[
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-03",
        "title": "Weintek cMT3092X",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-03",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-03.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users.</strong></p>\n<p>The following versions of Weintek cMT3092X are affected:</p>\n<ul>\n<li>cMT3092X firmware &lt;20210218&nbsp;</li>\n<li>EasyWeb &lt;v2.1.20</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.8</td>\n<td>Weintek</td>\n<td>Weintek cMT3092X</td>\n<td>Reliance on Cookies without Validation and Integrity Checking in a Security Decision, Incorrect Permission Assignment for Critical Resource, Plaintext Storage of a Password, Incorrect User Management</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Taiwan</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-60134</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-60134\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Weintek cMT3092X</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Weintek</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Weintek cMT3092X firmware: &lt;20210218, Weintek EasyWeb: &lt;v2.1.20</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors.<br><a href=\"https://www.weintek.com/globalw/Support/Knowledge.aspx\">https://www.weintek.com/globalw/Support/Knowledge.aspx</a></p>\n<p><strong>Mitigation</strong><br>Weintek has published a document with more details about this issue at https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf.<br><a href=\"https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf\">https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/784.html\">CWE-784 Reliance on Cookies without Validation and Integrity Checking in a Security Decision</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-61892</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-61892\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Weintek cMT3092X</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Weintek</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Weintek cMT3092X firmware: &lt;20210218, Weintek EasyWeb: &lt;v2.1.20</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors.<br><a href=\"https://www.weintek.com/globalw/Support/Knowledge.aspx\">https://www.weintek.com/globalw/Support/Knowledge.aspx</a></p>\n<p><strong>Mitigation</strong><br>Weintek has published a document with more details about this issue at https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf.<br><a href=\"https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf\">https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/732.html\">CWE-732 Incorrect Permission Assignment for Critical Resource</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-61886</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Weintek cMT3092X HMI stores user account passwords in plaintext.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-61886\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Weintek cMT3092X</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Weintek</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Weintek cMT3092X firmware: &lt;20210218, Weintek EasyWeb: &lt;v2.1.20</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors.<br><a href=\"https://www.weintek.com/globalw/Support/Knowledge.aspx\">https://www.weintek.com/globalw/Support/Knowledge.aspx</a></p>\n<p><strong>Mitigation</strong><br>Weintek has published a document with more details about this issue at https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf.<br><a href=\"https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf\">https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/256.html\">CWE-256 Plaintext Storage of a Password</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-60135</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An attacker can modify data that should be restricted to read\u2011only access.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-60135\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Weintek cMT3092X</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Weintek</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Weintek cMT3092X firmware: &lt;20210218, Weintek EasyWeb: &lt;v2.1.20</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors.<br><a href=\"https://www.weintek.com/globalw/Support/Knowledge.aspx\">https://www.weintek.com/globalw/Support/Knowledge.aspx</a></p>\n<p><strong>Mitigation</strong><br>Weintek has published a document with more details about this issue at https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf.<br><a href=\"https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf\">https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/286.html\">CWE-286 Incorrect User Management</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Vincenzo Giuseppe Colacino of Secoore reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Practice principles of least privilege.</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-23</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-23</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 23 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 23 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-05",
        "title": "Rockwell Automation ThinManager",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-05",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-05.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory.</strong></p>\n<p>The following versions of Rockwell Automation ThinManager are affected:</p>\n<ul>\n<li>ThinManager &gt;=13.0.0|&lt;13.0.7, &gt;=13.1.0|&lt;13.1.5, &gt;=13.2.0|&lt;13.2.4, &gt;=14.0.0|&lt;14.0.2</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.1</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation ThinManager</td>\n<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Critical Manufacturing, Energy, Food and Agriculture, Water and Wastewater</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-11917</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A path traversal security issue exists within Rockwell Automation ThinManager software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitrary files to restricted system directories outside of the application's intended directory.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-11917\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation ThinManager</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation ThinManager: &gt;=13.0.0|&lt;13.0.7, Rockwell Automation ThinManager: &gt;=13.1.0|&lt;13.1.5, Rockwell Automation ThinManager: &gt;=13.2.0|&lt;13.2.4, Rockwell Automation ThinManager: &gt;=14.0.0|&lt;14.0.2</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users using the affected software, should upgrade to one of the corrected versions as follows:</p>\n<p><strong>Vendor fix</strong><br>ThinManager Versions 13.0.0 - 13.0.7 --&gt; 13.0.8</p>\n<p><strong>Vendor fix</strong><br>ThinManager Versions 13.1.0 - 13.1.5 --&gt; 13.1.6</p>\n<p><strong>Vendor fix</strong><br>ThinManager Versions 13.2.0 - 13.2.4 --&gt; 13.2.5</p>\n<p><strong>Vendor fix</strong><br>ThinManager Versions 14.0.0 - 14.0.2 --&gt; 14.0.3</p>\n<p><strong>Mitigation</strong><br>Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information, refer to Rockwell Automation's Securitry Advisory page.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/22.html\">CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-14</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-14</td>\n<td>1</td>\n<td>Initial Publication by Rockwell Automation</td>\n</tr>\n<tr>\n<td>2026-07-23</td>\n<td>2</td>\n<td>Initial Republication of Rockwell Automation advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 23 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 23 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a",
        "title": "Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a",
        "summary": "<div class=\"c-page-title__buttons\"><a class=\"c-button\" href=\"https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF\">Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite</a></div>\n<h2><strong>Executive summary</strong>&nbsp;</h2>\n<p>A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group\u2019s activity is tracked in the cybersecurity community under several names (see <a href=\"#cyber1\">Cybersecurity industry tracking</a>), primarily as \u201cLAUNDRY BEAR,\u201d a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [<a href=\"#wc1\">1</a>].</p>\n<p>LAUNDRY BEAR\u2019s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data. Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated initial access techniques\u2014including password spraying, phishing, and pass-the-cookie\u2014allowing the group to successfully run high-volume operations. The latest campaign targeting ZCS uses a novel exploit that was a zero-day vulnerability when first exploited and continues to be successfully exploited. The vulnerability, Common Vulnerabilities and Exposures (CVE) <a href=\"https://www.cve.org/CVERecord?id=CVE-2025-66376\" target=\"_blank\">CVE-2025-66376</a>, was patched in November 2025. This demonstrates LAUNDRY BEAR\u2019s intent and ability to deploy increasingly sophisticated technical capabilities.</p>\n<p>Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR\u2019s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service. Once viewed, the exploit attempts to exfiltrate the victim\u2019s last 90 days of email communications, the organization email directory (i.e., Global Address List [GAL]), and other sensitive information to servers controlled by LAUNDRY BEAR. The exploit also attempts to establish persistent access to victim accounts through a variety of means as detailed in the <a href=\"#persistence1\">Persistence and credential access</a> section.</p>\n<p>This Cybersecurity Advisory (CSA) warns of this ongoing malicious threat activity and urges organizations to update their vulnerable software and implement additional mitigations to thwart these Russian state-supported actors\u2019 continued success. The CSA is being released by the following authoring and co-sealing agencies:</p>\n<ul>\n<li>United States National Security Agency (NSA)</li>\n<li>United States Federal Bureau of Investigation (FBI)</li>\n<li>Netherlands Defence Intelligence and Security Service (MIVD)</li>\n<li>Netherlands General Intelligence and Security Service (AIVD)</li>\n<li>United States Cybersecurity and Infrastructure Security Agency (CISA)</li>\n<li>United States Defense Counterintelligence and Security Agency (DCSA)</li>\n<li>United States Department of Defense Cyber Crime Center (DC3)</li>\n<li>United States Department of the Treasury</li>\n<li>United States Naval Criminal Investigative Service (NCIS)</li>\n<li>Australian Signals Directorate\u2019s Australian Cyber Security Centre (ASD\u2019s ACSC)</li>\n<li>Communications Security Establishment Canada\u2019s (CSE\u2019s) Canadian Centre for Cyber Security (Cyber Centre)</li>\n<li>New Zealand National Cyber Security Centre (NCSC-NZ)</li>\n<li>United Kingdom National Cyber Security Centre (NCSC-UK)</li>\n<li>Czech Republic National Cyber and Information Security Agency (N\u00daKIB)<a href=\"#f1\"><sup>1</sup></a></li>\n<li>Danish Defence Intelligence Service (DDIS)<a href=\"#f2\"><sup>2</sup></a></li>\n<li>Estonian Foreign Intelligence Service (EFIS)<a href=\"#f3\"><sup>3</sup></a></li>\n<li>Finnish Defence Intelligence (FDI)<a href=\"#f4\"><sup>4</sup></a></li>\n<li>Finnish Security and Intelligence Service (SUPO)<a href=\"#f5\"><sup>5</sup></a></li>\n<li>French General Directorate for Internal Security (DGSI)<a href=\"#f6\"><sup>6</sup></a></li>\n<li>French National Cybersecurity Agency (ANSSI)<a href=\"#f7\"><sup>7</sup></a></li>\n<li>Italian External Intelligence and Security Agency (AISE)<a href=\"#f8\"><sup>8</sup></a></li>\n<li>Italian Internal Intelligence and Security Agency (AISI)<a href=\"#f9\"><sup>9</sup></a></li>\n<li>Security and Intelligence Service of the Republic of Moldova (SIS RM)<a href=\"#f10\"><sup>10</sup></a></li>\n<li>Polish Foreign Intelligence Agency (AW)<a href=\"#f11\"><sup>11</sup></a></li>\n<li>The Military Counterintelligence Service of Poland (SKW)<a href=\"#f12\"><sup>12</sup></a></li>\n<li>Spain National Intelligence Centre (CNI)<a href=\"#f13\"><sup>13</sup></a></li>\n<li>Sweden National Cyber Security Centre (NCSC-SE)<a href=\"#f14\"><sup>14</sup></a></li>\n</ul>\n<p>The authoring agencies urge any organizations using ZCS to implement the recommendations listed within the <a href=\"#mitigations1\">Mitigations</a> section of this advisory to reduce the risk associated with this activity. This CSA also includes specific remediations for organizations to implement if they discover the presence of the listed <a href=\"#ioc1\">Indicators of compromise</a> (IOCs). &nbsp;</p>\n<p>As more organizations update their ZCS software based on this CSA, LAUNDRY BEAR may discontinue the current campaign exploiting this vulnerability; however, based on the success of this and previous campaigns, it is very likely that the group will continue to target ZCS and other email systems used by organizations in Western countries. The actors will almost certainly continue to rely on email to engage potential victims by exploiting novel vulnerabilities and, when necessary, use social engineering techniques to assist with their efforts. The authoring agencies recommend organizations regularly update their mail service software and continuously monitor their email systems and emails for malicious activity.</p>\n<p>For a downloadable list of IOCs, see:</p>\n<ul>\n<li><a href=\"https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.xml\">AA26-204A.stix.xml</a> (STIX XML)</li>\n<li><a href=\"https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.json\">AA26-204A.stix.json</a> (STIX JSON)</li>\n</ul>\n<h2><strong>Cybersecurity industry tracking</strong><a class=\"ck-anchor\" id=\"cyber1\"></a></h2>\n<p>The cybersecurity industry provides overlapping cyber threat intelligence, indicators of compromise (IOCs), and mitigation recommendations related to these Russian state-supported cyber actors. While not exhaustive, the following are threat group names commonly used for these actors within the cybersecurity community:</p>\n<ul>\n<li>LAUNDRY BEAR</li>\n<li>Void Blizzard [<a href=\"#wc2\">2</a>]</li>\n<li>CL-STA-1114 [<a href=\"#wc3\">3</a>]</li>\n<li>TA488 (formerly UNK_PitStop) [<a href=\"#wc4\">4</a>]</li>\n</ul>\n<p><strong>Note:</strong> Cybersecurity companies have different methods of tracking and attributing cyber actors, and this may not be a 1:1 correlation to the U.S. government\u2019s understanding for all activity related to these groupings.</p>\n<h2><strong>Background</strong></h2>\n<p>Public advisories from Netherlands General Intelligence and Security Service (AIVD), Netherlands Defence Intelligence and Security Service (MIVD), and Microsoft highlighted these Russian state-supported advanced persistent threat (APT) actors in May 2025, calling them LAUNDRY BEAR and Void Blizzard respectively [<a href=\"#wc1\">1</a>] [<a href=\"#wc2\">2</a>]. Both advisories assessed that the group was engaged in malicious cyber activity as early as April 2024. &nbsp;</p>\n<p>The May 2025 advisories highlighted a cluster of activity targeting cloud-based email environments, including Microsoft Exchange in particular, and abusing legitimate APIs to perform data exfiltration in bulk [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1114/002/\" target=\"_blank\">T1114.002</a>]. The group relied on unsophisticated means of initial access, including procuring stolen credentials on criminal marketplaces [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1078/\" target=\"_blank\">T1078</a>], and using social engineering techniques to lure targets into interacting with a malicious site masquerading as a legitimate one. As of April 2025, one of these sites resembled a European Defence &amp; Security Summit registration portal that required registrants to sign in to their Microsoft account to view. Once a user entered their Microsoft credentials into this malicious site, LAUNDRY BEAR\u2019s modified version of the open source adversary emulation toolkit, Evilginx, intercepted the user\u2019s credentials. LAUNDRY BEAR then used this authentication data, including passwords and session tokens, to access the compromised account and conduct mass email exfiltration, as well as harvest other information. This method of compromise is commonly known as an adversary-in-the-middle (AiTM) technique [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1557/\" target=\"_blank\">T1557</a>]. &nbsp;</p>\n<p>Beginning around July 2025, LAUNDRY BEAR shifted toward a more technical method of email compromise, highlighting their continued efforts to covertly acquire email communications from a variety of Western organizations of interest and deliver them to the Russian Federation. Using a custom-developed capability [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1587/001/\" target=\"_blank\">T1587.001</a>] named \u201c<em>\u0423\u043b\u0435\u0439</em>\u201d or \u201c<em>Ulej</em>\u201d (Russian for beehive), LAUNDRY BEAR successfully targeted and exfiltrated sensitive user information from organizations who use the Zimbra Collaboration Suite (ZCS) product [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1114/\" target=\"_blank\">T1114</a>]. Data LAUNDRY BEAR attempted to exfiltrate from compromised accounts included:</p>\n<ul>\n<li>Last 90 days of emails,</li>\n<li>Email address,</li>\n<li>Password [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1589/001/\" target=\"_blank\">T1589.001</a>],</li>\n<li>Global Address List (GAL) [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1087/\" target=\"_blank\">T1087</a>],</li>\n<li>Two-factor authentication (2FA) tokens, and</li>\n<li>Newly-created Application Passcode [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1098/\" target=\"_blank\">T1098</a>].</li>\n</ul>\n<p>The covert and persistent nature of this activity, along with the absence of any known financial extortion, almost certainly indicates this group\u2019s involvement in espionage activities with Russian government backing. Additionally, extensive Ukrainian targeting, prior to use against U.S. and other NATO allies, outlines an increasing trend within Russian cyber threat groups to target Ukrainian users first\u2014both as a priority target and as a testbench for malicious cyber techniques before broader global deployment.</p>\n<h2><strong>Targeting details</strong></h2>\n<p>LAUNDRY BEAR has targeted and compromised users in various organizations, including those associated with:</p>\n<ul>\n<li>the Defense Industrial Base (DIB), &nbsp;</li>\n<li>the federal and local government,</li>\n<li>education,</li>\n<li>energy,</li>\n<li>law enforcement, &nbsp;</li>\n<li>media, &nbsp;</li>\n<li>non-governmental organizations, and</li>\n<li>technology.</li>\n</ul>\n<h2><strong>Technical details</strong></h2>\n<p><strong>Note:</strong>\u202fThis advisory uses the\u202f<a href=\"https://attack.mitre.org/versions/v19/matrices/enterprise/\" target=\"_blank\">MITRE ATT&amp;CK\u00ae\u202fMatrix for Enterprise</a>\u202fframework, version 19.\u202fThis advisory also uses <a href=\"https://d3fend.mitre.org/\" target=\"_blank\">MITRE D3FEND<sup>TM</sup></a> version 1.4.0<a href=\"#f15\"><sup>15</sup></a>. See <a href=\"#appendixa\">Appendix A</a> and <a href=\"#appendixb\">Appendix B</a> for tables of the activity mapped to MITRE ATT&amp;CK and D3FEND tactics, techniques, and countermeasures.</p>\n<p><em>Ulej </em>is a novel data exfiltration and aggregation capability, that currently (as of the publication of this report) supports a campaign specifically targeting users of ZCS webmail servers. This capability is used to exploit <a href=\"https://www.cve.org/CVERecord?id=CVE-2025-66376\" target=\"_blank\">CVE-2025-66376</a> [Common Weakness Enumeration (CWE) <a href=\"https://cwe.mitre.org/data/definitions/79.html\" target=\"_blank\">CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'</a>)], but likely could be adapted to exploit other vulnerabilities. It exfiltrates emails and other sensitive user data from a victim\u2019s system immediately after exploitation and stores the data in an actor-controlled unattributable virtual private server (VPS) [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1074/002/\" target=\"_blank\">T1074.002</a>] running LAUNDRY BEAR\u2019s \u201cFlowerbed\u201d collection framework. The collected data is almost certainly further exfiltrated to internal network resources for review and long-term retention.</p>\n<h3><em><strong>Reconnaissance</strong></em></h3>\n<p>LAUNDRY BEAR uses the <em>Ulej </em>capability to exploit the <a href=\"https://www.cve.org/CVERecord?id=CVE-2025-66376\" target=\"_blank\">CVE-2025-66376</a> vulnerability in organizations using ZCS. This campaign\u2019s targeted victimology and limited exploitation capabilities likely indicate this group manually identifies and targets the victim organizations. LAUNDRY BEAR likely identifies organizations with public-facing Zimbra infrastructure by port scanning [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1595/\" target=\"_blank\">T1595</a>] and fingerprinting datasets easily procured through various commercial vendors [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1596/005/\" target=\"_blank\">T1596.005</a>]. &nbsp;</p>\n<p>After identifying a target organization, the group likely compiles email addresses for individual users to target with the exploit [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1589/002/\" target=\"_blank\">T1589.002</a>] from datasets offered by commercial vendors [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1597/002/\" target=\"_blank\">T1597.002</a>], open source intelligence [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1593/\" target=\"_blank\">T1593</a>], or previously exfiltrated data [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1597/\" target=\"_blank\">T1597</a>]. &nbsp;</p>\n<h3><em><strong>Resource development </strong></em><a class=\"ck-anchor\" id=\"resourcedev1\"></a></h3>\n<p>The actors procure VPSs from a variety of providers [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1583/003/\" target=\"_blank\">T1583.003</a>], including those with Know Your Customer (KYC) requirements, and often use fabricated identities. LAUNDRY BEAR primarily uses Mullvad VPN [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1583/\">T1583</a>] when interacting with these servers, further demonstrating the group\u2019s intent to mask their identity and maintain operations security (OPSEC). After the server is provisioned, an automated process deploys the Docker containers necessary for <em>Ulej\u2019s</em> Flowerbed framework [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1608/\">T1608</a>], which then receives and aggregates the data <em>Ulej</em> exfiltrates. These servers are typically only used for 7-60 days before moving to new infrastructure.</p>\n<h4><strong>Flowerbed framework</strong></h4>\n<p>Flowerbed is a Python project that uses Docker for containerization. The project includes four different Docker containers:</p>\n<ul>\n<li>Catcher,</li>\n<li>Certbot,</li>\n<li>Nginx, and</li>\n<li>Gardener.</li>\n</ul>\n<p>Catcher acts as both a DNS and HTTP server to receive and aggregate exfiltrated victim information [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1048/\">T1048</a>]. For additional information on Catcher, refer to the <a href=\"#exfil1\">Exfiltration</a> section of this advisory. Flowerbed\u2019s next container, Certbot, is based on one of the official Certbot containers, which allows for automated generation of Let\u2019s Encrypt certificates using DNS challenges through Cloudflare. This certificate can then be used by the Nginx container, which serves as an HTTPS reverse proxy for Catcher, enabling Flowerbed to disguise some of its exfiltration activity through an encrypted communications channel [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1048/002/\" target=\"_blank\">T1048.002</a>]. The Nginx reverse proxy also validates that the Server Name Indicator (SNI) value contains \u201c*.i.*\u201d prior to forwarding the traffic to Catcher. If the SNI does not contain that string, the Nginx server returns a 444 error to the client. This is likely an attempt to reject non-Ulej connections. Finally, the Gardener container functions as a health check for the Catcher service. Gardener is a simple Python script that validates Catcher correctly receives and processes data.</p>\n<p>The simplistic Flowerbed codebase has indications that artificial intelligence (AI) played a role in its development. This highlights how AI is increasingly being used to develop malicious capabilities [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1588/007/\" target=\"_blank\">T1588.007</a>]. The dependence on AI for a simple capability, such as Flowerbed, alongside a previous reliance on open source capabilities, such as Evilginx2 [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1588/002/\" target=\"_blank\">T1588.002</a>], likely indicates a lack of advanced technical knowledge within LAUNDRY BEAR, especially in relation to true software development capabilities.</p>\n<h3><em><strong>Initial access</strong></em></h3>\n<p>To gain initial access, LAUNDRY BEAR sends an email containing a malicious JavaScript payload to the target [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1566/\" target=\"_blank\">T1566</a>]. Through exploitation of <a href=\"https://www.cve.org/CVERecord?id=CVE-2025-66376\" target=\"_blank\">CVE-2025-66376</a>, this JavaScript payload is immediately executed once the user views the malicious email [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1203/\" target=\"_blank\">T1203</a>], such as the one shown in <a href=\"#figure1\"><strong>Figure 1</strong></a>, in the ZCS webmail platform. Since at least November 2025, LAUNDRY BEAR began sending these phishing emails from victim infrastructure through compromised accounts [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1199/\" target=\"_blank\">T1199</a>], as shown in the email metadata in <a href=\"#figure2\"><strong>Figure 2</strong></a>. These compromised accounts were likely previous victims of this, or another LAUNDRY BEAR, campaign and their use is intended to further obfuscate and frustrate anti-phishing tools and training.</p>\n<p><a class=\"ck-anchor\" id=\"figure1\"></a></p>\n\n\n\n<figure class=\"c-figure c-figure--image\" role=\"group\">\n  \n  <div class=\"c-figure__media\">    <img loading=\"lazy\" src=\"/sites/default/files/styles/large/public/2026-07/figure1.png?itok=yrzcl7tK\" width=\"604\" height=\"235\" alt=\"Figure 1: Example of malicious email\">\n\n\n\n</div>\n      <figcaption class=\"c-figure__caption\"><em><strong>Figure 1: Example of malicious email</strong></em></figcaption>\n  </figure>\n<p><a class=\"ck-anchor\" id=\"figure2\"></a></p>\n\n\n\n<figure class=\"c-figure c-figure--image\" role=\"group\">\n  \n  <div class=\"c-figure__media\">    <img loading=\"lazy\" src=\"/sites/default/files/styles/large/public/2026-07/figure2.png?itok=vEulmmyx\" width=\"604\" height=\"102\" alt=\"Figure 2: Headers from an example malicious email\">\n\n\n\n</div>\n      <figcaption class=\"c-figure__caption\"><em><strong>Figure 2: Headers from an example malicious email</strong></em></figcaption>\n  </figure>\n<p>According to the National Vulnerability Database (NVD), <a href=\"https://nvd.nist.gov/vuln/detail/CVE-2025-66376\" target=\"_blank\">CVE-2025-66376</a> was initially published on 5 January 2026. This vulnerability allows for execution of a JavaScript payload included in email content due to improper sanitization of Cascading Style Sheet\u2019s (CSS) @import directives within an email [<a href=\"#wc5\">5</a>]. Because the activity attributed to this campaign began in July 2025\u2014months before Synacor released a patch and the CVE was published\u2014the payload initially exploited a zero-day vulnerability at that time [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1587/004/\" target=\"_blank\">T1587.004</a>]. &nbsp;</p>\n<p><strong>Utilization of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability.</strong></p>\n<p>Hidden in LAUNDRY BEAR\u2019s email is a Base64 encoded payload within the \u201conload\u201d field of a Scalable Vector Graphics (SVG) element [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1027/017/\" target=\"_blank\">T1027.017</a>], as shown in <a href=\"#figure3\"><strong>Figure 3</strong></a>. Leading up to the inclusion of this payload in the SVG element are various instances of @import directives, as required to leverage <a href=\"https://www.cve.org/CVERecord?id=CVE-2025-66376\">CVE-2025-66376</a>. This payload includes an XOR encrypted final script encoded in a Base64 inner payload (see <a href=\"#figure3\"><strong>Figure 3</strong></a>) [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1027/013/\" target=\"_blank\">T1027.013</a>]. The outer payload decodes and decrypts the inner payload using an XOR function and a hardcoded key and then executes the script contained within the inner payload containing the collection and exfiltration logic. By changing the key used for the XOR encryption of the inner payload or adding additional @import directives with non-functional code [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1027/010/\" target=\"_blank\">T1027.010</a>], LAUNDRY BEAR can easily generate new payloads that bypass basic threat detection signatures. This malicious payload attempts to collect and exfiltrate information in 12 asynchronous stages [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1119/\">T1119</a>]. The stages in order of appearance within the payload are as follows:</p>\n<ol>\n<li>sendStartPing,</li>\n<li>gather_email,</li>\n<li>gather_environment,</li>\n<li>gather_2fa_codes,</li>\n<li>gather_app_password,</li>\n<li>gather_device_status,</li>\n<li>gather_oauth_consumers,</li>\n<li>gather_autocomplete_password,</li>\n<li>enable_mail_protocols,</li>\n<li>gather_gal,</li>\n<li>sendArchives, and</li>\n<li>sendFinishPing.&nbsp;</li>\n</ol>\n<p><a class=\"ck-anchor\" id=\"figure3\"></a></p>\n\n\n\n<figure class=\"c-figure c-figure--image\" role=\"group\">\n  \n  <div class=\"c-figure__media\">    <img loading=\"lazy\" src=\"/sites/default/files/styles/large/public/2026-07/figure3_0.png?itok=M-bj5-nb\" width=\"607\" height=\"577\" alt=\"Figure 3: Malicious payload of example email\">\n\n\n\n</div>\n      <figcaption class=\"c-figure__caption\"><em><strong>Figure 3: Malicious payload of example email</strong></em></figcaption>\n  </figure>\n<p>Use of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1587/\" target=\"_blank\">T1587</a>].</p>\n<h3><em><strong>Persistence and credential access</strong></em><a class=\"ck-anchor\" id=\"persistence1\"></a></h3>\n<p>To establish sustained persistence into the victim\u2019s email account, the script attempts to modify account preferences and collect authentication information. Any collected credentials are later exfiltrated, as further described in the <a href=\"#exfil1\">Exfiltration</a> section below. Other campaigns attributed to LAUNDRY BEAR also demonstrated the group\u2019s ability to circumvent multi-factor authentication through session token replay [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1550/004/\" target=\"_blank\">T1550.004</a>], and the Zimbra campaign follows a similar trend.</p>\n<p>The script used in this campaign tries to discover the victim\u2019s email address during the <em>gather_email</em> stage [<a href=\"https://attack.mitre.org/techniques/T1087/\" target=\"_blank\">T1087</a>]. The script searches for this email address in two ways. First, it examines the <em>batchInfoResponse </em>variable, which an HTML script element on the webpage can define, for an email address. Even if the script finds an email address there, it also checks whether it acquired a Cross-Site Request Forgery (CSRF) token as described later in the <a href=\"#collection1\">Collection</a> section of this advisory. If so, the script uses the \u201cGetIdentitiesRequest\u201d Simple Object Access Protocol (SOAP) command under the \u201cZimbraAccount\u201d namespace to determine the victim\u2019s email address [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1185/\" target=\"_blank\">T1185</a>] and then exfiltrates it. However, if the script does not have a CSRF token or the SOAP request fails, the script exfiltrates the email value recovered from the first method instead. If both attempts fail to capture the victim\u2019s email, the script sends a JavaScript Object Notation (JSON) payload with a key of \u201cemail\u201d and value of <em>null </em>over HTTPS and does not attempt DNS exfiltration.</p>\n<p>During the <em>gather_autocomplete_password</em> stage, the script attempts to collect the victim\u2019s saved password via the autocomplete feature of the victim\u2019s password manager. The script injects two HTML div elements requesting login credentials onto the page outside of the victim\u2019s view, as shown in <a href=\"#figure4\"><strong>Figure 4</strong></a><strong> </strong>and <a href=\"#figure5\"><strong>Figure 5</strong></a>. After waiting five seconds, the script then attempts to extract the password provided automatically by the password manager from the input element shown in <a href=\"#figure4\"><strong>Figure 4</strong></a>. If there is no value in that input field, it checks the password input field shown in <a href=\"#figure5\"><strong>Figure 5</strong></a>. If neither input field contains a value, a JSON payload with a key of \u201cautocomplete_password\u201d and value of <em>null </em>is sent over HTTPS and DNS exfiltration is not attempted.</p>\n<p><a class=\"ck-anchor\" id=\"figure4\"></a></p>\n\n\n\n<figure class=\"c-figure c-figure--image\" role=\"group\">\n  \n  <div class=\"c-figure__media\">    <img loading=\"lazy\" src=\"/sites/default/files/styles/large/public/2026-07/figure4.png?itok=ZOZ8JHZC\" width=\"1024\" height=\"188\" alt=\"Figure 4: First illegitimate login HTML element\">\n\n\n\n</div>\n      <figcaption class=\"c-figure__caption\"><em><strong>Figure 4: First illegitimate login HTML element</strong></em></figcaption>\n  </figure>\n<p><a class=\"ck-anchor\" id=\"figure5\"></a></p>\n\n\n\n<figure class=\"c-figure c-figure--image\" role=\"group\">\n  \n  <div class=\"c-figure__media\">    <img loading=\"lazy\" src=\"/sites/default/files/styles/large/public/2026-07/figure5.png?itok=8xZU_GCa\" width=\"1024\" height=\"115\" alt=\"Figure 5: Second illegitimate login HTML element\">\n\n\n\n</div>\n      <figcaption class=\"c-figure__caption\"><em><strong>Figure 5: Second illegitimate login HTML element</strong></em></figcaption>\n  </figure>\n<p>LAUNDRY BEAR almost certainly relies on a mail client using the Internet Message Access Protocol (IMAP) for persistent access to the victim\u2019s mailbox. During the <em>enable_mail_protocols</em> stage, a SOAP request leveraging the \u201cModifyPrefsRequest\u201d command under the \u201cZimbraAccount\u201d namespace is sent. This request attempts to set the \u201czimbraPrefImapEnabled\u201d preference to TRUE. While the default setting for \u201czimbraPrefImapEnabled\u201d is not well documented, this action is almost certainly intended to ensure that IMAP access to the victim\u2019s mailbox is enabled.</p>\n<p>ZCS does not support 2FA for some mail clients, including IMAP. To support users who rely on IMAP clients, ZCS allows for the generation of Application Passcodes. Application Passcodes are randomly generated passwords that can be used for clients that cannot support the normal 2FA process to authenticate. During the <em>gather_app_password</em> stage, the script makes a SOAP request using the \u201cCreateAppSpecificPasswordRequest\u201d command under the \u201cZimbraAccount\u201d namespace to create a new Application Passcode [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1556/006/\" target=\"_blank\">T1556.006</a>]. The SOAP request uses \u201cZimbraWeb\u201d as the name of the application.</p>\n<p>Additionally, the script also attempts to collect 2FA tokens. During the <em>gather_2fa_codes</em> stage, the script makes a SOAP request using the \u201cGetScratchCodesRequest\u201d command under the \u201cZimbraAccount\u201d namespace. The script then attempts to exfiltrate any non-null 2FA codes collected this way. The number of codes can vary, and each code is exfiltrated to Flowerbed individually.</p>\n<h3><em><strong>Collection</strong></em><a class=\"ck-anchor\" id=\"collection1\"></a></h3>\n<p>As demonstrated in the <a href=\"#persistence1\">Persistence and credential access</a> section, this script relies heavily on SOAP requests to collect victim information. To make these requests, the script aims to acquire the victim\u2019s current CSRF token, which it attempts to access within the webpage\u2019s local storage using localStorage.getItem(\"csrfToken\"). If the script is unable to acquire this CSRF token, it will be unable to make any SOAP requests. In addition to the SOAP commands documented in the <a href=\"#persistence1\">Persistence and credential access</a> section, other SOAP commands executed to collect victim information are shown in <a href=\"#table1\"><strong>Table 1</strong></a>.</p>\n<p><a class=\"ck-anchor\" id=\"table1\"></a></p>\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 1: Additional SOAP commands used</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW195872110 BCX8\">\n<div class=\"OutlineElement Ltr SCXW195872110 BCX8\">\n<p><strong>SOAP Command&nbsp;</strong></p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW195872110 BCX8\">\n<div class=\"OutlineElement Ltr SCXW195872110 BCX8\">\n<p><strong>Namespace&nbsp;</strong></p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW195872110 BCX8\">\n<div class=\"OutlineElement Ltr SCXW195872110 BCX8\">\n<p><strong>Stage&nbsp;</strong></p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW195872110 BCX8\">\n<div class=\"OutlineElement Ltr SCXW195872110 BCX8\">\n<p>GetInfoRequest&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW195872110 BCX8\">\n<div class=\"OutlineElement Ltr SCXW195872110 BCX8\">\n<p>zimbraAccount&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW195872110 BCX8\">\n<div class=\"OutlineElement Ltr SCXW195872110 BCX8\">\n<p>gather_environment&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW195872110 BCX8\">\n<div class=\"OutlineElement Ltr SCXW195872110 BCX8\">\n<p>GetDeviceStatusRequest&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW195872110 BCX8\">\n<div class=\"OutlineElement Ltr SCXW195872110 BCX8\">\n<p>zimbraSync&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW195872110 BCX8\">\n<div class=\"OutlineElement Ltr SCXW195872110 BCX8\">\n<p>gather_device_status&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW195872110 BCX8\">\n<div class=\"OutlineElement Ltr SCXW195872110 BCX8\">\n<p>GetOAuthConsumersRequest&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW195872110 BCX8\">\n<div class=\"OutlineElement Ltr SCXW195872110 BCX8\">\n<p>zimbraAccount&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW195872110 BCX8\">\n<div class=\"OutlineElement Ltr SCXW195872110 BCX8\">\n<p>gather_oauth_consumers&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW195872110 BCX8\">\n<div class=\"OutlineElement Ltr SCXW195872110 BCX8\">\n<p>SearchGalRequest&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW195872110 BCX8\">\n<div class=\"OutlineElement Ltr SCXW195872110 BCX8\">\n<p>zimbraAccount&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW195872110 BCX8\">\n<div class=\"OutlineElement Ltr SCXW195872110 BCX8\">\n<p>gather_gal&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n<p>The script attempts to collect the victim\u2019s GAL through brute force by searching for each two-character combination from a character set of \u201cabcdefghijklmnopqrstuvwxyz1234567890.-_\u201d. These queries are conducted using 20 batches of SOAP requests with 77 \u201cSearchGalRequest\u201d SOAP commands in each batch except for the last request containing only 58.</p>\n<p>During the <em>gather_environment</em> stage, the script attempts to determine which type of ZCS webmail client the victim is using. The script checks the user\u2019s current URL to determine the client type being used, checking for certain indicators (shown in <a href=\"#table2\"><strong>Table 2</strong></a>) to determine the client type. The corresponding value is then used as the payload when exfiltrating the client type.</p>\n<p><a class=\"ck-anchor\" id=\"table2\"></a></p>\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 2: ZCS webmail client types</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW28945023 BCX8\">\n<div class=\"OutlineElement Ltr SCXW28945023 BCX8\">\n<p><strong>Indicator&nbsp;</strong></p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW28945023 BCX8\">\n<div class=\"OutlineElement Ltr SCXW28945023 BCX8\">\n<p><strong>Client Type&nbsp;</strong></p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW28945023 BCX8\">\n<div class=\"OutlineElement Ltr SCXW28945023 BCX8\">\n<p><strong>Associated Value&nbsp;</strong></p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW28945023 BCX8\">\n<div class=\"OutlineElement Ltr SCXW28945023 BCX8\">\n<p>?client=advanced&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW28945023 BCX8\">\n<div class=\"OutlineElement Ltr SCXW28945023 BCX8\">\n<p>Advanced&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW28945023 BCX8\">\n<div class=\"OutlineElement Ltr SCXW28945023 BCX8\">\n<p>c&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW28945023 BCX8\">\n<div class=\"OutlineElement Ltr SCXW28945023 BCX8\">\n<p>/h/&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW28945023 BCX8\">\n<div class=\"OutlineElement Ltr SCXW28945023 BCX8\">\n<p>Standard&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW28945023 BCX8\">\n<div class=\"OutlineElement Ltr SCXW28945023 BCX8\">\n<p>h&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW28945023 BCX8\">\n<div class=\"OutlineElement Ltr SCXW28945023 BCX8\">\n<p>/modern/&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW28945023 BCX8\">\n<div class=\"OutlineElement Ltr SCXW28945023 BCX8\">\n<p>Modern&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW28945023 BCX8\">\n<div class=\"OutlineElement Ltr SCXW28945023 BCX8\">\n<p>m&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n<p>As part of collection, the script attempts to harvest any emails not marked as \u201cjunk\u201d from the last 90 days from the victim\u2019s account. Emails are collected daily by an HTTP GET request to the URL path, \u201c/home/~/?fmt=tgz&amp;meta=0&amp;query=date:-{DAY_OFFSET}d AND (not in:junk)\u201d. The <em>{DAY_OFFSET}</em> value would be between 0 and 89 representing how many days ago the email was sent or received. To prevent redundant collection and exfiltration of emails, a variable with a name based on the email date being queried, using a format of <em>zd_comp_YYYY-MM-DD</em>, and value of <em>true</em>, is saved to the <em>window.top.localStorage</em> property. This variable is saved regardless of whether the email is successfully exfiltrated. &nbsp;</p>\n<p>According to Mozilla documentation, if the user is not in a private browsing session, any data stored to localStorage does not typically expire. This means that if the user happens to execute the script again from the same computer, the script avoids attempting to re-exfiltrate previously captured emails. However, the script always attempts to pull any emails with a <em>{DAY_OFFSET} </em>of zero. In other words, the script always pulls emails sent or received the same day it is run. After email results are returned from the query for each day of email activity, those results are then passed to Flowerbed as described in the <a href=\"#exfil1\">Exfiltration</a> section.</p>\n<p>The script also provides LAUNDRY BEAR with telemetry on any errors that occur during the collection process. This is accomplished by executing any collection or exfiltration code through helper functions that contain error handling logic. If an error occurs, a payload containing information on the error itself, the context of the error happening, and the stage in which the error occurred is sent to Flowerbed as described in the <a href=\"#exfil1\">Exfiltration</a> section below. For cases where the error occurs within a SOAP request, \u201c:api\u201d is concatenated to the stage value in the payload. If an error occurs during the batch SOAP requests that occur when collecting the GAL of the victim, the stage value will use a format of <em>gather_gal:{VAL}:api</em>. The <em>{VAL}</em> placeholder indicates which batch request, a number from 0 to 19, the error occurred in. Errors that occur during the password autocomplete interception process will use \u201cgather_autocomplete_password:dom\u201d for the stage value. Finally, if an error occurs when attempting to collect or exfiltrate a specific day\u2019s emails, the stage will include which day the error occurred on, using the previously defined placeholder <em>{DAY_OFFSET},</em> with a format of <em>sendArchive:day-{DAY_OFFSET}</em>.</p>\n<h3><em><strong>Exfiltration</strong></em><a class=\"ck-anchor\" id=\"exfil1\"></a></h3>\n<p>At the end of each stage in the collection process, the script attempts to exfiltrate acquired information to Flowerbed. The script primarily relies on two forms of data exfiltration: DNS [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1048/003/\" target=\"_blank\">T1048.003</a>] and HTTPS. Some information is exfiltrated over both the DNS and HTTPS channels.</p>\n<p>Prior to exfiltration, a randomized 10- or 11-character alphanumeric string is generated as an identifier for the victim. This identifier is included in the URL of both the DNS- and HTTPS-based exfiltration. &nbsp;</p>\n<h4><strong>DNS exfiltration</strong></h4>\n<p>DNS exfiltration occurs through DNS A record queries. To ensure data exfiltrated through DNS is not corrupted when traversing through non-actor-controlled DNS infrastructure, <em>Ulej </em>maintains compliance with RFC 1035, Domain Names - Implementation and Specification, specifically accounting for the case insensitivity and subdomain length requirements. Base32 encoding is used to create a case-insensitive payload. Once the payload is encoded, a period (\u201c.\u201d) is added every 60 characters to ensure each subdomain is under 63 characters long. The script then creates a new image object sourced from a URL with the scheme defined in <a href=\"#figure6\"><strong>Figure 6</strong></a>. Any traffic involving DNS exfiltration will have \u201cd-\u201c prefixing the victim identifier, and the subdomain immediately following indicates the type of information being exfiltrated.</p>\n<p><a class=\"ck-anchor\" id=\"figure6\"></a></p>\n\n\n\n<figure class=\"c-figure c-figure--image\" role=\"group\">\n  \n  <div class=\"c-figure__media\">    <img loading=\"lazy\" src=\"/sites/default/files/styles/large/public/2026-07/Figure6.png?itok=Tv8RT8o8\" width=\"1024\" height=\"49\" alt=\"Figure 6: Structure for information exfiltrated by DNS\">\n\n\n\n</div>\n      <figcaption class=\"c-figure__caption\"><em><strong>Figure 6: Structure for information exfiltrated by DNS</strong></em></figcaption>\n  </figure>\n<p>When the script generates an image object, the browser tries to retrieve the complete domain of the URL specified as the source of the image. This triggers a DNS request sent to the actor-controlled server and processed by Flowerbed. <a href=\"#table3\"><strong>Table 3</strong></a> lists both the information exfiltrated via DNS and their corresponding data type identifiers in the DNS queries. &nbsp;</p>\n<p><a class=\"ck-anchor\" id=\"table3\"></a></p>\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 3: DNS exfiltration</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p><strong>Type of Information&nbsp;</strong></p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p><strong>Exfiltration Stage&nbsp;</strong></p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p><strong>Data Type&nbsp;</strong></p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p>Victim\u2019s Email Address&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p>gather_email&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p>e&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p>Client Type&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p>gather_environment&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p>c&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p>Zimbra Version&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p>gather_environment&nbsp;&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p>v&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p>URL at Time of Exploitation&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p>gather_environment&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p>url&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p>2FA Scratch Codes&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p>gather_2fa_codes&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p>2fa&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p>Newly Created Application Password&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p>gather_app_password&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p>pa&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p>Harvested Autocomplete Password&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p>gather_autocomplete_password&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW258158484 BCX8\">\n<div class=\"OutlineElement Ltr SCXW258158484 BCX8\">\n<p>pw&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n<h4><strong>HTTPS exfiltration</strong></h4>\n<p>Any information exfiltrated via DNS is also exfiltrated through HTTPS, as well as additional data including email content, contacts, attachments, and error logging information. By using Let\u2019s Encrypt certificates, this group can quickly deploy new infrastructure and leverage encrypted HTTPS communications with valid server certificates when exfiltrating information from the victim\u2019s environment. The HTTPS exfiltration capability only uses two HTTP content types, defined in <a href=\"#table4\"><strong>Table 4</strong></a>. Traffic associated with HTTPS exfiltration will use the URL scheme shown in <a href=\"#figure7\"><strong>Figure 7</strong></a>. &nbsp;</p>\n<p><a class=\"ck-anchor\" id=\"table4\"></a></p>\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 4: HTTPS exfiltration types</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW3397685 BCX8\">\n<div class=\"OutlineElement Ltr SCXW3397685 BCX8\">\n<p><strong>Content Type&nbsp;</strong></p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW3397685 BCX8\">\n<div class=\"OutlineElement Ltr SCXW3397685 BCX8\">\n<p><strong>URL Path&nbsp;</strong></p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW3397685 BCX8\">\n<div class=\"OutlineElement Ltr SCXW3397685 BCX8\">\n<p>application/json&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW3397685 BCX8\">\n<div class=\"OutlineElement Ltr SCXW3397685 BCX8\">\n<p>/v/p&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW3397685 BCX8\">\n<div class=\"OutlineElement Ltr SCXW3397685 BCX8\">\n<p>application/octet-stream&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW3397685 BCX8\">\n<div class=\"OutlineElement Ltr SCXW3397685 BCX8\">\n<p>/v/d&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n<p><a class=\"ck-anchor\" id=\"figure7\"></a></p>\n\n\n\n<figure class=\"c-figure c-figure--image\" role=\"group\">\n  \n  <div class=\"c-figure__media\">    <img loading=\"lazy\" src=\"/sites/default/files/styles/large/public/2026-07/Figure%207.png?itok=CdTcyMdN\" width=\"1024\" height=\"50\" alt=\"Figure 7: Structure for information exfiltrated by HTTPS\">\n\n\n\n</div>\n      <figcaption class=\"c-figure__caption\"><em><strong>Figure 7: Structure for information exfiltrated by HTTPS</strong></em></figcaption>\n  </figure>\n<p>Some of the data transmitted via HTTPS uses the standard JSON content type format. The script includes the information in a POST request to actor-controlled infrastructure. &nbsp;</p>\n<p><a href=\"#table5\"><strong>Table 5</strong></a> provides a summary of the JSON-based exfiltration.</p>\n<p><a class=\"ck-anchor\" id=\"table5\"></a></p>\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 5: HTTPS JSON exfiltration &nbsp;</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW25077005 BCX8\">\n<div class=\"OutlineElement Ltr SCXW25077005 BCX8\">\n<p><strong>Type of Information&nbsp;</strong></p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW25077005 BCX8\">\n<div class=\"OutlineElement Ltr SCXW25077005 BCX8\">\n<p><strong>Exfiltration Stage&nbsp;</strong></p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW25077005 BCX8\">\n<div class=\"OutlineElement Ltr SCXW25077005 BCX8\">\n<p><strong>JSON Key(s)&nbsp;</strong></p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW25077005 BCX8\">\n<div class=\"OutlineElement Ltr SCXW25077005 BCX8\">\n<p>Victim\u2019s Email Address&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW25077005 BCX8\">\n<div class=\"OutlineElement Ltr SCXW25077005 BCX8\">\n<p>gather_email&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW25077005 BCX8\">\n<div class=\"OutlineElement Ltr SCXW25077005 BCX8\">\n<p>email&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW25077005 BCX8\">\n<div class=\"OutlineElement Ltr SCXW25077005 BCX8\">\n<p>Client Type, Version, and Current URL&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW25077005 BCX8\">\n<div class=\"OutlineElement Ltr SCXW25077005 BCX8\">\n<p>gather_environment&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW25077005 BCX8\">\n<div class=\"OutlineElement Ltr SCXW25077005 BCX8\">\n<p>client, version, full_url&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW25077005 BCX8\">\n<div class=\"OutlineElement Ltr SCXW25077005 BCX8\">\n<p>Newly Created Application Password&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW25077005 BCX8\">\n<div class=\"OutlineElement Ltr SCXW25077005 BCX8\">\n<p>gather_app_password&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW25077005 BCX8\">\n<div class=\"OutlineElement Ltr SCXW25077005 BCX8\">\n<p>app_password&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW25077005 BCX8\">\n<div class=\"OutlineElement Ltr SCXW25077005 BCX8\">\n<p>Harvested Autocomplete Password&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW25077005 BCX8\">\n<div class=\"OutlineElement Ltr SCXW25077005 BCX8\">\n<p>gather_autocomplete_password&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW25077005 BCX8\">\n<div class=\"OutlineElement Ltr SCXW25077005 BCX8\">\n<p>autocomplete_password&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n<p>The script transmits all HTTPS exfiltration not identified in <a href=\"#table5\"><strong>Table 5</strong></a> using the Octet-Stream content type as binary data. The POST requests for this method include a filename in the \u201cX-Filename\u201d header. Traditionally, developers use headers prefixed with \u201cX-\u201d to denote custom headers that do not follow a defined standard. The purpose of including this header remains unclear since the Catcher capability ignores the provided filename when saving the data. <a href=\"#table6\"><strong>Table 6</strong></a> summarizes the data exfiltrated in this format.</p>\n<div class=\"OutlineElement Ltr SCXW189907655 BCX8\">\n<div class=\"TableContainer Ltr SCXW189907655 BCX8\">\n<div class=\"WACAltTextDescribedBy SCXW189907655 BCX8\"><a class=\"ck-anchor\" id=\"table6\"></a></div>\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>&nbsp;Table 6: HTTPS binary exfiltration</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW189907655 BCX8\">\n<div class=\"OutlineElement Ltr SCXW189907655 BCX8\">\n<p><strong>Type of Information&nbsp;</strong></p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW189907655 BCX8\">\n<div class=\"OutlineElement Ltr SCXW189907655 BCX8\">\n<p><strong>Exfiltration Stage&nbsp;</strong></p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW189907655 BCX8\">\n<div class=\"OutlineElement Ltr SCXW189907655 BCX8\">\n<p><strong>X-Filename Header&nbsp;</strong></p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW189907655 BCX8\">\n<div class=\"OutlineElement Ltr SCXW189907655 BCX8\">\n<p>SOAP request for GetInfoRequest&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW189907655 BCX8\">\n<div class=\"OutlineElement Ltr SCXW189907655 BCX8\">\n<p>gather_environment&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW189907655 BCX8\">\n<div class=\"OutlineElement Ltr SCXW189907655 BCX8\">\n<p>zimbra_batch_analytics.json&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW189907655 BCX8\">\n<div class=\"OutlineElement Ltr SCXW189907655 BCX8\">\n<p>SOAP request for GetScratchCodesRequest&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW189907655 BCX8\">\n<div class=\"OutlineElement Ltr SCXW189907655 BCX8\">\n<p>gather_2fa_codes&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW189907655 BCX8\">\n<div class=\"OutlineElement Ltr SCXW189907655 BCX8\">\n<p>zimbra_batch_analytics.json&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW189907655 BCX8\">\n<div class=\"OutlineElement Ltr SCXW189907655 BCX8\">\n<p>SOAP request for GetDeviceStatusRequest&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW189907655 BCX8\">\n<div class=\"OutlineElement Ltr SCXW189907655 BCX8\">\n<p>gather_device_status&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW189907655 BCX8\">\n<div class=\"OutlineElement Ltr SCXW189907655 BCX8\">\n<p>zimbra_batch_analytics.json&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW189907655 BCX8\">\n<div class=\"OutlineElement Ltr SCXW189907655 BCX8\">\n<p>SOAP request for GetOAuthConsumersRequest&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW189907655 BCX8\">\n<div class=\"OutlineElement Ltr SCXW189907655 BCX8\">\n<p>gather_oauth_consumers&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW189907655 BCX8\">\n<div class=\"OutlineElement Ltr SCXW189907655 BCX8\">\n<p>zimbra_batch_analytics.json&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW189907655 BCX8\">\n<div class=\"OutlineElement Ltr SCXW189907655 BCX8\">\n<p>Victim Organization\u2019s Global Address List&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW189907655 BCX8\">\n<div class=\"OutlineElement Ltr SCXW189907655 BCX8\">\n<p>gather_gal&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW189907655 BCX8\">\n<div class=\"OutlineElement Ltr SCXW189907655 BCX8\">\n<p>telemetry_{1-20}.json&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW189907655 BCX8\">\n<div class=\"OutlineElement Ltr SCXW189907655 BCX8\">\n<p>Last 90 Days of Victim\u2019s Emails&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW189907655 BCX8\">\n<div class=\"OutlineElement Ltr SCXW189907655 BCX8\">\n<p>sendArchives&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW189907655 BCX8\">\n<div class=\"OutlineElement Ltr SCXW189907655 BCX8\">\n<p>telemetryData_{0-89}.json&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n<p>The script sends all exfiltrated data identified in <a href=\"#table6\"><strong>Table 6</strong></a> to the Catcher service exactly as received from the SOAP request in a JSON payload, except for email exfiltration. For email exfiltration, the script sends it as a GZIP compressed archive [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1560/\" target=\"_blank\">T1560</a>]. Although most of the exfiltration consists of valid JSON, the script still attempts to exfiltrate all information identified in <a href=\"#table6\"><strong>Table 6</strong></a> using the application/octet-stream content typing rather than application/json.</p>\n<p>At the beginning and end of the collection and exfiltration activity, during the <em>sendStartPing</em> and <em>sendFinishPing </em>stages respectively, the script submits a POST request with a JSON payload to indicate that the script is starting or finishing execution. Throughout execution, the script also logs error events and send the logs using similar JSON payloads. The script sends the JSON in a POST request to the URL documented in <a href=\"#figure2\"><strong>Figure 2</strong></a>, using a URL path of \u201c/v/p\u201d and with a \u201csubtype\u201d key that shows which type of action it logged (<em>start, finish, or error</em>). &nbsp;</p>\n<h4><strong>Catcher</strong></h4>\n<p><em>Ulej </em>exfiltrates information to Flowerbed to be handled by a service named Catcher. Catcher is a containerized Python application, running in Docker as part of Flowerbed, which is detailed in the <a href=\"#resourcedev1\">Resource development</a> section. It receives exfiltrated data and temporarily stores it, enabling its eventual transfer to infrastructure designed for long-term, secure storage.</p>\n<p>Catcher acts as an HTTP server over port 8000 and a DNS server on port 53. As described in the <a href=\"#resourcedev1\">Resource development</a> section, the Flowerbed project uses an additional Docker container running an Nginx reverse proxy to enable HTTPS support. This reverse proxy uses a certificate generated by Let\u2019s Encrypt and forwards all traffic with an SNI containing \u201c*.i.*\u201d to port 8000 within the Catcher container.</p>\n<p>The DNS service can accept A, AAAA, MX, TXT, and CAA queries. For any MX, AAAA, or CAA queries, the server will always provide an empty response. The system only supports TXT records as needed to process Automatic Certificate Management Environment (ACME) requests, which enable the assignment of Let\u2019s Encrypt certificates. If the server receives an A query, Catcher will always respond with the public IP address of the Flowerbed server. &nbsp;</p>\n<p>However, if a query includes a domain formatted as shown in <a href=\"#figure6\"><strong>Figure 6</strong></a> and <a href=\"#figure7\"><strong>Figure 7</strong></a>, the service saves a log file in JSON format to disk containing the following details of the DNS query:</p>\n<ul>\n<li>Time of query,</li>\n<li>Source IP address for query,</li>\n<li>Queried domain, and</li>\n<li>Type of query.</li>\n</ul>\n<p>The HTTP server typically responds with OK, except in cases where the path is \u201cpixel.gif\u201d when the response contains a 1x1 gif image with a SHA-256 hash of ef1955ae757c8b966c83248350331bd3a30f658ced11f387f8ebf05ab3368629. Like the DNS service, the HTTP service will only log entries when the domain found in the host header of the request follows the expected formatting as seen in <a href=\"#figure6\"><strong>Figure 6</strong></a> and <a href=\"#figure7\"><strong>Figure 7</strong></a>. As the HTTPS exfiltration uses non-standardized binary and JSON-formatted payloads when exfiltrating to Catcher, Catcher will check the content type of the request. If the content type is set to \u201capplication/json\u201d, Catcher encodes the data in Base64 and includes it in the JSON log entry written to disk. If the content type is set to any other value, Catcher leaves the Base64 payload in the JSON log entry blank and saves the payload to a separate file with the same filename as the JSON log entry with a \u201c.bin\u201d file extension. An HTTPS exfiltration event causes Catcher to save a JSON formatted log file to disk containing the following information from the HTTP request:</p>\n<ul>\n<li>Time,</li>\n<li>Source IP address,</li>\n<li>Request method,</li>\n<li>Host,</li>\n<li>Path,</li>\n<li>Query string,</li>\n<li>Headers, and</li>\n<li>Base64 payload.</li>\n</ul>\n<p>These JSON event log files and binary output files are then initially saved to the directory <em>/root/hits/tmp</em> and later moved to the <em>/root/hits/ready</em> directory once processed. This prevents incomplete files, which are still being uploaded to Catcher, from premature exfiltration from the server. Approximately every 60 seconds, a likely automated workflow establishes a Secure Shell (SSH) connection with the server hosting Flowerbed for a few seconds, almost certainly exfiltrating the data processed by Catcher to non-public-facing infrastructure. The command in <a href=\"#figure8\"><strong>Figure 8</strong></a> also executes hourly to remove all files last modified at least two days ago from the <em>/root/hits/ready</em> directory.</p>\n<p><a class=\"ck-anchor\" id=\"figure8\"></a></p>\n\n\n\n<figure class=\"c-figure c-figure--image\" role=\"group\">\n  \n  <div class=\"c-figure__media\">    <img loading=\"lazy\" src=\"/sites/default/files/styles/large/public/2026-07/Figure%208-Command%20used%20for%20automated%20directory%20cleanup.png?itok=IqvZvbLK\" width=\"1024\" height=\"92\" alt=\"Figure 8: Command used for automated directory cleanup\">\n\n\n\n</div>\n      <figcaption class=\"c-figure__caption\"><em><strong>Figure 8: Command used for automated directory cleanup</strong></em></figcaption>\n  </figure>\n<h2><strong>Response strategies</strong></h2>\n<h3><em><strong>Mitigations</strong></em><a class=\"ck-anchor\" id=\"mitigations1\"></a></h3>\n<p>In many cases, by the time an organization identifies a compromise related to this campaign, numerous sensitive and proprietary emails have already been exfiltrated. The significant risk posed by this cyber threat emphasizes the importance for organizations that use ZCS and other similar webmail solutions to take proactive steps to mitigate this risk.</p>\n<p>All organizations that use the ZCS webmail service should <strong>immediately prioritize</strong> ensuring that their ZCS is not running a vulnerable version. A patch for <a href=\"https://www.cve.org/CVERecord?id=CVE-2025-66376\" target=\"_blank\">CVE-2025-66376</a> was released for both 10.1.13 and 10.0.18 versions of ZCS [<a href=\"https://d3fend.mitre.org/technique/d3f:ApplicationHardening\">D3-AH</a>]. If immediate patching is not feasible, organizations should advise employees to use alternative mail clients to access email and avoid using the Classic ZCS webmail client until ZCS is updated to a non-vulnerable version [<a href=\"https://d3fend.mitre.org/tactic/d3f:Isolate/\" target=\"_blank\">d3f:Isolate</a>].</p>\n<p>System administrators should closely monitor any Internet-connected ZCS or other email systems and the workstations that access those systems and promptly apply available software updates [<a href=\"https://d3fend.mitre.org/technique/d3f:ApplicationHardening\" target=\"_blank\">D3-AH</a>]. Administrators can maintain awareness of active vulnerability exploitation by referencing open source resources, including <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">CISA\u2019s Known Exploited Vulnerabilities Catalog</a> and <a href=\"https://www.ncsc.gov.uk/collection/vulnerability-management/guidance/responding-to-active-exploitation\" target=\"_blank\">NCSC-UK\u2019s Responding to active exploitation of vulnerabilities</a> guidance.</p>\n<p>Organizations should consider using a third-party authentication service that supports passkeys for authentication to mediate access to ZCS and other services that do not natively support passkeys. By doing so, organizations can work to eliminate the possibility of automated password collection from autocomplete or password reuse [<a href=\"https://d3fend.mitre.org/technique/d3f:CredentialHardening\" target=\"_blank\">D3-CH</a>]. However, Application Passcodes may still be necessary and should be monitored closely. &nbsp;</p>\n<p>Organizations should implement network monitoring capabilities with collection and short-term retention of packet capture or NetFlow data and maintain log collection and storage [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#MaintainLogCollectionStorage3Q\">CPG 3.Q</a>]. This will allow organizations to monitor for and identify suspicious network activity [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#IdentifyAdverseEvents4B\">CPG 4.B</a>], such as:</p>\n<ul>\n<li>Significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization [<a href=\"https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis\" target=\"_blank\">D3-NTA</a>];</li>\n<li>Frequent DNS queries for a suspicious domain with seemingly random subdomains [<a href=\"https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis\" target=\"_blank\">D3-DNSTA</a>];</li>\n<li>A sudden spike of connections to a server associated with a recently established domain [<a href=\"https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation\">D3-NTCD</a>]; and &nbsp;</li>\n<li>Connections to internal services, such as webmail, from VPN providers frequently leveraged by this group for nefarious activity, such as Mullvad VPN [<a href=\"https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation\">D3-NTCD</a>].</li>\n</ul>\n<p>Additionally, for organizations that can inspect the content of outbound HTTPS connections via break-and-inspect infrastructure, security teams should identify traffic matching the characteristics described in the <a href=\"#exfil1\">Exfiltration</a> section of this advisory.</p>\n<h3><em><strong>Indicators of compromise (IOCs)</strong></em><a class=\"ck-anchor\" id=\"ioc1\"></a></h3>\n<h4><strong>Flowerbed infrastructure</strong></h4>\n<p>The following indicators have been attributed to use by LAUNDRY BEAR for their campaign targeting ZCS\u2019s webmail service as of the publication of this advisory. (<strong>Disclaimer: </strong>Due to the frequency of operational structure changes by this group, these indicators are intended solely for historic attribution purposes. Some indicators, such as IPs, compromised emails, and domains, may be outdated, so organizations should check for current activity before acting on these IOCs.) <a href=\"#table7\"><strong>Table 7</strong></a> provides details about the server infrastructure used to host Flowerbed, and <a href=\"#table8\"><strong>Table 8</strong></a> lists the corresponding SHA-1 hash values for the Let\u2019s Encrypt certificates used by that infrastructure [<a href=\"https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis\" target=\"_blank\">D3-IAA</a>].</p>\n<p><a class=\"ck-anchor\" id=\"table7\"></a></p>\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 7: Flowerbed server infrastructure</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p><strong>Domain&nbsp;</strong></p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p><strong>IP Address&nbsp;</strong></p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p><strong>First Seen&nbsp;</strong></p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p><strong>Last Seen&nbsp;</strong></p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>zmailanalytics[.]com&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>216.252.238[.]104&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>8 July 2025&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>15 October 2025&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>zimbra-metadata[.]com&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>216.252.238[.]18&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>20 August 2025&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>14 October 2025&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>analyticemailmeter[.]com&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>37.120.247[.]228&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>24 September 2025&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>18 March 2026&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>emailanalytics.com[.]ua&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>185.86.79[.]95&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>24 September 2025&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>18 March 2026&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>mailnalysis[.]com&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>104.248.134[.]194&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>11 November 2025&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>17 February 2026&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>zimbrastat[.]com&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>64.226.124[.]190&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>18 December 2025&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>18 March 2026&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>zimbrasoft.com[.]ua&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>193.238.152[.]66&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>20 January 2026&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>18 March 2026&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>synacorzimbra[.]nl&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>216.252.238[.]64&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>3 February 2026&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>30 March 2026&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>istc-cloud[.]com&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>194.156.103[.]193&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>5 February 2026&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW193774983 BCX8\">\n<div class=\"OutlineElement Ltr SCXW193774983 BCX8\">\n<p>30 March 2026&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n<p><a class=\"ck-anchor\" id=\"table8\"></a></p>\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 8: Flowerbed X.509 certificate SHA-1 hashes &nbsp;</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p><strong>Associated Domain&nbsp;</strong></p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p><strong>X.509 SHA-1 Hash&nbsp;</strong></p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p><strong>First Seen&nbsp;</strong></p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p><strong>Last Seen&nbsp;</strong></p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>zmailanalytics[.]com&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>2e4f314bc9943cab5005d6fde0b271c74d47bc9d&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>8 Jul 2025&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>6 Aug 2025&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>*.i.zmailanalytics[.]com&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>50a87d926621dd06389ba50d86e0ff574ed713a8&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>6 Aug 2025&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>13 Oct 2025&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>*.i.zimbra-metadata[.]com&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>c5a72420e7bb308d078e62128430897f82194c95&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>20 Aug 2025&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>14 Oct 2025&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>*.i.analyticemailmeter[.]com&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>8959c4d29e29f02ea94ea8bb21c8df2594c5549d&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>24 Sep 2025&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>8 Nov 2025&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>*.i.emailanalytics.com[.]ua&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>62eb76432597694edb01c1fe57aab0cfe03a7178&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>25 Sep 2025&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>27 Sep 2025&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>*.i.mailnalysis[.]com&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>cddf5c3be1e07f28140aed165b929bf2d614922a&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>12 Nov 2025&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>17 Dec 2025&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>*.i.zimbrastat[.]com&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>18b3ad442ce73cc8656d51d75bbd7c855f2cb7e8&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>18 Dec 2025&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>28 Dec 2025&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>*.i.zimbrasoft.com[.]ua&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>1b25041ececf2457eef0270fc1d785cec8ec9ded&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>21 Jan 2026&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>10 Feb 2026&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>*.i.synacorzimbra[.]nl&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>e4fe6466a4f9a4249fe330651e914e45bbdca44a&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>5 Feb 2026&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>22 Mar 2026&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>*.i.istc-cloud[.]com&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>b6b77c9a455225d525834a403ca9ef5481ed0447&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>12 Feb 2026&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW66173475 BCX8\">\n<div class=\"OutlineElement Ltr SCXW66173475 BCX8\">\n<p>30 Mar 2026&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n<p>LAUNDRY BEAR has used the following email addresses to procure resources used for this campaign:</p>\n<ul>\n<li>ivanka.zurabishvili@proton[.]me,</li>\n<li>zmul1@buildandconsulting[.]com,</li>\n<li>garrysmithme@pinmx[.]net, and</li>\n<li>hostingclient@pinmx[.]net.</li>\n</ul>\n<h4><strong>Phishing distribution</strong></h4>\n<p>LAUNDRY BEAR primarily relied on ProtonMail for distribution of malicious email. However, as stated above, LAUNDRY BEAR\u2019s more recent efforts likely have shifted to distributing the payload through previous victims. &nbsp;</p>\n<p>The following email addresses have distributed payloads attributed to this campaign:</p>\n<ul>\n<li>c.laurent.ejfa@proton[.]me,</li>\n<li>j.moreau.epsc@proton[.]me,</li>\n<li>liberty.insights@proton[.]me,</li>\n<li>certain email addresses (presumably compromised) at the isofts.kiev[.]ua domain (i.e., ending with @isofts.kiev[.]ua), and</li>\n<li>certain email addresses (presumably compromised) at the navs.edu[.]ua domain (i.e., ending with @navs.edu[.]ua).</li>\n</ul>\n<p>Additionally, the following are SHA-256 hashes of email samples containing the malicious payload attributed to this campaign:</p>\n<ul>\n<li>98df604ecc57f884a2e6ce3266a0013ad64455cac48442c2312cfa4765007aaf,</li>\n<li>60db9abae75cd8ccc49dd7ea5feb41677566dcd442f12ebc5745ffd2810fb874,</li>\n<li>b1f5beb1175fc5c7d1806a2f0d900eb124c54f0286c5c52b66eea7a6633adb1d, and</li>\n<li>1517b3caa495f6c4e832df9c75fc94667e3c233773f7fa4e056d5e30e5ead760.</li>\n</ul>\n<h4><strong>Post-compromise artifacts</strong></h4>\n<p>Currently, the script does not remove artifacts. This leaves additional opportunities to identify victims of this activity. While emphasis should always be placed on consistent monitoring of network traffic and endpoint activity, there are a variety of persistent artifacts described below that can be used to identify victims of this campaign.</p>\n<p>This <em>Ulej </em>capability relies on creating a significant number of SOAP requests to collect account information for exfiltration. ZCS logs from these requests are stored, by default, in the <em>/opt/zimbra/log/mailbox.log</em> file [<a href=\"https://d3fend.mitre.org/technique/d3f:ProcessAnalysis\" target=\"_blank\">D3-PA</a>]. A significant amount of SOAP request activity that aligns with what was described in the <a href=\"#persistence1\">Persistence and credential access</a> and <a href=\"#collection1\">Collection</a> sections of this advisory could indicate a potential compromise. Specific examples of high-risk SOAP request activity might include:</p>\n<ul>\n<li>Many <em>SearchGalRequest </em>command requests from a single user over a short period of time;</li>\n<li>Use of the <em>CreateAppSpecificPasswordRequest</em> command, especially in cases where it is creating an Application Passcode named \u201cZimbraWeb\u201d; and</li>\n<li>Use of the GetScratchCodesRequest command.</li>\n</ul>\n<p>While LAUNDRY BEAR uses the localStorage property to track what days had emails previously exfiltrated, defenders can use this property to identify victims of this campaign and determine the scope of exfiltrated information [<a href=\"https://d3fend.mitre.org/technique/d3f:ProcessAnalysis\" target=\"_blank\">D3-PA</a>]. Review of the items stored in that property for an organization\u2019s ZCS webmail client page on an endpoint device could indicate compromise if there are items named with a format of <em>zd_comp_YYYY-MM-DD,</em> as explained in the <a href=\"#collection1\">Collection</a> section of this advisory.</p>\n<p>While Application Passcodes have non-malicious purposes, in this case instances of these passcodes with the name \u201cZimbraWeb\u201d are almost certainly malicious. The ZCS webmail application can support 2FA natively and does not require the use of an Application Passcode, so there is no reason that there should be one named \u201cZimbraWeb.\u201d</p>\n<p>In instances where organizations identify victims of this campaign, they should also examine the inbox of the suspected victim for the original phishing email [<a href=\"https://d3fend.mitre.org/technique/d3f:MessageAnalysis\" target=\"_blank\">D3-MA</a>]. If an email that has a payload exploiting <a href=\"https://www.cve.org/CVERecord?id=CVE-2025-66376\">CVE-2025-66376</a> is discovered, <strong>steps should be taken immediately to identify and quarantine other instances of emails with similar body content, senders, and subject lines to prevent further exploitation and exfiltration. &nbsp;</strong></p>\n<h3><em><strong>Remediation</strong></em></h3>\n<p>In the event an organization identifies activity associated with this campaign, that organization should take steps to minimize further exploitation. The organization should consider requesting that employees minimize use of the ZCS webmail client until the organization updates to a patched version that is not vulnerable to <a href=\"https://www.cve.org/CVERecord?id=CVE-2025-66376\" target=\"_blank\">CVE-2025-66376</a>.</p>\n<p>Organizations should use identifiers from the <a href=\"#ioc1\">IOCs</a> section of this report to identify any individuals compromised by this campaign and record the date(s) of compromise(s) to determine the scale and scope of emails exfiltrated.</p>\n<p>All users from the organization should have all Application Passcodes and 2FA scratch keys revoked. Affected organizations should require all employees to change passwords in line with establishing minimum password strength requirements [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#EstablishMinimumPasswordStrength3B\">CPG 3.B</a>] and creating unique credentials [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#CreateUniqueCredentials3C\">CPG 3.C</a>], specifically noting that compromised employees might have had any password stored in a password manager exfiltrated.</p>\n<h2><strong>Works cited</strong></h2>\n<p>[1<a class=\"ck-anchor\" id=\"wc1\"></a>] Netherlands General Intelligence and Security Service (AIVD) and Netherlands Defence Intelligence and Security Service (MIVD). AIVD and MIVD identify a new Russian cyber threat actor. 2025. <a href=\"https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf\" target=\"_blank\">https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf</a></p>\n<p>[2]<a class=\"ck-anchor\" id=\"wc2\"></a> Microsoft Corporation. New Russia-affiliated actor Void Blizzard targets critical sectors for espionage. 2025. <a href=\"https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/\" target=\"_blank\">https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/</a></p>\n<p>[3]<a class=\"ck-anchor\" id=\"wc3\"></a> Palo Alto Networks Unit 42. Russian Global Webmail Espionage. 2026. <a href=\"https://unit42.paloaltonetworks.com/russian-webmail-espionage/\">https://unit42.paloaltonetworks.com/russian-webmail-espionage/&nbsp;</a></p>\n<p>[4]<a class=\"ck-anchor\" id=\"wc4\"></a> Proofpoint. TA488 Targets Zimbra Mailservers with Half-Click Exploits. 2026. <a href=\"https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit\">https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit</a></p>\n<p>[5]<a class=\"ck-anchor\" id=\"wc5\"></a> Seqrite. Operation GhostMail: Russian APT exploits Zimbra Webmail to Target Ukraine State Agency. 2026. <a href=\"https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/\" target=\"_blank\">https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/ &nbsp;</a></p>\n<h2><strong>Footnotes</strong></h2>\n<p><sup>1</sup><a class=\"ck-anchor\" id=\"f1\"></a> N\u00e1rodn\u00ed \u00fa\u0159ad pro kybernetickou a informa\u010dn\u00ed bezpe\u010dnost<br><sup>2</sup><a class=\"ck-anchor\" id=\"f2\"></a><sup> </sup>Forsvarets Efterretningstjeneste<br><sup>3</sup><a class=\"ck-anchor\" id=\"f3\"></a><sup> </sup>V\u00e4lisluureamet<br><sup>4</sup><a class=\"ck-anchor\" id=\"f4\"></a> Sotilastiedustelu<br><sup>5</sup><a class=\"ck-anchor\" id=\"f5\"></a><sup>&nbsp;</sup> Suojelupoliisi<br><sup>6</sup><a class=\"ck-anchor\" id=\"f6\"></a> Direction g\u00e9n\u00e9rale de la s\u00e9curit\u00e9 int\u00e9rieure<br><sup>7</sup><a class=\"ck-anchor\" id=\"f7\"></a> Agence nationale de la s\u00e9curit\u00e9 des syst\u00e8mes d\u2019information<br><sup>8</sup><a class=\"ck-anchor\" id=\"f8\"></a> Agenzia Informazioni e Sicurezza Esterna<br><sup>9</sup><a class=\"ck-anchor\" id=\"f9\"></a> Agenzia Informazioni e Sicurezza Interna<br><sup>10</sup><a class=\"ck-anchor\" id=\"f10\"></a> Serviciul de Informa\u021bii \u0219i Securitate al Republicii Moldova<br><sup>11 </sup><a class=\"ck-anchor\" id=\"f11\"></a>Agencja Wywiadu<br><sup>12</sup><a class=\"ck-anchor\" id=\"f12\"></a><sup> </sup>S\u0142u\u017cba Kontrwywiadu Wojskowego<br><sup>13</sup><a class=\"ck-anchor\" id=\"f13\"></a><sup> </sup>Centro Nacional de Inteligencia<br><sup>14 </sup><a class=\"ck-anchor\" id=\"f14\"></a>Nationellt Cybers\u00e4kerhetscenter<br><sup>15</sup><a class=\"ck-anchor\" id=\"f15\"></a> MITRE and ATT&amp;CK are registered trademarks of The MITRE Corporation. MITRE D3FEND is a trademark of The MITRE Corporation.</p>\n<h2><strong>Acknowledgements</strong></h2>\n<p>The authoring agencies acknowledge the contributions to this advisory from Palo Alto Networks Unit 42 and Proofpoint.</p>\n<h2><strong>Disclaimer of endorsement</strong></h2>\n<p>The information and opinions contained in this document are provided \"as is\" and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes.</p>\n<p>Organizations have no obligation to respond or provide information back to the authoring organizations in response to this joint advisory. If, after reviewing the information provided, an organization decides to provide information to the authoring organizations, reporting must be consistent with all applicable laws and policies.</p>\n<h2><strong>Purpose</strong></h2>\n<p>This document was developed in furtherance of the authoring agencies\u2019 cybersecurity missions, including their responsibilities to identify and disseminate threats, and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.</p>\n<h2><strong>Contact</strong></h2>\n<div class=\"SCXW95230887 BCX8\">\n<div class=\"OutlineElement Ltr SCXW95230887 BCX8\">\n<p><strong>United States organizations&nbsp;</strong></p>\n<ul>\n<li><strong>National Security Agency</strong>&nbsp;<br>Cybersecurity Report Feedback: <a href=\"mailto:CybersecurityReports@nsa.gov\" target=\"_blank\"><u>CybersecurityReports@nsa.gov</u></a>&nbsp;<br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href=\"mailto:DIB_Defense@cyber.nsa.gov\" target=\"_blank\"><u>DIB_Defense@cyber.nsa.gov</u></a>&nbsp;<br>Media Inquiries / Press Desk: NSA Media Relations: 443-634-0721, <a href=\"mailto:MediaRelations@nsa.gov\" target=\"_blank\"><u>MediaRelations@nsa.gov</u></a>&nbsp;</li>\n<li><strong>Cybersecurity and Infrastructure Security Agency</strong>&nbsp;<br>CISA\u2019s 24/7 Operations Center (<a href=\"mailto:contact@cisa.dhs.gov\" target=\"_blank\"><u>contact@cisa.dhs.gov</u></a>), or by calling 1-844-Say-CISA (1-844-729-2472).&nbsp;</li>\n<li><strong>Federal Bureau of Investigation</strong>&nbsp;<br>If you or someone you know has fallen victim to this campaign, file a complaint with <a class=\"Hyperlink SCXW95230887 BCX8\" href=\"https://www.ic3.gov/\" target=\"_blank\" rel=\"noreferrer noopener\"><u>IC3</u></a>.&nbsp;</li>\n<li><strong>Defense Counterintelligence and Security Agency&nbsp;</strong>&nbsp;<br>DCSA Counterintelligence, Cyber Mission Center, Cyber Threat Operations Branch: <a href=\"mailto:DCSA.CI.CyberOps@mail.mil\" target=\"_blank\"><u>DCSA.CI.CyberOps@mail.mil</u></a>&nbsp;<br>Cleared Contactors (CCs) should contact their DCSA Counterintelligence Special Agent to report information pertaining to suspicious contacts or physical/digital efforts to obtain illegal or unauthorized access to the CC\u2019s cleared facility/information, as required by 32 CFR 117.&nbsp;<br>Media/Public Inquiries: <a href=\"mailto:dcsa.quantico.dcsa-hq.mbx.pa@mail.mil\" target=\"_blank\"><u>dcsa.quantico.dcsa-hq.mbx.pa@mail.mil</u></a>&nbsp;&nbsp;</li>\n<li><strong>Department of Defense Cyber Crime Center&nbsp;</strong>&nbsp;<br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href=\"mailto:DC3.DCISE@us.af.mil\" target=\"_blank\"><u>DC3.DCISE@us.af.mil</u></a>&nbsp;<br>Defense Industrial Base mandatory cyber incident reporting as required by 10 U.S. Code Sections 391 and 393 and Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 is submitted at <a href=\"https://dibnet.dod.mil/\" target=\"_blank\"><u>https://dibnet.dod.mil</u></a>&nbsp;<br>Media Inquiries / Press Desk: <a href=\"mailto:DC3.Information@us.af.mil\" target=\"_blank\"><u>DC3.Information@us.af.mil</u></a>&nbsp;</li>\n<li><strong>Naval Criminal Investigative Service</strong>&nbsp;<br>To report criminal activity impacting the United States Navy, go to <a href=\"http://www.ncis.navy.mil/\" target=\"_blank\"><u>www.ncis.navy.mil</u></a> and click \u201cSubmit a Tip\u201d</li>\n</ul>\n<p><strong>Dutch organizations</strong>&nbsp;</p>\n<ul>\n<li>Defence Intelligence and Security Service (MIVD): <a href=\"https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid\" target=\"_blank\"><u>https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid</u></a>&nbsp;&nbsp;</li>\n<li>General Intelligence and Security Service (AIVD): <a href=\"https://www.aivd.nl/\" target=\"_blank\"><u>https://www.aivd.nl</u></a>&nbsp;</li>\n</ul>\n<p><strong>Australian organizations&nbsp;</strong></p>\n<ul>\n<li>Australian Signals Directorate&nbsp;<br>Visit <a href=\"https://www.cyber.gov.au/about-us/about-asd-acsc/contact-us#no-back\" target=\"_blank\"><u>cyber.gov.au</u></a> or call 1300 292 371 (1300 CYBER 1) to report cybersecurity incidents and access alerts and advisories.&nbsp;</li>\n</ul>\n<p><strong>Canadian organizations&nbsp;</strong></p>\n<ul>\n<li>The Canadian Centre for Cyber Security (Cyber Centre), part of the Communications Security Establishment, encourages Canadian organizations to report cyber incidents and to strengthen the security of their networking devices. &nbsp;<br>Report an incident or suspicious activity to the Cyber Centre by email at <a href=\"mailto:contact@cyber.gc.ca\" target=\"_blank\"><u>contact@cyber.gc.ca</u></a>, online via the reporting tool <a href=\"https://www.cyber.gc.ca/en/incident-management\" target=\"_blank\"><u>Report a cyber incident - Canadian Centre for Cyber Security</u></a> or by phone at 1-833-CYBER-88 (1-833-292-3788).&nbsp;</li>\n</ul>\n<p><strong>New Zealand organizations&nbsp;</strong></p>\n<ul>\n<li>New Zealand National Cyber Security Centre (NCSC-NZ): <a href=\"mailto:info@ncsc.govt.nz\" target=\"_blank\"><u>info@ncsc.govt.nz</u></a>&nbsp;</li>\n</ul>\n<p><strong>United Kingdom organizations&nbsp;</strong></p>\n<ul>\n<li>Report significant cyber security incidents to <a href=\"https://ncsc.gov.uk/report-an-incident\" target=\"_blank\"><u>ncsc.gov.uk/report-an-incident</u></a> (monitored 24/7)&nbsp;</li>\n</ul>\n<p><strong>Estonia organizations&nbsp;</strong></p>\n<ul>\n<li>Estonian Foreign Intelligence Service (EFIS): <a href=\"mailto:info@valisluureamet.ee\" target=\"_blank\"><u>info@valisluureamet.ee</u></a>&nbsp;</li>\n</ul>\n<p><strong>Finnish organizations&nbsp;</strong></p>\n<ul>\n<li>Finnish Security and Intelligence Service: <a href=\"https://supo.fi/en/contact\" target=\"_blank\"><u>supo.fi/en/contact</u></a>&nbsp;</li>\n</ul>\n<p><strong>French organizations&nbsp;</strong></p>\n<ul>\n<li>French organizations are encouraged to report suspicious activity or incident related information found in this advisory by contacting ANSSI/CERT-FR at: <a href=\"mailto:cert-fr@ssi.gouv.fr\" target=\"_blank\"><u>cert-fr@ssi.gouv.fr</u></a> or by phone at: 3218 or +33 9 70 83 32 18.&nbsp;</li>\n</ul>\n<p><strong>Italian Organizations&nbsp;</strong></p>\n<ul>\n<li>Italian External Intelligence and Security Agency (AISE):&nbsp;&nbsp;<br>Visit <a href=\"https://www.sicurezzanazionale.gov.it/\" target=\"_blank\"><u>https://www.sicurezzanazionale.gov.it/</u></a>&nbsp;&nbsp;</li>\n<li>Italian Internal Intelligence and Security Agency (AISI):&nbsp;&nbsp;<br>Visit <a href=\"https://www.sicurezzanazionale.gov.it/\" target=\"_blank\"><u>https://www.sicurezzanazionale.gov.it/</u></a>&nbsp;</li>\n</ul>\n<div class=\"OutlineElement Ltr SCXW214395380 BCX8\">\n<p><strong>Moldovan organizations&nbsp;</strong></p>\n</div>\n<div class=\"ListContainerWrapper SCXW214395380 BCX8\">\n<ul type=\"disc\">\n<li>Security and Intelligence Service of the Republic of Moldova (SIS RM): <a href=\"mailto:cybersec@sis.md\" target=\"_blank\"><u>cybersec@sis.md</u></a>&nbsp;</li>\n</ul>\n</div>\n<p><strong>Polish organizations&nbsp;</strong></p>\n<ul>\n<li>Polish Foreign Intelligence Agency (AW): <a href=\"mailto:ctiteam@aw.gov.pl\" target=\"_blank\"><u>ctiteam@aw.gov.pl</u></a></li>\n</ul>\n</div>\n</div>\n<h2><strong>Appendix A: MITRE ATT&amp;CK tactics and techniques</strong><a class=\"ck-anchor\" id=\"appendixa\"></a></h2>\n<p>See <a href=\"#table9\"><strong>Table 9</strong></a> through <a href=\"#table19\"><strong>Table 19</strong></a> for all the threat actor tactics and techniques referenced in this advisory.<a class=\"ck-anchor\" id=\"table9\"></a></p>\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<div class=\"TableContainer Ltr SCXW76044448 BCX8\">\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 9: Reconnaissance&nbsp;</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>Technique Title</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>ID</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>Use</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Gather Victim Identity Information: Credentials&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1589/001/\" target=\"_blank\"><u>T1589.001</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>The payload attempts to intercept a victim\u2019s password from their password manager.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Gather Victim Identity Information: Email Addresses&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1589/002/\" target=\"_blank\"><u>T1589.002</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>The payload attempts to grab the victim\u2019s email address from various data stores.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Search Open Websites/Domains&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1593/\" target=\"_blank\"><u>T1593</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>This group likely leverages public information to support target development.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Active Scanning&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1595/\" target=\"_blank\"><u>T1595</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Port scanning can be used by this group to assist with determining exploitability of identified targets.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Search Open Technical Databases: Scan Databases&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1596/005/\" target=\"_blank\"><u>T1596.005</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Various public datasets can provide information to support discovery of exploitable targets.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Search Closed Sources&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1597/\" target=\"_blank\"><u>T1597</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Previously exfiltrated data can be used to enhance target development efforts.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Search Closed Sources: Purchase Technical Data&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1597/002/\" target=\"_blank\"><u>T1597.002</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Commercial datasets can also be used to support target development efforts.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<div class=\"TableContainer Ltr SCXW76044448 BCX8\">\n<div class=\"WACAltTextDescribedBy SCXW76044448 BCX8\"><a class=\"ck-anchor\" id=\"table10\"></a></div>\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 10: Resource Development&nbsp;</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>Technique Title</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>ID</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>Use</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Acquire Infrastructure&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1583/\" target=\"_blank\"><u>T1583</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>This group used Mullvad VPN to anonymize traffic sent to operational infrastructure.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Acquire Infrastructure: Virtual Private Server&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1583/003/\" target=\"_blank\"><u>T1583.003</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>This group procured VPS servers from a variety of vendors.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Develop Capabilities&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1587/\" target=\"_blank\"><u>T1587</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>The <em>Ulej</em> capability was developed likely for use by this group to conduct spear phishing campaigns.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Develop Capabilities: Malware&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1587/001/\" target=\"_blank\"><u>T1587.001</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Development of a novel payload that steals a victim\u2019s emails and other sensitive account information.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Develop Capabilities: Exploits&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1587/004/\" target=\"_blank\"><u>T1587.004</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Development of a novel, at the time, cross-site-scripting (XSS) exploit that enables execution of arbitrary JavaScript.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Obtain Capabilities: Tool&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1588/002/\" target=\"_blank\"><u>T1588.002</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Open source tools, such as Evilginx2, have also been used by the group.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Obtain Capabilities: Artificial Intelligence&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1588/007/\" target=\"_blank\"><u>T1588.007</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>The group appears to have leveraged AI to support development efforts.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Stage Capabilities&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1608/\" target=\"_blank\"><u>T1608</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Flowerbed is deployed to a procured server in the cloud.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<div class=\"TableContainer Ltr SCXW76044448 BCX8\">\n<p><a class=\"ck-anchor\" id=\"table11\"></a></p>\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 11: Initial Access&nbsp;</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>Technique Title</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>ID</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>Use</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Valid Accounts&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1078/\" target=\"_blank\"><u>T1078</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>This actor has used commercial datasets to acquire account credentials and gain unauthorized access to accounts. Additionally, this actor is believed to use previously compromised accounts to conduct spear phishing.&nbsp;&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Trusted Relationship&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1199/\" target=\"_blank\"><u>T1199</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>The group sends malicious payloads to targeted individuals using previously compromised accounts that might have an established relationship with the target.&nbsp;&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Phishing&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1566/\" target=\"_blank\"><u>T1566</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>The actors used spear phishing to lure users into opening malicious email.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<div class=\"TableContainer Ltr SCXW76044448 BCX8\">\n<p><a class=\"ck-anchor\" id=\"table12\"></a></p>\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 12: Execution&nbsp;</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>Technique Title</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>ID</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>Use</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Exploitation for Client Execution&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1203/\" target=\"_blank\"><u>T1203</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>An XSS vulnerability was leveraged to execute the JavaScript payload.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<div class=\"TableContainer Ltr SCXW76044448 BCX8\">\n<p><a class=\"ck-anchor\" id=\"table13\"></a></p>\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 13: Persistence&nbsp;</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>Technique Title</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>ID</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>Use</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Account Manipulation&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1098/\" target=\"_blank\"><u>T1098</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Enabling IMAP and Application Passcodes provides persistent access to the compromised account.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Modify Authentication Process: Multi-Factor Authentication&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1556/006/\" target=\"_blank\"><u>T1556.006</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Creating Application Passcodes to bypass 2FA and stealing a user\u2019s \u201cScratch Keys,\u201d which can be used in place of a 2FA token.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<div class=\"TableContainer Ltr SCXW76044448 BCX8\">\n<p><a class=\"ck-anchor\" id=\"table14\"></a></p>\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 14: Privilege Escalation&nbsp;</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>Technique Title</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>ID</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>Use</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Valid Accounts&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1078/\" target=\"_blank\"><u>T1078</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>This actor has used commercial datasets to acquire account credentials and gain unauthorized privileged access to accounts.&nbsp;&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n<p><a class=\"ck-anchor\" id=\"table15\"></a></p>\n</div>\n</div>\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<div class=\"TableContainer Ltr SCXW76044448 BCX8\">\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 15: Stealth&nbsp;</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>Technique Title</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>ID</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>Use</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Obfuscated Files or Information: Command Obfuscation&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1027/010/\" target=\"_blank\"><u>T1027.010</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Obfuscated JavaScript payload sent to targets to exploit the XSS vulnerability.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Obfuscated Files or Information: Encrypted/Encoded File&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1027/013/\" target=\"_blank\"><u>T1027.013</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>The JavaScript payload included both a Base64-encoded and XOR-encrypted inner payload.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Obfuscated Files or Information: SVG Smuggling&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1027/017/\" target=\"_blank\"><u>T1027.017</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>The payload was contained in an \u201conload\u201d attribute within an SVG image included in the malicious email.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Use Alternate Authentication Material: Web Session Cookie&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1550/004/\" target=\"_blank\"><u>T1550.004</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Previous campaigns using AiTM leveraged stealing and use of a victim\u2019s session cookies to authenticate.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<div class=\"TableContainer Ltr SCXW76044448 BCX8\">\n<p><a class=\"ck-anchor\" id=\"table16\"></a></p>\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 16: Credential Access&nbsp;</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>Technique Title</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>ID</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>Use</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Modify Authentication Process: Multi-Factor Authentication&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1556/006/\" target=\"_blank\"><u>T1556.006</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Creating Application Passcodes to bypass 2FA and stealing a user\u2019s \u201cScratch Keys,\u201d which can be used in place of a 2FA token.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Adversary-in-the-Middle&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1557/\" target=\"_blank\"><u>T1557</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Previous campaigns used Evilginx2 as an AiTM toolkit to intercept credentials and session cookies.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n<p><a class=\"ck-anchor\" id=\"table17\"></a></p>\n</div>\n</div>\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<div class=\"TableContainer Ltr SCXW76044448 BCX8\">\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 17: Collection&nbsp;</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>Technique Title</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>ID</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>Use</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Data Staged: Remote Data Staging&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1074/002/\" target=\"_blank\"><u>T1074.002</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Exfiltrated data was sent to an actor-controlled VPS prior to assumed long-term storage solutions.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Email Collection&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1114/\" target=\"_blank\"><u>T1114</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>This group has emphasized collection of emails.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Email Collection: Remote Email Collection&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1114/002/\" target=\"_blank\"><u>T1114.002</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Emails are collected via API calls to the ZCS mail server and are not collected from emails stored directly on the victim\u2019s device.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Automated Collection&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1119/\" target=\"_blank\"><u>T1119</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Upon execution, the JavaScript payload automatically collects all relevant information in stages.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Browser Session Hijacking&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1185/\" target=\"_blank\"><u>T1185</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>The JavaScript payload leverages the user\u2019s authenticated browser session to make API requests as the user.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Archive Collected Data&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1560/\" target=\"_blank\"><u>T1560</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Emails are exfiltrated with GZIP compression.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<div class=\"TableContainer Ltr SCXW76044448 BCX8\">\n<p><a class=\"ck-anchor\" id=\"table18\"></a></p>\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 18: Discovery&nbsp;</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>Technique Title</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>ID</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>Use</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Account Discovery&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1087/\" target=\"_blank\"><u>T1087</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Stolen Global Access Lists provide the group with new users to target.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n<p><a class=\"ck-anchor\" id=\"table19\"></a></p>\n</div>\n</div>\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<div class=\"TableContainer Ltr SCXW76044448 BCX8\">\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 19: Exfiltration&nbsp;</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>Technique Title</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>ID</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p class=\"text-align-center\"><strong>Use</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Exfiltration Over Alternative Protocol&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1048/\" target=\"_blank\"><u>T1048</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Victim information was exfiltrated over both HTTPS and DNS.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1048/002/\" target=\"_blank\"><u>T1048.002</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Some payloads, especially ones with large amounts of data, were exfiltrated over HTTPS.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v19/techniques/T1048/003/\" target=\"_blank\"><u>T1048.003</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW76044448 BCX8\">\n<div class=\"OutlineElement Ltr SCXW76044448 BCX8\">\n<p>Some smaller bandwidth payloads were exfiltrated over DNS using Base32 encoding.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n<h2><strong>Appendix B: MITRE D3FEND countermeasures </strong><a class=\"ck-anchor\" id=\"appendixb\"></a></h2>\n<p>See <a href=\"#table20\"><strong>Table 20</strong></a> for a mapping of several of the cybersecurity countermeasures mentioned in this advisory. <a class=\"ck-anchor\" id=\"table20\"></a></p>\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<div class=\"TableContainer Ltr SCXW46665017 BCX8\">\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 20: MITRE D3FEND Countermeasures&nbsp;</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p class=\"text-align-center\"><strong>Countermeasure Title</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p class=\"text-align-center\"><strong>ID</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p class=\"text-align-center\"><strong>Description</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p>Application Hardening&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p><a href=\"https://d3fend.mitre.org/technique/d3f:ApplicationHardening\" target=\"_blank\"><u>D3-AH</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"ListContainerWrapper SCXW46665017 BCX8\">\n<ul type=\"disc\">\n<li>Organizations should immediately prioritize patching <a href=\"https://www.cve.org/CVERecord?id=CVE-2025-66376\" target=\"_blank\"><u>CVE-2025-66376</u></a>.&nbsp;&nbsp;</li>\n<li>Organizations should promptly apply software updates to all email systems.&nbsp;</li>\n</ul>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p>Isolate&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p><a href=\"https://d3fend.mitre.org/tactic/d3f:Isolate/\" target=\"_blank\"><u>d3f:Isolate</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p>Organizations that cannot feasibly patch should use alternative mail clients.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p>Credential Hardening&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p><a href=\"https://d3fend.mitre.org/technique/d3f:CredentialHardening\" target=\"_blank\"><u>D3-CH</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p>Organizations should consider using a third-party authentication service that supports passkeys to mediate access to ZCS and other services that do not natively support passkeys.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p>Network Traffic Analysis&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p><a href=\"https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis\" target=\"_blank\"><u>D3-NTA</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p>Organizations should monitor for significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p>DNS Traffic Analysis&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p><a href=\"https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis\" target=\"_blank\"><u>D3-DNSTA</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p>Organizations should monitor for frequent DNS queries to a suspicious domain for seemingly random subdomains.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p>Network Traffic Community Deviation&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p><a href=\"https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation\" target=\"_blank\"><u>D3-NTCD</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"ListContainerWrapper SCXW46665017 BCX8\">\n<ul type=\"disc\">\n<li>Organizations should monitor for a sudden spike of connections to a server associated with a recently established domain.&nbsp;</li>\n<li>Organizations should monitor for connections to internal services, such as webmail, from VPN providers.&nbsp;</li>\n</ul>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p>Identifier Activity Analysis&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p><a href=\"https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis\" target=\"_blank\"><u>D3-IAA</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p>Organizations should search for the listed known IOCs.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p>Process Analysis&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"OutlineElement Ltr SCXW46665017 BCX8\">\n<p><a href=\"https://d3fend.mitre.org/technique/d3f:ProcessAnalysis\" target=\"_blank\"><u>D3-PA</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW46665017 BCX8\">\n<div class=\"ListContainerWrapper SCXW46665017 BCX8\">\n<ul type=\"disc\">\n<li>Organizations should search ZCS log files for specific commands used by the malicious script.&nbsp;</li>\n<li>Organizations should search the localStorage property in web browsers for the ZCS webmail client for \u201cZimbraWeb\u201d Application Passcodes.&nbsp;</li>\n</ul>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>Message Analysis</td>\n<td><a href=\"https://d3fend.mitre.org/technique/d3f:MessageAnalysis\">D3-MA</a></td>\n<td>Organizations that suspect they have victims of this campaign should search for emails with a malicious payload to identify other victims.</td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>",
        "summary_is_html": true,
        "first_seen": "Thu, 23 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 23 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-02",
        "title": "Johnson Controls XAAP Android",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device.</strong></p>\n<p>The following versions of Johnson Controls XAAP Android are affected:</p>\n<ul>\n<li>XAAP Android &lt;1.53</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 3.3</td>\n<td>Johnson Controls</td>\n<td>Johnson Controls XAAP Android</td>\n<td>Cleartext Storage of Sensitive Information</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Ireland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-34490</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A cleartext storage weakness exists in the Fire Solutions Android application, which stores application data locally on the device without encryption. An attacker with physical access to the device and one able to compromise the device through a separate, unrelated flaw, could potentially read this data in plaintext. Exploitation does not require network access and is limited to the local device environment.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-34490\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls XAAP Android</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls XAAP Android: &lt;1.53</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Johnson Controls recommends users update the XAAP Android application to version 1.53 or later, which contains the fix for this vulnerability.</p>\n<p><strong>Mitigation</strong><br>Johnson Controls recommends users restrict physical access to devices running the XAAP Android application.</p>\n<p><strong>Mitigation</strong><br>Johnson Controls recommends users ensure devices are hardened with up-to-date Android OS versions, device encryption enabled, and screen lock protections in place.</p>\n<p><strong>Mitigation</strong><br>Johnson Controls recommends users implement a Mobile Device Management (MDM) solution to enforce security policies, including encryption requirements, application whitelisting, and remote wipe capabilities.</p>\n<p><strong>Mitigation</strong><br>Johnson Controls recommends users Avoid rooting or jailbreaking devices used in production environments, as this weakens OS-level security controls that help protect local application data.</p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-10.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/312.html\">CWE-312 Cleartext Storage of Sensitive Information</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>3.3</td>\n<td>LOW</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N\">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>4.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Johnson Controls reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-23</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-23</td>\n<td>1</td>\n<td>Initial Republication of Johnson Controls JCI-PSA-2026-10</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 23 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 23 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-06",
        "title": "MZ Automation libIEC61850",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-06",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-06.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions.</strong></p>\n<p>The following versions of MZ Automation libIEC61850 are affected:</p>\n<ul>\n<li>libIEC61850 &gt;=v1.0.0|&lt;=v1.6.1&nbsp;</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.1</td>\n<td>MZ Automation</td>\n<td>MZ Automation libIEC61850</td>\n<td>Stack-based Buffer Overflow, Heap-based Buffer Overflow, Improper Handling of Syntactically Invalid Structure, NULL Pointer Dereference</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy, Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-50039</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause a memory corruption via a ReadRequest.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-50039\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>MZ Automation libIEC61850</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>MZ Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>MZ Automation libIEC61850: &gt;=v1.0.0|&lt;=v1.6.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>MZ Automation recommends updating to the latest build of the libIEC61850 standard. Documentation can be found at https://github.com/mz-automation/libiec61850.<br><a href=\"https://github.com/mz-automation/libiec61850\">https://github.com/mz-automation/libiec61850</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/121.html\">CWE-121 Stack-based Buffer Overflow</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-49035</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memory corruption or denial of service may occur in configurations where ASLR is enabled.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-49035\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>MZ Automation libIEC61850</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>MZ Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>MZ Automation libIEC61850: &gt;=v1.0.0|&lt;=v1.6.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>MZ Automation recommends updating to the latest build of the libIEC61850 standard. Documentation can be found at https://github.com/mz-automation/libiec61850.<br><a href=\"https://github.com/mz-automation/libiec61850\">https://github.com/mz-automation/libiec61850</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/122.html\">CWE-122 Heap-based Buffer Overflow</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.2</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-50103</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adjacent attacker to crash a subscribing application by sending a crafted GOOSE frame containing a malformed TLV value.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-50103\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>MZ Automation libIEC61850</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>MZ Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>MZ Automation libIEC61850: &gt;=v1.0.0|&lt;=v1.6.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>MZ Automation recommends updating to the latest build of the libIEC61850 standard. Documentation can be found at https://github.com/mz-automation/libiec61850.<br><a href=\"https://github.com/mz-automation/libiec61850\">https://github.com/mz-automation/libiec61850</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/228.html\">CWE-228 Improper Handling of Syntactically Invalid Structure</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-50032</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to crash the server by sending a WriteRequest with an empty listOfData field.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-50032\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>MZ Automation libIEC61850</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>MZ Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>MZ Automation libIEC61850: &gt;=v1.0.0|&lt;=v1.6.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>MZ Automation recommends updating to the latest build of the libIEC61850 standard. Documentation can be found at https://github.com/mz-automation/libiec61850.<br><a href=\"https://github.com/mz-automation/libiec61850\">https://github.com/mz-automation/libiec61850</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/476.html\">CWE-476 NULL Pointer Dereference</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Abhinav Agarwal reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-23</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-23</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 23 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 23 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-07",
        "title": "MZ Automation lib60870",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-07",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-07.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service.</strong></p>\n<p>The following versions of MZ Automation lib60870 are affected:</p>\n<ul>\n<li>lib60870 &lt;=2.4.0</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.2</td>\n<td>MZ Automation</td>\n<td>MZ Automation lib60870</td>\n<td>Out-of-bounds Read</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Energy, Water and Wastewater</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-16002</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-16002\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>MZ Automation lib60870</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>MZ Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>MZ Automation lib60870: &lt;=2.4.0</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>MZ automation recommends users update to version 2.4.1 or later. Documentation can be found at https://github.com/mz-automation/lib60870/security/advisories/GHSA-f5xp-w6f3-vvrv.<br><a href=\"https://github.com/mz-automation/lib60870/security/advisories/GHSA-f5xp-w6f3-vvrv\">https://github.com/mz-automation/lib60870/security/advisories/GHSA-f5xp-w6f3-vvrv</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Lars Tray reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this (these) vulnerability(ies).</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-23</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-23</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 23 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 23 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01",
        "title": "Johnson Controls C-CURE 9000 and Victor application server",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution.</strong></p>\n<p>The following versions of Johnson Controls C-CURE 9000 and Victor application server are affected:</p>\n<ul>\n<li>C-CURE 9000 and victor &lt;=v2.90_v3.0&nbsp;</li>\n<li>victor Web &lt;=v7.1&nbsp;</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.6</td>\n<td>Johnson Controls</td>\n<td>Johnson Controls C-CURE 9000 and Victor application server</td>\n<td>Server-Side Request Forgery (SSRF), Execution with Unnecessary Privileges</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Ireland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-21655</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Under certain circumstances, successful exploitation of this vulnerability could allow an unauthenticated attacker on the adjacent network to achieve arbitrary code execution on the C-CURE 9000 or victor application server, as well as connected clients (e.g., workstations of physical security personnel). Such an attack could impact physical security controls.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-21655\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls C-CURE 9000 and Victor application server</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls C-CURE 9000 and victor: &lt;=v2.90_v3.0</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation: (CVE-2026-21655) Upgrade to C-CURE 9000 / victor version 3.20 or later, which addresses the vulnerable deserialization path (LV1.1).</p>\n<p><strong>Vendor fix</strong><br>Network segmentation - Isolate the C-CURE 9000 and victor application servers on a dedicated network segment and restrict access to port 8999 to only authorized systems that require connectivity.</p>\n<p><strong>Mitigation</strong><br>Firewall / access control lists - Implement strict firewall rules to block all unnecessary inbound connections to port 8999 from untrusted network segments.</p>\n<p><strong>Mitigation</strong><br>Intrusion detection / prevention - Deploy IDS/IPS signatures tuned to detect known .NET deserialization exploit payloads (e.g., ysoserial.net patterns) targeting port 8999.</p>\n<p><strong>Mitigation</strong><br>Application whitelisting - Enforce application whitelisting on application server hosts to prevent unauthorized executables from being launched by the server process.</p>\n<p><strong>Mitigation</strong><br>Least privilege - Ensure the application server process runs with the minimum privileges necessary, reducing the impact of successful exploitation.</p>\n<p><strong>Mitigation</strong><br>Monitor and audit - Enable detailed logging on application server hosts and monitor for anomalous process creation by SoftwareHouse.CrossFire.Server.exe.</p>\n<p><strong>Mitigation</strong><br>Disable unnecessary services - If the ClientConnectionManager_NF.SynchronousServerNotification callback interface is not required, disable or restrict it to reduce attack surface.</p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories\">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/918.html\">CWE-918 Server-Side Request Forgery (SSRF)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-21653</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Under certain circumstances, successful exploitation of this vulnerability could allow an attacker to forge server-side HTTP requests from the victor Web application. This could be leveraged to interact with internal services running on the host or accessible on the local network, potentially leading to unauthorized information disclosure or lateral movement within the network.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-21653\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls C-CURE 9000 and Victor application server</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls victor Web: &lt;v7.0</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>(CVE-2026-21653, CVE-2026-34496) Update all victor Web installations to version 7.0 or later, which contains the fix for this vulnerability. The fix has been validated through independent retest.</p>\n<p><strong>Mitigation</strong><br>Firewall / access control lists - Implement strict firewall rules to block all unnecessary inbound connections to port 8999 from untrusted network segments.</p>\n<p><strong>Mitigation</strong><br>Intrusion detection / prevention - Deploy IDS/IPS signatures tuned to detect known .NET deserialization exploit payloads (e.g., ysoserial.net patterns) targeting port 8999.</p>\n<p><strong>Mitigation</strong><br>Application whitelisting - Enforce application whitelisting on application server hosts to prevent unauthorized executables from being launched by the server process.</p>\n<p><strong>Mitigation</strong><br>Least privilege - Ensure the application server process runs with the minimum privileges necessary, reducing the impact of successful exploitation.</p>\n<p><strong>Mitigation</strong><br>Monitor and audit - Enable detailed logging on application server hosts and monitor for anomalous process creation by SoftwareHouse.CrossFire.Server.exe.</p>\n<p><strong>Mitigation</strong><br>Disable unnecessary services - If the ClientConnectionManager_NF.SynchronousServerNotification callback interface is not required, disable or restrict it to reduce attack surface.</p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories\">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/918.html\">CWE-918 Server-Side Request Forgery (SSRF)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.6</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.4</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-34496</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Under certain circumstances, successful exploitation of this vulnerability could result in low privilege users accessing unauthorized pages such as Users and Logs. Successful exploitation could allow an attacker to view sensitive system information, user account details, and audit logs beyond their intended access level, potentially enabling further attacks or unauthorized administrative actions.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-34496\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls C-CURE 9000 and Victor application server</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls victor Web: &lt;=v7.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>(CVE-2026-21653, CVE-2026-34496) Update all victor Web installations to version 7.0 or later, which contains the fix for this vulnerability. The fix has been validated through independent retest.</p>\n<p><strong>Mitigation</strong><br>Firewall / access control lists - Implement strict firewall rules to block all unnecessary inbound connections to port 8999 from untrusted network segments.</p>\n<p><strong>Mitigation</strong><br>Intrusion detection / prevention - Deploy IDS/IPS signatures tuned to detect known .NET deserialization exploit payloads (e.g., ysoserial.net patterns) targeting port 8999.</p>\n<p><strong>Mitigation</strong><br>Application whitelisting - Enforce application whitelisting on application server hosts to prevent unauthorized executables from being launched by the server process.</p>\n<p><strong>Mitigation</strong><br>Least privilege - Ensure the application server process runs with the minimum privileges necessary, reducing the impact of successful exploitation.</p>\n<p><strong>Mitigation</strong><br>Monitor and audit - Enable detailed logging on application server hosts and monitor for anomalous process creation by SoftwareHouse.CrossFire.Server.exe.</p>\n<p><strong>Mitigation</strong><br>Disable unnecessary services - If the ClientConnectionManager_NF.SynchronousServerNotification callback interface is not required, disable or restrict it to reduce attack surface.</p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories\">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/250.html\">CWE-250 Execution with Unnecessary Privileges</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Harrison Neal reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-23</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-23</td>\n<td>1</td>\n<td>Initial Republication of Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 23 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 23 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-04",
        "title": "Panduit IntraVUE",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-04",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-04.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider knowledge, or advanced tooling.</strong></p>\n<p>The following versions of Panduit IntraVUE are affected:</p>\n<ul>\n<li>IntraVUE &lt;=3.2.1a14&nbsp;</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 10</td>\n<td>Pronetiqs</td>\n<td>Panduit IntraVUE</td>\n<td>Plaintext Storage of a Password, Unintended Proxy or Intermediary ('Confused Deputy'), Exposure of Sensitive System Information to an Unauthorized Control Sphere, Inadequate Encryption Strength</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy, Information Technology, Water and Wastewater</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Netherlands</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-40430</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-40430\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Panduit IntraVUE</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Pronetiqs</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Pronetiqs IntraVUE: &lt;=3.2.1a14</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Pronetiqs advises users to update to the latest version of the IntraVUE software, version 3.2.1a16 or later.</p>\n<p><strong>Mitigation</strong><br>For further questions, please contact Pronetiqs at info@pronetiqs.com.<br><a href=\"mailto:info@pronetiqs.com\">mailto:info@pronetiqs.com</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/256.html\">CWE-256 Plaintext Storage of a Password</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-42933</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-42933\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Panduit IntraVUE</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Pronetiqs</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Pronetiqs IntraVUE: &lt;=3.2.1a14</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Pronetiqs advises users to update to the latest version of the IntraVUE software, version 3.2.1a16 or later.</p>\n<p><strong>Mitigation</strong><br>For further questions, please contact Pronetiqs at info@pronetiqs.com.<br><a href=\"mailto:info@pronetiqs.com\">mailto:info@pronetiqs.com</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/441.html\">CWE-441 Unintended Proxy or Intermediary ('Confused Deputy')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>10</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>10</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-44955</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could allow for asset discovery by unauthenticated users.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-44955\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Panduit IntraVUE</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Pronetiqs</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Pronetiqs IntraVUE: &lt;=3.2.1a14</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Pronetiqs advises users to update to the latest version of the IntraVUE software, version 3.2.1a16 or later.</p>\n<p><strong>Mitigation</strong><br>For further questions, please contact Pronetiqs at info@pronetiqs.com.<br><a href=\"mailto:info@pronetiqs.com\">mailto:info@pronetiqs.com</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/497.html\">CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-50044</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an attacker to steal admin credentials via weak hash or a pass-the-hash attack.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-50044\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Panduit IntraVUE</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Pronetiqs</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Pronetiqs IntraVUE: &lt;=3.2.1a14</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Pronetiqs advises users to update to the latest version of the IntraVUE software, version 3.2.1a16 or later.</p>\n<p><strong>Mitigation</strong><br>For further questions, please contact Pronetiqs at info@pronetiqs.com.<br><a href=\"mailto:info@pronetiqs.com\">mailto:info@pronetiqs.com</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/326.html\">CWE-326 Inadequate Encryption Strength</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N\">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-28698</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-28698\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Panduit IntraVUE</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Pronetiqs</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Pronetiqs IntraVUE: &lt;=3.2.1a14</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Pronetiqs advises users to update to the latest version of the IntraVUE software, version 3.2.1a16 or later.</p>\n<p><strong>Mitigation</strong><br>For further questions, please contact Pronetiqs at info@pronetiqs.com.<br><a href=\"mailto:info@pronetiqs.com\">mailto:info@pronetiqs.com</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/497.html\">CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.2</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Phlebas of Lumintel reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-23</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-23</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 23 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 23 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/07/22/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Two Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/07/22/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added two new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-16232\" target=\"_blank\">CVE-2026-16232</a> Check Point SmartConsole Improper Authentication Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-50522\" target=\"_blank\">CVE-2026-50522</a> Microsoft SharePoint Deserialization of Untrusted Data Vulnerability</li>\n</ul>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Wed, 22 Jul 26 12:00:00 +0000",
        "last_updated": "Wed, 22 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-08",
        "title": "Rockwell Automation 1718-AENTR/1719-AENTR",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-08",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-08.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product.</strong></p>\n<p>The following versions of Rockwell Automation 1718-AENTR/1719-AENTR are affected:</p>\n<ul>\n<li>1718/ 1719 Ex I/O 3.011&nbsp;</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation 1718-AENTR/1719-AENTR</td>\n<td>Allocation of Resources Without Limits or Throttling</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-9140</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose communication. A power cycle is required to recover.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9140\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation 1718-AENTR/1719-AENTR</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation 1718/ 1719 Ex I/O: 3.011</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users to upgrade to 1718/ 1719 Ex I/O version 3.012 or later.</p>\n<p><strong>Mitigation</strong><br>Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight).<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/770.html\">CWE-770 Allocation of Resources Without Limits or Throttling</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-21</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-21</td>\n<td>1</td>\n<td>Initial Republication of Rockwell Automation Security Advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 21 Jul 26 12:00:00 +0000",
        "last_updated": "Tue, 21 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-04",
        "title": "Siemens SIDIS Secured SmartPlug",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-04",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-04.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version.</strong></p>\n<p>The following versions of Siemens SIDIS Secured SmartPlug are affected:</p>\n<ul>\n<li>SIDIS Secured SmartPlug vers:intdot/&lt;7.26.0310&nbsp;</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.8</td>\n<td>Siemens</td>\n<td>Siemens SIDIS Secured SmartPlug</td>\n<td>Improper Enforcement of Message Integrity During Transmission in a Communication Channel, Reusing a Nonce, Key Pair in Encryption, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Integer Overflow or Wraparound, Out-of-bounds Read, Covert Timing Channel, Detection of Error Condition Without Action, Incorrect Authorization</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2022-23303</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2022-23303\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SIDIS Secured SmartPlug</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SIDIS Secured SmartPlug &lt; V7.26.0310</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V7.26.0310 or later version</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/924.html\">CWE-924 Improper Enforcement of Message Integrity During Transmission in a Communication Channel</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2022-23304</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2022-23304\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SIDIS Secured SmartPlug</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SIDIS Secured SmartPlug &lt; V7.26.0310</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V7.26.0310 or later version</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/924.html\">CWE-924 Improper Enforcement of Message Integrity During Transmission in a Communication Channel</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2022-37660</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that successfully bootstrapped public keys with another entity using PKEX in the past, will be able to subvert a future bootstrapping by passively observing public keys, re-using the encrypting element Qi and subtracting it from the captured message M (X = M - Qi). This will result in the public ephemeral key X; the only element required to subvert the PKEX association.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2022-37660\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SIDIS Secured SmartPlug</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SIDIS Secured SmartPlug &lt; V7.26.0310</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V7.26.0310 or later version</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/323.html\">CWE-323 Reusing a Nonce, Key Pair in Encryption</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2022-48174</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2022-48174\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SIDIS Secured SmartPlug</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SIDIS Secured SmartPlug &lt; V7.26.0310</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V7.26.0310 or later version</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-5222</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-5222\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SIDIS Secured SmartPlug</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SIDIS Secured SmartPlug &lt; V7.26.0310</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V7.26.0310 or later version</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/120.html\">CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-5914</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-5914\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SIDIS Secured SmartPlug</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SIDIS Secured SmartPlug &lt; V7.26.0310</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V7.26.0310 or later version</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/190.html\">CWE-190 Integer Overflow or Wraparound</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-9230</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-9230\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SIDIS Secured SmartPlug</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SIDIS Secured SmartPlug &lt; V7.26.0310</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V7.26.0310 or later version</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-9231</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64 bit ARM platforms. Impact summary: A timing side-channel in SM2 signature computations on 64 bit ARM platforms could allow recovering the private key by an attacker.. While remote key recovery over a network was not attempted by the reporter, timing measurements revealed a timing signal which may allow such an attack. OpenSSL does not directly support certificates with SM2 keys in TLS, and so this CVE is not relevant in most TLS contexts. However, given that it is possible to add support for such certificates via a custom provider, coupled with the fact that in such a custom provider context the private key may be recoverable via remote timing measurements, we consider this to be a Moderate severity issue. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as SM2 is not an approved algorithm.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-9231\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SIDIS Secured SmartPlug</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SIDIS Secured SmartPlug &lt; V7.26.0310</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V7.26.0310 or later version</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/385.html\">CWE-385 Covert Timing Channel</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-9232</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority component of the HTTP URL is an IPv6 address. Impact summary: An out-of-bounds read can trigger a crash which leads to Denial of Service for an application. The OpenSSL HTTP client API functions can be used directly by applications but they are also used by the OCSP client functions and CMP (Certificate Management Protocol) client implementation in OpenSSL. However the URLs used by these implementations are unlikely to be controlled by an attacker. In this vulnerable code the out of bounds read can only trigger a crash. Furthermore the vulnerability requires an attacker-controlled URL to be passed from an application to the OpenSSL function and the user has to have a 'no_proxy' environment variable set. For the aforementioned reasons the issue was assessed as Low severity. The vulnerable code was introduced in the following patch releases: 3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the HTTP client implementation is outside the OpenSSL FIPS module boundary.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-9232\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SIDIS Secured SmartPlug</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SIDIS Secured SmartPlug &lt; V7.26.0310</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V7.26.0310 or later version</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-26465</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-26465\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SIDIS Secured SmartPlug</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SIDIS Secured SmartPlug &lt; V7.26.0310</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V7.26.0310 or later version</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/390.html\">CWE-390 Detection of Error Condition Without Action</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N\">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-32462</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-32462\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SIDIS Secured SmartPlug</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SIDIS Secured SmartPlug &lt; V7.26.0310</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V7.26.0310 or later version</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/863.html\">CWE-863 Incorrect Authorization</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>2.8</td>\n<td>LOW</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N\">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-5121</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-5121\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SIDIS Secured SmartPlug</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SIDIS Secured SmartPlug &lt; V7.26.0310</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V7.26.0310 or later version</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/190.html\">CWE-190 Integer Overflow or Wraparound</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-585531 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-14</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-14</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-07-21</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-585531 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 21 Jul 26 12:00:00 +0000",
        "last_updated": "Tue, 21 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Four Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added four new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2021-27137\" target=\"_blank\">CVE-2021-27137</a> DD-WRT Stack-Based Buffer Overflow Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-0770\" target=\"_blank\">CVE-2026-0770</a> Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability &nbsp;</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-63030\" target=\"_blank\">CVE-2026-63030</a> WordPress Core Interpretation Conflict Vulnerability &nbsp;</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-60137\" target=\"_blank\">CVE-2026-60137</a> WordPress Core SQL Injection Vulnerability</li>\n</ul>\n<p>These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Tue, 21 Jul 26 12:00:00 +0000",
        "last_updated": "Tue, 21 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-05",
        "title": "Siemens IAM Client",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-05",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-05.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.</strong></p>\n<p>The following versions of Siemens IAM Client are affected:</p>\n<ul>\n<li>COMOS V10.4.5 vers:intdot/&lt;10.4.5.0.2&nbsp;</li>\n<li>COMOS V10.6 vers:intdot/&lt;10.6.1&nbsp;</li>\n<li>Designcenter NX vers:intdot/&lt;2512.7000&nbsp;</li>\n<li>Simcenter 3D vers:intdot/&lt;2512.7000&nbsp;</li>\n<li>Simcenter Femap V2506 vers:intdot/&lt;2506.0003&nbsp;</li>\n<li>Simcenter Femap V2512 vers:intdot/&lt;2512.0002&nbsp;</li>\n<li>Simcenter Nastran vers:intdot/&lt;2606&nbsp;</li>\n<li>Simcenter STAR-CCM+ vers:intdot/&lt;2606&nbsp;</li>\n<li>Solid Edge SE2025 vers:intdot/&lt;225.0.13.3&nbsp;</li>\n<li>Solid Edge SE2026 vers:intdot/&lt;226.0.04.003&nbsp;</li>\n<li>Teamcenter Visualization V2412 vers:intdot/&lt;2412.0012&nbsp;</li>\n<li>Teamcenter Visualization V2506 vers:intdot/&lt;2506.0009&nbsp;</li>\n<li>Teamcenter Visualization V2512 vers:intdot/&lt;2512.2605&nbsp;</li>\n<li>Tecnomatix Plant Simulation V2404 vers:intdot/&lt;2404.0022&nbsp;</li>\n<li>Tecnomatix Plant Simulation V2504 vers:intdot/&lt;2504.0010&nbsp;</li>\n<li>Tecnomatix Process Simulate vers:intdot/&lt;2606&nbsp;</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 6.7</td>\n<td>Siemens</td>\n<td>Siemens IAM Client</td>\n<td>Untrusted Search Path</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Critical Manufacturing, Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-40945</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Untrusted search path in IAM Client SDK may allow an authenticated user to potentially enable escalation of privilege via local access.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-40945\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens IAM Client</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>COMOS V10.4.5 &lt; V10.4.5.0.2, COMOS V10.6 &lt; V10.6.1, Designcenter NX &lt; V2512.7000, Simcenter 3D &lt; V2512.7000, Simcenter Femap V2506 &lt; V2506.0003, Simcenter Femap V2512 &lt; V2512.0002, Simcenter Nastran &lt; V2606, Simcenter STAR-CCM+ &lt; V2606, Solid Edge SE2025 &lt; V225.0.13.3, Solid Edge SE2026 &lt; V226.0.04.003, Teamcenter Visualization V2412 &lt; V2412.0012, Teamcenter Visualization V2506 &lt; V2506.0009, Teamcenter Visualization V2512 &lt; V2512.2605, Tecnomatix Plant Simulation V2404 &lt; V2404.0022, Tecnomatix Plant Simulation V2504 &lt; V2504.0010, Tecnomatix Process Simulate &lt; V2606</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V10.6.1 or later version<br><a href=\"https://support.sw.siemens.com/product/222981661/\">https://support.sw.siemens.com/product/222981661/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V225.0 Update 13 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V226.0 Update 04 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V2404.0022 or later version<br><a href=\"https://support.sw.siemens.com/product/297028302/\">https://support.sw.siemens.com/product/297028302/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V2412.0012 or later version<br><a href=\"https://support.sw.siemens.com/product/229029598/\">https://support.sw.siemens.com/product/229029598/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V2504.0010 or later version<br><a href=\"https://support.sw.siemens.com/product/297028302/\">https://support.sw.siemens.com/product/297028302/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V2506.0003 or later version<br><a href=\"https://support.sw.siemens.com/product/275652363/\">https://support.sw.siemens.com/product/275652363/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V2506.0009 or later version<br><a href=\"https://support.sw.siemens.com/product/229029598/\">https://support.sw.siemens.com/product/229029598/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V2512.0002 or later version<br><a href=\"https://support.sw.siemens.com/product/275652363/\">https://support.sw.siemens.com/product/275652363/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V2512.2605 or later version<br><a href=\"https://support.sw.siemens.com/product/229029598/\">https://support.sw.siemens.com/product/229029598/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V2512.7000 or later version<br><a href=\"https://support.sw.siemens.com/product/209349590/\">https://support.sw.siemens.com/product/209349590/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V2512.7000 or later version<br><a href=\"https://support.sw.siemens.com/product/289054037/\">https://support.sw.siemens.com/product/289054037/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V2606 or later version<br><a href=\"https://support.sw.siemens.com/product/289054037/\">https://support.sw.siemens.com/product/289054037/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V10.4.5.0.2 or later version. Contact customer support to receive patch and update information</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/426.html\">CWE-426 Untrusted Search Path</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.7</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-288252 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-14</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-14</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-07-21</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-288252 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 21 Jul 26 12:00:00 +0000",
        "last_updated": "Tue, 21 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-02",
        "title": "Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/</strong></p>\n<p>The following versions of Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW are affected:</p>\n<ul>\n<li>RUGGEDCOM APE1808 vers:all/*&nbsp;</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.2</td>\n<td>Siemens</td>\n<td>Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW</td>\n<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Missing Authorization, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-0266</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS\u00ae software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma\u00ae Access are not affected by this vulnerability.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-0266\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Contact customer support to receive patch and update information</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/79.html\">CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>2.4</td>\n<td>LOW</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N\">CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-0272</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A privilege escalation vulnerability in Palo Alto Networks PAN-OS\u00ae software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW, and Prisma\u00ae Access are not impacted by this vulnerability.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-0272\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Contact customer support to receive patch and update information</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/862.html\">CWE-862 Missing Authorization</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N\">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-0273</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A command injection vulnerability in Palo Alto Networks PAN-OS\u00ae software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma\u00ae Access are not affected by this vulnerability.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-0273\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Contact customer support to receive patch and update information</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/78.html\">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-104023 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-14</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-14</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-07-21</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-104023 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 21 Jul 26 12:00:00 +0000",
        "last_updated": "Tue, 21 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-09",
        "title": "Rockwell Automation 1734 POINT I/O",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-09",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-09.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product.</strong></p>\n<p>The following versions of Rockwell Automation 1734 POINT I/O are affected:</p>\n<ul>\n<li>1734 POINT I/O 3.023&nbsp;</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation 1734 POINT I/O</td>\n<td>Allocation of Resources Without Limits or Throttling</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-10573</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service security issue exists in 1734 POINT I/O module. The security issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A restart is required to recover.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-10573\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation 1734 POINT I/O</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation 1734 POINT I/O: 3.023</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Rockwell Automation recommends users are to migrate to 5034-OB8.</p>\n<p><strong>Mitigation</strong><br>Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight).<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/770.html\">CWE-770 Allocation of Resources Without Limits or Throttling</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-21</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-21</td>\n<td>1</td>\n<td>Initial Republication of Rockwell Automation Security Advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 21 Jul 26 12:00:00 +0000",
        "last_updated": "Tue, 21 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-07",
        "title": "Rockwell Automation FactoryTalk Services Platform",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-07",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-07.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations.</strong></p>\n<p>The following versions of Rockwell Automation FactoryTalk Services Platform are affected:</p>\n<ul>\n<li>FactoryTalk Directory (FTSP) 6.60&nbsp;</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.8</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation FactoryTalk Services Platform</td>\n<td>Weak Authentication</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-10714</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A security issue exists within FactoryTalk Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the application not verifying that the JWT algorithm is configured for RSA, enabling an attacker to set the algorithm to \"none\" and craft forged tokens. This could allow an authenticated low-privilege user to impersonate any authorized user on the FTSP server, resulting in unauthorized access to system configuration and the ability to grant permissions to other systems protected by FTSP.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-10714\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation FactoryTalk Services Platform</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation FactoryTalk Directory (FTSP): 6.60</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users using FactoryTalk Services Platform v6.60 should apply either the individual patch (RAID 1158263) or the February 2026 Patch Roll-up, or later update.</p>\n<p><strong>Mitigation</strong><br>Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell's security best practices.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information, refer to Rockwell Automation's security advisory SD1786 page.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1786.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1786.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/1390.html\">CWE-1390 Weak Authentication</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H\">CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-21</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-21</td>\n<td>1</td>\n<td>Initial Republication of Rockwell Automation SD1786</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 21 Jul 26 12:00:00 +0000",
        "last_updated": "Tue, 21 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-10",
        "title": "Rockwell Automation Studio 5000 Logix Designer",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-10",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-10.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code.</strong></p>\n<p>The following versions of Rockwell Automation Studio 5000 Logix Designer are affected:</p>\n<ul>\n<li>Studio 5000 Logix Designer V36.00 (CVE-2026-9108)</li>\n<li>Studio 5000 Logix Designer V35.00 (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128)</li>\n<li>Studio 5000 Logix Designer V35.01 (CVE-2026-9108)</li>\n<li>Studio 5000 Logix Designer &gt;=V34.00|&lt;=V34.03 (CVE-2026-9108)</li>\n<li>Studio 5000 Logix Designer &gt;=V33.00|&lt;=V33.03 (CVE-2026-9108)</li>\n<li>Studio 5000 Logix Designer &gt;=V32.00|&lt;=V32.04 (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128)</li>\n<li>Studio 5000 Logix Designer V34.00 (CVE-2026-9127)</li>\n<li>Studio 5000 Logix Designer V34.01 (CVE-2026-9127)</li>\n<li>Studio 5000 Logix Designer V33.00 (CVE-2026-9127)</li>\n<li>Studio 5000 Logix Designer V33.02 (CVE-2026-9127)</li>\n<li>Studio 5000 Logix Designer &gt;=V34.00|&lt;=V34.02 (CVE-2026-9128)</li>\n<li>Studio 5000 Logix Designer &gt;=V33.00|&lt;=V33.02 (CVE-2026-9128)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation Studio 5000 Logix Designer</td>\n<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Incorrect Authorization, Unquoted Search Path or Element</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-9108</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A path traversal security issue exists within Studio 5000 Logix Designer due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9108\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation Studio 5000 Logix Designer</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation Studio 5000 Logix Designer: V36.00, Rockwell Automation Studio 5000 Logix Designer: V35.00, Rockwell Automation Studio 5000 Logix Designer: V35.01, Rockwell Automation Studio 5000 Logix Designer: &gt;=V34.00|&lt;=V34.03, Rockwell Automation Studio 5000 Logix Designer: &gt;=V33.00|&lt;=V33.03, Rockwell Automation Studio 5000 Logix Designer: &gt;=V32.00|&lt;=V32.04</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users to upgrade to the following: Studio 5000 Logix Designer: V37.00, 36.01, 35.02, 34.04, 33.04, 32.05 (CVE-2026-9108)</p>\n<p><strong>Mitigation</strong><br>Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight).<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/22.html\">CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.7</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.4</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-9127</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A remote code execution security issue exists within Studio 5000 Logix Designer due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9127\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation Studio 5000 Logix Designer</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation Studio 5000 Logix Designer: V35.00, Rockwell Automation Studio 5000 Logix Designer: &gt;=V32.00|&lt;=V32.04, Rockwell Automation Studio 5000 Logix Designer: V34.00, Rockwell Automation Studio 5000 Logix Designer: V34.01, Rockwell Automation Studio 5000 Logix Designer: V33.00, Rockwell Automation Studio 5000 Logix Designer: V33.02</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Studio 5000 Logix Designer: V36.00, 35.01, 34.02, 33.02, 32.05 (CVE-2026-9127)</p>\n<p><strong>Mitigation</strong><br>Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight).<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/863.html\">CWE-863 Incorrect Authorization</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H\">CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-9128</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A code execution security issue exists within Studio 5000 Logix Designer due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. If exploited, an attacker could plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9128\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation Studio 5000 Logix Designer</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation Studio 5000 Logix Designer: V35.00, Rockwell Automation Studio 5000 Logix Designer: &gt;=V32.00|&lt;=V32.04, Rockwell Automation Studio 5000 Logix Designer: &gt;=V34.00|&lt;=V34.02, Rockwell Automation Studio 5000 Logix Designer: &gt;=V33.00|&lt;=V33.02</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Studio 5000 Logix Designer: V36.00, 35.01, 34.03, 33.03, 32.05 (CVE-2026-9128)</p>\n<p><strong>Mitigation</strong><br>Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight).<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/428.html\">CWE-428 Unquoted Search Path or Element</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H\">CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities have a high attack complexity.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-21</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-21</td>\n<td>1</td>\n<td>Initial Republication of Rockwell Automation Security Advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 21 Jul 26 12:00:00 +0000",
        "last_updated": "Tue, 21 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-06",
        "title": "Siemens CADRA",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-06",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-06.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</strong></p>\n<p>The following versions of Siemens CADRA are affected:</p>\n<ul>\n<li>CADRA vers:intdot/&lt;2511, vers:all/*&nbsp;</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.8</td>\n<td>Siemens</td>\n<td>Siemens CADRA</td>\n<td>Improper Input Validation, Incorrect Bitwise Shift of Integer, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Integer Overflow or Wraparound, Access of Resource Using Incompatible Type ('Type Confusion')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Commercial Facilities, Communications, Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2005-2096</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2005-2096\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens CADRA</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CADRA &lt; V2511</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V2511 or later version</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/20.html\">CWE-20 Improper Input Validation</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2016-9840</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2016-9840\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens CADRA</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CADRA &lt; V2511</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V2511 or later version</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/20.html\">CWE-20 Improper Input Validation</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2016-9841</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2016-9841\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens CADRA</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CADRA &lt; V2511</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V2511 or later version</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/20.html\">CWE-20 Improper Input Validation</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2016-9842</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2016-9842\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens CADRA</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CADRA &lt; V2511</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V2511 or later version</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/1335.html\">CWE-1335 Incorrect Bitwise Shift of Integer</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2017-14919</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2017-14919\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens CADRA</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CADRA &lt; V2511</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V2511 or later version</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/20.html\">CWE-20 Improper Input Validation</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.0</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2018-25032</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2018-25032\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens CADRA</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CADRA &lt; V2511</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V2511 or later version</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2022-37434</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2022-37434\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens CADRA</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CADRA &lt; V2511</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V2511 or later version</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/120.html\">CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2023-45853</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2023-45853\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens CADRA</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CADRA &lt; V2511</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V2511 or later version</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/190.html\">CWE-190 Integer Overflow or Wraparound</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-10585</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-10585\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens CADRA</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CADRA</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Block access to untrusted or external web content from sensitive systems</p>\n<p><strong>None available</strong><br>Currently no fix is available</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/843.html\">CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-13223</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-13223\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens CADRA</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CADRA</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Block access to untrusted or external web content from sensitive systems</p>\n<p><strong>None available</strong><br>Currently no fix is available</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/843.html\">CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-22184</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user executes the untgz command with an excessively long archive name supplied via the command line, leading to an out-of-bounds write in a fixed-size global buffer.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-22184\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens CADRA</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CADRA</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>None available</strong><br>Currently no fix is available</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>0</td>\n<td>NONE</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:N\">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-470355 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-14</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-14</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-07-21</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-470355 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 21 Jul 26 12:00:00 +0000",
        "last_updated": "Tue, 21 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-03",
        "title": "Siemens Opcenter X",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-03",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-03.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version.</strong></p>\n<p>The following versions of Siemens Opcenter X are affected:</p>\n<ul>\n<li>Opcenter X vers:intdot/&lt;2604</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 10</td>\n<td>Siemens</td>\n<td>Siemens Opcenter X</td>\n<td>Improper Verification of Cryptographic Signature</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-56451</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-56451\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Opcenter X</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Opcenter X &lt; V2604</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V2604 or later version<br><a href=\"https://support.sw.siemens.com/product/206159703/\">https://support.sw.siemens.com/product/206159703/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/347.html\">CWE-347 Improper Verification of Cryptographic Signature</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>10</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-096828 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-14</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-14</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-07-21</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-096828 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 21 Jul 26 12:00:00 +0000",
        "last_updated": "Tue, 21 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-01",
        "title": "Tycon Systems TPDIN-Monitor-WEB2",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.</strong></p>\n<p>The following versions of Tycon Systems TPDIN-Monitor-WEB2 are affected:</p>\n<ul>\n<li>TPDIN-Monitor-WEB2 2.3.9&nbsp;</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.8</td>\n<td>Tycon Systems</td>\n<td>Tycon Systems TPDIN-Monitor-WEB2</td>\n<td>Authentication Bypass Using an Alternate Path or Channel, Cleartext Storage of Sensitive Information</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-61884</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The web management interface of the affected device does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, device reboot, remote access service configuration, and network settings, which could allow an attacker to disrupt connected infrastructure or cause physical damage to equipment.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-61884\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Tycon Systems TPDIN-Monitor-WEB2</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Tycon Systems</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Tycon Systems TPDIN-Monitor-WEB2: 2.3.9</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Tycon Systems did not respond to CISA's attempts at coordination. Users of Tycon Systems TPDIN-Monitor-WEB2 are encouraged to contact Tycon Systems and keep their systems up to date.<br><a href=\"https://www.tyconsystems.com/contact\">https://www.tyconsystems.com/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/288.html\">CWE-288 Authentication Bypass Using an Alternate Path or Channel</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-55985</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The device's web management interface stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-55985\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Tycon Systems TPDIN-Monitor-WEB2</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Tycon Systems</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Tycon Systems TPDIN-Monitor-WEB2: 2.3.9</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Tycon Systems did not respond to CISA's attempts at coordination. Users of Tycon Systems TPDIN-Monitor-WEB2 are encouraged to contact Tycon Systems and keep their systems up to date.<br><a href=\"https://www.tyconsystems.com/contact\">https://www.tyconsystems.com/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/312.html\">CWE-312 Cleartext Storage of Sensitive Information</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>4.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Abdiwelli Guled reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-21</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-21</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 21 Jul 26 12:00:00 +0000",
        "last_updated": "Tue, 21 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-03",
        "title": "NASA Core Flight System (cFS) Health & Safety (HS) Application",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-03",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-03.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.</strong></p>\n<p>The following versions of NASA Core Flight System (cFS) Health &amp; Safety (HS) Application are affected:</p>\n<ul>\n<li>Core Flight System (cFS) Health &amp; Safety (HS) Application</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>NASA</td>\n<td>NASA Core Flight System (cFS) Health &amp; Safety (HS) Application</td>\n<td>NULL Pointer Dereference</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-15352</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A vulnerability exists in the Health &amp; Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-15352\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>NASA Core Flight System (cFS) Health &amp; Safety (HS) Application</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>NASA</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>NASA Core Flight System (cFS) Health &amp; Safety (HS) Application: &lt;v7.0.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>NASA recommends users update to v7.0.1 (https://github.com/nasa/HS/releases/tag/v7.0.1)<br><a href=\"https://github.com/nasa/HS/releases/tag/v7.0.1\">https://github.com/nasa/HS/releases/tag/v7.0.1</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/476.html\">CWE-476 NULL Pointer Dereference</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Grady DeRosa reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-16</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-16</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 16 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 16 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-04",
        "title": "AutomationDirect Productivity Suite",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-04",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-04.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker with local or physical access to cause memory corruption, unintended information disclosure, application instability, or a denial-of-service condition in the affected product.</strong></p>\n<p>The following versions of AutomationDirect Productivity Suite are affected:</p>\n<ul>\n<li>Productivity Suite &lt;=v4.6.2.2 (CVE-2026-60063, CVE-2026-61389, CVE-2026-60140, CVE-2026-57896, CVE-2026-60073, CVE-2026-61378)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7</td>\n<td>AutomationDirect</td>\n<td>AutomationDirect Productivity Suite</td>\n<td>Out-of-bounds Write, Out-of-bounds Read, Divide By Zero</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-60063</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL request, potentially resulting in privilege escalation or system instability.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-60063\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>AutomationDirect Productivity Suite</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>AutomationDirect</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>AutomationDirect Productivity Suite: &lt;=v4.6.2.2</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>AutomationDirect recommends that users update Productivity suite to v4.7.0.47 and above https://www.automationdirect.com/support/software-downloads.<br><a href=\"https://www.automationdirect.com/support/software-downloads\">https://www.automationdirect.com/support/software-downloads</a></p>\n<p><strong>Mitigation</strong><br>If the update cannot be applied right away, the following compensating controls are recommended until the upgrade can be performed.</p>\n<p><strong>Mitigation</strong><br>Disconnect the engineering workstation from external networks (e.g., the internet or corporate LAN) to reduce exposure.</p>\n<p><strong>Mitigation</strong><br>Use only trusted, dedicated internal networks or air-gapped systems for device communication.</p>\n<p><strong>Mitigation</strong><br>Restrict both physical and logical access to authorized personnel only.</p>\n<p><strong>Mitigation</strong><br>Configure whitelisting so that only trusted, pre-approved applications are allowed to run. Block any unauthorized software.</p>\n<p><strong>Mitigation</strong><br>Use antivirus or EDR tools and configure host-based firewalls to block unauthorized access attempts.</p>\n<p><strong>Mitigation</strong><br>Enable and regularly review system logs to detect suspicious or unauthorized activity.</p>\n<p><strong>Mitigation</strong><br>Maintain secure, tested backups of the PLC and its configurations to minimize downtime in case of an incident.</p>\n<p><strong>Mitigation</strong><br>Continuously evaluate risks associated with running outdated firmware and adjust compensating measures accordingly.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-61389</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL request, potentially resulting in privilege escalation or system instability.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-61389\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>AutomationDirect Productivity Suite</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>AutomationDirect</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>AutomationDirect Productivity Suite: &lt;=v4.6.2.2</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>AutomationDirect recommends that users update Productivity suite to v4.7.0.47 and above https://www.automationdirect.com/support/software-downloads.<br><a href=\"https://www.automationdirect.com/support/software-downloads\">https://www.automationdirect.com/support/software-downloads</a></p>\n<p><strong>Mitigation</strong><br>If the update cannot be applied right away, the following compensating controls are recommended until the upgrade can be performed.</p>\n<p><strong>Mitigation</strong><br>Disconnect the engineering workstation from external networks (e.g., the internet or corporate LAN) to reduce exposure.</p>\n<p><strong>Mitigation</strong><br>Use only trusted, dedicated internal networks or air-gapped systems for device communication.</p>\n<p><strong>Mitigation</strong><br>Restrict both physical and logical access to authorized personnel only.</p>\n<p><strong>Mitigation</strong><br>Configure whitelisting so that only trusted, pre-approved applications are allowed to run. Block any unauthorized software.</p>\n<p><strong>Mitigation</strong><br>Use antivirus or EDR tools and configure host-based firewalls to block unauthorized access attempts.</p>\n<p><strong>Mitigation</strong><br>Enable and regularly review system logs to detect suspicious or unauthorized activity.</p>\n<p><strong>Mitigation</strong><br>Maintain secure, tested backups of the PLC and its configurations to minimize downtime in case of an incident.</p>\n<p><strong>Mitigation</strong><br>Continuously evaluate risks associated with running outdated firmware and adjust compensating measures accordingly.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-60140</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCTL request. This can lead to exposing sensitive information or causing the affected product to become unstable or unavailable.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-60140\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>AutomationDirect Productivity Suite</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>AutomationDirect</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>AutomationDirect Productivity Suite: &lt;=v4.6.2.2</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>AutomationDirect recommends that users update Productivity suite to v4.7.0.47 and above https://www.automationdirect.com/support/software-downloads.<br><a href=\"https://www.automationdirect.com/support/software-downloads\">https://www.automationdirect.com/support/software-downloads</a></p>\n<p><strong>Mitigation</strong><br>If the update cannot be applied right away, the following compensating controls are recommended until the upgrade can be performed.</p>\n<p><strong>Mitigation</strong><br>Disconnect the engineering workstation from external networks (e.g., the internet or corporate LAN) to reduce exposure.</p>\n<p><strong>Mitigation</strong><br>Use only trusted, dedicated internal networks or air-gapped systems for device communication.</p>\n<p><strong>Mitigation</strong><br>Restrict both physical and logical access to authorized personnel only.</p>\n<p><strong>Mitigation</strong><br>Configure whitelisting so that only trusted, pre-approved applications are allowed to run. Block any unauthorized software.</p>\n<p><strong>Mitigation</strong><br>Use antivirus or EDR tools and configure host-based firewalls to block unauthorized access attempts.</p>\n<p><strong>Mitigation</strong><br>Enable and regularly review system logs to detect suspicious or unauthorized activity.</p>\n<p><strong>Mitigation</strong><br>Maintain secure, tested backups of the PLC and its configurations to minimize downtime in case of an incident.</p>\n<p><strong>Mitigation</strong><br>Continuously evaluate risks associated with running outdated firmware and adjust compensating measures accordingly.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.1</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H\">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-57896</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCTL request. This could lead to limited information disclosure or disruption of the affected product.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-57896\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>AutomationDirect Productivity Suite</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>AutomationDirect</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>AutomationDirect Productivity Suite: &lt;=v4.6.2.2</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>AutomationDirect recommends that users update Productivity suite to v4.7.0.47 and above https://www.automationdirect.com/support/software-downloads.<br><a href=\"https://www.automationdirect.com/support/software-downloads\">https://www.automationdirect.com/support/software-downloads</a></p>\n<p><strong>Mitigation</strong><br>If the update cannot be applied right away, the following compensating controls are recommended until the upgrade can be performed.</p>\n<p><strong>Mitigation</strong><br>Disconnect the engineering workstation from external networks (e.g., the internet or corporate LAN) to reduce exposure.</p>\n<p><strong>Mitigation</strong><br>Use only trusted, dedicated internal networks or air-gapped systems for device communication.</p>\n<p><strong>Mitigation</strong><br>Restrict both physical and logical access to authorized personnel only.</p>\n<p><strong>Mitigation</strong><br>Configure whitelisting so that only trusted, pre-approved applications are allowed to run. Block any unauthorized software.</p>\n<p><strong>Mitigation</strong><br>Use antivirus or EDR tools and configure host-based firewalls to block unauthorized access attempts.</p>\n<p><strong>Mitigation</strong><br>Enable and regularly review system logs to detect suspicious or unauthorized activity.</p>\n<p><strong>Mitigation</strong><br>Maintain secure, tested backups of the PLC and its configurations to minimize downtime in case of an incident.</p>\n<p><strong>Mitigation</strong><br>Continuously evaluate risks associated with running outdated firmware and adjust compensating measures accordingly.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.1</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H\">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-60073</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An out-of-bounds read in the Productivity Suite allows a physical attacker to control the length of data sent to a USB device. This can lead to a system crash or disclosure of kernel memory.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-60073\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>AutomationDirect Productivity Suite</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>AutomationDirect</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>AutomationDirect Productivity Suite: &lt;=v4.6.2.2</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>AutomationDirect recommends that users update Productivity suite to v4.7.0.47 and above https://www.automationdirect.com/support/software-downloads.<br><a href=\"https://www.automationdirect.com/support/software-downloads\">https://www.automationdirect.com/support/software-downloads</a></p>\n<p><strong>Mitigation</strong><br>If the update cannot be applied right away, the following compensating controls are recommended until the upgrade can be performed.</p>\n<p><strong>Mitigation</strong><br>Disconnect the engineering workstation from external networks (e.g., the internet or corporate LAN) to reduce exposure.</p>\n<p><strong>Mitigation</strong><br>Use only trusted, dedicated internal networks or air-gapped systems for device communication.</p>\n<p><strong>Mitigation</strong><br>Restrict both physical and logical access to authorized personnel only.</p>\n<p><strong>Mitigation</strong><br>Configure whitelisting so that only trusted, pre-approved applications are allowed to run. Block any unauthorized software.</p>\n<p><strong>Mitigation</strong><br>Use antivirus or EDR tools and configure host-based firewalls to block unauthorized access attempts.</p>\n<p><strong>Mitigation</strong><br>Enable and regularly review system logs to detect suspicious or unauthorized activity.</p>\n<p><strong>Mitigation</strong><br>Maintain secure, tested backups of the PLC and its configurations to minimize downtime in case of an incident.</p>\n<p><strong>Mitigation</strong><br>Continuously evaluate risks associated with running outdated firmware and adjust compensating measures accordingly.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H\">CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.2</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-61378</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A divide-by-zero vulnerability in the Productivity Suite allows a local attacker to cause a division by zero leading to a system crash.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-61378\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>AutomationDirect Productivity Suite</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>AutomationDirect</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>AutomationDirect Productivity Suite: &lt;=v4.6.2.2</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>AutomationDirect recommends that users update Productivity suite to v4.7.0.47 and above https://www.automationdirect.com/support/software-downloads.<br><a href=\"https://www.automationdirect.com/support/software-downloads\">https://www.automationdirect.com/support/software-downloads</a></p>\n<p><strong>Mitigation</strong><br>If the update cannot be applied right away, the following compensating controls are recommended until the upgrade can be performed.</p>\n<p><strong>Mitigation</strong><br>Disconnect the engineering workstation from external networks (e.g., the internet or corporate LAN) to reduce exposure.</p>\n<p><strong>Mitigation</strong><br>Use only trusted, dedicated internal networks or air-gapped systems for device communication.</p>\n<p><strong>Mitigation</strong><br>Restrict both physical and logical access to authorized personnel only.</p>\n<p><strong>Mitigation</strong><br>Configure whitelisting so that only trusted, pre-approved applications are allowed to run. Block any unauthorized software.</p>\n<p><strong>Mitigation</strong><br>Use antivirus or EDR tools and configure host-based firewalls to block unauthorized access attempts.</p>\n<p><strong>Mitigation</strong><br>Enable and regularly review system logs to detect suspicious or unauthorized activity.</p>\n<p><strong>Mitigation</strong><br>Maintain secure, tested backups of the PLC and its configurations to minimize downtime in case of an incident.</p>\n<p><strong>Mitigation</strong><br>Continuously evaluate risks associated with running outdated firmware and adjust compensating measures accordingly.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/369.html\">CWE-369 Divide By Zero</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Luca Borzacchiello of Nozomi Networks reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-16</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-16</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 16 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 16 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-01",
        "title": "Rockwell Automation Arena",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation these vulnerabilities could allow an attacker to execute arbitrary code in the context of the current process.</strong></p>\n<p>The following versions of Rockwell Automation Arena are affected:</p>\n<ul>\n<li>Arena &lt;=V17.00.00 (CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, CVE-2026-8314)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.8</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation Arena</td>\n<td>Out-of-bounds Write</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-8085</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A security issue exists within Arena Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-8085\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation Arena</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation Arena: &lt;=V17.00.00</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Rockwell Automation recommends users to update to V17.00.01</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-8312</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A security issue exists within Arena Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-8312\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation Arena</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation Arena: &lt;=V17.00.00</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Rockwell Automation recommends users to update to V17.00.01</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-8313</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A security issue exists within Arena Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-8313\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation Arena</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation Arena: &lt;=V17.00.00</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Rockwell Automation recommends users to update to V17.00.01</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-8314</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A security issue exists within Arena Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-8314\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation Arena</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation Arena: &lt;=V17.00.00</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Rockwell Automation recommends users to update to V17.00.01</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Michael Heinzl reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-16</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-16</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 16 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 16 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/07/16/cisa-adds-three-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Three Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/07/16/cisa-adds-three-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added three new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-25089\" target=\"_blank\">CVE-2026-25089</a> Fortinet FortiSandbox OS Command Injection Vulnerability &nbsp;</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-39808\" target=\"_blank\">CVE-2026-39808</a> Fortinet FortiSandbox OS Command Injection Vulnerability &nbsp;</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-58644\" target=\"_blank\">CVE-2026-58644</a> Microsoft SharePoint Deserialization of Untrusted Data Vulnerability</li>\n</ul>\n<p>These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Thu, 16 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 16 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-06",
        "title": "Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-06",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-06.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition.</strong></p>\n<p>The following versions of Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix are affected:</p>\n<ul>\n<li>CompactLogix 5370 &lt;=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)</li>\n<li>Compact GuardLogix 5370 &lt;=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)</li>\n<li>ControlLogix 5570 &lt;=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)</li>\n<li>GuardLogix 5570 &lt;=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)</li>\n<li>CompactLogix 5380 &lt;=V34.012 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)</li>\n<li>CompactLogix 5380 &lt;=V35.011 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)</li>\n<li>Compact GuardLogix 5380 &lt;=V34.012 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)</li>\n<li>Compact GuardLogix 5380 &lt;=V35.011 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)</li>\n<li>CompactLogix 5480 &lt;=V34.012 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)</li>\n<li>CompactLogix 5480 &lt;=V35.011 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)</li>\n<li>ControlLogix 5580 &lt;=V34.012 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)</li>\n<li>ControlLogix 5580 &lt;=V35.011 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)</li>\n<li>GuardLogix 5580 &lt;=V34.012 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)</li>\n<li>GuardLogix 5580 &lt;=V35.011 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)</li>\n<li>CompactLogix 5380 Recovery Image &lt;=1.072 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)</li>\n<li>Compact GuardLogix 5380 Recovery Image &lt;=1.072 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)</li>\n<li>CompactLogix 5480 Recovery Image &lt;=1.072 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)</li>\n<li>ControlLogix 5580 Recovery Image &lt;=1.072 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)</li>\n<li>GuardLogix 5580 Recovery Image &lt;=1.072 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.6</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix</td>\n<td>Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-12011</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service issue exists in 5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, causing the device to enter a major non-recoverable fault (MNRF).</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-12011\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation CompactLogix 5370: &lt;=V35.015, Rockwell Automation Compact GuardLogix 5370: &lt;=V35.015, Rockwell Automation ControlLogix 5570: &lt;=V35.015, Rockwell Automation GuardLogix 5570: &lt;=V35.015, Rockwell Automation CompactLogix 5380: &lt;=V34.012, Rockwell Automation CompactLogix 5380: &lt;=V35.011, Rockwell Automation Compact GuardLogix 5380: &lt;=V34.012, Rockwell Automation Compact GuardLogix 5380: &lt;=V35.011, Rockwell Automation CompactLogix 5480: &lt;=V34.012, Rockwell Automation CompactLogix 5480: &lt;=V35.011, Rockwell Automation ControlLogix 5580: &lt;=V34.012, Rockwell Automation ControlLogix 5580: &lt;=V35.011, Rockwell Automation GuardLogix 5580: &lt;=V34.012, Rockwell Automation GuardLogix 5580: &lt;=V35.011, Rockwell Automation CompactLogix 5380 Recovery Image: &lt;=1.072, Rockwell Automation Compact GuardLogix 5380 Recovery Image: &lt;=1.072, Rockwell Automation CompactLogix 5480 Recovery Image: &lt;=1.072, Rockwell Automation ControlLogix 5580 Recovery Image: &lt;=1.072, Rockwell Automation GuardLogix 5580 Recovery Image: &lt;=1.072</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommend updating to the following: CompactLogix 5370: Update to V35.016, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>Compact GuardLogix 5370: Update to V35.016, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>ControlLogix 5570: Update to V35.016, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>GuardLogix 5570: Update to V35.016, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>CompactLogix 5380: Update to V34.014, V35.013, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>Compact GuardLogix 5380: Update to V34.014, V35.013, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>CompactLogix 5480: Update to V34.014, V35.013, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>ControlLogix 5580: Update to V34.014, V35.013, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>GuardLogix 5580: Update to V34.014, V35.013, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>CompactLogix 5380 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed</p>\n<p><strong>Vendor fix</strong><br>Compact GuardLogix 5380 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed</p>\n<p><strong>Vendor fix</strong><br>CompactLogix 5480 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed</p>\n<p><strong>Vendor fix</strong><br>ControlLogix 5580 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed</p>\n<p><strong>Vendor fix</strong><br>GuardLogix 5580 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/120.html\">CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.2</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-12012</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major nonrecoverable fault (MNRF).</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-12012\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation CompactLogix 5370: &lt;=V35.015, Rockwell Automation Compact GuardLogix 5370: &lt;=V35.015, Rockwell Automation ControlLogix 5570: &lt;=V35.015, Rockwell Automation GuardLogix 5570: &lt;=V35.015, Rockwell Automation CompactLogix 5380: &lt;=V34.012, Rockwell Automation CompactLogix 5380: &lt;=V35.011, Rockwell Automation Compact GuardLogix 5380: &lt;=V34.012, Rockwell Automation Compact GuardLogix 5380: &lt;=V35.011, Rockwell Automation CompactLogix 5480: &lt;=V34.012, Rockwell Automation CompactLogix 5480: &lt;=V35.011, Rockwell Automation ControlLogix 5580: &lt;=V34.012, Rockwell Automation ControlLogix 5580: &lt;=V35.011, Rockwell Automation GuardLogix 5580: &lt;=V34.012, Rockwell Automation GuardLogix 5580: &lt;=V35.011, Rockwell Automation CompactLogix 5380 Recovery Image: &lt;=1.072, Rockwell Automation Compact GuardLogix 5380 Recovery Image: &lt;=1.072, Rockwell Automation CompactLogix 5480 Recovery Image: &lt;=1.072, Rockwell Automation ControlLogix 5580 Recovery Image: &lt;=1.072, Rockwell Automation GuardLogix 5580 Recovery Image: &lt;=1.072</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommend updating to the following: CompactLogix 5370: Update to V35.016, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>Compact GuardLogix 5370: Update to V35.016, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>ControlLogix 5570: Update to V35.016, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>GuardLogix 5570: Update to V35.016, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>CompactLogix 5380: Update to V34.014, V35.013, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>Compact GuardLogix 5380: Update to V34.014, V35.013, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>CompactLogix 5480: Update to V34.014, V35.013, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>ControlLogix 5580: Update to V34.014, V35.013, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>GuardLogix 5580: Update to V34.014, V35.013, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>CompactLogix 5380 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed</p>\n<p><strong>Vendor fix</strong><br>Compact GuardLogix 5380 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed</p>\n<p><strong>Vendor fix</strong><br>CompactLogix 5480 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed</p>\n<p><strong>Vendor fix</strong><br>ControlLogix 5580 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed</p>\n<p><strong>Vendor fix</strong><br>GuardLogix 5580 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/120.html\">CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.2</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-11698</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF).</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-11698\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation CompactLogix 5370: &lt;=V35.015, Rockwell Automation Compact GuardLogix 5370: &lt;=V35.015, Rockwell Automation ControlLogix 5570: &lt;=V35.015, Rockwell Automation GuardLogix 5570: &lt;=V35.015, Rockwell Automation CompactLogix 5380: &lt;=V34.012, Rockwell Automation CompactLogix 5380: &lt;=V35.011, Rockwell Automation Compact GuardLogix 5380: &lt;=V34.012, Rockwell Automation Compact GuardLogix 5380: &lt;=V35.011, Rockwell Automation CompactLogix 5480: &lt;=V34.012, Rockwell Automation CompactLogix 5480: &lt;=V35.011, Rockwell Automation ControlLogix 5580: &lt;=V34.012, Rockwell Automation ControlLogix 5580: &lt;=V35.011, Rockwell Automation GuardLogix 5580: &lt;=V34.012, Rockwell Automation GuardLogix 5580: &lt;=V35.011, Rockwell Automation CompactLogix 5380 Recovery Image: &lt;=1.072, Rockwell Automation Compact GuardLogix 5380 Recovery Image: &lt;=1.072, Rockwell Automation CompactLogix 5480 Recovery Image: &lt;=1.072, Rockwell Automation ControlLogix 5580 Recovery Image: &lt;=1.072, Rockwell Automation GuardLogix 5580 Recovery Image: &lt;=1.072</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommend updating to the following: CompactLogix 5370: Update to V35.016, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>Compact GuardLogix 5370: Update to V35.016, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>ControlLogix 5570: Update to V35.016, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>GuardLogix 5570: Update to V35.016, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>CompactLogix 5380: Update to V34.014, V35.013, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>Compact GuardLogix 5380: Update to V34.014, V35.013, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>CompactLogix 5480: Update to V34.014, V35.013, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>ControlLogix 5580: Update to V34.014, V35.013, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>GuardLogix 5580: Update to V34.014, V35.013, V36.011 and later</p>\n<p><strong>Vendor fix</strong><br>CompactLogix 5380 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed</p>\n<p><strong>Vendor fix</strong><br>Compact GuardLogix 5380 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed</p>\n<p><strong>Vendor fix</strong><br>CompactLogix 5480 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed</p>\n<p><strong>Vendor fix</strong><br>ControlLogix 5580 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed</p>\n<p><strong>Vendor fix</strong><br>GuardLogix 5580 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/120.html\">CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.2</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-16</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-16</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 16 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 16 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-02",
        "title": "Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.</strong></p>\n<p>The following versions of Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT are affected:</p>\n<ul>\n<li>1756-EN3 &lt;=V12.001 (CVE-2026-9653)</li>\n<li>1756-EN2 &lt;=V12.001 (CVE-2026-9653)</li>\n<li>1756-ENBT V6.006 (CVE-2026-9653)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT</td>\n<td>Improper Validation of Integrity Check Value</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-9653</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9653\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation 1756-EN3: &lt;=V12.001, Rockwell Automation 1756-EN2: &lt;=V12.001, Rockwell Automation 1756-ENBT: V6.006</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users take the following actions: 1756-EN3: Update to V12.002</p>\n<p><strong>Vendor fix</strong><br>1756-EN2: Update to V12.002</p>\n<p><strong>Vendor fix</strong><br>1756-ENBT: Product is discontinued, fix is unavailable</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/354.html\">CWE-354 Improper Validation of Integrity Check Value</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Tyler Lentz of Idaho National Laboratory reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-16</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-16</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 16 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 16 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-09",
        "title": "Rockwell Automation FactoryTalk DataMosaix",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-09",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-09.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious scripts on the server.</strong></p>\n<p>The following versions of Rockwell Automation FactoryTalk DataMosaix are affected:</p>\n<ul>\n<li>DataMosaix Private Cloud &lt;=8.02 (CVE-2026-9292)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 6.1</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation FactoryTalk DataMosaix</td>\n<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-9292</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A Stored Cross-Site Scripting security issue exists within FactoryTalk DataMosaix Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on the server. This vulnerability can result in the execution of malicious JavaScript when other users access the affected page, potentially allowing for account takeover, credential theft, or redirection to a malicious website.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9292\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation FactoryTalk DataMosaix</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation DataMosaix Private Cloud: &lt;=8.02</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users to upgrade to the following: DataMosaix Private Cloud versions 8.03 or later.</p>\n<p><strong>Mitigation</strong><br>Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight).<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information, see Rockwell Automation Security Advisory SD1787 (https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1787.html).<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1787.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1787.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/79.html\">CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.1</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N\">CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.4</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-16</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-16</td>\n<td>1</td>\n<td>Initial Republication of Rockwell Automation Security Advisory SD1787</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 16 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 16 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-07",
        "title": "SALTO ProAccess Space",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-07",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-07.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability allows an authenticated attacker to escalate privileges and access spaces outside their assigned partition, within the same Salto ProAccess Space installation or system. Exploitation requires valid authenticated operator credentials and the partition feature to be enabled; installations without partitioning are not affected.</strong></p>\n<p>The following versions of SALTO ProAccess Space are affected:</p>\n<ul>\n<li>ProAccess Space &lt;6.13 (CVE-2026-11889)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 6.5</td>\n<td>SALTO</td>\n<td>SALTO ProAccess Space</td>\n<td>Authorization Bypass Through User-Controlled Key</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Commercial Facilities, Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Spain</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-11889</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation attack that could allow an authorized attacker to access any space managed by the affected product.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-11889\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>SALTO ProAccess Space</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>SALTO</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SALTO ProAccess Space: &lt;6.13</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users of SALTO ProAccess using the tenancy feature should upgrade to version 6.13.</p>\n<p><strong>Vendor fix</strong><br>To further enhance security after applying the update: 1. Operate ProAccess Space on a protected internal network and avoid exposing it directly to the Internet. 2. Restrict operator-level accounts to the minimum required and apply least-privilege principles. 3. If feasible, disable the partitioning feature and operate under a single partition. 4. When strong tenant separation is required, consider running separate Space instances (isolated environments) rather than relying solely on logical partitioning.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/639.html\">CWE-639 Authorization Bypass Through User-Controlled Key</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Bernhard Lorenz of Limes Security reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-16</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-16</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 16 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 16 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-08",
        "title": "Rockwell Automation Flex 5000 Adapter",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-08",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-08.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition on the affected product.</strong></p>\n<p>The following versions of Rockwell Automation Flex 5000 Adapter are affected:</p>\n<ul>\n<li>Flex 5000 Adapter 6.011 (CVE-2026-12659)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation Flex 5000 Adapter</td>\n<td>Double Free</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-12659</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets sent to the adapter. A power cycle is required to recover the module and associated I/O.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-12659\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation Flex 5000 Adapter</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation Flex 5000 Adapter: 6.011</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users to upgrade to the following: Flex 5000 Adapter version 6.012.</p>\n<p><strong>Mitigation</strong><br>Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight).<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information, see Rockwell Automation Security Advisory SD1789 (https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1789.html).<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1789.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1789.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/415.html\">CWE-415 Double Free</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-16</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-16</td>\n<td>1</td>\n<td>Initial Republication of Rockwell Automation Security Advisory SD1789</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 16 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 16 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-05",
        "title": "Siemens SICAM 8",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-05",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-05.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: - SICAM A8000 Device firmware - CPCI85 for CP-8031/CP-8050 - SICORE for CP-8010/CP-8012 - SICAM EGS Device firmware - CPCI85 - SICAM S8000 - SICORE Siemens has released new versions for the affected products and recommends to update to the latest versions.</strong></p>\n<p>The following versions of Siemens SICAM 8 are affected:</p>\n<ul>\n<li>CPCI85 Central Processing/Communication vers:intdot/&lt;26.20 (CVE-2026-54798, CVE-2026-54799, CVE-2026-54800, CVE-2026-54801)</li>\n<li>SICORE Base system vers:intdot/&lt;26.20.0 (CVE-2026-54798, CVE-2026-54799, CVE-2026-54800, CVE-2026-54801)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.2</td>\n<td>Siemens</td>\n<td>Siemens SICAM 8</td>\n<td>Active Debug Code, Initialization of a Resource with an Insecure Default, Unverified Password Change</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-54798</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected application includes a debugging interface that is accessible through HTTP endpoints. This could allow an authenticated attacker to disrupt the system by crashing the web process causing denial of service conditions.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-54798\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SICAM 8</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CPCI85 Central Processing/Communication &lt; V26.20, SICORE Base system &lt; V26.20.0</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V26.20 or later version The firmware CPCI85 V26.20 is present within \u201cCP-8031/CP-8050 Package\u201d V26.20 https://support.industry.siemens.com/cs/ww/en/view/109804985/ and also within \u201cSICAM EGS Package\u201d V26.20 https://support.industry.siemens.com/cs/document/109972536/</p>\n<p><strong>Vendor fix</strong><br>Update to V26.20.0 or later version The firmware SICORE V26.20.0 is present within \u201cCP-8010/CP-8012 Package\u201d V26.20 https://support.industry.siemens.com/cs/ww/en/view/109972894/ and also within \u201cSICAM S8000 Package\u201d V26.20 https://support.industry.siemens.com/cs/document/109818240</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/489.html\">CWE-489 Active Debug Code</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-54799</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected application contains a vulnerability in its firmware update mechanism's signature validation process. This could allow an attacker to install malicious firmware, leading to persistent code execution and system compromise.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-54799\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SICAM 8</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CPCI85 Central Processing/Communication &lt; V26.20, SICORE Base system &lt; V26.20.0</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V26.20 or later version The firmware CPCI85 V26.20 is present within \u201cCP-8031/CP-8050 Package\u201d V26.20 https://support.industry.siemens.com/cs/ww/en/view/109804985/ and also within \u201cSICAM EGS Package\u201d V26.20 https://support.industry.siemens.com/cs/document/109972536/</p>\n<p><strong>Vendor fix</strong><br>Update to V26.20.0 or later version The firmware SICORE V26.20.0 is present within \u201cCP-8010/CP-8012 Package\u201d V26.20 https://support.industry.siemens.com/cs/ww/en/view/109972894/ and also within \u201cSICAM S8000 Package\u201d V26.20 https://support.industry.siemens.com/cs/document/109818240</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/489.html\">CWE-489 Active Debug Code</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.7</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-54800</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an attacker to gain unauthorized access and control over critical system functions.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-54800\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SICAM 8</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CPCI85 Central Processing/Communication &lt; V26.20, SICORE Base system &lt; V26.20.0</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V26.20 or later version The firmware CPCI85 V26.20 is present within \u201cCP-8031/CP-8050 Package\u201d V26.20 https://support.industry.siemens.com/cs/ww/en/view/109804985/ and also within \u201cSICAM EGS Package\u201d V26.20 https://support.industry.siemens.com/cs/document/109972536/</p>\n<p><strong>Vendor fix</strong><br>Update to V26.20.0 or later version The firmware SICORE V26.20.0 is present within \u201cCP-8010/CP-8012 Package\u201d V26.20 https://support.industry.siemens.com/cs/ww/en/view/109972894/ and also within \u201cSICAM S8000 Package\u201d V26.20 https://support.industry.siemens.com/cs/document/109818240</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/1188.html\">CWE-1188 Initialization of a Resource with an Insecure Default</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>4.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N\">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-54801</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected application contains insufficient validation of authentication credentials when processing administrative account modifications through the web API. This could allow an authenticated attacker to bypass security controls and gain unauthorized elevated privileges.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-54801\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SICAM 8</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CPCI85 Central Processing/Communication &lt; V26.20, SICORE Base system &lt; V26.20.0</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V26.20 or later version The firmware CPCI85 V26.20 is present within \u201cCP-8031/CP-8050 Package\u201d V26.20 https://support.industry.siemens.com/cs/ww/en/view/109804985/ and also within \u201cSICAM EGS Package\u201d V26.20 https://support.industry.siemens.com/cs/document/109972536/</p>\n<p><strong>Vendor fix</strong><br>Update to V26.20.0 or later version The firmware SICORE V26.20.0 is present within \u201cCP-8010/CP-8012 Package\u201d V26.20 https://support.industry.siemens.com/cs/ww/en/view/109972894/ and also within \u201cSICAM S8000 Package\u201d V26.20 https://support.industry.siemens.com/cs/document/109818240</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/620.html\">CWE-620 Unverified Password Change</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>Operators of critical power systems (e.g. TSOs or DSOs) worldwide are usually required by regulations to build resilience into the power grids by applying multi-level redundant secondary protection schemes. It is therefore recommended that the operators check whether appropriate resilient protection measures are in place. The risk of cyber incidents impacting the grid's reliability can thus be minimized by virtue of the grid design. Siemens strongly recommends applying the provided security updates using the corresponding tooling and documented procedures made available with the product. If supported by the product, an automated means to apply the security updates across multiple product instances may be used. Siemens strongly recommends prior validation of any security update before being applied, and supervision by trained staff of the update process in the target environment. As a general security measure Siemens strongly recommends to protect network access with appropriate mechanisms (e.g. firewalls, segmentation, VPN). It is advised to configure the environment according to our operational guidelines in order to run the devices in a protected IT environment. Recommended security guidelines can be found at: https://www.siemens.com/gridsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact Siemens: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens SSA-229470 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-09</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-09</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-07-16</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens SSA-229470 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 16 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 16 Jul 26 12:00:00 +0000"
    }
]