[
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/24/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/24/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://edit.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-21962\" target=\"_blank\">CVE-2026-21962</a> Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://edit.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://edit.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://edit.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a class=\"ext\" href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Mon, 24 Aug 26 12:00:00 +0000",
        "last_updated": "Mon, 24 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/21/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/21/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-73570\" target=\"_blank\">CVE-2026-73570</a> Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Fri, 21 Aug 26 12:00:00 +0000",
        "last_updated": "Fri, 21 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-232-01",
        "title": "Johnson Controls Simplex Incident Manager",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-232-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-232-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems.</strong></p>\n<p>The following versions of Johnson Controls Simplex Incident Manager are affected:</p>\n<ul>\n<li>Simplex Incident Manager &lt;=V2.01 (CVE-2026-27875)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 5.8</td>\n<td>Johnson Controls Inc.</td>\n<td>Johnson Controls Simplex Incident Manager</td>\n<td>Cleartext Storage of Sensitive Information in Memory</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Ireland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-27875</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Simplex Incident Manager application stores user credentials (such as passwords and authentication tokens) in an unencrypted form within system memory while running. This exposes sensitive information to potential extraction by anyone with local access to the system, including attackers leveraging memory-dumping tools or insiders with elevated privileges.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-27875\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls Simplex Incident Manager</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls Inc.</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls Simplex Incident Manager: &lt;=V2.01</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Johnson Controls has released a patched version (v2.01.01) to address this vulnerability. To help reduce the risk of exploitation, Johnson Controls suggests considering the following defensive measures: Upgrade the Simplex Incident Manager to version v1.01.05 or later. Restrict local access to systems running the Simplex Incident Manager to authorized personnel only. Implement endpoint protection and monitoring to detect memory-dumping tools or suspicious processes. Enforce strong access control policies and the principle of least privilege on host systems. Utilize full-disk encryption and secure boot to reduce the risk of offline memory analysis. Monitor for unauthorized local access attempts and implement audit logging.</p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-28.<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories\">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>\n<p><strong>Mitigation</strong><br>Aligning with CISA recommendations, Johnson Controls recommends taking steps to minimize risks to all building automation systems.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/316.html\">CWE-316 Cleartext Storage of Sensitive Information in Memory</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L\">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Johnson Controls reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely. This vulnerability has a high attack complexity.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-20</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-20</td>\n<td>1</td>\n<td>Initial Republication of Johnson Controls Product Security Advisory JCI-PSA-2026-28</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 20 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 20 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/20/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Two Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/20/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added two new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-72529\" target=\"_blank\">CVE-2026-72529</a> TrueConf Server Missing Authentication for Critical Function Vulnerability &nbsp;</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-72530\" target=\"_blank\">CVE-2026-72530</a> TrueConf Server Code Injection Vulnerability</li>\n</ul>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Thu, 20 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 20 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a",
        "title": "Defending Against an Active Threat to Siemens S7 Series PLCs",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a",
        "summary": "<h2><strong>Executive summary</strong></h2>\n<p><em><strong>Note:</strong> This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape.</em></p>\n<p><strong>Top Mitigations</strong></p>\n<ul type=\"disc\">\n<li><strong>Inventory&nbsp;</strong>all Siemens S7 Series programmable logic controllers (PLCs)</li>\n<li><strong>Apply&nbsp;</strong>critical security patches<strong>&nbsp;</strong></li>\n<li><strong>Ensure&nbsp;</strong>PLCs are <strong>not&nbsp;</strong>accessible<strong>&nbsp;</strong>from the Internet</li>\n<li><strong>Strengthen&nbsp;</strong>access controls</li>\n<li><strong>Monitor&nbsp;</strong>for unauthorized activity</li>\n<li><strong>Harden&nbsp;</strong>PLC services, protocols, and ladder logic integrity<strong>&nbsp;</strong></li>\n<li><strong>Hunt&nbsp;</strong>for anomalies that may indicate a compromise</li>\n</ul>\n<p>The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA)\u2014hereafter referred to as the authoring agencies\u2014are releasing this Cybersecurity Advisory to warn owners and operators of industrial control systems (ICSs) of an active cyber threat to Siemens S7 Series PLCs and provide relevant mitigations to protect and defend them.&nbsp;</p>\n<p>The threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools. The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected. The U.S. critical infrastructure sectors most targeted by this threat activity include <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/critical-manufacturing-sector\">Critical Manufacturing</a>, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/energy-sector\">Energy</a>, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/water-and-wastewater-sector\">Water and Wastewater</a>, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/chemical-sector\">Chemical</a>, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/food-and-agriculture-sector\">Food and Agriculture</a>, and <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/commercial-facilities-sector\">Commercial Facilities</a>. This is not a theoretical risk\u2014it is an active threat. Depending on the specific circumstances, exploitation of poorly protected PLCs&nbsp;could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems.&nbsp;</p>\n<p>The authoring agencies urge all owners and operators of operational technology (OT) systems using Siemens S7 Series and other PLC devices to proactively check their systems:</p>\n<ul type=\"disc\">\n<li>are properly protected with all applicable security patches and updates,&nbsp;</li>\n<li>are isolated from the Internet wherever possible,&nbsp;</li>\n<li>have strong access controls, and&nbsp;</li>\n<li>employ security tooling to monitor ICS environments for anomalous or malicious activity.</li>\n</ul>\n<p>These mitigations are particularly important for owners and operators who work with third-party service providers or system integrators who may have remote access to PLCs, as the asset owners may not realize that their systems are exposed and at risk.</p>\n<h2><strong>Technical details</strong></h2>\n<p><strong>Note:</strong>&nbsp;This advisory uses the <a href=\"https://attack.mitre.org/versions/v19/matrices/ics/\" target=\"_blank\">MITRE ATT&amp;CK<sup>\u00ae</sup>&nbsp;Matrix for ICS</a><a href=\"#Note1\"><strong><sup>1</sup></strong></a> framework, version 19, and the&nbsp;<a href=\"https://attack.mitre.org/versions/v19/matrices/enterprise/\" target=\"_blank\" title=\"MITRE ATTACK Matrix for Enterprise\">MITRE ATT&amp;CK&nbsp;Matrix for Enterprise</a>&nbsp;framework, version 19.&nbsp;This advisory also uses <a href=\"https://d3fend.mitre.org/\" target=\"_blank\">MITRE D3FEND<sup>TM</sup></a>, version 1.5.0. See <a href=\"#AppA\"><strong>Appendix A</strong></a> and <a href=\"#AppB\"><strong>Appendix B</strong></a> for tables of the activity mapped to MITRE ATT&amp;CK and MITRE D3FEND tactics, techniques, and countermeasures.</p>\n<h3><em><strong>Threat actor targeting</strong></em></h3>\n<p>Threat actors are actively targeting the following Siemens PLC models:</p>\n<ul type=\"disc\">\n<li><strong>S7-200 Series</strong>&nbsp;(all CPU variants)</li>\n<li><strong>S7-300 Series</strong>&nbsp;(all CPU variants including 314, 315, 317 models)</li>\n<li><strong>S7-400 Series</strong>&nbsp;(all CPU variants)</li>\n<li><strong>S7-1200 Series</strong>&nbsp;(CPU 1211C, 1212C, 1214C, 1215C, 1217C variants)</li>\n<li><strong>S7-1500 Series</strong>&nbsp;(all CPU variants, including F-series safety controllers)</li>\n</ul>\n<p>Threat actors are using AI assistance to generate exploitation scripts using publicly available information on these Siemens S7 Series PLCs for initial access, credential access, denial of service, and other objectives. If these PLCs are exposed to the Internet or insufficiently segmented, then threat actors can exploit various critical and high severity known vulnerabilities in these PLCs.</p>\n<p><strong>Note:</strong>&nbsp;Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools. In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures. Threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploitable PLCs, and use AI-generated scripts to act on that information. If PLCs are exposed to the Internet, they are at high risk for exploitation.&nbsp;</p>\n<p>Threat actors are leveraging open source industrial automation libraries\u2014specifically <code>snap7.dll</code>/<code>python-snap7</code>\u2014combined with AI-assisted scripting to create custom tools that mimic legitimate OT monitoring solutions. These tools provide read/write access to Siemens S7 Series PLC memory, configuration data, and ladder logic programs via the S7comm protocol.</p>\n<h3><em><strong>Threat actor techniques</strong></em></h3>\n<p>Threat actors are:</p>\n<ul type=\"disc\">\n<li><strong>Using Internet scanning services</strong>&nbsp;(e.g., Censys, ZoomEye) to identify Internet-exposed or insufficiently segmented Siemens S7 Series PLCs [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1596/005/\" target=\"_blank\">T1596.005</a>]</li>\n<li><strong>Rapidly iterating exploit code</strong>&nbsp;through AI-assisted development, lowering technical barriers to ICS attacks [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1587/004/\" target=\"_blank\">T1587.004</a>, <a href=\"https://attack.mitre.org/versions/v19/techniques/T1588/007/\" target=\"_blank\">T1588.007</a>]</li>\n<li><strong>Taking advantage of insecure credentials</strong> to access exposed devices that have unconfigured (default) or minimally configured authentication [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1694/\" target=\"_blank\">T1694</a>]</li>\n<li><strong>Deploying AI-generated Python scripts</strong>&nbsp;that incorporate the <code>snap7.dll</code> library from public repositories [<a href=\"https://attack.mitre.org/versions/v19/techniques/T0834/\" target=\"_blank\">T0834</a>] to gain read/write access to the PLC and mimic legitimate tools</li>\n<li><strong>Masquerading malicious scripts as legitimate monitoring tools</strong>&nbsp;to evade detection by security teams [<a href=\"https://attack.mitre.org/versions/v19/techniques/T0849/\" target=\"_blank\">T0849</a>]</li>\n<li><strong>Conducting read/write operations</strong>&nbsp;on data blocks, potentially for reconnaissance, capability testing, or pre-positioning for effects operations [<a href=\"https://attack.mitre.org/versions/v19/techniques/T0893/\" target=\"_blank\">T0893</a>, <a href=\"https://attack.mitre.org/versions/v19/techniques/T0821/\" target=\"_blank\">T0821</a>]</li>\n</ul>\n<p>The authoring agencies assess this activity pattern is likely intended as persistent reconnaissance in targeted sectors and facilities to develop capabilities and prepare to cause operational effects against critical infrastructure. For capability development, actors are testing and refining their exploitation techniques against specific PLC models to improve their ability to compromise the PLCs. To prepare for operational effects, actors are leveraging read access to understand target environments, enabling preparation and positioning for future write operations to cause disruption or other operational impacts.</p>\n<h3><em><strong>Potential operational impacts</strong></em></h3>\n<p>The U.S. critical infrastructure sectors most targeted by this threat activity include <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/critical-manufacturing-sector\">Critical Manufacturing</a>, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/energy-sector\">Energy</a>, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/water-and-wastewater-sector\">Water and Wastewater</a>, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/chemical-sector\">Chemical</a>, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/food-and-agriculture-sector\">Food and Agriculture</a>, and <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/commercial-facilities-sector\">Commercial Facilities</a>. Additionally, Siemens S7 Series PLCs are used in other sectors, including the <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/defense-industrial-base-sector\">Defense Industrial Base (DIB)</a>, and could be targeted there as well. Unauthorized access to PLCs could result in:</p>\n<ul type=\"disc\">\n<li><strong>Disruption of critical industrial processes</strong>&nbsp;affecting production throughput, product quality, and public services</li>\n<li><strong>Safety incidents affecting personnel</strong>&nbsp;through manipulation of safety interlocks, emergency shutdown systems, or process parameters</li>\n<li><strong>Equipment damage and extended operational downtime</strong>&nbsp;from process upsets, improper sequencing, or forced equipment operation outside design parameters</li>\n<li><strong>Compromise of sensitive operational data</strong>,&nbsp;including proprietary process recipes, control strategies, and facility configurations</li>\n<li><strong>Cascading impacts across interconnected systems</strong>&nbsp;affecting supply chains, dependent facilities, and integrated business operations</li>\n<li><strong>Regulatory compliance violations</strong>&nbsp;and potential liability from process safety management failures</li>\n</ul>\n<h2><strong>Mitigation actions</strong></h2>\n<p>Since threat actors are developing capabilities using AI to compromise PLCs using known vulnerabilities, misconfigurations, and other weaknesses and then may use compromised PLCs to interfere with normal operations, the authoring agencies urge organizations to implement comprehensive defense-in-depth strategies, in addition to Common Vulnerabilities and Exposures (CVE) remediation, to protect and defend their PLCs.</p>\n<h3><em><strong>Detection opportunities</strong></em></h3>\n<p>Organizations should implement detection strategies and hunt for anomalies that may indicate a compromise, focusing on [<a href=\"https://d3fend.mitre.org/technique/d3f:PlatformMonitoring/\" target=\"_blank\">D3-PM</a>]:</p>\n<ul type=\"disc\">\n<li><strong>Anomalous S7comm behavior:</strong>&nbsp;Connections from non-engineering workstations, unusual data block access patterns, or write operations outside change windows</li>\n<li><strong>Reconnaissance indicators:</strong>&nbsp;Sequential IP scanning on port <code>102</code>, repeated connection attempts with varying parameters, or enumeration of CPU properties</li>\n<li><strong>Tool artifacts:</strong>&nbsp;<code>Snap7.dll</code> library usage outside approved engineering workstations, Python scripts with S7comm functionality, or unauthorized monitoring software installations</li>\n<li><strong>Temporal anomalies:</strong>&nbsp;S7comm activity during off-hours, unexpected connection patterns consistent with automated scripting rather than human operators, or configuration changes without corresponding work orders or change tickets</li>\n<li><strong>Geographic anomalies:</strong>&nbsp;Connections originating from unexpected countries or IP ranges not associated with vendors or integrators</li>\n</ul>\n<h3><em><strong>Preventative hardening actions</strong></em></h3>\n<p>To counter threats to PLCs, the authoring agencies recommend all PLC owners and operators follow the mitigations in joint guidance <a href=\"https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology\">Primary Mitigations to Reduce Cyber Threats to Operational Technology</a>.</p>\n<p>To harden Siemens S7 Series PLCs, the authoring agencies strongly urge all owners implement the hardening steps below. Entities that rely on systems integrators or third-party managed service providers should share this advisory with those parties and request implementation of the following mitigations:</p>\n<h4><strong>1. Conduct an immediate inventory of all Siemens S7 Series PLCs in your environment [</strong><a href=\"https://d3fend.mitre.org/technique/d3f:HardwareComponentInventory/\" target=\"_blank\"><strong>D3-HCI</strong></a><strong>]:</strong></h4>\n<ul type=\"disc\">\n<li>Verify current firmware versions for all S7-200, S7-300, S7-400, S7-1200, and S7-1500 controllers against backup gold copy</li>\n<li>Identify any systems directly or indirectly accessible from untrusted networks</li>\n<li>Map all engineering workstations with Totally Integrated Automation (TIA) Portal, STEP 7, or S7 programming access</li>\n</ul>\n<h4><strong>2. Apply critical security patches as soon as possible [</strong><a href=\"https://d3fend.mitre.org/technique/d3f:SoftwareUpdate/\"><strong>D3-SU</strong></a><strong>]:</strong></h4>\n<ul type=\"disc\">\n<li>Update Siemens S7 Series PLC firmware to the latest versions that address known vulnerabilities</li>\n<li>Prioritize Internet-facing or demilitarized zone (DMZ)-resident controllers</li>\n<li>Update TIA Portal and STEP 7 software to current versions</li>\n<li>Consult <a href=\"https://www.siemens.com/en-us/content/cert-services/#6cOXgBJ3xa94mcOefayaUh\" target=\"_blank\">Siemens ProductCERT advisories</a> for information on known vulnerabilities, along with relevant workarounds and mitigations</li>\n<li>Test all updates in a development environment before production deployment</li>\n</ul>\n<h4><strong>3. Verify network segmentation and ensure PLCs are NOT accessible from the Internet [</strong><a href=\"https://d3fend.mitre.org/technique/d3f:NetworkIsolation/\" target=\"_blank\"><strong>D3-NI</strong></a><strong>]:</strong></h4>\n<ul type=\"disc\">\n<li>Audit firewall rules for any exposed S7comm services (Transmission Control Protocol [TCP] port <code>102</code>)</li>\n<li>Block TCP port <code>102</code> at perimeter firewalls entirely</li>\n<li>Implement a DMZ architecture that separates OT and IT networks</li>\n<li>Deploy unidirectional gateways for data historian connections where appropriate</li>\n<li>Verify there is no unauthorized routing between corporate and industrial networks</li>\n</ul>\n<h4><strong>4. Review and strengthen access controls [</strong><a href=\"https://d3fend.mitre.org/technique/d3f:NetworkAccessMediation/\" target=\"_blank\"><strong>D3-NAM</strong></a><strong>, </strong><a href=\"https://d3fend.mitre.org/technique/d3f:CredentialHardening/\" target=\"_blank\"><strong>D3-CH</strong></a><strong>]:</strong></h4>\n<ul type=\"disc\">\n<li>Restrict TIA Portal/STEP 7 access to authorized engineering workstations only by MAC/IP allowlisting on PLCs</li>\n<li>Enable PLC password protection on all Siemens S7 Series controllers&nbsp;</li>\n<li>Configure protection levels (such as write protection and read/write protection) on Siemens S7 Series devices</li>\n<li>Remove or change default SNMP community strings</li>\n<li>Implement application allowlisting on all engineering workstations</li>\n<li>Enable multi-factor authentication for all remote access to OT networks</li>\n</ul>\n<h4><strong>5. Enable comprehensive logging and monitoring [</strong><a href=\"https://d3fend.mitre.org/technique/d3f:PlatformMonitoring/\" target=\"_blank\"><strong>D3-PM</strong></a><strong>, </strong><a href=\"https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis/\" target=\"_blank\"><strong>D3-NTA</strong></a><strong>]:</strong></h4>\n<ul type=\"disc\">\n<li>Deploy ICS-aware intrusion detection&nbsp;(e.g., Claroty, Dragos Platform, Nozomi Networks, or similar)</li>\n<li>Monitor all S7comm traffic on TCP port <code>102</code>&nbsp;for connections outside maintenance windows</li>\n<li>Alert on unauthorized PUT/GET operations, especially write commands to data blocks or configuration areas of memory</li>\n<li>Log all TIA Portal/STEP 7 connections to PLCs with timestamps and source IPs</li>\n<li>Establish a baseline for legitimate behavior and configure monitoring tools to alert on deviations</li>\n<li>Monitor for Python processes with <code>snap7.dll</code> library imports on engineering workstations</li>\n<li>Watch for sequential IP scanning patterns or block reads of configuration data</li>\n</ul>\n<h4><strong>6. Implement S7-specific hardening measures [</strong><a href=\"https://d3fend.mitre.org/technique/d3f:ApplicationConfigurationHardening/\" target=\"_blank\"><strong>D3-ACH</strong></a><strong>]:</strong></h4>\n<ul type=\"disc\">\n<li>Disable web servers on Siemens S7 Series devices if not operationally required</li>\n<li>Disable unused communication protocols (such as Modbus TCP and PROFINET, if they are not required)</li>\n<li>Configure connection resources to limit simultaneous S7comm sessions</li>\n<li>Enable TIA Portal/STEP 7 \u201ccomplete restart protection\u201d and \u201cknow-how protection\u201d features where available</li>\n<li>Evaluate for ladder logic changes in online/offline modes</li>\n</ul>\n<h4><strong>7. Contact Siemens for model-specific guidance:</strong></h4>\n<ul type=\"disc\">\n<li>Engage Siemens Technical Support for hardening recommendations specific to your CPU models and firmware versions</li>\n<li>Verify patch compatibility with your specific operational environment and third-party integrations</li>\n<li>Request assistance with protection level configuration and access control implementation</li>\n</ul>\n<h2><strong>Conclusion</strong></h2>\n<p>There is an active threat targeting Internet-exposed Siemens S7 Series PLCs. The combination of known vulnerabilities, accessible exploitation libraries, and AI-assisted development creates a high-probability attack scenario against inadequately protected PLC installations. Organizations should treat this Cybersecurity Advisory with urgency and coordinate response efforts across security, engineering, executive leadership, plant operations, and vendor support teams to implement the recommended detection and hardening actions.</p>\n<h2><strong>Resources</strong></h2>\n<ul>\n<li><a href=\"https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology\">Primary Mitigations to Reduce Cyber Threats to Operational Technology</a></li>\n<li><a href=\"https://www.ic3.gov/CSA/2026/260114.pdf\" target=\"_blank\">Secure connectivity principles for Operational Technology (OT): How organisations should design, secure, and manage connectivity in OT</a></li>\n<li><a href=\"https://media.defense.gov/2022/Sep/22/2003083007/-1/-1/0/CSA_ICS_Know_the_Opponent_.PDF\" target=\"_blank\">Control System Defense: Know the Opponent</a></li>\n</ul>\n<h2><strong>Incident reporting&nbsp;</strong></h2>\n<p>U.S. organizations are encouraged to report suspicious or criminal activity related to information in this advisory to CISA and/or the FBI. Contact CISA via CISA\u2019s 24/7 Operations Center at <a href=\"mailto:contact@cisa.dhs.gov\">contact@cisa.dhs.gov</a> or 1-844-Say-CISA (1-844-729-2472). File a claim with FBI\u2019s <a href=\"https://ic3.gov/\" target=\"_blank\">Internet Crime Complaint Center</a> (IC3) or contact your local <a href=\"https://www.fbi.gov/contact-us/field-offices\" target=\"_blank\">FBI field office</a>. When available, please include the following information regarding the incident:&nbsp;</p>\n<ul type=\"disc\">\n<li>Date, time, and location of the incident;</li>\n<li>Type of activity;</li>\n<li>Number of people affected;</li>\n<li>Type of equipment used for the activity; and</li>\n<li>Name of the submitting company or organization, and a designated point of contact.</li>\n</ul>\n<p>Entities required to report incidents to DOE should follow established reporting requirements, as appropriate. For other energy sector inquiries, contact <a href=\"mailto:EnergySRMA@hq.doe.gov\">EnergySRMA@hq.doe.gov</a>.</p>\n<p>In addition, consider contacting Siemens ProductCERT via <a href=\"https://www.siemens.com/cert\" target=\"_blank\">https://www.siemens.com/cert</a>&nbsp;or email&nbsp;<a href=\"mailto:productcert@siemens.com\">productcert@siemens.com</a>.&nbsp;</p>\n<p><em><strong>Disclaimer of endorsement</strong></em><br>The information and opinions contained in this document are provided \"as is\" and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes.</p>\n<p><em><strong>Purpose</strong></em><br>This document was developed in furtherance of the authoring agencies\u2019 cybersecurity missions, including their responsibilities to identify and disseminate threats and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.</p>\n<p><em><strong>Contact</strong></em><br>Cybersecurity Report Feedback:&nbsp;<a href=\"mailto:CybersecurityReports@nsa.gov\">CybersecurityReports@nsa.gov</a></p>\n<p>Defense Industrial Base Inquiries and Cybersecurity Services:&nbsp;<a href=\"mailto:DIB_Defense@cyber.nsa.gov\">DIB_Defense@cyber.nsa.gov</a></p>\n<p>Media Inquiries / Press Desk: NSA Media Relations: 443-634-0721,&nbsp;<a href=\"mailto:MediaRelations@nsa.gov\">MediaRelations@nsa.gov</a></p>\n<p>Contact Siemens ProductCERT for up-to-date information about the security of Siemens products or to report cybersecurity vulnerabilities at&nbsp;<a href=\"mailto:productcert@siemens.com\">productcert@siemens.com</a>. For support with increasing the security of installed Siemens PLCs, contact Siemens Industrial Cybersecurity Services at&nbsp;<a href=\"mailto:services.automation@siemens.com\">services.automation@siemens.com</a>. See&nbsp;<a href=\"https://www.siemens.com/en-us/content/cert-services/\" target=\"_blank\">Siemens ProductCERT and Siemens CERT</a> for more information.</p>\n<h2><a class=\"ck-anchor\" id=\"AppA\"><strong>Appendix A</strong></a><strong>: MITRE ATT&amp;CK tactics and techniques</strong></h2>\n<p>See <a href=\"#Table1\"><strong>Table 1</strong></a><strong> </strong>for the threat actor tactics and techniques referenced in this advisory.</p>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table1\"></a><em><strong>Table 1: MITRE ATT&amp;CK tactics and techniques</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<p class=\"text-align-center\"><strong>Tactic</strong></p>\n</th>\n<th role=\"columnheader\">\n<p class=\"text-align-center\"><strong>Technique Title</strong></p>\n</th>\n<th role=\"columnheader\">\n<p class=\"text-align-center\"><strong>ID</strong></p>\n</th>\n<th role=\"columnheader\">\n<p class=\"text-align-center\"><strong>Use</strong></p>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Reconnaissance</td>\n<td>Search Open Technical Databases: Scan Databases</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1596/005/\" target=\"_blank\">T1596.005</a></td>\n<td>Using Internet scanning services&nbsp;to identify Internet-exposed or poorly segmented Siemens S7 Series PLCs</td>\n</tr>\n<tr>\n<td>Resource Development</td>\n<td>Develop Capabilities: Exploits</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1587/004/\" target=\"_blank\">T1587.004</a></td>\n<td>Developing exploits for known Siemens S7 Series PLC vulnerabilities</td>\n</tr>\n<tr>\n<td>Resource Development</td>\n<td>Obtain Capabilities: Artificial Intelligence</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1588/007/\" target=\"_blank\">T1588.007</a></td>\n<td>Rapidly iterating exploit code&nbsp;through AI-assisted development</td>\n</tr>\n<tr>\n<td>Execution</td>\n<td>Native API</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T0834/\" target=\"_blank\">T0834</a></td>\n<td>Deploying AI-generated Python scripts&nbsp;incorporating the <code>snap7.dll</code> library</td>\n</tr>\n<tr>\n<td>Execution</td>\n<td>Modify Controller Tasking</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T0821/\" target=\"_blank\">T0821</a></td>\n<td>Conducting write operations&nbsp;on data blocks, potentially for pre-positioning for effects operations</td>\n</tr>\n<tr>\n<td>Evasion</td>\n<td>Masquerading</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T0849/\" target=\"_blank\">T0849</a></td>\n<td>Masquerading as legitimate monitoring tools&nbsp;to evade detection</td>\n</tr>\n<tr>\n<td>Lateral Movement</td>\n<td>Insecure Credentials</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1694/\" target=\"_blank\">T1694</a></td>\n<td>Accessing exposed devices that have unconfigured (default) or minimally configured authentication</td>\n</tr>\n<tr>\n<td>Collection</td>\n<td>Data from Local System</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T0893/\" target=\"_blank\">T0893</a></td>\n<td>Conducting read operations&nbsp;on data blocks, potentially for reconnaissance</td>\n</tr>\n</tbody>\n</table>\n<h2><a class=\"ck-anchor\" id=\"AppB\"><strong>Appendix B</strong></a><strong>: MITRE D3FEND countermeasures</strong></h2>\n<p>See <a href=\"#Table2\"><strong>Table 2</strong></a> for a mapping of several of the cybersecurity countermeasures mentioned in this advisory.</p>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table2\"></a><em><strong>Table 2: MITRE D3FEND Countermeasures</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<p class=\"text-align-center\"><strong>Countermeasure Title</strong></p>\n</th>\n<th role=\"columnheader\">\n<p class=\"text-align-center\"><strong>ID</strong></p>\n</th>\n<th role=\"columnheader\">\n<p class=\"text-align-center\"><strong>Description</strong></p>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Hardware Component Inventory</td>\n<td><a href=\"https://d3fend.mitre.org/technique/d3f:HardwareComponentInventory/\" target=\"_blank\">D3-HCI</a></td>\n<td>Conduct an immediate inventory of all Siemens S7 Series PLCs</td>\n</tr>\n<tr>\n<td>Software Update</td>\n<td><a href=\"https://d3fend.mitre.org/technique/d3f:SoftwareUpdate/\" target=\"_blank\">D3-SU</a></td>\n<td>Apply critical security patches as soon as possible</td>\n</tr>\n<tr>\n<td>Network Isolation</td>\n<td><a href=\"https://d3fend.mitre.org/technique/d3f:NetworkIsolation/\" target=\"_blank\">D3-NI</a></td>\n<td>Verify network segmentation and ensure PLCs are <strong>not</strong> accessible from the Internet</td>\n</tr>\n<tr>\n<td>Network Access Mediation</td>\n<td><a href=\"https://d3fend.mitre.org/technique/d3f:NetworkAccessMediation/\" target=\"_blank\">D3-NAM</a></td>\n<td>Restrict TIA Portal/STEP 7 access to authorized engineering workstations only via MAC/IP allowlisting on PLCs</td>\n</tr>\n<tr>\n<td>Credential Hardening</td>\n<td><a href=\"https://d3fend.mitre.org/technique/d3f:CredentialHardening/\" target=\"_blank\">D3-CH</a></td>\n<td>\n<ul type=\"disc\">\n<li>Enable PLC password protection on all S7 controllers</li>\n<li>Enable multi-factor authentication for all remote access to OT networks</li>\n</ul>\n</td>\n</tr>\n<tr>\n<td>Platform Monitoring</td>\n<td><a href=\"https://d3fend.mitre.org/technique/d3f:PlatformMonitoring/\" target=\"_blank\">D3-PM</a></td>\n<td>\n<ul type=\"disc\">\n<li>Deploy ICS-aware intrusion detection</li>\n<li>Alert on unauthorized PUT/GET operations</li>\n<li>Monitor for unexpected behavior deviations</li>\n<li>Monitor for <code>snap7.dll library</code> imports</li>\n<li>Hunt for indicators of compromise</li>\n</ul>\n</td>\n</tr>\n<tr>\n<td>Network Traffic Analysis</td>\n<td><a href=\"https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis/\" target=\"_blank\">D3-NTA</a></td>\n<td>\n<ul type=\"disc\">\n<li>Alert on unexpected S7comm traffic on TCP port <code>102</code>&nbsp;</li>\n<li>Watch for sequential IP scanning patterns</li>\n</ul>\n</td>\n</tr>\n<tr>\n<td>Application Configuration Hardening</td>\n<td><a href=\"https://d3fend.mitre.org/technique/d3f:ApplicationConfigurationHardening/\" target=\"_blank\">D3-ACH</a></td>\n<td>\n<ul type=\"disc\">\n<li>Disable unused web servers and protocols</li>\n<li>Remove SNMP community strings</li>\n<li>Watch for ladder logic changes</li>\n</ul>\n</td>\n</tr>\n</tbody>\n</table>\n<h2><strong>Notes</strong></h2>\n<p><a class=\"ck-anchor\" id=\"Note1\"><sup>1</sup></a> MITRE and ATT&amp;CK are registered trademarks of The MITRE Corporation. MITRE D3FEND is a trademark of the MITRE Corporation.</p>",
        "summary_is_html": true,
        "first_seen": "Wed, 19 Aug 26 12:00:00 +0000",
        "last_updated": "Wed, 19 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/19/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/19/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-64849\" target=\"_blank\">CVE-2026-64849</a> MLflow Server-Side Request Forgery Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Wed, 19 Aug 26 12:00:00 +0000",
        "last_updated": "Wed, 19 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-230-02",
        "title": "Siemens Simcenter Nastran",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-230-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-230-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions for the affected products and recommends to update to the latest versions.</strong></p>\n<p>The following versions of Siemens Simcenter Nastran are affected:</p>\n<ul>\n<li>Simcenter Femap vers:intdot/&lt;2606 (CVE-2026-59086)</li>\n<li>Simcenter Nastran vers:intdot/&lt;2606 (CVE-2026-59086)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.8</td>\n<td>Siemens</td>\n<td>Siemens Simcenter Nastran</td>\n<td>Stack-based Buffer Overflow</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Defense Industrial Base, Energy, Healthcare and Public Health, Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-59086</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-59086\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Simcenter Nastran</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Simcenter Femap &lt; V2606, Simcenter Nastran &lt; V2606</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V2606 or later version<br><a href=\"https://support.sw.siemens.com/product/275652363/\">https://support.sw.siemens.com/product/275652363/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/121.html\">CWE-121 Stack-based Buffer Overflow</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Michael Heinzl reported this vulnerability to Siemens ProductCERT.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-069220 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-11</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-11</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-08-13</td>\n<td>2</td>\n<td>Added Simcenter Femap with fix</td>\n</tr>\n<tr>\n<td>2026-08-18</td>\n<td>3</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-069220 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 18 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 18 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/18/cisa-adds-four-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Four Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/18/cisa-adds-four-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added four new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-33824\" target=\"_blank\">CVE-2026-33824</a> Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-55040\" target=\"_blank\">CVE-2026-55040</a> Microsoft SharePoint Weak Authentication Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-59310\" target=\"_blank\">CVE-2026-59310</a> Broadcom VMware vCenter Path Traversal Vulnerability &nbsp;</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-65400\" target=\"_blank\">CVE-2026-65400</a> Apple macOS Improper Authentication Vulnerability</li>\n</ul>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.</p>",
        "summary_is_html": true,
        "first_seen": "Tue, 18 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 18 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-230-01",
        "title": "CISA Malcolm",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-230-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-230-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code.</strong></p>\n<p>The following versions of CISA Malcolm are affected:</p>\n<ul>\n<li>Malcolm &lt;26.06.1 (CVE-2026-55676)</li>\n<li>Malcolm &lt;26.07.0 (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177)</li>\n<li>Malcolm &lt;=26.07.1 (CVE-2026-19670, CVE-2026-19671)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.8</td>\n<td>CISA</td>\n<td>CISA Malcolm</td>\n<td>Allocation of Resources Without Limits or Throttling, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangerous Type, Incorrect Authorization, Improper Handling of Highly Compressed Data (Data Amplification)</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-63133</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, safe-extract.py extracts uploaded archives with no limit on entry count, directory depth, total entries, or output size. A small malicious archive containing a large number of directory or file entries causes the filebeat processing container to create an unbounded number of filesystem objects, exhausting inodes or filesystem metadata and denying service to the processing pipeline and any service sharing the same mount. Version 26.07.0 fixes the issue.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-63133\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>CISA Malcolm</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>CISA</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CISA Malcolm: &lt;26.07.0</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Malcolm version 26.07.0 addresses these issues. For more information, see https://github.com/cisagov/Malcolm/pull/1043. (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177)<br><a href=\"https://github.com/cisagov/Malcolm/pull/1043\">https://github.com/cisagov/Malcolm/pull/1043</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/770.html\">CWE-770 Allocation of Resources Without Limits or Throttling</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-63134</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, safe-extract.py protects file extraction with libarchive's secure flags, but creates directory entries with a raw os.makedirs(os.path.join(dest, entry.pathname)) that has no traversal protection. An uploaded malicious archive containing a directory entry with a ../ sequence or an absolute path causes the filebeat processing container to create directories outside the intended extraction directory. Version 26.07.0 fixes the issue.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-63134\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>CISA Malcolm</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>CISA</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CISA Malcolm: &lt;26.07.0</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Malcolm version 26.07.0 addresses these issues. For more information, see https://github.com/cisagov/Malcolm/pull/1043. (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177)<br><a href=\"https://github.com/cisagov/Malcolm/pull/1043\">https://github.com/cisagov/Malcolm/pull/1043</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/22.html\">CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.4</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-55676</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at POST /server/php/submit.php and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that should restrict accepted file types is an empty array by default (file-upload/php/config.php:16), so the type check is a no-op and every extension is accepted. The filename sanitizer keeps the .php extension intact. Committed files land in /var/www/upload/server/php/files (file-upload/php/config.php:7), and the component's nginx routes any URL ending in .php to php-fpm. An authenticated GET /server/php/files/.php then executes the uploaded code as www-data. Prior to version 26.06.1, in RBAC mode, the upload endpoint is reachable by the granular ROLE_UPLOAD role (nginx/lua/nginx_auth_helpers.lua:71), a role intended only for submitting capture files. As a result, a user holding the upload-only role runs arbitrary PHP as www-data inside the file-upload container. Version 26.06.1 fixes the issue.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-55676\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>CISA Malcolm</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>CISA</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CISA Malcolm: &lt;26.06.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Malcolm version 26.06.1 addresses this issue. For more information, see https://github.com/cisagov/Malcolm/pull/1026. (CVE-2026-55676)<br><a href=\"https://github.com/cisagov/Malcolm/pull/1026\">https://github.com/cisagov/Malcolm/pull/1026</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/434.html\">CWE-434 Unrestricted Upload of File with Dangerous Type</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-63177</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized ngx.var.request_uri, while Nginx itself routes requests using the normalized path. An authenticated low-privilege user can prepend a traversal segment (for example /x/../upload/...) so that Nginx routes the request to a restricted backend while the Lua role check fails to match any rule and falls open, granting access it should deny. Version 26.07.0 fixes the issue.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-63177\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>CISA Malcolm</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>CISA</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CISA Malcolm: &lt;26.07.0</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Malcolm version 26.07.0 addresses these issues. For more information, see https://github.com/cisagov/Malcolm/pull/1043. (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177)<br><a href=\"https://github.com/cisagov/Malcolm/pull/1043\">https://github.com/cisagov/Malcolm/pull/1043</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/863.html\">CWE-863 Incorrect Authorization</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:L/SI:L/SA:L\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:L/SI:L/SA:L</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-19670</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /auth, /admin_login, /arkime/api/esadmin, NetBox, upload endpoints) by pattern-matching the raw, percent-encoded request URI. Nginx itself, however, selects which location block actually serves the request using the percent-decoded, normalized URI. Because the RBAC check never percent-decodes its input, an authenticated low-privilege user can request an admin-only path using percent-encoding (e.g. /%68tadmin.php) and have nginx route it to the restricted location while the Lua RBAC gate evaluating the un-decoded raw string finds no matching restriction and grants access.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-19670\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>CISA Malcolm</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>CISA</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CISA Malcolm: &lt;=26.07.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Malcolm version 26.08.0 addresses this issue. For more information, see https://github.com/cisagov/Malcolm/security/advisories/GHSA-jr6p-63pg-hr6g. (CVE-2026-19670)<br><a href=\"https://github.com/cisagov/Malcolm/security/advisories/GHSA-jr6p-63pg-hr6g\">https://github.com/cisagov/Malcolm/security/advisories/GHSA-jr6p-63pg-hr6g</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/863.html\">CWE-863 Incorrect Authorization</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.4</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-19671</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extracting container archives (zip/tar/rar/7z via libarchive), but those limits are not applied when the uploaded file is a single-stream compressed format (.gz, .bz2, .xz, .lzma, .lz) that isn't a .tar.*-style archive. Any authenticated user permitted to upload PCAP/log files can upload a small, highly compressible file (e.g. a gzip bomb) that decompresses to an effectively unbounded size on disk, exhausting the shared Docker volume used by OpenSearch, Logstash, Arkime, and Zeek, and disrupting the platform for all users.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-19671\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>CISA Malcolm</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>CISA</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CISA Malcolm: &lt;=26.07.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Malcolm version 26.08.0 addresses this issue. For more information, see https://github.com/cisagov/Malcolm/security/advisories/GHSA-f2v6-8cj4-mhr6. (CVE-2026-19671)<br><a href=\"https://github.com/cisagov/Malcolm/security/advisories/GHSA-f2v6-8cj4-mhr6\">https://github.com/cisagov/Malcolm/security/advisories/GHSA-f2v6-8cj4-mhr6</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/409.html\">CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>pavanchow reported CVE-2026-63133, CVE-2026-63134, and CVE-2026-63177 to CISA.</li>\n<li>kah-ja, DeathRipper21 reported CVE-2026-55676 to CISA.</li>\n<li>tinyb0y reported CVE-2026-19670 and CVE-2026-19671 to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-18</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-18</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 18 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 18 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/17/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog\u00a0",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/17/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-62593\" target=\"_blank\">CVE-2025-62593</a> Ray-Project Ray Code Injection Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Mon, 17 Aug 26 12:00:00 +0000",
        "last_updated": "Mon, 17 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-14",
        "title": "Johnson Controls Metasys",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-14",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-14.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access.</strong></p>\n<p>The following versions of Johnson Controls Metasys are affected:</p>\n<ul>\n<li>Metasys 12 vers:all/* (CVE-2026-34491)</li>\n<li>Metasys 13 vers:all/* (CVE-2026-34491)</li>\n<li>Metasys 14</li>\n<li>Metasys 15</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8</td>\n<td>Johnson Controls Inc</td>\n<td>Johnson Controls Metasys</td>\n<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Ireland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-34491</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A low-privilege user can inject a malicious XSS payload into the Metasys UI via a crafted URL. The payload persists across logins and executes in the browser context of other users, including administrators.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-34491\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls Metasys</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls Inc</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls Inc Metasys 12: vers:all/*, Johnson Controls Inc Metasys 13: vers:all/*, Johnson Controls Inc Metasys 14: &lt;v14.1.5, Johnson Controls Inc Metasys 15: &lt;v15.0.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Johnson Controls recommends the following actions:</p>\n<p><strong>Mitigation</strong><br>User are recommended to apply the latest available patches for affected Metasys versions</p>\n<p><strong>Mitigation</strong><br>Metasys 16.0: Not impacted, fixed prior to release</p>\n<p><strong>Vendor fix</strong><br>Metasys 15.0: Patch released 2026-03-25</p>\n<p><strong>Vendor fix</strong><br>Metasys 14.1.5: Forecast release 2026-07-15</p>\n<p><strong>Vendor fix</strong><br>Metasys 13: End of support, update to later version</p>\n<p><strong>Vendor fix</strong><br>Metasys 12: End of support, update to later version</p>\n<p><strong>Mitigation</strong><br>Metasys 11 &amp; prior: Not affected (vulnerability introduced at version 12)</p>\n<p><strong>Mitigation</strong><br>To help reduce the risk of exploitation, we suggest considering the following defensive measures:</p>\n<p><strong>Mitigation</strong><br>Upgrade to Metasys version 16.0 or apply the latest available patch for your version (15.0.1 or 14.1.5 when available)</p>\n<p><strong>Mitigation</strong><br>Restrict network access to the Metasys UI to trusted networks and users only; do not expose the interface directly to the internet</p>\n<p><strong>Mitigation</strong><br>Implement network segmentation to isolate building automation systems from the corporate IT network</p>\n<p><strong>Mitigation</strong><br>Enforce least-privilege access controls \u2013 limit user accounts to the minimum permissions necessary</p>\n<p><strong>Mitigation</strong><br>Implement Content Security Policy (CSP) headers and other HTTP security headers where possible at the network/proxy level</p>\n<p><strong>Mitigation</strong><br>Monitor for suspicious URL patterns and unexpected script execution in Metasys UI access logs</p>\n<p><strong>Mitigation</strong><br>Use a web application firewall (WAF) in front of the Metasys UI to detect and block common XSS payloads</p>\n<p><strong>Mitigation</strong><br>Educate users to avoid clicking on untrusted or unexpected links that target the Metasys UI</p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-11 at the following location: Security Advisories.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/79.html\">CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>An anonymous researcher reported this vulnerability to Johnson Controls</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-13</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-13</td>\n<td>1</td>\n<td>Initial Publication.</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-09",
        "title": "Siemens Siveillance Video",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-09",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-09.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions.</strong></p>\n<p>The following versions of Siemens Siveillance Video are affected:</p>\n<ul>\n<li>Siveillance Video V2023 R3 vers:intdot/&lt;23.3.27 (CVE-2026-3014)</li>\n<li>Siveillance Video V2024 R1 vers:intdot/&lt;24.1.16 (CVE-2026-3014)</li>\n<li>Siveillance Video V2025 vers:intdot/&lt;25.1.15 (CVE-2026-3014)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.1</td>\n<td>Siemens</td>\n<td>Siemens Siveillance Video</td>\n<td>Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Communications, Commercial Facilities</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-3014</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Milestone has released a new version of XProtect\u00ae (and several cumulative patch updates) which fix security vulnerability in Management Server API. The vulnerability causes users with edit permissions to the Management Server to be able to execute arbitrary code in context of the Management Server Service.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-3014\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Siveillance Video</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Siveillance Video V2023 R3 &lt; V23.3.27, Siveillance Video V2024 R1 &lt; V24.1.16, Siveillance Video V2025 &lt; V25.1.15</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V23.3 HotfixRev27 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109827783/\">https://support.industry.siemens.com/cs/ww/en/view/109827783/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V24.1 HotfixRev16 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109976123/\">https://support.industry.siemens.com/cs/ww/en/view/109976123/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V25.1 HotfixRev15 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109988670/\">https://support.industry.siemens.com/cs/ww/en/view/109988670/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/78.html\">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.1</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Milestone PSIRT reported this vulnerability to Siemens</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure Siemens strongly recommends to protect network access to affected products with appropriate mechanisms. It is advised to follow recommended security practices in order to run the devices in a protected IT environment.</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens SSA-825228 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-11</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-11</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-08-13</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens SSA-825228 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-03",
        "title": "Johnson Controls Inc. Airwall",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-03",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-03.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized access to protected system resources.</strong></p>\n<p>The following versions of Johnson Controls Inc. Airwall are affected:</p>\n<ul>\n<li>Airwall &lt;=4.0.4 (CVE-2026-64887, CVE-2026-34492)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 6.8</td>\n<td>Johnson Controls Inc.</td>\n<td>Johnson Controls Inc. Airwall</td>\n<td>Use of Hard-coded Cryptographic Key, External Control of File Name or Path</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Ireland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-64887</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A hardcoded password or cryptographic key was identified in the Airwall application. A hardcoded credential leads to a significant authentication failure that can be difficult for system or application administrators to detect. Once discovered, it is difficult to remediate without manually modifying or patching the software. The hardcoded key is identical across all installations of the product and across all customer organizations, meaning a single disclosure of the key - common on the internet - grants any knowledgeable attacker access to all affected deployments. An attacker with access to application code or binary files can use the hardcoded key to decrypt sensitive application data stored in configuration and database files, enabling further data disclosure or compromise of application infrastructure.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-64887\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls Inc. Airwall</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls Inc.</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls Inc. Airwall: &lt;=4.0.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>To help reduce risk of exploitation, Johnson Controls recommends the following defensive measures: Apply v4.1.0 or later patches for all Airwalls.</p>\n<p><strong>Mitigation</strong><br>Store all cryptographic keys in a secure key management system (KMS) or hardware security module (HSM) rather than embedding them in source code or configuration files. (CVE-2026-64887)</p>\n<p><strong>Mitigation</strong><br>Implement a regular key rotation policy to limit the exposure window if a key is compromised. (CVE-2026-64887)</p>\n<p><strong>Mitigation</strong><br>Use unique cryptographic keys per device, installation, or deployment instance to prevent a single compromised key from affecting all installations. (CVE-2026-64887)</p>\n<p><strong>Mitigation</strong><br>Remove any hard-coded keys from source code repositories and binaries, replacing them with references to secure external key stores. (CVE-2026-64887)Apply the principle of least privilege to key access, ensuring only authorized processes and personnel can retrieve cryptographic material. (CVE-2026-64887)</p>\n<p><strong>Mitigation</strong><br>Use static analysis and secrets-scanning tools in CI/CD pipelines to detect and prevent hard-coded keys from being committed to source control. (CVE-2026-64887)</p>\n<p><strong>Mitigation</strong><br>Encrypt keys at rest and in transit and ensure key-wrapping mechanisms are in place for any keys stored on disk. (CVE-2026-64887)</p>\n<p><strong>Mitigation</strong><br>Audit and monitor access to cryptographic keys, logging all retrieval and usage events for anomaly detection. (CVE-2026-64887)</p>\n<p><strong>Mitigation</strong><br>Refer to and follow all steps in the product hardening guide or the JCI universal hardening guide found here https://www.johnsoncontrols.com/trust-center/cybersecurity/resources (CVE-2026-64887)<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/resources\">https://www.johnsoncontrols.com/trust-center/cybersecurity/resources</a></p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-25 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories (CVE-2026-64887)<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories\">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/321.html\">CWE-321 Use of Hard-coded Cryptographic Key</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N\">CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-34492</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An arbitrary file read vulnerability was identified in the Airwall application. This issue occurs when user-supplied input is directly incorporated into filesystem access functions without adequate validation or sanitization. As a result, an attacker can request and obtain the contents of arbitrary files on the server, including sensitive configuration files, source code, credential stores, and private keys, provided the application process has permission to read them. The vulnerability is commonly exploited through path traversal sequences (e.g., ../) or absolute file paths (e.g., /etc/passwd). Encoding variations of traversal sequences (e.g., %2e%2e%2f) can also bypass basic filters.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-34492\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls Inc. Airwall</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls Inc.</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls Inc. Airwall: &lt;=4.0.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>To help reduce risk of exploitation, Johnson Controls recommends the following defensive measures: Apply v4.1.0 or later patches for all Airwalls.</p>\n<p><strong>Mitigation</strong><br>Validate and sanitize all user-supplied input before using it in file system operations (CVE-2026-34492)</p>\n<p><strong>Mitigation</strong><br>Implement strict allowlists for permitted file paths, file names, and directories (CVE-2026-34492)</p>\n<p><strong>Mitigation</strong><br>Use canonicalization to resolve path traversal sequences before validation (CVE-2026-34492)</p>\n<p><strong>Mitigation</strong><br>Apply the principle of least privilege to the application file system access permissions (CVE-2026-34492)</p>\n<p><strong>Mitigation</strong><br>Deploy sandboxing or chroot jails to restrict the application's file system scope (CVE-2026-34492)</p>\n<p><strong>Mitigation</strong><br>Avoid passing user-controlled data directly to file system APIs (CVE-2026-34492)</p>\n<p><strong>Mitigation</strong><br>Refer to and follow all steps in the product hardening guide or the JCI universal hardening guide found here https://www.johnsoncontrols.com/trust-center/cybersecurity/resources (CVE-2026-34492)<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/resources\">https://www.johnsoncontrols.com/trust-center/cybersecurity/resources</a></p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-18 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories (CVE-2026-34492)<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories\">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/73.html\">CWE-73 External Control of File Name or Path</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.4</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L\">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Johnson Controls reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this (these) vulnerability(ies) has been reported to CISA at this time. This (these) vulnerability(ies) is (are) not exploitable remotely. This (these) vulnerability(ies) has (have) a high attack complexity.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-13</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-13</td>\n<td>1</td>\n<td>Initial Republication of Johnson Controls JCI-PSA-2026-18 and JCI-PSA-2026-25</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-08",
        "title": "Siemens Desigo DXR and PXC Controllers",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-08",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-08.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions.</strong></p>\n<p>The following versions of Siemens Desigo DXR and PXC Controllers are affected:</p>\n<ul>\n<li>Desigo DXR2 vers:intdot/&lt;01.21.233.16-7862 (CVE-2026-59693)</li>\n<li>Desigo PXC3 vers:intdot/&lt;01.21.233.16-7862 (CVE-2026-59693)</li>\n<li>Desigo PXC4 vers:intdot/&lt;02.21.194.36-2715 (CVE-2026-59693)</li>\n<li>Desigo PXC5.E003 vers:intdot/&lt;02.21.194.36-2715 (CVE-2026-59693)</li>\n<li>Desigo PXC5.E24 vers:intdot/&lt;02.21.194.36-2715 (CVE-2026-59693)</li>\n<li>Desigo PXC7 vers:intdot/&lt;02.21.194.36-2715 (CVE-2026-59693)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 4.3</td>\n<td>Siemens</td>\n<td>Siemens Desigo DXR and PXC Controllers</td>\n<td>Improper Check for Unusual or Exceptional Conditions</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Commercial Facilities, Critical Manufacturing, Energy, Healthcare and Public Health, Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-59693</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected devices are vulnerable to a denial-of-service (DoS) vulnerability. An attacker can exploit this issue by sending a malformed BACnet packet, causing the device to stop responding to BACnet queries. Recovery requires a device reset or reboot to restore normal functionality.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-59693\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Desigo DXR and PXC Controllers</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Desigo DXR2 &lt; V01.21.233.16-7862, Desigo PXC3 &lt; V01.21.233.16-7862, Desigo PXC4 &lt; V02.21.194.36-2715, Desigo PXC5.E003 &lt; V02.21.194.36-2715, Desigo PXC5.E24 &lt; V02.21.194.36-2715, Desigo PXC7 &lt; V02.21.194.36-2715</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V01.21.233.16-7862 or later version Please contact your local Siemens office for additional support in obtaining the update.</p>\n<p><strong>Vendor fix</strong><br>Update to V02.21.194.36-2715 or later version Please contact your local Siemens office for additional support in obtaining the update.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/754.html\">CWE-754 Improper Check for Unusual or Exceptional Conditions</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>4.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Thomas EBI of Sauter reported this vulnerability to Siemens</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and following the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens SSA-781903 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-11</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-11</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-08-13</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens SSA-781903 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-07",
        "title": "Siemens License Server (SLS)",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-07",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-07.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version.</strong></p>\n<p>The following versions of Siemens License Server (SLS) are affected:</p>\n<ul>\n<li>Siemens License Server (SLS) vers:intdot/&lt;5.1, vers:intdot/&lt;5.3 (CVE-2026-69108, CVE-2026-69109)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>Siemens</td>\n<td>Siemens License Server (SLS)</td>\n<td>Incorrect Permission Assignment for Critical Resource, Path Traversal: '.../...//'</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-69108</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and plant malicious files as root, leading to full system compromise.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-69108\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens License Server (SLS)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Siemens License Server (SLS) &lt; V5.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V5.1 or later version<br><a href=\"https://support.sw.siemens.com/product/1586485382/\">https://support.sw.siemens.com/product/1586485382/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/732.html\">CWE-732 Incorrect Permission Assignment for Critical Resource</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N\">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-69109</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the application.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-69109\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens License Server (SLS)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Siemens License Server (SLS) &lt; V5.3</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V5.3 or later version<br><a href=\"https://support.sw.siemens.com/product/1586485382/\">https://support.sw.siemens.com/product/1586485382/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/35.html\">CWE-35 Path Traversal: '.../...//'</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-077553 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-11</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-11</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-08-13</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-077553 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-225-01",
        "title": "Flow Neuroscience FL-100",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-225-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-225-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to manipulate brain stimulation parameters and override safety limits.</strong></p>\n<p>The following versions of Flow Neuroscience FL-100 are affected:</p>\n<ul>\n<li>Flow Neuroscience FL-100</li>\n<li>Halo Neuroscience FL-100</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.1</td>\n<td>Flow Neuroscience</td>\n<td>Flow Neuroscience FL-100</td>\n<td>Use of Hard-coded Credentials</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Healthcare and Public Health</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Sweden</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-18164</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth range to arbitrarilymanipulate brain stimulation parameters and state.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-18164\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Flow Neuroscience FL-100</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Flow Neuroscience</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Flow Neuroscience Flow Neuroscience FL-100: &lt;July_2026, Flow Neuroscience Halo Neuroscience FL-100: &lt;July_2026</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users are encouraged to install the latest firmware updates provided by Flow Neuroscience via the Flow app.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/798.html\">CWE-798 Use of Hard-coded Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>A.C. Buglione reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-13</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-13</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-13",
        "title": "Siemens LOGO! Soft Comfort",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-13",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-13.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt project data or remove project passwords. The lack of password salting enables offline dictionary or brute-force attacks against the password hashes. Successful exploitation could result in unauthorized access to, or modification of, sensitive project logic and configurations. Siemens has released a new version for LOGO! Soft Comfort and recommends to update to the latest version.</strong></p>\n<p>The following versions of Siemens LOGO! Soft Comfort are affected:</p>\n<ul>\n<li>LOGO! Soft Comfort vers:intdot/&lt;9 (CVE-2026-57262, CVE-2026-57263)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 6.8</td>\n<td>Siemens</td>\n<td>Siemens LOGO! Soft Comfort</td>\n<td>Use of Hard-coded Cryptographic Key, Use of a One-Way Hash without a Salt</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Commercial Facilities, Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-57262</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Affected products use a static, hardcoded AES master key to encrypt project files. This could allow a local attacker to extract the master key from the application files or memory and use it to decrypt project files or remove project passwords entirely without knowing the actual user-defined password.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-57262\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens LOGO! Soft Comfort</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>LOGO! Soft Comfort &lt; V9</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V9 or later version Note: A hardware upgrade to LOGO! V9 BM or later is also required to avoid compatibility mode, in which the vulnerabilities addressed by this advisory remain present.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/321.html\">CWE-321 Use of Hard-coded Cryptographic Key</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N\">CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-57263</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The project password feature in the affected products stores the password as an unsalted SHA-256 hash. This could allow an attacker who has obtained the project file to perform efficient offline dictionary or brute-force attacks against the unsalted hash.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-57263\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens LOGO! Soft Comfort</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>LOGO! Soft Comfort &lt; V9</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V9 or later version Note: A hardware upgrade to LOGO! V9 BM or later is also required to avoid compatibility mode, in which the vulnerabilities addressed by this advisory remain present.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/759.html\">CWE-759 Use of a One-Way Hash without a Salt</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N\">CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-751328 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-11</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-11</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-08-13</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-751328 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-12",
        "title": "Siemens Solid Edge",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-12",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-12.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.</strong></p>\n<p>The following versions of Siemens Solid Edge are affected:</p>\n<ul>\n<li>Solid Edge SE2025 vers:intdot/&lt;225.0.15 (CVE-2026-50058, CVE-2026-50059, CVE-2026-50060, CVE-2026-50061, CVE-2026-50062, CVE-2026-50063, CVE-2026-50064)</li>\n<li>Solid Edge SE2026 vers:intdot/&lt;226.0.7 (CVE-2026-50058, CVE-2026-50059, CVE-2026-50060, CVE-2026-50061, CVE-2026-50062, CVE-2026-50063, CVE-2026-50064)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.8</td>\n<td>Siemens</td>\n<td>Siemens Solid Edge</td>\n<td>Out-of-bounds Read, Out-of-bounds Write, Use After Free</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-50058</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected applications contains an out of bounds read vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-50058\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Solid Edge</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Solid Edge SE2025 &lt; V225.0.15, Solid Edge SE2026 &lt; V226.0.7</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V225.0 Update 15 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V226.0 Update 7 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-50059</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected applications contains an out of bounds write vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-50059\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Solid Edge</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Solid Edge SE2025 &lt; V225.0.15, Solid Edge SE2026 &lt; V226.0.7</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V225.0 Update 15 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V226.0 Update 7 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-50060</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-50060\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Solid Edge</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Solid Edge SE2025 &lt; V225.0.15, Solid Edge SE2026 &lt; V226.0.7</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V225.0 Update 15 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V226.0 Update 7 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/416.html\">CWE-416 Use After Free</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-50061</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-50061\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Solid Edge</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Solid Edge SE2025 &lt; V225.0.15, Solid Edge SE2026 &lt; V226.0.7</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V225.0 Update 15 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V226.0 Update 7 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/416.html\">CWE-416 Use After Free</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-50062</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected applications contains an out of bounds read vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-50062\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Solid Edge</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Solid Edge SE2025 &lt; V225.0.15, Solid Edge SE2026 &lt; V226.0.7</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V225.0 Update 15 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V226.0 Update 7 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-50063</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected applications contains an out of bounds read vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-50063\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Solid Edge</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Solid Edge SE2025 &lt; V225.0.15, Solid Edge SE2026 &lt; V226.0.7</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V225.0 Update 15 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V226.0 Update 7 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-50064</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected applications contains an out of bounds write vulnerability while parsing specially crafted PSM files. This could allow an attacker to execute code in the context of the current process.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-50064\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Solid Edge</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Solid Edge SE2025 &lt; V225.0.15, Solid Edge SE2026 &lt; V226.0.7</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V225.0 Update 15 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V226.0 Update 7 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-621657 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-11</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-11</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-08-13</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-621657 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-05",
        "title": "ANDRITZ HIPASE-250 and 250 SCALA",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-05",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-05.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to read data from the device or gain access to affected workstations.</strong></p>\n<p>The following versions of ANDRITZ HIPASE-250 and 250 SCALA are affected:</p>\n<ul>\n<li>HIPASE-250 &lt;=7.20 (CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, CVE-2026-65313)</li>\n<li>250 SCALA &lt;=7.20 (CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, CVE-2026-65313)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.1</td>\n<td>ANDRITZ</td>\n<td>ANDRITZ HIPASE-250 and 250 SCALA</td>\n<td>Storing Passwords in a Recoverable Format, Missing Authentication for Critical Function, Use of Hard-coded Credentials</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Austria</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-65309</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-65309\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ANDRITZ HIPASE-250 and 250 SCALA</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ANDRITZ</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ANDRITZ HIPASE-250: &lt;=7.20, ANDRITZ 250 SCALA: &lt;=7.20</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>ANDRITZ has addressed these issues in version V8.00.00 (released 2024-12) and in version V8.15.00 (released 2026-07) and encourages users to keep their systems updated to the latest version (currently HIPASE-250 Version V8.15.00). For more information, users can contact ANDRITZ at the following website: https://www.andritz.com/group-en/contact<br><a href=\"https://www.andritz.com/group-en/contact\">https://www.andritz.com/group-en/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/257.html\">CWE-257 Storing Passwords in a Recoverable Format</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-65310</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with network access can read live process values and server configuration.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-65310\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ANDRITZ HIPASE-250 and 250 SCALA</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ANDRITZ</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ANDRITZ HIPASE-250: &lt;=7.20, ANDRITZ 250 SCALA: &lt;=7.20</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>ANDRITZ has addressed these issues in version V8.00.00 (released 2024-12) and in version V8.15.00 (released 2026-07) and encourages users to keep their systems updated to the latest version (currently HIPASE-250 Version V8.15.00). For more information, users can contact ANDRITZ at the following website: https://www.andritz.com/group-en/contact<br><a href=\"https://www.andritz.com/group-en/contact\">https://www.andritz.com/group-en/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-65311</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target without requiring authentication. A remote, unauthenticated attacker with network access to the service may suppress audit logging, potentially concealing other activity on the system.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-65311\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ANDRITZ HIPASE-250 and 250 SCALA</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ANDRITZ</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ANDRITZ HIPASE-250: &lt;=7.20, ANDRITZ 250 SCALA: &lt;=7.20</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>ANDRITZ has addressed these issues in version V8.00.00 (released 2024-12) and in version V8.15.00 (released 2026-07) and encourages users to keep their systems updated to the latest version (currently HIPASE-250 Version V8.15.00). For more information, users can contact ANDRITZ at the following website: https://www.andritz.com/group-en/contact<br><a href=\"https://www.andritz.com/group-en/contact\">https://www.andritz.com/group-en/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-65313</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-65313\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ANDRITZ HIPASE-250 and 250 SCALA</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ANDRITZ</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ANDRITZ HIPASE-250: &lt;=7.20, ANDRITZ 250 SCALA: &lt;=7.20</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>ANDRITZ has addressed these issues in version V8.00.00 (released 2024-12) and in version V8.15.00 (released 2026-07) and encourages users to keep their systems updated to the latest version (currently HIPASE-250 Version V8.15.00). For more information, users can contact ANDRITZ at the following website: https://www.andritz.com/group-en/contact<br><a href=\"https://www.andritz.com/group-en/contact\">https://www.andritz.com/group-en/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/798.html\">CWE-798 Use of Hard-coded Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Duc Anh Nguyen and Ta Duc Thien of NTCS OT Penetration Testing Team reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-13</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-13</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-11",
        "title": "Siemens Simcenter Femap",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-11",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-11.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for Simcenter Femap and recommends to update to the latest version.</strong></p>\n<p>The following versions of Siemens Simcenter Femap are affected:</p>\n<ul>\n<li>Simcenter Femap vers:intdot/&lt;2606.0001 (CVE-2026-59700, CVE-2026-59701)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.8</td>\n<td>Siemens</td>\n<td>Siemens Simcenter Femap</td>\n<td>Out-of-bounds Read</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-59700</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-59700\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Simcenter Femap</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Simcenter Femap &lt; V2606.0001</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V2606.0001 or later version<br><a href=\"https://support.sw.siemens.com/product/275652363/\">https://support.sw.siemens.com/product/275652363/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-59701</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-59701\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Simcenter Femap</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Simcenter Femap &lt; V2606.0001</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V2606.0001 or later version<br><a href=\"https://support.sw.siemens.com/product/275652363/\">https://support.sw.siemens.com/product/275652363/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-584312 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-11</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-11</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-08-13</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-584312 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-01",
        "title": "AVEVA Enterprise SCADA",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization.</strong></p>\n<p>The following versions of AVEVA Enterprise SCADA are affected:</p>\n<ul>\n<li>Enterprise SCADA 2025 (CVE-2025-7639)</li>\n<li>Enterprise SCADA &gt;=2024|&lt;=2024_SP1_P01 (CVE-2025-7639)</li>\n<li>Enterprise SCADA &gt;=2023|&lt;=2023_SP1 (CVE-2025-7639)</li>\n<li>Enterprise SCADA &gt;=2022|&lt;=2022_SP2_P2 (CVE-2025-7639)</li>\n<li>Enterprise SCADA &lt;=2021_SP2_P5 (CVE-2025-7639)</li>\n<li>Enterprise SCADA HMI 2024|2024|R2 (CVE-2025-7639)</li>\n<li>Enterprise SCADA HMI &lt;=2023_P1 (CVE-2025-7639)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.1</td>\n<td>AVEVA</td>\n<td>AVEVA Enterprise SCADA</td>\n<td>Deserialization of Untrusted Data</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United Kingdom</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-7639</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The vulnerability, if exploited, could allow an authenticated miscreant with \"DNA Authority - Operator\" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of Enterprise SCADA security group \"DNA Apps\".</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-7639\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>AVEVA Enterprise SCADA</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>AVEVA</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>AVEVA Enterprise SCADA: 2025, AVEVA Enterprise SCADA: &gt;=2024|&lt;=2024_SP1_P01, AVEVA Enterprise SCADA: &gt;=2023|&lt;=2023_SP1, AVEVA Enterprise SCADA: &gt;=2022|&lt;=2022_SP2_P2, AVEVA Enterprise SCADA: &lt;=2021_SP2_P5, AVEVA Enterprise SCADA HMI: 2024|2024_R2, AVEVA Enterprise SCADA HMI: &lt;=2023_P1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>AVEVA recommends that customers using affected product versions should perform the following to mitigate the risk of exploit: 1. Evaluate the impact of these vulnerabilities based on your operational environment, architecture, and product implementation. 2. Plan an upgrade of Servers and Clients to one of the available fixed versions listed in this document. 3. Configure Servers and Clients as described in this document.</p>\n<p><strong>Mitigation</strong><br>Contact your AVEVA Technical Support representative, Customer Success Manager, Account Manager, or Solution Integrator to obtain the security update best applicable to the product version currently deployed in your environment: Servers: AVEVA Enterprise SCADA v2025 P1 or higher, AVEVA Enterprise SCADA v2024 SP1 P2, AVEVA Enterprise SCADA v2023 SP1 P1, AVEVA Enterprise SCADA v2022 SP2 P3, AVEVA Enterprise SCADA v2021 SP2 P6, AVEVA Pipeline Operations for Gas/Liquids v2025 P1 or higher, AVEVA Pipeline Operations for Gas/Liquids v2024 SP1 P2, AVEVA Pipeline Operations for Gas/Liquids v2023 SP1 P1, AVEVA Pipeline Operations for Gas/Liquids v2022 SP2 P3, AVEVA Pipeline Operations for Gas/Liquids v2021 SP2 P6 Clients: AVEVA Enterprise SCADA HMI v2024 R2 HF7 or higher, AVEVA Enterprise SCADA HMI v2024 P1, AVEVA Enterprise SCADA HMI v2023 P2 HF1, AVEVA Pipeline Integrity Monitor (delivered on Pipeline Simulation media) v2025 SP1 P2 or higher, AVEVA Pipeline Training Simulator (delivered on Pipeline Simulation media) v2025 SP1 P2 or higher, Measurement Advisor 2025 P1 or higher, Measurement Advisor 2021 SP1 HF16</p>\n<p><strong>Mitigation</strong><br>To fully mitigate the risk of exploit, the following configuration changes must be implemented after all server and client nodes have been upgraded to compatible versions that support the fix:Server Components: Change \"BinarySerializer\" -&gt; \"Mode\" setting from 'Binary Formatter' to 'Json'. Change \"BinarySerializer\" -&gt; \"AcceptBinaryFormattedData\" setting from 'true' to 'false'. Re-cache the XOS Event Handlers assembly</p>\n<p><strong>Mitigation</strong><br>Client Components: Configure clients/products that interface with Enterprise SCADA to only use JSON serialization.</p>\n<p><strong>Mitigation</strong><br>HMI: Migrate HMI displays</p>\n<p><strong>Mitigation</strong><br>For step-by-step instructions on where and how to apply these configuration settings, how to migrate HMI displays, compatible server-client versions list, and additional details please refer to KB117814 \"AVEVA Midstream Product Bulletin - Removal of Binary Formatter\"<br><a href=\"https://softwaresupportsp.aveva.com/en-US/knowledge/details/000117814?lang=en_US\">https://softwaresupportsp.aveva.com/en-US/knowledge/details/000117814?lang=en_US</a></p>\n<p><strong>Mitigation</strong><br>AVEVA recommends the following general defensive measures: Audit devices, network topology, and perimeter defences to ensure all applicable security best practices from AVEVA's Enterprise SCADA Reference System Architecture are adhered to. Audit assigned permissions to ensure that only trusted users are given \"DNA Authority - Operator\" rights: https://docs.aveva.com/bundle/scada-ent-2025/page/651008.html Disallow BLT Test clients in production environmentsFor additional details on defensive measures, refer to Section 5 of KB117814 \"AVEVA Midstream Product Bulletin - Removal of Binary Formatter<br><a href=\"https://docs.aveva.com/bundle/scada-ent-2025/page/651008.html\">https://docs.aveva.com/bundle/scada-ent-2025/page/651008.html</a></p>\n<p><strong>Mitigation</strong><br>For more information on this vulnerability, including security updates, users should see the security bulletin AVEVA-2026-005.<br><a href=\"https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-005.pdf\">https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-005.pdf</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/502.html\">CWE-502 Deserialization of Untrusted Data</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H\">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.1</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>AVEVA reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks. Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability has a high attack complexity.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-13</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-13</td>\n<td>1</td>\n<td>Initial Republication of AVEVA security bulletin AVEVA-2026-005</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-04",
        "title": "Hitachi Energy APM Edge Product",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-04",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-04.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Hitachi Energy is aware of Dirty Frag vulnerabilities that affect APM Edge product versions listed in this document. Successful exploitation of these vulnerabilities could result in impact on confidentiality, integrity and availability of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.</strong></p>\n<p>The following versions of Hitachi Energy APM Edge Product are affected:</p>\n<ul>\n<li>APM Edge vers:APM_Edge/&lt;=6.10 (CVE-2026-43284, CVE-2026-43500)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.8</td>\n<td>Hitachi Energy</td>\n<td>Hitachi Energy APM Edge Product</td>\n<td>Write-what-where Condition, Out-of-bounds Write</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Switzerland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-43284</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>CWE-123: Write-what-where Condition A vulnerability exists in the IPsec ESP subsystem (esp4, esp6) of the Linux kernel used in APM Edge that allows a local unprivileged user to escalate privileges to root. The flaw exists in how the kernel handles memory pages when processing ESP encrypted network packets. An attacker can craft a packet that causes the kernel to decrypt data directly into memory pages it does not own, including the cached copies of privileged operating system binaries. When one of those binaries is executed, the attacker's injected code runs with root privileges. In APM Edge, the vulnerable kernel modules (esp4, esp6) can be loaded by any local user and exploited.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-43284\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Hitachi Energy APM Edge Product</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Hitachi Energy</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>APM Edge versions 6.10 and prior</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Disable the esp4 and esp6 modules [2]</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/123.html\">CWE-123 Write-what-where Condition</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-43500</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>CWE-787: Out-of-bounds Write A vulnerability exists in the RxRPC protocol implementation of Linux kernel used in APM Edge that allows a local unprivileged user to escalate privileges to root. RxRPC incorrectly processes incoming network packets that carry externally owned memory fragments. During packet processing, the kernel writes decrypted data directly into memory pages it does not own, including cached copies of privileged operating system binaries. Upon execution of a corrupted binary, the attacker's injected code runs with root privileges. In APM Edge, the vulnerable kernel module (rxrpc) can be loaded by any local user and exploited.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-43500\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Hitachi Energy APM Edge Product</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Hitachi Energy</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>APM Edge versions 6.10 and prior</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Disable the rxrpc module [2]</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Hitachi Energy Internal Team reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Notice</h2>\n<p>The information in this document is subject to change without notice and should not be construed as a commitment by Hitachi Energy. Hitachi Energy provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall Hitachi Energy or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if Hitachi Energy or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from Hitachi Energy and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners.</p>\n<hr>\n<h2>Support</h2>\n<p>For additional information and support please contact your product provider or Hitachi Energy service organization. For contact information, see https://www.hitachienergy.com/contact-us/ for Hitachi Energy contact-centers.</p>\n<hr>\n<h2>General Mitigation Factors</h2>\n<p>Recommended security practices and firewall configurations can help protect a process control network from attacks that originate from outside the network. Such practices include that process control systems are physically protected from direct access by unauthorized personnel, have no direct connections to the Internet, and are separated from other networks by means of a firewall system that has a minimal number of ports exposed, and others that have to be evaluated case by case. Process control systems should not be used for Internet surfing, instant messaging, or receiving e-mails. Portable computers and removable storage media should be carefully scanned for viruses before they are connected to a control system. Proper password policies and processes should be followed. Additional information on Industrial Control Systems Cybersecurity Best Practices can be found in the Hitachi Energy \u201cIndustrial Control Systems Cybersecurity Best Practices\u201d Cybersecurity Notification. [1]</p>\n<hr>\n<h2>SSVC</h2>\n<p>SSVCv2/E:N/A:N/2026-07-24T07:30:06Z/</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Hitachi Energy PSIRT 8DBD000256 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Hitachi Energy PSIRT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-28</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-28</td>\n<td>1</td>\n<td>Initial public release</td>\n</tr>\n<tr>\n<td>2026-08-13</td>\n<td>2</td>\n<td>Initial CISA Republication of Hitachi Energy PSIRT 8DBD000256 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-02",
        "title": "Haiwell IoT Cloud HMI Gateway",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges.</strong></p>\n<p>The following versions of Haiwell IoT Cloud HMI Gateway are affected:</p>\n<ul>\n<li>Haiwell IoT Cloud HMI Gateway 3.40.1.12 (CVE-2026-19188)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 10</td>\n<td>Haiwell</td>\n<td>Haiwell IoT Cloud HMI Gateway</td>\n<td>Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Energy, Critical Manufacturing, Water and Wastewater</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>China</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-19188</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-19188\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Haiwell IoT Cloud HMI Gateway</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Haiwell</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Haiwell Haiwell IoT Cloud HMI Gateway: 3.40.1.12</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Haiwell has addressed the issue in patch version number Scada-v3.50.1.19, which is available for download on their website: https://en.haiwell.com/app/system/entrance.php?m=include&amp;c=access&amp;a=dodown&amp;lang=en&amp;id=361<br><a href=\"https://en.haiwell.com/app/system/entrance.php?m=include&amp;c=access&amp;a=dodown&amp;lang=en&amp;id=361\">https://en.haiwell.com/app/system/entrance.php?m=include&amp;c=access&amp;a=dodown&amp;lang=en&amp;id=361</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/78.html\">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>10</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>10</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Fiqram Akmal reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-13</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-13</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-10",
        "title": "Siemens Parasolid",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-10",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-10.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.</strong></p>\n<p>The following versions of Siemens Parasolid are affected:</p>\n<ul>\n<li>Parasolid V38.0 vers:intdot/&lt;38.0.235 (CVE-2026-64629)</li>\n<li>Parasolid V38.1 vers:intdot/&lt;38.1.230 (CVE-2026-64629)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.8</td>\n<td>Siemens</td>\n<td>Siemens Parasolid</td>\n<td>Out-of-bounds Read</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-64629</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-64629\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Parasolid</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Parasolid V38.0 &lt; V38.0.235, Parasolid V38.1 &lt; V38.1.230</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V38.0.235 or later version<br><a href=\"https://support.sw.siemens.com/product/258316782/\">https://support.sw.siemens.com/product/258316782/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V38.1.230 or later version<br><a href=\"https://support.sw.siemens.com/product/258316782/\">https://support.sw.siemens.com/product/258316782/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-138516 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-11</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-11</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-08-13</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-138516 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-06",
        "title": "Siemens RUGGEDCOM APE1808",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-06",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-06.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens recommends to contact customer support for additional information, and follow Fortinet advisory for workarounds and mitigation measures.</strong></p>\n<p>The following versions of Siemens RUGGEDCOM APE1808 are affected:</p>\n<ul>\n<li>RUGGEDCOM APE1808 vers:all/* (CVE-2026-23573, CVE-2026-59839)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 6.1</td>\n<td>Siemens</td>\n<td>Siemens RUGGEDCOM APE1808</td>\n<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy, Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-23573</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.8.0, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.3, FortiProxy 7.2.0 through 7.2.9 may allow an authenticated remote user to execute code or commands via crafted requests.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-23573\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens RUGGEDCOM APE1808</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>RUGGEDCOM APE1808 with Fortinet NGFW</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Contact customer support to receive detailed information</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/79.html\">CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.1</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-59839</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated attacker with physical access to the device to delete the file system via crafted CLI commands</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-59839\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens RUGGEDCOM APE1808</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>RUGGEDCOM APE1808 with Fortinet NGFW</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Contact customer support to receive detailed information</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/22.html\">CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H\">CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-127084 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-11</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-11</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-08-12</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-127084 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Wed, 12 Aug 26 12:00:00 +0000",
        "last_updated": "Wed, 12 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01",
        "title": "Johnson Controls C-CURE 9000 and Victor application server (Update A)",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution.</strong></p>\n<p>The following versions of Johnson Controls C-CURE 9000 and Victor application server (Update A) are affected:</p>\n<ul>\n<li>C-CURE 9000 &lt;=v3.10.1 (CVE-2026-21655)</li>\n<li>victor Application Server &lt;=v4.10 (CVE-2026-21655)</li>\n<li>victor &lt;=v7.0 (CVE-2026-21655)</li>\n<li>victor Web</li>\n<li>victor Web &lt;=v7.1 (CVE-2026-34496)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.6</td>\n<td>Johnson Controls</td>\n<td>Johnson Controls C-CURE 9000 and Victor application server (Update A)</td>\n<td>Server-Side Request Forgery (SSRF), Execution with Unnecessary Privileges</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Ireland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-21655</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Under certain circumstances, successful exploitation of this vulnerability could allow an unauthenticated attacker on an adjacent network to achieve arbitrary code execution on the C-CURE 9000, victor application server and victor, as well as connected clients (e.g., workstations of physical security personnel). Such attack could impact physical security controls.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-21655\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls C-CURE 9000 and Victor application server (Update A)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls C-CURE 9000: &lt;=v3.10.1, Johnson Controls victor Application Server: &lt;=v4.10, Johnson Controls victor: &lt;=v7.0</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Johnson Controls recommends the following upgrades to address the vulnerable deserialization path: Upgrade to C-CURE 9000 v3.20 or later</p>\n<p><strong>Vendor fix</strong><br>Johnson Controls recommends the following upgrades to address the vulnerable deserialization path: Upgrade victor Application Server to v4.20 or later</p>\n<p><strong>Vendor fix</strong><br>Johnson Controls recommends the following upgrades to address the vulnerable deserialization path: Upgrade victor to v8.0 or later</p>\n<p><strong>Mitigation</strong><br>Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation. Johnson Controls recommends following both steps in the mitigation guidance. However, until an upgrade is completed, the defensive measures outlined will reduce the attack surface: Firewall / access control lists - Implement strict firewall rules to block all unnecessary inbound connections to port 8999 from untrusted network segments. Intrusion detection / prevention - Deploy IDS/IPS signatures tuned to detect known .NET deserialization exploit payloads (e.g., ysoserial.net patterns) targeting port 8999. Application whitelisting - Enforce application whitelisting on application server hosts to prevent unauthorized executables from being launched by the server process. Least privilege - Ensure the application server process runs with the minimum privileges necessary, reducing the impact of successful exploitation. Monitor and audit - Enable detailed logging on application server hosts and monitor for anomalous process creation by SoftwareHouse.CrossFire.Server.exe. Disable unnecessary services - If the ClientConnectionManager_NF.SynchronousServerNotification callback interface is not required, disable or restrict it to reduce attack surface.</p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories\">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/918.html\">CWE-918 Server-Side Request Forgery (SSRF)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.6</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.4</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-21653</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Under certain circumstances, successful exploitation of this vulnerability could allow an attacker to forge server-side HTTP requests from the victor Web application. This could be leveraged to interact with internal services running on the host or accessible on the local network, potentially leading to unauthorized information disclosure or lateral movement within the network.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-21653\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls C-CURE 9000 and Victor application server (Update A)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls victor Web: &lt;v7.0</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Johnson Controls recommends the following upgrades to address the vulnerable deserialization path: Upgrade victor Application Server to v4.20 or later</p>\n<p><strong>Vendor fix</strong><br>Johnson Controls recommends the following upgrades to address the vulnerable deserialization path: Upgrade victor to v8.0 or later</p>\n<p><strong>Mitigation</strong><br>Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation. Johnson Controls recommends following both steps in the mitigation guidance. However, until an upgrade is completed, the defensive measures outlined will reduce the attack surface: Firewall / access control lists - Implement strict firewall rules to block all unnecessary inbound connections to port 8999 from untrusted network segments. Intrusion detection / prevention - Deploy IDS/IPS signatures tuned to detect known .NET deserialization exploit payloads (e.g., ysoserial.net patterns) targeting port 8999. Application whitelisting - Enforce application whitelisting on application server hosts to prevent unauthorized executables from being launched by the server process. Least privilege - Ensure the application server process runs with the minimum privileges necessary, reducing the impact of successful exploitation. Monitor and audit - Enable detailed logging on application server hosts and monitor for anomalous process creation by SoftwareHouse.CrossFire.Server.exe. Disable unnecessary services - If the ClientConnectionManager_NF.SynchronousServerNotification callback interface is not required, disable or restrict it to reduce attack surface.</p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories\">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/918.html\">CWE-918 Server-Side Request Forgery (SSRF)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.6</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.4</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-34496</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Under certain circumstances, successful exploitation of this vulnerability could result in low privilege users accessing unauthorized pages such as Users and Logs. Successful exploitation could allow an attacker to view sensitive system information, user account details, and audit logs beyond their intended access level, potentially enabling further attacks or unauthorized administrative actions.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-34496\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls C-CURE 9000 and Victor application server (Update A)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls victor Web: &lt;=v7.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Johnson Controls recommends the following upgrades to address the vulnerable deserialization path: Upgrade victor Application Server to v4.20 or later</p>\n<p><strong>Vendor fix</strong><br>Johnson Controls recommends the following upgrades to address the vulnerable deserialization path: Upgrade victor to v8.0 or later</p>\n<p><strong>Mitigation</strong><br>Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation. Johnson Controls recommends following both steps in the mitigation guidance. However, until an upgrade is completed, the defensive measures outlined will reduce the attack surface: Firewall / access control lists - Implement strict firewall rules to block all unnecessary inbound connections to port 8999 from untrusted network segments. Intrusion detection / prevention - Deploy IDS/IPS signatures tuned to detect known .NET deserialization exploit payloads (e.g., ysoserial.net patterns) targeting port 8999. Application whitelisting - Enforce application whitelisting on application server hosts to prevent unauthorized executables from being launched by the server process. Least privilege - Ensure the application server process runs with the minimum privileges necessary, reducing the impact of successful exploitation. Monitor and audit - Enable detailed logging on application server hosts and monitor for anomalous process creation by SoftwareHouse.CrossFire.Server.exe. Disable unnecessary services - If the ClientConnectionManager_NF.SynchronousServerNotification callback interface is not required, disable or restrict it to reduce attack surface.</p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories\">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/250.html\">CWE-250 Execution with Unnecessary Privileges</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Harrison Neal reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-23</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-23</td>\n<td>1</td>\n<td>Initial Republication of Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16.</td>\n</tr>\n<tr>\n<td>2026-08-11</td>\n<td>2</td>\n<td>Update A - Made changes to affected products and mitigations.</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 11 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 11 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-01",
        "title": "Mira Hormone Monitor, Mira Android App",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-223-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token information, and obtain control of user accounts.</strong></p>\n<p>The following versions of Mira Hormone Monitor, Mira Android App are affected:</p>\n<ul>\n<li>Mira Monitor Firmware 1.7.1.47 (CVE-2026-66875, CVE-2026-66098, CVE-2026-67558, CVE-2026-67568, CVE-2026-68067, CVE-2026-66340, CVE-2026-64934, CVE-2026-66832)</li>\n<li>Mira Android App 4.5.15.4 (CVE-2026-66875, CVE-2026-66098, CVE-2026-67558, CVE-2026-67568, CVE-2026-68067, CVE-2026-66340, CVE-2026-64934, CVE-2026-66832)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.8</td>\n<td>Quanovate Tech Inc. (operating as Mira / Mira Care)</td>\n<td>Mira Hormone Monitor, Mira Android App</td>\n<td>Missing Authentication for Critical Function, Authentication Bypass by Spoofing, Use of Hard-coded Credentials, Weak Authentication, Improper Restriction of Excessive Authentication Attempts, Reliance on Untrusted Inputs in a Security Decision, Use of GET Request Method With Sensitive Query Strings</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Healthcare and Public Health</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-66875</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10\u201330 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or undocumented command opcodes, and passively track the user via a static random BLE address that never rotates.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-66875\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Mira Hormone Monitor, Mira Android App</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care)</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-66098</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootloader mode. An attacker could cause a denial-of-service condition or disrupt ovulation tracking and fertility monitoring workflow.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-66098\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Mira Hormone Monitor, Mira Android App</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care)</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-67558</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live session token information and inject forged hormone measurements into the victim's cloud record and clinical trend view.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-67558\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Mira Hormone Monitor, Mira Android App</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care)</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/290.html\">CWE-290 Authentication Bypass by Spoofing</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.4</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N\">CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-67568</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-67568\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Mira Hormone Monitor, Mira Android App</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care)</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/798.html\">CWE-798 Use of Hard-coded Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.1</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-68067</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-68067\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Mira Hormone Monitor, Mira Android App</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care)</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/1390.html\">CWE-1390 Weak Authentication</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-66340</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout after repeated failed login attempts. An attacker can use brute-force methods to obtain gain access to user accounts.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-66340\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Mira Hormone Monitor, Mira Android App</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care)</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/307.html\">CWE-307 Improper Restriction of Excessive Authentication Attempts</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-64934</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, without independently attesting the version from the device itself. An authenticated attacker could submit arbitrary firmware version strings for their own device, allowing them to evade vendor-side vulnerable-fleet analytics, suppress security update prompts to the user, and misrepresent patch-adoption metrics.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-64934\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Mira Hormone Monitor, Mira Android App</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care)</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/807.html\">CWE-807 Reliance on Untrusted Inputs in a Security Decision</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>4.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-66832</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent user identifier is included in the WebView's User-Agent header. Both are then transmitted to third-party web properties, referrer logs, and any JavaScript running in the WebView context.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-66832\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Mira Hormone Monitor, Mira Android App</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care)</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/598.html\">CWE-598 Use of GET Request Method With Sensitive Query Strings</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Gigi Xiaoqing Liu, Muzzammil Mohammed, Narmina Karimova, and En Mong of Northeastern University SPQR Lab reported these vulnerabilities to Quanovate Tech</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-11</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-11</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 11 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 11 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Three Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added three new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-20349\" target=\"_blank\">CVE-2026-20349</a> Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-68820\" target=\"_blank\">CVE-2026-68820</a> Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-72898\" target=\"_blank\">CVE-2026-72898</a> Metabase SQL Injection Vulnerability</li>\n</ul>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance</p>",
        "summary_is_html": true,
        "first_seen": "Tue, 11 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 11 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-02",
        "title": "Pulsetto Vagus Nerve Stimulator",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-223-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to use hidden commands to disable electrical safety mechanisms or modify other stimulation output settings.</strong></p>\n<p>The following versions of Pulsetto Vagus Nerve Stimulator are affected:</p>\n<ul>\n<li>Pulsetto Vagus Nerve Stimulator vers:all/* (CVE-2026-18844)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.1</td>\n<td>Pulsetto</td>\n<td>Pulsetto Vagus Nerve Stimulator</td>\n<td>Hidden Functionality</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Healthcare and Public Health</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Lithuania</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-18844</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The firmware of the affected product accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully processed by the device when it is powered on.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-18844\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Pulsetto Vagus Nerve Stimulator</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Pulsetto</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Pulsetto Pulsetto Vagus Nerve Stimulator: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Pulsetto has not responded to requests to work with CISA to mitigate this vulnerability. Users are encouraged to reach out directly to Pulsetto for assistance at info@pulsetto.tech.<br><a href=\"mailto:info@pulsetto.tech\">mailto:info@pulsetto.tech</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/912.html\">CWE-912 Hidden Functionality</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>A.C. Buglione reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-11</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-11</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 11 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 11 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a",
        "title": "#StopRansomware: Gunra Ransomware",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a",
        "summary": "<h2><strong>Advisory at a Glance</strong></h2>\n<table>\n<tbody>\n<tr>\n<th>Title</th>\n<td>#StopRansomware: Gunra Ransomware</td>\n</tr>\n<tr>\n<th>Original Publication</th>\n<td>August 10, 2026</td>\n</tr>\n<tr>\n<th>Executive Summary</th>\n<td>Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid. This advisory provides technical details of the activity, as well as tailored detection and mitigation guidance to protect at-risk organizations from Gunra.</td>\n</tr>\n<tr>\n<th>Key Actions</th>\n<td>\n<ul type=\"square\">\n<li><strong>Prioritize patching known exploited vulnerabilities in internet-facing systems</strong>, including virtual private network (VPN) gateways and remote desktop protocol (RDP)-exposed infrastructure.</li>\n<li><strong>Implement and test offline, immutable backups</strong> stored in a physically separate, segmented location to ensure recoverability without ransom payment.</li>\n<li><strong>Segment networks</strong> to restrict lateral movement from an initially compromised device to other systems in the organization.</li>\n</ul>\n</td>\n</tr>\n<tr>\n<th>Indicators of Compromise</th>\n<td>\n<p>For a downloadable copy of indicators of compromise, see:</p>\n<ul type=\"square\">\n<li><a href=\"https://www.cisa.gov/sites/default/files/2026-08/AA26-222A-stix.xml\">AA26-222A STIX XML</a> (54 KB)</li>\n<li><a href=\"https://www.cisa.gov/sites/default/files/2026-08/AA26-222A-stix.json\">AA26-222A STIX JSON</a> (61 KB)</li>\n</ul>\n</td>\n</tr>\n<tr>\n<th>Intended Audience</th>\n<td>\n<p><strong>Organizations:</strong> Government, Critical Infrastructure</p>\n<p><strong>Sectors: </strong><a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/healthcare-and-public-health-sector\" title=\"Healthcare and Public Health\">Healthcare and public health</a>, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/financial-services-sector\" title=\"financial services\">financial services</a> and insurance, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/critical-manufacturing-sector\" title=\"critical manufacturing\">critical manufacturing</a> and construction, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/transportation-systems-sector\" title=\"transportation systems\">transportation systems</a> and logistics, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/government-services-facilities-sector\" title=\"government services and facilities\">government services and facilities</a>, utilities, academia, media and communications, retail, and professional and nonprofit services.</p>\n<p><strong>Roles:</strong> <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/cybersecurity-architecture\" target=\"_blank\" title=\"Cybersecurity architects\">Cybersecurity architects</a>, <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/defensive-cybersecurity\" target=\"_blank\" title=\"Defensive cybersecurity analysts\">defensive cybersecurity analysts</a>, <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/vulnerability-analysis\" target=\"_blank\" title=\"vulnerability analysts\">vulnerability analysts</a>, <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/systems-administration\" target=\"_blank\" title=\"systems administrators\">systems administrators</a>, and <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/systems-security-management\" target=\"_blank\" title=\"security systems managers\">security systems managers</a>.</p>\n</td>\n</tr>\n</tbody>\n</table>\n<h2><strong>Introduction</strong></h2>\n<p><strong>Note: </strong>This joint Cybersecurity Advisory is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit <a href=\"https://www.cisa.gov/stopransomware\" title=\"Stopransomware.gov\">stopransomware.gov</a> to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources.</p>\n<p>The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), Department of Defense Cyber Crime Center (DC3), National Security Agency (NSA), U.S. Secret Service (USSS), and Republic of Korea\u2019s National Police Agency (KNPA)\u2014hereafter referred to as \u201cthe authoring agencies\u201d\u2014are releasing this joint advisory to alert organizations to the emerging Gunra ransomware threat and to provide detection and mitigation guidance.</p>\n<p>Gunra first emerged in April 2025 as a sophisticated double-extortion ransomware variant derived from the leaked Conti<a href=\"#Note1\"><sup>1</sup></a> ransomware source code. As of early 2026, Gunra expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program advertised on dark web forums to financially motivated cybercriminals. Gunra actors demand ransom via a customized, Tor-based negotiation portal and threaten to publish exfiltrated data on a dedicated leak site (DLS) if victims do not comply.</p>\n<p>Gunra victims observed on the actors\u2019 DLS span organizations across multiple sectors in the Americas, Europe, Middle East, Africa, and the Asia-Pacific.<a href=\"#Note2\"><sup>2</sup></a> These sectors include:</p>\n<ul type=\"square\">\n<li><a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/healthcare-and-public-health-sector\" title=\"Healthcare and public health\">Healthcare and public health</a></li>\n<li><a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/financial-services-sector\" title=\"Financial services\">Financial services</a> and insurance</li>\n<li><a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/critical-manufacturing-sector\" title=\"Critical manufacturing\">Critical manufacturing</a> and construction</li>\n<li><a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/transportation-systems-sector\" title=\"Transportation systems\">Transportation systems</a> and logistics</li>\n<li><a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/government-services-facilities-sector\" title=\"Government services and facilities\">Government services and facilities</a></li>\n<li>Utilities</li>\n<li>Academia</li>\n<li>Media and communications</li>\n<li>Retail</li>\n<li>Professional and nonprofit services &nbsp;</li>\n</ul>\n<p>The authoring agencies encourage organizations to implement the recommendations in the <a href=\"#Mitigations\"><strong>Mitigations</strong></a> section of this advisory to mitigate cyber threats related to Gunra ransomware, including:</p>\n<ul>\n<li><strong>Prioritizing patching known exploited vulnerabilities</strong> in internet-facing systems, including virtual private network (VPN) gateways and remote desktop protocol (RDP)-exposed infrastructure.</li>\n<li><strong>Implementing and testing offline, immutable backups</strong> stored in a physically separate, segmented location to ensure recoverability without ransom payment.</li>\n<li><strong>Segmenting networks</strong> to restrict lateral movement from an initially compromised device to other systems in the organization.</li>\n</ul>\n<p>Download the PDF version of this report:</p>\n\n\n\n\n\n<div class=\"c-file\">\n    <div class=\"c-file__download\">\n    <a href=\"/sites/default/files/2026-08/aa26-222a-stopransomware-gunra-ransomware_508c.pdf\" class=\"c-file__link\" target=\"_blank\">AA26-222A StopRansomware Gunra Ransomware</a>\n    <span class=\"c-file__size\">(PDF,       1.07 MB\n  )</span>\n  </div>\n</div>\n<p>For a downloadable copy of IOCs, see:</p>\n\n\n\n\n\n<div class=\"c-file\">\n    <div class=\"c-file__download\">\n    <a href=\"/sites/default/files/2026-08/AA26-222A-stix.xml\" class=\"c-file__link\" target=\"_blank\">AA26-222A STIX XML</a>\n    <span class=\"c-file__size\">(XML,       54.18 KB\n  )</span>\n  </div>\n</div>\n\n\n\n\n\n<div class=\"c-file\">\n    <div class=\"c-file__download\">\n    <a href=\"/sites/default/files/2026-08/AA26-222A-stix.json\" class=\"c-file__link\" target=\"_blank\">AA26-222A STIX JSON</a>\n    <span class=\"c-file__size\">(JSON,       61.00 KB\n  )</span>\n  </div>\n</div>\n<h2><strong>Technical Details</strong></h2>\n<p><strong>Note:</strong> This advisory uses the <a href=\"https://attack.mitre.org/versions/v19/matrices/enterprise/\" target=\"_blank\" title=\"MITRE ATTACK Matrix for Enterprise\">MITRE ATT&amp;CK<sup>\u00ae</sup> Matrix for Enterprise</a> framework, version 19.1.&nbsp;See the<strong> </strong><a href=\"#MITRE\"><strong>MITRE ATT&amp;CK Tactics and Techniques</strong></a> section of this advisory for a table of the threat actors\u2019 activity mapped to MITRE ATT&amp;CK tactics and techniques.</p>\n<h3><strong>Overview</strong></h3>\n<p>The FBI originally observed Gunra ransomware in April 2025. The threat actors quickly established a DLS on the Tor network to list victims and publish exfiltrated data. As of January 2026, Gunra launched a formal RaaS affiliate program on dark web forums, providing affiliates with access to a management panel, a configurable ransomware builder, cross-platform locker payloads, and structured affiliate documentation.<a href=\"#Note3\"><sup>3</sup></a><sup> &nbsp;</sup>The FBI observed the group adopting new branding aliases (notably operating under the name Golden Community) to support this expansion. Gunra has further commercialized its platform by actively recruiting penetration testers and ethical hackers to serve as initial access brokers, offering a share of the ransom profits in exchange for enterprise network access.</p>\n<p>Based on FBI observations, Gunra actors use a traditional double-extortion model, exfiltrating sensitive victim data prior to encryption and threatening to publish the leaked data on their DLS unless the ransom is paid. Victims receive a ransom note in every affected directory guiding them to a Tor-based negotiation portal where they are assigned a Client ID and an initial password. Subsequently, victims receive instructions to contact the Gunra actors via qTox (an encrypted messaging application) to negotiate ransom payments within five to seven days. If the ransom is not paid, Gunra actors threaten to sell victim data on the DLS.</p>\n<p>Gunra ransomware appears to be based on, or significantly influenced by, the Conti ransomware source code leaked in 2022.<a href=\"#Note4\"><sup>4</sup></a> Initially, Gunra actors\u2019 campaigns focused on Windows environments; reporting in mid-2025 indicated the group introduced a Linux variant and moved toward broader cross-platform targeting.<a href=\"#Note5\"><sup>5</sup></a>&nbsp;</p>\n<h3><strong>Initial Access</strong></h3>\n<p>The FBI observed Gunra actors obtaining initial access [<a href=\"https://attack.mitre.org/versions/v19/tactics/TA0001/\" target=\"_blank\" title=\"TA0001\">TA0001</a>] primarily through the exploitation of known vulnerabilities in internet-facing devices [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1190/\" target=\"_blank\" title=\"T1190\">T1190</a>], including firewall and VPN appliances. The FBI observed exploits based on the following Common Vulnerabilities and Exposures (CVEs):</p>\n<ul type=\"square\">\n<li><a href=\"https://cve.org/CVERecord?id=CVE-2024-55591\" title=\"CVE-2024-55591\">CVE-2024-55591</a> [<a href=\"https://cwe.mitre.org/data/definitions/288.html\" target=\"_blank\" title=\"CWE-288: Authentication Bypass Using an Alternate Path or Channel\">CWE-288: Authentication Bypass Using an Alternate Path or Channel</a>]: Authentication bypass vulnerability affecting specific FortiOS and FortiProxy versions (see CVE record for more details).</li>\n<li><a href=\"https://cve.org/CVERecord?id=CVE-2025-24472\" title=\"CVE-2025-24472\">CVE-2025-24472</a> [<a href=\"https://cwe.mitre.org/data/definitions/288.html\" target=\"_blank\" title=\"CWE-288: Authentication Bypass Using an Alternate Path or Channel\">CWE-288: Authentication Bypass Using an Alternate Path or Channel</a>]: Authentication bypass vulnerability affecting specific FortiOS and FortiProxy versions (see CVE record for more details).</li>\n</ul>\n<p>Additionally, for initial access, KNPA observed Gunra actors exploit credential-exposure and Secure Shell (SSH) access control vulnerabilities in internet-facing VPN gateways to gain unauthorized remote access.</p>\n<h3><strong>Execution</strong></h3>\n<p>Gunra\u2019s Windows encryptor relies on native operating system (OS) application programming interfaces (APIs) to drive both execution and targeted encryption activity. The binary uses the <code>FindFirstFileW</code>/<code>FindNextFileW</code> API calls [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1106\" target=\"_blank\" title=\"T1106\">T1106</a>] to enumerate files and directories on all accessible drive letters (A through Z), enabling comprehensive traversal of the file system prior to encryption of victim data.</p>\n<h3><strong>Persistence, Privilege Escalation, Lateral Movement, and Command and Control</strong></h3>\n<p>Gunra actors regularly exploit Impacket libraries <code>psexec.py</code> and <code>smbclient.py</code> to move laterally across victim networks using the Server Message Block (SMB) protocol [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1021/002/\" target=\"_blank\" title=\"T1021.002\">T1021.002</a>].</p>\n<p>KPNA observed that against one victim, Gunra actors gained access to an administrator account for a secure socket layer (SSL)-VPN appliance [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1133/\" target=\"_blank\" title=\"T1133\">T1133</a>] by exploiting default credentials when account lockout controls were not present [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1078/001/\" target=\"_blank\" title=\"T1078.001\">T1078.001</a>][<a href=\"https://attack.mitre.org/versions/v19/techniques/T1078/002/\" target=\"_blank\" title=\"T1078.002\">T1078.002</a>]. The actors subsequently downloaded OpenSSH (an SSH tunneling tool) [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1105/\" target=\"_blank\" title=\"T1105\">T1105</a>] from an external attacker-controlled server to establish connections between compromised systems and maintain persistence in the victim\u2019s environment [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1572/\" target=\"_blank\" title=\"T1572\">T1572</a>].</p>\n<p>After gaining access to an internet-connected workstation used by a network administrator, Gunra actors accessed the SSL-VPN administrative web console and identified an unused account that had access to both the internet-facing and internal corporate networks. The actors modified the account configuration to bypass the mandatory password change requirement enforced on the account and subsequently leveraged it for malicious activities [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1098/\" target=\"_blank\" title=\"T1098\">T1098</a>].</p>\n<p>Using stolen session information, Gunra actors gained initial access to the internal virtual desktop infrastructure (VDI) environment and conducted lateral movement via RDP [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1021/001/\" target=\"_blank\" title=\"T1021.001\">T1021.001</a>]. The actors pivoted to multiple critical systems, including the VDI authentication web server, the internal Active Directory (AD) server, and virtual desktops assigned to IT personnel.</p>\n<h3><strong>Credential Access</strong></h3>\n<p>The FBI observed multiple instances of Gunra actors using <code>secretsdump.py</code> (another Impacket library) to conduct OS credential dumping [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1003/003\" target=\"_blank\" title=\"T1003.003\">T1003.003</a>] against compromised domain controllers to extract password hashes of user accounts from the NT Directory Services (NTDS) file. This enabled pass-the-hash [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1550/002/\" target=\"_blank\" title=\"T1550.002\">T1550.002</a>] or pass-the-ticket [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1550/003/\" target=\"_blank\" title=\"T1550.003\">T1550.003</a>] attacks for lateral movement into other privileged systems.</p>\n<p>For one victim, Gunra actors manipulated the network traffic control functionality of an SSL-VPN appliance to collect credentials and session information transmitted by users authenticating to a corporate VDI authentication portal [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1040/\" target=\"_blank\" title=\"T1040\">T1040</a>]. The actors then used stolen session cookies to conduct session hijacking [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1539/\" target=\"_blank\" title=\"T1539\">T1539</a>], impersonating legitimate users to gain access to the internal network.</p>\n<p>For the same victim, the Gunra actors modified authentication processing files on the corporate VDI authentication portal server to allow successful authentication when a specific, Gunra-designated one time password (OTP) value was entered, thereby enabling the continuous bypass of multi-factor authentication (MFA) [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1556/006/\" target=\"_blank\" title=\"T1556.006\">T1556.006</a>].</p>\n<p>Additionally, the actors accessed a Hiware system access control server via SSH from a compromised virtual desktop and stole a symmetric encryption key stored on the server. The stolen key enabled the actors to decrypt passwords for enterprise server accounts stored within the database [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1555/\" target=\"_blank\" title=\"T1555\">T1555</a>] and perform credential dumping of credentials associated with all enterprise servers [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1003/\" target=\"_blank\" title=\"T1003\">T1003</a>].</p>\n<h3><strong>Stealth, Defense Impairment, and Discovery</strong></h3>\n<p>Gunra employs multiple stealth and defense impairment techniques to hinder detection and analysis. While active within victim networks, Gunra actors typically attempt to mask their presence by deleting system/network access logs [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1685/\" target=\"_blank\" title=\"T1685\">T1685</a>] and clearing command history [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1070/003\" target=\"_blank\" title=\"T1070.003\">T1070.003</a>]. Additionally, to evade administrator detection, Gunra actors primarily conduct malicious activities and internal infrastructure reconnaissance [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1049/\" target=\"_blank\" title=\"T1049\">T1049</a>] during late-night and early-morning hours (10:00 p.m. \u2013 06:00 a.m.) [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1678/\" target=\"_blank\" title=\"T1678\">T1678</a>].</p>\n<p>The ransomware binary is self-contained and performs full volume encryption without observable network indicators (e.g., domain name system, HTTP).<a href=\"#Note6\"><sup>6</sup></a> The Windows binary includes the&nbsp;<code>IsDebuggerPresent</code> API [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1622\" target=\"_blank\" title=\"T1622\">T1622</a>], which defends against reverse engineering by detecting if the application is being run in a debugger.<a href=\"#Note7\"><sup>7</sup></a>&nbsp;</p>\n<p>To avoid dedicating encryption resources to non-critical files, the binary includes filtering logic to exclude common system directories (e.g.,&nbsp;<code>C:\\Windows</code>,&nbsp;<code>C:\\Program Files</code>,&nbsp;<code>C:\\Program Files (x86)</code>) from the file system reconnaissance [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1679/\" target=\"_blank\" title=\"T1679\">T1679</a>]. For files that pass the initial filter, the binary checks against a second set of filter rules that exclude file extensions related to system-critical files (e.g.,&nbsp;<code>.exe</code>,&nbsp;<code>.dll</code>,&nbsp;<code>.sys</code>). Files with extensions consistent with user data (e.g., documents, databases, images, archives) are approved and added to the work queue for data encryption.<a href=\"#Note8\"><sup>8</sup></a>&nbsp;</p>\n<p>Prior to encryption, Gunra performs file and directory discovery across all accessible drive letters (A through Z) to identify victim data for targeting [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1083\" target=\"_blank\" title=\"T1083\">T1083</a>].<a href=\"#Note9\"><sup>9</sup></a>&nbsp;</p>\n<h3><strong>Collection and Exfiltration</strong></h3>\n<p>Prior to data encryption, Gunra actors collect sensitive victim data as part of their double-extortion strategy. The FBI observed actors collecting files from victims that included business-critical documents, databases, personally identifiable information (PII), and internal email communications [<a href=\"https://attack.mitre.org/versions/v19/tactics/TA0009/\" target=\"_blank\" title=\"TA0009\">TA0009</a>][<a href=\"https://attack.mitre.org/versions/v19/techniques/T1114/\" target=\"_blank\" title=\"T1114\">T1114</a>]. Gunra actors\u2019 custom support for filtering redundant system files during initial discovery/file system reconnaissance streamlines the actors\u2019 collection of user-specific data from local victim machines [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1005\" target=\"_blank\" title=\"T1005\">T1005</a>].</p>\n<p>The FBI observed Gunra actors use a malicious executable (<code>main.exe</code>) to exfiltrate victim data from Microsoft OneDrive and SharePoint [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1530\" target=\"_blank\" title=\"T1530\">T1530</a>]. For at least one known Gunra victim, the actors generated compressed archives with sensitive data [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1560\" target=\"_blank\" title=\"T1560\">T1560</a>] and exfiltrated the archives to the file-sharing service Mega [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1567\" target=\"_blank\" title=\"T1567\">T1567</a>]; the volume of exfiltrated data ranged up to tens of terabytes.<a href=\"#Note10\"><sup>10</sup></a>&nbsp;</p>\n<p>In addition to collecting business-critical documents, the KNPA identified a victim case in which Gunra actors connected to the VDI environments of IT personnel and collected sensitive documents containing system and network configuration information [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1005/\" target=\"_blank\" title=\"T1005\">T1005</a>]. The actors then leveraged enterprise server credentials stolen from a system access control server to deploy ransomware to encrypt key assets, including database servers and network attached storage (NAS) systems [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1486/\" target=\"_blank\" title=\"T1486\">T1486</a>].</p>\n<p>The FBI observed several common open source tools on Gunra infrastructure that Gunra actors use to facilitate collection and exfiltration of data, including 7-Zip, RClone, and FileZilla [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1048\" target=\"_blank\" title=\"T1048\">T1048</a>] (see <a href=\"#LeveragedTools\"><strong>Leveraged Tools</strong></a> for a full list of tools used maliciously by Gunra actors).</p>\n<h3><strong>Impact</strong></h3>\n<p>Gunra\u2019s double-extortion model relies on both data exfiltration and data encryption for optimal success. The binary achieves high speed file encryption of entire file systems by leveraging a multi-threaded architecture that supports parallel encryption of multiple files simultaneously using strong ChaCha20 + RSA-4096 encryption [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1486/\" target=\"_blank\" title=\"T1048\">T1486</a>]. Upon successful encryption of a file, the binary renames the encrypted file with the file extension&nbsp;<code>.ENCRT</code>. Gunra also used the <code>.CRYPT</code> file extension in one documented sample from July 2025.<a href=\"#Note11\"><sup>11</sup></a>&nbsp;</p>\n<p>After the binary completes the encryption process for all files in a specific directory, Gunra actors write a static ransom note named&nbsp;<code>R3ADM3.txt</code> to the directory. To avoid unnecessary overhead, the binary also contains logic to prevent encryption of the ransom notes (<code>R3ADM3.txt</code>) and re-encryption of already encrypted files (<code>.ENCRT</code>).<a href=\"#Note12\"><sup>12</sup></a>&nbsp;</p>\n<p>In their ransom notes, Gunra actors typically demand that victims initiate negotiation discussions within five to seven days via a Tor-based negotiation portal or qTox, or risk having their data leaked on Gunra\u2019s DLS. The FBI observed Gunra actors attempting to communicate directly with management staff at victim companies via email to solicit ransom payments with limited success. Gunra actors instructed victims to send ransom payments to specific cryptocurrency wallet addresses [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1657\" target=\"_blank\" title=\"T1657\">T1657</a>] and generally started negotiations at arbitrarily high ransom amounts (over tens of millions in US dollars).</p>\n<p>If Gunra victims do not negotiate or pay ransom, the actors publicly disclose the victims on their DLS and offer a preview of victims\u2019 leaked data. This preview typically includes a directory listing of a victim\u2019s exposed OneDrive and SharePoint files, but not the content of the files. Between June and July of 2025, Gunra actors operated a clearnet mirror of their Tor-based DLS at domain <code>datapub.news</code>. By March 2026, Gunra had moved their original Tor-based DLS to a different <code>.onion</code> address. On Gunra\u2019s current Tor-based DLS, the actors advertise the sale of datasets from specific victims and instruct interested parties to contact them via qTox for more information.</p>\n<p>To increase the likelihood of ransom payment and prevent system recovery [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1490/\" target=\"_blank\" title=\"T1490\">T1490</a>], Gunra actors also used Windows Management Instrumentation (WMI) [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1047\" target=\"_blank\" title=\"T1047\">T1047</a>] to initiate deletion of volume shadow copies prior to encryption, as demonstrated in the following example [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1059/003/\" target=\"_blank\" title=\"T1059.003\">T1059.003</a>]:<a href=\"#Note13\"><sup>13</sup></a><sup> &nbsp;</sup></p>\n<p><code>cmd.exe /c C:\\Windows\\System32\\wbem\\WMIC.exe shadowcopy where \"ID='{guid of shadowcopy}'\" delete</code></p>\n<p>Additionally, against one Gunra victim, Gunra actors deleted backup and archived data stored on backup infrastructure at both the primary data center and disaster recovery center before and after the ransomware deployment [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1490/\" target=\"_blank\" title=\"T1490\">T1490</a>].</p>\n<h3><a class=\"ck-anchor\" id=\"LeveragedTools\"><strong>Leveraged Tools</strong></a></h3>\n<p><a href=\"#Table1\"><strong>Table 1</strong></a> lists publicly available tools and applications used by Gunra ransomware actors. If network defenders identify use of these tools on their network, they should investigate further to determine possible malicious activity.</p>\n<p><strong>Disclaimer:</strong> Use of these tools and applications should not be attributed as malicious without analytical evidence to support threat actor use and/or control.</p>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table1\"></a>Table 1. Tools Used by Gunra Ransomware Actors</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Tool Name</th>\n<th role=\"columnheader\">Description</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>FileZilla</td>\n<td>Open source, cross-platform File Transfer Protocol (FTP) application that supports file transfers between devices and remote servers.</td>\n</tr>\n<tr>\n<td>Amass</td>\n<td>Open source reconnaissance tool for network mapping and information gathering.</td>\n</tr>\n<tr>\n<td>RClone</td>\n<td>Open source command-line program designed to manage files in cloud storage.</td>\n</tr>\n<tr>\n<td>Sliver</td>\n<td>Penetration testing toolset that allows remote command and control of systems.</td>\n</tr>\n<tr>\n<td>7-Zip</td>\n<td>Open source, cross-platform file archiver utility.</td>\n</tr>\n<tr>\n<td>WinRAR</td>\n<td>Open source file archiver utility for Microsoft Windows.</td>\n</tr>\n<tr>\n<td>DBeaver</td>\n<td>Open source database management tool for managing Structured Query Language (SQL) databases like MySQL, MariaDB, PostgreSQL, SQLite, etc.</td>\n</tr>\n<tr>\n<td>Slack</td>\n<td>Cloud-based team communication and collaboration platform.</td>\n</tr>\n<tr>\n<td>Microsoft Visual Studio Code</td>\n<td>Open source extendable source code editor.</td>\n</tr>\n<tr>\n<td>MobaXterm</td>\n<td>Windows application with support for multiple remote computing protocols, including SSH, X11, RDP, virtual network computing (VNC), FTP, etc.</td>\n</tr>\n<tr>\n<td>AnyDesk</td>\n<td>Common, legitimate remote monitoring and management (RMM) tool that can be used by a cyber actor to obtain remote access and maintain persistence. AnyDesk also supports remote file transfer.</td>\n</tr>\n<tr>\n<td>Google Remote Desktop</td>\n<td>Web-based remote desktop software tool developed by Google that runs on a proprietary Google protocol.</td>\n</tr>\n<tr>\n<td>Mimikatz</td>\n<td>Post-exploitation tool that allows users to access and exfiltrate authentication credentials from Windows systems.</td>\n</tr>\n<tr>\n<td>Impacket</td>\n<td>Suite of networking utilities, including&nbsp;<code>smbclient</code>,&nbsp;<code>psexec</code>,&nbsp;<code>secretsdump</code>, etc. Gunra utilized several tools from this suite.</td>\n</tr>\n</tbody>\n</table>\n<h2><strong>Indicators of Compromise</strong></h2>\n<p><a href=\"#Table2\"><strong>Table 2</strong></a> lists IP addresses and domains associated with Gunra ransomware infrastructure since early 2025.</p>\n<p><strong>Disclaimer:</strong> Observed IP addresses/domains may be historical in nature. The authoring agencies recommend organizations investigate or vet these IP addresses prior to taking action, such as blocking.</p>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table2\"></a>Table 2. IP Addresses/Domains</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">IP Address/Domain</th>\n<th role=\"columnheader\">First Seen</th>\n<th role=\"columnheader\">Last Seen&nbsp;</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>23.239.119[.]2</td>\n<td>&nbsp;July 2025</td>\n<td>Nov. 6, 2025</td>\n</tr>\n<tr>\n<td>23.239.119[.]3</td>\n<td>July 2025</td>\n<td>&nbsp;Nov. 6, 2025</td>\n</tr>\n<tr>\n<td>23.239.119[.]4&nbsp;&nbsp;</td>\n<td>July 2025&nbsp;&nbsp;</td>\n<td>Nov. 6, 2025</td>\n</tr>\n<tr>\n<td>23.239.119[.]5</td>\n<td>July 2025</td>\n<td>Nov. 6, 2025</td>\n</tr>\n<tr>\n<td>23.239.119[.]6</td>\n<td>July 2025</td>\n<td>Nov. 6, 2025</td>\n</tr>\n<tr>\n<td>86.54.28[.]216</td>\n<td>June 7, 2025</td>\n<td>July 23, 2025</td>\n</tr>\n<tr>\n<td>103.125.234[.]14</td>\n<td>Nov. 2025</td>\n<td>Dec. 2025</td>\n</tr>\n<tr>\n<td>70.36.99[.]82</td>\n<td>Nov. 2025</td>\n<td>Dec. 2025</td>\n</tr>\n<tr>\n<td>211.21.210[.]181</td>\n<td>Nov. 2025</td>\n<td>Dec. 2025</td>\n</tr>\n<tr>\n<td>123.184.143[.]105</td>\n<td>Nov. 2025</td>\n<td>Dec. 2025</td>\n</tr>\n<tr>\n<td>182.204.21[.]240</td>\n<td>Nov. 2025</td>\n<td>Dec. 2025</td>\n</tr>\n<tr>\n<td>182.204.16[.]112</td>\n<td>Nov. 2025</td>\n<td>Dec. 2025</td>\n</tr>\n<tr>\n<td>123.244.187[.]144</td>\n<td>Nov. 2025</td>\n<td>Dec. 2025</td>\n</tr>\n<tr>\n<td>182.204.39[.]118</td>\n<td>Nov. 2025</td>\n<td>Dec. 2025</td>\n</tr>\n<tr>\n<td>67.43.53[.]10</td>\n<td>Nov. 2025</td>\n<td>Dec. 2025</td>\n</tr>\n<tr>\n<td>123.246.37[.]108</td>\n<td>Nov. 2025</td>\n<td>Dec. 2025</td>\n</tr>\n<tr>\n<td>91.201.66[.]146</td>\n<td>Nov. 2025</td>\n<td>Dec. 2025</td>\n</tr>\n<tr>\n<td>Datapub[.]news</td>\n<td>June 2025</td>\n<td>July 2025</td>\n</tr>\n<tr>\n<td>gunrabxbig445sjqa535uaymzerj6fp4nwc6ngc2xughf2pedjdhk4ad[.]onion</td>\n<td>Apr. 2025</td>\n<td>Feb. 2026</td>\n</tr>\n<tr>\n<td>lgiil72vkmdtbc3qv4tyq6wedyjxqr2qd4ze7xl2cxgerdnymxj7soqd[.]onion</td>\n<td>Mar. 2026</td>\n<td>July 2026</td>\n</tr>\n<tr>\n<td>nsnhzysbntsqdwpys6mhml33muccsvterxewh5rkbmcab7bg2ttevjqd[.]onion</td>\n<td>Jan. 2026</td>\n<td>Jan. 2026</td>\n</tr>\n</tbody>\n</table>\n<p>&nbsp;</p>\n<p><a href=\"#Table3\"><strong>Table 3</strong></a> lists email addresses associated with Gunra actors.</p>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table3\"></a>Table 3. Gunra Email Addresses</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Email Address</th>\n<th role=\"columnheader\">Description</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>a00f105546345756@proton[.]me</td>\n<td>Ransom negotiation</td>\n</tr>\n<tr>\n<td>4569f6322bc3b22e9@proton[.]me</td>\n<td>Ransom negotiation</td>\n</tr>\n<tr>\n<td>ilovemycubscout@gmail[.]com</td>\n<td>Ransom negotiation</td>\n</tr>\n<tr>\n<td>6449a3c1e612168526@proton[.]me</td>\n<td>Ransom negotiation</td>\n</tr>\n</tbody>\n</table>\n<p>The following qTox IDs are associated with Gunra actors:</p>\n<ul type=\"square\">\n<li>2507312EC10BB44ED9DAA04E3C5C27E8C13154649B1A02E73ACFAE1681EE0208D05133A8FB22</li>\n<li>0FE87CED0C611AE97E049C64288557F49E8271E91399E849328B078DA789A573031783235BEF</li>\n<li>47829AF1C943D4C296C910706923AS199BDA4995B076ED9A9016F7DEF161D445DF00F13E6900</li>\n<li>9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47</li>\n</ul>\n<p><a href=\"#Table4\"><strong>Table 4</strong></a> lists malicious files associated with Gunra ransomware.</p>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table4\"></a>Table 4. Malicious Files (SHA256)</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Filename</th>\n<th role=\"columnheader\">Hash (SHA256)</th>\n<th role=\"columnheader\">Description</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>main.exe</td>\n<td>2dc70a12d158d437e45a55b1d52f3d61c6082a1e1667573302ba3b62813e2751</td>\n<td>Tool to exfil OneDrive and SharePoint</td>\n</tr>\n<tr>\n<td>main.exe</td>\n<td>834efe9b392c6c000877ea5613a079445affc16fe8af5997d68c55cafc95e5d1</td>\n<td>Tool to exfil OneDrive and SharePoint</td>\n</tr>\n<tr>\n<td>cryptor.exe</td>\n<td>91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0</td>\n<td>Malicious executable</td>\n</tr>\n<tr>\n<td>msmp.exe</td>\n<td>a82e496b7b5279cb6b93393ec167dd3f50aff1557366784b25f9e51cb23689d9</td>\n<td>Malicious executable</td>\n</tr>\n</tbody>\n</table>\n<p><a href=\"#Table5\"><strong>Table 5</strong></a> lists malicious accounts created by Gunra actors to gain initial access to victim Fortinet devices.</p>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table5\"></a>Table 5. Malicious Fortinet User Accounts</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Username</th>\n<th role=\"columnheader\">Details</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>forticloud-sync</td>\n<td><a href=\"https://www.cve.org/CVERecord?id=CVE-2024-55591\" target=\"_blank\" title=\"CVE-2024-55591\">CVE-2024-55591</a> and <a href=\"https://www.cve.org/CVERecord?id=CVE-2025-24472\" target=\"_blank\" title=\"CVE-2025-24472\">CVE-2025-24472</a> allow threat actors to exploit scheduled tasks on vulnerable FortiOS firewall devices to create a new, malicious persistent user forticloud-sync with super user privileges and a hard-coded password.</td>\n</tr>\n</tbody>\n</table>\n<h2><a class=\"ck-anchor\" id=\"MITRE\"><strong>MITRE ATT&amp;CK Tactics and Techniques</strong></a></h2>\n<p>See <a href=\"#Table6\"><strong>Table 6</strong></a> to <a href=\"#Table18\"><strong>Table 18</strong></a> for all referenced threat actor tactics and techniques in this advisory. For assistance with mapping malicious cyber activity to the MITRE ATT&amp;CK framework, see CISA and MITRE ATT&amp;CK\u2019s <a href=\"https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping\" title=\"Best Practices for MITRE ATT&amp;CK Mapping\">Best Practices for MITRE ATT&amp;CK Mapping</a> and CISA\u2019s <a href=\"https://github.com/cisagov/Decider/\" target=\"_blank\" title=\"Decider Tool\">Decider Tool</a>.</p>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table6\"></a>Table 6. Initial Access</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Exploit Public-Facing Application</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1190/\" target=\"_blank\" title=\"T1190\">T1190</a></td>\n<td>Gunra actors exploited vulnerabilities in FortiGate firewall and SSL-VPN appliances to gain initial access to victim networks.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 7. Execution</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Windows Management Instrumentation</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1047\" target=\"_blank\" title=\"T1047\">T1047</a></td>\n<td>The Gunra ransomware binary contained specific WMI commands to delete volume shadow copies on victim machines.</td>\n</tr>\n<tr>\n<td>Native API</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1106\" target=\"_blank\" title=\"T1106\">T1106</a></td>\n<td>The Gunra ransomware binary utilized Native APIs (<code>FindFirstFileW</code>, <code>FindNextFileW</code>) for file system discovery.</td>\n</tr>\n<tr>\n<td>Command and Scripting Interpreter: Windows Command Shell</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1059/003/\" target=\"_blank\" title=\"T1059.003\">T1059.003</a></td>\n<td>Gunra actors executed commands via <code>cmd.exe</code> on Windows to initiate the WMI command.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 8. Persistence</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Account Manipulation</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1098/\" target=\"_blank\" title=\"T1098\">T1098</a></td>\n<td>Gunra actors gained access to an unused account for a victim network. They altered the account configuration to bypass the mandatory password change requirement, which allowed them to use the compromised account for subsequent malicious activities.</td>\n</tr>\n<tr>\n<td>External Remote Services</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1133/\" target=\"_blank\" title=\"T1133\">T1133</a></td>\n<td>Gunra actors used external-facing remote services in combination with an administrator account to gain access.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 9. Privilege Escalation</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Valid Accounts: Default Accounts</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1078/001/\" target=\"_blank\" title=\"T1078.001\">T1078.001</a></td>\n<td>Gunra actors compromised an SSL-VPN appliance by exploiting default credentials and the absence of account lockout controls to obtain administrator access to the victim network device.</td>\n</tr>\n<tr>\n<td>Valid Accounts: Domain Accounts</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1078/002/\" target=\"_blank\" title=\"T1078.002\">T1078.002</a></td>\n<td>Gunra actors gained access to an administrator account for an SSL appliance.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 10. Stealth</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Debugger Evasion</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1622\" target=\"_blank\" title=\"T1622\">T1622</a></td>\n<td>The Gunra ransomware Windows encryptor binary contained the <code>IsDebuggerPresent</code> API to defend against reverse engineering and debugging activity.</td>\n</tr>\n<tr>\n<td>Indicator Removal: Clear Command History</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1070/003\" target=\"_blank\" title=\"T1070.003\">T1070.003</a></td>\n<td>Gunra actors cleared command history files on victim machines to prevent detection of their malicious activity.</td>\n</tr>\n<tr>\n<td>Delay Execution</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1678/\" target=\"_blank\" title=\"T1678\">T1678</a></td>\n<td>Gunra actors strategically timed their reconnaissance and malicious network activities to late night or early morning to avoid detection by the victim.</td>\n</tr>\n<tr>\n<td>Selective Exclusion</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1679/\" target=\"_blank\" title=\"T1679\">T1679</a></td>\n<td>The Gunra ransomware binary programmatically excludes certain directories and filetypes from encryption to ensure system critical files continue to function and that ransom notes are readable. In addition, the binary contains logic to prevent re-encryption of already Gunra-encrypted files.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 11. Defense Impairment</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Disable or Modify Tools</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1685/\" target=\"_blank\" title=\"T1685\">T1685</a></td>\n<td>Gunra actors cleared system/network logs on victim machines to prevent detection of their malicious activity.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 12. Credential Access</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>OS Credential Dumping: NTDS</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1003/003\" target=\"_blank\" title=\"T1003.003\">T1003.003</a></td>\n<td>Gunra actors used <code>secretsdump.py</code> on multiple victim domain controllers to extract password hashes for user accounts from the NTDS files.</td>\n</tr>\n<tr>\n<td>Network Sniffing</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1040/\" target=\"_blank\" title=\"T1040\">T1040</a></td>\n<td>Gunra actors abused SSL-VPN network traffic controls to capture users\u2019 VDI login credentials and session information in transit, effectively sniffing authentication traffic for a victim network.</td>\n</tr>\n<tr>\n<td>Steal Web Session Cookie</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1539/\" target=\"_blank\" title=\"T1539\">T1539</a></td>\n<td>Gunra actors captured legitimate VDI session data for a victim, which allowed them to steal and reuse session cookies to hijack active sessions and impersonate legitimate users on the internal victim network.</td>\n</tr>\n<tr>\n<td>Credentials from Password Stores</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1555/\" target=\"_blank\" title=\"T1555\">T1555</a></td>\n<td>From a compromised virtual desktop, Gunra actors accessed the Hiware access control server for a victim and stole its symmetric encryption key.</td>\n</tr>\n<tr>\n<td>OS Credential Dumping</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1003/\" target=\"_blank\" title=\"T1003\">T1003</a></td>\n<td>Gunra actors used a stolen symmetric encryption key from a Hiware system access control server to decrypt and dump stored enterprise server passwords.</td>\n</tr>\n<tr>\n<td>Modify Authentication Process: Multi-Factor Authentication</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1556/006/\" target=\"_blank\" title=\"T1556.006\">T1556.006</a></td>\n<td>Gunra actors altered files in a victim\u2019s VDI authentication server portal so that a specific attacker-chosen OTP always succeeded, creating a persistent backdoor that bypassed MFA.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 13. Discovery</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>File and Directory Discovery</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1083\" target=\"_blank\" title=\"T1083\">T1083</a></td>\n<td>The Gunra ransomware binary contains custom instructions to enumerate the complete directory structure of victim machines to identify user-data files and directories for encryption.</td>\n</tr>\n<tr>\n<td>System Network Connections Discovery</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1049\" target=\"_blank\" title=\"T1049\">T1049</a></td>\n<td>Gunra actors enumerated active system network connections to map reachable internal infrastructure prior to ransomware deployment.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 14. Lateral Movement</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Remote Services: Remote Desktop Protocol</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1021/001/\" target=\"_blank\" title=\"T1021.001\">T1021.001</a></td>\n<td>Gunra actors used stolen VDI session information to access a victim\u2019s internal VDI environment, then moved laterally via RDP to access the victim\u2019s VDI authentication web server, internal AD server, and IT staff virtual desktops.</td>\n</tr>\n<tr>\n<td>Remote Services: SMB/Windows Admin Shares</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1021/002/\" target=\"_blank\" title=\"T1021.002\">T1021.002</a></td>\n<td>Gunra actors used SMB administrative shares with valid credentials to move laterally and deploy tools across compromised systems.</td>\n</tr>\n<tr>\n<td>Use Alternate Authentication Material: Pass the Hash</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1550/002/\" target=\"_blank\" title=\"T1550.002\">T1550.002</a></td>\n<td>Gunra actors used pass-the-hash methods to move laterally to privileged systems.</td>\n</tr>\n<tr>\n<td>Use Alternate Authentication Material: Pass the Ticket</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1550/003/\" target=\"_blank\" title=\"T1550.003\">T1550.003</a></td>\n<td>Gunra actors used pass-the-ticket methods to move laterally to privileged systems.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 15. Collection</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Collection</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/tactics/TA0009/\" target=\"_blank\" title=\"TA0009\">TA0009</a></td>\n<td>Gunra actors were observed collecting business-critical documents, databases, PII, and internal email communications.</td>\n</tr>\n<tr>\n<td>Archive Collected Data</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1560\" target=\"_blank\" title=\"T1560\">T1560</a></td>\n<td>Gunra actors were observed utilizing tools such as 7-Zip, WinRAR, RClone, and others to copy and archive victim data for exfiltration.</td>\n</tr>\n<tr>\n<td>Data from Cloud Storage</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1530\" target=\"_blank\" title=\"T1530\">T1530</a></td>\n<td>Gunra actors launched a malicious application (<code>main.exe</code>) that specifically targeted Microsoft Cloud Services (OneDrive and SharePoint) for data exfiltration.</td>\n</tr>\n<tr>\n<td>Data from Local System</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1005\" target=\"_blank\" title=\"T1005\">T1005</a></td>\n<td>\n<p>The Gunra ransomware binary recursed through the full directory structure of a compromised device to identify user-data files and directories for targeted exfiltration and subsequent encryption.</p>\n<p>In one instance, Gunra actors were observed collecting system and network configuration network information by connecting to the VDI environments of IT personnel.</p>\n</td>\n</tr>\n<tr>\n<td>Email Collection</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1114/\" target=\"_blank\" title=\"T1114\">T1114</a></td>\n<td>Gunra actors collected internal email communications.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 16. Command and Control</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Ingress Tool Transfer</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1105/\" target=\"_blank\" title=\"T1105\">T1105</a></td>\n<td>After obtaining admin access to a victim\u2019s SSL-VPN appliance, Gunra actors downloaded an SSH tunneling tool from an external server to create and maintain persistent tunnel connections to compromised systems in the victim\u2019s network.</td>\n</tr>\n<tr>\n<td>Protocol Tunneling</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1572/\" target=\"_blank\" title=\"T1572\">T1572</a></td>\n<td>Gunra actors used an SSH tunneling tool to establish connections and maintain persistence between compromised systems.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 17. Exfiltration</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Exfiltration Over Web Service</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1567\" target=\"_blank\" title=\"T1567\">T1567</a></td>\n<td>Gunra actors were observed archiving victim data and exfiltrating it over the file-sharing service Mega.</td>\n</tr>\n<tr>\n<td>Exfiltration Over Alternative Protocol</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1048\" target=\"_blank\" title=\"T1048\">T1048</a></td>\n<td>Gunra actors used Filezilla software to exfiltrate data over FTP.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table18\"></a>Table 18. Impact</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Data Encrypted for Impact</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1486\" target=\"_blank\" title=\"T1486\">T1486</a></td>\n<td>\n<p>Gunra actors encrypt victim data using combined ChaCha20 + RSA-4096 algorithms to prevent victim access to critical business files. Gunra encryptors are available for Windows and Linux, increasing the potential attack surface within a victim network.</p>\n<p>In one instance, Gunra actors encrypted key assets that included database servers and NAS systems.</p>\n</td>\n</tr>\n<tr>\n<td>Financial Theft</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1657\" target=\"_blank\" title=\"T1657\">T1657</a></td>\n<td>Under the double-extortion model, Gunra actors demand ransom payment through a ransom note (<code>R34DM3.txt</code>) in cryptocurrency. The note instructs victims to make the payment to prevent public leaks of their sensitive business data and acquire decryption keys to unlock encrypted files on compromised systems.</td>\n</tr>\n<tr>\n<td>Inhibit System Recovery</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1490\" target=\"_blank\" title=\"T1490\">T1490</a></td>\n<td>\n<p>To augment encryption of critical data on victim networks and prevent system recovery, Gunra actors disable backup features, such as volume shadow copies.</p>\n<p>In one instance, Gunra actors prevented restoration from backups by deleting backup and archived data stored at the primary data center and disaster recovery center.</p>\n</td>\n</tr>\n</tbody>\n</table>\n<h2><strong>Incident Response</strong></h2>\n<p>If a potential compromise is detected, but ransomware actors have not (yet) encrypted items, organizations should take the following actions:</p>\n<ol>\n<li><strong>Determine which hosts were compromised and isolate them</strong> by quarantining or taking them offline.<br>\n<ol type=\"a\">\n<li><strong>If the incident involves a Gunra Linux variant,</strong> <strong>preserve encrypted files, file timestamps, ransom notes, and relevant system logs</strong>.<br>\n<ol type=\"i\">\n<li>As of March 2026, researchers identified a weakness in the Gunra ransomware\u2019s Linux Executable and Linkable Format (ELF) variants (appended with <code>.GNRA</code>); the encryption keys use a weak pseudorandom number generator (PRNG) seeded with the predictable system&nbsp;<code>srand(time(NULL)</code>).<a href=\"#Note14\"><sup>14</sup></a> Defenders may leverage this to mathematically reconstruct the keys using file timestamps and recover files without paying the ransom.</li>\n</ol>\n</li>\n</ol>\n</li>\n<li><strong>Initiate threat hunting activities to scope the intrusion</strong>. Collect and review relevant artifacts, logs, and other data to identify threat actor TTPs, compromised devices and accounts, a timeline of activity, etc. Responders should consider:<br>\n<ol type=\"a\">\n<li>Reviewing logs of network appliances (e.g., edge devices) to audit actions associated with privileged users to identify anomalous activity.</li>\n<li>Collecting copies of ransom notes to identify current threat actor communication platforms.</li>\n<li>Auditing the creation of new files (particularly archives) to determine possible pre- or post-exfiltration activity.</li>\n</ol>\n</li>\n<li><strong>Report the compromise</strong> to the FBI and other agencies as appropriate (see <a href=\"#Reporting\"><strong>Reporting</strong></a><strong> </strong>for contact information).</li>\n<li><strong>Apply eviction countermeasures</strong>, including those listed below, to contain the incident and eradicate the threat actor from the network (<strong>Note:</strong> Start applying countermeasures after collecting enough threat hunting data to inform effective countermeasure selection; this will likely overlap with threat hunting activities).<br>\n<ol type=\"a\">\n<li>Identify and disable malicious, actor-controlled accounts.</li>\n<li>Identify and secure legitimate, privileged accounts.</li>\n<li>Use CISA\u2019s <a href=\"https://cisa.gov/eviction-strategies-tool?utm_source=&amp;utm_medium=CSAEviction\" title=\"Eviction Strategies Tool\">Eviction Strategies Tool</a> to assemble countermeasures for a systematic eviction plan\u2014the tool comprises <strong>Playbook-NG</strong> (a web application) and <strong>COUN7ER</strong> (a database of post-compromise countermeasures mapped to adversary TTPs).<br>\n<ol type=\"i\">\n<li>Use Playbook-NG and COUN7ER together to assemble a systematic eviction plan, or playbook, that leverages distinct countermeasures to contain and evict cyber threat actors. The playbook features a list of recommended response actions based on threat actor TTPs and includes each action\u2019s intended outcome, preparatory steps, and associated risks. For more information, see CISA\u2019s <a href=\"https://www.cisa.gov/resources-tools/resources/eviction-strategies-tool\" title=\"Eviction Strategies Tool Fact Sheet\">Eviction Strategies Tool Fact Sheet</a>.</li>\n</ol>\n</li>\n</ol>\n</li>\n<li><strong>Harden the network to prevent additional malicious activity</strong> (see <a href=\"#Mitigations\"><strong>Mitigations</strong></a><strong> </strong>for guidance).</li>\n</ol>\n<p>If compromise is detected and items have been encrypted, see the \u201cRansomware and Data Extortion Response Checklist\u201d in CISA\u2019s joint <a href=\"https://www.cisa.gov/sites/default/files/2025-03/StopRansomware-Guide%20508.pdf\" title=\"#StopRansomware Guide\">#StopRansomware Guide</a>.</p>\n<h2><a class=\"ck-anchor\" id=\"Mitigations\"><strong>Mitigations</strong></a></h2>\n<p>The authoring agencies recommend organizations implement the mitigations below to improve your organization\u2019s cybersecurity posture on the basis of Gunra actor activity. These mitigations align with the <a href=\"https://www.cisa.gov/cpg\" title=\"Cross-Sector Cybersecurity Performance Goals (CPGs)\">Cross-Sector Cybersecurity Performance Goals (CPGs)</a> developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats and TTPs. Visit CISA\u2019s <a href=\"https://www.cisa.gov/cpg\" title=\"CPGs webpage\">CPGs webpage</a> for more information on the CPGs, including additional recommended baseline protections.</p>\n<ul type=\"square\">\n<li><strong>Prioritize patching known exploited vulnerabilities&nbsp;</strong>[<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#MitigateKnownVulnerabilities2B\" title=\"CPG 2.B\">CPG 2.B</a>] <strong>and the CVEs in this advisory</strong> in internet-facing systems\u2014including VPN gateways and RDP-exposed infrastructure\u2014and keep all OSs, software, and firmware up to date to support this.</li>\n<li><strong>Implement a recovery plan</strong> to maintain and retain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, and secure location (e.g., hard drive, storage device, the cloud) [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementLogicalPhysicalNetworkSegmentation3I\" title=\"CPG 3.I\">CPG 3.I</a>, <a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#MaintainSystemBackupsRestorationAbility3O\" title=\"3.O\">3.O</a>, <a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ManageIncidentResponsePlans1C\" title=\"1.C\">1.C</a>].</li>\n<li><strong>Review domain controllers, servers, workstations, and active directories</strong> for new and/or unrecognized accounts [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ManageOrganizationalAssets2A\" title=\"CPG 2.A\">CPG 2.A</a>, <a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#DocumentNetworkTopology2E\" title=\"2.E\">2.E</a>].</li>\n<li><strong>Audit user accounts with administrative privileges and configure access controls</strong> according to the principle of least privilege [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#AdministratorsMaintainSeparateUserandPrivilegedAccounts3G\" title=\"CPG 3.G\">CPG 3.G</a>].</li>\n<li><strong>Segment networks</strong> [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementLogicalPhysicalNetworkSegmentation3I\" title=\"CPG 3.I\">CPG 3.I</a>] to prevent the spread of ransomware.<br>\n<ul type=\"circle\">\n<li>Network segmentation can help prevent the spread of ransomware by controlling traffic flows between\u2014and access to\u2014various subnetworks and by restricting adversary lateral movement.</li>\n</ul>\n</li>\n<li><strong>Require MFA</strong> for all services to the extent possible, particularly for webmail, VPNs, and accounts that access critical systems [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementMultifactorAuthentication3F\" target=\"_blank\" title=\"CPG 3.F\">CPG 3.F</a>].</li>\n<li><strong>Disable command-line and scripting activities and permissions.</strong> Privilege escalation and lateral movement often depend on software utilities running from the command line. If threat actors are not able to run these tools, they will have difficulty escalating privileges and/or moving laterally [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#AdministratorsMaintainSeparateUserandPrivilegedAccounts3G\" title=\"CPG 3.G\">CPG 3.G</a>, <a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#DisableAutorunMacrosByDefault3M\" title=\"3.M\">3.M</a>].</li>\n</ul>\n<h2><strong>Validate Security Controls</strong></h2>\n<p>In addition to applying mitigations, the authoring agencies recommend exercising, testing, and validating your organization's security program against the threat behaviors mapped to the MITRE ATT&amp;CK for Enterprise framework in this advisory. The authoring agencies recommend testing your existing security controls inventory to assess how they perform against the ATT&amp;CK techniques described in this advisory.</p>\n<p>To get started:</p>\n<ol>\n<li>Select an ATT&amp;CK technique described in this advisory (see <a href=\"#Table6\"><strong>Table 6</strong></a> to <a href=\"#Table18\"><strong>Table 18</strong></a>).</li>\n<li>Align your security technologies against the technique.</li>\n<li>Test your technologies against the technique.</li>\n<li>Analyze your detection and prevention technologies\u2019 performance.</li>\n<li>Repeat the process for all security technologies to obtain a set of comprehensive performance data.</li>\n<li>Tune your security program, including people, processes, and technologies, based on the data generated by this process.</li>\n</ol>\n<p>The authoring agencies recommend continually testing your security program, at scale, in a production environment to ensure optimal performance against the MITRE ATT&amp;CK techniques identified in this advisory.</p>\n<h2><strong>Resources</strong></h2>\n<ul type=\"square\">\n<li><a href=\"https://www.stopransomware.gov/\" target=\"_blank\" title=\"StopRansomware.gov\">StopRansomware.gov</a>: Whole-of-government, central location for ransomware resources and alerts.</li>\n<li><a href=\"https://www.cisa.gov/resources-tools/resources/stopransomware-guide\" title=\"#StopRansomware Guide\">#StopRansomware Guide</a>: Resource to mitigate a ransomware attack.</li>\n<li><a href=\"https://www.cisa.gov/cyber-hygiene-services\" title=\"Cyber Hygiene Services\">Cyber Hygiene Services</a>, <a href=\"https://github.com/cisagov/cset/releases/tag/v10.3.0.0\" target=\"_blank\" title=\"Ransomware Readiness Assessment\">Ransomware Readiness Assessment</a>: CISA\u2019s no-cost cyber hygiene services.</li>\n<li>USSS\u2019s <a href=\"https://www.secretservice.gov/investigations/cyberincident\" target=\"_blank\" title=\"Preparing for a Cyber Incident\">Preparing for a Cyber Incident</a>: Outlines basic steps an organization can take before, during, and after a cyber incident.</li>\n</ul>\n<h2><a class=\"ck-anchor\" id=\"Reporting\"><strong>Reporting</strong></a></h2>\n<p>Your organization has no obligation to respond or provide information back to the FBI and other authoring agencies in response to this joint advisory. If, after reviewing the information provided, your organization decides to provide information to the FBI and other authoring agencies, reporting must be consistent with applicable state and federal laws.</p>\n<p>The FBI and other authoring agencies are interested in any information that can be shared, to include boundary logs showing communication to and from foreign IP addresses, a sample ransom note, communications with threat actors, cryptocurrency wallet information, decryptor files, and/or a benign sample of an encrypted file.</p>\n<p>Additional details of interest include a targeted company point of contact, status and scope of infection, estimated loss, operational impact, transaction IDs, date of infection, date detected, initial attack vector, and host- and network-based indicators.</p>\n<p>The authoring agencies do not encourage paying ransom as payment does not guarantee victim files will be recovered. Furthermore, payment may also embolden adversaries to target additional organizations, encourage other criminal actors to engage in the distribution of ransomware, and/or fund illicit activities. Regardless of whether you or your organization have decided to pay the ransom, the FBI and CISA urge you to promptly report ransomware incidents to the FBI\u2019s <a href=\"https://www.ic3.gov/Home/ComplaintChoice\" target=\"_blank\" title=\"Internet Crime Complaint Center (IC3)\">Internet Crime Complaint Center (IC3)</a> or a <a href=\"https://www.fbi.gov/contact-us/field-offices\" target=\"_blank\" title=\"local FBI field office\">local FBI field office</a>, to USSS via a <a href=\"https://www.secretservice.gov/contact/field-offices\" target=\"_blank\" title=\"local USSS Field Office\">local USSS Field Office</a>, or CISA via the agency\u2019s <a href=\"https://www.cisa.gov/report\" title=\"Incident Reporting System\">Incident Reporting System</a> or its 24/7 Operations Center (<a href=\"mailto:contact@cisa.dhs.gov\" title=\"contact@cisa.dhs.gov\">contact@cisa.dhs.gov</a>), or by calling 1-844-Say-CISA (1-844-729-2472).</p>\n<p><strong>South Korean organizations:</strong> Report cybersecurity incidents to KNPA via the <a href=\"https://www.ecrm.police.go.kr/\" target=\"_blank\" title=\"online cybercrime reporting system\">online cybercrime reporting system</a> or by calling 112.</p>\n<h2><strong>Disclaimer</strong></h2>\n<p>The information in this report is being provided \u201cas is\u201d for informational purposes only. CISA and co-sealers do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA and co-sealers.</p>\n<h2><strong>Version History</strong></h2>\n<p><strong>August 10, 2026: </strong>Initial version.</p>\n<h2><strong>Notes</strong></h2>\n<p><a class=\"ck-anchor\" id=\"Note1\"><sup>1</sup></a> For information on historical Conti ransomware activity, see CISA and FBI\u2019s <a href=\"https://www.cisa.gov/news-events/alerts/2021/09/22/conti-ransomware\">Conti Ransomware</a> advisory.</p>\n<p><a class=\"ck-anchor\" id=\"Note2\"><sup>2</sup></a> Breakglass Intelligence, \u201cGunra Ransomware\u2019s Linux Variant Has a Fatal Flaw: time()-Seeded rand() Makes Encrypted Files Recoverable Without Paying,\u201d Breakglass Intelligence, March 12, 2026, <a href=\"https://intel.breakglass.tech/post/gunra-ransomware-s-linux-variant-has-a-fatal-flaw-time-seeded-rand-makes-encrypted-files-recoverable-without-paying\" target=\"_blank\">https://intel.breakglass.tech/post/gunra-ransomware-s-linux-variant-has-a-fatal-flaw-time-seeded-rand-makes-encrypted-files-recoverable-without-paying</a>; Jeffrey Francis Bonaobra, Melvin Singwa, Emmanuel Panopio \u201cGunra Ransomware Group Unveils Efficient Linux Variant,\u201d Trend Micro, July 29, 2025, <a href=\"https://www.trendmicro.com/en_us/research/25/g/gunra-ransomware-linux-variant.html\" target=\"_blank\">https://www.trendmicro.com/en_us/research/25/g/gunra-ransomware-linux-variant.html</a>; and CYFIRMA, \u201cGunra Ransomware \u2013 A Brief Analysis,\u201d CYFIRMA, May 3, 2025, <a href=\"https://www.cyfirma.com/research/gunra-ransomware-a-brief-analysis/\" target=\"_blank\">https://www.cyfirma.com/research/gunra-ransomware-a-brief-analysis/</a>.</p>\n<p><a class=\"ck-anchor\" id=\"Note3\"><sup>3</sup></a> CloudSEK, \u201cInside Gunra RaaS: From Affiliate Recruitment on the Dark Web to Full Technical Dissection of their Locker,\u201d CloudSEK, February 11, 2026, <a href=\"https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker\" target=\"_blank\">https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker</a>.</p>\n<p><a class=\"ck-anchor\" id=\"Note4\"><sup>4</sup></a> CYFIRMA, \u201c<a href=\"https://www.cyfirma.com/research/gunra-ransomware-a-brief-analysis/\" target=\"_blank\">Gunra Ransomware \u2013 A Brief Analysis</a>\u201d; and Breakglass Intelligence, \u201c<a href=\"https://intel.breakglass.tech/post/gunra-ransomware-s-linux-variant-has-a-fatal-flaw-time-seeded-rand-makes-encrypted-files-recoverable-without-paying\" target=\"_blank\">Gunra Ransomware\u2019s Linux Variant Has a Fatal Flaw</a>.\u201d</p>\n<p><a class=\"ck-anchor\" id=\"Note5\"><sup>5</sup></a> Bonaobra, \u201c<a href=\"https://www.trendmicro.com/en_us/research/25/g/gunra-ransomware-linux-variant.html\" target=\"_blank\">Gunra Ransomware Group Unveils Efficient Linux Variant</a>\u201d; and CloudSEK, \u201c<a href=\"https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker\" target=\"_blank\">Inside Gunra RaaS</a>.\u201d</p>\n<p><a class=\"ck-anchor\" id=\"Note6\"><sup>6</sup></a> CloudSEK, \u201c<a href=\"https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker\" target=\"_blank\">Inside Gunra RaaS</a>.\u201d</p>\n<p><a class=\"ck-anchor\" id=\"Note7\"><sup>7</sup></a> CYFIRMA, \u201c<a href=\"https://www.cyfirma.com/research/gunra-ransomware-a-brief-analysis/\" target=\"_blank\">Gunra Ransomware \u2013 A Brief Analysis</a>.\u201d</p>\n<p><a class=\"ck-anchor\" id=\"Note8\"><sup>8</sup></a> CloudSEK, \u201c<a href=\"https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker\" target=\"_blank\">Inside Gunra RaaS</a>.\u201d</p>\n<p><a class=\"ck-anchor\" id=\"Note9\"><sup>9</sup></a> CloudSEK, \u201c<a href=\"https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker\" target=\"_blank\">Inside Gunra RaaS</a>.\u201d</p>\n<p><a class=\"ck-anchor\" id=\"Note10\"><sup>10</sup></a> Bonaobra, \u201c<a href=\"https://www.trendmicro.com/en_us/research/25/g/gunra-ransomware-linux-variant.html\" target=\"_blank\">Gunra Ransomware Group Unveils Efficient Linux Variant</a>.\u201d</p>\n<p><a class=\"ck-anchor\" id=\"Note11\"><sup>11</sup></a> VirusTotal, \u201cVirusTotal - File - 91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0,\u201d <em>VirusTotal</em>, <a href=\"https://www.virustotal.com/gui/file/91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0/details\" target=\"_blank\">https://www.virustotal.com/gui/file/91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0/details</a>.</p>\n<p><a class=\"ck-anchor\" id=\"Note12\"><sup>12</sup></a> CloudSEK, \u201c<a href=\"https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker\" target=\"_blank\">Inside Gunra RaaS</a>.\u201d</p>\n<p><a class=\"ck-anchor\" id=\"Note13\"><sup>13</sup></a> CYFIRMA, \u201c<a href=\"https://www.cyfirma.com/research/gunra-ransomware-a-brief-analysis/\" target=\"_blank\">Gunra Ransomware \u2013 A Brief Analysis</a>.\u201d</p>\n<p><a class=\"ck-anchor\" id=\"Note14\"><sup>14</sup></a> Breakglass Intelligence, \u201c<a href=\"https://intel.breakglass.tech/post/gunra-ransomware-s-linux-variant-has-a-fatal-flaw-time-seeded-rand-makes-encrypted-files-recoverable-without-paying\" target=\"_blank\">Gunra Ransomware\u2019s Linux Variant Has a Fatal Flaw</a>.\u201d</p>\n<p>&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Mon, 10 Aug 26 12:00:00 +0000",
        "last_updated": "Mon, 10 Aug 26 12:00:00 +0000"
    }
]