[
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01",
        "title": "Johnson Controls C-CURE 9000 and Victor application server (Update A)",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution.</strong></p>\n<p>The following versions of Johnson Controls C-CURE 9000 and Victor application server (Update A) are affected:</p>\n<ul>\n<li>C-CURE 9000 &lt;=v3.10.1 (CVE-2026-21655)</li>\n<li>victor Application Server &lt;=v4.10 (CVE-2026-21655)</li>\n<li>victor &lt;=v7.0 (CVE-2026-21655)</li>\n<li>victor Web</li>\n<li>victor Web &lt;=v7.1 (CVE-2026-34496)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.6</td>\n<td>Johnson Controls</td>\n<td>Johnson Controls C-CURE 9000 and Victor application server (Update A)</td>\n<td>Server-Side Request Forgery (SSRF), Execution with Unnecessary Privileges</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Ireland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-21655</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Under certain circumstances, successful exploitation of this vulnerability could allow an unauthenticated attacker on an adjacent network to achieve arbitrary code execution on the C-CURE 9000, victor application server and victor, as well as connected clients (e.g., workstations of physical security personnel). Such attack could impact physical security controls.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-21655\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls C-CURE 9000 and Victor application server (Update A)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls C-CURE 9000: &lt;=v3.10.1, Johnson Controls victor Application Server: &lt;=v4.10, Johnson Controls victor: &lt;=v7.0</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Johnson Controls recommends the following upgrades to address the vulnerable deserialization path: Upgrade to C-CURE 9000 v3.20 or later</p>\n<p><strong>Vendor fix</strong><br>Johnson Controls recommends the following upgrades to address the vulnerable deserialization path: Upgrade victor Application Server to v4.20 or later</p>\n<p><strong>Vendor fix</strong><br>Johnson Controls recommends the following upgrades to address the vulnerable deserialization path: Upgrade victor to v8.0 or later</p>\n<p><strong>Mitigation</strong><br>Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation. Johnson Controls recommends following both steps in the mitigation guidance. However, until an upgrade is completed, the defensive measures outlined will reduce the attack surface: Firewall / access control lists - Implement strict firewall rules to block all unnecessary inbound connections to port 8999 from untrusted network segments. Intrusion detection / prevention - Deploy IDS/IPS signatures tuned to detect known .NET deserialization exploit payloads (e.g., ysoserial.net patterns) targeting port 8999. Application whitelisting - Enforce application whitelisting on application server hosts to prevent unauthorized executables from being launched by the server process. Least privilege - Ensure the application server process runs with the minimum privileges necessary, reducing the impact of successful exploitation. Monitor and audit - Enable detailed logging on application server hosts and monitor for anomalous process creation by SoftwareHouse.CrossFire.Server.exe. Disable unnecessary services - If the ClientConnectionManager_NF.SynchronousServerNotification callback interface is not required, disable or restrict it to reduce attack surface.</p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories\">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/918.html\">CWE-918 Server-Side Request Forgery (SSRF)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.6</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.4</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-21653</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Under certain circumstances, successful exploitation of this vulnerability could allow an attacker to forge server-side HTTP requests from the victor Web application. This could be leveraged to interact with internal services running on the host or accessible on the local network, potentially leading to unauthorized information disclosure or lateral movement within the network.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-21653\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls C-CURE 9000 and Victor application server (Update A)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls victor Web: &lt;v7.0</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Johnson Controls recommends the following upgrades to address the vulnerable deserialization path: Upgrade victor Application Server to v4.20 or later</p>\n<p><strong>Vendor fix</strong><br>Johnson Controls recommends the following upgrades to address the vulnerable deserialization path: Upgrade victor to v8.0 or later</p>\n<p><strong>Mitigation</strong><br>Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation. Johnson Controls recommends following both steps in the mitigation guidance. However, until an upgrade is completed, the defensive measures outlined will reduce the attack surface: Firewall / access control lists - Implement strict firewall rules to block all unnecessary inbound connections to port 8999 from untrusted network segments. Intrusion detection / prevention - Deploy IDS/IPS signatures tuned to detect known .NET deserialization exploit payloads (e.g., ysoserial.net patterns) targeting port 8999. Application whitelisting - Enforce application whitelisting on application server hosts to prevent unauthorized executables from being launched by the server process. Least privilege - Ensure the application server process runs with the minimum privileges necessary, reducing the impact of successful exploitation. Monitor and audit - Enable detailed logging on application server hosts and monitor for anomalous process creation by SoftwareHouse.CrossFire.Server.exe. Disable unnecessary services - If the ClientConnectionManager_NF.SynchronousServerNotification callback interface is not required, disable or restrict it to reduce attack surface.</p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories\">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/918.html\">CWE-918 Server-Side Request Forgery (SSRF)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.6</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.4</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-34496</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Under certain circumstances, successful exploitation of this vulnerability could result in low privilege users accessing unauthorized pages such as Users and Logs. Successful exploitation could allow an attacker to view sensitive system information, user account details, and audit logs beyond their intended access level, potentially enabling further attacks or unauthorized administrative actions.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-34496\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls C-CURE 9000 and Victor application server (Update A)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls victor Web: &lt;=v7.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Johnson Controls recommends the following upgrades to address the vulnerable deserialization path: Upgrade victor Application Server to v4.20 or later</p>\n<p><strong>Vendor fix</strong><br>Johnson Controls recommends the following upgrades to address the vulnerable deserialization path: Upgrade victor to v8.0 or later</p>\n<p><strong>Mitigation</strong><br>Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation. Johnson Controls recommends following both steps in the mitigation guidance. However, until an upgrade is completed, the defensive measures outlined will reduce the attack surface: Firewall / access control lists - Implement strict firewall rules to block all unnecessary inbound connections to port 8999 from untrusted network segments. Intrusion detection / prevention - Deploy IDS/IPS signatures tuned to detect known .NET deserialization exploit payloads (e.g., ysoserial.net patterns) targeting port 8999. Application whitelisting - Enforce application whitelisting on application server hosts to prevent unauthorized executables from being launched by the server process. Least privilege - Ensure the application server process runs with the minimum privileges necessary, reducing the impact of successful exploitation. Monitor and audit - Enable detailed logging on application server hosts and monitor for anomalous process creation by SoftwareHouse.CrossFire.Server.exe. Disable unnecessary services - If the ClientConnectionManager_NF.SynchronousServerNotification callback interface is not required, disable or restrict it to reduce attack surface.</p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories\">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/250.html\">CWE-250 Execution with Unnecessary Privileges</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Harrison Neal reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-23</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-23</td>\n<td>1</td>\n<td>Initial Republication of Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16.</td>\n</tr>\n<tr>\n<td>2026-08-11</td>\n<td>2</td>\n<td>Update A - Made changes to affected products and mitigations.</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 11 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 11 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-02",
        "title": "Pulsetto Vagus Nerve Stimulator",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-223-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to use hidden commands to disable electrical safety mechanisms or modify other stimulation output settings.</strong></p>\n<p>The following versions of Pulsetto Vagus Nerve Stimulator are affected:</p>\n<ul>\n<li>Pulsetto Vagus Nerve Stimulator vers:all/* (CVE-2026-18844)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.1</td>\n<td>Pulsetto</td>\n<td>Pulsetto Vagus Nerve Stimulator</td>\n<td>Hidden Functionality</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Healthcare and Public Health</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Lithuania</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-18844</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The firmware of the affected product accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully processed by the device when it is powered on.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-18844\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Pulsetto Vagus Nerve Stimulator</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Pulsetto</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Pulsetto Pulsetto Vagus Nerve Stimulator: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Pulsetto has not responded to requests to work with CISA to mitigate this vulnerability. Users are encouraged to reach out directly to Pulsetto for assistance at info@pulsetto.tech.<br><a href=\"mailto:info@pulsetto.tech\">mailto:info@pulsetto.tech</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/912.html\">CWE-912 Hidden Functionality</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>A.C. Buglione reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-11</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-11</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 11 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 11 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Three Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added three new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-20349\" target=\"_blank\">CVE-2026-20349</a> Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-68820\" target=\"_blank\">CVE-2026-68820</a> Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-72898\" target=\"_blank\">CVE-2026-72898</a> Metabase SQL Injection Vulnerability</li>\n</ul>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance</p>",
        "summary_is_html": true,
        "first_seen": "Tue, 11 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 11 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-01",
        "title": "Mira Hormone Monitor, Mira Android App",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-223-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token information, and obtain control of user accounts.</strong></p>\n<p>The following versions of Mira Hormone Monitor, Mira Android App are affected:</p>\n<ul>\n<li>Mira Monitor Firmware 1.7.1.47 (CVE-2026-66875, CVE-2026-66098, CVE-2026-67558, CVE-2026-67568, CVE-2026-68067, CVE-2026-66340, CVE-2026-64934, CVE-2026-66832)</li>\n<li>Mira Android App 4.5.15.4 (CVE-2026-66875, CVE-2026-66098, CVE-2026-67558, CVE-2026-67568, CVE-2026-68067, CVE-2026-66340, CVE-2026-64934, CVE-2026-66832)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.8</td>\n<td>Quanovate Tech Inc. (operating as Mira / Mira Care)</td>\n<td>Mira Hormone Monitor, Mira Android App</td>\n<td>Missing Authentication for Critical Function, Authentication Bypass by Spoofing, Use of Hard-coded Credentials, Weak Authentication, Improper Restriction of Excessive Authentication Attempts, Reliance on Untrusted Inputs in a Security Decision, Use of GET Request Method With Sensitive Query Strings</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Healthcare and Public Health</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-66875</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10\u201330 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or undocumented command opcodes, and passively track the user via a static random BLE address that never rotates.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-66875\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Mira Hormone Monitor, Mira Android App</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care)</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-66098</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootloader mode. An attacker could cause a denial-of-service condition or disrupt ovulation tracking and fertility monitoring workflow.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-66098\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Mira Hormone Monitor, Mira Android App</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care)</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-67558</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live session token information and inject forged hormone measurements into the victim's cloud record and clinical trend view.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-67558\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Mira Hormone Monitor, Mira Android App</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care)</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/290.html\">CWE-290 Authentication Bypass by Spoofing</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.4</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N\">CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-67568</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-67568\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Mira Hormone Monitor, Mira Android App</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care)</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/798.html\">CWE-798 Use of Hard-coded Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.1</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-68067</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-68067\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Mira Hormone Monitor, Mira Android App</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care)</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/1390.html\">CWE-1390 Weak Authentication</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-66340</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout after repeated failed login attempts. An attacker can use brute-force methods to obtain gain access to user accounts.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-66340\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Mira Hormone Monitor, Mira Android App</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care)</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/307.html\">CWE-307 Improper Restriction of Excessive Authentication Attempts</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-64934</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, without independently attesting the version from the device itself. An authenticated attacker could submit arbitrary firmware version strings for their own device, allowing them to evade vendor-side vulnerable-fleet analytics, suppress security update prompts to the user, and misrepresent patch-adoption metrics.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-64934\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Mira Hormone Monitor, Mira Android App</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care)</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/807.html\">CWE-807 Reliance on Untrusted Inputs in a Security Decision</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>4.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-66832</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent user identifier is included in the WebView's User-Agent header. Both are then transmitted to third-party web properties, referrer logs, and any JavaScript running in the WebView context.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-66832\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Mira Hormone Monitor, Mira Android App</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care)</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/598.html\">CWE-598 Use of GET Request Method With Sensitive Query Strings</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Gigi Xiaoqing Liu, Muzzammil Mohammed, Narmina Karimova, and En Mong of Northeastern University SPQR Lab reported these vulnerabilities to Quanovate Tech</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-11</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-11</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 11 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 11 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a",
        "title": "#StopRansomware: Gunra Ransomware",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a",
        "summary": "<h2><strong>Advisory at a Glance</strong></h2>\n<table>\n<tbody>\n<tr>\n<th>Title</th>\n<td>#StopRansomware: Gunra Ransomware</td>\n</tr>\n<tr>\n<th>Original Publication</th>\n<td>August 10, 2026</td>\n</tr>\n<tr>\n<th>Executive Summary</th>\n<td>Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid. This advisory provides technical details of the activity, as well as tailored detection and mitigation guidance to protect at-risk organizations from Gunra.</td>\n</tr>\n<tr>\n<th>Key Actions</th>\n<td>\n<ul type=\"square\">\n<li><strong>Prioritize patching known exploited vulnerabilities in internet-facing systems</strong>, including virtual private network (VPN) gateways and remote desktop protocol (RDP)-exposed infrastructure.</li>\n<li><strong>Implement and test offline, immutable backups</strong> stored in a physically separate, segmented location to ensure recoverability without ransom payment.</li>\n<li><strong>Segment networks</strong> to restrict lateral movement from an initially compromised device to other systems in the organization.</li>\n</ul>\n</td>\n</tr>\n<tr>\n<th>Indicators of Compromise</th>\n<td>\n<p>For a downloadable copy of indicators of compromise, see:</p>\n<ul type=\"square\">\n<li><a href=\"https://www.cisa.gov/sites/default/files/2026-08/AA26-222A-stix.xml\">AA26-222A STIX XML</a> (54 KB)</li>\n<li><a href=\"https://www.cisa.gov/sites/default/files/2026-08/AA26-222A-stix.json\">AA26-222A STIX JSON</a> (61 KB)</li>\n</ul>\n</td>\n</tr>\n<tr>\n<th>Intended Audience</th>\n<td>\n<p><strong>Organizations:</strong> Government, Critical Infrastructure</p>\n<p><strong>Sectors: </strong><a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/healthcare-and-public-health-sector\" title=\"Healthcare and Public Health\">Healthcare and public health</a>, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/financial-services-sector\" title=\"financial services\">financial services</a> and insurance, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/critical-manufacturing-sector\" title=\"critical manufacturing\">critical manufacturing</a> and construction, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/transportation-systems-sector\" title=\"transportation systems\">transportation systems</a> and logistics, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/government-services-facilities-sector\" title=\"government services and facilities\">government services and facilities</a>, utilities, academia, media and communications, retail, and professional and nonprofit services.</p>\n<p><strong>Roles:</strong> <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/cybersecurity-architecture\" target=\"_blank\" title=\"Cybersecurity architects\">Cybersecurity architects</a>, <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/defensive-cybersecurity\" target=\"_blank\" title=\"Defensive cybersecurity analysts\">defensive cybersecurity analysts</a>, <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/vulnerability-analysis\" target=\"_blank\" title=\"vulnerability analysts\">vulnerability analysts</a>, <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/systems-administration\" target=\"_blank\" title=\"systems administrators\">systems administrators</a>, and <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/systems-security-management\" target=\"_blank\" title=\"security systems managers\">security systems managers</a>.</p>\n</td>\n</tr>\n</tbody>\n</table>\n<h2><strong>Introduction</strong></h2>\n<p><strong>Note: </strong>This joint Cybersecurity Advisory is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit <a href=\"https://www.cisa.gov/stopransomware\" title=\"Stopransomware.gov\">stopransomware.gov</a> to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources.</p>\n<p>The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), Department of Defense Cyber Crime Center (DC3), National Security Agency (NSA), U.S. Secret Service (USSS), and Republic of Korea\u2019s National Police Agency (KNPA)\u2014hereafter referred to as \u201cthe authoring agencies\u201d\u2014are releasing this joint advisory to alert organizations to the emerging Gunra ransomware threat and to provide detection and mitigation guidance.</p>\n<p>Gunra first emerged in April 2025 as a sophisticated double-extortion ransomware variant derived from the leaked Conti<a href=\"#Note1\"><sup>1</sup></a> ransomware source code. As of early 2026, Gunra expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program advertised on dark web forums to financially motivated cybercriminals. Gunra actors demand ransom via a customized, Tor-based negotiation portal and threaten to publish exfiltrated data on a dedicated leak site (DLS) if victims do not comply.</p>\n<p>Gunra victims observed on the actors\u2019 DLS span organizations across multiple sectors in the Americas, Europe, Middle East, Africa, and the Asia-Pacific.<a href=\"#Note2\"><sup>2</sup></a> These sectors include:</p>\n<ul type=\"square\">\n<li><a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/healthcare-and-public-health-sector\" title=\"Healthcare and public health\">Healthcare and public health</a></li>\n<li><a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/financial-services-sector\" title=\"Financial services\">Financial services</a> and insurance</li>\n<li><a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/critical-manufacturing-sector\" title=\"Critical manufacturing\">Critical manufacturing</a> and construction</li>\n<li><a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/transportation-systems-sector\" title=\"Transportation systems\">Transportation systems</a> and logistics</li>\n<li><a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/government-services-facilities-sector\" title=\"Government services and facilities\">Government services and facilities</a></li>\n<li>Utilities</li>\n<li>Academia</li>\n<li>Media and communications</li>\n<li>Retail</li>\n<li>Professional and nonprofit services &nbsp;</li>\n</ul>\n<p>The authoring agencies encourage organizations to implement the recommendations in the <a href=\"#Mitigations\"><strong>Mitigations</strong></a> section of this advisory to mitigate cyber threats related to Gunra ransomware, including:</p>\n<ul>\n<li><strong>Prioritizing patching known exploited vulnerabilities</strong> in internet-facing systems, including virtual private network (VPN) gateways and remote desktop protocol (RDP)-exposed infrastructure.</li>\n<li><strong>Implementing and testing offline, immutable backups</strong> stored in a physically separate, segmented location to ensure recoverability without ransom payment.</li>\n<li><strong>Segmenting networks</strong> to restrict lateral movement from an initially compromised device to other systems in the organization.</li>\n</ul>\n<p>Download the PDF version of this report:</p>\n\n\n\n\n\n<div class=\"c-file\">\n    <div class=\"c-file__download\">\n    <a href=\"/sites/default/files/2026-08/aa26-222a-stopransomware-gunra-ransomware_508c.pdf\" class=\"c-file__link\" target=\"_blank\">AA26-222A StopRansomware Gunra Ransomware</a>\n    <span class=\"c-file__size\">(PDF,       1.07 MB\n  )</span>\n  </div>\n</div>\n<p>For a downloadable copy of IOCs, see:</p>\n\n\n\n\n\n<div class=\"c-file\">\n    <div class=\"c-file__download\">\n    <a href=\"/sites/default/files/2026-08/AA26-222A-stix.xml\" class=\"c-file__link\" target=\"_blank\">AA26-222A STIX XML</a>\n    <span class=\"c-file__size\">(XML,       54.18 KB\n  )</span>\n  </div>\n</div>\n\n\n\n\n\n<div class=\"c-file\">\n    <div class=\"c-file__download\">\n    <a href=\"/sites/default/files/2026-08/AA26-222A-stix.json\" class=\"c-file__link\" target=\"_blank\">AA26-222A STIX JSON</a>\n    <span class=\"c-file__size\">(JSON,       61.00 KB\n  )</span>\n  </div>\n</div>\n<h2><strong>Technical Details</strong></h2>\n<p><strong>Note:</strong> This advisory uses the <a href=\"https://attack.mitre.org/versions/v19/matrices/enterprise/\" target=\"_blank\" title=\"MITRE ATTACK Matrix for Enterprise\">MITRE ATT&amp;CK<sup>\u00ae</sup> Matrix for Enterprise</a> framework, version 19.1.&nbsp;See the<strong> </strong><a href=\"#MITRE\"><strong>MITRE ATT&amp;CK Tactics and Techniques</strong></a> section of this advisory for a table of the threat actors\u2019 activity mapped to MITRE ATT&amp;CK tactics and techniques.</p>\n<h3><strong>Overview</strong></h3>\n<p>The FBI originally observed Gunra ransomware in April 2025. The threat actors quickly established a DLS on the Tor network to list victims and publish exfiltrated data. As of January 2026, Gunra launched a formal RaaS affiliate program on dark web forums, providing affiliates with access to a management panel, a configurable ransomware builder, cross-platform locker payloads, and structured affiliate documentation.<a href=\"#Note3\"><sup>3</sup></a><sup> &nbsp;</sup>The FBI observed the group adopting new branding aliases (notably operating under the name Golden Community) to support this expansion. Gunra has further commercialized its platform by actively recruiting penetration testers and ethical hackers to serve as initial access brokers, offering a share of the ransom profits in exchange for enterprise network access.</p>\n<p>Based on FBI observations, Gunra actors use a traditional double-extortion model, exfiltrating sensitive victim data prior to encryption and threatening to publish the leaked data on their DLS unless the ransom is paid. Victims receive a ransom note in every affected directory guiding them to a Tor-based negotiation portal where they are assigned a Client ID and an initial password. Subsequently, victims receive instructions to contact the Gunra actors via qTox (an encrypted messaging application) to negotiate ransom payments within five to seven days. If the ransom is not paid, Gunra actors threaten to sell victim data on the DLS.</p>\n<p>Gunra ransomware appears to be based on, or significantly influenced by, the Conti ransomware source code leaked in 2022.<a href=\"#Note4\"><sup>4</sup></a> Initially, Gunra actors\u2019 campaigns focused on Windows environments; reporting in mid-2025 indicated the group introduced a Linux variant and moved toward broader cross-platform targeting.<a href=\"#Note5\"><sup>5</sup></a>&nbsp;</p>\n<h3><strong>Initial Access</strong></h3>\n<p>The FBI observed Gunra actors obtaining initial access [<a href=\"https://attack.mitre.org/versions/v19/tactics/TA0001/\" target=\"_blank\" title=\"TA0001\">TA0001</a>] primarily through the exploitation of known vulnerabilities in internet-facing devices [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1190/\" target=\"_blank\" title=\"T1190\">T1190</a>], including firewall and VPN appliances. The FBI observed exploits based on the following Common Vulnerabilities and Exposures (CVEs):</p>\n<ul type=\"square\">\n<li><a href=\"https://cve.org/CVERecord?id=CVE-2024-55591\" title=\"CVE-2024-55591\">CVE-2024-55591</a> [<a href=\"https://cwe.mitre.org/data/definitions/288.html\" target=\"_blank\" title=\"CWE-288: Authentication Bypass Using an Alternate Path or Channel\">CWE-288: Authentication Bypass Using an Alternate Path or Channel</a>]: Authentication bypass vulnerability affecting specific FortiOS and FortiProxy versions (see CVE record for more details).</li>\n<li><a href=\"https://cve.org/CVERecord?id=CVE-2025-24472\" title=\"CVE-2025-24472\">CVE-2025-24472</a> [<a href=\"https://cwe.mitre.org/data/definitions/288.html\" target=\"_blank\" title=\"CWE-288: Authentication Bypass Using an Alternate Path or Channel\">CWE-288: Authentication Bypass Using an Alternate Path or Channel</a>]: Authentication bypass vulnerability affecting specific FortiOS and FortiProxy versions (see CVE record for more details).</li>\n</ul>\n<p>Additionally, for initial access, KNPA observed Gunra actors exploit credential-exposure and Secure Shell (SSH) access control vulnerabilities in internet-facing VPN gateways to gain unauthorized remote access.</p>\n<h3><strong>Execution</strong></h3>\n<p>Gunra\u2019s Windows encryptor relies on native operating system (OS) application programming interfaces (APIs) to drive both execution and targeted encryption activity. The binary uses the <code>FindFirstFileW</code>/<code>FindNextFileW</code> API calls [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1106\" target=\"_blank\" title=\"T1106\">T1106</a>] to enumerate files and directories on all accessible drive letters (A through Z), enabling comprehensive traversal of the file system prior to encryption of victim data.</p>\n<h3><strong>Persistence, Privilege Escalation, Lateral Movement, and Command and Control</strong></h3>\n<p>Gunra actors regularly exploit Impacket libraries <code>psexec.py</code> and <code>smbclient.py</code> to move laterally across victim networks using the Server Message Block (SMB) protocol [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1021/002/\" target=\"_blank\" title=\"T1021.002\">T1021.002</a>].</p>\n<p>KPNA observed that against one victim, Gunra actors gained access to an administrator account for a secure socket layer (SSL)-VPN appliance [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1133/\" target=\"_blank\" title=\"T1133\">T1133</a>] by exploiting default credentials when account lockout controls were not present [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1078/001/\" target=\"_blank\" title=\"T1078.001\">T1078.001</a>][<a href=\"https://attack.mitre.org/versions/v19/techniques/T1078/002/\" target=\"_blank\" title=\"T1078.002\">T1078.002</a>]. The actors subsequently downloaded OpenSSH (an SSH tunneling tool) [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1105/\" target=\"_blank\" title=\"T1105\">T1105</a>] from an external attacker-controlled server to establish connections between compromised systems and maintain persistence in the victim\u2019s environment [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1572/\" target=\"_blank\" title=\"T1572\">T1572</a>].</p>\n<p>After gaining access to an internet-connected workstation used by a network administrator, Gunra actors accessed the SSL-VPN administrative web console and identified an unused account that had access to both the internet-facing and internal corporate networks. The actors modified the account configuration to bypass the mandatory password change requirement enforced on the account and subsequently leveraged it for malicious activities [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1098/\" target=\"_blank\" title=\"T1098\">T1098</a>].</p>\n<p>Using stolen session information, Gunra actors gained initial access to the internal virtual desktop infrastructure (VDI) environment and conducted lateral movement via RDP [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1021/001/\" target=\"_blank\" title=\"T1021.001\">T1021.001</a>]. The actors pivoted to multiple critical systems, including the VDI authentication web server, the internal Active Directory (AD) server, and virtual desktops assigned to IT personnel.</p>\n<h3><strong>Credential Access</strong></h3>\n<p>The FBI observed multiple instances of Gunra actors using <code>secretsdump.py</code> (another Impacket library) to conduct OS credential dumping [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1003/003\" target=\"_blank\" title=\"T1003.003\">T1003.003</a>] against compromised domain controllers to extract password hashes of user accounts from the NT Directory Services (NTDS) file. This enabled pass-the-hash [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1550/002/\" target=\"_blank\" title=\"T1550.002\">T1550.002</a>] or pass-the-ticket [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1550/003/\" target=\"_blank\" title=\"T1550.003\">T1550.003</a>] attacks for lateral movement into other privileged systems.</p>\n<p>For one victim, Gunra actors manipulated the network traffic control functionality of an SSL-VPN appliance to collect credentials and session information transmitted by users authenticating to a corporate VDI authentication portal [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1040/\" target=\"_blank\" title=\"T1040\">T1040</a>]. The actors then used stolen session cookies to conduct session hijacking [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1539/\" target=\"_blank\" title=\"T1539\">T1539</a>], impersonating legitimate users to gain access to the internal network.</p>\n<p>For the same victim, the Gunra actors modified authentication processing files on the corporate VDI authentication portal server to allow successful authentication when a specific, Gunra-designated one time password (OTP) value was entered, thereby enabling the continuous bypass of multi-factor authentication (MFA) [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1556/006/\" target=\"_blank\" title=\"T1556.006\">T1556.006</a>].</p>\n<p>Additionally, the actors accessed a Hiware system access control server via SSH from a compromised virtual desktop and stole a symmetric encryption key stored on the server. The stolen key enabled the actors to decrypt passwords for enterprise server accounts stored within the database [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1555/\" target=\"_blank\" title=\"T1555\">T1555</a>] and perform credential dumping of credentials associated with all enterprise servers [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1003/\" target=\"_blank\" title=\"T1003\">T1003</a>].</p>\n<h3><strong>Stealth, Defense Impairment, and Discovery</strong></h3>\n<p>Gunra employs multiple stealth and defense impairment techniques to hinder detection and analysis. While active within victim networks, Gunra actors typically attempt to mask their presence by deleting system/network access logs [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1685/\" target=\"_blank\" title=\"T1685\">T1685</a>] and clearing command history [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1070/003\" target=\"_blank\" title=\"T1070.003\">T1070.003</a>]. Additionally, to evade administrator detection, Gunra actors primarily conduct malicious activities and internal infrastructure reconnaissance [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1049/\" target=\"_blank\" title=\"T1049\">T1049</a>] during late-night and early-morning hours (10:00 p.m. \u2013 06:00 a.m.) [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1678/\" target=\"_blank\" title=\"T1678\">T1678</a>].</p>\n<p>The ransomware binary is self-contained and performs full volume encryption without observable network indicators (e.g., domain name system, HTTP).<a href=\"#Note6\"><sup>6</sup></a> The Windows binary includes the&nbsp;<code>IsDebuggerPresent</code> API [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1622\" target=\"_blank\" title=\"T1622\">T1622</a>], which defends against reverse engineering by detecting if the application is being run in a debugger.<a href=\"#Note7\"><sup>7</sup></a>&nbsp;</p>\n<p>To avoid dedicating encryption resources to non-critical files, the binary includes filtering logic to exclude common system directories (e.g.,&nbsp;<code>C:\\Windows</code>,&nbsp;<code>C:\\Program Files</code>,&nbsp;<code>C:\\Program Files (x86)</code>) from the file system reconnaissance [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1679/\" target=\"_blank\" title=\"T1679\">T1679</a>]. For files that pass the initial filter, the binary checks against a second set of filter rules that exclude file extensions related to system-critical files (e.g.,&nbsp;<code>.exe</code>,&nbsp;<code>.dll</code>,&nbsp;<code>.sys</code>). Files with extensions consistent with user data (e.g., documents, databases, images, archives) are approved and added to the work queue for data encryption.<a href=\"#Note8\"><sup>8</sup></a>&nbsp;</p>\n<p>Prior to encryption, Gunra performs file and directory discovery across all accessible drive letters (A through Z) to identify victim data for targeting [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1083\" target=\"_blank\" title=\"T1083\">T1083</a>].<a href=\"#Note9\"><sup>9</sup></a>&nbsp;</p>\n<h3><strong>Collection and Exfiltration</strong></h3>\n<p>Prior to data encryption, Gunra actors collect sensitive victim data as part of their double-extortion strategy. The FBI observed actors collecting files from victims that included business-critical documents, databases, personally identifiable information (PII), and internal email communications [<a href=\"https://attack.mitre.org/versions/v19/tactics/TA0009/\" target=\"_blank\" title=\"TA0009\">TA0009</a>][<a href=\"https://attack.mitre.org/versions/v19/techniques/T1114/\" target=\"_blank\" title=\"T1114\">T1114</a>]. Gunra actors\u2019 custom support for filtering redundant system files during initial discovery/file system reconnaissance streamlines the actors\u2019 collection of user-specific data from local victim machines [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1005\" target=\"_blank\" title=\"T1005\">T1005</a>].</p>\n<p>The FBI observed Gunra actors use a malicious executable (<code>main.exe</code>) to exfiltrate victim data from Microsoft OneDrive and SharePoint [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1530\" target=\"_blank\" title=\"T1530\">T1530</a>]. For at least one known Gunra victim, the actors generated compressed archives with sensitive data [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1560\" target=\"_blank\" title=\"T1560\">T1560</a>] and exfiltrated the archives to the file-sharing service Mega [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1567\" target=\"_blank\" title=\"T1567\">T1567</a>]; the volume of exfiltrated data ranged up to tens of terabytes.<a href=\"#Note10\"><sup>10</sup></a>&nbsp;</p>\n<p>In addition to collecting business-critical documents, the KNPA identified a victim case in which Gunra actors connected to the VDI environments of IT personnel and collected sensitive documents containing system and network configuration information [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1005/\" target=\"_blank\" title=\"T1005\">T1005</a>]. The actors then leveraged enterprise server credentials stolen from a system access control server to deploy ransomware to encrypt key assets, including database servers and network attached storage (NAS) systems [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1486/\" target=\"_blank\" title=\"T1486\">T1486</a>].</p>\n<p>The FBI observed several common open source tools on Gunra infrastructure that Gunra actors use to facilitate collection and exfiltration of data, including 7-Zip, RClone, and FileZilla [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1048\" target=\"_blank\" title=\"T1048\">T1048</a>] (see <a href=\"#LeveragedTools\"><strong>Leveraged Tools</strong></a> for a full list of tools used maliciously by Gunra actors).</p>\n<h3><strong>Impact</strong></h3>\n<p>Gunra\u2019s double-extortion model relies on both data exfiltration and data encryption for optimal success. The binary achieves high speed file encryption of entire file systems by leveraging a multi-threaded architecture that supports parallel encryption of multiple files simultaneously using strong ChaCha20 + RSA-4096 encryption [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1486/\" target=\"_blank\" title=\"T1048\">T1486</a>]. Upon successful encryption of a file, the binary renames the encrypted file with the file extension&nbsp;<code>.ENCRT</code>. Gunra also used the <code>.CRYPT</code> file extension in one documented sample from July 2025.<a href=\"#Note11\"><sup>11</sup></a>&nbsp;</p>\n<p>After the binary completes the encryption process for all files in a specific directory, Gunra actors write a static ransom note named&nbsp;<code>R3ADM3.txt</code> to the directory. To avoid unnecessary overhead, the binary also contains logic to prevent encryption of the ransom notes (<code>R3ADM3.txt</code>) and re-encryption of already encrypted files (<code>.ENCRT</code>).<a href=\"#Note12\"><sup>12</sup></a>&nbsp;</p>\n<p>In their ransom notes, Gunra actors typically demand that victims initiate negotiation discussions within five to seven days via a Tor-based negotiation portal or qTox, or risk having their data leaked on Gunra\u2019s DLS. The FBI observed Gunra actors attempting to communicate directly with management staff at victim companies via email to solicit ransom payments with limited success. Gunra actors instructed victims to send ransom payments to specific cryptocurrency wallet addresses [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1657\" target=\"_blank\" title=\"T1657\">T1657</a>] and generally started negotiations at arbitrarily high ransom amounts (over tens of millions in US dollars).</p>\n<p>If Gunra victims do not negotiate or pay ransom, the actors publicly disclose the victims on their DLS and offer a preview of victims\u2019 leaked data. This preview typically includes a directory listing of a victim\u2019s exposed OneDrive and SharePoint files, but not the content of the files. Between June and July of 2025, Gunra actors operated a clearnet mirror of their Tor-based DLS at domain <code>datapub.news</code>. By March 2026, Gunra had moved their original Tor-based DLS to a different <code>.onion</code> address. On Gunra\u2019s current Tor-based DLS, the actors advertise the sale of datasets from specific victims and instruct interested parties to contact them via qTox for more information.</p>\n<p>To increase the likelihood of ransom payment and prevent system recovery [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1490/\" target=\"_blank\" title=\"T1490\">T1490</a>], Gunra actors also used Windows Management Instrumentation (WMI) [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1047\" target=\"_blank\" title=\"T1047\">T1047</a>] to initiate deletion of volume shadow copies prior to encryption, as demonstrated in the following example [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1059/003/\" target=\"_blank\" title=\"T1059.003\">T1059.003</a>]:<a href=\"#Note13\"><sup>13</sup></a><sup> &nbsp;</sup></p>\n<p><code>cmd.exe /c C:\\Windows\\System32\\wbem\\WMIC.exe shadowcopy where \"ID='{guid of shadowcopy}'\" delete</code></p>\n<p>Additionally, against one Gunra victim, Gunra actors deleted backup and archived data stored on backup infrastructure at both the primary data center and disaster recovery center before and after the ransomware deployment [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1490/\" target=\"_blank\" title=\"T1490\">T1490</a>].</p>\n<h3><a class=\"ck-anchor\" id=\"LeveragedTools\"><strong>Leveraged Tools</strong></a></h3>\n<p><a href=\"#Table1\"><strong>Table 1</strong></a> lists publicly available tools and applications used by Gunra ransomware actors. If network defenders identify use of these tools on their network, they should investigate further to determine possible malicious activity.</p>\n<p><strong>Disclaimer:</strong> Use of these tools and applications should not be attributed as malicious without analytical evidence to support threat actor use and/or control.</p>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table1\"></a>Table 1. Tools Used by Gunra Ransomware Actors</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Tool Name</th>\n<th role=\"columnheader\">Description</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>FileZilla</td>\n<td>Open source, cross-platform File Transfer Protocol (FTP) application that supports file transfers between devices and remote servers.</td>\n</tr>\n<tr>\n<td>Amass</td>\n<td>Open source reconnaissance tool for network mapping and information gathering.</td>\n</tr>\n<tr>\n<td>RClone</td>\n<td>Open source command-line program designed to manage files in cloud storage.</td>\n</tr>\n<tr>\n<td>Sliver</td>\n<td>Penetration testing toolset that allows remote command and control of systems.</td>\n</tr>\n<tr>\n<td>7-Zip</td>\n<td>Open source, cross-platform file archiver utility.</td>\n</tr>\n<tr>\n<td>WinRAR</td>\n<td>Open source file archiver utility for Microsoft Windows.</td>\n</tr>\n<tr>\n<td>DBeaver</td>\n<td>Open source database management tool for managing Structured Query Language (SQL) databases like MySQL, MariaDB, PostgreSQL, SQLite, etc.</td>\n</tr>\n<tr>\n<td>Slack</td>\n<td>Cloud-based team communication and collaboration platform.</td>\n</tr>\n<tr>\n<td>Microsoft Visual Studio Code</td>\n<td>Open source extendable source code editor.</td>\n</tr>\n<tr>\n<td>MobaXterm</td>\n<td>Windows application with support for multiple remote computing protocols, including SSH, X11, RDP, virtual network computing (VNC), FTP, etc.</td>\n</tr>\n<tr>\n<td>AnyDesk</td>\n<td>Common, legitimate remote monitoring and management (RMM) tool that can be used by a cyber actor to obtain remote access and maintain persistence. AnyDesk also supports remote file transfer.</td>\n</tr>\n<tr>\n<td>Google Remote Desktop</td>\n<td>Web-based remote desktop software tool developed by Google that runs on a proprietary Google protocol.</td>\n</tr>\n<tr>\n<td>Mimikatz</td>\n<td>Post-exploitation tool that allows users to access and exfiltrate authentication credentials from Windows systems.</td>\n</tr>\n<tr>\n<td>Impacket</td>\n<td>Suite of networking utilities, including&nbsp;<code>smbclient</code>,&nbsp;<code>psexec</code>,&nbsp;<code>secretsdump</code>, etc. Gunra utilized several tools from this suite.</td>\n</tr>\n</tbody>\n</table>\n<h2><strong>Indicators of Compromise</strong></h2>\n<p><a href=\"#Table2\"><strong>Table 2</strong></a> lists IP addresses and domains associated with Gunra ransomware infrastructure since early 2025.</p>\n<p><strong>Disclaimer:</strong> Observed IP addresses/domains may be historical in nature. The authoring agencies recommend organizations investigate or vet these IP addresses prior to taking action, such as blocking.</p>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table2\"></a>Table 2. IP Addresses/Domains</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">IP Address/Domain</th>\n<th role=\"columnheader\">First Seen</th>\n<th role=\"columnheader\">Last Seen&nbsp;</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>23.239.119[.]2</td>\n<td>&nbsp;July 2025</td>\n<td>Nov. 6, 2025</td>\n</tr>\n<tr>\n<td>23.239.119[.]3</td>\n<td>July 2025</td>\n<td>&nbsp;Nov. 6, 2025</td>\n</tr>\n<tr>\n<td>23.239.119[.]4&nbsp;&nbsp;</td>\n<td>July 2025&nbsp;&nbsp;</td>\n<td>Nov. 6, 2025</td>\n</tr>\n<tr>\n<td>23.239.119[.]5</td>\n<td>July 2025</td>\n<td>Nov. 6, 2025</td>\n</tr>\n<tr>\n<td>23.239.119[.]6</td>\n<td>July 2025</td>\n<td>Nov. 6, 2025</td>\n</tr>\n<tr>\n<td>86.54.28[.]216</td>\n<td>June 7, 2025</td>\n<td>July 23, 2025</td>\n</tr>\n<tr>\n<td>103.125.234[.]14</td>\n<td>Nov. 2025</td>\n<td>Dec. 2025</td>\n</tr>\n<tr>\n<td>70.36.99[.]82</td>\n<td>Nov. 2025</td>\n<td>Dec. 2025</td>\n</tr>\n<tr>\n<td>211.21.210[.]181</td>\n<td>Nov. 2025</td>\n<td>Dec. 2025</td>\n</tr>\n<tr>\n<td>123.184.143[.]105</td>\n<td>Nov. 2025</td>\n<td>Dec. 2025</td>\n</tr>\n<tr>\n<td>182.204.21[.]240</td>\n<td>Nov. 2025</td>\n<td>Dec. 2025</td>\n</tr>\n<tr>\n<td>182.204.16[.]112</td>\n<td>Nov. 2025</td>\n<td>Dec. 2025</td>\n</tr>\n<tr>\n<td>123.244.187[.]144</td>\n<td>Nov. 2025</td>\n<td>Dec. 2025</td>\n</tr>\n<tr>\n<td>182.204.39[.]118</td>\n<td>Nov. 2025</td>\n<td>Dec. 2025</td>\n</tr>\n<tr>\n<td>67.43.53[.]10</td>\n<td>Nov. 2025</td>\n<td>Dec. 2025</td>\n</tr>\n<tr>\n<td>123.246.37[.]108</td>\n<td>Nov. 2025</td>\n<td>Dec. 2025</td>\n</tr>\n<tr>\n<td>91.201.66[.]146</td>\n<td>Nov. 2025</td>\n<td>Dec. 2025</td>\n</tr>\n<tr>\n<td>Datapub[.]news</td>\n<td>June 2025</td>\n<td>July 2025</td>\n</tr>\n<tr>\n<td>gunrabxbig445sjqa535uaymzerj6fp4nwc6ngc2xughf2pedjdhk4ad[.]onion</td>\n<td>Apr. 2025</td>\n<td>Feb. 2026</td>\n</tr>\n<tr>\n<td>lgiil72vkmdtbc3qv4tyq6wedyjxqr2qd4ze7xl2cxgerdnymxj7soqd[.]onion</td>\n<td>Mar. 2026</td>\n<td>July 2026</td>\n</tr>\n<tr>\n<td>nsnhzysbntsqdwpys6mhml33muccsvterxewh5rkbmcab7bg2ttevjqd[.]onion</td>\n<td>Jan. 2026</td>\n<td>Jan. 2026</td>\n</tr>\n</tbody>\n</table>\n<p>&nbsp;</p>\n<p><a href=\"#Table3\"><strong>Table 3</strong></a> lists email addresses associated with Gunra actors.</p>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table3\"></a>Table 3. Gunra Email Addresses</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Email Address</th>\n<th role=\"columnheader\">Description</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>a00f105546345756@proton[.]me</td>\n<td>Ransom negotiation</td>\n</tr>\n<tr>\n<td>4569f6322bc3b22e9@proton[.]me</td>\n<td>Ransom negotiation</td>\n</tr>\n<tr>\n<td>ilovemycubscout@gmail[.]com</td>\n<td>Ransom negotiation</td>\n</tr>\n<tr>\n<td>6449a3c1e612168526@proton[.]me</td>\n<td>Ransom negotiation</td>\n</tr>\n</tbody>\n</table>\n<p>The following qTox IDs are associated with Gunra actors:</p>\n<ul type=\"square\">\n<li>2507312EC10BB44ED9DAA04E3C5C27E8C13154649B1A02E73ACFAE1681EE0208D05133A8FB22</li>\n<li>0FE87CED0C611AE97E049C64288557F49E8271E91399E849328B078DA789A573031783235BEF</li>\n<li>47829AF1C943D4C296C910706923AS199BDA4995B076ED9A9016F7DEF161D445DF00F13E6900</li>\n<li>9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47</li>\n</ul>\n<p><a href=\"#Table4\"><strong>Table 4</strong></a> lists malicious files associated with Gunra ransomware.</p>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table4\"></a>Table 4. Malicious Files (SHA256)</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Filename</th>\n<th role=\"columnheader\">Hash (SHA256)</th>\n<th role=\"columnheader\">Description</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>main.exe</td>\n<td>2dc70a12d158d437e45a55b1d52f3d61c6082a1e1667573302ba3b62813e2751</td>\n<td>Tool to exfil OneDrive and SharePoint</td>\n</tr>\n<tr>\n<td>main.exe</td>\n<td>834efe9b392c6c000877ea5613a079445affc16fe8af5997d68c55cafc95e5d1</td>\n<td>Tool to exfil OneDrive and SharePoint</td>\n</tr>\n<tr>\n<td>cryptor.exe</td>\n<td>91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0</td>\n<td>Malicious executable</td>\n</tr>\n<tr>\n<td>msmp.exe</td>\n<td>a82e496b7b5279cb6b93393ec167dd3f50aff1557366784b25f9e51cb23689d9</td>\n<td>Malicious executable</td>\n</tr>\n</tbody>\n</table>\n<p><a href=\"#Table5\"><strong>Table 5</strong></a> lists malicious accounts created by Gunra actors to gain initial access to victim Fortinet devices.</p>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table5\"></a>Table 5. Malicious Fortinet User Accounts</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Username</th>\n<th role=\"columnheader\">Details</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>forticloud-sync</td>\n<td><a href=\"https://www.cve.org/CVERecord?id=CVE-2024-55591\" target=\"_blank\" title=\"CVE-2024-55591\">CVE-2024-55591</a> and <a href=\"https://www.cve.org/CVERecord?id=CVE-2025-24472\" target=\"_blank\" title=\"CVE-2025-24472\">CVE-2025-24472</a> allow threat actors to exploit scheduled tasks on vulnerable FortiOS firewall devices to create a new, malicious persistent user forticloud-sync with super user privileges and a hard-coded password.</td>\n</tr>\n</tbody>\n</table>\n<h2><a class=\"ck-anchor\" id=\"MITRE\"><strong>MITRE ATT&amp;CK Tactics and Techniques</strong></a></h2>\n<p>See <a href=\"#Table6\"><strong>Table 6</strong></a> to <a href=\"#Table18\"><strong>Table 18</strong></a> for all referenced threat actor tactics and techniques in this advisory. For assistance with mapping malicious cyber activity to the MITRE ATT&amp;CK framework, see CISA and MITRE ATT&amp;CK\u2019s <a href=\"https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping\" title=\"Best Practices for MITRE ATT&amp;CK Mapping\">Best Practices for MITRE ATT&amp;CK Mapping</a> and CISA\u2019s <a href=\"https://github.com/cisagov/Decider/\" target=\"_blank\" title=\"Decider Tool\">Decider Tool</a>.</p>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table6\"></a>Table 6. Initial Access</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Exploit Public-Facing Application</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1190/\" target=\"_blank\" title=\"T1190\">T1190</a></td>\n<td>Gunra actors exploited vulnerabilities in FortiGate firewall and SSL-VPN appliances to gain initial access to victim networks.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 7. Execution</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Windows Management Instrumentation</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1047\" target=\"_blank\" title=\"T1047\">T1047</a></td>\n<td>The Gunra ransomware binary contained specific WMI commands to delete volume shadow copies on victim machines.</td>\n</tr>\n<tr>\n<td>Native API</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1106\" target=\"_blank\" title=\"T1106\">T1106</a></td>\n<td>The Gunra ransomware binary utilized Native APIs (<code>FindFirstFileW</code>, <code>FindNextFileW</code>) for file system discovery.</td>\n</tr>\n<tr>\n<td>Command and Scripting Interpreter: Windows Command Shell</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1059/003/\" target=\"_blank\" title=\"T1059.003\">T1059.003</a></td>\n<td>Gunra actors executed commands via <code>cmd.exe</code> on Windows to initiate the WMI command.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 8. Persistence</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Account Manipulation</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1098/\" target=\"_blank\" title=\"T1098\">T1098</a></td>\n<td>Gunra actors gained access to an unused account for a victim network. They altered the account configuration to bypass the mandatory password change requirement, which allowed them to use the compromised account for subsequent malicious activities.</td>\n</tr>\n<tr>\n<td>External Remote Services</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1133/\" target=\"_blank\" title=\"T1133\">T1133</a></td>\n<td>Gunra actors used external-facing remote services in combination with an administrator account to gain access.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 9. Privilege Escalation</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Valid Accounts: Default Accounts</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1078/001/\" target=\"_blank\" title=\"T1078.001\">T1078.001</a></td>\n<td>Gunra actors compromised an SSL-VPN appliance by exploiting default credentials and the absence of account lockout controls to obtain administrator access to the victim network device.</td>\n</tr>\n<tr>\n<td>Valid Accounts: Domain Accounts</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1078/002/\" target=\"_blank\" title=\"T1078.002\">T1078.002</a></td>\n<td>Gunra actors gained access to an administrator account for an SSL appliance.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 10. Stealth</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Debugger Evasion</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1622\" target=\"_blank\" title=\"T1622\">T1622</a></td>\n<td>The Gunra ransomware Windows encryptor binary contained the <code>IsDebuggerPresent</code> API to defend against reverse engineering and debugging activity.</td>\n</tr>\n<tr>\n<td>Indicator Removal: Clear Command History</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1070/003\" target=\"_blank\" title=\"T1070.003\">T1070.003</a></td>\n<td>Gunra actors cleared command history files on victim machines to prevent detection of their malicious activity.</td>\n</tr>\n<tr>\n<td>Delay Execution</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1678/\" target=\"_blank\" title=\"T1678\">T1678</a></td>\n<td>Gunra actors strategically timed their reconnaissance and malicious network activities to late night or early morning to avoid detection by the victim.</td>\n</tr>\n<tr>\n<td>Selective Exclusion</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1679/\" target=\"_blank\" title=\"T1679\">T1679</a></td>\n<td>The Gunra ransomware binary programmatically excludes certain directories and filetypes from encryption to ensure system critical files continue to function and that ransom notes are readable. In addition, the binary contains logic to prevent re-encryption of already Gunra-encrypted files.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 11. Defense Impairment</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Disable or Modify Tools</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1685/\" target=\"_blank\" title=\"T1685\">T1685</a></td>\n<td>Gunra actors cleared system/network logs on victim machines to prevent detection of their malicious activity.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 12. Credential Access</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>OS Credential Dumping: NTDS</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1003/003\" target=\"_blank\" title=\"T1003.003\">T1003.003</a></td>\n<td>Gunra actors used <code>secretsdump.py</code> on multiple victim domain controllers to extract password hashes for user accounts from the NTDS files.</td>\n</tr>\n<tr>\n<td>Network Sniffing</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1040/\" target=\"_blank\" title=\"T1040\">T1040</a></td>\n<td>Gunra actors abused SSL-VPN network traffic controls to capture users\u2019 VDI login credentials and session information in transit, effectively sniffing authentication traffic for a victim network.</td>\n</tr>\n<tr>\n<td>Steal Web Session Cookie</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1539/\" target=\"_blank\" title=\"T1539\">T1539</a></td>\n<td>Gunra actors captured legitimate VDI session data for a victim, which allowed them to steal and reuse session cookies to hijack active sessions and impersonate legitimate users on the internal victim network.</td>\n</tr>\n<tr>\n<td>Credentials from Password Stores</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1555/\" target=\"_blank\" title=\"T1555\">T1555</a></td>\n<td>From a compromised virtual desktop, Gunra actors accessed the Hiware access control server for a victim and stole its symmetric encryption key.</td>\n</tr>\n<tr>\n<td>OS Credential Dumping</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1003/\" target=\"_blank\" title=\"T1003\">T1003</a></td>\n<td>Gunra actors used a stolen symmetric encryption key from a Hiware system access control server to decrypt and dump stored enterprise server passwords.</td>\n</tr>\n<tr>\n<td>Modify Authentication Process: Multi-Factor Authentication</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1556/006/\" target=\"_blank\" title=\"T1556.006\">T1556.006</a></td>\n<td>Gunra actors altered files in a victim\u2019s VDI authentication server portal so that a specific attacker-chosen OTP always succeeded, creating a persistent backdoor that bypassed MFA.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 13. Discovery</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>File and Directory Discovery</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1083\" target=\"_blank\" title=\"T1083\">T1083</a></td>\n<td>The Gunra ransomware binary contains custom instructions to enumerate the complete directory structure of victim machines to identify user-data files and directories for encryption.</td>\n</tr>\n<tr>\n<td>System Network Connections Discovery</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1049\" target=\"_blank\" title=\"T1049\">T1049</a></td>\n<td>Gunra actors enumerated active system network connections to map reachable internal infrastructure prior to ransomware deployment.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 14. Lateral Movement</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Remote Services: Remote Desktop Protocol</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1021/001/\" target=\"_blank\" title=\"T1021.001\">T1021.001</a></td>\n<td>Gunra actors used stolen VDI session information to access a victim\u2019s internal VDI environment, then moved laterally via RDP to access the victim\u2019s VDI authentication web server, internal AD server, and IT staff virtual desktops.</td>\n</tr>\n<tr>\n<td>Remote Services: SMB/Windows Admin Shares</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1021/002/\" target=\"_blank\" title=\"T1021.002\">T1021.002</a></td>\n<td>Gunra actors used SMB administrative shares with valid credentials to move laterally and deploy tools across compromised systems.</td>\n</tr>\n<tr>\n<td>Use Alternate Authentication Material: Pass the Hash</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1550/002/\" target=\"_blank\" title=\"T1550.002\">T1550.002</a></td>\n<td>Gunra actors used pass-the-hash methods to move laterally to privileged systems.</td>\n</tr>\n<tr>\n<td>Use Alternate Authentication Material: Pass the Ticket</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1550/003/\" target=\"_blank\" title=\"T1550.003\">T1550.003</a></td>\n<td>Gunra actors used pass-the-ticket methods to move laterally to privileged systems.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 15. Collection</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Collection</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/tactics/TA0009/\" target=\"_blank\" title=\"TA0009\">TA0009</a></td>\n<td>Gunra actors were observed collecting business-critical documents, databases, PII, and internal email communications.</td>\n</tr>\n<tr>\n<td>Archive Collected Data</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1560\" target=\"_blank\" title=\"T1560\">T1560</a></td>\n<td>Gunra actors were observed utilizing tools such as 7-Zip, WinRAR, RClone, and others to copy and archive victim data for exfiltration.</td>\n</tr>\n<tr>\n<td>Data from Cloud Storage</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1530\" target=\"_blank\" title=\"T1530\">T1530</a></td>\n<td>Gunra actors launched a malicious application (<code>main.exe</code>) that specifically targeted Microsoft Cloud Services (OneDrive and SharePoint) for data exfiltration.</td>\n</tr>\n<tr>\n<td>Data from Local System</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1005\" target=\"_blank\" title=\"T1005\">T1005</a></td>\n<td>\n<p>The Gunra ransomware binary recursed through the full directory structure of a compromised device to identify user-data files and directories for targeted exfiltration and subsequent encryption.</p>\n<p>In one instance, Gunra actors were observed collecting system and network configuration network information by connecting to the VDI environments of IT personnel.</p>\n</td>\n</tr>\n<tr>\n<td>Email Collection</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1114/\" target=\"_blank\" title=\"T1114\">T1114</a></td>\n<td>Gunra actors collected internal email communications.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 16. Command and Control</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Ingress Tool Transfer</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1105/\" target=\"_blank\" title=\"T1105\">T1105</a></td>\n<td>After obtaining admin access to a victim\u2019s SSL-VPN appliance, Gunra actors downloaded an SSH tunneling tool from an external server to create and maintain persistent tunnel connections to compromised systems in the victim\u2019s network.</td>\n</tr>\n<tr>\n<td>Protocol Tunneling</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1572/\" target=\"_blank\" title=\"T1572\">T1572</a></td>\n<td>Gunra actors used an SSH tunneling tool to establish connections and maintain persistence between compromised systems.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 17. Exfiltration</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Exfiltration Over Web Service</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1567\" target=\"_blank\" title=\"T1567\">T1567</a></td>\n<td>Gunra actors were observed archiving victim data and exfiltrating it over the file-sharing service Mega.</td>\n</tr>\n<tr>\n<td>Exfiltration Over Alternative Protocol</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1048\" target=\"_blank\" title=\"T1048\">T1048</a></td>\n<td>Gunra actors used Filezilla software to exfiltrate data over FTP.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table18\"></a>Table 18. Impact</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Data Encrypted for Impact</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1486\" target=\"_blank\" title=\"T1486\">T1486</a></td>\n<td>\n<p>Gunra actors encrypt victim data using combined ChaCha20 + RSA-4096 algorithms to prevent victim access to critical business files. Gunra encryptors are available for Windows and Linux, increasing the potential attack surface within a victim network.</p>\n<p>In one instance, Gunra actors encrypted key assets that included database servers and NAS systems.</p>\n</td>\n</tr>\n<tr>\n<td>Financial Theft</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1657\" target=\"_blank\" title=\"T1657\">T1657</a></td>\n<td>Under the double-extortion model, Gunra actors demand ransom payment through a ransom note (<code>R34DM3.txt</code>) in cryptocurrency. The note instructs victims to make the payment to prevent public leaks of their sensitive business data and acquire decryption keys to unlock encrypted files on compromised systems.</td>\n</tr>\n<tr>\n<td>Inhibit System Recovery</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1490\" target=\"_blank\" title=\"T1490\">T1490</a></td>\n<td>\n<p>To augment encryption of critical data on victim networks and prevent system recovery, Gunra actors disable backup features, such as volume shadow copies.</p>\n<p>In one instance, Gunra actors prevented restoration from backups by deleting backup and archived data stored at the primary data center and disaster recovery center.</p>\n</td>\n</tr>\n</tbody>\n</table>\n<h2><strong>Incident Response</strong></h2>\n<p>If a potential compromise is detected, but ransomware actors have not (yet) encrypted items, organizations should take the following actions:</p>\n<ol>\n<li><strong>Determine which hosts were compromised and isolate them</strong> by quarantining or taking them offline.<br>\n<ol type=\"a\">\n<li><strong>If the incident involves a Gunra Linux variant,</strong> <strong>preserve encrypted files, file timestamps, ransom notes, and relevant system logs</strong>.<br>\n<ol type=\"i\">\n<li>As of March 2026, researchers identified a weakness in the Gunra ransomware\u2019s Linux Executable and Linkable Format (ELF) variants (appended with <code>.GNRA</code>); the encryption keys use a weak pseudorandom number generator (PRNG) seeded with the predictable system&nbsp;<code>srand(time(NULL)</code>).<a href=\"#Note14\"><sup>14</sup></a> Defenders may leverage this to mathematically reconstruct the keys using file timestamps and recover files without paying the ransom.</li>\n</ol>\n</li>\n</ol>\n</li>\n<li><strong>Initiate threat hunting activities to scope the intrusion</strong>. Collect and review relevant artifacts, logs, and other data to identify threat actor TTPs, compromised devices and accounts, a timeline of activity, etc. Responders should consider:<br>\n<ol type=\"a\">\n<li>Reviewing logs of network appliances (e.g., edge devices) to audit actions associated with privileged users to identify anomalous activity.</li>\n<li>Collecting copies of ransom notes to identify current threat actor communication platforms.</li>\n<li>Auditing the creation of new files (particularly archives) to determine possible pre- or post-exfiltration activity.</li>\n</ol>\n</li>\n<li><strong>Report the compromise</strong> to the FBI and other agencies as appropriate (see <a href=\"#Reporting\"><strong>Reporting</strong></a><strong> </strong>for contact information).</li>\n<li><strong>Apply eviction countermeasures</strong>, including those listed below, to contain the incident and eradicate the threat actor from the network (<strong>Note:</strong> Start applying countermeasures after collecting enough threat hunting data to inform effective countermeasure selection; this will likely overlap with threat hunting activities).<br>\n<ol type=\"a\">\n<li>Identify and disable malicious, actor-controlled accounts.</li>\n<li>Identify and secure legitimate, privileged accounts.</li>\n<li>Use CISA\u2019s <a href=\"https://cisa.gov/eviction-strategies-tool?utm_source=&amp;utm_medium=CSAEviction\" title=\"Eviction Strategies Tool\">Eviction Strategies Tool</a> to assemble countermeasures for a systematic eviction plan\u2014the tool comprises <strong>Playbook-NG</strong> (a web application) and <strong>COUN7ER</strong> (a database of post-compromise countermeasures mapped to adversary TTPs).<br>\n<ol type=\"i\">\n<li>Use Playbook-NG and COUN7ER together to assemble a systematic eviction plan, or playbook, that leverages distinct countermeasures to contain and evict cyber threat actors. The playbook features a list of recommended response actions based on threat actor TTPs and includes each action\u2019s intended outcome, preparatory steps, and associated risks. For more information, see CISA\u2019s <a href=\"https://www.cisa.gov/resources-tools/resources/eviction-strategies-tool\" title=\"Eviction Strategies Tool Fact Sheet\">Eviction Strategies Tool Fact Sheet</a>.</li>\n</ol>\n</li>\n</ol>\n</li>\n<li><strong>Harden the network to prevent additional malicious activity</strong> (see <a href=\"#Mitigations\"><strong>Mitigations</strong></a><strong> </strong>for guidance).</li>\n</ol>\n<p>If compromise is detected and items have been encrypted, see the \u201cRansomware and Data Extortion Response Checklist\u201d in CISA\u2019s joint <a href=\"https://www.cisa.gov/sites/default/files/2025-03/StopRansomware-Guide%20508.pdf\" title=\"#StopRansomware Guide\">#StopRansomware Guide</a>.</p>\n<h2><a class=\"ck-anchor\" id=\"Mitigations\"><strong>Mitigations</strong></a></h2>\n<p>The authoring agencies recommend organizations implement the mitigations below to improve your organization\u2019s cybersecurity posture on the basis of Gunra actor activity. These mitigations align with the <a href=\"https://www.cisa.gov/cpg\" title=\"Cross-Sector Cybersecurity Performance Goals (CPGs)\">Cross-Sector Cybersecurity Performance Goals (CPGs)</a> developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats and TTPs. Visit CISA\u2019s <a href=\"https://www.cisa.gov/cpg\" title=\"CPGs webpage\">CPGs webpage</a> for more information on the CPGs, including additional recommended baseline protections.</p>\n<ul type=\"square\">\n<li><strong>Prioritize patching known exploited vulnerabilities&nbsp;</strong>[<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#MitigateKnownVulnerabilities2B\" title=\"CPG 2.B\">CPG 2.B</a>] <strong>and the CVEs in this advisory</strong> in internet-facing systems\u2014including VPN gateways and RDP-exposed infrastructure\u2014and keep all OSs, software, and firmware up to date to support this.</li>\n<li><strong>Implement a recovery plan</strong> to maintain and retain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, and secure location (e.g., hard drive, storage device, the cloud) [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementLogicalPhysicalNetworkSegmentation3I\" title=\"CPG 3.I\">CPG 3.I</a>, <a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#MaintainSystemBackupsRestorationAbility3O\" title=\"3.O\">3.O</a>, <a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ManageIncidentResponsePlans1C\" title=\"1.C\">1.C</a>].</li>\n<li><strong>Review domain controllers, servers, workstations, and active directories</strong> for new and/or unrecognized accounts [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ManageOrganizationalAssets2A\" title=\"CPG 2.A\">CPG 2.A</a>, <a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#DocumentNetworkTopology2E\" title=\"2.E\">2.E</a>].</li>\n<li><strong>Audit user accounts with administrative privileges and configure access controls</strong> according to the principle of least privilege [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#AdministratorsMaintainSeparateUserandPrivilegedAccounts3G\" title=\"CPG 3.G\">CPG 3.G</a>].</li>\n<li><strong>Segment networks</strong> [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementLogicalPhysicalNetworkSegmentation3I\" title=\"CPG 3.I\">CPG 3.I</a>] to prevent the spread of ransomware.<br>\n<ul type=\"circle\">\n<li>Network segmentation can help prevent the spread of ransomware by controlling traffic flows between\u2014and access to\u2014various subnetworks and by restricting adversary lateral movement.</li>\n</ul>\n</li>\n<li><strong>Require MFA</strong> for all services to the extent possible, particularly for webmail, VPNs, and accounts that access critical systems [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementMultifactorAuthentication3F\" target=\"_blank\" title=\"CPG 3.F\">CPG 3.F</a>].</li>\n<li><strong>Disable command-line and scripting activities and permissions.</strong> Privilege escalation and lateral movement often depend on software utilities running from the command line. If threat actors are not able to run these tools, they will have difficulty escalating privileges and/or moving laterally [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#AdministratorsMaintainSeparateUserandPrivilegedAccounts3G\" title=\"CPG 3.G\">CPG 3.G</a>, <a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#DisableAutorunMacrosByDefault3M\" title=\"3.M\">3.M</a>].</li>\n</ul>\n<h2><strong>Validate Security Controls</strong></h2>\n<p>In addition to applying mitigations, the authoring agencies recommend exercising, testing, and validating your organization's security program against the threat behaviors mapped to the MITRE ATT&amp;CK for Enterprise framework in this advisory. The authoring agencies recommend testing your existing security controls inventory to assess how they perform against the ATT&amp;CK techniques described in this advisory.</p>\n<p>To get started:</p>\n<ol>\n<li>Select an ATT&amp;CK technique described in this advisory (see <a href=\"#Table6\"><strong>Table 6</strong></a> to <a href=\"#Table18\"><strong>Table 18</strong></a>).</li>\n<li>Align your security technologies against the technique.</li>\n<li>Test your technologies against the technique.</li>\n<li>Analyze your detection and prevention technologies\u2019 performance.</li>\n<li>Repeat the process for all security technologies to obtain a set of comprehensive performance data.</li>\n<li>Tune your security program, including people, processes, and technologies, based on the data generated by this process.</li>\n</ol>\n<p>The authoring agencies recommend continually testing your security program, at scale, in a production environment to ensure optimal performance against the MITRE ATT&amp;CK techniques identified in this advisory.</p>\n<h2><strong>Resources</strong></h2>\n<ul type=\"square\">\n<li><a href=\"https://www.stopransomware.gov/\" target=\"_blank\" title=\"StopRansomware.gov\">StopRansomware.gov</a>: Whole-of-government, central location for ransomware resources and alerts.</li>\n<li><a href=\"https://www.cisa.gov/resources-tools/resources/stopransomware-guide\" title=\"#StopRansomware Guide\">#StopRansomware Guide</a>: Resource to mitigate a ransomware attack.</li>\n<li><a href=\"https://www.cisa.gov/cyber-hygiene-services\" title=\"Cyber Hygiene Services\">Cyber Hygiene Services</a>, <a href=\"https://github.com/cisagov/cset/releases/tag/v10.3.0.0\" target=\"_blank\" title=\"Ransomware Readiness Assessment\">Ransomware Readiness Assessment</a>: CISA\u2019s no-cost cyber hygiene services.</li>\n<li>USSS\u2019s <a href=\"https://www.secretservice.gov/investigations/cyberincident\" target=\"_blank\" title=\"Preparing for a Cyber Incident\">Preparing for a Cyber Incident</a>: Outlines basic steps an organization can take before, during, and after a cyber incident.</li>\n</ul>\n<h2><a class=\"ck-anchor\" id=\"Reporting\"><strong>Reporting</strong></a></h2>\n<p>Your organization has no obligation to respond or provide information back to the FBI and other authoring agencies in response to this joint advisory. If, after reviewing the information provided, your organization decides to provide information to the FBI and other authoring agencies, reporting must be consistent with applicable state and federal laws.</p>\n<p>The FBI and other authoring agencies are interested in any information that can be shared, to include boundary logs showing communication to and from foreign IP addresses, a sample ransom note, communications with threat actors, cryptocurrency wallet information, decryptor files, and/or a benign sample of an encrypted file.</p>\n<p>Additional details of interest include a targeted company point of contact, status and scope of infection, estimated loss, operational impact, transaction IDs, date of infection, date detected, initial attack vector, and host- and network-based indicators.</p>\n<p>The authoring agencies do not encourage paying ransom as payment does not guarantee victim files will be recovered. Furthermore, payment may also embolden adversaries to target additional organizations, encourage other criminal actors to engage in the distribution of ransomware, and/or fund illicit activities. Regardless of whether you or your organization have decided to pay the ransom, the FBI and CISA urge you to promptly report ransomware incidents to the FBI\u2019s <a href=\"https://www.ic3.gov/Home/ComplaintChoice\" target=\"_blank\" title=\"Internet Crime Complaint Center (IC3)\">Internet Crime Complaint Center (IC3)</a> or a <a href=\"https://www.fbi.gov/contact-us/field-offices\" target=\"_blank\" title=\"local FBI field office\">local FBI field office</a>, to USSS via a <a href=\"https://www.secretservice.gov/contact/field-offices\" target=\"_blank\" title=\"local USSS Field Office\">local USSS Field Office</a>, or CISA via the agency\u2019s <a href=\"https://www.cisa.gov/report\" title=\"Incident Reporting System\">Incident Reporting System</a> or its 24/7 Operations Center (<a href=\"mailto:contact@cisa.dhs.gov\" title=\"contact@cisa.dhs.gov\">contact@cisa.dhs.gov</a>), or by calling 1-844-Say-CISA (1-844-729-2472).</p>\n<p><strong>South Korean organizations:</strong> Report cybersecurity incidents to KNPA via the <a href=\"https://www.ecrm.police.go.kr/\" target=\"_blank\" title=\"online cybercrime reporting system\">online cybercrime reporting system</a> or by calling 112.</p>\n<h2><strong>Disclaimer</strong></h2>\n<p>The information in this report is being provided \u201cas is\u201d for informational purposes only. CISA and co-sealers do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA and co-sealers.</p>\n<h2><strong>Version History</strong></h2>\n<p><strong>August 10, 2026: </strong>Initial version.</p>\n<h2><strong>Notes</strong></h2>\n<p><a class=\"ck-anchor\" id=\"Note1\"><sup>1</sup></a> For information on historical Conti ransomware activity, see CISA and FBI\u2019s <a href=\"https://www.cisa.gov/news-events/alerts/2021/09/22/conti-ransomware\">Conti Ransomware</a> advisory.</p>\n<p><a class=\"ck-anchor\" id=\"Note2\"><sup>2</sup></a> Breakglass Intelligence, \u201cGunra Ransomware\u2019s Linux Variant Has a Fatal Flaw: time()-Seeded rand() Makes Encrypted Files Recoverable Without Paying,\u201d Breakglass Intelligence, March 12, 2026, <a href=\"https://intel.breakglass.tech/post/gunra-ransomware-s-linux-variant-has-a-fatal-flaw-time-seeded-rand-makes-encrypted-files-recoverable-without-paying\" target=\"_blank\">https://intel.breakglass.tech/post/gunra-ransomware-s-linux-variant-has-a-fatal-flaw-time-seeded-rand-makes-encrypted-files-recoverable-without-paying</a>; Jeffrey Francis Bonaobra, Melvin Singwa, Emmanuel Panopio \u201cGunra Ransomware Group Unveils Efficient Linux Variant,\u201d Trend Micro, July 29, 2025, <a href=\"https://www.trendmicro.com/en_us/research/25/g/gunra-ransomware-linux-variant.html\" target=\"_blank\">https://www.trendmicro.com/en_us/research/25/g/gunra-ransomware-linux-variant.html</a>; and CYFIRMA, \u201cGunra Ransomware \u2013 A Brief Analysis,\u201d CYFIRMA, May 3, 2025, <a href=\"https://www.cyfirma.com/research/gunra-ransomware-a-brief-analysis/\" target=\"_blank\">https://www.cyfirma.com/research/gunra-ransomware-a-brief-analysis/</a>.</p>\n<p><a class=\"ck-anchor\" id=\"Note3\"><sup>3</sup></a> CloudSEK, \u201cInside Gunra RaaS: From Affiliate Recruitment on the Dark Web to Full Technical Dissection of their Locker,\u201d CloudSEK, February 11, 2026, <a href=\"https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker\" target=\"_blank\">https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker</a>.</p>\n<p><a class=\"ck-anchor\" id=\"Note4\"><sup>4</sup></a> CYFIRMA, \u201c<a href=\"https://www.cyfirma.com/research/gunra-ransomware-a-brief-analysis/\" target=\"_blank\">Gunra Ransomware \u2013 A Brief Analysis</a>\u201d; and Breakglass Intelligence, \u201c<a href=\"https://intel.breakglass.tech/post/gunra-ransomware-s-linux-variant-has-a-fatal-flaw-time-seeded-rand-makes-encrypted-files-recoverable-without-paying\" target=\"_blank\">Gunra Ransomware\u2019s Linux Variant Has a Fatal Flaw</a>.\u201d</p>\n<p><a class=\"ck-anchor\" id=\"Note5\"><sup>5</sup></a> Bonaobra, \u201c<a href=\"https://www.trendmicro.com/en_us/research/25/g/gunra-ransomware-linux-variant.html\" target=\"_blank\">Gunra Ransomware Group Unveils Efficient Linux Variant</a>\u201d; and CloudSEK, \u201c<a href=\"https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker\" target=\"_blank\">Inside Gunra RaaS</a>.\u201d</p>\n<p><a class=\"ck-anchor\" id=\"Note6\"><sup>6</sup></a> CloudSEK, \u201c<a href=\"https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker\" target=\"_blank\">Inside Gunra RaaS</a>.\u201d</p>\n<p><a class=\"ck-anchor\" id=\"Note7\"><sup>7</sup></a> CYFIRMA, \u201c<a href=\"https://www.cyfirma.com/research/gunra-ransomware-a-brief-analysis/\" target=\"_blank\">Gunra Ransomware \u2013 A Brief Analysis</a>.\u201d</p>\n<p><a class=\"ck-anchor\" id=\"Note8\"><sup>8</sup></a> CloudSEK, \u201c<a href=\"https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker\" target=\"_blank\">Inside Gunra RaaS</a>.\u201d</p>\n<p><a class=\"ck-anchor\" id=\"Note9\"><sup>9</sup></a> CloudSEK, \u201c<a href=\"https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker\" target=\"_blank\">Inside Gunra RaaS</a>.\u201d</p>\n<p><a class=\"ck-anchor\" id=\"Note10\"><sup>10</sup></a> Bonaobra, \u201c<a href=\"https://www.trendmicro.com/en_us/research/25/g/gunra-ransomware-linux-variant.html\" target=\"_blank\">Gunra Ransomware Group Unveils Efficient Linux Variant</a>.\u201d</p>\n<p><a class=\"ck-anchor\" id=\"Note11\"><sup>11</sup></a> VirusTotal, \u201cVirusTotal - File - 91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0,\u201d <em>VirusTotal</em>, <a href=\"https://www.virustotal.com/gui/file/91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0/details\" target=\"_blank\">https://www.virustotal.com/gui/file/91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0/details</a>.</p>\n<p><a class=\"ck-anchor\" id=\"Note12\"><sup>12</sup></a> CloudSEK, \u201c<a href=\"https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker\" target=\"_blank\">Inside Gunra RaaS</a>.\u201d</p>\n<p><a class=\"ck-anchor\" id=\"Note13\"><sup>13</sup></a> CYFIRMA, \u201c<a href=\"https://www.cyfirma.com/research/gunra-ransomware-a-brief-analysis/\" target=\"_blank\">Gunra Ransomware \u2013 A Brief Analysis</a>.\u201d</p>\n<p><a class=\"ck-anchor\" id=\"Note14\"><sup>14</sup></a> Breakglass Intelligence, \u201c<a href=\"https://intel.breakglass.tech/post/gunra-ransomware-s-linux-variant-has-a-fatal-flaw-time-seeded-rand-makes-encrypted-files-recoverable-without-paying\" target=\"_blank\">Gunra Ransomware\u2019s Linux Variant Has a Fatal Flaw</a>.\u201d</p>\n<p>&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Mon, 10 Aug 26 12:00:00 +0000",
        "last_updated": "Mon, 10 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-219-01",
        "title": "CPDLC over ATN-B1 Vulnerabilities",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-219-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-219-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>ATN-B1 CPDLC relies on legacy clear text unauthenticated radio frequency links. Research demonstrates that these characteristics allow unauthorized message injection, denial-of-service conditions, and forced session resets. These vulnerabilities do not constitute an unsafe aircraft condition but can degrade operational safety margins by increasing workload, delaying safety-critical instructions, and reducing situational awareness.</strong></p>\n<p>The following versions of CPDLC over ATN-B1 Vulnerabilities are affected:</p>\n<ul>\n<li>ATN-B1 CPDLC vers:all/* (CVE-2025-71409, CVE-2025-71410, CVE-2025-71411, CVE-2025-71412, CVE-2025-71413)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Standard</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.1</td>\n<td>Advisory Circular 90-117 Data Link Communications</td>\n<td>CPDLC over ATN-B1 Vulnerabilities</td>\n<td>Missing Authentication for Critical Function, Allocation of Resources Without Limits or Throttling, Improper Check for Unusual or Exceptional Conditions</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Global</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-71409</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and potential pilot confusion. This type of attack can be carried out remotely over radio frequency.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-71409\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>CPDLC over ATN-B1 Vulnerabilities</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Standard:</strong><br>Advisory Circular 90-117 Data Link Communications</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Advisory Circular 90-117 Data Link Communications ATN-B1 CPDLC: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>None available</strong><br>Currently, there is no mitigation available for CVE-2025-71409, CVE-2025-71410, CVE-2025-71411, CVE-2025-71412, CVE-2025-71413.</p>\n<p><strong>Mitigation</strong><br>These vulnerabilities in the CPDLC protocol stack are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting.</p>\n<p><strong>Mitigation</strong><br>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p><strong>Mitigation</strong><br>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities have a high attack complexity.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L\">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L\">CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-71410</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and lead to a loss of CPDLC functions requiring a reversion to voice communication and increased controller workload. This type of attack can be carried out remotely over radio frequency.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-71410\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>CPDLC over ATN-B1 Vulnerabilities</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Standard:</strong><br>Advisory Circular 90-117 Data Link Communications</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Advisory Circular 90-117 Data Link Communications ATN-B1 CPDLC: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>None available</strong><br>Currently, there is no mitigation available for CVE-2025-71409, CVE-2025-71410, CVE-2025-71411, CVE-2025-71412, CVE-2025-71413.</p>\n<p><strong>Mitigation</strong><br>These vulnerabilities in the CPDLC protocol stack are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting.</p>\n<p><strong>Mitigation</strong><br>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p><strong>Mitigation</strong><br>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities have a high attack complexity.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/770.html\">CWE-770 Allocation of Resources Without Limits or Throttling</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-71411</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-71411\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>CPDLC over ATN-B1 Vulnerabilities</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Standard:</strong><br>Advisory Circular 90-117 Data Link Communications</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Advisory Circular 90-117 Data Link Communications ATN-B1 CPDLC: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>None available</strong><br>Currently, there is no mitigation available for CVE-2025-71409, CVE-2025-71410, CVE-2025-71411, CVE-2025-71412, CVE-2025-71413.</p>\n<p><strong>Mitigation</strong><br>These vulnerabilities in the CPDLC protocol stack are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting.</p>\n<p><strong>Mitigation</strong><br>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p><strong>Mitigation</strong><br>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities have a high attack complexity.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/770.html\">CWE-770 Allocation of Resources Without Limits or Throttling</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-71412</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion, and improper response actions by flight crews, traffic controllers, and ground operations. This type of attack can be carried out remotely over radio frequency.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-71412\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>CPDLC over ATN-B1 Vulnerabilities</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Standard:</strong><br>Advisory Circular 90-117 Data Link Communications</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Advisory Circular 90-117 Data Link Communications ATN-B1 CPDLC: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>None available</strong><br>Currently, there is no mitigation available for CVE-2025-71409, CVE-2025-71410, CVE-2025-71411, CVE-2025-71412, CVE-2025-71413.</p>\n<p><strong>Mitigation</strong><br>These vulnerabilities in the CPDLC protocol stack are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting.</p>\n<p><strong>Mitigation</strong><br>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p><strong>Mitigation</strong><br>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities have a high attack complexity.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/754.html\">CWE-754 Improper Check for Unusual or Exceptional Conditions</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L\">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L\">CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-71413</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets which may result in increased workload and reduced situational awareness. This type of attack can be carried out remotely over radio frequency.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-71413\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>CPDLC over ATN-B1 Vulnerabilities</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Standard:</strong><br>Advisory Circular 90-117 Data Link Communications</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Advisory Circular 90-117 Data Link Communications ATN-B1 CPDLC: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>None available</strong><br>Currently, there is no mitigation available for CVE-2025-71409, CVE-2025-71410, CVE-2025-71411, CVE-2025-71412, CVE-2025-71413.</p>\n<p><strong>Mitigation</strong><br>These vulnerabilities in the CPDLC protocol stack are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting.</p>\n<p><strong>Mitigation</strong><br>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p><strong>Mitigation</strong><br>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities have a high attack complexity.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/754.html\">CWE-754 Improper Check for Unusual or Exceptional Conditions</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Martin Strohmeier of Armasuisse reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-07</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-07</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Fri, 07 Aug 26 12:00:00 +0000",
        "last_updated": "Fri, 07 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/07/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/07/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-8037\" target=\"_blank\">CVE-2026-8037</a> Progress LoadMaster Command Injection Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.</p>\n<p>&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Fri, 07 Aug 26 12:00:00 +0000",
        "last_updated": "Fri, 07 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-218-01",
        "title": "ABB Ability Zenon",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-218-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-218-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data.</strong></p>\n<p>The following versions of ABB Ability Zenon are affected:</p>\n<ul>\n<li>IIoT services with MongoDB (4.2) installed on ABB Ability Zenon vers:all/*&nbsp;</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.8</td>\n<td>ABB</td>\n<td>ABB Ability Zenon</td>\n<td>Improper Handling of Length Parameter Inconsistency, Improper Neutralization of Null Byte or NUL Character, Collapse of Data into Unsafe Value, Undefined Behavior for Input to API, Incorrect Regular Expression, Uncaught Exception, Reachable Assertion, Allocation of Resources Without Limits or Throttling, Out-of-bounds Write, Improper Output Neutralization for Logs, Improper Certificate Validation, Execution with Unnecessary Privileges</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Communications, Critical Manufacturing, Dams, Energy, Healthcare and Public Health, Information Technology, Water and Wastewater</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Switzerland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-14847</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-14847\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB Ability Zenon</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>\n<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>\n<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>\n<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>\n<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>\n<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section \"General security recommendations\" for further advice on how to keep your system secure.</p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch\">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://psirt.abb.com/csaf/2026/9akk108472a9037.json\">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/130.html\">CWE-130 Improper Handling of Length Parameter Inconsistency</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2020-7928</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects MongoDB Server v4.4 versions prior to 4.4.1; MongoDB Server v4.2 versions prior to 4.2.9; MongoDB Server v4.0 versions prior to 4.0.20 and MongoDB Server v3.6 versions prior to 3.6.20.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2020-7928\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB Ability Zenon</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>\n<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>\n<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>\n<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>\n<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>\n<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section \"General security recommendations\" for further advice on how to keep your system secure.</p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch\">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://psirt.abb.com/csaf/2026/9akk108472a9037.json\">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/158.html\">CWE-158 Improper Neutralization of Null Byte or NUL Character</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2020-7921</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting protection mechanisms following administrative action. This issue affects MongoDB Server v4.2 versions prior to 4.2.3; MongoDB Server v4.0 versions prior to 4.0.15; MongoDB Server v4.3 versions prior to 4.3.3 and MongoDB Server v3.6 versions prior to 3.6.18.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2020-7921\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB Ability Zenon</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>\n<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>\n<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>\n<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>\n<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>\n<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section \"General security recommendations\" for further advice on how to keep your system secure.</p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch\">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://psirt.abb.com/csaf/2026/9akk108472a9037.json\">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/182.html\">CWE-182 Collapse of Data into Unsafe Value</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N\">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2020-7925</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2020-7925\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB Ability Zenon</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>\n<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>\n<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>\n<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>\n<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>\n<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section \"General security recommendations\" for further advice on how to keep your system secure.</p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch\">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://psirt.abb.com/csaf/2026/9akk108472a9037.json\">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/475.html\">CWE-475 Undefined Behavior for Input to API</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2020-7929</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue affects MongoDB Server v3.6 versions prior to 3.6.21 and MongoDB Server v4.0 versions prior to 4.0.20.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2020-7929\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB Ability Zenon</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>\n<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>\n<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>\n<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>\n<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>\n<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section \"General security recommendations\" for further advice on how to keep your system secure.</p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch\">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://psirt.abb.com/csaf/2026/9akk108472a9037.json\">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/185.html\">CWE-185 Incorrect Regular Expression</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2020-7923</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc7; MongoDB Server v4.2 versions prior to 4.2.8 and MongoDB Server v4.0 versions prior to 4.0.19.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2020-7923\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB Ability Zenon</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>\n<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>\n<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>\n<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>\n<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>\n<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section \"General security recommendations\" for further advice on how to keep your system secure.</p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch\">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://psirt.abb.com/csaf/2026/9akk108472a9037.json\">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/248.html\">CWE-248 Uncaught Exception</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2021-20330</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions prior to 4.0.27; MongoDB Server v4.2 versions prior to 4.2.16; MongoDB Server v4.4 versions prior to 4.4.9.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2021-20330\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB Ability Zenon</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>\n<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>\n<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>\n<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>\n<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>\n<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section \"General security recommendations\" for further advice on how to keep your system secure.</p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch\">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://psirt.abb.com/csaf/2026/9akk108472a9037.json\">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/617.html\">CWE-617 Reachable Assertion</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2021-32036</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.3; MongoDB Server v4.4 versions prior to and including 4.4.9; MongoDB Server v4.2 versions prior to and including 4.2.16 and MongoDB Server v4.0 versions prior to and including 4.0.28</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2021-32036\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB Ability Zenon</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>\n<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>\n<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>\n<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>\n<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>\n<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section \"General security recommendations\" for further advice on how to keep your system secure.</p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch\">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://psirt.abb.com/csaf/2026/9akk108472a9037.json\">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/770.html\">CWE-770 Allocation of Resources Without Limits or Throttling</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2021-32040</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and cause a stack overflow due to the size of the stack frames used by that stage. If an attacker could cause such an aggregation to occur, they could maliciously crash MongoDB in a DoS attack. This vulnerability affects MongoDB Server v4.4 versions prior to and including 4.4.28, MongoDB Server v5.0 versions prior to 5.0.4 and MongoDB Server v4.2 versions prior to 4.2.16. Workaround: &gt;= v4.2.16 users and all v4.4 users can add the --setParameter internalPipelineLengthLimit=50 instead of the default 1000 to mongod at startup to prevent a crash.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2021-32040\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB Ability Zenon</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>\n<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>\n<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>\n<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>\n<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>\n<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section \"General security recommendations\" for further advice on how to keep your system secure.</p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch\">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://psirt.abb.com/csaf/2026/9akk108472a9037.json\">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2021-20333</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0 versions prior to 4.0.21 and MongoDB Server v4.2 versions prior to 4.2.10.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2021-20333\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB Ability Zenon</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>\n<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>\n<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>\n<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>\n<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>\n<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section \"General security recommendations\" for further advice on how to keep your system secure.</p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch\">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://psirt.abb.com/csaf/2026/9akk108472a9037.json\">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/117.html\">CWE-117 Improper Output Neutralization for Logs</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2020-7924</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, may result in MongoDB skipping all certificate validation. This may result in accepting invalid certificates. This issue affects: MongoDB Inc. MongoDB Database Tools 3.6 versions later than 3.6.5; 3.6 versions prior to 3.6.21; 4.0 versions prior to 4.0.21; 4.2 versions prior to 4.2.11; 100 versions prior to 100.2.0. MongoDB Inc. Mongomirror 0 versions later than 0.6.0.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2020-7924\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB Ability Zenon</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>\n<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>\n<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>\n<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>\n<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>\n<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section \"General security recommendations\" for further advice on how to keep your system secure.</p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch\">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://psirt.abb.com/csaf/2026/9akk108472a9037.json\">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/295.html\">CWE-295 Improper Certificate Validation</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2021-20328</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server's certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Java driver and the KMS service rendering Field Level Encryption ineffective. This issue was discovered during internal testing and affects all versions of the Java driver that support CSFLE. The Java async, Scala, and reactive streams drivers are not impacted. This vulnerability does not impact driver traffic payloads with CSFLE-supported key services originating from applications residing inside the AWS, GCP, and Azure network fabrics due to compensating controls in these environments. This issue does not impact driver workloads that don't use Field Level Encryption.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2021-20328\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB Ability Zenon</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>\n<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>\n<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>\n<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>\n<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>\n<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section \"General security recommendations\" for further advice on how to keep your system secure.</p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch\">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://psirt.abb.com/csaf/2026/9akk108472a9037.json\">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/295.html\">CWE-295 Improper Certificate Validation</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N\">CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2021-20334</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary software with the privileges of the user who is running MongoDB Compass. This issue affects: MongoDB Inc. MongoDB Compass 1.x version 1.3.0 on Windows and later versions; 1.x versions prior to 1.25.0 on Windows.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2021-20334\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB Ability Zenon</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>\n<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>\n<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>\n<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>\n<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>\n<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section \"General security recommendations\" for further advice on how to keep your system secure.</p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch\">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href=\"https://psirt.abb.com/csaf/2026/9akk108472a9037.json\">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/250.html\">CWE-250 Execution with Unnecessary Privileges</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>ABB PSIRT reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-30</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-30</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n<tr>\n<td>2026-08-06</td>\n<td>2</td>\n<td>Initial Republication of ABB PSIRT 9AKK108472A9037</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 06 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 06 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-218-02",
        "title": "Johnson Controls Inc. TL280",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-218-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-218-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device.</strong></p>\n<p>The following versions of Johnson Controls Inc. TL280 are affected:</p>\n<ul>\n<li>TL280 &lt;5.63 (CVE-2026-27871)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 4.1</td>\n<td>Johnson Controls Inc.</td>\n<td>Johnson Controls Inc. TL280</td>\n<td>Use of a Broken or Risky Cryptographic Algorithm</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Ireland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-27871</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Hardcoded credentials refer to usernames, passwords, or other authentication information that are embedded directly into the source code of a firmware file. These credentials are often used to access system login and other areas of an application.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-27871\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls Inc. TL280</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls Inc.</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls Inc. TL280: &lt;5.63</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>To help reduce the risk of exploitation, Johnson Control suggests considering the following defensive measures: Apply firmware update 5.63.</p>\n<p><strong>Mitigation</strong><br>Johnson Controls suggests the following defensive measures: Restrict network access to affected cameras to trusted management VLANs only - do not expose these devices directly to the internet or untrusted network segments.</p>\n<p><strong>Mitigation</strong><br>Monitor device access logs for any anomalous authentication activity.</p>\n<p><strong>Mitigation</strong><br>Rotate any shared or downstream credentials that may have been derived from or associated with the hard-coded values.</p>\n<p><strong>Mitigation</strong><br>Implement network segmentation and place ICS/SCADA devices and systems behind firewalls, isolating them from the business network.</p>\n<p><strong>Mitigation</strong><br>When remote access is required, use secure methods such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be kept up to date.</p>\n<p><strong>Mitigation</strong><br>Minimize network exposure for all control system devices and/or systems; ensure they are not accessible from the internet.</p>\n<p><strong>Mitigation</strong><br>Conduct regular firmware integrity checks to detect unauthorized modifications.</p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-08 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories\">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/327.html\">CWE-327 Use of a Broken or Risky Cryptographic Algorithm</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>4.1</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L\">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>2.1</td>\n<td>LOW</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Z reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability has a high attack complexity.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-06</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-06</td>\n<td>1</td>\n<td>Initial Republication of Johnson Controls Security Advisory JCI-PSA-2026-08</td>\n</tr>\n<tr>\n<td>2026-08-11</td>\n<td>2</td>\n<td>Revision - Update to acknowledgement section</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 06 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 06 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-218-01",
        "title": "Medixant RadiAnt DICOM",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-218-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-218-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to cause the application to crash if a maliciously crafted DICOM file is opened.</strong></p>\n<p>The following versions of Medixant RadiAnt DICOM are affected:</p>\n<ul>\n<li>RadiAnt DICOM &lt;=2025.2</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 4.3</td>\n<td>Medixant</td>\n<td>Medixant RadiAnt DICOM</td>\n<td>Out-of-bounds Write</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Healthcare and Public Health</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Poland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-17264</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of-bounds write, which may allow an attacker to remotely execute arbitrary code.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-17264\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Medixant RadiAnt DICOM</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Medixant</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Medixant RadiAnt DICOM: &lt;=2025.2</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users should update to version 2026.1. It is also recommended to open DICOM files only from trusted and reliable sources. Additionally, the application is compiled with exploit mitigation mechanisms enabled, including Control Flow Guard (CFG), Data Execution Prevention (DEP), and Address Space Layout Randomization (ASLR), which significantly reduces the practical exploitability of the issue.<br><a href=\"https://www.radiantviewer.com/files/RadiAnt-2026.1-Setup.exe\">https://www.radiantviewer.com/files/RadiAnt-2026.1-Setup.exe</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>4.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>banda, oriotie, ax123, jihyeon4725, lacroix, and minzu reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-06</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-06</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 06 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 06 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/05/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/05/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-63077\" target=\"_blank\">CVE-2026-63077 </a>JetBrains TeamCity Deserialization of Untrusted Data Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Wed, 05 Aug 26 12:00:00 +0000",
        "last_updated": "Wed, 05 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-216-01",
        "title": "Acrisure KARR BT and DR-100",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-216-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-216-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations.</strong></p>\n<p>The following versions of Acrisure KARR BT and DR-100 are affected:</p>\n<ul>\n<li>KARR BT firmware &lt;July_20_2026</li>\n<li>DR-100 firmware &lt;July_20_2026</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.1</td>\n<td>Acrisure</td>\n<td>Acrisure KARR BT and DR-100</td>\n<td>Use of Hard-coded Cryptographic Key</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-18411</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the vehicle, potentially allowing unauthorized access to vehicle functions, including door unlocking and engine immobilization.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-18411\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Acrisure KARR BT and DR-100</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Acrisure</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Acrisure KARR BT firmware: &lt;July_20_2026, Acrisure DR-100 firmware: &lt;July_20_2026</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Acrisure Protection Group released a firmware update on July 20, 2026, to address this vulnerability. They recommend that affected users should follow the directions found here: https://www.karrsecurity.com/karr-security-firmware-update-instructions.<br><a href=\"https://www.karrsecurity.com/karr-security-firmware-update-instructions\">https://www.karrsecurity.com/karr-security-firmware-update-instructions</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/321.html\">CWE-321 Use of Hard-coded Cryptographic Key</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Aaron Schulman, Jerry Yu, Yibo Wei, Sumanth Rao, Mohak Vaswani, Jefferson Chien, Christian Dameff, Nishant Bhaskar of UC San Diego team reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-04</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-04</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 04 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 04 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Three Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added three new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9198\" target=\"_blank\">CVE-2026-9198</a> IBM Langflow Code Injection Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-18556\" target=\"_blank\">CVE-2026-18556</a> N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-34486\" target=\"_blank\">CVE-2026-34486</a> Apache Tomcat Missing Encryption of Sensitive Data Vulnerability</li>\n</ul>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Tue, 04 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 04 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-216-01",
        "title": "Thermo Fisher Applied Biosystems Genetic Analyzers",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-216-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-216-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to modify .fsa/.hid output files, tampering with DNA data and resulting in inaccurate test results.</strong></p>\n<p>The following versions of Thermo Fisher Applied Biosystems Genetic Analyzers are affected:</p>\n<ul>\n<li>Applied Biosystems 3500/3500xL Series Data Collection Software &lt;=4.0.2&nbsp;</li>\n<li>Applied Biosystems 3730/3730xL Series Data Collection Software &lt;=5.0.2&nbsp;</li>\n<li>Applied Biosystems SeqStudio Genetic Analyzer Data Collection Software &lt;=1.2.5&nbsp;</li>\n<li>Applied Biosystems SeqStudio Flex Series Instrument Software &lt;=1.2.0&nbsp;</li>\n<li>Applied Biosystems GeneMapper ID-X Software &lt;=v1.7.3&nbsp;</li>\n<li>Applied Biosystems 3130 Series Data Collection Software &lt;=4.1&nbsp;</li>\n<li>ABI PRISM 3100/3100-Avant Data Collection Software &lt;=2.0&nbsp;</li>\n<li>ABI PRISM 310 Data Collection Software &lt;=3.1&nbsp;</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.4</td>\n<td>Thermo Fisher</td>\n<td>Thermo Fisher Applied Biosystems Genetic Analyzers</td>\n<td>Missing Support for Integrity Check</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Healthcare and Public Health</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-17583</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product is vulnerable because its .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-17583\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Thermo Fisher Applied Biosystems Genetic Analyzers</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Thermo Fisher</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Thermo Fisher Applied Biosystems 3500/3500xL Series Data Collection Software: &lt;=4.0.2, Thermo Fisher Applied Biosystems 3730/3730xL Series Data Collection Software: &lt;=5.0.2, Thermo Fisher Applied Biosystems SeqStudio Genetic Analyzer Data Collection Software: &lt;=1.2.5, Thermo Fisher Applied Biosystems SeqStudio Flex Series Instrument Software: &lt;=1.2.0, Thermo Fisher Applied Biosystems GeneMapper ID-X Software: &lt;=v1.7.3, Thermo Fisher Applied Biosystems 3130 Series Data Collection Software: &lt;=4.1, Thermo Fisher ABI PRISM 3100/3100-Avant Data Collection Software: &lt;=2.0, Thermo Fisher ABI PRISM 310 Data Collection Software: &lt;=3.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Thermo Fisher has developed security updates to address the vulnerability. The security updates implement the use of digital signatures on the instrument software that adds an extralayer of protection. Moving forward, this will help users verify that data files have not been modified.</p>\n<p><strong>Vendor fix</strong><br>Applied Biosystems 3500/3500xL Series Data Collection Software: Update to version 4.0.3<br><a href=\"https://downloads.thermofisher.com/3500_DCS_v4.0.3_Patch/v4.0.3_Patch_Installer.exe\">https://downloads.thermofisher.com/3500_DCS_v4.0.3_Patch/v4.0.3_Patch_Installer.exe</a></p>\n<p><strong>Vendor fix</strong><br>Applied Biosystems 3730/3730xL Series Data Collection Software: Update to version 5.0.3<br><a href=\"https://downloads.thermofisher.com/3730xl_UDC_v5.0.3_Patch/3730xl_UDC_v5.0.3_Patch.exe\">https://downloads.thermofisher.com/3730xl_UDC_v5.0.3_Patch/3730xl_UDC_v5.0.3_Patch.exe</a></p>\n<p><strong>Vendor fix</strong><br>Applied Biosystems SeqStudio Genetic Analyzer Data Collection Software: Update to version 1.2.6<br><a href=\"https://downloads.thermofisher.com/SeqStudio/1.2.6/SeqStudio-1.2.6.abpkg\">https://downloads.thermofisher.com/SeqStudio/1.2.6/SeqStudio-1.2.6.abpkg</a></p>\n<p><strong>Vendor fix</strong><br>Applied Biosystems SeqStudio Flex Series Instrument Software: Update to version 1.2.1<br><a href=\"https://downloads.thermofisher.com/SeqStudioFlex/1.2.1/SeqStudioFlex-1.2.1.abpkg\">https://downloads.thermofisher.com/SeqStudioFlex/1.2.1/SeqStudioFlex-1.2.1.abpkg</a></p>\n<p><strong>Vendor fix</strong><br>Applied Biosystems GeneMapper ID-X Software: Update to version 1.7.4<br><a href=\"https://downloads.thermofisher.com/GeneMapperID-Xv1.7.4_Patch/GMIDX_v1.7.4_Patch.exe\">https://downloads.thermofisher.com/GeneMapperID-Xv1.7.4_Patch/GMIDX_v1.7.4_Patch.exe</a></p>\n<p><strong>Vendor fix</strong><br>Applied Biosystems 3130 Series Data Collection Software: Product is End of Life (EoL), no update provided</p>\n<p><strong>Vendor fix</strong><br>ABI PRISM 3100/3100-Avant Data Collection Software: Product is End of Life (EoL), no update provided</p>\n<p><strong>Vendor fix</strong><br>ABI PRISM 310 Data Collection Software: Product is End of Life (EoL), no update provided</p>\n<p><strong>Mitigation</strong><br>For users who are unable to immediately implement all applicable security updates, Thermo Fisher Scientific recommends implementing the following interim mitigation measures until the applicable updates have been installed:&nbsp;</p>\n<p>-Maintain a secure chain of custody for files generated by the HID instrumentation throughout the analysis workflow.<br>-Store generated files on encrypted, password-protected storage media (for example, encrypted USB drives or encrypted hard drives).<br>-Restrict access to generated files to authorized personnel in accordance with your laboratory's access control policies.<br>-Apply the principle of least privilege by limiting user permissions on systems operating the HID instrumentation or hosting associated data analysis and secondary analysis software.<br>-Leverage firewall rules and network access control lists (NACLs) to restrict internet connectivity to only trusted sources.</p>\n<p><strong>Mitigation</strong><br>For more information, refer to Thermo Fisher's security bulletin.<br><a href=\"https://documents.thermofisher.com/TFS-Assets/CORP/Product-Guides/fsa_hid_bulletin.pdf\">https://documents.thermofisher.com/TFS-Assets/CORP/Product-Guides/fsa_hid_bulletin.pdf</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/353.html\">CWE-353 Missing Support for Integrity Check</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.4</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Nathaniel Adams, Laura Gaydosh-Combs, and Kevin Dyer reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-04</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-04</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 04 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 04 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/03/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/03/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-18577\" target=\"_blank\">CVE-2026-18577</a> N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.</p>",
        "summary_is_html": true,
        "first_seen": "Mon, 03 Aug 26 12:00:00 +0000",
        "last_updated": "Mon, 03 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-01",
        "title": "MikroTik RouterOS",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low\u2011privilege API access, enabling full VPN impersonation and decryption of all associated traffic.</strong></p>\n<p>The following versions of MikroTik RouterOS are affected:</p>\n<ul>\n<li>RouterOS vers:all/* (CVE-2026-14227)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 4.9</td>\n<td>MikroTik</td>\n<td>MikroTik RouterOS</td>\n<td>Insufficient Session Expiration</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Latvia</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-14227</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An API session\u2011management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or user\u2011group changes. As a result, an authenticated user whose permissions have been reduced may continue accessing information.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-14227\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>MikroTik RouterOS</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>MikroTik</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>MikroTik RouterOS: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>MikroTik recommends administrators to ensure that when a user's permissions are downgraded, the affected user is fully logged out so the new policy can take effect.</p>\n<p><strong>Mitigation</strong><br>For more information, contact MikroTik (https://mikrotik.com/support).<br><a href=\"https://mikrotik.com/support\">https://mikrotik.com/support</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/613.html\">CWE-613 Insufficient Session Expiration</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>4.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Andre Santos reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-30</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-30</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 30 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 30 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10",
        "title": "MZ Automation GmbH libiec61850",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-10.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device.</strong></p>\n<p>The following versions of MZ Automation GmbH libiec61850 are affected:</p>\n<ul>\n<li>libiec61850 &lt;1.6.2 (CVE-2026-66720, CVE-2026-66369, CVE-2026-63550, CVE-2026-65421, CVE-2026-66364, CVE-2026-66349, CVE-2026-56758, CVE-2026-66360)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>MZ Automation GmbH</td>\n<td>MZ Automation GmbH libiec61850</td>\n<td>Out-of-bounds Read</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-66720</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and resulting in a denial-of-service condition.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-66720\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>MZ Automation GmbH libiec61850</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>MZ Automation GmbH</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>MZ Automation GmbH libiec61850: &lt;1.6.2</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>MZ Automation GmbH recommends that users update to version 1.6.2.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-66369</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly, resulting in a heap out-of-bounds read. On affected platforms, this condition reliably terminates the subscriber process and causes a denial-of-service.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-66369\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>MZ Automation GmbH libiec61850</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>MZ Automation GmbH</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>MZ Automation GmbH libiec61850: &lt;1.6.2</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>MZ Automation GmbH recommends that users update to version 1.6.2.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-63550</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over an established MMS session (TCP port 102), the decoder may advance its internal read position incorrectly, leading to a heap out-of-bounds read. This condition causes the MMS handling process to terminate unexpectedly, resulting in a denial-of-service.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-63550\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>MZ Automation GmbH libiec61850</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>MZ Automation GmbH</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>MZ Automation GmbH libiec61850: &lt;1.6.2</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>MZ Automation GmbH recommends that users update to version 1.6.2.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-65421</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service process and a denial-of-service condition.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-65421\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>MZ Automation GmbH libiec61850</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>MZ Automation GmbH</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>MZ Automation GmbH libiec61850: &lt;1.6.2</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>MZ Automation GmbH recommends that users update to version 1.6.2.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-66364</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an attacker controlled inner element length may exceed its enclosing length, causing the parser to over read by one byte. This out-of-bounds read reliably terminates the subscriber process, resulting in a denial-of-service condition.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-66364\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>MZ Automation GmbH libiec61850</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>MZ Automation GmbH</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>MZ Automation GmbH libiec61850: &lt;1.6.2</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>MZ Automation GmbH recommends that users update to version 1.6.2.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-66349</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established session, the decoder may advance its internal buffer incorrectly due to a missing bounds check. This results in a one byte heap out-of-bounds read and causes the MMS service process to terminate, leading to a denial-of-service condition.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-66349\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>MZ Automation GmbH libiec61850</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>MZ Automation GmbH</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>MZ Automation GmbH libiec61850: &lt;1.6.2</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>MZ Automation GmbH recommends that users update to version 1.6.2.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-56758</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain fields within the calling AP title, an attacker controlled length value of zero or one may cause the parser to read past the end of a heap buffer.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-56758\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>MZ Automation GmbH libiec61850</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>MZ Automation GmbH</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>MZ Automation GmbH libiec61850: &lt;1.6.2</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>MZ Automation GmbH recommends that users update to version 1.6.2.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-66360</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of the encoded presentation data allows an attacker controlled field with a zero length value to trigger a bounded heap over read. This condition occurs before MMS session establishment, a crafted TCP/102 connection attempt can trigger the issue. The resulting over read causes the process to terminate, leading to a denial of service condition.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-66360\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>MZ Automation GmbH libiec61850</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>MZ Automation GmbH</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>MZ Automation GmbH libiec61850: &lt;1.6.2</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>MZ Automation GmbH recommends that users update to version 1.6.2.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Arun Babu of Central Power Research Institute reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-30</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-30</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 30 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 30 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-03",
        "title": "Toptech Systems RCU II+ and Multiload II+",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-03",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-03.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources.</strong></p>\n<p>The following versions of Toptech Systems RCU II+ and Multiload II+ are affected:</p>\n<ul>\n<li>RCU II+ &lt;2025-11-24 (CVE-2026-12562)</li>\n<li>Multiload II+ &lt;2025-11-24 (CVE-2026-12562)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.8</td>\n<td>Toptech Systems</td>\n<td>Toptech Systems RCU II+ and Multiload II+</td>\n<td>Missing Authentication for Critical Function</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-12562</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the embedded system. This vulnerability stems from a network-accessible port running a Target Communications Framework (TCF) service that does not require any authentication, allowing an attacker to directly interact with the Linux environment that powers the device. Once connected, an attacker can freely view and modify the filesystem, manipulate running processes, and control network interfaces, enabling deep alteration of system behavior.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-12562\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Toptech Systems RCU II+ and Multiload II+</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Toptech Systems</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Toptech Systems RCU II+: &lt;2025-11-24, Toptech Systems Multiload II+: &lt;2025-11-24</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Toptech Systems provides two methods for remediating affected RCU II+ and Multiload II+ units: First, move the device to a closed or segmented network without untrusted access.</p>\n<p><strong>Mitigation</strong><br>Run one of the RCU II+/Multiload II+ Vulnerability Removal Tools (VRT) available at: https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.zip<br><a href=\"https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.zip\">https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.zip</a></p>\n<p><strong>Mitigation</strong><br>https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.gz. This option does not require breaking Weights and Measures seals and has the least operational impact.<br><a href=\"https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.gz\">https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.gz</a></p>\n<p><strong>Mitigation</strong><br>Install the latest firmware from: https://s3.amazonaws.com/docs.toptech.com/index.html#downloads/Firmware/RCUII+_MLII+_SMPII+/. This method requires stopping the bay and breaking the W&amp;M seal. Be sure to back up the current ML configuration before performing the firmware update.<br><a href=\"https://s3.amazonaws.com/docs.toptech.com/index.html#downloads/Firmware/RCUII+_MLII+_SMPII+/\">https://s3.amazonaws.com/docs.toptech.com/index.html#downloads/Firmware/RCUII+_MLII+_SMPII+/</a></p>\n<p><strong>Mitigation</strong><br>For questions, contact Toptech Systems Support at security@toptech.com.<br><a href=\"mailto:security@toptech.com\">mailto:security@toptech.com</a></p>\n<p><strong>Mitigation</strong><br>Additional details are available in Toptech System's firmware vulnerability notice: https://s3.amazonaws.com/docs.toptech.com/nonpublic/2025%2012%2001%20RCU%20IIPlus%20MultiLoad%20IIPlus%20Vulnerability%20Notice.pdf<br><a href=\"https://s3.amazonaws.com/docs.toptech.com/nonpublic/2025%2012%2001%20RCU%20IIPlus%20MultiLoad%20IIPlus%20Vulnerability%20Notice.pdf\">https://s3.amazonaws.com/docs.toptech.com/nonpublic/2025%2012%2001%20RCU%20IIPlus%20MultiLoad%20IIPlus%20Vulnerability%20Notice.pdf</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Donald Green of Southwest Research Institute reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-30</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-30</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n<tr>\n<td>2026-08-05</td>\n<td>2</td>\n<td>Revision - Revised mitigation section</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 30 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 30 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-04",
        "title": "Schneider Electric IGSS",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-04",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-04.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. The IGSS Definition module is a design-time component used by system integrators to create mimic diagrams for plant personnel, enabling them to monitor and control the SCADA system. Failure to apply the remediation provided below may risk loss of data or arbitrary code execution, which could result in the loss of control of the system.</strong></p>\n<p>The following versions of Schneider Electric IGSS are affected:</p>\n<ul>\n<li>IGSS ()</li>\n<li>IGSS Definition (Def.exe) module vers:intdot/&lt;=18.0.0.26124, 18.0.0.26125 ()</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.8</td>\n<td>Schneider Electric</td>\n<td>Schneider Electric IGSS</td>\n<td>Out-of-bounds Write</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Commercial Facilities, Critical Manufacturing, Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>France</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-12927</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file is imported to IGSS Definition.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-12927\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Schneider Electric IGSS</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Schneider Electric</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>&nbsp;</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>fixed, known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Version 18.0.0.26125 of the IGSS Definition module includes a fix for this vulnerability and is available for download through IGSS Master &gt; Update IGSS Software or here: https://igss.schneider-electric.com/igss/igssupdates/v180/IGSSUPDATE.ZIP&nbsp;<br><a href=\"https://igss.schneider-electric.com/igss/igssupdates/v180/IGSSUPDATE.ZIP\">https://igss.schneider-electric.com/igss/igssupdates/v180/IGSSUPDATE.ZIP</a></p>\n<p><strong>Mitigation</strong><br>If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: Avoid executing commands, importing or opening files from untrusted sources.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Schneider Electric reported this vulnerability to CISA.</li>\n<li>Michael Heinzl reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>General Security Recommendations</h2>\n<p>We strongly recommend the following industry cybersecurity best practices. * Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network. * Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks. * Place all controllers in locked cabinets and never leave them in the \u201cProgram\u201d mode. * Never connect programming software to any network other than the network intended for that device. * Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks. * Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation. * Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet. * When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices. For more information refer to the Schneider Electric [Recommended Cybersecurity Best Practices](https://www.se.com/us/en/download/document/7EN52-0390/) document.</p>\n<hr>\n<h2>For More Information</h2>\n<p>This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process. For further information related to cybersecurity in Schneider Electric's products, visit the company's cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp</p>\n<hr>\n<h2>LEGAL DISCLAIMER</h2>\n<p>THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS \u201cNOTIFICATION\u201d) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN \u201cAS-IS\u201d BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION</p>\n<hr>\n<h2>About Schneider Electric</h2>\n<p>Schneider's purpose is to create Impact by empowering all to make the most of our energy and resources, bridging progress and sustainability for all. We call this Life Is On. Our mission is to be the trusted partner in sustainability and efficiency. We are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart industries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep domain expertise, we provide integrated end-to-end lifecycle AI enabled industrial IoT solutions with connected products, automation, software and services, delivering digital twins to enable profitable growth for our customers. We are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries to ensure proximity to our customers and stakeholders. We embrace diversity and inclusion in everything we do, guided by our meaningful purpose of a sustainable future for all. www.se.com</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Schneider Electric SEVD-2026-195-01 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-14</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-14</td>\n<td>1</td>\n<td>Original Release</td>\n</tr>\n<tr>\n<td>2026-07-30</td>\n<td>2</td>\n<td>Initial CISA Republication of Schneider Electric SEVD-2026-195-01 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 30 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 30 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-07",
        "title": "Mitsubishi Electric CC-Link IE TSN Communication Protocol",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-07",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-07.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly.</strong></p>\n<p>The following versions of Mitsubishi Electric CC-Link IE TSN Communication Protocol are affected:</p>\n<ul>\n<li>Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-16 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-32 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-64 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-128 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-256 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-N32 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-P32 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-N32 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-P32 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Master/local module RJ71GN11-T2 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Master/local module RJ71GN11-SX vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Master/local module RJ71GN11-EIP vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Master/local module FX5-CCLGN-MS vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric CC-Link IE TSN interface board NZ81GN11-SX vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric CC-Link IE TSN interface board NZ81GN11-T2 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Motion module RD78G4 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Motion module RD78G8 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Motion module RD78G16 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Motion module RD78G64 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Motion module RD78GHV vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Motion module RD78GHW vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Motion module FX5-40SSC-G vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Motion module FX5-80SSC-G vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Motion Control Board MR-EM441G vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2S1-32D vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2S1-32T vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2S1-32TE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2S1-32DT vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2S1-32DTE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2B1-32D vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2B1-32T vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2B1-32TE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2B1-32DT vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2B1-32DTE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GNCF1-32D vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GNCF1-32T vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GNCE3-32D vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GNCE3-32DT vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN12A4-16D vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN12A4-16DE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN12A2-16T vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN12A2-16TE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN12A42-16DT vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN12A42-16DTE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2S1-16D vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2S1-16T vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2S1-16TE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2B1-16D vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2B1-16T vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2B1-16TE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8D vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8D-K vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8TE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8TE-K vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-16DTE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-16DTE-K vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module with safety functions NZ2GNS12A2-14DT vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module with safety functions NZ2GNS12A2-16DTE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Analog-Digital converter module NZ2GN2S-60AD4 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Analog-Digital converter module NZ2GN2B-60AD4 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Digital-Analog converter module NZ2GN2S-60DA4 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Digital-Analog converter module NZ2GN2B-60DA4 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric CC-Link IE TSN compatible coupler NZ2FT-GN vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric FPGA module NZ2GN2S-D41P01 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric FPGA module NZ2GN2S-D41D01 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric FPGA module NZ2GN2S-D41PD02 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Tension meter LM7-1LG vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Tension meter LM7-2LG vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5W-G vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-HS vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-RJ vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-LL vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5D-G4 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric AC Servo MELSERVO-J5 MR-MD333G vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric AC Servo MELSERVO-JET MR-JET-G vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric AC Servo MELSERVO-JET MR-JET-G4-HS vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A8NCG vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A8NCG-S vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A800-GN vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-E800-E vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-E800-SCE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Industrial Robot CR800-D series controller Network Base Card 2F-DQ535-TSN vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric CC-Link IE TSN expansion unit FCU8-EX569 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric CC-Link IE TSN-CC-Link IE Field Network bridge module NZ2GN-GFB vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric CC-Link IE TSN-AnyWireASLINK bridge module NZ2AW1GNAL vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Energy Measuring Unit CC-Link IE TSN Communication Unit EMU4-CM-TSN vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Industrial Computer MELIPC series MI2532-W vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Industrial Computer MELIPC series MI2332-W vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric GOT3000 Series GT3715-FHCBD vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric GOT3000 Series GT3712-WXCBD vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric GOT3000 Series GT3715-XRBA vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric GOT3000 Series GT3715-XRBD vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric GOT3000 Series GT3712-XRBA vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric GOT3000 Series GT3712-XRBD vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric GOT3000 Series GT3710-XRBA vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric GOT3000 Series GT3710-XRBD vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric GOT3000 Series GT3708-XRBA vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric GOT3000 Series GT3708-XRBD vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Communication Unit GT25-J71GN13-T2 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Motion Control Software SWM-G vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Motion Control Software SWM-G-N1 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Communication Software for Windows SW1DND-CCIETCT-M vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Master/Local module Designated communication LSI DeviceKit NZ2KT-NPETNG51 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Master/Local module Designated communication LSI NZ2GACP610-60 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP620-60 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP620-300 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP621-90 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP621-720 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Master/Local module Designated communication LSI SDK SW1DNN-GN610SRC-M vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Remote station software development kit SW1DNC-GNSDK1S-M vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Remote station software development kit SW1DNC-GNSDK2S-M vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Liner Track System MTR-S series Linear track control module MTR-SCU00-4G vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Liner Track System MTR-S series Linear track control module MTR-SCU00-PG vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Analysis Support Software MELSOFT VIMA SW1DNN-VIMA-M vers:all/* (CVE-2026-13584)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.1</td>\n<td>Mitsubishi Electric</td>\n<td>Mitsubishi Electric CC-Link IE TSN Communication Protocol</td>\n<td>Improper Enforcement of Message Integrity During Transmission in a Communication Channel</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Japan</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-13584</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Improper Enforcement of Message Integrity During Transmission in a Communication Channel (CWE-924) vulnerability exists in the CC-Link IE TSN communication protocol. This vulnerability could allow an attacker with access to the same network segment to tamper with communication data, such as control input and output values, by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-13584\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Mitsubishi Electric CC-Link IE TSN Communication Protocol</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Mitsubishi Electric</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-16: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-64: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-128: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-256: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-N32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-P32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-N32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-P32: vers:all/*, Mitsubishi Electric Master/local module RJ71GN11-T2: vers:all/*, Mitsubishi Electric Master/local module RJ71GN11-SX: vers:all/*, Mitsubishi Electric Master/local module RJ71GN11-EIP: vers:all/*, Mitsubishi Electric Master/local module FX5-CCLGN-MS: vers:all/*, Mitsubishi Electric CC-Link IE TSN interface board NZ81GN11-SX: vers:all/*, Mitsubishi Electric CC-Link IE TSN interface board NZ81GN11-T2: vers:all/*, Mitsubishi Electric Motion module RD78G4: vers:all/*, Mitsubishi Electric Motion module RD78G8: vers:all/*, Mitsubishi Electric Motion module RD78G16: vers:all/*, Mitsubishi Electric Motion module RD78G64: vers:all/*, Mitsubishi Electric Motion module RD78GHV: vers:all/*, Mitsubishi Electric Motion module RD78GHW: vers:all/*, Mitsubishi Electric Motion module FX5-40SSC-G: vers:all/*, Mitsubishi Electric Motion module FX5-80SSC-G: vers:all/*, Mitsubishi Electric Motion Control Board MR-EM441G: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-32D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-32T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-32TE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-32DT: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-32DTE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-32D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-32T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-32TE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-32DT: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-32DTE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GNCF1-32D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GNCF1-32T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GNCE3-32D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GNCE3-32DT: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A4-16D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A4-16DE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A2-16T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A2-16TE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A42-16DT: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A42-16DTE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-16D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-16T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-16TE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-16D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-16T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-16TE: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8D: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8D-K: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8TE: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8TE-K: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-16DTE: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-16DTE-K: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNS12A2-14DT: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNS12A2-16DTE: vers:all/*, Mitsubishi Electric Analog-Digital converter module NZ2GN2S-60AD4: vers:all/*, Mitsubishi Electric Analog-Digital converter module NZ2GN2B-60AD4: vers:all/*, Mitsubishi Electric Digital-Analog converter module NZ2GN2S-60DA4: vers:all/*, Mitsubishi Electric Digital-Analog converter module NZ2GN2B-60DA4: vers:all/*, Mitsubishi Electric CC-Link IE TSN compatible coupler NZ2FT-GN: vers:all/*, Mitsubishi Electric FPGA module NZ2GN2S-D41P01: vers:all/*, Mitsubishi Electric FPGA module NZ2GN2S-D41D01: vers:all/*, Mitsubishi Electric FPGA module NZ2GN2S-D41PD02: vers:all/*, Mitsubishi Electric Tension meter LM7-1LG: vers:all/*, Mitsubishi Electric Tension meter LM7-2LG: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5W-G: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-HS: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-RJ: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-LL: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5D-G4 : vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-MD333G: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-JET MR-JET-G: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-JET MR-JET-G4-HS: vers:all/*, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A8NCG: vers:all/*, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A8NCG-S: vers:all/*, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A800-GN: vers:all/*, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-E800-E: vers:all/*, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-E800-SCE: vers:all/*, Mitsubishi Electric Industrial Robot CR800-D series controller Network Base Card 2F-DQ535-TSN: vers:all/*, Mitsubishi Electric CC-Link IE TSN expansion unit FCU8-EX569: vers:all/*, Mitsubishi Electric CC-Link IE TSN-CC-Link IE Field Network bridge module NZ2GN-GFB: vers:all/*, Mitsubishi Electric CC-Link IE TSN-AnyWireASLINK bridge module NZ2AW1GNAL: vers:all/*, Mitsubishi Electric Energy Measuring Unit CC-Link IE TSN Communication Unit EMU4-CM-TSN: vers:all/*, Mitsubishi Electric Industrial Computer MELIPC series MI2532-W: vers:all/*, Mitsubishi Electric Industrial Computer MELIPC series MI2332-W: vers:all/*, Mitsubishi Electric GOT3000 Series GT3715-FHCBD: vers:all/*, Mitsubishi Electric GOT3000 Series GT3712-WXCBD: vers:all/*, Mitsubishi Electric GOT3000 Series GT3715-XRBA: vers:all/*, Mitsubishi Electric GOT3000 Series GT3715-XRBD: vers:all/*, Mitsubishi Electric GOT3000 Series GT3712-XRBA: vers:all/*, Mitsubishi Electric GOT3000 Series GT3712-XRBD: vers:all/*, Mitsubishi Electric GOT3000 Series GT3710-XRBA: vers:all/*, Mitsubishi Electric GOT3000 Series GT3710-XRBD: vers:all/*, Mitsubishi Electric GOT3000 Series GT3708-XRBA: vers:all/*, Mitsubishi Electric GOT3000 Series GT3708-XRBD: vers:all/*, Mitsubishi Electric CC-Link IE TSN Communication Unit GT25-J71GN13-T2: vers:all/*, Mitsubishi Electric Motion Control Software SWM-G: vers:all/*, Mitsubishi Electric Motion Control Software SWM-G-N1: vers:all/*, Mitsubishi Electric CC-Link IE TSN Communication Software for Windows SW1DND-CCIETCT-M: vers:all/*, Mitsubishi Electric Master/Local module Designated communication LSI DeviceKit NZ2KT-NPETNG51: vers:all/*, Mitsubishi Electric Master/Local module Designated communication LSI NZ2GACP610-60: vers:all/*, Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP620-60: vers:all/*, Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP620-300: vers:all/*, Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP621-90: vers:all/*, Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP621-720: vers:all/*, Mitsubishi Electric CC-Link IE TSN Master/Local module Designated communication LSI SDK SW1DNN-GN610SRC-M: vers:all/*, Mitsubishi Electric Remote station software development kit SW1DNC-GNSDK1S-M: vers:all/*, Mitsubishi Electric Remote station software development kit SW1DNC-GNSDK2S-M: vers:all/*, Mitsubishi Electric Liner Track System MTR-S series Linear track control module MTR-SCU00-4G: vers:all/*, Mitsubishi Electric Liner Track System MTR-S series Linear track control module MTR-SCU00-PG: vers:all/*, Mitsubishi Electric Analysis Support Software MELSOFT VIMA SW1DNN-VIMA-M: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>No fix planned</strong><br>For customers using the affected products, please refer to Mitsubishi Electric's security advisory, \"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-005_en.pdf\" and take the measures described there.<br><a href=\"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-005_en.pdf\">https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-005_en.pdf</a></p>\n<p><strong>Mitigation</strong><br>For customers of the affected products, Mitsubishi Electric recommends restricting physical access to the affected products and the CC-Link IE TSN network to which the affected products are connected by taking measures such as the following: (a) managing access to and from the site where the affected products are installed, (b) locking the control panel in which the affected products and/or the network devices are installed, and (c) locking the Ethernet ports such as with port lock accessories, to minimize the risk of exploitation of this vulnerability.</p>\n<p><strong>Mitigation</strong><br>For customers of the affected products, Mitsubishi Electric recommends using the affected products within a trusted network where communication with untrusted networks and hosts is blocked by a firewall or similar measures, to minimize the risk of exploitation of this vulnerability.</p>\n<p><strong>Mitigation</strong><br>For customers of the affected products, Mitsubishi Electric recommends appropriately configuring credentials and access privileges for network devices installed at the boundary between trusted networks and external networks, to minimize the risk of exploitation of this vulnerability.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/924.html\">CWE-924 Improper Enforcement of Message Integrity During Transmission in a Communication Channel</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Alessandro Di Pinto, Giovanni Dini Gentilini, Luca Cremona, and Gabriele Quagliarella of Nozomi Networks, Inc. reported this vulnerability to Mitsubishi Electric</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Mitsubishi Electric 2026-005 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Mitsubishi Electric directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-30</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-30</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n<tr>\n<td>2026-07-30</td>\n<td>2</td>\n<td>Initial CISA Republication of Mitsubishi Electric 2026-005 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 30 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 30 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-09",
        "title": "Watchfire Controller Software",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-09",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-09.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller.</strong></p>\n<p>The following versions of Watchfire Controller Software are affected:</p>\n<ul>\n<li>BC550 12.30 (CVE-2026-5846)</li>\n<li>BC750 11.33 (CVE-2026-5846)</li>\n<li>BC750 12.35 (CVE-2026-5846)</li>\n<li>BC760 12.38 (CVE-2026-5846)</li>\n<li>BC760 13.00 (CVE-2026-5846)</li>\n<li>BC760DC 12.39 (CVE-2026-5846)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 5.7</td>\n<td>Watchfire</td>\n<td>Watchfire Controller Software</td>\n<td>Use of Hard-coded Cryptographic Key</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Commercial Facilities, Critical Manufacturing, Healthcare and Public Health, Financial Services</li>\n<li><strong>Countries/Areas Deployed: </strong>United States, Dominican Republic, Canada, Peru, El Salvador</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-5846</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-5846\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Watchfire Controller Software</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Watchfire</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Watchfire BC550: 12.30, Watchfire BC750: 11.33, Watchfire BC750: 12.35, Watchfire BC760: 12.38, Watchfire BC760: 13.00, Watchfire BC760DC: 12.39</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Watchfire has applied the required security patch to all affected controllers under its management. Watchfire recommends users verify their controller software version and upgrade to one of the approved versions below, if they are not already on an approved patch level.</p>\n<p><strong>Vendor fix</strong><br>Watchfire has issued patches to disable the use of the existing certificates. Users using BC550; 12.30 should upgrade to 12.31 SP1</p>\n<p><strong>Vendor fix</strong><br>Watchfire has issued patches to disable the use of the existing certificates. Users using BC750; 11.33 should upgrade to 11.34</p>\n<p><strong>Vendor fix</strong><br>Watchfire has issued patches to disable the use of the existing certificates. Users using BC750; 12.35 should upgrade to 12.36 SP1</p>\n<p><strong>Vendor fix</strong><br>Watchfire has issued patches to disable the use of the existing certificates. Users using BC760; 12.38 should upgrade to 12.41 SP1</p>\n<p><strong>Vendor fix</strong><br>Watchfire has issued patches to disable the use of the existing certificates. Users using BC760; 13.00 should upgrade to 14.00 SP1</p>\n<p><strong>Vendor fix</strong><br>Watchfire has issued patches to disable the use of the existing certificates. Users using BC760DC; 12.39 should upgrade to 12.41 SP1</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/321.html\">CWE-321 Use of Hard-coded Cryptographic Key</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.7</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N\">CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Reporter Name(s): James Tillson</li>\n<li>reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability has a high attack complexity.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-30</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-30</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n<tr>\n<td>2026-07-31</td>\n<td>2</td>\n<td>Updated Product and Remediation details</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 30 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 30 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs",
        "title": "CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs",
        "summary": "<p>CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in boil water notices and sustained manual operations.&nbsp;</p>\n<p>These threat actors are targeting water entities of all sizes. Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans. OT assets exposed to the internet have an increased risk of defacement, configuration changes, operational disruptions, and, in severe cases, physical damage.</p>\n<p>CISA recommends organizations implement the following mitigations:</p>\n<ul type=\"disc\">\n<li>Disconnect the PLC from the internet. Remote access for operational purposes should go through a VPN or gateway device, not directly to the PLC.</li>\n<li>Enable password protection and change default passwords.</li>\n<li>Allowlist IPs to only allow remote access from known engineering laptops or other critical OT assets.</li>\n</ul>\n<p>After disconnecting PLCs from the internet, operators should ensure they have a known clean backup of the PLC image in case they are locked out by a modified password. <strong>Note:&nbsp;</strong>Owners, operators, and integrators of Rockwell Automation MicroLogix 1400 PLCs should see Rockwell Automation\u2019s <a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1790.html\" target=\"_blank\">IMPORTANT NOTICE: Restoring Access to a MicroLogix\u2122 1400 Controller When the Password Is Unknown</a> for guidance addressing this activity.</p>\n<p>To securely enable remote access to your OT systems, CISA recommends system owners, operators, and integrators see the following resources for guidance:&nbsp;</p>\n<ul type=\"disc\">\n<li>CISA: <a href=\"https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology\">Primary Mitigations to Reduce Cyber Threats to Operational Technology</a></li>\n<li>United Kingdom's National Cyber Security Center: <a href=\"https://www.ncsc.gov.uk/collection/operational-technology/secure-connectivity\" target=\"_blank\">Secure Connectivity Principles for Operational Technology</a>&nbsp;</li>\n<li>Federal Bureau of Investigation (FBI): <a href=\"https://www.ic3.gov/PSA/2026/PSA260730.pdf\" target=\"_blank\">Malicious Cyber Actors Targeting Water and Wastewater Sector Internet Facing Programmable Logic Controllers, Causing Operational Disruptions</a></li>\n</ul>\n<p>For additional support, contact the Environmental Protection Agency\u2019s <a href=\"https://www.epa.gov/cyberwater/forms/cybersecurity-technical-assistance-program-water-sector\" target=\"_blank\">Cybersecurity Technical Assistance Program for the Water Sector</a> or your <a href=\"https://www.cisa.gov/about/regions\">CISA Regional Office</a>.</p>\n<p>To report a cyber incident, contact CISA\u2019s 24/7 Operations Center (<a href=\"mailto:contact@cisa.dhs.gov\" target=\"_blank\">contact@cisa.dhs.gov</a>), or call 1-844-Say-CISA (1-844-729-2472). Please see <a href=\"https://www.cisa.gov/reporting-cyber-incident\">Reporting a Cyber Incident</a> for more details or contact <a href=\"https://www.ic3.gov/\" target=\"_blank\">FBI\u2019s Internet Crime Complaint Center (IC3)</a> or your <a href=\"https://www.fbi.gov/contact-us/field-offices\" target=\"_blank\">local FBI field office</a>.</p>\n<p>When available, please include the following information regarding the incident:&nbsp;</p>\n<ul type=\"disc\">\n<li>Date, time, and location of the incident</li>\n<li>Type of activity</li>\n<li>Number of people affected</li>\n<li>Type of equipment used for the activity</li>\n<li>Name of the submitting company or organization, and a designated point of contact</li>\n</ul>\n<h2><strong>Disclaimer</strong></h2>\n<p>The information in this report is being provided \u201cas is\u201d for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA.\u202f</p>\n<h2><strong>Acknowledgements</strong></h2>\n<p>The Environmental Protection Agency and the Federal Bureau of Investigation contributed to this Alert.</p>",
        "summary_is_html": true,
        "first_seen": "Thu, 30 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 30 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-02",
        "title": "Johnson Controls OpenBlue Employee",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content.</strong></p>\n<p>The following versions of Johnson Controls OpenBlue Employee are affected:</p>\n<ul>\n<li>OpenBlue Employee (FMS Employee) &lt;=V2025.3.1 (CVE-2026-21662, CVE-2026-34495, CVE-2026-34497)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 2.4</td>\n<td>Johnson Controls Inc.</td>\n<td>Johnson Controls OpenBlue Employee</td>\n<td>Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Ireland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-21662</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The application does not adequately restrict the types of files that can be uploaded, allowing an attacker to submit files with dangerous content types. Uploaded files may be stored in predictable locations and could be leveraged for further exploitation against the application or its users.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-21662\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls OpenBlue Employee</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls Inc.</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls Inc. OpenBlue Employee (FMS Employee): &lt;=V2025.3.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation: Apply the latest product update for OpenBlue Employee (FMS Employee). Customers running V2025.3.1 [LV1.1] or earlier should apply the latest available update.</p>\n<p><strong>Mitigation</strong><br>Limit application access to authorized users and enforce strong authentication.</p>\n<p><strong>Mitigation</strong><br>Enable the \"Do Not Show Files\" location setting if the feature is not being actively used.</p>\n<p><strong>Mitigation</strong><br>Employ a Web Application Firewall (WAF) to help detect and block malicious requests.</p>\n<p><strong>Mitigation</strong><br>Investigate and promptly remove any suspicious files or content discovered within the application.</p>\n<p><strong>Mitigation</strong><br>Limit internet exposure by restricting access to trusted networks or VPN users where practical.</p>\n<p><strong>Mitigation</strong><br>Review uploaded content periodically and remove content that is no longer required.</p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-09 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories\">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/434.html\">CWE-434 Unrestricted Upload of File with Dangerous Type</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>2.4</td>\n<td>LOW</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N\">CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>4.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-34495</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Stored XSS occurs when the application improperly handles user input and stores malicious JavaScript code within its database. This script is then rendered and executed whenever another user accesses the compromised page. Unlike reflected XSS, persistent XSS is particularly dangerous because the payload remains active until it is manually removed from the system.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-34495\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls OpenBlue Employee</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls Inc.</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls Inc. OpenBlue Employee (FMS Employee): &lt;=V2025.3.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation: Apply the latest product update for OpenBlue Employee (FMS Employee). Customers running V2025.3.1 [LV1.1] or earlier should apply the latest available update.</p>\n<p><strong>Mitigation</strong><br>Limit application access to authorized users and enforce strong authentication.</p>\n<p><strong>Mitigation</strong><br>Enable the \"Do Not Show Files\" location setting if the feature is not being actively used.</p>\n<p><strong>Mitigation</strong><br>Employ a Web Application Firewall (WAF) to help detect and block malicious requests.</p>\n<p><strong>Mitigation</strong><br>Investigate and promptly remove any suspicious files or content discovered within the application.</p>\n<p><strong>Mitigation</strong><br>Limit internet exposure by restricting access to trusted networks or VPN users where practical.</p>\n<p><strong>Mitigation</strong><br>Review uploaded content periodically and remove content that is no longer required.</p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-09 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories\">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/79.html\">CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>2.4</td>\n<td>LOW</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N\">CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>4.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-34497</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>HTML injection occurs when user-controlled input is embedded into web pages without proper encoding or sanitization, allowing attackers to inject arbitrary HTML markup. This vulnerability enables attackers to manipulate the Document Object Model (DOM) structure and alter the visual presentation of web content. Unlike Cross-Site Scripting (XSS), HTML injection typically involves static HTML content rather than executable JavaScript, though it can serve as a stepping stone to more severe attacks.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-34497\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls OpenBlue Employee</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls Inc.</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls Inc. OpenBlue Employee (FMS Employee): &lt;=V2025.3.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation: Apply the latest product update for OpenBlue Employee (FMS Employee). Customers running V2025.3.1 [LV1.1] or earlier should apply the latest available update.</p>\n<p><strong>Mitigation</strong><br>Limit application access to authorized users and enforce strong authentication.</p>\n<p><strong>Mitigation</strong><br>Enable the \"Do Not Show Files\" location setting if the feature is not being actively used.</p>\n<p><strong>Mitigation</strong><br>Employ a Web Application Firewall (WAF) to help detect and block malicious requests.</p>\n<p><strong>Mitigation</strong><br>Investigate and promptly remove any suspicious files or content discovered within the application.</p>\n<p><strong>Mitigation</strong><br>Limit internet exposure by restricting access to trusted networks or VPN users where practical.</p>\n<p><strong>Mitigation</strong><br>Review uploaded content periodically and remove content that is no longer required.</p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-09 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories\">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/80.html\">CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>2.4</td>\n<td>LOW</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N\">CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>4.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Johnson Controls reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-30</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-30</td>\n<td>1</td>\n<td>Initial Republication of Johnson Controls Inc. Security Advisory JCI-PSA-2026-09</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 30 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 30 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-05",
        "title": "Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-05",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-05.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.</strong></p>\n<p>The following versions of Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module are affected:</p>\n<ul>\n<li>ControlLogix 5580 &gt;=V36|&lt;=V37 (CVE-2026-9636)</li>\n<li>CompactLogix 5380 &gt;=V36|&lt;=V37 (CVE-2026-9636)</li>\n<li>GuardLogix 5580 &gt;=V36|&lt;=V37 (CVE-2026-9636)</li>\n<li>Compact GuardLogix 5380 &gt;=V36|&lt;=V37 (CVE-2026-9636)</li>\n<li>1756-EN4TR V6.001 (CVE-2026-9636)</li>\n<li>1756-EN4TR V7.001 (CVE-2026-9636)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 5.9</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module</td>\n<td>Improper Check for Certificate Revocation</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-9636</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A security issue exists within CompactLogix 5380, ControlLogix 5580, and EN4TR communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate certificate that has been revoked via a Certificate Revocation List (CRL). This could allow a network-based attacker to establish a connection using a certificate that should be untrusted, potentially bypassing CIP Security protections.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9636\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation ControlLogix 5580: &gt;=V36|&lt;=V37, Rockwell Automation CompactLogix 5380: &gt;=V36|&lt;=V37, Rockwell Automation GuardLogix 5580: &gt;=V36|&lt;=V37, Rockwell Automation Compact GuardLogix 5380: &gt;=V36|&lt;=V37, Rockwell Automation 1756-EN4TR: V6.001, Rockwell Automation 1756-EN4TR: V7.001</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommend users update to the following versions: ControlLogix 5580: Update to V38.011</p>\n<p><strong>Vendor fix</strong><br>CompactLogix 5380: Update to V38.011</p>\n<p><strong>Vendor fix</strong><br>GuardLogix 5580: Update to V38.011</p>\n<p><strong>Vendor fix</strong><br>Compact GuardLogix 5380: Update to V38.011</p>\n<p><strong>Vendor fix</strong><br>1756-EN4TR: Update to V8.001</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/299.html\">CWE-299 Improper Check for Certificate Revocation</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-30</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-30</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 30 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 30 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-11",
        "title": "MZ Automation lib60870",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-11",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-11.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could crash the device being accessed.</strong></p>\n<p>The following versions of MZ Automation lib60870 are affected:</p>\n<ul>\n<li>lib60870 2.4.0 (CVE-2026-61893, CVE-2026-63033)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 6.5</td>\n<td>MZ Automation GmbH</td>\n<td>MZ Automation lib60870</td>\n<td>Out-of-bounds Read</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Energy, Water and Wastewater, Critical Manufacturing, Chemical</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-61893</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-61893\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>MZ Automation lib60870</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>MZ Automation GmbH</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>MZ Automation GmbH lib60870: 2.4.0</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>MZ Automation recommends users update to version 2.4.1 when available.</p>\n<p><strong>Vendor fix</strong><br>See MZ Automation advisories for more information: https://github.com/mz-automation/lib60870/security/advisories/GHSA-g3w7-x5rx-83xm<br><a href=\"https://github.com/mz-automation/lib60870/security/advisories/GHSA-g3w7-x5rx-83xm\">https://github.com/mz-automation/lib60870/security/advisories/GHSA-g3w7-x5rx-83xm</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-63033</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationObject_ParseObjectAddress to read one byte past the end of the heap-allocated message buffer.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-63033\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>MZ Automation lib60870</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>MZ Automation GmbH</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>MZ Automation GmbH lib60870: 2.4.0</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>MZ Automation recommends users update to version 2.4.1 when available.</p>\n<p><strong>Vendor fix</strong><br>See MZ Automation advisory for more information: https://github.com/mz-automation/lib60870/security/advisories/GHSA-7v97-jmwv-w5j7&nbsp;<br><a href=\"https://github.com/mz-automation/lib60870/security/advisories/GHSA-7v97-jmwv-w5j7\">https://github.com/mz-automation/lib60870/security/advisories/GHSA-7v97-jmwv-w5j7</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>arun babu puthuparambil of Central Power Research Institute, Bengaluru, India reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-30</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-30</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 30 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 30 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/resources-tools/resources/open-source-software-security-principles-and-practices",
        "title": "Open Source Software: Security Principles and Practices",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/resources-tools/resources/open-source-software-security-principles-and-practices",
        "summary": "<p>Open source software (OSS) is embedded in nearly every modern system, from business applications to critical infrastructure. Our new Open Source Software: Security Principles and Practices guidance helps agencies securely use, evaluate, and publish open source software. It covers OSS risk management across the full lifecycle, introduces the C4 Framework for trust assessment, and provides specific recommendations for vulnerability management, software bill of materials use, secure development, and handling open source artificial intelligence systems.</p>\n<p>Visit CISA\u2019s <a href=\"https://www.cisa.gov/opensource\">Open Source Security webpage</a> for more resources.</p>\n<p>CISA is committed to providing access to our web pages and documents for individuals with disabilities, both members of the public and federal employees. If the format of any elements or content within this document interferes with your ability to access the information, as defined in the Rehabilitation Act, please email <a href=\"mailto:opensource@cisa.dhs.gov\" target=\"_blank\">opensource@cisa.dhs.gov</a>. To enable us to respond in a manner most helpful to you, please indicate the nature of your accessibility problem and the preferred format in which to receive the material.&nbsp;</p>\n<div class=\"c-text-cta\">\n<div class=\"l-constrain c-text-cta__inner\">\n<div class=\"c-text-cta__content\">\n<h2>Please share your thoughts!</h2>\n<div class=\"c-text-cta__summary\">\n<div class=\"c-text-cta__summary\">\n<div class=\"c-text-cta__summary\">\n<p>We welcome your feedback.</p>\n</div>\n</div>\n</div>\n<p><a class=\"c-button c-button--on-dark\" href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_9n4TtB8uttUPaM6?product=https://www.cisa.gov/resources-tools/resources/open-source-software-security-principles-and-practices\">CISA Product Survey</a></p>\n</div>\n</div>\n</div>",
        "summary_is_html": true,
        "first_seen": "Thu, 30 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 30 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-08",
        "title": "o6 Automation open62541",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-08",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-08.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code.</strong></p>\n<p>The following versions of o6 Automation open62541 are affected:</p>\n<ul>\n<li>open62541 on Windows and Linux &gt;=from_1.3.0|&lt;=1.3.17 (CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559)</li>\n<li>open62541 on Windows and Linux &gt;=from_1.4.0|&lt;=1.4.16 (CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559)</li>\n<li>open62541 on Windows and Linux &gt;=from_1.5.0|&lt;=1.5.4 (CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559)</li>\n<li>open62541 on Windows and Linux master (CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.8</td>\n<td>o6 Automation GmbH</td>\n<td>o6 Automation open62541</td>\n<td>Integer Underflow (Wrap or Wraparound), Integer Overflow or Wraparound, Use After Free</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy, Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-63362</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cause a denial of service via a crafted UDP packet.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-63362\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>o6 Automation open62541</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>o6 Automation GmbH</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>o6 Automation GmbH open62541 on Windows and Linux: &gt;=from_1.3.0|&lt;=1.3.17, o6 Automation GmbH open62541 on Windows and Linux: &gt;=from_1.4.0|&lt;=1.4.16, o6 Automation GmbH open62541 on Windows and Linux: &gt;=from_1.5.0|&lt;=1.5.4, o6 Automation GmbH open62541 on Windows and Linux: master</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>o6 Automation has prepared mitigations and fixes to address these issues and recommends that users update to the newest version. The new version can be obtained by contacting o6 Automation https://www.o6-automation.com/contact or by downloading from the following locations:<br><a href=\"https://www.o6-automation.com/contact\">https://www.o6-automation.com/contact</a></p>\n<p><strong>Mitigation</strong><br>https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f<br><a href=\"https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f\">https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f</a></p>\n<p><strong>Mitigation</strong><br>https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60<br><a href=\"https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60\">https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60</a></p>\n<p><strong>Mitigation</strong><br>https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e<br><a href=\"https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e\">https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e</a></p>\n<p><strong>Mitigation</strong><br>https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df<br><a href=\"https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df\">https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df</a></p>\n<p><strong>Mitigation</strong><br>For more information, see open62541 Security Advisories SA-2026-0012, SA-2026-0014, and SA-2026-0015 or contact o6 Automation: https://www.o6-automation.com/contact<br><a href=\"https://www.o6-automation.com/contact\">https://www.o6-automation.com/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/191.html\">CWE-191 Integer Underflow (Wrap or Wraparound)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-65423</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-65423\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>o6 Automation open62541</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>o6 Automation GmbH</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>o6 Automation GmbH open62541 on Windows and Linux: &gt;=from_1.3.0|&lt;=1.3.17, o6 Automation GmbH open62541 on Windows and Linux: &gt;=from_1.4.0|&lt;=1.4.16, o6 Automation GmbH open62541 on Windows and Linux: &gt;=from_1.5.0|&lt;=1.5.4, o6 Automation GmbH open62541 on Windows and Linux: master</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>o6 Automation has prepared mitigations and fixes to address these issues and recommends that users update to the newest version. The new version can be obtained by contacting o6 Automation https://www.o6-automation.com/contact or by downloading from the following locations:<br><a href=\"https://www.o6-automation.com/contact\">https://www.o6-automation.com/contact</a></p>\n<p><strong>Mitigation</strong><br>https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f<br><a href=\"https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f\">https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f</a></p>\n<p><strong>Mitigation</strong><br>https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60<br><a href=\"https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60\">https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60</a></p>\n<p><strong>Mitigation</strong><br>https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e<br><a href=\"https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e\">https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e</a></p>\n<p><strong>Mitigation</strong><br>https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df<br><a href=\"https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df\">https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df</a></p>\n<p><strong>Mitigation</strong><br>For more information, see open62541 Security Advisories SA-2026-0012, SA-2026-0014, and SA-2026-0015 or contact o6 Automation: https://www.o6-automation.com/contact<br><a href=\"https://www.o6-automation.com/contact\">https://www.o6-automation.com/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/190.html\">CWE-190 Integer Overflow or Wraparound</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-63035</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-63035\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>o6 Automation open62541</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>o6 Automation GmbH</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>o6 Automation GmbH open62541 on Windows and Linux: &gt;=from_1.3.0|&lt;=1.3.17, o6 Automation GmbH open62541 on Windows and Linux: &gt;=from_1.4.0|&lt;=1.4.16, o6 Automation GmbH open62541 on Windows and Linux: &gt;=from_1.5.0|&lt;=1.5.4, o6 Automation GmbH open62541 on Windows and Linux: master</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>o6 Automation has prepared mitigations and fixes to address these issues and recommends that users update to the newest version. The new version can be obtained by contacting o6 Automation https://www.o6-automation.com/contact or by downloading from the following locations:<br><a href=\"https://www.o6-automation.com/contact\">https://www.o6-automation.com/contact</a></p>\n<p><strong>Mitigation</strong><br>https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f<br><a href=\"https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f\">https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f</a></p>\n<p><strong>Mitigation</strong><br>https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60<br><a href=\"https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60\">https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60</a></p>\n<p><strong>Mitigation</strong><br>https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e<br><a href=\"https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e\">https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e</a></p>\n<p><strong>Mitigation</strong><br>https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df<br><a href=\"https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df\">https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df</a></p>\n<p><strong>Mitigation</strong><br>For more information, see open62541 Security Advisories SA-2026-0012, SA-2026-0014, and SA-2026-0015 or contact o6 Automation: https://www.o6-automation.com/contact<br><a href=\"https://www.o6-automation.com/contact\">https://www.o6-automation.com/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/416.html\">CWE-416 Use After Free</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-63559</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to read out-of-bounds heap memory, potentially disclosing sensitive information.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-63559\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>o6 Automation open62541</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>o6 Automation GmbH</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>o6 Automation GmbH open62541 on Windows and Linux: &gt;=from_1.3.0|&lt;=1.3.17, o6 Automation GmbH open62541 on Windows and Linux: &gt;=from_1.4.0|&lt;=1.4.16, o6 Automation GmbH open62541 on Windows and Linux: &gt;=from_1.5.0|&lt;=1.5.4, o6 Automation GmbH open62541 on Windows and Linux: master</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>o6 Automation has prepared mitigations and fixes to address these issues and recommends that users update to the newest version. The new version can be obtained by contacting o6 Automation https://www.o6-automation.com/contact or by downloading from the following locations:<br><a href=\"https://www.o6-automation.com/contact\">https://www.o6-automation.com/contact</a></p>\n<p><strong>Mitigation</strong><br>https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f<br><a href=\"https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f\">https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f</a></p>\n<p><strong>Mitigation</strong><br>https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60<br><a href=\"https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60\">https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60</a></p>\n<p><strong>Mitigation</strong><br>https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e<br><a href=\"https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e\">https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e</a></p>\n<p><strong>Mitigation</strong><br>https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df<br><a href=\"https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df\">https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df</a></p>\n<p><strong>Mitigation</strong><br>For more information, see open62541 Security Advisories SA-2026-0012, SA-2026-0014, and SA-2026-0015 or contact o6 Automation: https://www.o6-automation.com/contact<br><a href=\"https://www.o6-automation.com/contact\">https://www.o6-automation.com/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/190.html\">CWE-190 Integer Overflow or Wraparound</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Asher Davila and Malav Vyas of Palo Alto Networks reported these vulnerabilities to CISA</li>\n<li>Abhinav Agarwal reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-30</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-30</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 30 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 30 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-06",
        "title": "NASA Core Flight System (cFS) Health & Safety (HS) Application",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-06",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-06.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.</strong></p>\n<p>The following versions of NASA Core Flight System (cFS) Health &amp; Safety (HS) Application are affected:</p>\n<ul>\n<li>Core Flight System (cFS) Health &amp; Safety (HS) Application &lt;=v7.0.1 (CVE-2026-18064)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>NASA</td>\n<td>NASA Core Flight System (cFS) Health &amp; Safety (HS) Application</td>\n<td>NULL Pointer Dereference</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-18064</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a denial-of-service condition and processor reset.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-18064\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>NASA Core Flight System (cFS) Health &amp; Safety (HS) Application</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>NASA</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>NASA Core Flight System (cFS) Health &amp; Safety (HS) Application: &lt;=v7.0.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>NASA reports that an official fix is currently under development and is expected to be included in a future software release.</p>\n<p><strong>Mitigation</strong><br>As an interim mitigation, users can update their HS app from the HS repo (https://github.com/nasa/HS) to the latest dev branch. The fix is in the dev branch starting at commit 828855f971db4b6714367ed0a970f52dbeab2965<br><a href=\"https://github.com/nasa/HS\">https://github.com/nasa/HS</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/476.html\">CWE-476 NULL Pointer Dereference</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Michael Holmquist of Hasp Labs reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-30</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-30</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 30 Jul 26 12:00:00 +0000",
        "last_updated": "Thu, 30 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/resources-tools/resources/2026-minimum-elements-software-bill-materials-sbom",
        "title": "2026 Minimum Elements for a Software Bill of Materials (SBOM)",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/resources-tools/resources/2026-minimum-elements-software-bill-materials-sbom",
        "summary": "<p>CISA, the National Security Agency, the Federal Bureau of Investigation, and international partners released joint guidance,&nbsp;<a href=\"https://www.cisa.gov/sites/default/files/2026-07/2026_cisa_sbom_minimum_elements_508c.pdf\">2026 Minimum Elements for a Software Bill of Materials (SBOM)</a>, that updates and replaces the minimum elements for an SBOM published by the National Telecommunications and Information Administration (NTIA) in 2021. The new guidance incorporates stakeholder feedback from a 2025 public comment period&nbsp;and reflects current SBOM tools and needs while preserving the core principles of the original NTIA document.</p>\n<p>An SBOM serves as an \u201cingredients list\u201d for software and is a key building block of software security and supply chain risk management. Organizations can use SBOM data to better understand the makeup of their software components and supply chains and make more risk-informed decisions. Minimum elements for an SBOM describe the baseline technologies and practices that an SBOM should include.&nbsp;</p>\n<p>While the minimum elements for an SBOM apply to all software, some software types\u2014such as artificial intelligence<a>&nbsp;</a>and software as a service in cloud environments\u2014may require additional elements. Any effort to improve software transparency, regardless of the software type, should begin with the application of minimum elements.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Wed, 29 Jul 26 12:00:00 +0000",
        "last_updated": "Wed, 29 Jul 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/07/29/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/07/29/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-20316\" target=\"_blank\">CVE-2026-20316</a> Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Wed, 29 Jul 26 12:00:00 +0000",
        "last_updated": "Wed, 29 Jul 26 12:00:00 +0000"
    }
]