01
OFFIS DCMTK Toolkit
OFFIS — DCMTK
Gepubliceerd
30 juni 2026
Laatste update
30 juni 2026
Getroffen sectoren
Risk evaluation
Successful exploitation of these vulnerabilities could allow an attacker to write files, access unauthorized information, exhaust memory, or crash affected DCMTK client or server processes.
Mitigatiesamenvatting
The maintainer was notified of these vulnerabilities and has provided a fix. The fix is included in the latest commits and can be obtained in the following snapshot:
Revisiegeschiedenis (1)
Initiële publicatie — 30 juni 2026
Initial Publication
ICSA-26-181-07
Delta Electronics DVP12SE PLC
Delta Electronics — DVP12SE PLC
Gepubliceerd
30 juni 2026
Laatste update
30 juni 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
Successful exploitation of these vulnerabilities could allow an attacker to remotely issue commands, modify operational values, interfere with control logic, and alter device behavior without authentication or privilege enforcement.
Mitigatiesamenvatting
Delta Electronics is aware of these vulnerabilities and is currently working on a fix.
Revisiegeschiedenis (1)
Initiële publicatie — 30 juni 2026
Initial Publication
ICSA-26-181-06
StoneFly Storage Concentrator
StoneFly — Storage Concentrator
Gepubliceerd
30 juni 2026
Laatste update
30 juni 2026
Getroffen sectoren
Risk evaluation
Successful exploitation of these vulnerabilities could allow attackers to gain broad unauthorized access, execute arbitrary commands with root privileges, steal sensitive data, and perform actions on behalf of legitimate users across interconnected systems.
Mitigatiesamenvatting
StoneFly recommends that users upgrade to Storage Concentrator version 8.0.4.29 or later to remediate these vulnerabilities.
Revisiegeschiedenis (1)
Initiële publicatie — 30 juni 2026
Initial Publication
ICSA-26-181-05
XZ Utils vulnerability impacting B&R Products
B&R Industrial Automation GmbH — PPC3100
Risk evaluation
An update is available that resolves vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the product to stop or corrupt memory data.
Mitigatiesamenvatting
The problem is corrected in the following product versions: Product Terminal OS Version - PPC3100 1.8.1 - C50 1.8.0 - C80 1.8.0 - FT50 1.8.1 - MT50 1.8.1 - T30 1.8.0 - T80 1.8.0 - T50 1.8.1 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.
Revisiegeschiedenis (2)
Initiële publicatie — 10 juni 2026
Initial version.
Update A — 30 juni 2026
Initial CISA Republication of ABB PSIRT SA26P009 advisory
ICSA-26-181-03
Schneider Electric EcoStruxure IT Data Center Expert
Schneider Electric — EcoStruxure IT Data Center Expert
Risk evaluation
Schneider Electric is aware of a vulnerability in its EcoStruxure™ IT Data Center Expert. The EcoStruxure™ IT Data Center Expert product is a scalable monitoring software that collects, organizes, and distributes critical device information providing a comprehensive view of equipment. Failure to apply the remediation provided below may risk information disclosure.
Mitigatiesamenvatting
v9.1.2 of EcoStruxure™ IT Data Center Expert includes a fix for this vulnerability and is available for download here: https://www.se.com/en/product-range/61851-ecostruxure-it-data- center-expert/#software-and-firmware
Revisiegeschiedenis (2)
Initiële publicatie — 9 juni 2026
Original Release
Update A — 30 juni 2026
Initial CISA Republication of Schneider Electric CPCERT SEVD-2026-160-01 advisory
ICSA-26-181-02
Frangoteam FUXA SCADA/HMI
Frangoteam — FUXA SCADA/HMI
Risk evaluation
Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to enumerate all user accounts and role assignments on a FUXA SCADA/HMI instance.
Mitigatiesamenvatting
Frangoteam recommends users apply the latest version of FUXA 1.3.2 or later https://github.com/frangoteam/FUXA/releases.
Revisiegeschiedenis (1)
Initiële publicatie — 30 juni 2026
Initial Publication
ICSA-26-181-01
Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M
Mitsubishi Electric — MELSOFT Update Manager SW1DND-UDM-M
Gepubliceerd
30 juni 2026
Laatste update
30 juni 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
Successful exploitation of these vulnerabilities could allow a local attacker to tamper with or destroy information in the affected product, cause a denial-of-service condition in the affected product, or execute arbitrary code when a specially crafted archive file is decompressed by the 7-Zip component included in MELSOFT Update Manager.
Mitigatiesamenvatting
Mitsubishi Electric has identified the following specific workarounds and mitigations users can apply to reduce risk:
Revisiegeschiedenis (1)
Initiële publicatie — 30 juni 2026
Initial Republication of Mitsubishi Electric 2026-004
ICSMA-26-176-02
OHIF Viewers DICOM
Open Health Imaging Foundation (OHIF) — OHIF DICOM Web Viewer Framework
Risk evaluation
Successful exploitation of this vulnerability in a custom integration version could allow an attacker to steal an authenticated clinician's token via a crafted link.
Mitigatiesamenvatting
The maintainer has fixed the reported vulnerability and released version 3.12.2 (2026-05-18). The fix is located at OHIF/Viewers#5985 (master), OHIF/Viewers#5978 (release/3.12).
Revisiegeschiedenis (1)
Initiële publicatie — 25 juni 2026
Initial Publication
ICSMA-26-176-01
pydicom pynetdicom Library
pydicom — pynetdicom
Risk evaluation
Successful exploitation of this vulnerability could allow an unauthenticated attacker to write to arbitrary file paths.
Mitigatiesamenvatting
The maintainer of pynetdicom has not responded to requests to work with CISA to mitigate this vulnerability. For update information, refer to the github page https://github.com/pydicom/pynetdicom.
Revisiegeschiedenis (1)
Initiële publicatie — 25 juni 2026
Initial Publication
ICSA-26-181-04
Schneider Electric EasyLogic T150 and Saitel DP RTU
Schneider Electric — EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller
Gepubliceerd
9 juni 2026
Laatste update
25 juni 2026
Gekoppelde CVE's
Getroffen sectoren
Onderstations, Transmissie, Energieopwekking
Risk evaluation
Schneider Electric is aware of a vulnerability in its EasyLogic T150 (formerly known as Saitel DR) and Saitel DP Remote Terminal Unit & Controller products. The [EasyLogic T150 (formerly known as Saitel DR RTU)](https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=62685#overview) is a field device, offering a solid and powerful modular platform for data acquisition, communication, automation and IED integration for distribution and transmission networks, generation sector and railway. The [Saitel DP RTU](https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=61747) is a modular platform for medium voltage and high voltage public distribution and transmission substation control. Failure to apply the mitigations provided below may risk credential harvesting and unauthorized access attacks, which could result in exposure of sensitive information and compromise of device integrity and operations when an attacker has subsequent physical access to the device.
Mitigatiesamenvatting
Version 11.06.32 of EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller includes a fix for these vulnerabilities and is available:• Contact Schneider Electric’s Customer Care Center to download this firmware.• Reboot needed: Yes.
Revisiegeschiedenis (2)
Initiële publicatie — 9 juni 2026
Original Release
Update A — 30 juni 2026
Initial CISA Republication of Schneider Electric CPCERT SEVD-2026-160-02 advisory
ICSA-26-176-07
Schneider Electric PowerLogic P7
Schneider Electric — PowerLogic™ P7
Gepubliceerd
9 juni 2026
Laatste update
25 juni 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
Schneider Electric is aware of a vulnerability in its PowerLogic™ P7 product. The PowerLogic™ P7 is a protection and control platform designed for complex and advanced electrical network applications. Failure to apply the remediation provided below may risk unauthorized execution of privileged commands or loss of HMI operability and configuration functionality, which could result in loss of control over system operations and disruption of critical services.
Mitigatiesamenvatting
Version V02.004.001 of PowerLogicTM P7 includes a fix for this vulnerability and is available for download here: • Contact Schneider Electric’s Customer Care Center to download this firmware. • Reboot needed: Yes
Revisiegeschiedenis (2)
Initiële publicatie — 9 juni 2026
Original Release
Update A — 25 juni 2026
Initial CISA Republication of Schneider Electric CPCERT SEVD-2026-160-03 advisory
ICSA-26-176-06
Delta Electronics DTM Soft
Delta Electronics — DTMSoft
Risk evaluation
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code.
Mitigatiesamenvatting
Delta Electronics is aware of the vulnerability and is currently working on a fix.
Revisiegeschiedenis (1)
Initiële publicatie — 25 juni 2026
Initial Republication of Delta Electronics Product Cybersecurity Advisory Delta-PCSA-2026-00010
ICSMA-26-169-01
Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT
Apollo Pharmacy — Blood Glucose Monitoring System (Model No. APG-01 BT)
Gepubliceerd
18 juni 2026
Laatste update
18 juni 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
Successful exploitation of these vulnerabilities could allow an attacker to obtain sensitive health-related information and prevent legitimate users from establishing a connection with the device.
Mitigatiesamenvatting
Apollo Pharmacy did not respond to CISA's requests to coordinate. Users are encouraged to reach out to Apollo Pharmacy directly for more information:https://www.apollopharmacy.in/contact-us.
Revisiegeschiedenis (1)
Initiële publicatie — 18 juni 2026
Initial Publication
ICSMA-26-148-01
Fourth Frontier Frontier X Mobile Application, Frontier X2
Fourth Frontier — Frontier X Android application
Risk evaluation
Successful exploitation of this vulnerability could allow an attacker to read and write arbitrary handle values and change clinical readings, which could result in taking control of the device and lead to patient harm.
Mitigatiesamenvatting
Fourth Frontier is aware of the vulnerability and is working on a fix. Users are encouraged to reach out to Fourth Frontier directly for assistance. https://fourthfrontier.com/pages/contact-usl.
Revisiegeschiedenis (1)
Initiële publicatie — 28 mei 2026
Initial Publication
ICSMA-26-146-01
Eppendorf BioFlo 320
Eppendorf — BioFlo 320 Bioreactor
Risk evaluation
Successful exploitation of this vulnerability could allow an attacker to gain full access to functionality and data with the bioreactor.
Mitigatiesamenvatting
Eppendorf has released a software update that permanently removes VNC access from the controller. Users should download and apply this update from: https://www.eppendorf.com/software-downloads.
Revisiegeschiedenis (1)
Initiële publicatie — 26 mei 2026
Initial Publication
ICSMA-26-083-01
Grassroots DICOM (GDCM)
Grassroots — Grassroots DICOM (GDCM)
Risk evaluation
Successful exploitation of this vulnerability could allow an attacker to send a specially crafted file, and when parsed, could result in a denial-of-service condition.
Mitigatiesamenvatting
The maintainer of Grassroots DICOM (GDCM) has not responded to requests to work with CISA to mitigate this vulnerability. For update information refer to the software page on SourceForge.
Revisiegeschiedenis (1)
Initiële publicatie — 24 maart 2026
Initial Publication.
ICSMA-26-041-01
ZOLL ePCR IOS Mobile Application
ZOLL — ePCR IOS Mobile Application
Gepubliceerd
10 februari 2026
Laatste update
10 februari 2026
Gekoppelde CVE's
Getroffen sectoren
Risk evaluation
Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to protected health information (PHI) or device telemetry.
Mitigatiesamenvatting
ZOLL ePCR IOS application was decommissioned in May 2025. ZOLL has no current plans to provide a replacement application. If users have questions or concerns, they are encouraged to reach out directly to ZOLL Support. https://www.zolldata.com/contact-us.
Revisiegeschiedenis (1)
Initiële publicatie — 10 februari 2026
Initial Publication