Historical snapshot · Cybersecurity

CISA Advisories

Cybersecurity advisories and mitigation guidance for networks and critical infrastructure.

This page is an archived snapshot of the CISA Advisories feed collected on Feb 10, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
30 recordsOfficial source · JSON
· CISA Cybersecurity Advisory

TP-Link Systems Inc. VIGI Series IP Camera

View CSAF Summary Successful exploitation of this vulnerability could result in unauthorized users gaining administrative access to affected closed circuit television cameras. The following versions of TP-Link Systems Inc. VIGI Series IP Camera are affected: VIGI Cx45 Series Models C345, C445 <=3.1.0_Build_250820_Rel.57668n (CVE-2026-0629) VIGI Cx55 Series Models C355, C455 <=3.1.0_Build_250820_Rel.58873n…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could result in unauthorized users gaining administrative access to affected closed circuit television cameras. The following versions of TP-Link Systems Inc. VIGI Series IP Camera are affected: VIGI Cx45 Series Models C345, C445 <=3.1.0_Build_250820_Rel.57668n (CVE-2026-0629) VIGI Cx55 Series Models C355, C455 <=3.1.0_Build_250820_Rel.58873n (CVE-2026-0629) VIGI Cx85 Series Models C385, C485 <=3.0.2_Build_250630_Rel.71279n (CVE-2026-0629) VIGI C340S Series <=3.1.0_Build_250625_Rel.65381n (CVE-2026-0629) VIGI C540S Series Models C540S, EasyCam C540S <=3.1.0_Build_250625_Rel.66601n (CVE-2026-0629) VIGI C540V Series <=2.1.0_Build_250702_Rel.54300n (CVE-2026-0629) VIGI C250 Series <=2.1.0_Build_250702_Rel.54301n (CVE-2026-0629) VIGI Cx50 Series Models C350, C450 <=2.1.0_Build_250702_Rel.54294n (CVE-2026-0629) VIGI Cx20I (1.0) Series Models C220I 1.0, C320I 1.0, C420I 1.0 <=2.1.0_Build_251014_Rel.58331n (CVE-2026-0629) VIGI Cx20I (1.20) Series Models C220I 1.20, C320I 1.20, C420I 1.20 <=2.1.0_Build_250701_Rel.44071n (CVE-2026-0629) VIGI Cx30I (1.0) Series Models C230I 1.0, C330I 1.0, C430I 1.0 <=2.1.0_Build_250701_Rel.45506n (CVE-2026-0629) VIGI Cx30I (1.20) Series Models C230I 1.20, C330I 1.20, C430I 1.20 <=2.1.0_Build_250701_Rel.44555n (CVE-2026-0629) VIGI Cx30 (1.0) Series Models C230 1.0, C330 1.0, C430 1.0 <=2.1.0_Build_250701_Rel.46796n (CVE-2026-0629) VIGI Cx30 (1.20) Series Models C230 1.20, C330 1.20, C430 1.20 <=2.1.0_Build_250701_Rel.46796n (CVE-2026-0629) VIGI Cx40I (1.0) Series Models C240I 1.0, C340I 1.0, C440I 1.0 <=2.1.0_Build_250701_Rel.46003n (CVE-2026-0629) VIGI Cx40I (1.20) Series Models C240I 1.20, C340I 1.20, C440I 1.20 <=2.1.0_Build_250701_Rel.45041n (CVE-2026-0629) VIGI C230I Mini Series <=2.1.0_Build_250701_Rel.47570n (CVE-2026-0629) VIGI C240 1.0 Series <=2.1.0_Build_250701_Rel.48425n (CVE-2026-0629) VIGI C340 2.0 Series <=2.1.0_Build_250701_Rel.49304n (CVE-2026-0629) VIGI C440 2.0 Series <=2.1.0_Build_250701_Rel.49778n (CVE-2026-0629) VIGI C540 2.0 Series <=2.1.0_Build_250701_Rel.50397n (CVE-2026-0629) VIGI C540‑4G Series <=2.2.0_Build_250826_Rel.56808n (CVE-2026-0629) VIGI Cx40‑W Series Models C340‑W 2.0/2.20, C440‑W 2.0, C540‑W 2.0 <=2.1.1_Build_250717 (CVE-2026-0629) VIGI Cx20 Series Models C320, C420 <=2.1.0_Build_250701_Rel.39597n (CVE-2026-0629) VIGI InSight Sx45 Series Models S245, S345, S445 <=3.1.0_Build_250820_Rel.57668n (CVE-2026-0629) VIGI InSight Sx55 Series Models S355, S455 <=3.1.0_Build_250820_Rel.58873n (CVE-2026-0629) VIGI InSight Sx85 Series Models S285, S385 <=3.0.2_Build_250630_Rel.71279n (CVE-2026-0629) VIGI InSight Sx45ZI Series Models S245ZI, S345ZI, S445ZI <=1.2.0_Build_250820_Rel.60930n (CVE-2026-0629) VIGI InSight Sx85PI Series Models S385PI, S485PI <=1.2.0_Build_250827_Rel.66817n (CVE-2026-0629) VIGI InSight S655I Series <=1.1.1_Build_250625_Rel.64224n (CVE-2026-0629) VIGI InSight S345‑4G Series <=2.1.0_Build_250725_Rel.36867n (CVE-2026-0629) VIGI InSight Sx25 Series Models S225, S325, S425 <=1.1.0_Build_250630_Rel.39597n (CVE-2026-0629) CVSS Vendor Equipment Vulnerabilities v3 8.8 TP-Link Systems Inc. TP-Link Systems Inc. VIGI Series IP Camera Improper Authentication Background Critical Infrastructure Sectors: Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-0629 An authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models allows an attacker on the LAN to reset the admin password without verification by manipulating client-side state. Attackers can gain full administrative access to the device, compromising configuration and network security. View CVE Details Affected Products TP-Link Systems Inc. VIGI Series IP Camera Vendor: TP-Link Systems Inc. Product Version: TP-Link Systems Inc. VIGI Cx45 Series Models C345, C445: <=3.1.0_Build_250820_Rel.57668n, TP-Link Systems Inc. VIGI Cx55 Series Models C355, C455: <=3.1.0_Build_250820_Rel.58873n, TP-Link Systems Inc. VIGI Cx85 Series Models C385, C485: <=3.0.2_Build_250630_Rel.71279n, TP-Link Systems Inc. VIGI C340S Series: <=3.1.0_Build_250625_Rel.65381n, TP-Link Systems Inc. VIGI C540S Series Models C540S, EasyCam C540S: <=3.1.0_Build_250625_Rel.66601n, TP-Link Systems Inc. VIGI C540V Series: <=2.1.0_Build_250702_Rel.54300n, TP-Link Systems Inc. VIGI C250 Series: <=2.1.0_Build_250702_Rel.54301n, TP-Link Systems Inc. VIGI Cx50 Series Models C350, C450: <=2.1.0_Build_250702_Rel.54294n, TP-Link Systems Inc. VIGI Cx20I (1.0) Series Models C220I 1.0, C320I 1.0, C420I 1.0: <=2.1.0_Build_251014_Rel.58331n, TP-Link Systems Inc. VIGI Cx20I (1.20) Series Models C220I 1.20, C320I 1.20, C420I 1.20: <=2.1.0_Build_250701_Rel.44071n, TP-Link Systems Inc. VIGI Cx30I (1.0) Series Models C230I 1.0, C330I 1.0, C430I 1.0: <=2.1.0_Build_250701_Rel.45506n, TP-Link Systems Inc. VIGI Cx30I (1.20) Series Models C230I 1.20, C330I 1.20, C430I 1.20: <=2.1.0_Build_250701_Rel.44555n, TP-Link Systems Inc. VIGI Cx30 (1.0) Series Models C230 1.0, C330 1.0, C430 1.0: <=2.1.0_Build_250701_Rel.46796n, TP-Link Systems Inc. VIGI Cx30 (1.20) Series Models C230 1.20, C330 1.20, C430 1.20: <=2.1.0_Build_250701_Rel.46796n, TP-Link Systems Inc. VIGI Cx40I (1.0) Series Models C240I 1.0, C340I 1.0, C440I 1.0: <=2.1.0_Build_250701_Rel.46003n, TP-Link Systems Inc. VIGI Cx40I (1.20) Series Models C240I 1.20, C340I 1.20, C440I 1.20: <=2.1.0_Build_250701_Rel.45041n, TP-Link Systems Inc. VIGI C230I Mini Series: <=2.1.0_Build_250701_Rel.47570n, TP-Link Systems Inc. VIGI C240 1.0 Series: <=2.1.0_Build_250701_Rel.48425n, TP-Link Systems Inc. VIGI C340 2.0 Series: <=2.1.0_Build_250701_Rel.49304n, TP-Link Systems Inc. VIGI C440 2.0 Series: <=2.1.0_Build_250701_Rel.49778n, TP-Link Systems Inc. VIGI C540 2.0 Series: <=2.1.0_Build_250701_Rel.50397n, TP-Link Systems Inc. VIGI C540‑4G Series: <=2.2.0_Build_250826_Rel.56808n, TP-Link Systems Inc. VIGI Cx40‑W Series Models C340‑W 2.0/2.20, C440‑W 2.0, C540‑W 2.0: <=2.1.1_Build_250717, TP-Link Systems Inc. VIGI Cx20 Series Models C320, C420: <=2.1.0_Build_250701_Rel.39597n, TP-Link Systems Inc. VIGI InSight Sx45 Series Models S245, S345, S445: <=3.1.0_Build_250820_Rel.57668n, TP-Link Systems Inc. VIGI InSight Sx55 Series Models S355, S455: <=3.1.0_Build_250820_Rel.58873n, TP-Link Systems Inc. VIGI InSight Sx85 Series Models S285, S385: <=3.0.2_Build_250630_Rel.71279n, TP-Link Systems Inc. VIGI InSight Sx45ZI Series Models S245ZI, S345ZI, S445ZI: <=1.2.0_Build_250820_Rel.60930n, TP-Link Systems Inc. VIGI InSight Sx85PI Series Models S385PI, S485PI: <=1.2.0_Build_250827_Rel.66817n, TP-Link Systems Inc. VIGI InSight S655I Series: <=1.1.1_Build_250625_Rel.64224n, TP-Link Systems Inc. VIGI InSight S345‑4G Series: <=2.1.0_Build_250725_Rel.36867n, TP-Link Systems Inc. VIGI InSight Sx25 Series Models S225, S325, S425: <=1.1.0_Build_250630_Rel.39597n Product Status: known_affected Remediations Mitigation TP-Link Communications strongly recommends that users with affected devices take the following actions: Mitigation Download and update to the latest firmware version to fix the vulnerability from the following links. Mitigation United States users should visit the TP-Link US Download Center here: https://www.vigi.com/us/support/download/. Mitigation Global English users should visit the TP-Link EN Download Center:https://www.vigi.com/es/support/download/. Mitigation India users should visit the TP-Link India Download Center:https://www.vigi.com/in/support/download/. Mitigation Please visit https://www.tp-link.com/us/support/faq/4906/ for the TP-Link advisory. Relevant CWE: CWE-287 Improper Authentication Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Acknowledgments Arko Dhar of Redinent Innovations reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely. Revision History Initial Release Date: 2026-02-05 Date Revision Summary 2026-02-05 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Mitsubishi Electric MELSEC iQ-R Series

View CSAF Summary Successful exploitation of this vulnerability may allow an attacker to read device data or part of a control program from the affected product, write device data in the affected product, or cause a denial-of-service condition on the affected product. The following versions of Mitsubishi Electric MELSEC iQ-R Series are affected: MELSEC iQ-R Series R08/16/32/120PCPU firmware <=48 (CVE-2025-15080)…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability may allow an attacker to read device data or part of a control program from the affected product, write device data in the affected product, or cause a denial-of-service condition on the affected product. The following versions of Mitsubishi Electric MELSEC iQ-R Series are affected: MELSEC iQ-R Series R08/16/32/120PCPU firmware <=48 (CVE-2025-15080) CVSS Vendor Equipment Vulnerabilities v3 9.4 Mitsubishi Electric Mitsubishi Electric MELSEC iQ-R Series Improper Validation of Specified Quantity in Input Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Japan Vulnerabilities Expand All + CVE-2025-15080 An information disclosure, information tampering, and denial-of-service vulnerability exists in Mitsubishi Electric proprietary protocol communication and SLMP communication used in FA products. An attacker may be able to read device data or part of a control program from the affected product, write device data in the affected product, or cause a denial-of-service condition on the affected product by sending a specially crafted packet containing a specific command to the affected product. View CVE Details Affected Products Mitsubishi Electric MELSEC iQ-R Series Vendor: Mitsubishi Electric Product Version: Mitsubishi Electric MELSEC iQ-R Series R08/16/32/120PCPU firmware: <=48 Product Status: known_affected Remediations Mitigation Mitsubishi Electric recommends users of the affected products follow the procedure below to update firmware version 49 or later. Download the update file for the fixed version, the engineering software for firmware upgrade, and the manual from the download website at https://www.mitsubishielectric.com/fa/download/index.html . For details on updating the firmware, see MELSEC iQ-R Module Configuration Manual "Appendix 2 Firmware Update Function". Mitigation Mitsubishi Electric recommends the following mitigations to reduce the risk of exploiting this vulnerability: Use a firewall or virtual private network (VPN) block access from untrusted networks and hosts using a firewall. Use the product within a LAN and block access from untrusted networks and hosts through a firewall. Use firewalls, IP filters, and similar controls to minimize connections to the product and prevent access from untrusted networks and hosts. For details on the IP filter function, refer to "IP Filter" in section 1.13, Security, of the MELSEC iQ-R Ethernet User's Manual (Application). Restrict physical access to the affected product and its connected LAN. Mitigation For specific update instructions and additional details see the Mitsubishi Electric advisory at https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-020_en.pdf . Mitigation For further information, contact your local Mitsubishi Electric representative at https://www.mitsubishielectric.com/fa/service-support/index.html . Relevant CWE: CWE-1284 Improper Validation of Specified Quantity in Input Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.4 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H Acknowledgments Mitsubishi Electric reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-02-05 Date Revision Summary 2026-02-05 1 Initial Republication of Mitsubishi Electric 2025-020 Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Hitachi Energy FOX61x

View CSAF Summary Hitachi Energy is aware of a vulnerability that affects FOX61x product versions listed in this document. Successful exploitation of this vulnerability can lead to forgery attacks potentially causing impact on confidentiality, integrity and availability for the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. Note: This is applicable only…
Read full source summary
View CSAF Summary Hitachi Energy is aware of a vulnerability that affects FOX61x product versions listed in this document. Successful exploitation of this vulnerability can lead to forgery attacks potentially causing impact on confidentiality, integrity and availability for the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. Note: This is applicable only if FOX61x devices are configured to use remote RADIUS authentication. The following versions of Hitachi Energy FOX61x are affected: FOX61x R18, vers:FOX61x/<=R17A (CVE-2024-3596, CVE-2024-3596) CVSS Vendor Equipment Vulnerabilities v3 9 Hitachi Energy Hitachi Energy FOX61x Improper Enforcement of Message Integrity During Transmission in a Communication Channel Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2024-3596 The RADIUS protocol under RFC 2865 is vulnerable to forgery attacks that allow a local attacker to modify any valid response (Access-Accept, Access-Reject, or Access-Challenge) into another response by exploiting a chosen-prefix collision attack on the MD5 Response Authenticator signature.. View CVE Details Affected Products Hitachi Energy FOX61x Vendor: Hitachi Energy Product Version: FOX61x version R18, FOX61x version R17A and earlier Product Status: known_affected Remediations Mitigation Enable the RADIUS Message-Authenticator option in both the FOX61x and RADIUS Server configurations. Refer to the Technical User Documentation at https://publisher.hitachienergy.com/preview?DocumentID=1KHW029042&LanguageCode=en&DocumentPartId=R18&Action=launch. Vendor fix Update to FOX61x R18, then enable the RADIUS Message-Authenticator option in both the FOX61x and RADIUS Server configurations. Refer to the Technical User Documentation at https://publisher.hitachienergy.com/preview?DocumentID=1KHW029042&LanguageCode=en&DocumentPartId=R18&Action=launch. Mitigation If the upgrade is not possible, apply general mitigation factors with segmentation of FOX management traffic to minimize the risk. Mitigation For more information, see the associated Hitachi Energy cybersecurity advisory 8DBD000225 Radius MD5 Vulnerability in Hitachi Energy FOX61x product at https://publisher.hitachienergy.com/preview?DocumentID=8DBD000225&LanguageCode=en or https://publisher.hitachienergy.com/preview?DocumentID=8DBD000225-CSAF&LanguageCode=en&DocumentPartId=&Action=Launch . Mitigation Hitachi Energy recommends implementing security practices and firewall configurations to help protect process control networks from external attacks. Such practices include ensuring that process control systems are physically protected from unauthorized access, have no direct Internet connections, and are separated from other networks by a firewall system that minimizes exposed ports, and any additional ports should be evaluated on a case-by-case basis. Process control systems should not be used for web browsing, instant messaging, or email. Portable computers and removable storage media should be thoroughly scanned for malware before being connected to a control system. Organizations should enforce proper password policies and procedures. Relevant CWE: CWE-924 Improper Enforcement of Message Integrity During Transmission in a Communication Channel Metrics CVSS Version Base Score Base Severity Vector String 3.1 9 CRITICAL CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H Acknowledgments Hitachi Energy reported this vulnerability to CISA. Notice The information in this document is subject to change without notice and should not be construed as a commitment by Hitachi Energy. Hitachi Energy provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall Hitachi Energy or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if Hitachi Energy or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from Hitachi Energy and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners. Support For additional information and support please contact your product provider or Hitachi Energy service organization. For contact information, see https://www.hitachienergy.com/contact-us/ for Hitachi Energy contact-centers. General Mitigation Factors Recommended security practices and firewall configurations can help protect a process control network from attacks that originate from outside the network. Such practices include that process control systems are physically protected from direct access by unauthorized personnel, have no direct connections to the Internet, and are separated from other networks by means of a firewall system that has a minimal number of ports exposed, and others that have to be evaluated case by case. Process control systems should not be used for Internet surfing, instant messaging, or receiving e-mails. Portable computers and removable storage media should be carefully scanned for viruses before they are connected to a control system. Proper password policies and processes should be followed. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Hitachi Energy PSIRT 8DBD000225 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Hitachi Energy PSIRT directly for any questions regarding this advisory. Revision History Initial Release Date: 2026-01-27 Date Revision Summary 2026-01-27 1 Initial public release 2026-02-05 2 Initial CISA Republication of Hitachi Energy PSIRT 8DBD000225 advisory Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

o6 Automation GmbH Open62541

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition and memory corruption. The following versions of o6 Automation GmbH Open62541 are affected: Open62541 >=1.5-rc1|<1.5-rc2 (CVE-2026-1301) CVSS Vendor Equipment Vulnerabilities v3 5.7 o6 Automation GmbH o6 Automation GmbH Open62541 Out-of-bounds Write Background Critical Infrastructure…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition and memory corruption. The following versions of o6 Automation GmbH Open62541 are affected: Open62541 >=1.5-rc1|<1.5-rc2 (CVE-2026-1301) CVSS Vendor Equipment Vulnerabilities v3 5.7 o6 Automation GmbH o6 Automation GmbH Open62541 Out-of-bounds Write Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-1301 In builds with PubSub and JSON enabled, a crafted JSON message can cause the decoder to write beyond a heap-allocated array before authentication, reliably crashing the process and corrupting memory. View CVE Details Affected Products o6 Automation GmbH Open62541 Vendor: o6 Automation GmbH Product Version: o6 Automation GmbH Open62541: >=1.5-rc1|<1.5-rc2 Product Status: known_affected Remediations Mitigation o6 Automation GmbH recommends users upgrade to the stable release of v1.5.0. Relevant CWE: CWE-787 Out-of-bounds Write Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.7 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H Acknowledgments Andrew Fasano of NIST CAISI reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-02-05 Date Revision Summary 2026-02-05 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-11953 React Native Community CLI OS Command Injection Vulnerability CVE-2026-24423 SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant…
Read full source summary
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-11953 React Native Community CLI OS Command Injection Vulnerability CVE-2026-24423 SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
· CISA Cybersecurity Advisory

Hitachi Energy XMC20

View CSAF Summary Hitachi Energy is aware of a vulnerability that affects XMC20 product versions listed in this document. Successful exploitation of this vulnerability can lead to forgery attacks potentially causing impact on confidentiality, integrity and availability for the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. Note: This is applicable only if…
Read full source summary
View CSAF Summary Hitachi Energy is aware of a vulnerability that affects XMC20 product versions listed in this document. Successful exploitation of this vulnerability can lead to forgery attacks potentially causing impact on confidentiality, integrity and availability for the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. Note: This is applicable only if XMC20 devices are configured to use remote RADIUS authentication. The following versions of Hitachi Energy XMC20 are affected: XMC20 R18, vers:XMC20/<=R17A (CVE-2024-3596, CVE-2024-3596) CVSS Vendor Equipment Vulnerabilities v3 9 Hitachi Energy Hitachi Energy XMC20 Improper Enforcement of Message Integrity During Transmission in a Communication Channel Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2024-3596 The RADIUS protocol under RFC 2865 is susceptible to forgery attacks by a local attacker. An attacker can modify any valid response (Access-Accept, Access-Reject, or Access-Challenge) into another response using a chosen-prefix collision attack targeting the MD5 Response Authenticator signature. View CVE Details Affected Products Hitachi Energy XMC20 Vendor: Hitachi Energy Product Version: XMC20 version R18, XMC20 version R17A and earlier Product Status: known_affected Remediations Mitigation Enable the RADIUS Message-Authenticator option in both the XMC20 and RADIUS server configurations. Refer to the Technical User Documentation at https://publisher.hitachienergy.com/preview?DocumentID=1KHW029001&LanguageCode=en&DocumentPartId=R18&Action=launch. Vendor fix Update to XMC20 R18 and then enable the RADIUS Message-Authenticator option in both the XMC20 and RADIUS server configurations. Refer to the Technical User Documentation at https://publisher.hitachienergy.com/preview?DocumentID=1KHW029001&LanguageCode=en&DocumentPartId=R18&Action=launch. Mitigation If the upgrade is not possible, apply general mitigation factors with segmentation of FOX management traffic to minimize the risk. Mitigation For more information, see the associated Hitachi Energy cybersecurity advisory 8DBD000233 RADIUS MD5 Vulnerability in Hitachi Energy XMC20 product available in PDF format here https://publisher.hitachienergy.com/preview?DocumentID=8DBD000233&LanguageCode=en&DocumentPartId=&Action=launch or JSON format here https://publisher.hitachienergy.com/preview?DocumentID=8DBD000233-CSAF&LanguageCode=en&DocumentPartId=&Action=Launch. Mitigation Hitachi Energy recommends implementing security practices and firewall configurations to help protect process control networks from external attacks. Such practices include ensuring that process control systems are physically protected from unauthorized access, have no direct Internet connections, and are separated from other networks by a firewall system that minimizes exposed ports, and any additional ports should be evaluated on a case-by-case basis. Process control systems should not be used for web browsing, instant messaging, or email. Portable computers and removable storage media should be thoroughly scanned for malware before being connected to a control system. Organizations should enforce proper password policies and procedures. Relevant CWE: CWE-924 Improper Enforcement of Message Integrity During Transmission in a Communication Channel Metrics CVSS Version Base Score Base Severity Vector String 3.1 9 CRITICAL CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H Acknowledgments Hitachi Energy reported this vulnerability to CISA. Notice The information in this document is subject to change without notice and should not be construed as a commitment by Hitachi Energy. Hitachi Energy provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall Hitachi Energy or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if Hitachi Energy or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from Hitachi Energy and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners. Support For additional information and support please contact your product provider or Hitachi Energy service organization. For contact information, see https://www.hitachienergy.com/contact-us/ for Hitachi Energy contact-centers. General Mitigation Factors Recommended security practices and firewall configurations can help protect a process control network from attacks that originate from outside the network. Such practices include that process control systems are physically protected from direct access by unauthorized personnel, have no direct connections to the Internet, and are separated from other networks by means of a firewall system that has a minimal number of ports exposed, and others that have to be evaluated case by case. Process control systems should not be used for Internet surfing, instant messaging, or receiving e-mails. Portable computers and removable storage media should be carefully scanned for viruses before they are connected to a control system. Proper password policies and processes should be followed. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Hitachi Energy PSIRT 8DBD000233 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Hitachi Energy PSIRT directly for any questions regarding this advisory. Revision History Initial Release Date: 2026-01-27 Date Revision Summary 2026-01-27 1 Initial public release 2026-02-05 2 Initial CISA Republication of Hitachi Energy PSIRT 8DBD000233 advisory Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Ilevia EVE X1 Server

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary shell commands and the disclosure of sensitive system information. The following versions of Ilevia EVE X1 Server are affected: EVE X1 <=4.7.18.0 (CVE-2025-34185, CVE-2025-34184, CVE-2025-34183, CVE-2025-34186, CVE-2025-34187, CVE-2025-34517, CVE-2025-34518, CVE-2025-34512, CVE-2025-34513) CVSS Vendor…
Read full source summary
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary shell commands and the disclosure of sensitive system information. The following versions of Ilevia EVE X1 Server are affected: EVE X1 <=4.7.18.0 (CVE-2025-34185, CVE-2025-34184, CVE-2025-34183, CVE-2025-34186, CVE-2025-34187, CVE-2025-34517, CVE-2025-34518, CVE-2025-34512, CVE-2025-34513) CVSS Vendor Equipment Vulnerabilities v3 9.8 Ilevia Ilevia EVE X1 Server Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Insertion of Sensitive Information into Log File, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Italy Vulnerabilities Expand All + CVE-2025-34185 Ilevia EVE X1 Server contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote attackers can retrieve arbitrary files from the server, exposing sensitive system information and credentials. View CVE Details Affected Products Ilevia EVE X1 Server Vendor: Ilevia Product Version: Ilevia EVE X1: <=4.7.18.0 Product Status: known_affected Remediations Mitigation Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces. Relevant CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2025-34184 Ilevia EVE X1 Server contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote attackers can execute arbitrary system commands by injecting payloads into the 'passwd' HTTP POST parameter, leading to full system compromise or denial of service. View CVE Details Affected Products Ilevia EVE X1 Server Vendor: Ilevia Product Version: Ilevia EVE X1: <=4.7.18.0 Product Status: known_affected Remediations Mitigation Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces. Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2025-34183 Ilevia EVE X1 Server contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from exposed .log files. This flaw enables full authentication bypass and system compromise through credential reuse. View CVE Details Affected Products Ilevia EVE X1 Server Vendor: Ilevia Product Version: Ilevia EVE X1: <=4.7.18.0 Product Status: known_affected Remediations Mitigation Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces. Relevant CWE: CWE-532 Insertion of Sensitive Information into Log File Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2025-34186 Ilevia EVE X1/X5 Server contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing attackers to inject special characters and manipulate command parsing. Due to the binary's interpretation of non-zero exit codes as successful authentication, remote attackers can bypass authentication and gain full access to the system. View CVE Details Affected Products Ilevia EVE X1 Server Vendor: Ilevia Product Version: Ilevia EVE X1: <=4.7.18.0 Product Status: known_affected Remediations Mitigation Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces. Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2025-34187 Ilevia EVE X1/X5 Server contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash scripts. If these scripts are writable by web-facing users or accessible via command injection, attackers can replace them with malicious payloads. Execution with sudo grants full root access, resulting in remote privilege escalation and potential system compromise. View CVE Details Affected Products Ilevia EVE X1 Server Vendor: Ilevia Product Version: Ilevia EVE X1: <=4.7.18.0 Product Status: known_affected Remediations Mitigation Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces. Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2025-34517 Ilevia EVE X1 Server firmware contains an absolute path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet. View CVE Details Affected Products Ilevia EVE X1 Server Vendor: Ilevia Product Version: Ilevia EVE X1: <=4.7.18.0 Product Status: known_affected Remediations Mitigation Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces. Relevant CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2025-34518 Ilevia EVE X1 Server firmware contains a relative path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet. View CVE Details Affected Products Ilevia EVE X1 Server Vendor: Ilevia Product Version: Ilevia EVE X1: <=4.7.18.0 Product Status: known_affected Remediations Mitigation Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces. Relevant CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2025-34512 Ilevia EVE X1 Server firmware contains a reflected cross-site scripting (XSS) vulnerability in index.php that allows an unauthenticated attacker to execute arbitrary code. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet. View CVE Details Affected Products Ilevia EVE X1 Server Vendor: Ilevia Product Version: Ilevia EVE X1: <=4.7.18.0 Product Status: known_affected Remediations Mitigation Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces. Relevant CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N CVE-2025-34513 Ilevia EVE X1 Server firmware contains an OS command injection vulnerability in mbus_build_from_csv.php that allows an unauthenticated attacker to execute arbitrary code. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet. View CVE Details Affected Products Ilevia EVE X1 Server Vendor: Ilevia Product Version: Ilevia EVE X1: <=4.7.18.0 Product Status: known_affected Remediations Mitigation Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces. Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Acknowledgments Gjoko Krstic of Zero Science Lab reported these vulnerabilities to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-02-05 Date Revision Summary 2026-02-05 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Reducing the Attack Surface for End-of-Support Edge Devices

Introduction The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.K.’s National Cyber Security Centre (NCSC) are releasing this fact sheet to urge defensive action against malicious cyber activity by nation-state threat actors. Nation-state threat actors exploit end-of-support (EOS) edge devices—including, but not limited to, load balancers, firewalls,…
Read full source summary
Introduction The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.K.’s National Cyber Security Centre (NCSC) are releasing this fact sheet to urge defensive action against malicious cyber activity by nation-state threat actors. Nation-state threat actors exploit end-of-support (EOS) edge devices—including, but not limited to, load balancers, firewalls, routers, and virtual private network (VPN) gateways—to gain network access, maintain presence, and compromise sensitive data. Organizations using EOS devices are particularly vulnerable to compromise, especially if they are using EOS devices exposed to the public internet or external systems at the network’s “edge.” CISA’s Binding Operational Directive (BOD) 26-02: Mitigating Risk From End-of-Support Edge Devices requires U.S. Federal Civilian Executive Branch (FCEB) agencies to manage the lifecycle of edge devices to defend against malicious cyber activity. Although the BOD 26-02 requirement only applies to FCEB agencies, CISA, FBI, and NCSC strongly encourage organizations to follow the guidance in the BOD and this fact sheet to safeguard systems, data, and operations from nation-state threat actors. What Are EOS Edge Devices? Edge devices include technology that resides on the boundary of an organization’s network and is accessible from the public internet and other external environments. An edge device becomes an “end-of-support” or “unsupported” device when its manufacturer no longer: Monitors it for defects in its software and/or firmware, and Updates it with patches for common vulnerabilities and exposures (CVEs), security updates, and software fixes (hotfixes). EOS edge devices pose significant risks for organizations because threat actors can exploit unresolved security gaps. Nation-state threat actors can exploit these devices as entry points to access modern, supported environments, placing organizations’ data, services, and overall security at serious risk. EOS devices may also cause compatibility issues that disrupt productivity. Mitigations Organizations should be prepared to respond to malicious cyber activity. As the nation’s cyber defense agency, CISA and its partners stand ready to help prepare organizations to respond to and mitigate the impact of malicious cyber activity. CISA and its partners strongly urge all organizations to review BOD 26-02 and implement the following mitigations. Maintain Asset Inventory and Audits Keeping track of all devices within a network will equip network defenders with the awareness necessary to protect vulnerable assets. Actively scan networks for undocumented and outdated edge devices. Maintain an inventory of all edge devices and their respective support timelines. Regularly review inventory and EOS dates. Critical infrastructure owners and operators, see Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators. Replace EOS Edge Devices and Software Network defenders should proactively monitor for and replace unsupported edge devices to reduce a network perimeter’s vulnerability. Take prompt action to replace EOS edge devices; as these devices age, managing their risks becomes increasingly challenging and costly. Install Updates and Patch Known CVEs Software updates will patch known CVEs; if automatic updates are not enabled, network defenders should proactively monitor for these updates. Ensure EOS devices operate on the latest supported software version when immediate replacement is not possible. By using the latest software update, organizations can address CVEs and other known vulnerabilities identified up to the time of the update. Enable automatic updates on all devices to install timely patches. Resources The following resources provide further guidance on protecting systems from cyber threats linked to EOS software or devices: CISA: Edge Device Security webpage provides edge device best practices to help organizations secure their network perimeters against modern cyber threats. CISA: Guidance and Strategies to Protect Network Edge Devices offers practical advice and recommendations for protecting edge devices, focusing on minimizing vulnerabilities and improving network resilience. CISA: Known Exploited Vulnerabilities Catalog provides a regularly updated list of vulnerabilities actively exploited by threat actors, allowing organizations to prioritize remediation efforts effectively. ASD’s ACSC: Managing the risks of legacy IT: Executive guidance provides strategies and high-level guidance for executives to mitigate risks stemming from outdated and legacy IT systems. ASD’s ACSC: Mitigation strategies for edge devices: Practitioner guidance offers detailed technical advice and actionable steps for IT practitioners to enhance the security of edge devices in their networks. CISA: No-Cost Cybersecurity Services and Tools lists no-cost services and tools provided by CISA, as well as private and public sector organizations across the cyber community, to strengthen security postures and address cyber risks. CISA: Technical Approaches to Uncovering and Remediating Malicious Activity presents detailed technical methodologies and best practices for detecting, analyzing, and addressing malicious activity within networks. OASIS: OpenEoX provides robust guidance on the secure lifecycle management and handling of EOS software and associated tools to reduce security vulnerabilities. NCSC: Guidance on digital forensics and protective monitoring specifications for producers of network devices and appliances delivers best practices and recommendations for conducting digital forensic investigations and implementing protective monitoring to safeguard network devices against cyber threats. Please share your thoughts! We welcome your feedback CISA PRODUCT SURVEY
· CISA Cybersecurity Advisory

Synectix LAN 232 TRIO

View CSAF Summary Successful exploitation of this vulnerability could result in an unauthenticated attacker modifying critical device settings or factory resetting the device. The following versions of Synectix LAN 232 TRIO are affected: LAN 232 TRIO vers:all/* (CVE-2026-1633) CVSS Vendor Equipment Vulnerabilities v3 10 Synectix Synectix LAN 232 TRIO Missing Authentication for Critical Function Background Critical…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could result in an unauthenticated attacker modifying critical device settings or factory resetting the device. The following versions of Synectix LAN 232 TRIO are affected: LAN 232 TRIO vers:all/* (CVE-2026-1633) CVSS Vendor Equipment Vulnerabilities v3 10 Synectix Synectix LAN 232 TRIO Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Critical Manufacturing, Emergency Services, Energy, Information Technology, Transportation Systems, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-1633 The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authentication, allowing unauthenticated users to modify critical device settings or factory reset the device. View CVE Details Affected Products Synectix LAN 232 TRIO Vendor: Synectix Product Version: Synectix LAN 232 TRIO: vers:all/* Product Status: known_affected Remediations Mitigation The affected products should be considered end-of-life, as Synectix is no longer in business and therefore firmware fixes, mitigations and updates will be unavailable. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 10 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Acknowledgments Souvik Kandar of MicroSec (microsec.io) reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-02-03 Date Revision Summary 2026-02-03 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

RISS SRL MOMA Seismic Station

View CSAF Summary Successful exploitation of this vulnerability could result in an unauthenticated attacker creating a denial-of-service condition. The following versions of RISS SRL MOMA Seismic Station are affected: MOMA Seismic Station <=v2.4.2520 (CVE-2026-1632) CVSS Vendor Equipment Vulnerabilities v3 9.1 RISS SRL RISS SRL MOMA Seismic Station Missing Authentication for Critical Function Background Critical…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could result in an unauthenticated attacker creating a denial-of-service condition. The following versions of RISS SRL MOMA Seismic Station are affected: MOMA Seismic Station <=v2.4.2520 (CVE-2026-1632) CVSS Vendor Equipment Vulnerabilities v3 9.1 RISS SRL RISS SRL MOMA Seismic Station Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Critical Manufacturing, Dams, Energy, Water and Wastewater, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Italy Vulnerabilities Expand All + CVE-2026-1632 MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication, which could allow an unauthenticated attacker to modify configuration settings, acquire device data or remotely reset the device. View CVE Details Affected Products RISS SRL MOMA Seismic Station Vendor: RISS SRL Product Version: RISS SRL MOMA Seismic Station: <=v2.4.2520 Product Status: known_affected Remediations Vendor fix RISS SRL did not respond to CISA's request for coordination. Users of RISS MOMA Seismic Station are encouraged to contact RISS SRL (info@riss-srl.com) for more information. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.1 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Acknowledgments Souvik Kandar reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-02-03 Date Revision Summary 2026-02-03 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Mitsubishi Electric FREQSHIP-mini for Windows

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to, modify, delete, or destroy information stored on the system where the affected product is installed, or cause a denial-of-service condition on the affected system. The following versions of Mitsubishi Electric FREQSHIP-mini for Windows are affected: FREQSHIP-mini for Windows >=8.0.0|<=8.0.2…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to, modify, delete, or destroy information stored on the system where the affected product is installed, or cause a denial-of-service condition on the affected system. The following versions of Mitsubishi Electric FREQSHIP-mini for Windows are affected: FREQSHIP-mini for Windows >=8.0.0|<=8.0.2 (CVE-2025-10314) CVSS Vendor Equipment Vulnerabilities v3 8.8 Mitsubishi Electric Mitsubishi Electric FREQSHIP-mini for Windows Incorrect Default Permissions Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Information Technology, Healthcare and Public Health, Government Services and Facilities Countries/Areas Deployed: Japan Company Headquarters Location: Japan Vulnerabilities Expand All + CVE-2025-10314 A malicious code execution vulnerability exists in Mitsubishi's small-capacity UPS shutdown software, FREQSHIP-mini for Windows, due to incorrect default permissions. A local attacker may be able to execute arbitrary code with system privileges by replacing service executable or DLL files in the installation directory with specially crafted files. View CVE Details Affected Products Mitsubishi Electric FREQSHIP-mini for Windows Vendor: Mitsubishi Electric Product Version: Mitsubishi Electric FREQSHIP-mini for Windows: >=8.0.0|<=8.0.2 Product Status: known_affected Remediations Vendor fix The vulnerability has been addressed in FREQSHIP-mini for Windows version 8.1.0 or later. Download and install the updated version from the Mitsubishi Electric download site at https://www.mitsubishielectric.co.jp/fa/download/index.html . Mitigation Mitsubishi Electric recommends that customers take the following mitigation measures to minimize the risk of this vulnerability being exploited: Use the PCs with the affected product installed only within a LAN, and block remote logins from untrusted networks, hosts, and non-administrator users. Block unauthorized access by using a firewall or virtual private network (VPN), etc., and allow remote login only for administrators when connecting the PCs with the affected product installed to the internet. Restrict physical access to the PC and its connected network to prevent unauthorized access. Do not click on links or open attachments in emails from untrusted sources. Install and regularly update antivirus software. Mitigation Mitsubishi Electric Corporation recommends users contact their local Mitsubishi Electric representative at https://www.mitsubishielectric.co.jp/fa/support/purchase/index.html with questions. Mitigation For additional details, refer to Mitsubishi Electric's security advisory at https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2025-019_en.pdf . Relevant CWE: CWE-276 Incorrect Default Permissions Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Acknowledgments Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc. reported this vulnerability to Mitsubishi Electric Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely. Revision History Initial Release Date: 2026-02-03 Date Revision Summary 2026-02-03 1 Initial Republication of Mitsubishi Electric 2025-019. Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Avation Light Engine Pro

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take full control of the device. The following versions of Avation Light Engine Pro are affected: Light Engine Pro vers:all/* (CVE-2026-1341) CVSS Vendor Equipment Vulnerabilities v3 9.8 Avation Avation Light Engine Pro Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Commercial…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take full control of the device. The following versions of Avation Light Engine Pro are affected: Light Engine Pro vers:all/* (CVE-2026-1341) CVSS Vendor Equipment Vulnerabilities v3 9.8 Avation Avation Light Engine Pro Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: Australia Vulnerabilities Expand All + CVE-2026-1341 Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control. View CVE Details Affected Products Avation Light Engine Pro Vendor: Avation Product Version: Avation Light Engine Pro: vers:all/* Product Status: known_affected Remediations Vendor fix Avation has not responded to CISA's request to coordinate. Users of Avation Light Engine Pro are encouraged to contact Avation for more information. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Acknowledgments Souvik Kandar reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-02-03 Date Revision Summary 2026-02-03 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2019-19006 Sangoma FreePBX Improper Authentication Vulnerability CVE-2021-39935 GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability CVE-2025-40551 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability CVE-2025-64328…
Read full source summary
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2019-19006 Sangoma FreePBX Improper Authentication Vulnerability CVE-2021-39935 GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability CVE-2025-40551 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability CVE-2025-64328 Sangoma FreePBX OS Command Injection Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
· CISA Cybersecurity Advisory

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-1281 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant…
Read full source summary
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-1281 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
· CISA Cybersecurity Advisory

Rockwell Automation ArmorStart LT

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation ArmorStart LT are affected: ArmorStart LT 290D <=V2.002 (CVE-2025-9464, CVE-2025-9465, CVE-2025-9466, CVE-2025-9278, CVE-2025-9279, CVE-2025-9280, CVE-2025-9281, CVE-2025-9282, CVE-2025-9283) ArmorStart LT 291D <=V2.002 (CVE-2025-9464,…
Read full source summary
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation ArmorStart LT are affected: ArmorStart LT 290D <=V2.002 (CVE-2025-9464, CVE-2025-9465, CVE-2025-9466, CVE-2025-9278, CVE-2025-9279, CVE-2025-9280, CVE-2025-9281, CVE-2025-9282, CVE-2025-9283) ArmorStart LT 291D <=V2.002 (CVE-2025-9464, CVE-2025-9465, CVE-2025-9466, CVE-2025-9278, CVE-2025-9279, CVE-2025-9280, CVE-2025-9281, CVE-2025-9282, CVE-2025-9283) ArmorStart LT 294D <=V2.002 (CVE-2025-9464, CVE-2025-9465, CVE-2025-9466, CVE-2025-9278, CVE-2025-9279, CVE-2025-9280, CVE-2025-9281, CVE-2025-9282, CVE-2025-9283) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation ArmorStart LT Uncontrolled Resource Consumption Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2025-9464 A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. This vulnerability is triggered during fuzzing of multiple CIP classes, which causes the CIP port to become unresponsive. View CVE Details Affected Products Rockwell Automation ArmorStart LT Vendor: Rockwell Automation Product Version: Rockwell Automation ArmorStart LT 290D: <=V2.002, Rockwell Automation ArmorStart LT 291D: <=V2.002, Rockwell Automation ArmorStart LT 294D: <=V2.002 Product Status: known_affected Remediations Mitigation There is no patch or upgrade at this time. Rockwell Automation recommends users apply security best practices to mitigate the risk of these vulnerabilities. Mitigation See Rockwell Automation's SD1768 advisory for more information. Relevant CWE: CWE-400 Uncontrolled Resource Consumption Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2025-9465 A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. View CVE Details Affected Products Rockwell Automation ArmorStart LT Vendor: Rockwell Automation Product Version: Rockwell Automation ArmorStart LT 290D: <=V2.002, Rockwell Automation ArmorStart LT 291D: <=V2.002, Rockwell Automation ArmorStart LT 294D: <=V2.002 Product Status: known_affected Remediations Mitigation There is no patch or upgrade at this time. Rockwell Automation recommends users apply security best practices to mitigate the risk of these vulnerabilities. Mitigation See Rockwell Automation's SD1768 advisory for more information. Relevant CWE: CWE-400 Uncontrolled Resource Consumption Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2025-9466 A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP and CIP grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. View CVE Details Affected Products Rockwell Automation ArmorStart LT Vendor: Rockwell Automation Product Version: Rockwell Automation ArmorStart LT 290D: <=V2.002, Rockwell Automation ArmorStart LT 291D: <=V2.002, Rockwell Automation ArmorStart LT 294D: <=V2.002 Product Status: known_affected Remediations Mitigation There is no patch or upgrade at this time. Rockwell Automation recommends users apply security best practices to mitigate the risk of these vulnerabilities. Mitigation See Rockwell Automation's SD1768 advisory for more information. Relevant CWE: CWE-400 Uncontrolled Resource Consumption Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2025-9278 A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. After running a Burp Suite active scan, the device loses ICMP connectivity, causing the web application to become inaccessible. View CVE Details Affected Products Rockwell Automation ArmorStart LT Vendor: Rockwell Automation Product Version: Rockwell Automation ArmorStart LT 290D: <=V2.002, Rockwell Automation ArmorStart LT 291D: <=V2.002, Rockwell Automation ArmorStart LT 294D: <=V2.002 Product Status: known_affected Remediations Mitigation There is no patch or upgrade at this time. Rockwell Automation recommends users apply security best practices to mitigate the risk of these vulnerabilities. Mitigation See Rockwell Automation's SD1768 advisory for more information. Relevant CWE: CWE-400 Uncontrolled Resource Consumption Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2025-9279 A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limit Storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. View CVE Details Affected Products Rockwell Automation ArmorStart LT Vendor: Rockwell Automation Product Version: Rockwell Automation ArmorStart LT 290D: <=V2.002, Rockwell Automation ArmorStart LT 291D: <=V2.002, Rockwell Automation ArmorStart LT 294D: <=V2.002 Product Status: known_affected Remediations Mitigation There is no patch or upgrade at this time. Rockwell Automation recommends users apply security best practices to mitigate the risk of these vulnerabilities. Mitigation See Rockwell Automation's SD1768 advisory for more information. Relevant CWE: CWE-400 Uncontrolled Resource Consumption Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2025-9280 A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. Fuzzing performed using Defensics causes the device to become unresponsive, requiring a reboot. View CVE Details Affected Products Rockwell Automation ArmorStart LT Vendor: Rockwell Automation Product Version: Rockwell Automation ArmorStart LT 290D: <=V2.002, Rockwell Automation ArmorStart LT 291D: <=V2.002, Rockwell Automation ArmorStart LT 294D: <=V2.002 Product Status: known_affected Remediations Mitigation There is no patch or upgrade at this time. Rockwell Automation recommends users apply security best practices to mitigate the risk of these vulnerabilities. Mitigation See Rockwell Automation's SD1768 advisory for more information. Relevant CWE: CWE-400 Uncontrolled Resource Consumption Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2025-9281 A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive step limit storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. View CVE Details Affected Products Rockwell Automation ArmorStart LT Vendor: Rockwell Automation Product Version: Rockwell Automation ArmorStart LT 290D: <=V2.002, Rockwell Automation ArmorStart LT 291D: <=V2.002, Rockwell Automation ArmorStart LT 294D: <=V2.002 Product Status: known_affected Remediations Mitigation There is no patch or upgrade at this time. Rockwell Automation recommends users apply security best practices to mitigate the risk of these vulnerabilities. Mitigation See Rockwell Automation's SD1768 advisory for more information. Relevant CWE: CWE-400 Uncontrolled Resource Consumption Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2025-9282 A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive limited storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. View CVE Details Affected Products Rockwell Automation ArmorStart LT Vendor: Rockwell Automation Product Version: Rockwell Automation ArmorStart LT 290D: <=V2.002, Rockwell Automation ArmorStart LT 291D: <=V2.002, Rockwell Automation ArmorStart LT 294D: <=V2.002 Product Status: known_affected Remediations Mitigation There is no patch or upgrade at this time. Rockwell Automation recommends users apply security best practices to mitigate the risk of these vulnerabilities. Mitigation See Rockwell Automation's SD1768 advisory for more information. Relevant CWE: CWE-400 Uncontrolled Resource Consumption Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2025-9283 A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limits Storms tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. View CVE Details Affected Products Rockwell Automation ArmorStart LT Vendor: Rockwell Automation Product Version: Rockwell Automation ArmorStart LT 290D: <=V2.002, Rockwell Automation ArmorStart LT 291D: <=V2.002, Rockwell Automation ArmorStart LT 294D: <=V2.002 Product Status: known_affected Remediations Mitigation There is no patch or upgrade at this time. Rockwell Automation recommends users apply security best practices to mitigate the risk of these vulnerabilities. Mitigation See Rockwell Automation's SD1768 advisory for more information. Relevant CWE: CWE-400 Uncontrolled Resource Consumption Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Acknowledgments Rockwell Automation reported these vulnerabilties to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-01-29 Date Revision Summary 2026-01-29 1 Initial Republication of Rockwell Automation advisory SD1768 Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Rockwell Automation ControlLogix

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation ControlLogix are affected: ControlLogix Redundancy Enhanced Module Catalog 1756-RM2 Firmware vers:all/* (CVE-2025-14027) ControlLogix Redundancy Enhanced Module Catalog 1756-RM2XT Firmware vers:all/* (CVE-2025-14027) CVSS Vendor Equipment…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation ControlLogix are affected: ControlLogix Redundancy Enhanced Module Catalog 1756-RM2 Firmware vers:all/* (CVE-2025-14027) ControlLogix Redundancy Enhanced Module Catalog 1756-RM2XT Firmware vers:all/* (CVE-2025-14027) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation ControlLogix Missing Release of Memory after Effective Lifetime Background Critical Infrastructure Sectors: Chemical, Energy, Critical Manufacturing, Food and Agriculture, Transportation Systems, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2025-14027 Multiple denial-of-service issues exist in 1756-RM2 and 1756-RM2XT firmware (ControlLogix Redundancy Enhanced Modules). These issues can be triggered through various crafted inputs, including malformed Class 3 messages, memory leak conditions, and other resource exhaustion scenarios. Exploitation may cause the device to become unresponsive and, in some cases, result in a major nonrecoverable fault. Recovery may require a restart. View CVE Details Affected Products Rockwell Automation ControlLogix Vendor: Rockwell Automation Product Version: Rockwell Automation ControlLogix Redundancy Enhanced Module Catalog 1756-RM2 Firmware: vers:all/*, Rockwell Automation ControlLogix Redundancy Enhanced Module Catalog 1756-RM2XT Firmware: vers:all/* Product Status: known_affected Remediations Mitigation Rockwell Automation recommends that users upgrade from the 1756-RM2 to 1756-RM3. Mitigation If users are unable to upgrade to the 1756-RM3, security best practices should be applied. Mitigation See Rockwell Automation's SD1769 advisory for more information. Relevant CWE: CWE-401 Missing Release of Memory after Effective Lifetime Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Acknowledgments Rockwell Automation reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-01-29 Date Revision Summary 2026-01-29 1 Initial Republication of Rockwell Automation advisory SD1769 Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

KiloView Encoder Series (Update A)

View CSAF Summary Successful exploitation of this vulnerability could allow an unauthenticated attacker to create or delete administrator accounts, granting full administrative control. The following versions of KiloView Encoder Series are affected: Encoder Series E1 hardware Version 1.4 4.7.2516 (CVE-2026-1453) Encoder Series E1 hardware Version 1.6.20…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an unauthenticated attacker to create or delete administrator accounts, granting full administrative control. The following versions of KiloView Encoder Series are affected: Encoder Series E1 hardware Version 1.4 4.7.2516 (CVE-2026-1453) Encoder Series E1 hardware Version 1.6.20 4.7.2511|4.8.2523|4.8.2611|4.6.2400|4.7.2512|4.8.2561|4.8.2554|4.3.2029|4.8.2555|4.6.2408 (CVE-2026-1453) Encoder Series E1-s hardware Version 1.4 4.7.2516|4.8.2519|4.8.2525|4.8.2611|4.8.2561|4.8.2554|4.8.2523 (CVE-2026-1453) Encoder Series E2 hardware Version 1.7.20 4.8.2611|4.8.2561 (CVE-2026-1453) Encoder Series E2 hardware Version 1.8.20 4.8.2523|4.8.2611|4.8.2554 (CVE-2026-1453) Encoder Series G1 hardware Version 1.6.20 4.8.2561 (CVE-2026-1453) Encoder Series P1 hardware Version 1.3.20 4.8.2633|4.8.2608 (CVE-2026-1453) Encoder Series P2 hardware Version 1.8.20 4.8.2633 (CVE-2026-1453) Encoder Series RE1 hardware Version 2.0.00 4.7.2513 (CVE-2026-1453) Encoder Series RE1 hardware Version 3.0.00 4.8.2519|4.8.2561|4.8.2611|4.8.2525 (CVE-2026-1453) CVSS Vendor Equipment Vulnerabilities v3 9.8 KiloView KiloView Encoder Series Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Communications, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-1453 A missing authentication for critical function vulnerability in KiloView Encoder Series could allow an unauthenticated attacker to create or delete administrator accounts. This vulnerability can grant the attacker full administrative control over the product. View CVE Details Affected Products KiloView Encoder Series Vendor: KiloView Product Version: KiloView Encoder Series E1 hardware Version 1.4: 4.7.2516, KiloView Encoder Series E1 hardware Version 1.6.20: 4.7.2511|4.8.2523|4.8.2611|4.6.2400|4.7.2512|4.8.2561|4.8.2554|4.3.2029|4.8.2555|4.6.2408, KiloView Encoder Series E1-s hardware Version 1.4: 4.7.2516|4.8.2519|4.8.2525|4.8.2611|4.8.2561|4.8.2554|4.8.2523, KiloView Encoder Series E2 hardware Version 1.7.20: 4.8.2611|4.8.2561, KiloView Encoder Series E2 hardware Version 1.8.20: 4.8.2523|4.8.2611|4.8.2554, KiloView Encoder Series G1 hardware Version 1.6.20: 4.8.2561, KiloView Encoder Series P1 hardware Version 1.3.20: 4.8.2633|4.8.2608, KiloView Encoder Series P2 hardware Version 1.8.20: 4.8.2633, KiloView Encoder Series RE1 hardware Version 2.0.00: 4.7.2513, KiloView Encoder Series RE1 hardware Version 3.0.00: 4.8.2519|4.8.2561|4.8.2611|4.8.2525 Product Status: known_affected Remediations Mitigation KiloView states that these specific hardware versions are end-of-life; therefore, no patches will be released due to hardware limitations. KiloView recommends that users implement mitigation measures such as network isolation or upgrade to newer hardware generations. Mitigation Users of affected versions of KiloView Encoder Series are invited to contact KiloView customer support at https://www.kiloview.com/contact/ for additional information. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Acknowledgments Muhammad Ammar (0xam225) reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-01-29 Date Revision Summary 2026-01-29 1 Initial Publication 2026-02-05 2 Update A - Affected products are end-of-life Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Fortinet Releases Guidance to Address Ongoing Exploitation of Authentication Bypass Vulnerability CVE-2026-24858

Newly disclosed vulnerability Common Vulnerabilities and Exposures (CVE)-2026-24858 [Common Weakness Enumeration (CWE)-288: Authentication Bypass Using an Alternate Path or Channel] allows malicious actors with a FortiCloud account and a registered device to log in to separate devices registered to other users in FortiOS, FortiManager, FortiWeb, FortiProxy, and FortiAnalyzer, if FortiCloud single sign on (SSO) is…
Read full source summary
Newly disclosed vulnerability Common Vulnerabilities and Exposures (CVE)-2026-24858 [Common Weakness Enumeration (CWE)-288: Authentication Bypass Using an Alternate Path or Channel] allows malicious actors with a FortiCloud account and a registered device to log in to separate devices registered to other users in FortiOS, FortiManager, FortiWeb, FortiProxy, and FortiAnalyzer, if FortiCloud single sign on (SSO) is enabled on devices.1 Users are vulnerable to CVE-2026-24858 even if they updated Fortinet devices to address previously disclosed FortiCloud SSO bypass vulnerabilities CVE-2025-59718 and CVE-2025-59719 [CWE-347: Improper Verification of Cryptographic Signature].2 CVE-2025-59718 and CVE-2025-59719 affect FortiOS, FortiWeb, FortiProxy, and FortiSwitch Manager, and allow malicious actors to bypass the SSO login authentication via a crafted Security Assertion Markup Language (SAML) message.3 On Fortinet devices that had been fully upgraded to the latest release addressing CVE-2025-59718 and CVE-2025-59719 at the time of CVE-2026-24858 exploitation, Fortinet observed the following malicious activity: Unauthorized firewall configuration changes on FortiGate devices. Unauthorized creation of accounts. Unauthorized configuration changes of virtual private networks (VPNs) to grant access to new accounts.4 According to Fortinet, on Jan. 26, 2026, Fortinet disabled all FortiCloud SSO authentication to mitigate CVE-2026-24858, then reinstated the service on Jan. 27, 2026, with changes to prevent exploitation of vulnerable devices. CISA added CVE-2026-24858 to its Known Exploited Vulnerabilities (KEV) Catalog on Jan. 27, 2026. CISA urges users to check for indicators of compromise on all internet-accessible Fortinet products affected by this vulnerability and immediately apply updates as soon as they are available using Fortinet’s instructions: Administrative FortiCloud SSO authentication bypass Analysis of Single Sign-On Abuse on FortiOS Disclaimer The information in this report is being provided “as is” for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA. Notes Fortinet, “Administrative FortiCloud SSO Authentication Bypass,” FortiGuard Labs, last modified January 27, 2026, https://fortiguard.fortinet.com/psirt/FG-IR-26-060. Fortinet, “Multiple Fortinet Products’ FortiCloud SSO Login Authentication Bypass,” FortiGuard Labs, last modified December 9, 2025, https://fortiguard.fortinet.com/psirt/FG-IR-25-647. Carl Windsor, “Analysis of Single Sign-On Abuse on FortiOS,” PSIRT Blogs (blog), Fortinet, last modified January 22, 2026, https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios. Arctic Wolf Labs, “Arctic Wolf Observes Malicious Configuration Changes on Fortinet FortiGate Devices via SSO Accounts,” Arctic Wolf Blog (blog), Arctic Wolf, last modified January 21, 2026, https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-configuration-changes-fortinet-fortigate-devices-via-sso-accounts/.
· CISA Cybersecurity Advisory

iba Systems ibaPDA

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized actions on the file system. The following versions of iba Systems ibaPDA are affected: ibaPDA (CVE-2025-14988) CVSS Vendor Equipment Vulnerabilities v3 9.8 iba Systems iba Systems ibaPDA Incorrect Permission Assignment for Critical Resource Background Critical Infrastructure Sectors: Critical Manufacturing…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized actions on the file system. The following versions of iba Systems ibaPDA are affected: ibaPDA (CVE-2025-14988) CVSS Vendor Equipment Vulnerabilities v3 9.8 iba Systems iba Systems ibaPDA Incorrect Permission Assignment for Critical Resource Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2025-14988 A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain conditions. This may impact the confidentiality, integrity, or availability of the system. View CVE Details Affected Products iba Systems ibaPDA Vendor: iba Systems Product Version: iba Systems ibaPDA: 8.12.0 Product Status: known_affected Remediations Vendor fix iba Systems recommends users update to ibaPDA v8.12.1 or a later version. Mitigation If Installing the update is not possible, iba Systems recommends users: Mitigation Enable User Management:To activate user management, navigate to User Management settings under the Configure option. Set a password for the admin user to enable user management. Vendor fix Configure Server Access:To configure, open Server Access Manager (found under Configure in the ibaPDA Client). Set the configuration to restrict access. For example, only 127.0.0.1 (localhost) or specific system IP addresses to communicate with ibaPDA can connect to the ibaPDA Server. (In this example, only connections from localhost are permitted to access ibaPDA.) Vendor fix Restrict Connections to Localhost (if ibaPDA is only accessed from the system where it runs): Vendor fix Go to I/O Manager, then General, and deactivate the option "Automatically open necessary ports in Windows Firewall." (If this option remains active, after a restart of ibaPDA or a restart for data acquisition, the firewall will be reconfigured automatically.) Vendor fix Then, go to Advanced Windows Firewall settings and delete or deactivate all incoming rules for the ibaPDA Client and Server. Vendor fix Manually create firewall rules for the connection used for ibaPDA and verify that the correct ports are configured. For assistance with identifying the ports used by the ibaPDA service can be found in the iba Help Center. Vendor fix Note: After making the changes, verify that all ibaPDA services are operating as expected and that the data acquisition is functioning correctly. Relevant CWE: CWE-732 Incorrect Permission Assignment for Critical Resource Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Acknowledgments Siemens reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-01-27 Date Revision Summary 2026-01-27 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Johnson Controls Metasys Products

View CSAF Summary Successful exploitation of this vulnerability could result in remote SQL execution, leading to alteration or loss of data. The following versions of Johnson Controls Metasys Products are affected: Metasys Application and Data Server (ADS) (CVE-2025-26385) Metasys Extended Application and Data Server (ADX) (CVE-2025-26385) Metasys LCS8500 (CVE-2025-26385) Metasys NAE8500 (CVE-2025-26385) Metasys…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could result in remote SQL execution, leading to alteration or loss of data. The following versions of Johnson Controls Metasys Products are affected: Metasys Application and Data Server (ADS) (CVE-2025-26385) Metasys Extended Application and Data Server (ADX) (CVE-2025-26385) Metasys LCS8500 (CVE-2025-26385) Metasys NAE8500 (CVE-2025-26385) Metasys System Configuration Tool (SCT) (CVE-2025-26385) Metasys Controller Configuration Tool (CCT) (CVE-2025-26385) CVSS Vendor Equipment Vulnerabilities v3 10 Johnson Controls Johnson Controls Metasys Products Improper Neutralization of Special Elements used in a Command ('Command Injection') Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy, Government Services and Facilities, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2025-26385 Under certain circumstances a successful exploitation of this vulnerability could allow remote SQL execution. View CVE Details Affected Products Johnson Controls Metasys Products Vendor: Johnson Controls Product Version: Johnson Controls Metasys Application and Data Server (ADS): <=14.1, Johnson Controls Metasys Extended Application and Data Server (ADX):14.1, Johnson Controls Metasys LCS8500: >=12.0|<=14.1, Johnson Controls Metasys NAE8500: >=12.0|<=14.1, Johnson Controls Metasys System Configuration Tool (SCT): <=17.1, Johnson Controls Metasys Controller Configuration Tool (CCT): <=17.0 Product Status: known_affected Remediations Mitigation Johnson Controls recommends downloading and executing the Metasys patch for GIV-165989 from the License Portal. Login credentials are required. Mitigation Johnson Controls advises following the Metasys Release 14 Hardening Guide to ensure each Metasys installation is on a segmented network and not exposed to untrusted networks such as the internet. Mitigation Additionally, closing incoming TCP port 1433 can protect against exploitation of this vulnerability. Mitigation For more detailed mitigation instructions, visit Johnson Controls Product Security Advisory JCI-PSA-2026-02. Relevant CWE: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 10 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Acknowledgments Johnson Controls reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-01-27 Date Revision Summary 2026-01-27 1 Initial Republication of Johnson Controls advisory JCI-PSA-2026-02 Legal Notice and Terms of Use
Browse saved snapshots