Direct naar inhoud
IACS RadarIndustrial Cyber Exposure & Intelligence

CISA + leveranciers

ICS Advisories

Advisories specifiek gericht op industriële besturingssystemen — van CISA ICS-CERT en rechtstreeks van leveranciers (Siemens ProductCERT, ABB PSIRT) — inclusief revisiegeschiedenis (initiële publicatie, Update A, Update B) en gekoppelde CVE's.

132

Gevonden

Advisorydata: live koppeling— laatst opgehaald: 23 september 2026 om 01:39.

Filters

132 advisories gevonden

SSA-814963

SSA-814963: Insecure Inherited Permission in Mendix (Revoked)

SiemensMendix Runtime

Siemens ProductCERTlaag

Gepubliceerd

14 juli 2026

Laatste update

22 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

This advisory is revoked. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute.

Mitigatiesamenvatting

Zie de officiële CISA-advisory voor mitigerende maatregelen.

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A22 september 2026

    Revoked advisory as the CVE is rejected

Officiële bron: Siemens ProductCERT

7PAA010706

Freelance Missing Length Check

ABBSystem Version

ABB PSIRThoog

Gepubliceerd

18 september 2026

Laatste update

18 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

ABB is aware of a vulnerability in the product versions listed as affected in the advisory. An update is available that resolves the reported vulnerability in the product versions under maintenance. An attacker who successfully exploited this vulnerability could cause the product to stop or make the product inaccessible.

Mitigatiesamenvatting

Refer to section “General security recommendations” for further advice on how to keep your system secure, as well checking the section “Workarounds”.

Revisiegeschiedenis (1)
  1. Initiële publicatie18 september 2026

    Initial version.

Officiële bron: ABB PSIRT

ICSA-26-211-07

Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)

Mitsubishi ElectricMitsubishi Electric MELSEC MX Controller MX-R model MXR300-16

CISAhoog

Gepubliceerd

30 juli 2026

Laatste update

17 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly.

Mitigatiesamenvatting

For customers using the affected products, please refer to Mitsubishi Electric's security advisory, "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-005_en.pdf" and take the measures described there.

Revisiegeschiedenis (4)
  1. Initiële publicatie30 juli 2026

    Initial Publication

  2. Update A30 juli 2026

    CISA Republication - Initial CISA Republication of Mitsubishi Electric 2026-005 advisory

  3. Update B17 september 2026

    MXF100S-N32, MXF100S-P32, MXF100S-8-N32, MXF100S-8-P32, MXF100S-16-N32, MXF100S-16-P32, LD78G4, and LD78G16 have been added as affected products and MI2532-W, MI2332-W, and NZ2GACP610-60 have been removed from affected products.

  4. Update C17 september 2026

    CISA Republication update based on Mitsubishi Electric 2026-005 advisory

Officiële bron: CISA

4JDE002044

dynovaPRO™ Reset Credentials Vulnerability

ABBdynovaPRO™ cloud system < 2026-08-27 12:00 (CEST)

ABB PSIRTkritiek

Gepubliceerd

17 september 2026

Laatste update

17 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

ABB is aware of public reports of a vulnerability in the product listed as affected in the advisory. An update has been deployed to the cloud system that resolves a publicly reported vulnerability in the product versions listed above. An attacker who successfully exploited this vulnerability could take remote control of the product. The vulnerability has been identified in the keycloak authentication component which is integrated into dynovaPRO™. The vulnerability exists in the 'Forgot Password' functionality and allows unauthenticated attackers to bypass authentication and hijack user accounts. Users who have received a password reset mail before the mentioned date, without having requested it, are thereby potentially attacked by exploiting this vulnerability. ABB investigated potentially malicious user reset activities and blocked those user access immediately to reduce the exploitation risk. The credentials of those users have been deleted after the software fix was deployed and the users were informed that they must reset their password to gain access to dynovaPRO™ again.

Mitigatiesamenvatting

The following conditions reduce the risk of exploitation of this vulnerability: - Limited Attack Surface: The vulnerability is specific to the password reset functionality. Other authentication methods are not affected. - Email Notifications: Legitimate users receive email notifications during password reset attempts, which may alert them to unauthorized access attempts. Refer to section “General security recommendations” for further advise on how to keep your system secure.

Revisiegeschiedenis (1)
  1. Initiële publicatie17 september 2026

    Initial version

Officiële bron: ABB PSIRT

SSA-823812

SSA-823812: Denial of Service Vulnerability in WTV676 and WTV776 devices

SiemensWTV676-HB6035 Web Interface

Siemens ProductCERTmiddel

Gepubliceerd

16 september 2026

Laatste update

16 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V3.94 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie16 september 2026

    Publication Date

Officiële bron: Siemens ProductCERT

3BHS973333

AC 800PEC, AC 800PEC ARM, AC 800PEC Tool, Control Terminal (xCT) and AC 800PEC Tool Cheetah Impacted by multiple vulnerabilities in Wibu CodeMeter

ABBAC 800PEC

ABB PSIRThoog

Gepubliceerd

10 september 2026

Laatste update

10 september 2026

Getroffen sectoren

Risk evaluation

An update is available that resolves a publicly reported vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited these vulnerabilities could - Allow arbitrary files to be deleted with system privileges (CVE-2026-81572), - Read potentially sensitive configuration data and overwrite selected values in Server.ini (CVE-2026-81573) - Crash CodeMeter and disclose sensitive information such as process memory and stack canar-ies (CVE-2026-81574) - Crash CodeMeter (CVE-2026-81575), or - Read potentially sensitive license information (CVE-2026-81576)

Mitigatiesamenvatting

For CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, and CVE-2026-81576: If you enabled the network server functionality at some point but no longer need it, disable it: - Open the Registry Editor and navigate to Computer\HKEY_LOCAL_MACHINE\SOFTWARE\ WIBUSYSTEMS\CodeMeter\Server\CurrentVersion\, then change the value of IsNetworkServerfrom 1 to 0. - Restart CodeMeter.

Revisiegeschiedenis (1)
  1. Initiële publicatie10 september 2026

    Initial version.

Officiële bron: ABB PSIRT

2NGA003144

ABB AbilityTM zenon Security Risk Due to High-Severity Vulnerabilities in WIBU CodeMeter Runtime

ABBAbilityTM zenon

ABB PSIRThoog

Gepubliceerd

9 september 2026

Laatste update

9 september 2026

Getroffen sectoren

Risk evaluation

ABB is aware of publicly disclosed security vulnerabilities affecting the WIBU-Systems CodeMeter Runtime for Windows, identified as CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575 and CVE-2026-81576. The CodeMeter Runtime component is used within affected ABB zenon Software Platform installations for software licensing and license server functionality. Successful exploitation of the reported vulnerabilities could enable local privilege escalation on Windows systems and impact systems configured as CodeMeter license servers, potentially leading to unauthorized access, service disruption, or loss of system integrity. Refer to the WIBU-Systems advisory for detailed technical information on each vulnerability. Please see the References section for the WIBU-Systems security advisory.

Mitigatiesamenvatting

ABB recommends the following mitigation measures: - Update the WIBU-Systems CodeMeter Runtime to version 8.41a or later. - The latest CodeMeter Runtime software is available from the WIBU-Systems download page: User Software - Wibu-Systems, please see the References section for the corresponding link. - Where upgrading is not feasible, ABB recommends that asset owners perform a risk assessment and implement compensating controls such as network isolation, access restrictions, and enhanced monitoring of affected systems. ABB recommends that customers apply the update at earliest convenience. The vulnerabilities associated with CVE-2026-81573, CVE-2026-81574, CVE-2026-81575 and CVE-2026-81576 are exploitable only when the WIBU-Systems CodeMeter Runtime is configured as a network server, which is not the de-fault configuration. The CVE-2026-81572 vulnerability requires local access to the affected Windows system and execution by a low-privileged user. Consequently, systems with restricted local access, proper privilege management, and limited network exposure are less likely to be successfully compromised. Refer to section “General security recommendations” for further advise on how to keep your system secure.

Revisiegeschiedenis (1)
  1. Initiële publicatie9 september 2026

    Initial version.

Officiële bron: ABB PSIRT

SSA-019113

SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6

SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)

Siemens ProductCERTkritiek

Gepubliceerd

14 juli 2026

Laatste update

8 september 2026

Gekoppelde CVE's

CVE-2021-41617CVE-2023-28531CVE-2023-51384CVE-2023-52927CVE-2023-53292CVE-2024-26783CVE-2024-27056CVE-2024-28956CVE-2024-36903CVE-2024-36927CVE-2024-42079CVE-2024-46786CVE-2024-47736CVE-2024-47809CVE-2024-49968CVE-2024-49994CVE-2024-49998CVE-2024-50014CVE-2024-50063CVE-2024-50164CVE-2024-50298CVE-2024-53124CVE-2024-53170CVE-2024-54458CVE-2024-56631CVE-2024-56703CVE-2024-56719CVE-2024-57917CVE-2024-57924CVE-2024-57973CVE-2024-57977CVE-2024-57979CVE-2024-58011CVE-2024-58016CVE-2024-58020CVE-2024-58056CVE-2024-58058CVE-2024-58061CVE-2024-58086CVE-2025-21645CVE-2025-21648CVE-2025-21655CVE-2025-21676CVE-2025-21682CVE-2025-21702CVE-2025-21705CVE-2025-21706CVE-2025-21707CVE-2025-21718CVE-2025-21731CVE-2025-21745CVE-2025-21758CVE-2025-21760CVE-2025-21764CVE-2025-21765CVE-2025-21780CVE-2025-21795CVE-2025-21796CVE-2025-21802CVE-2025-21814CVE-2025-21846CVE-2025-21853CVE-2025-21861CVE-2025-21863CVE-2025-21864CVE-2025-21867CVE-2025-21875CVE-2025-21887CVE-2025-21913CVE-2025-21919CVE-2025-21925CVE-2025-21926CVE-2025-21938CVE-2025-21959CVE-2025-21999CVE-2025-22005CVE-2025-22015CVE-2025-22055CVE-2025-22056CVE-2025-22060CVE-2025-22083CVE-2025-22090CVE-2025-22095CVE-2025-22107CVE-2025-22111CVE-2025-22121CVE-2025-23136CVE-2025-23143CVE-2025-37785CVE-2025-37909CVE-2025-37917CVE-2025-37945CVE-2025-37959CVE-2025-37964CVE-2025-37972CVE-2025-37980CVE-2025-38125CVE-2025-38162CVE-2025-38192CVE-2025-38201CVE-2025-38232CVE-2025-38322CVE-2025-38591CVE-2025-38614CVE-2025-38681CVE-2025-38704CVE-2025-38721CVE-2025-38725CVE-2025-38727CVE-2025-38732CVE-2025-38736CVE-2025-39681CVE-2025-39691CVE-2025-39721CVE-2025-39748CVE-2025-39756CVE-2025-39764CVE-2025-39770CVE-2025-39773CVE-2025-39782CVE-2025-39795CVE-2025-39826CVE-2025-39827CVE-2025-39845CVE-2025-39866CVE-2025-39871CVE-2025-39931CVE-2025-39953CVE-2025-39955CVE-2025-39964CVE-2025-39977CVE-2025-39978CVE-2025-39980CVE-2025-40022CVE-2025-40070CVE-2025-40078CVE-2025-40080CVE-2025-40105CVE-2025-40135CVE-2025-40149CVE-2025-40196CVE-2025-40219CVE-2025-40261CVE-2025-40300CVE-2025-61984CVE-2025-61985CVE-2025-68206CVE-2025-68261CVE-2025-68264CVE-2025-68265CVE-2025-68266CVE-2025-68291CVE-2025-68337CVE-2025-68349CVE-2025-68363CVE-2025-68371CVE-2025-68724CVE-2025-68725CVE-2025-68742CVE-2025-68764CVE-2025-68773CVE-2025-68776CVE-2025-68782CVE-2025-68787CVE-2025-68788CVE-2025-68798CVE-2025-68803CVE-2025-68814CVE-2025-68816CVE-2025-68818CVE-2025-68820CVE-2025-71064CVE-2025-71075CVE-2025-71079CVE-2025-71085CVE-2025-71086CVE-2025-71088CVE-2025-71095CVE-2025-71097CVE-2025-71098CVE-2025-71104CVE-2025-71112CVE-2025-71113CVE-2025-71114CVE-2025-71120CVE-2025-71123CVE-2025-71131CVE-2025-71161CVE-2025-71162CVE-2025-71163CVE-2025-71185CVE-2025-71186CVE-2025-71189CVE-2025-71190CVE-2025-71191CVE-2025-71197CVE-2025-71221CVE-2025-71265CVE-2025-71266CVE-2025-71267CVE-2026-3497CVE-2026-22977CVE-2026-22979CVE-2026-22980CVE-2026-22982CVE-2026-22992CVE-2026-22994CVE-2026-23003CVE-2026-23005CVE-2026-23010CVE-2026-23011CVE-2026-23019CVE-2026-23026CVE-2026-23038CVE-2026-23054CVE-2026-23060CVE-2026-23083CVE-2026-23084CVE-2026-23086CVE-2026-23087CVE-2026-23095CVE-2026-23100CVE-2026-23103CVE-2026-23110CVE-2026-23111CVE-2026-23113CVE-2026-23154CVE-2026-23204CVE-2026-23231CVE-2026-23242CVE-2026-23243CVE-2026-23245CVE-2026-23255CVE-2026-23270CVE-2026-23271CVE-2026-23273CVE-2026-23274CVE-2026-23277CVE-2026-23284CVE-2026-23287CVE-2026-23290CVE-2026-23293CVE-2026-23300CVE-2026-23304CVE-2026-23319CVE-2026-23321CVE-2026-23335CVE-2026-23340CVE-2026-23343CVE-2026-23351CVE-2026-23359CVE-2026-23365CVE-2026-23368CVE-2026-23370CVE-2026-23378CVE-2026-23379CVE-2026-23381CVE-2026-23391CVE-2026-23392CVE-2026-23397CVE-2026-23398CVE-2026-23399CVE-2026-23414CVE-2026-23422CVE-2026-23434CVE-2026-23438CVE-2026-23439CVE-2026-23446CVE-2026-23449CVE-2026-23450CVE-2026-23452CVE-2026-23454CVE-2026-23455CVE-2026-23456CVE-2026-23457CVE-2026-23458CVE-2026-23463CVE-2026-23474CVE-2026-23475CVE-2026-27135CVE-2026-31389CVE-2026-31391CVE-2026-31396CVE-2026-31402CVE-2026-31403CVE-2026-31411CVE-2026-31414CVE-2026-31415CVE-2026-31416CVE-2026-31417CVE-2026-31418CVE-2026-31421CVE-2026-31422CVE-2026-31423CVE-2026-31424CVE-2026-31427CVE-2026-31428CVE-2026-31431CVE-2026-31441CVE-2026-31446CVE-2026-31447CVE-2026-31448CVE-2026-31449CVE-2026-31450CVE-2026-31452CVE-2026-31466CVE-2026-31469CVE-2026-31485CVE-2026-31494CVE-2026-31495CVE-2026-31496CVE-2026-31503CVE-2026-31504CVE-2026-31507CVE-2026-31508CVE-2026-31515CVE-2026-31518CVE-2026-31521CVE-2026-31533CVE-2026-31546CVE-2026-31555CVE-2026-31563CVE-2026-31565CVE-2026-31628CVE-2026-31634CVE-2026-31649CVE-2026-31651CVE-2026-31658CVE-2026-31664CVE-2026-31665CVE-2026-31669CVE-2026-31670CVE-2026-31671CVE-2026-31674CVE-2026-31680CVE-2026-31681CVE-2026-31682CVE-2026-31700CVE-2026-31737CVE-2026-31752CVE-2026-31761CVE-2026-31768CVE-2026-40355CVE-2026-41989CVE-2026-43011CVE-2026-43024CVE-2026-43025CVE-2026-43026CVE-2026-43027CVE-2026-43028CVE-2026-43030CVE-2026-43033CVE-2026-43035CVE-2026-43038CVE-2026-43040CVE-2026-43057CVE-2026-43071CVE-2026-43085CVE-2026-43089CVE-2026-43116CVE-2026-43216CVE-2026-43284CVE-2026-43303CVE-2026-43492CVE-2026-43499CVE-2026-43501CVE-2026-45841CVE-2026-46015CVE-2026-46021CVE-2026-46033CVE-2026-46037CVE-2026-46040CVE-2026-46046CVE-2026-46086CVE-2026-46101CVE-2026-46116CVE-2026-46132CVE-2026-46172CVE-2026-46173CVE-2026-46174CVE-2026-46193CVE-2026-46300CVE-2026-46303CVE-2026-46306CVE-2026-46323CVE-2026-46333CVE-2026-52910CVE-2026-52912CVE-2026-52930CVE-2026-52933CVE-2026-52942CVE-2026-52943CVE-2026-52946CVE-2026-52970CVE-2026-52986CVE-2026-52998CVE-2026-52999CVE-2026-53001CVE-2026-53002CVE-2026-53006CVE-2026-53012CVE-2026-53050CVE-2026-53134CVE-2026-53218CVE-2026-53219CVE-2026-53223CVE-2026-53236CVE-2026-53239CVE-2026-53249CVE-2026-53268CVE-2026-53269CVE-2026-53275CVE-2026-53295CVE-2026-53352CVE-2026-53400CVE-2026-63810CVE-2026-64279CVE-2026-64317CVE-2026-64370CVE-2026-64371CVE-2026-64375CVE-2026-64411CVE-2026-64412CVE-2026-64413CVE-2026-64422CVE-2026-64423CVE-2026-64425CVE-2026-64538CVE-2026-64545CVE-2026-64552CVE-2026-64560

Getroffen sectoren

Risk evaluation

Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A8 september 2026

    Added 79 CVEs; Added fix for CVE-2026-43284, CVE-2026-46300 and CVE-2026-31431

Officiële bron: Siemens ProductCERT

SSA-142885

SSA-142885: Multiple Vulnerabilities in Reyrolle 7SR5 Before V2.70

SiemensReyrolle 7SR5

Siemens ProductCERTkritiek

Risk evaluation

Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version.

Mitigatiesamenvatting

Update to V2.70 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie8 september 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-157465

SSA-157465: Reflected Cross-site scripting Vulnerability in Teamcenter

SiemensTeamcenter V2412

Siemens ProductCERTmiddel

Gepubliceerd

8 september 2026

Laatste update

8 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user's session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim's Teamcenter session. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V2412.0013 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie8 september 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-216014

SSA-216014: Vulnerabilities in EFI variable of SIMATIC IPCs, SIMATIC Tablet PCs, and SIMATIC Field PGs

SiemensSIMATIC Field PG M5

Siemens ProductCERThoog

Gepubliceerd

11 maart 2025

Laatste update

8 september 2026

Getroffen sectoren

Risk evaluation

Multiple vulnerabilities has been identified in Siemens SIMATIC IPCs, SIMATIC Tablet PCs, and SIMATIC Field PGs that can allow an authenticated attacker to alter the secure boot and password configurations. Siemens has released new versions of BIOS for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Restrict access to root/administrator permission for the operating system

Revisiegeschiedenis (4)
  1. Initiële publicatie11 maart 2025

    Publication Date

  2. Update A10 juni 2025

    Added SIMATIC IPC RC-543A and RW-543B; Updated SIMATIC IPC3000 Smart V3, IPC 347G, IPC 527G

  3. Update B11 november 2025

    Added fix for SIMATIC IPC227G / IPC277G / IPC277G PRO / IPC327G / IPC377G

  4. Update C10 februari 2026

    Added fix versions for IPC RW-543B and IPC RC-543B

Officiële bron: Siemens ProductCERT

SSA-229470

SSA-229470: Multiple Vulnerabilities in SICAM 8 Products Before V26.20

SiemensCPCI85 Central Processing/Communication

Siemens ProductCERThoog

Gepubliceerd

9 juli 2026

Laatste update

8 september 2026

Getroffen sectoren

Risk evaluation

Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: - SICAM A8000 Device firmware - CPCI85 for CP-8031/CP-8050 - SICORE for CP-8010/CP-8012 - SICAM EGS Device firmware - CPCI85 - SICAM S8000 - SICORE Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V26.20 or later version The firmware CPCI85 V26.20 is present within “CP-8031/CP-8050 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109804985/ and also within “SICAM EGS Package” V26.20 https://support.industry.siemens.com/cs/document/109972536/

Revisiegeschiedenis (2)
  1. Initiële publicatie9 juli 2026

    Publication Date

  2. Update A8 september 2026

    Added Acknowledgement

Officiële bron: Siemens ProductCERT

SSA-254516

SSA-254516: Arbitrary File Upload in OIS Web Module

SiemensSiveillance Control Pro V3.0

Siemens ProductCERTkritiek

Gepubliceerd

8 september 2026

Laatste update

8 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server. Siemens has released patches and updates for Siveillance OIS to apply to the products that incorporate the OIS service, and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V3.0.12.2173 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie8 september 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-282044

SSA-282044: DLL Hijacking Vulnerability in Siemens Web Installer used by the Online Software Delivery

SiemensAutomation License Manager V6.0

Siemens ProductCERThoog

Gepubliceerd

12 augustus 2025

Laatste update

8 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

The installers used to install several Siemens products are affected by a DLL hijacking vulnerability. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected installer component. This vulnerability poses a risk only during setup and installation phase of the affected applications downloaded e.g. via OSD (Online Software Delivery). Siemens has released new versions for several affected products and recommends using the latest versions during setup and installation. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Harden the application host to prevent local access by untrusted personnel

Revisiegeschiedenis (4)
  1. Initiële publicatie12 augustus 2025

    Publication Date

  2. Update A9 september 2025

    Added Sahil Shah to acknowledgment; Added fix for SIMATIC Energy Suite V19, SIMATIC Energy Suite V20, SIMATIC MTP CREATOR V4.x, SIMATIC Control Function Library (CFL) V3.x, TIA Portal Test Suite V19, TIA Portal Test Suite V20, SIMATIC WinCC Visualization Architect V19, SIMATIC WinCC Visualization Architect V20, SIMATIC S7-PCT; Updated No fix planned for SIMATIC ProSave V17,SIMATIC WinCC flexible ES, SIMATIC Control Function Library (CFL) V1.x, SIMATIC Control Function Library (CFL) V2.x

  3. Update B14 oktober 2025

    Added fix for MTP Creator V2.x, CFL V4.x, Simatic WinCC Unified Line Coordination and Simatic WinCC Unified Sequence

  4. Update C11 november 2025

    Added Fixes for PCS 7 Logic Matrix V9.1, PCS7 Advanced Process Faceplates V9.1, SIMATIC PCS 7 Basis Faceplates V9.1 PCS 7 Basis Library V9.1, SIMATIC Management Agent V9.1, SIMATIC Management Console V9.1, PCS 7 V9.1, PCS 7 V10.0

Officiële bron: Siemens ProductCERT

SSA-327438

SSA-327438: Multiple Vulnerabilities in SCALANCE LPE9403

SiemensSCALANCE LPE9403 (6GK5998-3GS00-2AC2)

Siemens ProductCERThoog

Risk evaluation

SCALANCE LPE9403 is affected by multiple vulnerabilities which lead to a compromise in availability, integrity and confidentiality. Siemens has released a new version for SCALANCE LPE9403 and recommends to update to the latest version. Siemens recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Restrict access to authorized and trusted personal only

Revisiegeschiedenis (3)
  1. Initiële publicatie13 mei 2025

    Publication Date

  2. Update A8 juli 2025

    Added fix for CVE-2025-40572, CVE-2025-40573, CVE-2025-40574, CVE-2025-40575, CVE-2025-40576, CVE-2025-40577, CVE-2025-40579, CVE-2025-40580

  3. Update B8 september 2026

    Added fix for devices with SINEMA Remote Connect Edge Client installed

Officiële bron: Siemens ProductCERT

SSA-328642

SSA-328642: "Copy Fail" Vulnerability in Multiple Industrial Products

SiemensSIMATIC AX Runtime Core Linux Common Debian

Siemens ProductCERThoog

Gepubliceerd

8 september 2026

Laatste update

8 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Limit access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only.

Revisiegeschiedenis (1)
  1. Initiële publicatie8 september 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-330084

SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family

SiemensDesigo CC ClickOnce Client V6

Siemens ProductCERThoog

Gepubliceerd

8 september 2026

Laatste update

8 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization.

Mitigatiesamenvatting

Evaluate authorization policy for Graphics application following Least Privilege principle, so only required users have access to the configuration.

Revisiegeschiedenis (1)
  1. Initiële publicatie8 september 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-331739

SSA-331739: Privilege Escalation Vulnerability in WIBU CodeMeter Runtime Affecting Siemens Products

SiemensSIMATIC PDM Maintenance Station V5.0

Siemens ProductCERThoog

Gepubliceerd

12 augustus 2025

Laatste update

8 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

WIBU Systems published information about a privilege escalation vulnerability under a certain circumstances and associated fix releases of CodeMeter Runtime, a product provided by WIBU Systems and used in several Siemens industrial products. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V3.18 P032 or later version

Revisiegeschiedenis (3)
  1. Initiële publicatie12 augustus 2025

    Publication Date

  2. Update A9 september 2025

    Removed Simatic Information Server and Simatic Process Historian as they are not affected.

  3. Update B8 september 2026

    Added fix for SIMATIC PDM Maintenance Station V5.0

Officiële bron: Siemens ProductCERT

SSA-434797

SSA-434797: Buffer Overflow Vulnerability in OpenSSL affecting Siemens Products

SiemensAI Lightweight Inference Server

Siemens ProductCERThoog

Gepubliceerd

9 juni 2026

Laatste update

8 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

As a defense-in-depth measure, organizations may review whether affected systems are exposed to untrusted CMS/PKCS#7 content from external sources.

Revisiegeschiedenis (4)
  1. Initiële publicatie9 juni 2026

    Publication Date

  2. Update A14 juli 2026

    Added SCALANCE X-200 family, X-200IRT family, X-200RNA family, X-300/408 family, SC-600 family to Known Not Affected and fix for SINUMERIK Access MyMachine /OPC UA , SIMOVE Fleetmanager. Updated remediation to No fix planned for SIMATIC Comfort/Mobile RT

  3. Update B11 augustus 2026

    Added RUGGEDCOM ROX II family and SIMATIC HMI Operator Device to Known Not Affected and removed SIMATIC Comfort/Mobile RT and updated SIMATIC Advanced HMI Panels and SIMATIC HMI Basic Panels to no fix available; Added fix for SIMATIC PDM V9.3 and added PCS neo V6.0 and Simatic Logon to affected products.

  4. Update C8 september 2026

    Updated remediation for AI Lightweight Inference Server to no fix planned.

Officiële bron: Siemens ProductCERT

SSA-503852

SSA-503852: Authentication Bypass Vulnerability in Industrial Edge Management

SiemensIndustrial Edge Management Cloud

Siemens ProductCERTkritiek

Gepubliceerd

8 september 2026

Laatste update

8 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Block direct internet access to IEM Pro / IEM Virtual The most effective immediate measure is to block direct internet access to your IEM Pro or IEM V instance. This ensures that no external attacks can occur via this vulnerability.

Revisiegeschiedenis (1)
  1. Initiële publicatie8 september 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-517424

SSA-517424: Path Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT

SiemensSIMOVE Fleetmanager V3.1

Siemens ProductCERThoog

Gepubliceerd

8 september 2026

Laatste update

8 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Configure appropriate user management by restricting services' access rights to project files

Revisiegeschiedenis (1)
  1. Initiële publicatie8 september 2026

    Publication Date

Officiële bron: Siemens ProductCERT

3ADR011572

Automation Builder, Drive Application Builder, Virtual Drive, Virtual DrivePlus Impacted by multiple vulnerabilities in Wibu CodeMeter

ABBAutomation Builder

ABB PSIRThoog

Gepubliceerd

3 september 2026

Laatste update

3 september 2026

Getroffen sectoren

Risk evaluation

An update is available that resolves publicly reported vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited these vulnerabilities could - allow arbitrary files to be deleted with system privileges (CVE-2026-81572), - read potentially sensitive configuration data and overwrite selected values in Server.ini (CVE-2026-81573), - crash CodeMeter and disclose sensitive information such as process memory and stack canaries (CVE-2026-81574), - crash CodeMeter (CVE-2026-81575), or - read potentially sensitive license information (CVE-2026-81576)

Mitigatiesamenvatting

For CVE-2026-81572 the exposure can be limited by auditing the list of local users and removing any unnecessary accounts. For CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, and CVE-2026-81576: If you enabled the network server functionality at some point but no longer need it, disable it: - Open the Registry Editor and navigate to Computer\HKEY_LOCAL_MACHINE\SOFTWARE\ WIBUSYSTEMS\CodeMeter\Server\CurrentVersion\, then change the value of IsNetworkServerfrom 1 to 0. - Restart CodeMeter.

Revisiegeschiedenis (1)
  1. Initiële publicatie3 september 2026

    Initial version.

Officiële bron: ABB PSIRT

SA26P012

mapp Services Use of Weak Authenticators in mapp Audit

B&R Industrial Automation GmbHmapp Audit

ABB PSIRThoog

Gepubliceerd

3 september 2026

Laatste update

3 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

An update is available that resolves a vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploits this vulnerability could gain access to the OPC UA server component on affected devices due to insufficient entropy of authenticators used by mapp Audit.

Mitigatiesamenvatting

The problem is corrected in the following product versions: mapp Services >= 6.8.0 B&R recommends that customers apply the update at earliest convenience when the vulnerable functionality mapp Audit is used. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revisiegeschiedenis (1)
  1. Initiële publicatie3 september 2026

    Initial version.

Officiële bron: ABB PSIRT

ICSA-26-202-01

Tycon Systems TPDIN-Monitor-WEB2 (Update A)

Tycon SystemsTPDIN-Monitor-WEB2

CISAkritiek

Gepubliceerd

21 juli 2026

Laatste update

3 september 2026

Getroffen sectoren

Risk evaluation

Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.

Mitigatiesamenvatting

Tycon Systems has released firmware 2.4.5, which resolves this vulnerability by requiring an administrator username and password to be set before the web interface is served. Further inquiries can be directed to security@tyconsystems.com.

Revisiegeschiedenis (2)
  1. Initiële publicatie21 juli 2026

    Initial Publication

  2. Update A3 september 2026

    Updated affected version range and vulnerability details based on vendor input.

Officiële bron: CISA

SSA-887643

SSA-887643: Account Hijacking Vulnerability in Mendix SAML module

SiemensMendix SAML (Mendix 10 compatible)

Siemens ProductCERThoog

Gepubliceerd

3 september 2026

Laatste update

3 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version.

Mitigatiesamenvatting

Update to V3.6.27 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie3 september 2026

    Publication Date

Officiële bron: Siemens ProductCERT

ICSA-26-202-09

Rockwell Automation 1734 POINT I/O (Update A)

Rockwell Automation1734 POINT I/O

CISAlaag

Gepubliceerd

21 juli 2026

Laatste update

1 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product.

Mitigatiesamenvatting

Rockwell Automation recommends users are to migrate to 5034-OB8.

Revisiegeschiedenis (2)
  1. Initiële publicatie21 juli 2026

    Initial Republication of Rockwell Automation Security Advisory

  2. Update A1 september 2026

    Update A - Updated impact statement and CVSS scores.

Officiële bron: CISA

SSA-682041

SSA-682041: Cross Site Scripting Vulnerability in Element Maps

SiemensElement maps-ng V47

Siemens ProductCERThoog

Gepubliceerd

27 augustus 2026

Laatste update

27 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label of map pins. This could allow an attacker to craft a malicious URL that, when loaded by a victim and the map pin is hovered over, executes arbitrary script code within the victim's browser session. This vulnerability affects only the @siemens/maps-ng package. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Deploy a strict Content Security Policy (CSP)

Revisiegeschiedenis (1)
  1. Initiële publicatie27 augustus 2026

    Publication Date

Officiële bron: Siemens ProductCERT

ICSA-26-232-01

Johnson Controls Simplex Incident Manager

Johnson Controls Inc.Simplex Incident Manager

CISAmiddel

Gepubliceerd

20 augustus 2026

Laatste update

20 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems.

Mitigatiesamenvatting

Johnson Controls has released a patched version (v2.01.01) to address this vulnerability. To help reduce the risk of exploitation, Johnson Controls suggests considering the following defensive measures: Upgrade the Simplex Incident Manager to version v1.01.05 or later. Restrict local access to systems running the Simplex Incident Manager to authorized personnel only. Implement endpoint protection and monitoring to detect memory-dumping tools or suspicious processes. Enforce strong access control policies and the principle of least privilege on host systems. Utilize full-disk encryption and secure boot to reduce the risk of offline memory analysis. Monitor for unauthorized local access attempts and implement audit logging.

Revisiegeschiedenis (1)
  1. Initiële publicatie20 augustus 2026

    Initial Republication of Johnson Controls Product Security Advisory JCI-PSA-2026-28

Officiële bron: CISA

ICSA-26-230-02

Siemens Simcenter Nastran

SiemensSimcenter Femap

CISAhoog

Gepubliceerd

11 augustus 2026

Laatste update

18 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V2606 or later version

Revisiegeschiedenis (3)
  1. Initiële publicatie11 augustus 2026

    Publication Date

  2. Update A13 augustus 2026

    Added Simcenter Femap with fix

  3. Update B18 augustus 2026

    Initial CISA Republication of Siemens ProductCERT SSA-069220 advisory

Officiële bron: CISA

ICSA-26-225-14

Johnson Controls Metasys

Johnson Controls Inc.Metasys 12

CISAhoog

Gepubliceerd

13 augustus 2026

Laatste update

13 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access.

Mitigatiesamenvatting

Johnson Controls recommends the following actions:

Revisiegeschiedenis (1)
  1. Initiële publicatie13 augustus 2026

    Initial Publication.

Officiële bron: CISA

ICSA-26-225-13

Siemens LOGO! Soft Comfort

SiemensLOGO! Soft Comfort

CISAmiddel

Gepubliceerd

11 augustus 2026

Laatste update

13 augustus 2026

Getroffen sectoren

Risk evaluation

Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt project data or remove project passwords. The lack of password salting enables offline dictionary or brute-force attacks against the password hashes. Successful exploitation could result in unauthorized access to, or modification of, sensitive project logic and configurations. Siemens has released a new version for LOGO! Soft Comfort and recommends to update to the latest version.

Mitigatiesamenvatting

Update to V9 or later version Note: A hardware upgrade to LOGO! V9 BM or later is also required to avoid compatibility mode, in which the vulnerabilities addressed by this advisory remain present.

Revisiegeschiedenis (2)
  1. Initiële publicatie11 augustus 2026

    Publication Date

  2. Update A13 augustus 2026

    Initial CISA Republication of Siemens ProductCERT SSA-751328 advisory

Officiële bron: CISA

ICSA-26-225-12

Siemens Solid Edge

SiemensSolid Edge SE2025

CISAhoog

Gepubliceerd

11 augustus 2026

Laatste update

13 augustus 2026

Getroffen sectoren

Risk evaluation

Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V225.0 Update 15 or later version

Revisiegeschiedenis (2)
  1. Initiële publicatie11 augustus 2026

    Publication Date

  2. Update A13 augustus 2026

    Initial CISA Republication of Siemens ProductCERT SSA-621657 advisory

Officiële bron: CISA

ICSA-26-225-11

Siemens Simcenter Femap

SiemensSimcenter Femap

CISAhoog

Gepubliceerd

11 augustus 2026

Laatste update

13 augustus 2026

Getroffen sectoren

Risk evaluation

Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for Simcenter Femap and recommends to update to the latest version.

Mitigatiesamenvatting

Update to V2606.0001 or later version

Revisiegeschiedenis (2)
  1. Initiële publicatie11 augustus 2026

    Publication Date

  2. Update A13 augustus 2026

    Initial CISA Republication of Siemens ProductCERT SSA-584312 advisory

Officiële bron: CISA

ICSA-26-225-10

Siemens Parasolid

SiemensParasolid V38.0

CISAhoog

Gepubliceerd

11 augustus 2026

Laatste update

13 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V38.0.235 or later version

Revisiegeschiedenis (2)
  1. Initiële publicatie11 augustus 2026

    Publication Date

  2. Update A13 augustus 2026

    Initial CISA Republication of Siemens ProductCERT SSA-138516 advisory

Officiële bron: CISA

ICSA-26-225-09

Siemens Siveillance Video

SiemensSiveillance Video V2023 R3

CISAkritiek

Gepubliceerd

11 augustus 2026

Laatste update

13 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V23.3 HotfixRev27 or later version

Revisiegeschiedenis (2)
  1. Initiële publicatie11 augustus 2026

    Publication Date

  2. Update A13 augustus 2026

    Initial CISA Republication of Siemens SSA-825228 advisory

Officiële bron: CISA

ICSA-26-225-08

Siemens Desigo DXR and PXC Controllers

SiemensDesigo DXR2

CISAmiddel

Gepubliceerd

11 augustus 2026

Laatste update

13 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V01.21.233.16-7862 or later version Please contact your local Siemens office for additional support in obtaining the update.

Revisiegeschiedenis (2)
  1. Initiële publicatie11 augustus 2026

    Publication Date

  2. Update A13 augustus 2026

    Initial CISA Republication of Siemens SSA-781903 advisory

Officiële bron: CISA

ICSA-26-225-05

ANDRITZ HIPASE-250 and 250 SCALA

ANDRITZHIPASE-250

CISAhoog

Gepubliceerd

13 augustus 2026

Laatste update

13 augustus 2026

Getroffen sectoren

Risk evaluation

Successful exploitation of these vulnerabilities could allow an attacker to read data from the device or gain access to affected workstations.

Mitigatiesamenvatting

ANDRITZ has addressed these issues in version V8.00.00 (released 2024-12) and in version V8.15.00 (released 2026-07) and encourages users to keep their systems updated to the latest version (currently HIPASE-250 Version V8.15.00). For more information, users can contact ANDRITZ at the following website: https://www.andritz.com/group-en/contact

Revisiegeschiedenis (1)
  1. Initiële publicatie13 augustus 2026

    Initial Publication

Officiële bron: CISA

ICSA-26-225-04

Hitachi Energy APM Edge Product

Hitachi EnergyAPM Edge

CISAhoog

Gepubliceerd

28 juli 2026

Laatste update

13 augustus 2026

Getroffen sectoren

Risk evaluation

Hitachi Energy is aware of Dirty Frag vulnerabilities that affect APM Edge product versions listed in this document. Successful exploitation of these vulnerabilities could result in impact on confidentiality, integrity and availability of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.

Mitigatiesamenvatting

Disable the esp4 and esp6 modules [2]

Revisiegeschiedenis (2)
  1. Initiële publicatie28 juli 2026

    Initial public release

  2. Update A13 augustus 2026

    Initial CISA Republication of Hitachi Energy PSIRT 8DBD000256 advisory

Officiële bron: CISA

ICSA-26-225-03

Johnson Controls Inc. Airwall

Johnson Controls Inc.Airwall

CISAmiddel

Gepubliceerd

13 augustus 2026

Laatste update

13 augustus 2026

Getroffen sectoren

Risk evaluation

Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized access to protected system resources.

Mitigatiesamenvatting

To help reduce risk of exploitation, Johnson Controls recommends the following defensive measures: Apply v4.1.0 or later patches for all Airwalls.

Revisiegeschiedenis (1)
  1. Initiële publicatie13 augustus 2026

    Initial Republication of Johnson Controls JCI-PSA-2026-18 and JCI-PSA-2026-25

Officiële bron: CISA

ICSA-26-225-02

Haiwell IoT Cloud HMI Gateway

HaiwellHaiwell IoT Cloud HMI Gateway

CISAkritiek

Gepubliceerd

13 augustus 2026

Laatste update

13 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges.

Mitigatiesamenvatting

Haiwell has addressed the issue in patch version number Scada-v3.50.1.19, which is available for download on their website: https://en.haiwell.com/app/system/entrance.php?m=include&c=access&a=dodown&lang=en&id=361

Revisiegeschiedenis (1)
  1. Initiële publicatie13 augustus 2026

    Initial Publication

Officiële bron: CISA

ICSA-26-225-01

AVEVA Enterprise SCADA

AVEVAEnterprise SCADA

CISAhoog

Gepubliceerd

13 augustus 2026

Laatste update

13 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization.

Mitigatiesamenvatting

AVEVA recommends that customers using affected product versions should perform the following to mitigate the risk of exploit: 1. Evaluate the impact of these vulnerabilities based on your operational environment, architecture, and product implementation. 2. Plan an upgrade of Servers and Clients to one of the available fixed versions listed in this document. 3. Configure Servers and Clients as described in this document.

Revisiegeschiedenis (1)
  1. Initiële publicatie13 augustus 2026

    Initial Republication of AVEVA security bulletin AVEVA-2026-005

Officiële bron: CISA

SSA-069220

SSA-069220: Stack Overflow Vulnerability in Simcenter Nastran Before V2606

SiemensSimcenter Femap

Siemens ProductCERThoog

Gepubliceerd

11 augustus 2026

Laatste update

13 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V2606 or later version

Revisiegeschiedenis (2)
  1. Initiële publicatie11 augustus 2026

    Publication Date

  2. Update A13 augustus 2026

    Added Simcenter Femap with fix

Officiële bron: Siemens ProductCERT

ICSA-26-225-07

Siemens License Server (SLS)

SiemensSiemens License Server (SLS)

CISAhoog

Gepubliceerd

11 augustus 2026

Laatste update

12 augustus 2026

Getroffen sectoren

Risk evaluation

Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version.

Mitigatiesamenvatting

Update to V5.1 or later version

Revisiegeschiedenis (2)
  1. Initiële publicatie11 augustus 2026

    Publication Date

  2. Update A12 augustus 2026

    Initial CISA Republication of Siemens ProductCERT SSA-077553 advisory

Officiële bron: CISA

ICSA-26-225-06

Siemens RUGGEDCOM APE1808

SiemensRUGGEDCOM APE1808

CISAmiddel

Gepubliceerd

11 augustus 2026

Laatste update

12 augustus 2026

Getroffen sectoren

Risk evaluation

Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens recommends to contact customer support for additional information, and follow Fortinet advisory for workarounds and mitigation measures.

Mitigatiesamenvatting

Contact customer support to receive detailed information

Revisiegeschiedenis (2)
  1. Initiële publicatie11 augustus 2026

    Publication Date

  2. Update A12 augustus 2026

    Initial CISA Republication of Siemens ProductCERT SSA-127084 advisory

Officiële bron: CISA

ICSA-26-204-01

Johnson Controls C-CURE 9000 and Victor application server (Update A)

Johnson ControlsC-CURE 9000

CISAkritiek

Gepubliceerd

23 juli 2026

Laatste update

11 augustus 2026

Getroffen sectoren

Risk evaluation

Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution.

Mitigatiesamenvatting

Johnson Controls recommends the following upgrades to address the vulnerable deserialization path: Upgrade to C-CURE 9000 v3.20 or later

Revisiegeschiedenis (2)
  1. Initiële publicatie23 juli 2026

    Initial Republication of Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16.

  2. Update A11 augustus 2026

    Update A - Made changes to affected products and mitigations.

Officiële bron: CISA

SSA-077553

SSA-077553: Multiple Vulnerabilities in Siemens License Server (SLS)

SiemensSiemens License Server (SLS)

Siemens ProductCERThoog

Gepubliceerd

11 augustus 2026

Laatste update

11 augustus 2026

Getroffen sectoren

Risk evaluation

Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version.

Mitigatiesamenvatting

Update to V5.1 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie11 augustus 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-104023

SSA-104023: Multiple Vulnerabilities in Palo Alto Networks PAN-OS on RUGGEDCOM APE1808 Devices

SiemensRUGGEDCOM APE1808

Siemens ProductCERTkritiek

Risk evaluation

Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/

Mitigatiesamenvatting

Contact customer support to receive patch and update information

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A11 augustus 2026

    Added CVE-2026-0279, CVE-2026-0280, CVE-2026-0281, CVE-2026-0282, CVE-2026-0283, CVE-2026-0284, CVE-2026-0285, CVE-2026-0286, CVE-2026-0287 and CVE-2026-0288

Officiële bron: Siemens ProductCERT

SSA-127084

SSA-127084: Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices

SiemensRUGGEDCOM APE1808

Siemens ProductCERTmiddel

Gepubliceerd

11 augustus 2026

Laatste update

11 augustus 2026

Getroffen sectoren

Risk evaluation

Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens recommends to contact customer support for additional information, and follow Fortinet advisory for workarounds and mitigation measures.

Mitigatiesamenvatting

Contact customer support to receive detailed information

Revisiegeschiedenis (1)
  1. Initiële publicatie11 augustus 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-138516

SSA-138516: Out of Bounds Read Vulnerability in Parasolid X_T File Parsing

SiemensParasolid V38.0

Siemens ProductCERThoog

Gepubliceerd

11 augustus 2026

Laatste update

11 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V38.0.235 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie11 augustus 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-306654

SSA-306654: Insyde BIOS Vulnerabilities in Siemens Industrial Products

SiemensRUGGEDCOM APE1808 - BIOS

Siemens ProductCERThoog

Risk evaluation

Insyde has published information on vulnerabilities in Insyde BIOS in February 2022. This advisory lists the Siemens Industrial products affected by these vulnerabilities. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

As a prerequisite for an attack, an attacker must be able to run untrusted code on affected systems. Siemens recommends limiting the possibilities to run untrusted code

Revisiegeschiedenis (4)
  1. Initiële publicatie22 februari 2022

    Publication Date

  2. Update A8 maart 2022

    Corrected AV:L for all CVEs, added RUGGEDCOM APE1808 and SIMATIC IPC477E PRO

  3. Update B12 juli 2022

    Added CVE-2021-43613, CVE-2021-43614 and CVE-2021-38489, add fix for SIMATIC Field PG M6, SIMATIC ITP1000 for all CVEs except CVE-2021-43613

  4. Update C9 augustus 2022

    Added fix for SIMATIC IPC227G, SIMATIC IPC277G, SIMATIC IPC327G, SIMATIC IPC377G, clarified affected versions for RUGGEDCOM APE1808

Officiële bron: Siemens ProductCERT

SSA-392349

SSA-392349: Denial of Service Vulnerability in Industrial Devices

SiemensIE/PB LINK HA (6GK1411-5BB00)

Siemens ProductCERThoog

Gepubliceerd

12 mei 2026

Laatste update

11 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Multiple industrial devices contain a vulnerability that could allow an attacker to cause a denial of service condition. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

As a mitigation, disable the ethernet ports on the CPU and use a communication module (like CP) for communication instead

Revisiegeschiedenis (3)
  1. Initiële publicatie12 mei 2026

    Publication Date

  2. Update A14 juli 2026

    Added fix for SCALANCE SC-600 family

  3. Update B11 augustus 2026

    Added fix for IE/PB LINK HA

Officiële bron: Siemens ProductCERT

SSA-584312

SSA-584312: File Parsing Vulnerabilities in Simcenter Femap Before V2606 MP1

SiemensSimcenter Femap

Siemens ProductCERThoog

Gepubliceerd

11 augustus 2026

Laatste update

11 augustus 2026

Getroffen sectoren

Risk evaluation

Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for Simcenter Femap and recommends to update to the latest version.

Mitigatiesamenvatting

Update to V2606.0001 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie11 augustus 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-621657

SSA-621657: File Parsing Vulnerabilities in Solid Edge Before Version SE2026 Update 7

SiemensSolid Edge SE2025

Siemens ProductCERThoog

Gepubliceerd

11 augustus 2026

Laatste update

11 augustus 2026

Getroffen sectoren

Risk evaluation

Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V225.0 Update 15 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie11 augustus 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-628843

SSA-628843: Out of Bound Read Vulnerability in TPM 2.0

SiemensSIMATIC CN 4100

Siemens ProductCERTmiddel

Gepubliceerd

14 april 2026

Laatste update

11 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

The products listed below contain a vulnerability that could allow an attacker to perform an out-of-bound read, potentially leading to information disclosure or denial of service of the TPM. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Currently no fix is planned

Revisiegeschiedenis (2)
  1. Initiële publicatie14 april 2026

    Publication Date

  2. Update A11 augustus 2026

    Added no fix planned for SIMATIC ITP1000 and for SIMATIC Field PG M5. Added fix for SIMATIC Field PG M6

Officiële bron: Siemens ProductCERT

SSA-686975

SSA-686975: IPU 2022.3 Vulnerabilities in Siemens Industrial Products using Intel CPUs

SiemensSIMATIC Field PG M5

Siemens ProductCERThoog

Gepubliceerd

14 februari 2023

Laatste update

11 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Intel has published information on vulnerabilities in Intel products in November 2022. This advisory lists the related Siemens Industrial products affected by these vulnerabilities that can be patched by applying the corresponding BIOS update ("2022.3 IPU – BIOS Advisory" Intel-SA-00688). Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

As a prerequisite for an attack, an attacker must be able to run untrusted code on affected systems. Siemens recommends limiting the possibilities to run untrusted code if possible.

Revisiegeschiedenis (4)
  1. Initiële publicatie14 februari 2023

    Publication Date

  2. Update A9 mei 2023

    Added affected products SIMATIC IPC PX-39A and SIMATIC IPC PX-39A pro

  3. Update B11 juli 2023

    Added fix for SIMATIC Field PG M5

  4. Update C8 augustus 2023

    Added fix for SIMATIC IPC BX-39A, SIMATIC IPC PX-39A, and SIMATIC IPC PX-39A pro

Officiële bron: Siemens ProductCERT

SSA-751328

SSA-751328: Recoverable Hardcoded AES Master Key in Siemens LOGO! Soft Comfort

SiemensLOGO! Soft Comfort

Siemens ProductCERTmiddel

Gepubliceerd

11 augustus 2026

Laatste update

11 augustus 2026

Getroffen sectoren

Risk evaluation

Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt project data or remove project passwords. The lack of password salting enables offline dictionary or brute-force attacks against the password hashes. Successful exploitation could result in unauthorized access to, or modification of, sensitive project logic and configurations. Siemens has released a new version for LOGO! Soft Comfort and recommends to update to the latest version.

Mitigatiesamenvatting

Update to V9 or later version Note: A hardware upgrade to LOGO! V9 BM or later is also required to avoid compatibility mode, in which the vulnerabilities addressed by this advisory remain present.

Revisiegeschiedenis (1)
  1. Initiële publicatie11 augustus 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-781903

SSA-781903: Denial of Service Vulnerability in Desigo DXR and PXC Controllers

SiemensDesigo DXR2

Siemens ProductCERTmiddel

Gepubliceerd

11 augustus 2026

Laatste update

11 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V01.21.233.16-7862 or later version Please contact your local Siemens office for additional support in obtaining the update.

Revisiegeschiedenis (1)
  1. Initiële publicatie11 augustus 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-825228

SSA-825228: Potential Remote Code Execution in Siveillance Video Management Servers

SiemensSiveillance Video V2023 R3

Siemens ProductCERTkritiek

Gepubliceerd

11 augustus 2026

Laatste update

11 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V23.3 HotfixRev27 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie11 augustus 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-827968

SSA-827968: Vulnerability in Nozomi Guardian/CMC Before V26.2.0 on RUGGEDCOM APE1808 Devices

SiemensRUGGEDCOM APE1808

Siemens ProductCERThoog

Risk evaluation

Nozomi Networks has published information on vulnerabilities in Nozomi Guardian/CMC. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Siemens has released a new version for RUGGEDCOM APE1808 and recommends to update to the latest version.

Mitigatiesamenvatting

Upgrade Nozomi Guardian to v26.2.0. Contact customer support to receive patch and update information

Revisiegeschiedenis (4)
  1. Initiële publicatie13 januari 2026

    Publication Date

  2. Update A14 april 2026

    Added CVE-2025-40894

  3. Update B12 mei 2026

    Added CVE-2025-40897 and CVE-2025-40899

  4. Update C9 juni 2026

    Added CVE-2025-40900, CVE-2025-40901, CVE-2025-40902, CVE--2025-40903 and CVE-2025-40904

Officiële bron: Siemens ProductCERT

SSA-834709

SSA-834709: Missing Authentication Vulnerability in Node-RED on SIMATIC IoT2050 Advanced with Industrial OS

SiemensSIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2)

Siemens ProductCERTkritiek

Gepubliceerd

11 augustus 2026

Laatste update

11 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released a new version for SIMATIC IoT2050 Advanced and strongly recommends to update to the latest version.

Mitigatiesamenvatting

Harden the Node-RED installation (see Node-RED User Guide)

Revisiegeschiedenis (1)
  1. Initiële publicatie11 augustus 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-864900

SSA-864900: Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices

SiemensRUGGEDCOM APE1808

Siemens ProductCERTkritiek

Risk evaluation

Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens has released a new version for RUGGEDCOM APE1808 and recommends to update to the latest version.

Mitigatiesamenvatting

Update Fortigate NGFW to V7.4.9 or later following the secure update recommendation procedure. Contact customer support to receive detailed information

Revisiegeschiedenis (4)
  1. Initiële publicatie13 mei 2025

    Publication Date

  2. Update A8 juli 2025

    Added CVE-2025-24471, CVE-2025-22862, CVE-2024-50562 and CVE-2025-25250

  3. Update B12 augustus 2025

    Added CVE-2024-55599

  4. Update C9 september 2025

    Added CVE-2025-25248 and CVE-2025-53744

Officiële bron: Siemens ProductCERT

ICSA-26-218-02

Johnson Controls Inc. TL280

Johnson Controls Inc.TL280

CISAmiddel

Gepubliceerd

6 augustus 2026

Laatste update

6 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device.

Mitigatiesamenvatting

To help reduce the risk of exploitation, Johnson Control suggests considering the following defensive measures: Apply firmware update 5.63.

Revisiegeschiedenis (1)
  1. Initiële publicatie6 augustus 2026

    Initial Republication of Johnson Controls Security Advisory JCI-PSA-2026-08

Officiële bron: CISA

ICSA-26-218-01

ABB Ability Zenon

ABBAbility Zenon

CISAhoog

Risk evaluation

ABB is aware of publicly reported vulnerabilities affecting MongoDB 4.2, which is bundled within the IIoT Services of the affected product versions. MongoDB 4.2 has reached end-of-life and contains multiple known security vulnerabilities. An attacker who successfully exploits these vulnerabilities could potentially access sensitive information, cause denial of service, or disrupt system availability.

Mitigatiesamenvatting

ABB recommends the following mitigation measures: - Replace bundled MongoDB with a supported version if IIoT services are required: - Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. - The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer - Uninstall IIoT Services wherever it’s not required: - If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section “General security recommendations” for further advise on how to keep your system secure.

Revisiegeschiedenis (2)
  1. Initiële publicatie30 juli 2026

    Initial version

  2. Update A6 augustus 2026

    Initial CISA Republication of ABB PSIRT 9AKK108472A9037 advisory

Officiële bron: CISA

ICSA-26-211-09

Watchfire Controller Software

WatchfireBC550

CISAmiddel

Gepubliceerd

30 juli 2026

Laatste update

31 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller.

Mitigatiesamenvatting

Watchfire has applied the required security patch to all affected controllers under its management. Watchfire recommends users verify their controller software version and upgrade to one of the approved versions below, if they are not already on an approved patch level.

Revisiegeschiedenis (2)
  1. Initiële publicatie30 juli 2026

    Initial Publication

  2. Update A31 juli 2026

    Updated Product and Remediation details

Officiële bron: CISA

ICSA-26-211-11

MZ Automation lib60870

MZ Automation GmbHlib60870

CISAmiddel

Gepubliceerd

30 juli 2026

Laatste update

30 juli 2026

Getroffen sectoren

Risk evaluation

Successful exploitation of these vulnerabilities could crash the device being accessed.

Mitigatiesamenvatting

MZ Automation recommends users update to version 2.4.1 when available.

Revisiegeschiedenis (1)
  1. Initiële publicatie30 juli 2026

    Initial Publication

Officiële bron: CISA

ICSA-26-211-10

MZ Automation GmbH libiec61850

MZ Automation GmbHlibiec61850

CISAhoog

Gepubliceerd

30 juli 2026

Laatste update

30 juli 2026

Getroffen sectoren

Risk evaluation

Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device.

Mitigatiesamenvatting

MZ Automation GmbH recommends that users update to version 1.6.2.

Revisiegeschiedenis (1)
  1. Initiële publicatie30 juli 2026

    Initial Publication

Officiële bron: CISA

ICSA-26-211-08

o6 Automation open62541

o6 Automation GmbHopen62541 on Windows and Linux

CISAhoog

Gepubliceerd

30 juli 2026

Laatste update

30 juli 2026

Getroffen sectoren

Risk evaluation

Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code.

Mitigatiesamenvatting

o6 Automation has prepared mitigations and fixes to address these issues and recommends that users update to the newest version. The new version can be obtained by contacting o6 Automation https://www.o6-automation.com/contact or by downloading from the following locations:

Revisiegeschiedenis (1)
  1. Initiële publicatie30 juli 2026

    Initial Publication

Officiële bron: CISA

ICSA-26-211-05

Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module

Rockwell AutomationControlLogix 5580

CISAmiddel

Gepubliceerd

30 juli 2026

Laatste update

30 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.

Mitigatiesamenvatting

Rockwell Automation recommend users update to the following versions: ControlLogix 5580: Update to V38.011

Revisiegeschiedenis (1)
  1. Initiële publicatie30 juli 2026

    Initial Publication

Officiële bron: CISA

ICSA-26-211-04

Schneider Electric IGSS

Schneider ElectricIGSS

CISAhoog

Gepubliceerd

14 juli 2026

Laatste update

30 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. The IGSS Definition module is a design-time component used by system integrators to create mimic diagrams for plant personnel, enabling them to monitor and control the SCADA system. Failure to apply the remediation provided below may risk loss of data or arbitrary code execution, which could result in the loss of control of the system.

Mitigatiesamenvatting

Version 18.0.0.26125 of the IGSS Definition module includes a fix for this vulnerability and is available for download through IGSS Master > Update IGSS Software or here: https://igss.schneider-electric.com/igss/igssupdates/v180/IGSSUPDATE.ZIP

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Original Release

  2. Update A30 juli 2026

    Initial CISA Republication of Schneider Electric SEVD-2026-195-01 advisory

Officiële bron: CISA

ICSA-26-211-03

Toptech Systems RCU II+ and Multiload II+

Toptech SystemsRCU II+

CISAhoog

Gepubliceerd

30 juli 2026

Laatste update

30 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources.

Mitigatiesamenvatting

Toptech Systems provides two methods for remediating affected RCU II+ and Multiload II+ units: First, move the device to a closed or segmented network without untrusted access.

Revisiegeschiedenis (1)
  1. Initiële publicatie30 juli 2026

    Initial Publication

Officiële bron: CISA

ICSA-26-211-02

Johnson Controls OpenBlue Employee

Johnson Controls Inc.OpenBlue Employee (FMS Employee)

CISAlaag

Gepubliceerd

30 juli 2026

Laatste update

30 juli 2026

Getroffen sectoren

Risk evaluation

Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content.

Mitigatiesamenvatting

Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation: Apply the latest product update for OpenBlue Employee (FMS Employee). Customers running V2025.3.1 [LV1.1] or earlier should apply the latest available update.

Revisiegeschiedenis (1)
  1. Initiële publicatie30 juli 2026

    Initial Republication of Johnson Controls Inc. Security Advisory JCI-PSA-2026-09

Officiële bron: CISA

9AKK108472A9037

ABB AbilityTM zenon Security Risk Due to End-of-Life MongoDB Component

ABBAbility Zenon

ABB PSIRThoog

Risk evaluation

ABB is aware of publicly reported vulnerabilities affecting MongoDB 4.2, which is bundled within the IIoT Services of the affected product versions. MongoDB 4.2 has reached end-of-life and contains multiple known security vulnerabilities. An attacker who successfully exploits these vulnerabilities could potentially access sensitive information, cause denial of service, or disrupt system availability.

Mitigatiesamenvatting

ABB recommends the following mitigation measures: - Replace bundled MongoDB with a supported version if IIoT services are required: - Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. - The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer - Uninstall IIoT Services wherever it’s not required: - If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section “General security recommendations” for further advise on how to keep your system secure.

Revisiegeschiedenis (1)
  1. Initiële publicatie30 juli 2026

    Initial version

Officiële bron: ABB PSIRT

ICSA-26-209-07

ABB KNX Update Tool

ABBKNX Update Tool (ABB)

CISAmiddel

Gepubliceerd

17 juli 2026

Laatste update

28 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The vulnerability report has been shared in responsible disclosure. An attacker who successfully exploited this vulnerability could cause the product to become unusable. ABB confirms the vulnerability but at the same time acknowledges that the issue affects exclusively classic KNX devices that are not supporting the latest KNX Secure standard. Due to a lack of security in legacy KNX devices, the issue cannot be resolved via a software change. In order to actively exploit this vulnerability, an attacker requires physical access to the bus, the affected device is connected to. ABB has no plans of corrective measures.

Mitigatiesamenvatting

Due to the nature of the classic KNX protocol stack and security concept, there are no options to resolve the vulnerability with a software update on a technical level. ABB recommends to follow general security recommendations listed in the security guideline (see References and General security recommendations). In addition, it shall be avoided to control sensitive functionality by legacy KNX devices such as, but not limited to, access control to e.g. hotel rooms or other protected areas. Note: Legacy KNX standards were never designed to meet state of the art security standards like introduced with KNX Data Secure published in 2017.

Revisiegeschiedenis (2)
  1. Initiële publicatie17 juli 2026

    Initial version

  2. Update A28 juli 2026

    Initial CISA Republication of ABB PSIRT 9AKK108472A9270 advisory

Officiële bron: CISA

ICSA-26-209-04

Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP

SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)

CISAkritiek

Gepubliceerd

14 juli 2026

Laatste update

28 juli 2026

Gekoppelde CVE's

CVE-2021-41617CVE-2023-28531CVE-2023-51384CVE-2023-52927CVE-2024-26783CVE-2024-27056CVE-2024-28956CVE-2024-36903CVE-2024-36927CVE-2024-42079CVE-2024-46786CVE-2024-47736CVE-2024-47809CVE-2024-49968CVE-2024-49994CVE-2024-49998CVE-2024-50014CVE-2024-50063CVE-2024-50164CVE-2024-50298CVE-2024-53124CVE-2024-53170CVE-2024-54458CVE-2024-56631CVE-2024-56703CVE-2024-56719CVE-2024-57917CVE-2024-57924CVE-2024-57973CVE-2024-57977CVE-2024-57979CVE-2024-58011CVE-2024-58016CVE-2024-58020CVE-2024-58056CVE-2024-58058CVE-2024-58061CVE-2024-58086CVE-2025-21645CVE-2025-21648CVE-2025-21655CVE-2025-21676CVE-2025-21682CVE-2025-21702CVE-2025-21705CVE-2025-21706CVE-2025-21707CVE-2025-21718CVE-2025-21731CVE-2025-21745CVE-2025-21758CVE-2025-21760CVE-2025-21764CVE-2025-21765CVE-2025-21780CVE-2025-21795CVE-2025-21796CVE-2025-21802CVE-2025-21814CVE-2025-21846CVE-2025-21853CVE-2025-21861CVE-2025-21864CVE-2025-21867CVE-2025-21875CVE-2025-21887CVE-2025-21913CVE-2025-21919CVE-2025-21925CVE-2025-21926CVE-2025-21938CVE-2025-21959CVE-2025-21999CVE-2025-22005CVE-2025-22015CVE-2025-22055CVE-2025-22056CVE-2025-22060CVE-2025-22083CVE-2025-22090CVE-2025-22095CVE-2025-22107CVE-2025-22111CVE-2025-22121CVE-2025-23136CVE-2025-23143CVE-2025-37785CVE-2025-37909CVE-2025-37917CVE-2025-37945CVE-2025-37959CVE-2025-37964CVE-2025-37972CVE-2025-37980CVE-2025-38125CVE-2025-38162CVE-2025-38192CVE-2025-38201CVE-2025-38232CVE-2025-38322CVE-2025-38591CVE-2025-38614CVE-2025-38681CVE-2025-38704CVE-2025-38721CVE-2025-38725CVE-2025-38727CVE-2025-38732CVE-2025-38736CVE-2025-39681CVE-2025-39691CVE-2025-39721CVE-2025-39748CVE-2025-39756CVE-2025-39764CVE-2025-39770CVE-2025-39773CVE-2025-39782CVE-2025-39795CVE-2025-39826CVE-2025-39827CVE-2025-39845CVE-2025-39866CVE-2025-39871CVE-2025-39931CVE-2025-39953CVE-2025-39955CVE-2025-39964CVE-2025-39977CVE-2025-39978CVE-2025-39980CVE-2025-40022CVE-2025-40070CVE-2025-40078CVE-2025-40080CVE-2025-40105CVE-2025-40135CVE-2025-40149CVE-2025-40219CVE-2025-40261CVE-2025-40300CVE-2025-61984CVE-2025-61985CVE-2025-68206CVE-2025-68261CVE-2025-68264CVE-2025-68265CVE-2025-68266CVE-2025-68291CVE-2025-68337CVE-2025-68349CVE-2025-68363CVE-2025-68371CVE-2025-68724CVE-2025-68725CVE-2025-68742CVE-2025-68764CVE-2025-68773CVE-2025-68776CVE-2025-68782CVE-2025-68787CVE-2025-68788CVE-2025-68798CVE-2025-68803CVE-2025-68814CVE-2025-68816CVE-2025-68818CVE-2025-68820CVE-2025-71064CVE-2025-71075CVE-2025-71079CVE-2025-71085CVE-2025-71086CVE-2025-71088CVE-2025-71095CVE-2025-71097CVE-2025-71098CVE-2025-71104CVE-2025-71112CVE-2025-71113CVE-2025-71114CVE-2025-71120CVE-2025-71123CVE-2025-71131CVE-2025-71161CVE-2025-71162CVE-2025-71163CVE-2025-71185CVE-2025-71186CVE-2025-71189CVE-2025-71190CVE-2025-71191CVE-2025-71197CVE-2025-71221CVE-2025-71265CVE-2025-71266CVE-2025-71267CVE-2026-3497CVE-2026-22977CVE-2026-22979CVE-2026-22980CVE-2026-22982CVE-2026-22992CVE-2026-22994CVE-2026-23003CVE-2026-23005CVE-2026-23010CVE-2026-23011CVE-2026-23019CVE-2026-23026CVE-2026-23038CVE-2026-23054CVE-2026-23060CVE-2026-23083CVE-2026-23084CVE-2026-23086CVE-2026-23087CVE-2026-23095CVE-2026-23100CVE-2026-23103CVE-2026-23110CVE-2026-23111CVE-2026-23113CVE-2026-23154CVE-2026-23204CVE-2026-23231CVE-2026-23242CVE-2026-23243CVE-2026-23245CVE-2026-23270CVE-2026-23271CVE-2026-23273CVE-2026-23274CVE-2026-23277CVE-2026-23284CVE-2026-23287CVE-2026-23290CVE-2026-23293CVE-2026-23300CVE-2026-23304CVE-2026-23319CVE-2026-23321CVE-2026-23335CVE-2026-23340CVE-2026-23343CVE-2026-23351CVE-2026-23359CVE-2026-23365CVE-2026-23368CVE-2026-23370CVE-2026-23378CVE-2026-23379CVE-2026-23381CVE-2026-23391CVE-2026-23392CVE-2026-23397CVE-2026-23398CVE-2026-23414CVE-2026-23422CVE-2026-23434CVE-2026-23438CVE-2026-23439CVE-2026-23446CVE-2026-23449CVE-2026-23450CVE-2026-23452CVE-2026-23454CVE-2026-23455CVE-2026-23456CVE-2026-23457CVE-2026-23458CVE-2026-23463CVE-2026-23474CVE-2026-23475CVE-2026-27135CVE-2026-31389CVE-2026-31391CVE-2026-31396CVE-2026-31402CVE-2026-31403CVE-2026-31411CVE-2026-31414CVE-2026-31415CVE-2026-31416CVE-2026-31417CVE-2026-31418CVE-2026-31421CVE-2026-31422CVE-2026-31423CVE-2026-31424CVE-2026-31427CVE-2026-31428CVE-2026-31431CVE-2026-31441CVE-2026-31446CVE-2026-31447CVE-2026-31448CVE-2026-31450CVE-2026-31452CVE-2026-31466CVE-2026-31469CVE-2026-31485CVE-2026-31494CVE-2026-31495CVE-2026-31496CVE-2026-31503CVE-2026-31504CVE-2026-31507CVE-2026-31508CVE-2026-31515CVE-2026-31518CVE-2026-31521CVE-2026-31533CVE-2026-31546CVE-2026-31555CVE-2026-31563CVE-2026-31565CVE-2026-31628CVE-2026-31634CVE-2026-31649CVE-2026-31651CVE-2026-31658CVE-2026-31664CVE-2026-31665CVE-2026-31669CVE-2026-31670CVE-2026-31671CVE-2026-31674CVE-2026-31680CVE-2026-31682CVE-2026-31737CVE-2026-31752CVE-2026-31761CVE-2026-31768CVE-2026-40355CVE-2026-41989CVE-2026-43011CVE-2026-43024CVE-2026-43025CVE-2026-43026CVE-2026-43027CVE-2026-43028CVE-2026-43030CVE-2026-43033CVE-2026-43035CVE-2026-43038CVE-2026-43040CVE-2026-43057CVE-2026-43284CVE-2026-46174CVE-2026-46300CVE-2026-46333

Getroffen sectoren

Risk evaluation

Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A28 juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-019113 advisory

Officiële bron: CISA

ICSA-26-209-03

Siemens SIMATIC S7-PLCSIM Advanced

SiemensSIMATIC S7-PLCSIM Advanced

CISAhoog

Gepubliceerd

14 juli 2026

Laatste update

28 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Disable the S7-PLCSIM Virtual Switch binding on the network adapter used by the affected instance. This prevents the adapter from entering an external communication mode and removes the attack vector entirely. (see SIMATIC S7-PLCSIM Advanced Function Manual V8.0, 11/2025 Section 5.3 and Section 6.1.2.3; and SIMATIC S7-PLCSIM Advanced Function Manual API V8.0, 11/2025 Section 7.2)

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A28 juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-828211 advisory

Officiële bron: CISA

ICSA-26-209-02

Siemens Mendix Runtime

SiemensMendix Runtime

CISAkritiek

Gepubliceerd

14 juli 2026

Laatste update

28 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely. This documentation gap may lead application developers to unknowingly apply overly permissive access rules to System.User, resulting in unintended exposure of sensitive user data or privilege escalation within deployed Mendix applications. A common misconfiguration identified is with the anonymous user role with a System.User entity to gain access to all stored records, even though no access rights are explicitly configured on that role. Siemens recommends Mendix developers to review their access rules based on updated documentation.

Mitigatiesamenvatting

Any security model relying solely on XPath constraints on a System.User specialization to restrict access should be revised to enforce restrictions at the App Security role-management configuration level instead.

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A28 juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-814963 advisory

Officiële bron: CISA

ICSA-26-209-01

Siemens Desigo CC

SiemensDesigo CC family V7

CISAkritiek

Gepubliceerd

14 juli 2026

Laatste update

28 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Currently no fix is available

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A28 juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-734552 advisory

Officiële bron: CISA

ICSA-26-204-07

MZ Automation lib60870

MZ Automationlib60870

CISAhoog

Gepubliceerd

23 juli 2026

Laatste update

23 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service.

Mitigatiesamenvatting

MZ automation recommends users update to version 2.4.1 or later. Documentation can be found at https://github.com/mz-automation/lib60870/security/advisories/GHSA-f5xp-w6f3-vvrv.

Revisiegeschiedenis (1)
  1. Initiële publicatie23 juli 2026

    Initial Publication

Officiële bron: CISA

ICSA-26-204-06

MZ Automation libIEC61850

MZ AutomationlibIEC61850

CISAhoog

Gepubliceerd

23 juli 2026

Laatste update

23 juli 2026

Getroffen sectoren

Risk evaluation

Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions.

Mitigatiesamenvatting

MZ Automation recommends updating to the latest build of the libIEC61850 standard. Documentation can be found at https://github.com/mz-automation/libiec61850.

Revisiegeschiedenis (1)
  1. Initiële publicatie23 juli 2026

    Initial Publication

Officiële bron: CISA

ICSA-26-204-05

Rockwell Automation ThinManager

Rockwell AutomationThinManager

CISAhoog

Gepubliceerd

14 juli 2026

Laatste update

23 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory.

Mitigatiesamenvatting

Users using the affected software, should upgrade to one of the corrected versions as follows:

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Initial Publication by Rockwell Automation

  2. Update A23 juli 2026

    Initial Republication of Rockwell Automation advisory

Officiële bron: CISA

ICSA-26-204-04

Panduit IntraVUE

PronetiqsIntraVUE

CISAkritiek

Gepubliceerd

23 juli 2026

Laatste update

23 juli 2026

Getroffen sectoren

Risk evaluation

Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider knowledge, or advanced tooling.

Mitigatiesamenvatting

Pronetiqs advises users to update to the latest version of the IntraVUE software, version 3.2.1a16 or later.

Revisiegeschiedenis (1)
  1. Initiële publicatie23 juli 2026

    Initial Publication

Officiële bron: CISA

ICSA-26-204-03

Weintek cMT3092X

WeintekcMT3092X firmware

CISAhoog

Gepubliceerd

23 juli 2026

Laatste update

23 juli 2026

Getroffen sectoren

Risk evaluation

Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users.

Mitigatiesamenvatting

Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors.

Revisiegeschiedenis (1)
  1. Initiële publicatie23 juli 2026

    Initial Publication

Officiële bron: CISA

ICSA-26-204-02

Johnson Controls XAAP Android

Johnson ControlsXAAP Android

CISAlaag

Gepubliceerd

23 juli 2026

Laatste update

23 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device.

Mitigatiesamenvatting

Johnson Controls recommends users update the XAAP Android application to version 1.53 or later, which contains the fix for this vulnerability.

Revisiegeschiedenis (1)
  1. Initiële publicatie23 juli 2026

    Initial Republication of Johnson Controls JCI-PSA-2026-10

Officiële bron: CISA

ICSA-26-202-10

Rockwell Automation Studio 5000 Logix Designer

Rockwell AutomationStudio 5000 Logix Designer

CISAhoog

Gepubliceerd

21 juli 2026

Laatste update

21 juli 2026

Getroffen sectoren

Risk evaluation

Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code.

Mitigatiesamenvatting

Rockwell Automation recommends users to upgrade to the following: Studio 5000 Logix Designer: V37.00, 36.01, 35.02, 34.04, 33.04, 32.05 (CVE-2026-9108)

Revisiegeschiedenis (1)
  1. Initiële publicatie21 juli 2026

    Initial Republication of Rockwell Automation Security Advisory

Officiële bron: CISA

ICSA-26-202-08

Rockwell Automation 1718-AENTR/1719-AENTR

Rockwell Automation1718/ 1719 Ex I/O

CISAhoog

Gepubliceerd

21 juli 2026

Laatste update

21 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product.

Mitigatiesamenvatting

Rockwell Automation recommends users to upgrade to 1718/ 1719 Ex I/O version 3.012 or later.

Revisiegeschiedenis (1)
  1. Initiële publicatie21 juli 2026

    Initial Republication of Rockwell Automation Security Advisory

Officiële bron: CISA

ICSA-26-202-07

Rockwell Automation FactoryTalk Services Platform

Rockwell AutomationFactoryTalk Directory (FTSP)

CISAhoog

Gepubliceerd

21 juli 2026

Laatste update

21 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations.

Mitigatiesamenvatting

Users using FactoryTalk Services Platform v6.60 should apply either the individual patch (RAID 1158263) or the February 2026 Patch Roll-up, or later update.

Revisiegeschiedenis (1)
  1. Initiële publicatie21 juli 2026

    Initial Republication of Rockwell Automation SD1786

Officiële bron: CISA

ICSA-26-202-06

Siemens CADRA

SiemensCADRA

CISAkritiek

Risk evaluation

CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Update to V2511 or later version

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A21 juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-470355 advisory

Officiële bron: CISA

ICSA-26-202-05

Siemens IAM Client

SiemensCOMOS V10.4.5

CISAmiddel

Gepubliceerd

14 juli 2026

Laatste update

21 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Update to V10.6.1 or later version

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A21 juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-288252 advisory

Officiële bron: CISA

ICSA-26-202-04

Siemens SIDIS Secured SmartPlug

SiemensSIDIS Secured SmartPlug

CISAkritiek

Risk evaluation

SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version.

Mitigatiesamenvatting

Update to V7.26.0310 or later version

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A21 juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-585531 advisory

Officiële bron: CISA

ICSA-26-202-03

Siemens Opcenter X

SiemensOpcenter X

CISAkritiek

Gepubliceerd

14 juli 2026

Laatste update

21 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version.

Mitigatiesamenvatting

Update to V2604 or later version

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A21 juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-096828 advisory

Officiële bron: CISA

ICSA-26-202-02

Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW

SiemensRUGGEDCOM APE1808

CISAhoog

Gepubliceerd

14 juli 2026

Laatste update

21 juli 2026

Getroffen sectoren

Risk evaluation

Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/

Mitigatiesamenvatting

Contact customer support to receive patch and update information

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A21 juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-104023 advisory

Officiële bron: CISA

9AKK108472A9270

ABB/EL/ELSB/Building Automation File integrity can be bypassed in KNX Update Tool for classic KNX products

ABBKNX Update Tool (ABB)

ABB PSIRTmiddel

Gepubliceerd

17 juli 2026

Laatste update

17 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The vulnerability report has been shared in responsible disclosure. An attacker who successfully exploited this vulnerability could cause the product to become unusable. ABB confirms the vulnerability but at the same time acknowledges that the issue affects exclusively classic KNX devices that are not supporting the latest KNX Secure standard. Due to a lack of security in legacy KNX devices, the issue cannot be resolved via a software change. In order to actively exploit this vulnerability, an attacker requires physical access to the bus, the affected device is connected to. ABB has no plans of corrective measures.

Mitigatiesamenvatting

Due to the nature of the classic KNX protocol stack and security concept, there are no options to resolve the vulnerability with a software update on a technical level. ABB recommends to follow general security recommendations listed in the security guideline (see References and General security recommendations). In addition, it shall be avoided to control sensitive functionality by legacy KNX devices such as, but not limited to, access control to e.g. hotel rooms or other protected areas. Note: Legacy KNX standards were never designed to meet state of the art security standards like introduced with KNX Data Secure published in 2017.

Revisiegeschiedenis (1)
  1. Initiële publicatie17 juli 2026

    Initial version

Officiële bron: ABB PSIRT

ICSA-26-197-09

Rockwell Automation FactoryTalk DataMosaix

Rockwell AutomationDataMosaix Private Cloud

CISAmiddel

Gepubliceerd

16 juli 2026

Laatste update

16 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious scripts on the server.

Mitigatiesamenvatting

Rockwell Automation recommends users to upgrade to the following: DataMosaix Private Cloud versions 8.03 or later.

Revisiegeschiedenis (1)
  1. Initiële publicatie16 juli 2026

    Initial Republication of Rockwell Automation Security Advisory SD1787

Officiële bron: CISA

ICSA-26-197-08

Rockwell Automation Flex 5000 Adapter

Rockwell AutomationFlex 5000 Adapter

CISAhoog

Gepubliceerd

16 juli 2026

Laatste update

16 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition on the affected product.

Mitigatiesamenvatting

Rockwell Automation recommends users to upgrade to the following: Flex 5000 Adapter version 6.012.

Revisiegeschiedenis (1)
  1. Initiële publicatie16 juli 2026

    Initial Republication of Rockwell Automation Security Advisory SD1789

Officiële bron: CISA

ICSA-26-197-07

SALTO ProAccess Space

SALTOProAccess Space

CISAmiddel

Gepubliceerd

16 juli 2026

Laatste update

16 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Successful exploitation of this vulnerability allows an authenticated attacker to escalate privileges and access spaces outside their assigned partition, within the same Salto ProAccess Space installation or system. Exploitation requires valid authenticated operator credentials and the partition feature to be enabled; installations without partitioning are not affected.

Mitigatiesamenvatting

Users of SALTO ProAccess using the tenancy feature should upgrade to version 6.13.

Revisiegeschiedenis (1)
  1. Initiële publicatie16 juli 2026

    Initial Publication

Officiële bron: CISA

SSA-082556

SSA-082556: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5

SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)

Siemens ProductCERTkritiek

Gepubliceerd

10 juni 2025

Laatste update

14 juli 2026

Gekoppelde CVE's

CVE-2021-41617CVE-2023-4527CVE-2023-4806CVE-2023-4911CVE-2023-5363CVE-2023-6246CVE-2023-6779CVE-2023-6780CVE-2023-28531CVE-2023-38545CVE-2023-38546CVE-2023-44487CVE-2023-46218CVE-2023-46219CVE-2023-48795CVE-2023-51384CVE-2023-51385CVE-2023-52927CVE-2024-2961CVE-2024-6119CVE-2024-6387CVE-2024-12133CVE-2024-12243CVE-2024-24855CVE-2024-26596CVE-2024-28085CVE-2024-33599CVE-2024-33600CVE-2024-33601CVE-2024-33602CVE-2024-34397CVE-2024-37370CVE-2024-37371CVE-2024-45490CVE-2024-45491CVE-2024-45492CVE-2024-47736CVE-2024-47809CVE-2024-49998CVE-2024-50246CVE-2024-50298CVE-2024-53166CVE-2024-56719CVE-2024-57924CVE-2024-57977CVE-2024-57996CVE-2024-58005CVE-2025-3198CVE-2025-4373CVE-2025-4598CVE-2025-5244CVE-2025-5245CVE-2025-6395CVE-2025-7425CVE-2025-7545CVE-2025-7546CVE-2025-8224CVE-2025-9230CVE-2025-9232CVE-2025-11082CVE-2025-11083CVE-2025-11412CVE-2025-11413CVE-2025-11414CVE-2025-11494CVE-2025-11495CVE-2025-11839CVE-2025-11840CVE-2025-21676CVE-2025-21682CVE-2025-21701CVE-2025-21702CVE-2025-21712CVE-2025-21724CVE-2025-21728CVE-2025-21745CVE-2025-21756CVE-2025-21758CVE-2025-21765CVE-2025-21766CVE-2025-21767CVE-2025-21795CVE-2025-21796CVE-2025-21848CVE-2025-21862CVE-2025-21864CVE-2025-21865CVE-2025-26465CVE-2025-31115CVE-2025-32988CVE-2025-32989CVE-2025-37945CVE-2025-37980CVE-2025-38058CVE-2025-38063CVE-2025-38067CVE-2025-38071CVE-2025-38079CVE-2025-38083CVE-2025-38100CVE-2025-38111CVE-2025-38124CVE-2025-38162CVE-2025-38167CVE-2025-38192CVE-2025-38198CVE-2025-38201CVE-2025-38212CVE-2025-38214CVE-2025-38215CVE-2025-38222CVE-2025-38231CVE-2025-38236CVE-2025-38280CVE-2025-38285CVE-2025-38312CVE-2025-38342CVE-2025-38350CVE-2025-38364CVE-2025-38393CVE-2025-38400CVE-2025-38430CVE-2025-38451CVE-2025-38457CVE-2025-38465CVE-2025-38466CVE-2025-38468CVE-2025-38470CVE-2025-38471CVE-2025-38477CVE-2025-38498CVE-2025-38499CVE-2025-38614CVE-2025-38685CVE-2025-38691CVE-2025-38701CVE-2025-38702CVE-2025-38704CVE-2025-38708CVE-2025-38721CVE-2025-38724CVE-2025-38727CVE-2025-39683CVE-2025-39689CVE-2025-39697CVE-2025-39724CVE-2025-39748CVE-2025-39756CVE-2025-39764CVE-2025-39770CVE-2025-39773CVE-2025-39783CVE-2025-39787CVE-2025-39795CVE-2025-39798CVE-2025-39866CVE-2025-39929CVE-2025-39931CVE-2025-39977CVE-2025-40022CVE-2025-40135CVE-2025-40219CVE-2025-40261CVE-2025-46836CVE-2025-59375CVE-2025-66382CVE-2025-68206CVE-2025-68265CVE-2025-71161CVE-2025-71221CVE-2025-71265CVE-2025-71266CVE-2025-71267CVE-2026-3904CVE-2026-4046CVE-2026-4437CVE-2026-4438CVE-2026-5435CVE-2026-5450CVE-2026-5928CVE-2026-6238CVE-2026-23100CVE-2026-23111CVE-2026-23113CVE-2026-23154CVE-2026-23204CVE-2026-23231CVE-2026-23242CVE-2026-23243CVE-2026-23245CVE-2026-23270CVE-2026-23271CVE-2026-23273CVE-2026-23274CVE-2026-23277CVE-2026-23284CVE-2026-23287CVE-2026-23290CVE-2026-23293CVE-2026-23300CVE-2026-23304CVE-2026-23319CVE-2026-23321CVE-2026-23335CVE-2026-23340CVE-2026-23343CVE-2026-23351CVE-2026-23359CVE-2026-23365CVE-2026-23368CVE-2026-23370CVE-2026-23378CVE-2026-23379CVE-2026-23381CVE-2026-23391CVE-2026-23392CVE-2026-23397CVE-2026-23398CVE-2026-23414CVE-2026-23422CVE-2026-23434CVE-2026-23438CVE-2026-23439CVE-2026-23446CVE-2026-23449CVE-2026-23450CVE-2026-23452CVE-2026-23454CVE-2026-23455CVE-2026-23456CVE-2026-23457CVE-2026-23458CVE-2026-23463CVE-2026-23474CVE-2026-23475CVE-2026-31389CVE-2026-31391CVE-2026-31396CVE-2026-31402CVE-2026-31403CVE-2026-31411CVE-2026-31414CVE-2026-31415CVE-2026-31416CVE-2026-31417CVE-2026-31418CVE-2026-31421CVE-2026-31422CVE-2026-31423CVE-2026-31424CVE-2026-31427CVE-2026-31428CVE-2026-31431CVE-2026-31441CVE-2026-31446CVE-2026-31447CVE-2026-31448CVE-2026-31450CVE-2026-31452CVE-2026-31466CVE-2026-31469CVE-2026-31485CVE-2026-31494CVE-2026-31495CVE-2026-31496CVE-2026-31503CVE-2026-31504CVE-2026-31507CVE-2026-31508CVE-2026-31515CVE-2026-31518CVE-2026-31521CVE-2026-31533CVE-2026-31546CVE-2026-31555CVE-2026-31563CVE-2026-31565CVE-2026-31628CVE-2026-31634CVE-2026-31649CVE-2026-31651CVE-2026-31658CVE-2026-31664CVE-2026-31665CVE-2026-31669CVE-2026-31670CVE-2026-31671CVE-2026-31674CVE-2026-31680CVE-2026-31682CVE-2026-31737CVE-2026-31752CVE-2026-31761CVE-2026-31768CVE-2026-32776CVE-2026-32777CVE-2026-32778CVE-2026-40355CVE-2026-41080CVE-2026-41989CVE-2026-43011CVE-2026-43024CVE-2026-43025CVE-2026-43026CVE-2026-43027CVE-2026-43028CVE-2026-43030CVE-2026-43033CVE-2026-43035CVE-2026-43038CVE-2026-43040CVE-2026-43057CVE-2026-43284CVE-2026-45186CVE-2026-46174CVE-2026-46300

Getroffen sectoren

Risk evaluation

Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.5 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. Note: This SSA advises vulnerabilities for firmware version V3.1.5 only; for version V3.1.6 refer to SSA-019113.

Mitigatiesamenvatting

Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.

Revisiegeschiedenis (4)
  1. Initiële publicatie10 juni 2025

    Publication Date

  2. Update A12 augustus 2025

    Added CVE-2025-6395, CVE-2025-32988, CVE-2025-32989, CVE-2025-32990

  3. Update B13 januari 2026

    Added CVE-2025-66382, CVE-2025-39929, CVE-2025-39931, CVE-2025-39977, CVE-2025-40022, CVE-2025-11082, CVE-2025-11083, CVE-2025-11412, CVE-2025-11413, CVE-2025-11414, CVE-2025-11494, CVE-2025-11495, CVE-2025-11839, CVE-2025-11840, CVE-2025-9230, CVE-2025-9232, CVE-2025-3198, CVE-2025-5244, CVE-2025-5245, CVE-2025-7545, CVE-2025-7546, CVE-2025-8224, CVE-2025-7425, CVE-2025-59375

  4. Update C10 februari 2026

    Added 22 CVEs

Officiële bron: Siemens ProductCERT

SSA-096828

SSA-096828: Token Invalidation Vulnerability in Opcenter X Before V2604

SiemensOpcenter X

Siemens ProductCERTkritiek

Gepubliceerd

14 juli 2026

Laatste update

14 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version.

Mitigatiesamenvatting

Update to V2604 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie14 juli 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-288252

SSA-288252: Unquoted Search Path Vulnerability in IAM Client

SiemensCOMOS V10.4.5

Siemens ProductCERTmiddel

Gepubliceerd

14 juli 2026

Laatste update

14 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Update to V10.6.1 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie14 juli 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-470355

SSA-470355: Zlib and Foxit Vulnerabilities in CADRA

SiemensCADRA

Siemens ProductCERTkritiek

Risk evaluation

CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Update to V2511 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie14 juli 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-555707

SSA-555707: Information Disclosure Vulnerability in Simcenter STAR-CCM+

SiemensSimcenter STAR-CCM+

Siemens ProductCERTmiddel

Gepubliceerd

9 augustus 2022

Laatste update

14 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Simcenter STAR-CCM+ contains an information disclosure vulnerability when using the Power-on-Demand public license server. An attacker could access a system's host, user, and display name. Siemens has updated the public Power-on-Demand public license server.

Mitigatiesamenvatting

Avoid using sensitive or personal data in user, host and display names

Revisiegeschiedenis (2)
  1. Initiële publicatie9 augustus 2022

    Publication Date

  2. Update A14 juli 2026

    Added fix for Simcenter STAR-CCM+

Officiële bron: Siemens ProductCERT

SA26P011

Security Issues addressed in APROL R 4.4-01P5

B&R Industrial Automation GmbHAPROL

ABB PSIRTkritiek

Gepubliceerd

6 juli 2026

Laatste update

6 juli 2026

Getroffen sectoren

Risk evaluation

An update is available that resolves several vulnerabilities and updates one or more 3rd party components in the product versions listed as affected in the advisory. An attacker who successfully exploited these vulnerabilities could impact the availability of the product, spoof identities or elevate privileges.

Mitigatiesamenvatting

The problem is corrected in the following product versions: - APROL >= R 4.4-01P5 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revisiegeschiedenis (1)
  1. Initiële publicatie6 juli 2026

    Initial version.

Officiële bron: ABB PSIRT

7PAA024620

ABB Ability Edgenius: Copy Fail

ABBOnbekend product

ABB PSIRThoog

Gepubliceerd

25 juni 2026

Laatste update

25 juni 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete control of the system

Mitigatiesamenvatting

The problem is corrected in the following product versions: - Edgenius 3.2.4.1 ABB recommends that customers apply the update at earliest convenience.

Revisiegeschiedenis (1)
  1. Initiële publicatie25 juni 2026

    Initial version.

Officiële bron: ABB PSIRT

7PAA020047

Advant Master Online Builder DLL vulnerability

ABBControl Builder A

ABB PSIRTmiddel

Gepubliceerd

23 juni 2026

Laatste update

23 juni 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

ABB became aware of vulnerability in the products versions listed as affected in the advisory, where an incorrect version of Online Builder (ONB) was included in the media. An update is available that resolves the vulnerability, see details in Recommended immediate actions.

Mitigatiesamenvatting

ABB has investigated the vulnerability and remediated it in the newly released versions. The vulnerability has been resolved in the product versions listed as fixed in the advisory. - Version 6.1.1-2 does not contain this vulnerability and therefore no update is required. The vulnerability was again introduced in 6.1.1-3 when an older ONB version was included in the release media. - Version 6.1.1-4 do not contain this vulnerability but present version 6.1.1-3 by 800xA System Installer and System Configuration Console (SCC). Version 6.1.1-4 is therefore withdrawn. - Version 6.2.0-2 do not contain this vulnerability but present version 6.2.0-1 by 800xA System Installer and System Configuration Console (SCC). Version 6.2.0-2 is therefore withdrawn. ABB recommends that customers apply the update at their earliest convenience. - Control Builder A: It is recommended to update Control Builder A to version 1.4/5 or later. - 800xA for Advant Master: - Versions 6.0.3-1 and earlier, - Versions 6.1.1-1 and earlier, - Versions 6.1.1-2, 6.1.1-3, and 6.1.1-4 should be updated to version 6.1.1-5 or later. - 800xA for Advant Master: - Versions 6.2.0-1 and 6.2.0-2 should be updated to version 6.2.0-3 or later.

Revisiegeschiedenis (1)
  1. Initiële publicatie23 juni 2026

    Initial version.

Officiële bron: ABB PSIRT

SA26P010

Impact of Linux Kernel vulnerabilities on B&R products

B&R Industrial Automation GmbHLinux for B&R

ABB PSIRThoog

Gepubliceerd

11 juni 2026

Laatste update

18 juni 2026

Getroffen sectoren

Risk evaluation

B&R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory. Successful local exploitation of these vulnerabilities could allow an attacker to escalate privileges on the affected system. Public proof-of-concept exploits are available for the vulnerabilities described herein. At the time of publication of this advisory, B&R had no evidence of active exploitation targeting B&R products.

Mitigatiesamenvatting

For affected products, software updates should be installed upon availability. Product Patch version - APROL : APROL-AutoYaST-DVD- V4.4-010.10.260602 Until remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.

Revisiegeschiedenis (2)
  1. Initiële publicatie11 juni 2026

    Initial version.

  2. Update A18 juni 2026

    Updating the CWE classification for CVE-2026-43494.

Officiële bron: ABB PSIRT

7PAA020361

Freelance Security Lock - Access to Windows OS

ABBSystem Version

ABB PSIRTmiddel

Gepubliceerd

10 juni 2026

Laatste update

17 juni 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

ABB is aware of a vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the product to stop or make the product inaccessible.

Mitigatiesamenvatting

ABB recommends using Freelance Extended User Management instead of Security Lock. Freelance Extended User Management is based on Windows user accounts and is available for Freelance 2019 or higher. For Freelance 2016 and earlier, please refer to chapter “General Security Information”. A fix for Freelance Security Lock is in preparation and will be announced in this updated document. Refer to section “General security recommendations” for further advise on how to keep your system secure. To reduce the likelihood of exploitation via keyboard shortcuts: - disable unnecessary accessibility features - use hardened OS configurations that suppress system-level shortcuts - implement BIOS/UEFI-level restrictions on keyboard input during runtime.

Revisiegeschiedenis (2)
  1. Initiële publicatie10 juni 2026

    Initial version.

  2. Update A17 juni 2026

    Correction on the product relationship

Officiële bron: ABB PSIRT

SA26P009

XZ Utils vulnerability impacting B&R Products

B&R Industrial Automation GmbHPPC3100

ABB PSIRThoog

Gepubliceerd

10 juni 2026

Laatste update

10 juni 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

An update is available that resolves vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the product to stop or corrupt memory data.

Mitigatiesamenvatting

The problem is corrected in the following product versions: Product Terminal OS Version - PPC3100 1.8.1 - C50 1.8.0 - C80 1.8.0 - FT50 1.8.1 - MT50 1.8.1 - T30 1.8.0 - T80 1.8.0 - T50 1.8.1 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revisiegeschiedenis (1)
  1. Initiële publicatie10 juni 2026

    Initial version.

Officiële bron: ABB PSIRT

9AKK108472A7840

Vulnerabilities in T-MAC Plus

ABBT-MAC Plus

ABB PSIRTkritiek

Gepubliceerd

3 juni 2026

Laatste update

3 juni 2026

Getroffen sectoren

Risk evaluation

ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. An attacker who successfully exploited any of these vulnerabilities could potentially compromise the system in different ways.

Mitigatiesamenvatting

ABB has investigated these vulnerabilities to provide adequate protection to customers. The problem is corrected in the following product versions: T-MAC Plus version 4.0-25 ABB recommends that customers apply the update at earliest convenience.

Revisiegeschiedenis (1)
  1. Initiële publicatie3 juni 2026

    Initial version.

Officiële bron: ABB PSIRT

SA25P006

PPT30 OPC-UA Server has issues handling concurrent connections

B&R Industrial Automation GmbHPPT30 Operating System

ABB PSIRThoog

Gepubliceerd

26 mei 2026

Laatste update

26 mei 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

B&R is aware of a vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploits this vulnerability could make the OPC-UA server of the product inaccessible.

Mitigatiesamenvatting

The problem is corrected in the following product versions: PPT30 Operating System 1.8.0 The OPC-UA server is not activated by default. B&R recommends that customers with the OPC-UA Server enabled to install the update at their earliest opportunity. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revisiegeschiedenis (1)
  1. Initiële publicatie26 mei 2026

    Initial version.

Officiële bron: ABB PSIRT

7PAA023732

System 800xA affected by 3rd party component vulnerabilities

ABB800xA History

ABB PSIRThoog

Risk evaluation

ABB is aware of public reports of vulnerabilities in 7-Zip version 18.5 and Microsoft Azure Data Studio version 1.32 included in the product versions listed as affected in the advisory. The vulnerability in 7-Zip can be exploited if attacker gains control over the system and extracts a malicious file using this version of 7-Zip. Otherwise, the attacker must force the user to visit malicious websites or click links and extract the package through 7-zip. Microsoft Azure Data Studio gets installed along with SQL Server Management Studio. An attacker who successfully exploits vulnerability in Microsoft Azure Data studio may compromise the security of the product by gaining privileges, reading sensitive information, executing commands, evading detection, etc. if the Authentication, Authorization and Accountability is not configured properly in the system. However, none of the products listed above uses Microsoft Azure Data Studio. Microsoft Azure Data Studio is automatically removed from the system from System 800xA 7.0 onwards. These vulnerabilities may appear when the product media is scanned. However, they can only be ex-ploited if the vulnerable software is installed on the system. For this reason, it is strongly advised to uninstall outdated or vulnerable versions of third-party software immediately.

Mitigatiesamenvatting

Workarounds are specific measures that a user can take to help block an attack, for example, temporarily disabling the vulnerable feature may remove the exposure with well-known impact on functionality. There are no workarounds. Uninstalling the affected third-party software fully eliminates the risk of vulnerabilities. Refer to the section ‘Recommended immediate actions’.

Revisiegeschiedenis (2)
  1. Initiële publicatie31 maart 2026

    Initial version.

  2. Update A22 mei 2026

    Added missing CVE description for CVE-2024-26203.

Officiële bron: ABB PSIRT

SA25P007

B&R Automation Studio Update of SQLite version

B&R Industrial Automation GmbHAutomation Studio

ABB PSIRTkritiek

Risk evaluation

ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that replaces an outdated third-party component. Although no successful exploitation was observed during testing of the affected B&R products, the identified vulnerabilities could present potential attack vectors that might enable unauthorized access, data exposure, or remote code execution.

Mitigatiesamenvatting

The problem is corrected in the following product versions: B&R Automation Studio 6.5 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revisiegeschiedenis (2)
  1. Initiële publicatie18 februari 2026

    Initial version.

  2. Update A14 mei 2026

    Corrected vendor name from 'ABB' to 'B&R Industrial Automation GmbH' to ensure accurate product matching.

Officiële bron: ABB PSIRT

SA26P001

​​PVI​ ​​Insertion of Sensitive Information into Logfile

B&R Industrial Automation GmbH​​PVI​

ABB PSIRTmiddel

Gepubliceerd

29 januari 2026

Laatste update

14 mei 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is now available that addresses and remediates the vulnerability. An attacker who successfully exploited this vulnerability could read sensitive information in the logging data of the PVI client application. Logging is deactivated by default in all PVI client versions.

Mitigatiesamenvatting

The problem is corrected in the following product versions: - PVI 6.5.0 Please note that PVI is included in the Automation Studio installation package and shares the same version number as the corresponding Automation Studio release. B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revisiegeschiedenis (2)
  1. Initiële publicatie29 januari 2026

    Initial version.

  2. Update A14 mei 2026

    Corrected vendor name from 'ABB' to 'B&R Industrial Automation GmbH' to ensure accurate product matching.

Officiële bron: ABB PSIRT

SA24P003

​B&R PCs vulnerable to PixieFail attack​

B&R Industrial Automation GmbHAPC4100

ABB PSIRThoog

Gepubliceerd

29 januari 2026

Laatste update

14 mei 2026

Getroffen sectoren

Risk evaluation

ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is now available that addresses and remediates the vulnerability. A network attacker could exploit the vulnerabilities to execute remote code, initiate DoS attacks, conduct DNS cache poisoning, or extract sensitive information.

Mitigatiesamenvatting

The problems are corrected in the following product versions: - APC4100 1.09 - APC910 No patch will be released (Please refer to the mitigation measures specified in this advisory). - C80 1.14 - MPC3100 1.24 - PPC1200 1.14 - PPC900 2.16 - APC2200 1.35 - PPC2200 1.35 - APC3100 1.45 - PPC3100 1.45 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revisiegeschiedenis (2)
  1. Initiële publicatie29 januari 2026

    Initial version.

  2. Update A14 mei 2026

    Corrected vendor name from 'ABB' to 'B&R Industrial Automation GmbH' to ensure accurate product matching.

Officiële bron: ABB PSIRT

SA25P005

B&R Automation Runtime Improper Handling of Flooding conditions on ANSL Server

B&R Industrial Automation GmbHAutomation Runtime

ABB PSIRTmiddel

Gepubliceerd

19 januari 2026

Laatste update

14 mei 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that resolves a vulnerability. An attacker who successfully exploited this vulnerability could cause the product to stop.

Mitigatiesamenvatting

The problem is corrected in the following product versions: - Automation Runtime 6 versions >= 6.5 - Automation Runtime 4 versions >= R4.93 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revisiegeschiedenis (2)
  1. Initiële publicatie19 januari 2026

    Initial version.

  2. Update A14 mei 2026

    Corrected vendor name from 'ABB' to 'B&R Industrial Automation GmbH' to ensure accurate product matching.

Officiële bron: ABB PSIRT

SA25P004

Automation Studio Insufficient Server Certificate Validation

B&R Industrial Automation GmbHAutomation Studio

ABB PSIRThoog

Gepubliceerd

19 januari 2026

Laatste update

14 mei 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that resolves a vulnerability. Successful exploitation of this vulnerability may enable an attacker to masquerade as a trusted party when B&R Automation Studio establishes a connection with a server via the ANSL over TLS or OPC-UA protocol.

Mitigatiesamenvatting

The problem is corrected in the following product versions: B&R Automation Studio version 6.5 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is de-scribed in the user manual.

Revisiegeschiedenis (2)
  1. Initiële publicatie19 januari 2026

    Initial Version

  2. Update A14 mei 2026

    Corrected vendor name from 'ABB' to 'B&R Industrial Automation GmbH' to ensure accurate product matching.

Officiële bron: ABB PSIRT

SA25P003

B&R Automation Runtime Vulnerabilities in System Diagnostic Manager (SDM)

B&R Industrial Automation GmbHAutomation Runtime

ABB PSIRTmiddel

Gepubliceerd

7 oktober 2025

Laatste update

14 mei 2026

Getroffen sectoren

Energieopwekking

Risk evaluation

An update is available that resolves a vulnerability identified by B&Rs internal security analysis in the product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could take over a remote session or execute code in the context of the user’s browser session.

Mitigatiesamenvatting

The problem is corrected in Automation Runtime 6.4. The System Diagnostic Manager (SDM) is disabled by default in Automation Runtime 6 and is not intended be enabled on active systems located outside properly secured production networks or in facilities lacking adequate physical and logical access controls to prevent any form of unauthorized interaction. For customers who use SDM on their systems, B&R recommends applying the update based on risk assessment at the earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revisiegeschiedenis (3)
  1. Initiële publicatie7 oktober 2025

    Initial version.

  2. Update A14 oktober 2025

    Added information about CVE-2025-11498.

  3. Update B14 mei 2026

    Corrected vendor name from 'ABB' to 'B&R Industrial Automation GmbH' to ensure accurate product matching.

Officiële bron: ABB PSIRT

7PAA020125

Denial of Service Vulnerabilities in System 800xA, Symphony® Plus IEC 61850 communication stack

ABBS+ Operations

ABB PSIRTmiddel

Gepubliceerd

13 april 2026

Laatste update

13 april 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

This vulnerability was privately reported relating to ABB’s implementation of the IEC 61850 communication stack for MMS client applications used in some Automation control system products. Note: IEC 61850 communication typically supports MMS and GOOSE protocols. Some ABB products support both, others only MMS (e.g. S+ Operations and PM 877). In any case, GOOSE communication is not impacted by this reported vulnerability. If an attacker gains access to a site’s IEC 61850 network, then exploiting this vulnerability will result in a device fault (PM 877, CI850 and CI868 modules) and will require a manual restart. If this attack is directed at a S+ Operations node running IEC 61850 connectivity, this will result in a crash in the IEC 61850 communication driver which, if continued a repeating basis, will also result in a denial-of-service situation. Note that this does not have an impact on the overall availability and functionality of the S+ Operations node, only the IEC 61850 communication function. The System 800xA IEC61850 Connect is not affected.

Mitigatiesamenvatting

ABB advises all customers to review their installations to determine if they are using an impacted product as listed above, no further analysis or tools are needed to make this determination. The recommended immediate actions per product are listed below: - CI868 (for AC 800M) Devices with firmware versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected in 6.1.1 and 7.0 tracks for 800xA. AC 800M 6.1.1-3 is planned for Q2 2027, AC 800M 7.0 has been released in December 2025. - CI850 (for Symphony Plus SD Series) Devices with firmware versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected in version C_0 or later (planned Q2 2026). - PM 877 (Symphony Plus MR) Devices with firmware versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected with firmware version 3.53 or later (planned Q1 2026). - S+ Operations Versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected in version 3.4 or later (released in January 2026). ABB recommends customers apply updates, as they become available, at their earliest convenience. It is also advisable to review the Mitigating Factors, Workarounds and General security recommendations sections for additional actions which may help reduce overall risk.

Revisiegeschiedenis (1)
  1. Initiële publicatie13 april 2026

    Initial version.

Officiële bron: ABB PSIRT

7PAA017341

PostgreSQL vulnerabilities in ABB Ability™ Symphony® Plus Engineering

ABBOnbekend product

ABB PSIRThoog

Gepubliceerd

13 april 2026

Laatste update

13 april 2026

Getroffen sectoren

Risk evaluation

ABB became aware of vulnerability in the products versions listed as affected in the advisory. The ABB S+ Engineering product versions are affected by vulnerabilities in PostgreSQL version 13.11 and earlier versions. If an attacker gains access to a site’s S+ Client Server network, they could exploit such vulnerabilities by executing arbitrary code and potentially compromising the entire system.

Mitigatiesamenvatting

ABB advises all customers to review their installations to determine if they are using an impacted product as listed above, no further analysis or tools are needed to make this determination. The recommended immediate actions per product are listed below: - Systems using S+ Engineering 2.2 through 2.4 SP2 should upgrade to S+ Engineering 2.4 SP2 RU1 (re-leased in December 2024) or later. - End users who are unable to install one of these updates should immediately look to implement the Mitigation and Workarounds listed below as this will restrict or prevent an attacker’s ability to com-promise the system. ABB recommends that customers apply the update at the earliest convenience.

Revisiegeschiedenis (1)
  1. Initiële publicatie13 april 2026

    Initial version.

Officiële bron: ABB PSIRT

4HZM000604

ABB Ability Camera Connect Vulnerabilities in outdated 3rd party component (SQLite 3.2.4)

ABBAbility Camera Connect

ABB PSIRTkritiek

Risk evaluation

ABB is aware of public reports of vulnerabilities in a 3rd party dependency SQLite Version 3.2.4 which was delivered together with the installation package of Camera Connect Version 2.0.0.42 and below. An update is available that resolves a privately reported outdated 3rd party component with vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited any of these vulnerabilities in the 3rd party component could potentially compromise the system in different ways.

Mitigatiesamenvatting

The problem is corrected in the following product versions: - ABB Ability Camera Connect 2.0.0.49. The easiest path to mitigate the problem is an update of ABB Ability Camera Connect system by the customer. ABB recommends that customers apply the update at earliest convenience.

Revisiegeschiedenis (1)
  1. Initiële publicatie26 maart 2026

    Initial version.

Officiële bron: ABB PSIRT

4JNO000329

AWIN Gateways Vulnerabilities in Embedded Webserver

ABBAWIN Firmware

ABB PSIRThoog

Gepubliceerd

13 maart 2026

Laatste update

13 maart 2026

Getroffen sectoren

Risk evaluation

ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. AWIN gateways are not intended to be internet-facing. An attacker who successfully exploited this vulnerability could take remote control of the product and reboot the device, potentially causing a denial of service. It can also reveal system specific configuration. ABB requires, as noted in the User Manual, that AWIN gateways should not be exposed to the internet or any other insecure network. Note. To exploit this vulnerability the attacker needs access to the AWIN gateways. These gateways are installed on sites which often have perimeter security, and the gateways are installed behind firewalls.

Mitigatiesamenvatting

Do the following actions: - Stop and disconnect any AWIN gateways that are exposed directly to the Internet. - Ensure that physical controls are in place, so no unauthorized personnel can access your devices, components, peripheral equipment, and networks. - Ensure that all AWIN gateways are upgraded to the latest firmware version. Please find the latest version of firmware on the respective product Release Notes. - When remote access is required, only use secure methods. The problem is corrected in the following product versions: - AWIN GW100 rev2: v2.1-0 - AWIN GW120: v2.0-0 ABB recommends that customers contact ABB to obtain the updated firmware as soon as possible. ABB Service Support engineer shall apply the firmware update at earliest convenience.

Revisiegeschiedenis (1)
  1. Initiële publicatie13 maart 2026

    Initial version.

Officiële bron: ABB PSIRT

3ADR011536

AC500 V3 Stack buffer overflow in Cryptographic Message Syntax

ABBAC500 V3 Firmware

ABB PSIRTkritiek

Gepubliceerd

12 maart 2026

Laatste update

12 maart 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves publicly reported vulnerability. An attacker who successfully exploited these vulnerabilities could cause a crash, denial-of-service (DoS), or potentially remote code execution.

Mitigatiesamenvatting

The problem is corrected in the following product version: - AC500 V3 firmware version 3.9.0 HF1 ABB recommends that customers apply the update at earliest convenience. This firmware version is released for all AC500 V3 PLC types and available for download from the ABB library. https://search.abb.com/library/Download.aspx?DocumentID=3ADR011537&LanguageCode=en&DocumentPartId=&Action=Launch

Revisiegeschiedenis (1)
  1. Initiële publicatie12 maart 2026

    Initial version.

Officiële bron: ABB PSIRT

3ADR011525

ABB Automation Builder Gateway for Windows with insecure defaults

ABBAutomation Builder

ABB PSIRTmiddel

Gepubliceerd

24 februari 2026

Laatste update

24 februari 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

ABB became aware of severe vulnerability in the products versions listed as affected in the advisory. The Windows gateway is accessible remotely by default. Unauthenticated attackers can therefore search for PLCs, but the user management of the PLCs prevents the actual access to the PLCs – unless it is disabled

Mitigatiesamenvatting

If remote access is not required, check the "LocalAddress" setting in the [CmpGwCommDrvTcp] section of the Gateway's configuration file as follows (restart of gateway required in case of changes): [CmpGwCommDrvTcp] LocalAddress=127.0.0.1 ; allow access only from the local computer The gateway configuration file can be located at (example for Automation Builder 2.8): %ProgramFiles%\ABB\AB2.8\AutomationBuilder\GatewayPLC\Gateway.cfg Starting with Automation Builder version 2.9.0 the vulnerability is closed by setting the default for the gateway to local access. Automation Builder 2.9.0 is available for download from the related download site. https://www.abb.com/global/en/areas/motion/digital-tools/automation-builder/software-download

Revisiegeschiedenis (1)
  1. Initiële publicatie24 februari 2026

    Initial version.

Officiële bron: ABB PSIRT

3ADR011524

AC500 V3 Multiple vulnerabilities

ABBAC500 V3

ABB PSIRThoog

Gepubliceerd

24 februari 2026

Laatste update

24 februari 2026

Getroffen sectoren

Risk evaluation

ABB became aware of severe vulnerability in the products versions listed as affected in the advisory. An update is available that resolves these vulnerabilities. An attacker who successfully exploited these vulnerabilities could bypass the user management and read visualization files (CVE-2025-2595), read and write certificates and keys (CVE-2025-41659) or cause a denial-of-service (DoS) (CVE-2025-41691).

Mitigatiesamenvatting

The problem is corrected in the following product versions: - AC500 V3 firmware version 3.9.0 ABB recommends that customers apply the update at earliest convenience. This firmware version is released for all AC500 V3 PLC types and available from Automation Builder 2.9.0. Automation Builder 2.9.0 is available for download from the related download site. https://www.abb.com/global/en/areas/motion/digital-tools/automation-builder/software-download

Revisiegeschiedenis (1)
  1. Initiële publicatie24 februari 2026

    Initial version.

Officiële bron: ABB PSIRT

7PAA013309

System 800xA SECURITY Advisory - ABB 800xA Base 6.0.x, 6.1.x CSLib communication DoS vulnerability

ABB800xA Base

ABB PSIRTmiddel

Gepubliceerd

5 juni 2024

Laatste update

23 januari 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

ABB is aware of a vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause services to crash and restart by sending specifically crafted messages. The vulnerability only affects 800xA services in PC based client/server nodes. Controllers are not affected by this vulnerability

Mitigatiesamenvatting

The problem is corrected in the following product versions: - ABB 800xA Base 6.2.0-0 (part of System 800xA 6.2.0.0) - ABB 800xA Base 6.1.1-3 (part of System 800xA 6.1.1.2) - ABB 800xA Base 6.0.3-10 (RollUp released in September’2025. RollUp requires System 800xA 6.0.3.4 to be installed in the system. See References for more details.) It is recommended to update to an active product version to obtain the latest corrections.

Revisiegeschiedenis (4)
  1. Initiële publicatie5 juni 2024

    Initial version

  2. Update A14 juni 2024

    Included CVSS v4.0 score

  3. Update B22 januari 2025

    Updated the planned release date for ABB 800xA Base 6.0.3-x

  4. Update C7 februari 2025

    Updated Affected Products and Recommended immediate actions

Officiële bron: ABB PSIRT

9AKK108472A1331

ABB Ability™ OPTIMAX® Authentication Bypass in Single-Sign On with Azure Active Directory

ABBOnbekend product

ABB PSIRThoog

Gepubliceerd

16 januari 2026

Laatste update

16 januari 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

ABB became aware of severe vulnerability in the products versions listed as affected in the advisory, if the optional integration with Azure Active Directory for Single-Sign On is enabled. We have not received any reports of this vulnerability being exploited. An attacker who successfully exploits this vulnerability could bypass user authentication and potentially cause the product to: - Shutdown the system, - Modify the configuration of the system, - Install and run arbitrary code

Mitigatiesamenvatting

The problem is corrected in the following product versions: - ABB Ability OPTIMAX v6.4.1-251120 (see References 9AKK108472A0435) or later - ABB Ability OPTIMAX v6.3.1-251120 (see References 9AKK108472A0437) or later ABB recommends that customers using earlier versions of OPTIMAX v6.4 and OPTIMAX v6.3 apply an update of the operating system at earliest convenience. Customers still using the meanwhile unsupported OPTIMAX v6.2 or v6.1 shall contact ABB to identify the right way forward.

Revisiegeschiedenis (1)
  1. Initiële publicatie16 januari 2026

    Initial version.

Officiële bron: ABB PSIRT

2CRT000009

WebPro SNMP Card PowerValue Multiple Vulnerabilities

ABBOnbekend product

ABB PSIRThoog

Gepubliceerd

7 januari 2026

Laatste update

7 januari 2026

Getroffen sectoren

Risk evaluation

ABB became aware of multiple internally discovered vulnerabilities in the WebPro SNMP card PowerValue for the product versions listed as affected in the advisory. Depending upon the vulnerability, an attacker with access to local network who successfully exploited this vulnerability could have - Unauthorized access - Insufficient Session Expiration leading to resource unavailability - Uncontrolled Resource Consumption leading to DOS attack ABB strongly advises customers to update the latest firmware of affected products.

Mitigatiesamenvatting

The problem is corrected in the following product versions: WebPro SNMP card PowerValue version 1.1.8.p ABB advises users of the affected product versions to reach out to ABB Digital Service Support (ch.ups.digital@abb.com) for guidance and recommended actions. Additionally, ABB recommends implementing defensive measures to reduce the risk of vulnerability exploitation, as outlined in the product instruction manual. Please refer to the section “Mitigation factors” for more information.

Revisiegeschiedenis (1)
  1. Initiële publicatie7 januari 2026

    Initial version.

Officiële bron: ABB PSIRT

4HZM000603

ABB Ability Camera Connect Vulnerabilities in outdated 3rd party component (VLC)

ABBAbility Camera Connect

ABB PSIRTkritiek

Risk evaluation

ABB is aware of public reports of vulnerabilities in a 3rd party component VLC media player Version 2.2.4 which was delivered together with the installation package of Camera Connect Version 1.5.0.14 and below. An update is available that resolves a privately reported outdated 3rd party component with vulnerabilities in the product versions listed as affected in this advisory. An attacker who successfully exploited any of these vulnerabilities in the 3rd party component could potentially compromise the system in different ways.

Mitigatiesamenvatting

The VLC-based component operates solely within completely isolated environments without internet access or any connectivity to external networks. Consequently: • No exposure to untrusted MMS streams: The integer overflow vulnerability relies on handling a maliciously crafted external stream, which is not possible in isolated environments • No remote attacker access: Without network ingress, attackers cannot trigger the vulnerability remotely. • Drastically reduced attack surface: The absence of any external media inputs effectively neutralizes the exploit path, significantly lowering the risk of both denial of service and code execution.

Revisiegeschiedenis (2)
  1. Initiële publicatie27 november 2025

    Initial version.

  2. Update A28 november 2025

    Correction in References

Officiële bron: ABB PSIRT

7PAA022088

Edgenius Management Portal Authentication Bypass

ABBAbility Edgenius

ABB PSIRTkritiek

Gepubliceerd

20 november 2025

Laatste update

20 november 2025

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

ABB identified a critical vulnerability present in ABB Ability Edgenius starting from version 3.2.0.0. We have not received any reports of this vulnerability being exploited. An unauthenticated attacker could exploit this vulnerability to: → install and run arbitrary code, → uninstall installed applications, → modify the configuration of installed applications, on systems running the vulnerable versions of ABB Ability Edgenius, including 3.2.0.0 through 3.2.1.1.

Mitigatiesamenvatting

ABB has prepared an update to fix this vulnerability included in the latest Roll-Up, ABB Ability Edgenius version 3.2.2.0. ABB advises customers to upgrade as soon as possible. Until the upgrade is applied, ABB advises customers to disable the Edgenius Management Portal to mitigate the vulnerability.

Revisiegeschiedenis (1)
  1. Initiële publicatie20 november 2025

    Initial version.

Officiële bron: ABB PSIRT

2NGA002813

PCM600 SharpZip library vulnerability

ABBOnbekend product

ABB PSIRTmiddel

Gepubliceerd

3 november 2025

Laatste update

3 november 2025

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

An update is available that resolves vulnerability in the product versions listed as affected in this advisory. An attacker who successfully exploited this vulnerability could insert and run arbitrary code in the system.

Mitigatiesamenvatting

The problem is corrected in the following product version: ABB Protection and control IED manager PCM600 version 2.14. ABB recommends that customers apply the update at earliest convenience. Note: RE_630 protection relays are not compatible with PCM600 version 2.14. When using earlier PCM600 versions with RE_630, the known vulnerability must be mitigated through system-level defenses. For mitigation guidance, refer to the General Security Recommendations.

Revisiegeschiedenis (1)
  1. Initiële publicatie3 november 2025

    Initial version.

Officiële bron: ABB PSIRT

4TZ00000006007

ALS-mini-S4/S8 IP Missing Authentication Vulnerability and its Mitigations

ABBALS-mini-s4 IP

ABB PSIRTkritiek

Gepubliceerd

20 oktober 2025

Laatste update

23 oktober 2025

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the pollution of heap memory which potentially takes remote control of the product and performs a write operation to the flash memory to alter the firmware behavior.

Mitigatiesamenvatting

ABB recommends that customers correctly configure the device in the network by referring to section Mitigating factors, or apply Workarounds to completely eliminate the attack vector.

Revisiegeschiedenis (2)
  1. Initiële publicatie20 oktober 2025

    Initial version.

  2. Update A23 oktober 2025

    Updated CVSS 3.1 score

Officiële bron: ABB PSIRT

9AKK108471A8948

Terra AC wallbox Heap Memory Corruption Vulnerability

ABBTerra AC wallbox (UL40/80A)

ABB PSIRTmiddel

Gepubliceerd

20 oktober 2025

Laatste update

21 oktober 2025

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the pollution of heap memory which potentially takes remote control of the product and performs a write operation to the flash memory to alter the firmware behavior.

Mitigatiesamenvatting

The problem is corrected in the product versions listed as fixed in the advisory. Terra AC wallbox (UL40/80A) 1.8.33 Terra AC wallbox (UL32A) 1.8.34 Terra AC MID 1.8.34 Terra AC Juno CE 1.8.34 Terra AC PTB 1.8.33 Terra AC wallbox (JP) 1.8.34 Additionally, we strongly recommend not use unsafe mode(http) to connect your charger to your backend even though OCPP is allowed to do in this way, which absolutely could be attacked by malicious man or organization as a common knowledge. ABB recommends that customers apply the update at earliest convenience.

Revisiegeschiedenis (2)
  1. Initiële publicatie20 oktober 2025

    Initial version.

  2. Update A21 oktober 2025

    Final version

Officiële bron: ABB PSIRT

3KXG200000R4801

CoreSense™ HM and CoreSense™ M10 File Path Traversal Vulnerability

ABBOnbekend product

ABB PSIRThoog

Gepubliceerd

16 april 2025

Laatste update

20 oktober 2025

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

An update is available that resolves vulnerability in the product versions listed as affected in this advisory. A path traversal vulnerability in these products can allow unauthenticated users to gain access to restricted directories. Exploiting this vulnerability can lead to complete system compromise and exposure of sensitive information.

Mitigatiesamenvatting

The vulnerabilities are corrected in the following version: CoreSense™ HM v2.3.4 & CoreSense™ M10 v1.4.1.31 ABB recommends that customers apply the update at the earliest convenience.

Revisiegeschiedenis (4)
  1. Initiële publicatie16 april 2025

    Initial version.

  2. Update A30 september 2025

    Addressed comments.

  3. Update B7 oktober 2025

    Fixed incorrect links.

  4. Update C20 oktober 2025

    Final version with corrected dates.

Officiële bron: ABB PSIRT

4TZ00000006008

LVS MConfig Insecure memory handling

ABBOnbekend product

ABB PSIRThoog

Gepubliceerd

8 oktober 2025

Laatste update

8 oktober 2025

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

ABB became aware of an internally discovered vulnerability in the MConfig product versions listed as affected in the advisory. An attacker with access to local networks who successfully exploits vulnerability could have access to application’s sensitive information. ABB strongly advises customers to update MConfig with latest software version.

Mitigatiesamenvatting

The vulnerability is resolved in the following product versions: MConfig version 1.4.9.22 ABB advises users to update their devices to the latest software version. Additionally, ABB recommends implementing defensive measures to reduce the risk of vulnerability exploitation, as outlined in the product instruction manual. Please refer to the section “Mitigation factors” for more information

Revisiegeschiedenis (1)
  1. Initiële publicatie8 oktober 2025

    Initial version.

Officiële bron: ABB PSIRT