Historical snapshot · Cybersecurity

CISA Advisories

Cybersecurity advisories and mitigation guidance for networks and critical infrastructure.

This page is an archived snapshot of the CISA Advisories feed collected on Aug 27, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
30 recordsOfficial source · JSON
· CISA Cybersecurity Advisory

CISA Vulnerability Review

Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and organizations can reduce their risk by addressing these underlying weaknesses and prioritizing vulnerabilities for action based on the risk they pose. The CISA Vulnerability Review…
Read full source summary
Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and organizations can reduce their risk by addressing these underlying weaknesses and prioritizing vulnerabilities for action based on the risk they pose. The CISA Vulnerability Review provides organizations with critical insights into the root causes of insecure software and practical steps they can take to address these flaws to prevent exploitation. Analyzing CISA and open source data from fiscal years 2024 and 2025, the review establishes a baseline of today’s vulnerability landscape before AI-enabled vulnerability discovery becomes more widespread. The review demonstrates the importance of Secure by Design principles in shifting cybersecurity efforts from reacting to threat actors to proactively fixing preventable software flaws. The review also identifies common software weaknesses that contribute to exploitable vulnerabilities and details practices software producers can use to prevent these weaknesses from recurring. By examining the patterns across vulnerability data, the review helps organizations focus on systemic improvements that can reduce entire classes of vulnerabilities rather than addressing individual vulnerabilities only after they are discovered. Additionally, the review shows organizations how to prioritize vulnerabilities for action using the framework outlined in Binding Operational Directive 26-04: Prioritizing Security Based on Risk. This framework evaluates vulnerabilities using four key criteria: exposure status, Known Exploited Vulnerability (KEV) Catalog status, potential for automated exploitation, and technical impact.
· CISA Cybersecurity Advisory

CISA Adds Six Known Exploited Vulnerabilities to Catalog

CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability CVE-2021-23758 Ajax.NET Professional Deserialization of Untrusted…
Read full source summary
CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability CVE-2021-23758 Ajax.NET Professional Deserialization of Untrusted Data Vulnerability CVE-2022-0995 Linux Kernel Out-of-Bounds Write Vulnerability CVE-2026-8452 Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
· CISA Cybersecurity Advisory

PayRange API

View CSAF Summary Successful exploitation of this vulnerability could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify the device to cause a denial of service, or alter a devices displayed image. The following versions of PayRange API are affected: PayRange API vers:all/* CVSS Vendor Equipment Vulnerabilities v3 8.8 PayRange PayRange API Missing…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify the device to cause a denial of service, or alter a devices displayed image. The following versions of PayRange API are affected: PayRange API vers:all/* CVSS Vendor Equipment Vulnerabilities v3 8.8 PayRange PayRange API Missing Authorization Background Critical Infrastructure Sectors: Commercial Facilities Countries/Areas Deployed: United States, Canada Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-18965 The affected product is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account. View CVE Details Affected Products PayRange API Vendor: PayRange Product Version: PayRange PayRange API: vers:all/* Product Status: known_affected Remediations Mitigation PayRange has not responded to requests to work with CISA to mitigate this vulnerability. Users of PayRange devices are invited to contact PayRange customer support at support@payrange.com for additional information. mailto:support@payrange.com Relevant CWE: CWE-862 Missing Authorization Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments Tahi Wilton Geary reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-08-25 Date Revision Summary 2026-08-25 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Rently Smart Home

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to access sensitive information and override user permissions. The following versions of Rently Smart Home are affected: Smart Home <=20.1.0 CVSS Vendor Equipment Vulnerabilities v3 8.1 Rently Rently Smart Home Insufficiently Protected Credentials Background Critical Infrastructure Sectors: Commercial Facilities, Communications,…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to access sensitive information and override user permissions. The following versions of Rently Smart Home are affected: Smart Home <=20.1.0 CVSS Vendor Equipment Vulnerabilities v3 8.1 Rently Rently Smart Home Insufficiently Protected Credentials Background Critical Infrastructure Sectors: Commercial Facilities, Communications, Information Technology Countries/Areas Deployed: United States, India Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-75960 Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions. View CVE Details Affected Products Rently Smart Home Vendor: Rently Product Version: Rently Smart Home: <=20.1.0 Product Status: known_affected Remediations Mitigation Rently has patched this vulnerability in late June. No user action is required. Mitigation For more information, contact Rently (support@rently.com). mailto:support@rently.com Relevant CWE: CWE-522 Insufficiently Protected Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.1 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments Berk Dusunur reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-08-25 Date Revision Summary 2026-08-25 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

A Tale of Two SOCs: Insights From Two Red Team Assessments

Advisory at a Glance Title A Tale of Two SOCs: Insights From Two Red Team Assessments Original Publication August 25, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems…
Read full source summary
Advisory at a Glance Title A Tale of Two SOCs: Insights From Two Red Team Assessments Original Publication August 25, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A failed to detect or contain the activity, but Organization B rapidly identified initial compromise attempts, isolated affected systems, and forced the red team into an assume breach model. This advisory details the red team’s activity and organizations’ defensive actions, offering lessons learned and mitigations to help critical infrastructure organizations strengthen detection, response, and protections in IT, cloud, and operational technology (OT) environments. Lessons Learned Untuned detection tools lead to missed threats. Without well-defined baselines and alert filtering, false positives and routine alerts overwhelm network defenders. Organizational silos and bureaucratic hurdles prevent effective incident response. Detection tools are only as effective as the people, processes, and procedures supporting them; fragmented communication, unclear responsibilities, and limited defender authority hinder effective incident response. Cloud environments are often an underestimated risk. Organizations often lack security controls for cloud environments and processes for responding to a cloud compromise. Key Actions Establish and continuously maintain a baseline and reduce alert noise by fine tuning. Break down silos and empower network defenders. Implement Conditional Access policies for workload identities and monitor for excessive or unused permissions. Establish and regularly review comprehensive procedures for detecting, remediating, and revoking access/refresh tokens in the event of a cloud compromise. Intended Audience Organizations: Federal Civilian Executive Branch agencies; state, local, tribal, and territorial governments; critical infrastructure. Roles: System administrators, incident responders, defensive cybersecurity analysts, vulnerability analysts, network operators, security systems managers, and all network defenders. Introduction The Cybersecurity and Infrastructure Security Agency’s (CISA’s) red team simulates real‑world malicious cyber operations to assess an organization’s ability to detect, investigate, and respond to malicious cyber activity. Emulating cyber threat actor tradecraft, the red team attempts to gain and maintain persistent access to an organization’s network and sensitive business systems (SBSs) while avoiding detection. CISA conducted two simultaneous red team assessments using similar tradecraft but observed different defensive responses. In one organization (Organization A), the team gained initial access to multiple workstations, gained elevated privileges over the domain, and moved laterally to SBSs and cloud resources undetected. In the second organization (Organization B), network defenders quickly detected the initial compromise and quarantined the affected systems. Because Organization B detected the initial compromise, the red team moved to an assume breach model, where Organization B trusted agents (TAs) provided access to a host that replicated the level of access the red team would have had if defenders had not detected their activity. From there, the red team escalated privileges and moved laterally to SBSs, cloud resources, and a bastion host in the OT demilitarized zone (DMZ), where defenders again detected activity and isolated the system. In coordination with the assessed organizations, CISA is releasing this Cybersecurity Advisory to describe the red team’s activity and the organization’s defensive responses and to share lessons learned that critical infrastructure organizations can use to strengthen their IT, cloud, and OT cybersecurity posture. CISA encourages critical infrastructure organizations to implement the recommendations in the Mitigations section of this advisory to reduce the likelihood and impact of malicious cyber incidents. Download the PDF version of this report: A Tale of Two SOCs: Insights From Two Red Team Assessments (PDF, 937.09 KB ) Technical Details Note: This advisory uses the MITRE ATT&CK® Matrix for Enterprise framework, version 19. See the MITRE ATT&CK Tactics and Techniques section of this advisory for a table of the red team’s activity mapped to MITRE ATT&CK tactics and techniques. Overview CISA is authorized—upon request—to provide analyses, expertise, and other technical assistance to critical infrastructure owners and operators and to provide operational and timely technical assistance to federal and non-federal entities, with respect to cybersecurity risks (see generally 6 U.S.C. §§ 652[c][5], 659[c][6]). CISA conducted two concurrent red team assessments: one at a Government Services and Facilities Sector organization (Organization A), and one at a Water and Wastewater Systems Sector organization (Organization B). During CISA’s red team assessments, the red team simulates malicious cyber operations to assess an organization’s threat detection and response capabilities. The red team attempts to gain and maintain persistent access to an organization’s enterprise network, avoid detection, evade defenses, and access SBSs (applications, data stores, or infrastructure components where compromise would materially impact the organization's operations, finances, or customer data) selected by the organization. For the assessments described in this advisory, the team also attempted to gain access to cloud resources and to demonstrate their ability to access Organization B’s OT systems without actually doing so. Organization A Red Team Cyber Threat Activity Initial Access and Active Directory Discovery During reconnaissance, CISA’s red team identified a web application with default credentials [T1589.001] for multiple built-in user accounts that allowed the team to send emails from an internal email address. The team used the internal email address to send phishing emails [T1566] and gained initial access to four workstations. From the workstations, the red team leveraged a modified BloodHound1 collector, customized to avoid static endpoint detection and response (EDR) signatures, to query and scrape Active Directory (AD) information. This information included AD users [T1087.002], computers [T1018], groups [T1069.002], access control lists, organizational units, and group policy objects (GPOs) [T1615]. The team found that one compromised workstation had the default Machine Account Quota (MAQ) of 10, allowing unprivileged users to add up to 10 computer accounts to the domain. The red team also queried the organization’s Active Directory Certificate Service (ADCS) certificate templates. Misconfigured ADCS templates are common and can allow low-privileged accounts to request a certificate on behalf of other users and computers, including highly privileged accounts. The team identified multiple templates with an ESC1 misconfiguration, which allows any user to request certificates for all users and computer accounts (see scenario ESC1 in SpecterOp’s Certified Pre-Owned: Abusing Active Directory Certificate Services). The red team exploited the misconfigured MAQ to create a machine account [T1136.002] and then exploited a misconfigured ADCS template to request a certificate for the newly created machine account [T1649]. They could then obtain certificates for any user account, providing means for lateral movement. Post Exploitation: Privilege Escalation and Lateral Movement Sensitive Business Systems After the red team gained elevated privileges over the domain, they began post-exploitation activities and attempted to access SBSs. To access the SBSs, the team needed to identify their network location and security controls. The team’s plan to achieve SBS access included the following steps: Use previously acquired AD data to identify users and groups related to the SBS. Query system center configuration manager (SCCM) servers to enumerate user-device relationships and identify the workstations assigned to each user [T1033]. Move laterally from the SCCM server to the target users’ workstations. Find credential material on the target user’s workstation to access the SBS. Verify administrative access to the SBS would allow compromise of the availability, integrity, and/or confidentiality of the system and its data. For each SBS, the red team used similar discovery and initial access techniques but unique credential retrieval methods. For SBS 1, a database, the team located cleartext credentials on an administrative user’s workstation providing access to the system [T1552]. For SBS 2, also a database, the red team searched the targeted user’s workstations for connections.json and product-preferences.xml files for a Structured Query Language (SQL) developer tool. The team decrypted these files to obtain the cleartext password to the database [T1552.001]. For SBS 3, an automated processing system, the red team acquired long-lived static Amazon Web Service (AWS) identity and access management (IAM) user credentials saved in configuration files in targeted users’ home directories. These credentials do not expire because the organization had not configured credential expiration or rotation. For SBS 2 and 3, the red team expanded access beyond users’ physical workstations to include their virtual desktops, which limited their access to the active, interactive sessions held by users. While virtual workstations add security controls, such as segmenting networks of sensitive systems to only allow virtual hosts, they are generally synchronized with a root drive of the distributed file system (DFS). The red team compromised the root DFS drive, granting them access to local files of all users’ virtual desktops, regardless of the existence of an active session. This allowed the team to quickly search for cloud configuration files containing credentials and database connection files for thousands of users. The red team obtained administrative access to all targeted SBSs without defensive intervention by proxying tools [T1090.001] through compromised workstations and using the collected credentials. Microsoft Entra Systems After compromising the target SBSs, the red team attempted to compromise Organization A’s Microsoft cloud environment by compromising Organization A’s Microsoft Entra ID (formerly Azure AD) through applications. The team targeted Entra ID applications with Application permissions, which allow applications to access data without user consent (compared to Delegated permissions, which allow applications to access data with user consent). By compromising an application that had elevated Application permissions, the red team would gain the same permissions as the application because these applications operate outside the scope of traditional conditional access policies (CAPs) that provide controls for user access and activity. Note: Microsoft’s Conditional Access for workload identities extends traditional CAPs to service principals (SPs) used by applications and governs Application permissions by allowing organizations to broadly apply access policies to applications. Implementing Conditional Access for workload identities would have protected against red team exploiting use of Application permissions; however, the red team never observed an organization using Conditional Access for workload identities. The team compromised applications and used their permissions by: Enumerating the organization’s cloud resources using the publicly available tools, including AzureHound2 and ROADrecon,3 to gather information about applications, their permissions, and their owners [T1526] [T1588.002]. Identifying applications with elevated permissions to the Microsoft Graph Resource application programming interface (API), including the following: Mail.Read – Read Outlook emails. Mail.ReadWrite – Read and write Outlook emails. Chat.Read.All – Access Teams messages. Files.Read.All – Access OneDrive. Application.ReadWrite.All – Add Client Secrets to any application or SP. AppRoleAssignment.ReadWrite.All – Lets an SP grant itself powerful Graph application permissions such as Chat.Read.All or RoleManagement.ReadWrite.Directory. Identifying the owner of an application with Mail.ReadWrite permissions. Moving laterally to the owner’s machine. Obtaining access to the user’s primary refresh token (PRT). A PRT is a secure artifact specifically issued to Microsoft first-party token brokers to enable single sign-on (SSO) across the applications used on those devices. For more information about PRT, see Microsoft’s Understanding Primary Refresh Token (PRT) in Microsoft Entra ID. Using the PRT to request access and refresh tokens for the targeted application’s owner. Access tokens are short-lived tokens issued by Entra ID that grant a client permission to access specific resources or APIs on behalf of a user. Refresh tokens are longer-lived tokens issued by Entra ID that allow a client to silently request new access tokens without requiring the user to sign in again. Using the access token to add a new client secret to the target application. A client secret is a confidential string used by the application to authenticate itself to Entra ID during token requests. Using the new client secret to request a new access token for the target application. Impersonating the application by using the access token [T1550.001] to retrieve and review target emails [T1114] via the Microsoft Graph API. This allowed the red team to review security operations center (SOC) staff emails to see if SOC staff were aware of the compromise. Organization A’s Response The organization did not respond effectively to red team activity. The red team observed this during their engagement by accessing SOC personnel emails and moving laterally to SOC workstations where they captured screenshots [T1113], used keyloggers [T1056.001], and retrieved Microsoft Teams messages [T1213.005]. The red team observed that the SOC received medium- and low-severity EDR alerts related to the red team activity but did not respond to them. Thousands of false positive alerts corresponding to normal business operations, many with a higher severity, obscured the alerts triggered by red team activity. Organizational silos further hindered detection and response. The organization had multiple SOCs and multiple EDR solutions. Staff did not communicate with staff from other SOCs or have visibility on their detection tools. SOC staff and system owners also did not communicate with each other. This led to SOC staff not actioning alerts from red team activity. For example, red team members noted chat exchanges regarding an SCCM in which defenders tried and failed to identify the system owner, its function, and its typical use. The SOC team eventually flagged the alert as a false positive. The red team believes this was because the SOC staff lacked standard operating procedures for escalating alerts and had limited personnel authority. Organization B Red Team Cyber Threat Activity Initial Access The CISA red team gained initial access to Organization B’s environment through a spearphishing campaign. The team gathered email addresses from public websites [T1589.002] and sent phishing emails that eventually led to three users clicking [T1204] on a malicious link, giving the red team access to three workstations. Each payload execution generated a medium-severity alert: “An executable file loaded an unexpected DLL file.” SOC staff triaged these alerts and manually isolated all three workstations within 10, 2, and 20 minutes. This effectively terminated the team’s command and control (C2) communications with the workstations. Before staff isolated one workstation, the red team enumerated Organization B’s domain’s AD structure by executing various Lightweight Directory Access Protocol (LDAP) queries through the callback. The data gathered included all users, groups, computers, domains, GPO, and subsequent relationships for the entire domain. Because the defenders removed their initial foothold, the red team switched to an assume breach model. Organization B’s TAs (organization IT staff who knew of the assessment and were in contact with the red team) executed a red-team-provided payload on a designated internal host. This host was associated with a standard user account with no administrative privileges, replicating the same level of access the red team would have maintained if Organization B’s defenders had not detected them. Domain Compromise With persistent access to the internal network, the red team searched for ways to escalate their privileges over the domain to facilitate lateral movement and access SBSs. The red team used the assume breach account to query the MAQ attribute of Organization B’s domain and discovered that all domain users were able to add accounts to the domain. The red team created a new machine account with a hostname designed to resemble a legitimate host. The creation of the machine account provided the red team with a domain account and a password that they controlled. This allowed them to execute standalone tools from a red-team-controlled Linux workstation. The tool’s traffic was proxied through the assume breach host, circumventing restrictions imposed by host-based EDR. The red team did not identify any escalation paths from the AD data; however, enumeration of SCCM distribution points led to the discovery of an XML file with cleartext credentials for a domain service account. AD data showed that the newly acquired service account had outbound object control over almost 1,000 accounts within the domain due to its group membership. Most notably, the service account had AllExtendedRights permission over a domain controller, which enabled the team to conduct a resource-based constrained delegation attack, granting them DCSync privileges [T1003.006] and the ability to obtain AD account credentials. The team used these credentials throughout the remainder of their assessment to access servers and workstations. One of the first accounts the red team DCSynced was the krbtgt account, which a malicious cyber actor could use to forge Golden Tickets that allow for impersonation of any user in Organization B’s domain. Post Exploitation Sensitive Business Systems The TAs provided the names of two SBSs, one of which the red team successfully compromised. To do this, the team reviewed previously collected BloodHound data and identified a user account with access to an SBS web server that allowed Kerberos authentication. Because the red team had already compromised the on-premises (on-prem) AD environment, they could impersonate this user to access the server. The team: Used DCSync to acquire the user’s AES256 password hash. Used the password hash to request a Kerberos ticket-granting ticket (TGT) for the user. Used the TGT to request a Kerberos service ticket [T1558] for the web server’s service principal name (SPN). After requesting the Kerberos service ticket, the red team imported it into a Windows virtual machine (VM) on their infrastructure. The red team configured their VM to proxy any traffic to Organization B’s network through a SOCKS proxy that tunneled traffic through a compromised host. Operational Technology Network The red team wanted to gain visibility of the OT network and identify OT network subnets. To do this, they first identified an IT workstation with Remote Desktop Protocol (RDP) files, including a file named ics-[redacted]-org, signifying that the user likely had remote access to the OT network. The red team identified that the workstation had remote access to a bastion host. A bastion host—sometimes referred to as a jump box or jump server—is a specialized, highly secured system (often a server or dedicated workstation) that serves as the sole access point between a network segment (such as an internal IT network) and a protected internal network (like an OT environment). The red team gained access to this bastion host using File Transfer Protocol (FTP) credentials to log in over Secure Shell (SSH) [T1021.004]. At this point, they had visibility over the OT network. They attempted to gain a C2 session on the server by dropping several payload files on the host and executing them. However, the callback never reached red team infrastructure because the host blocked outbound internet connections. The payload execution triggered an alert that led SOC staff to quarantine the host. Microsoft Entra Systems The red team attempted to access Organization B’s cloud-based Entra ID infrastructure to find a way to move from on-prem AD to the cloud. Organization B had a hybrid environment, and user credentials automatically synchronized between on-prem AD and cloud Entra ID. Given this, the red team looked for the on-prem server responsible for synchronization. Entra ID Connect (formerly Azure AD Connect) sets up an on-prem account with the prefix MSOL_ to synchronize credentials with Entra ID. The red team used the open source tool ADConnectDump4 to obtain cleartext credentials for the on-prem Microsoft Online (MSOL) account and the Entra ID account Sync_[redacted] [T1003]. With cleartext credentials for Sync_[redacted], the red team logged into the Azure portal. Sync_[redacted] was not intended for interactive logins and, in this case, did not have multifactor authentication (MFA) enabled. However, the red team used this account to obtain access tokens for use with AzureHound and ROADrecon to gather Entra ID data for Organization B’s tenant. Note: The red team obtained cleartext MSOL credentials and logged into the Azure portal because MSOL accounts used to have a large number of permissions; Microsoft has since removed these permissions. See Microsoft’s Action required: MSOnline and AzureAD PowerShell retirement - 2025 info and resources and Important update: Deprecation of Azure AD PowerShell and MSOnline PowerShell modules for more information. The interactive login from Sync_[redacted] triggered an automated alert from Microsoft, which sent the information to Organization B’s SOC staff, who then blocked the suspicious activity. The red team identified a computer account containing AZURESSO in its name, located in the on-prem AD environment. This account is part of the Seamless SSO implementation and allows users to use Kerberos tickets as the first step in authenticating to Entra ID. To abuse Seamless SSO, the red team acquired encrypted credentials of a target user via DCSync and then used the Rubeus “asktgs” module to request service tickets used for SSO. The red team imported the service tickets to their workstation and proxied their traffic through Organization B’s network using a SOCKS proxy. This allowed them to browse to https://portal[.]azure[.]com, while using legitimate Kerberos tickets, and the traffic appeared to originate from a trusted IP address. This approach allowed the red team to gain access to Entra ID as any user synced to AD without the user’s cleartext password. However, they could only use Kerberos tickets for the first phase of the sign-in process. If a user was set up to use MFA, then Entra ID would prompt the red team for a second factor during the sign-in process. Therefore, the red team was only able to log into any Entra ID account that did not have MFA enabled, which seemed limited to service accounts. They reviewed the previously obtained Entra ID data and looked for applications that had excessive permissions and were accessible to AD-synced service accounts. The red team identified an application that had permission to read, write, and send emails for all users within Organization B’s tenant. The application was owned by an AD-Synced account that was disabled in AD. Using a compromised host in the on-prem environment, they re-enabled this account, DCSynced its credentials, and used the AES256 hash to request Kerberos tickets. The red team used the tickets to authenticate to Entra ID and were then able to add a client secret to the application. This gave them the ability to retrieve the emails of every user within Organization B’s environment from the public internet. Organization B’s Response Organization B quickly triaged and responded to alerts after the red team gained initial access, effectively terminating the team’s C2 communications with the workstations and leading the red team to move to an assume breach model. These actions demonstrated a mature, proactive security posture and helped prevent wider compromise. When the red team gained access to a bastion host in the OT DMZ, Organization B had defensive controls that blocked outbound connections to red team infrastructure, and SOC staff quickly triaged and responded to an alert by isolating the host. When the red team logged into the organization’s Azure portal via a compromised account, it triggered an automated alert from Microsoft, which led the staff to block the suspicious account. In addition, Organization B had custom detections Entra ID Risky User Alerts for “Unfamiliar sign-in properties” and “Suspicious API traffic” that alerted to the AzureHound user agent and to accounts exceeding predefined request thresholds to the Microsoft Graph API. See Table 1 for Organization B’s defensive measures and associated response. Table 1. Red Team Activity and Organization B SOC Response Red Team Activity Defensive Measure SOC Response Outcome C2 payload executed on a workstation. Payload execution generated a medium-severity alert. Staff quarantined workstation; staff analyzed and reimaged before putting workstation back online. Red team lost access to a workstation. C2 payload executed on a second workstation. Payload execution generated a medium-severity alert. Staff quarantined workstation; staff analyzed and reimaged before putting workstation back online. Red team lost access to a workstation. C2 payload executed on a third workstation. Payload execution generated a medium-severity alert. Staff quarantined workstation; staff analyzed and reimaged before putting workstation back online. Red team lost access to a workstation. C2 payload executed on bastion host in the OT DMZ. Payload execution generated alerts. Staff quarantined the host. Red team lost access to the host. Used compromised Entra ID account to log into Azure. Automated alert from Microsoft. Staff blocked the account. Red team compromised a different account and accessed Entra ID by abusing Seamless SSO. Despite these strengths, Organization B had areas for improvement. The red team was eventually able to access Entra ID through a computer account that was part of the organization’s Seamless SSO implementation. The account did not have MFA and had overly permissive application permissions, indicating the need for more mature cloud security processes. Additionally, Organization B had excessive permissions and misconfigurations in AD and service accounts, which the red team leveraged for privilege escalation. This highlights the importance of regular audits and strict enforcement of least privilege principles. Organization B could improve credential hygiene, as the red team found credentials for OT systems stored in plaintext on jump servers. Finally, while segmentation and egress controls were effective, ongoing review and tightening of IT/OT connectivity and access architectures would reduce opportunities for lateral movement. Lessons Learned The red team identified lessons learned based on each organization’s response. Organization A and Organization B contrasted significantly in their ability to quickly identify and respond to red team activity. However, similar gaps in both organizations contributed to the red team’s compromise of their cloud systems. Untuned Detection Tools Lead to Missed Threats Organization A did not tune their detection tools to reduce alert noise, leading to an unmanageable level of alerts for SOC staff to review and action. The same red team activity that triggered alerts and action for Organization B led to no response for Organization A because SOC staff did not identify the activity as potentially malicious amid the overwhelming volume of alerts. Organization B had an established baseline and a fine-tuned alert system, allowing defenders to effectively filter out routine business activity and false positives. As a result, anomalies stood out, enabling the SOC staff to quickly detect and respond to red team activity. Without well-defined baselines and alert filtering, false positives and routine alerts overwhelm defenders, obscuring real threats. Organizations that tune alerts to highlight anomalies and filter out normal business activity enable defenders to focus on genuine incidents and respond rapidly. Organizational Silos and Bureaucratic Hurdles Prevent Effective Incident Response In Organization A, lack of communication and visibility created by organizational silos (among multiple SOCs and between SOC staff and system owners) hindered effective incident response, resulting in missed opportunities for identification of a major breach. Bureaucratic barriers arose because SOC staff managed systems without understanding their authorities as responsibilities and authorities varied across network segments. They had no escalation procedures and so defaulted to a “wait and see” approach. In contrast, Organization B empowered its defenders to act decisively. Staff quickly triaged alerts, investigated root causes, identified misconfigurations, and coordinated remediation with engineering. Detection tools are only as effective as the people, processes, and procedures supporting them. SOC staff should not operate in silos and should have clear authority unhindered by bureaucracy to effectively contain and resolve incidents. Organizations Underestimate Risks in Cloud Environments Both organizations underestimated the risks associated with cloud environments. They granted excessive permissions to cloud applications, allowing the red team to access cloud systems. They also lacked fully mature, defined processes for detecting and remediating compromise of cloud environments, allowing the red team to maintain access to cloud resources. Use of Long-Lived User Identity and Access Management Credentials Organization A used long-lived static IAM user credentials that were set to never expire. If a malicious actor obtains them, they will have all the user permissions, potentially enabling persistent, unrestricted access to the cloud environment. Excessive Permissions Both organizations lacked Conditional Access for workload identities. This feature extends Conditional Access beyond user accounts, covering non-human identities, such as applications. It allows organizations to broadly apply access policies to applications that control how and when the application is used to access resources. Instead, both organizations used broad application permissions for most apps, which the team was able to exploit for access to the environment. In both organizations, the team was able to exploit excessive permissions to read emails. Lack of Mature Remediation Processes for Tokens Both organizations lacked processes for revoking compromised access/refresh tokens. Without a well-defined, efficient process for remediating and revoking access/refresh tokens following a cloud compromise, malicious cyber actors evicted from on-prem environments may still leverage cloud access to regain entry. Organizations should establish mature procedures to detect and remediate compromises of cloud environments to prevent malicious cyber actors from reestablishing access. Issues The red team identified the following issues that contributed to their ability to maintain persistent access to Organization A and/or B and escalate privileges or move laterally: Misconfigured ADCS templates. In Organization A, the red team identified and exploited a certificate template with common template misconfiguration known as ESC1, an overly permissive certificate template where the CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag is enabled and low-privileged users can request certificates. This allows malicious actors to impersonate users. See SpecterOp’s Certified Pre-Owned: Abusing Active Directory Certificate Services for information about the ESC1 misconfiguration. Workstations where MAQ was misconfigured. In Organization A, the team gained access to a workstation where the MAQ was set to the default value of 10. This meant that unprivileged users could add up to 10 computer accounts to the domain. In Organization B, the MAQ was set to 1,000 for all domain users, allowing any user to create a large number of machine accounts. Service accounts with excessive permissions. In Organization B, the red team identified a domain service account with AllExtendedRights permission over a domain controller. AllExtendedRights enables malicious cyber actors to perform DCsync attacks and potentially impersonate any account in the domain, leading to full domain compromise. Cleartext credentials. In Organization A, the red team found and used cleartext credentials to obtain administrative access to SBSs. In Organization B, the red team identified a cleartext password in an XML file for a domain service account. Endpoint management systems that lacked additional security controls. In Organization A, the red team moved laterally from the SCCM server to users’ workstations. SCCM and other endpoint configuration managers (e.g., Jamf, BigFix) have broad administrative reach and are Tier 0 assets. If compromised, Tier 0 assets provide malicious actors with powerful escalation paths and control over the enterprise. The red team identified an additional issue that was not exploited during the assessment but could be exploited by malicious cyber actors: AD misconfigurations and user accounts with excessive permissions. In Organization B, the red team discovered that standard user accounts were improperly assigned to privileged administrative groups within the AD. MITRE ATT&CK Tactics and Techniques See Table 2 to Table 11 for all referenced threat actor tactics and techniques in this advisory. For assistance with mapping malicious cyber activity to the MITRE ATT&CK framework, see CISA and MITRE ATT&CK’s Best Practices for MITRE ATT&CK Mapping and CISA’s Decider Tool. Table 2. Reconnaissance Technique Title ID Use Gather Victim Identity Information: Credentials T1589.001 The red team performed reconnaissance and identified a web application with default credentials. Gather Victim Identity Information: Email Addresses T1589.002 The red team performed reconnaissance and gathered employee email addresses from public websites. Table 3. Resource Development Technique Title ID Use Obtain Capabilities: Tool T1588.002 The red team used publicly available tools, including AzureHound and ROADrecon. Table 4. Initial Access Technique Title ID Use Phishing T1566 The red team gained initial access to four Organization A workstations by sending phishing emails from an internal email address. The red team gained initial access to three Organization B workstations via spearphishing emails that eventually led users to click on a malicious payload. Table 5. Execution Technique Title ID Use User Execution T1204 The red team’s spearphishing emails eventually led to users clicking on a malicious payload. Table 6. Persistence Technique Title ID Use Create Account: Domain Account T1136.002 The red team exploited misconfigured MAQs to create machine accounts on a workstation. Table 7. Credential Access Technique Title ID Use Unsecured Credentials T1552 The red team located cleartext credentials on an administrative user’s workstation. The red team used the open source tool ADConnectDump to obtain cleartext credentials for cloud accounts. Unsecured Credentials: Credentials In Files T1552.001 The red team searched a targeted user’s workstations for connections.json and product-preferences.xml files for a SQL Developer tool. They then decrypted these files to obtain cleartext password to the database. The red team acquired long-lived static AWS IAM user credentials in configuration files in users’ home directories. OS Credential Dumping T1003 The red team obtained cleartext credentials for an on-prem MSOL account and Entra account. OS Credential Dumping: DCSync T1003.006 The red team used DCSync to obtain AD account credentials. Steal or Forge Authentication Certificates T1649 The red team could obtain certificates for any Organization A user account. This provided the means for lateral movement. Steal or Forge Kerberos Tickets T1558 The red team used a Kerberos TGT to request a Kerberos service ticket for a web server’s SPN. The red team used the Rubeus “asktgs” module to request service tickets used for SSO. Table 8. Discovery Technique Title ID Use Account Discovery: Domain Account T1087.002 The red team used a BloodHound collector to query and scrape AD information, including AD users. Remote System Discovery T1018 The red team used a BloodHound collector to query and scrape AD information, including computers. Permission Groups Discovery: Domain Groups T1069.002 The red team used a BloodHound collector to query and scrape AD information, including groups. Group Policy Discovery T1615 The red team used a BloodHound collector to query and scrape AD information, including GPOs. System Owner/User Discovery T1033 The red team queried SCCM servers to enumerate user-device relationships and identify the workstations assigned to users. Cloud Service Discovery T1526 The red team used publicly available tools to obtain a list of Entra applications, their permissions, and their owners. Table 9. Lateral Movement Technique Title ID Use Use Alternate Authentication Material: Application Access Token T1550.001 The red team used an application access token to access and review cloud emails. Remote Services: SSH T1021.004 The red team used FTP credentials to log into a bastion host over SSH. Table 10. Collection Technique Title ID Use Email Collection T1114 The red team reviewed Organization A SOC staff cloud emails to see if SOC staff were aware of the compromise. The red team had the ability to retrieve the emails of every user within Organization B’s environment from the public internet. Screen Capture T1113 The red team took screenshots of SOC staff workstations. Input Capture: Keylogging T1056.001 The red team used keyloggers on SOC staff workstations. Data from Information Repositories: Messaging Applications T1213.005 The red team pulled Microsoft Teams messages from SOC staff workstations. Table 11. Command and Control Technique Title ID Use Proxy: Internal Proxy T1090.001 The red team proxied through compromised workstations. Mitigations CISA recommends that organizations implement the mitigations below to strengthen their cybersecurity posture based on the Lessons Learned and identified Issues. These mitigations align with the Cross-Sector Cybersecurity Performance Goals (CPGs) developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats, tactics, techniques, and procedures. Visit CISA’s CPGs webpage for more information on the CPGs, including additional recommended baseline protections. Establish Baselines and Improve Monitoring Establish and continuously maintain a baseline of installed tools and software, account behavior, and network traffic. Reduce alert noise by refining monitoring tools and alerting mechanisms to differentiate between typical administrative actions and potential threat behavior. For information on establishing a baseline and reducing alert noise, see CISA’s joint Guidance Identifying and Mitigating Living Off the Land Techniques. Eliminate Silos and Bureaucratic Hurdles Break down silos by encouraging regular communication and collaboration between IT, security, and business units. Consider using joint exercises, shared tools, and creating cross-functional teams. Integrate detection with incident response workflows to enable rapid containment and remediation. Empower network defenders. Develop and communicate policies [CPG 1.A, CPG 1.B] that support rapid, coordinated response and clarify when defenders can act independently versus when escalation is required. Define clear roles and responsibilities so defenders know their authorities and escalation paths (if needed) during incidents. Grant defenders the authority to take necessary actions (e.g., isolating systems, blocking traffic) without excessive approvals. Conduct training and simulated incident response exercises to reinforce roles, improve coordination, and identify gaps in authorities or communication [CPG 6.A]. Enhance Cloud Security Controls Note: While both organizations used Microsoft Entra ID and Organization B also used AWS, many of the techniques used by the red team are applicable across identity providers and cloud environments and not necessarily unique to Microsoft and AWS. CISA encourages all organizations using cloud environments to implement the recommendations below. Secure and monitor access/refresh tokens and establish and regularly review comprehensive procedures for detecting, remediating, and revoking access/refresh tokens in the event of a cloud compromise. Implement automated token revocation and access reviews and conduct periodic incident response exercises to validate the effectiveness of these processes. Restrict access based on trusted network locations, device compliance, and risk signals (such as unusual activity or sign-in patterns). Monitor sign-in logs and policy evaluation results for workload identities to detect suspicious activity. Regularly check application permissions; make a risk-informed decision to identify and remove any that are not necessary, so each application only has the access it needs to function. Regularly audit SP credentials and rotate secrets or certificates to reduce exposure. Identify and disable legacy accounts. Enable phishing-resistant MFA for all user, administrative, and privileged accounts in cloud platforms [CPG 3.F]. Protect keys and secrets by storing them securely and enforcing mandatory rotation schedules; apply cryptographic boundary controls to internal and third-party credentials. Set up automated alerts for suspicious cloud application activity, such as abnormal API calls, and credential activity, such as login attempts from unusual locations. Leverage user and entity behavior analytics to analyze and correlate activities across multiple data sources and identify unusual credential or token usage. Continuously audit authentication and access logs for signs of replay or unauthorized access. Implement just-in-time (JIT) access for privileged accounts, replacing standing administrative rights with temporary, time-bound privilege elevations. For organizations using Entra ID: Monitor and control who has access to application identities. Implement CAPs for workload identities and monitor for excessive or unused permissions. Use Microsoft’s app governance to detect and manage risky SPs, which are special accounts used by applications and services. See Microsoft’s OAuth app visibility and insights with app governance - Microsoft Defender for Cloud Apps for more information. Integrate Entra ID tenant monitoring with on-prem security operations to promptly identify suspicious activity. Regularly review and restrict application permissions (e.g., Mail.Read, Files.Read.All). For guidance, see CISA’s Secure Cloud Business Applications (SCuBA) Project, which provides secure configuration baselines for Microsoft 365 (M365), including Microsoft Entra ID. Use CISA’s ScubaGear, a no-cost assessment tool that verifies M365 tenant configuration alignment to the policies described in SCuBA’s secure configuration baselines. Use certificate-based authentication certificates for application authentication instead of client secrets, when possible. See Microsoft’s Set Up Microsoft Entra CBA - Microsoft Entra ID. Review newly created secrets and/or certificates on existing applications. Limit secret lifetimes to a reasonable lifetime. In AWS environments: Mitigate the risks of long-lived IAM user credentials. Identify and audit all existing access keys and disable/delete unused or unnecessary keys. Require human users to use temporary AWS credentials through SSO. Users will assume an IAM role for AWS access and receive temporary credentials that expire within an hour. For more information on accessing AWS using temporary credentials, see Amazon’s documentation Security best practices in IAM and Compare IAM identities and credentials. Regularly review the environment to verify no long-lived credentials remain. Secure Active Directory and Manage Credentials Apply secure configurations to ADCS implementations. Disable the CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag from templates to prevent users from supplying and editing sensitive security settings within these templates. Restrict accounts that can enroll in all certificate templates to only those necessary, especially templates with the CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag. Remove FullControl, WriteDacl, and Write property permissions from low-privileged groups, such as domain users, to certificate template objects, where such permissions are not needed. Enforce manager approval for requested certificates. Apply additional guidance from CISA’s joint Guidance Detecting and Mitigating Active Directory Compromises (see Mitigating AD CS compromise, pages 15–16). Configure the MAQ to zero unless there is a specific operational need for non-administrative users to create computer accounts; this prevents standard user accounts from creating new machine accounts, reducing opportunities for malicious cyber actors to abuse this privilege. If some standard user accounts need to create computer accounts, set MAQ to the lowest possible value and restrict this capability to only users or groups with a business justification. Improve credential hygiene. Scan network shares and workstations for plaintext credentials and remove any found. Train staff on secure password storage practices and enforce policies prohibiting plaintext password storage. Use encrypted password vaults for storing credentials and limit access to only those who require it. Periodically audit credential stores and access logs for signs of misuse. Periodically audit AD permissions for misconfigurations and excessively privileged groups and accounts. Implement the principle of least privilege [CPG 3.H]. Grant standard user rights for standard user tasks such as email, web browsing, and using line-of-business applications. Periodically audit standard user accounts and minimize privileged access. Periodically audit AD permissions to verify that standard user accounts do not have excessive permissions and have not been added to admin groups. Evaluate which administrative groups should administer specific servers and workstations. Separate administrator accounts from standard user accounts [CPG 3.G]. Use designated workstations for administrators and standard users and prevent administrators from using admin workstations for non-admin purposes; this would reduce impact of credential theft from a user workstation. Use designated administrative accounts exclusively for admin purposes. If a standard user account needs administrative rights over their workstation, use a separate account that does not have administrative access to other hosts, such as servers. Consider using a privileged access management (PAM) solution to manage access to privileged accounts and resources. PAM solutions can log and alert usage to detect unusual activity, which could have alerted the assessed organizations when the red team accessed resources with admin accounts. Note: Treat password vaults associated with PAM solutions as high value assets (HVAs) with additional restrictions and monitoring. Configure time-based access for accounts set at the admin level and higher. The just-in-time access method provisions privileged access when needed and can support enforcement of the principle of least privilege, as well as the zero trust model. A network-wide policy automatically disables administrator accounts at the AD level when the account is not needed. When standard user accounts need administrative access, they submit their requests through an automated process that enables access to a system, but only for a set timeframe to support task completion. Secure Endpoint Configuration Managers Treat endpoint management systems (such as SCCM) as HVAs with additional restrictions and monitoring because they provide elevated access to thousands of hosts. Segment Operational Technology Networks Implement strict firewall rules and access controls between IT and OT environments [CPG 3.I]. Limit jump server access to OT networks and require MFA for all connections. Regularly review OT network architecture and access paths to minimize unnecessary connectivity. Monitor OT network traffic for signs of lateral movement or unauthorized access. Implement change management solutions to track and restrict modifications to OT components. Validate Security Controls In addition to applying mitigations, CISA recommends exercising, testing, and validating your organization's security program against the threat behaviors mapped to the MITRE ATT&CK Matrix for Enterprise framework in this advisory. CISA recommends testing your existing security controls inventory to assess how they perform against the ATT&CK techniques described in this advisory. To get started: Select an ATT&CK technique described in this advisory (see Table 2 to Table 11). Align your security technologies against the technique. Test your technologies against the technique. Analyze your detection and prevention technologies’ performance. Repeat the process for all security technologies to obtain a set of comprehensive performance data. Tune your security program, including people, processes, and technologies, based on the data generated by this process. CISA recommends continually testing your security program, at scale, in a production environment to ensure optimal performance against the MITRE ATT&CK techniques identified in this advisory. Resources Microsoft: Understanding primary refresh token (PRT) SpecterOps: Certified pre-owned: Abusing Active Directory Certificate Services Contact Information Organizations are encouraged to report suspicious or criminal activity related to information in this advisory to CISA via CISA’s 24/7 Operations Center at contact@cisa.dhs.gov or 1-844-Say-CISA (1-844-729-2472). When available, please include the following information regarding the incident: Date, time, and location of the incident; Type of activity; Number of people affected; Type of equipment used for the activity; and Name of the submitting company or organization, and a designated point of contact. Disclaimer The information in this report is being provided “as is” for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA. Version History August 25, 2026: Initial version. Notes 1 “SpecterOps / Bloodhound,” GitHub, last modified July 15, 2026, https://github.com/SpecterOps/BloodHound. 2 “SpecterOps / AzureHound,” GitHub, last modified June 4, 2026, https://github.com/SpecterOps/AzureHound. 3 “ROADrecon,” GitHub, https://github.com/dirkjanm/ROADtools/tree/master/roadrecon. 4 “dirkjanm/adconnectdumb,” GitHub, last modified August 25, 2026, https://github.com/dirkjanm/adconnectdump.
· CISA Cybersecurity Advisory

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-60004 Gitea Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes…
Read full source summary
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-60004 Gitea Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
· CISA Cybersecurity Advisory

Zoneminder

View CSAF Summary Successful exploitation of this vulnerability could result in full Remote Code Execution (RCE) as the web server user. The following versions of Zoneminder are affected: Zoneminder 1.37.48|1.38.3 CVSS Vendor Equipment Vulnerabilities v3 8.8 Zoneminder Zoneminder Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Background Critical Infrastructure Sectors:…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could result in full Remote Code Execution (RCE) as the web server user. The following versions of Zoneminder are affected: Zoneminder 1.37.48|1.38.3 CVSS Vendor Equipment Vulnerabilities v3 8.8 Zoneminder Zoneminder Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Background Critical Infrastructure Sectors: Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-76060 An authenticated OS Command Injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server. View CVE Details Affected Products Zoneminder Vendor: Zoneminder Product Version: Zoneminder Zoneminder: 1.37.48|1.38.3 Product Status: known_affected Remediations Vendor fix Zoneminder recommends upgrading to version 1.38.3 or later by downloading the installer for your system at: https://zoneminder.com/downloads. https://zoneminder.com/downloads Vendor fix Users may also get the source code from Zoneminder's Github: https://github.com/ZoneMinder/zoneminder. https://github.com/ZoneMinder/zoneminder Vendor fix For more details refer to Zoneminder's security advisories at: https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-88m4-hrgp-m9v3. https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-88m4-hrgp-m9v3 Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments CISA discovered a public Proof of Concept (PoC) as authored by Scriptkittens and reported it to Zoneminder Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-08-25 Date Revision Summary 2026-08-25 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Siemens SIMATIC IoT2050 Advanced

View CSAF Summary SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released a new version for SIMATIC IoT2050 Advanced and strongly recommends…
Read full source summary
View CSAF Summary SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released a new version for SIMATIC IoT2050 Advanced and strongly recommends to update to the latest version. The following versions of Siemens SIMATIC IoT2050 Advanced are affected: SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) vers:intdot/<4.3.4.1 CVSS Vendor Equipment Vulnerabilities v3 10 Siemens Siemens SIMATIC IoT2050 Advanced Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-58115 Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges. View CVE Details Affected Products Siemens SIMATIC IoT2050 Advanced Vendor: Siemens Product Version: SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) < V4.3.4.1 running Industrial OS with Node-RED installed Product Status: known_affected Remediations Mitigation Harden the Node-RED installation (see Node-RED User Guide) Mitigation Uninstall Node-RED Vendor fix Update to V4.3.4.1 or later version https://support.industry.siemens.com/cs/ww/en/view/109741799/ Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 10 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Acknowledgments Siemens ProductCERT reported this vulnerability to CISA. General Recommendations As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity Additional Resources For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories Terms of Use The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Siemens ProductCERT SSA-834709 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory. Revision History Initial Release Date: 2026-08-11 Date Revision Summary 2026-08-11 1 Publication Date 2026-08-25 2 Initial CISA Republication of Siemens ProductCERT SSA-834709 advisory Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

FURUNO FA-50 Class B AIS Transponder

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to alter device settings. The following versions of FURUNO FA-50 Class B AIS Transponder are affected: FURUNO FA-50 Class B AIS Transponder vers:all/* CVSS Vendor Equipment Vulnerabilities v3 9.1 FURUNO ELECTRIC CO.,LTD. FURUNO FA-50 Class B AIS Transponder Use of Hard-coded Credentials, Missing Authentication for Critical…
Read full source summary
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to alter device settings. The following versions of FURUNO FA-50 Class B AIS Transponder are affected: FURUNO FA-50 Class B AIS Transponder vers:all/* CVSS Vendor Equipment Vulnerabilities v3 9.1 FURUNO ELECTRIC CO.,LTD. FURUNO FA-50 Class B AIS Transponder Use of Hard-coded Credentials, Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Japan Vulnerabilities Expand All + CVE-2026-59769 An attacker, who knows the credentials and has access to the in-vessel network to which the device is connected to, may operate the settings screen using that credentials to alter the settings of the device. View CVE Details Affected Products FURUNO FA-50 Class B AIS Transponder Vendor: FURUNO ELECTRIC CO.,LTD. Product Version: FURUNO FA-50 Class B AIS Transponder: vers:all/* Product Status: known_affected Remediations Mitigation FURUNO ELECTRIC CO.,LTD. notes that production of this product ended in October 2020, and software updates will no longer be provided. FURUNO recommends users do not connect the product directly to the internet. To prevent unauthorized access, the vessel on which the product is installed should be properly locked and managed. Relevant CWE: CWE-798 Use of Hard-coded Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.1 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H 4.0 8.8 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-67578 Some configurations may be changed on the management screen without authentication. View CVE Details Affected Products FURUNO FA-50 Class B AIS Transponder Vendor: FURUNO ELECTRIC CO.,LTD. Product Version: FURUNO FA-50 Class B AIS Transponder: vers:all/* Product Status: known_affected Remediations Mitigation FURUNO ELECTRIC CO.,LTD. notes that production of this product ended in October 2020, and software updates will no longer be provided. FURUNO recommends users do not connect the product directly to the internet. To prevent unauthorized access, the vessel on which the product is installed should be properly locked and managed. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N Acknowledgments Souvik Kandar reported these vulnerabilities to CISA JPCERT/CC coordinated with Furuno Electric and CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-08-25 Date Revision Summary 2026-08-25 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Bendix EC80 Brake ECU

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause the loss of ABS functions, steering assist, speedometer, shifting capabilities, or disable automatic traction control. The following versions of Bendix EC80 Brake ECU are affected: EC80ESP+ J1708 Z228999 EC80ESP+ 6S/6M Z228999 EC80ESP+ PLC Z228999 EC80ESP+ 2nd CAN Z228999 EC80ESP+ Integrated TPMS Z228999 EC80ESP 6S/6M…
Read full source summary
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause the loss of ABS functions, steering assist, speedometer, shifting capabilities, or disable automatic traction control. The following versions of Bendix EC80 Brake ECU are affected: EC80ESP+ J1708 Z228999 EC80ESP+ 6S/6M Z228999 EC80ESP+ PLC Z228999 EC80ESP+ 2nd CAN Z228999 EC80ESP+ Integrated TPMS Z228999 EC80ESP 6S/6M Z266494 EC80ESP PLC Z266494 EC80ESP 2nd CAN Z266494 EC80ESP CAN Gateway Z266494 EC80ESP 4S/4M Z286098 EC80ESP PLC Z286098 CVSS Vendor Equipment Vulnerabilities v3 7.5 Bendix Bendix EC80 Brake ECU Stack-based Buffer Overflow, Out-of-bounds Write, Use of Hard-coded Credentials Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: United States, Canada Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-67560 The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering assist, speedometer, and shifting. View CVE Details Affected Products Bendix EC80 Brake ECU Vendor: Bendix Product Version: Bendix EC80ESP+ J1708: Z228999, Bendix EC80ESP+ 6S/6M: Z228999, Bendix EC80ESP+ PLC: Z228999, Bendix EC80ESP+ 2nd CAN: Z228999, Bendix EC80ESP+ Integrated TPMS: Z228999, Bendix EC80ESP 6S/6M: Z266494, Bendix EC80ESP PLC: Z266494, Bendix EC80ESP 2nd CAN: Z266494, Bendix EC80ESP CAN Gateway: Z266494, Bendix EC80ESP 4S/4M: Z286098, Bendix EC80ESP PLC: Z286098 Product Status: known_affected Remediations Mitigation Bendix recommends users update their firmware to the most recent firmware version releases. Users that need more help should contact Bendix directly at info@Bendix.com. mailto:info@Bendix.com Vendor fix EC80ESP+ J1708: Z228999 users should update their firmware to version Z300822. Vendor fix EC80ESP+ 6S/6M: Z228999 users should update their firmware to version Z300822. Vendor fix EC80ESP+ PLC: Z228999 users should update their firmware to version Z300822. Vendor fix EC80ESP+ 2nd CAN: Z228999 users should update their firmware to version Z300822. Vendor fix EC80ESP+ Integrated TPMS: Z228999 users should update their firmware to version Z300822. Vendor fix EC80ESP 6S/6M: Z266494 users should update their firmware to version Z302578. Vendor fix EC80ESP PLC: Z266494 users should update their firmware to version Z302578. Vendor fix EC80ESP 2nd CAN: Z266494 users should update their firmware to version Z302578. Vendor fix EC80ESP CAN Gateway: Z266494 users should update their firmware to version Z302578. Vendor fix EC80ESP 4S/4M: Z286098 users should update their firmware to version Z302579. Vendor fix EC80ESP PLC: Z286098 users should update their firmware to version Z302579. Relevant CWE: CWE-121 Stack-based Buffer Overflow Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 7.7 HIGH CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-68967 The affected product is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that could establish an arbitrary write primitive, which could crash the ECU. View CVE Details Affected Products Bendix EC80 Brake ECU Vendor: Bendix Product Version: Bendix EC80ESP+ J1708: Z228999, Bendix EC80ESP+ 6S/6M: Z228999, Bendix EC80ESP+ PLC: Z228999, Bendix EC80ESP+ 2nd CAN: Z228999, Bendix EC80ESP+ Integrated TPMS: Z228999, Bendix EC80ESP 6S/6M: Z266494, Bendix EC80ESP PLC: Z266494, Bendix EC80ESP 2nd CAN: Z266494, Bendix EC80ESP CAN Gateway: Z266494, Bendix EC80ESP 4S/4M: Z286098, Bendix EC80ESP PLC: Z286098 Product Status: known_affected Remediations Mitigation Bendix recommends users update their firmware to the most recent firmware version releases. Users that need more help should contact Bendix directly at info@Bendix.com. mailto:info@Bendix.com Vendor fix EC80ESP+ J1708: Z228999 users should update their firmware to version Z300822. Vendor fix EC80ESP+ 6S/6M: Z228999 users should update their firmware to version Z300822. Vendor fix EC80ESP+ PLC: Z228999 users should update their firmware to version Z300822. Vendor fix EC80ESP+ 2nd CAN: Z228999 users should update their firmware to version Z300822. Vendor fix EC80ESP+ Integrated TPMS: Z228999 users should update their firmware to version Z300822. Vendor fix EC80ESP 6S/6M: Z266494 users should update their firmware to version Z302578. Vendor fix EC80ESP PLC: Z266494 users should update their firmware to version Z302578. Vendor fix EC80ESP 2nd CAN: Z266494 users should update their firmware to version Z302578. Vendor fix EC80ESP CAN Gateway: Z266494 users should update their firmware to version Z302578. Vendor fix EC80ESP 4S/4M: Z286098 users should update their firmware to version Z302579. Vendor fix EC80ESP PLC: Z286098 users should update their firmware to version Z302579. Relevant CWE: CWE-787 Out-of-bounds Write Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N 4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-71396 The affected product uses hard-coded credentials, which could allow an attacker to disable automatic traction control. View CVE Details Affected Products Bendix EC80 Brake ECU Vendor: Bendix Product Version: Bendix EC80ESP+ J1708: Z228999, Bendix EC80ESP+ 6S/6M: Z228999, Bendix EC80ESP+ PLC: Z228999, Bendix EC80ESP+ 2nd CAN: Z228999, Bendix EC80ESP+ Integrated TPMS: Z228999, Bendix EC80ESP 6S/6M: Z266494, Bendix EC80ESP PLC: Z266494, Bendix EC80ESP 2nd CAN: Z266494, Bendix EC80ESP CAN Gateway: Z266494, Bendix EC80ESP 4S/4M: Z286098, Bendix EC80ESP PLC: Z286098 Product Status: known_affected Remediations Mitigation Bendix recommends users update their firmware to the most recent firmware version releases. Users that need more help should contact Bendix directly at info@Bendix.com. mailto:info@Bendix.com Vendor fix EC80ESP+ J1708: Z228999 users should update their firmware to version Z300822. Vendor fix EC80ESP+ 6S/6M: Z228999 users should update their firmware to version Z300822. Vendor fix EC80ESP+ PLC: Z228999 users should update their firmware to version Z300822. Vendor fix EC80ESP+ 2nd CAN: Z228999 users should update their firmware to version Z300822. Vendor fix EC80ESP+ Integrated TPMS: Z228999 users should update their firmware to version Z300822. Vendor fix EC80ESP 6S/6M: Z266494 users should update their firmware to version Z302578. Vendor fix EC80ESP PLC: Z266494 users should update their firmware to version Z302578. Vendor fix EC80ESP 2nd CAN: Z266494 users should update their firmware to version Z302578. Vendor fix EC80ESP CAN Gateway: Z266494 users should update their firmware to version Z302578. Vendor fix EC80ESP 4S/4M: Z286098 users should update their firmware to version Z302579. Vendor fix EC80ESP PLC: Z286098 users should update their firmware to version Z302579. Relevant CWE: CWE-798 Use of Hard-coded Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.4 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L 4.0 5.3 MEDIUM CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N Acknowledgments Ben Gardiner of NMFTA reported these vulnerabilities to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-08-25 Date Revision Summary 2026-08-25 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Ebyte NE2-D11

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized administrative access, disclose sensitive information, modify device configuration, hijack authenticated sessions, and disrupt device operation. The following versions of Ebyte NE2-D11 are affected: NE2-D11 Firmware FW-9167-0-11 CVSS Vendor Equipment Vulnerabilities v3 9.8 Ebyte Ebyte NE2-D11 Missing…
Read full source summary
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized administrative access, disclose sensitive information, modify device configuration, hijack authenticated sessions, and disrupt device operation. The following versions of Ebyte NE2-D11 are affected: NE2-D11 Firmware FW-9167-0-11 CVSS Vendor Equipment Vulnerabilities v3 9.8 Ebyte Ebyte NE2-D11 Missing Authentication for Critical Function, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials, Use of Client-Side Authentication, Use of GET Request Method With Sensitive Query Strings, Cross-Site Request Forgery (CSRF), Improper Restriction of Excessive Authentication Attempts, Improper Restriction of Rendered UI Layers or Frames, Missing Authorization Background Critical Infrastructure Sectors: Critical Manufacturing, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-73125 Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability. View CVE Details Affected Products Ebyte NE2-D11 Vendor: Ebyte Product Version: Ebyte NE2-D11 Firmware: FW-9167-0-11 Product Status: known_affected Remediations Mitigation Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-73809 A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web management interface does not adequately protect sensitive communications using transport-layer encryption. An attacker with access to network traffic could intercept authentication or session-related information transmitted between a user and the affected device. Successful exploitation could result in disclosure of sensitive information and unauthorized access to device management functionality. View CVE Details Affected Products Ebyte NE2-D11 Vendor: Ebyte Product Version: Ebyte NE2-D11 Firmware: FW-9167-0-11 Product Status: known_affected Remediations Mitigation Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information. Relevant CWE: CWE-319 Cleartext Transmission of Sensitive Information Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-73839 Administrative credentials may be exposed in plaintext within the Ebyte device's management interface, increasing the risk of credential compromise through visual or remote observation. This undermines the confidentiality of device access. View CVE Details Affected Products Ebyte NE2-D11 Vendor: Ebyte Product Version: Ebyte NE2-D11 Firmware: FW-9167-0-11 Product Status: known_affected Remediations Mitigation Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information. Relevant CWE: CWE-522 Insufficiently Protected Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 4.6 MEDIUM CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 5.1 MEDIUM CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-71187 Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtain administrative access to the device. View CVE Details Affected Products Ebyte NE2-D11 Vendor: Ebyte Product Version: Ebyte NE2-D11 Firmware: FW-9167-0-11 Product Status: known_affected Remediations Mitigation Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information. Relevant CWE: CWE-603 Use of Client-Side Authentication Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-76179 An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during client-side session handling, which may allow an attacker with access to exposed session information to obtain and reuse a valid token. Successful exploitation could allow an attacker to impersonate an authenticated user and gain unauthorized access to device management functionality. View CVE Details Affected Products Ebyte NE2-D11 Vendor: Ebyte Product Version: Ebyte NE2-D11 Firmware: FW-9167-0-11 Product Status: known_affected Remediations Mitigation Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information. Relevant CWE: CWE-598 Use of GET Request Method With Sensitive Query Strings Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-75814 Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management interface. An unauthenticated remote attacker could persuade an authenticated administrator to visit a crafted page, causing unauthorized configuration changes or a disruption of device availability. View CVE Details Affected Products Ebyte NE2-D11 Vendor: Ebyte Product Version: Ebyte NE2-D11 Firmware: FW-9167-0-11 Product Status: known_affected Remediations Mitigation Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information. Relevant CWE: CWE-352 Cross-Site Request Forgery (CSRF) Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 4.0 8.6 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-76940 The affected Ebyte device does not restrict repeated authentication attempts through rate limiting or account lockout mechanisms. This could allow an attacker to perform automated authentication attacks against deployments that rely on password based authentication. View CVE Details Affected Products Ebyte NE2-D11 Vendor: Ebyte Product Version: Ebyte NE2-D11 Firmware: FW-9167-0-11 Product Status: known_affected Remediations Mitigation Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information. Relevant CWE: CWE-307 Improper Restriction of Excessive Authentication Attempts Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-75548 The affected Ebyte device web management interface does not restrict the interface from being rendered within an external frame. An unauthenticated remote attacker could use a crafted webpage to mislead an authenticated administrator into initiating unintended configuration changes or disruptive actions. View CVE Details Affected Products Ebyte NE2-D11 Vendor: Ebyte Product Version: Ebyte NE2-D11 Firmware: FW-9167-0-11 Product Status: known_affected Remediations Mitigation Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information. Relevant CWE: CWE-1021 Improper Restriction of Rendered UI Layers or Frames Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N 4.0 5.3 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVE-2026-75813 Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthorized users to access or modify sensitive device settings. This could result in full compromise of device functionality. View CVE Details Affected Products Ebyte NE2-D11 Vendor: Ebyte Product Version: Ebyte NE2-D11 Firmware: FW-9167-0-11 Product Status: known_affected Remediations Mitigation Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information. Relevant CWE: CWE-862 Missing Authorization Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-76945 The affected Ebyte device relies on client-managed authentication tokens without sufficient server-side validation. An attacker may replay or manipulate authentication tokens to gain unauthorized access to administrative functionality. View CVE Details Affected Products Ebyte NE2-D11 Vendor: Ebyte Product Version: Ebyte NE2-D11 Firmware: FW-9167-0-11 Product Status: known_affected Remediations Mitigation Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information. Relevant CWE: CWE-603 Use of Client-Side Authentication Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-69658 MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device impersonation and disruption of messaging functions. View CVE Details Affected Products Ebyte NE2-D11 Vendor: Ebyte Product Version: Ebyte NE2-D11 Firmware: FW-9167-0-11 Product Status: known_affected Remediations Mitigation Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information. Relevant CWE: CWE-319 Cleartext Transmission of Sensitive Information Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments Jithin Nambiar reported these vulnerabilities to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-08-25 Date Revision Summary 2026-08-25 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-21962 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD)…
Read full source summary
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-21962 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
· CISA Cybersecurity Advisory

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-73570 Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security…
Read full source summary
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-73570 Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
· CISA Cybersecurity Advisory

Johnson Controls Simplex Incident Manager

View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems. The following versions of Johnson Controls Simplex Incident Manager are affected: Simplex Incident Manager <=V2.01 (CVE-2026-27875)…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems. The following versions of Johnson Controls Simplex Incident Manager are affected: Simplex Incident Manager <=V2.01 (CVE-2026-27875) CVSS Vendor Equipment Vulnerabilities v3 5.8 Johnson Controls Inc. Johnson Controls Simplex Incident Manager Cleartext Storage of Sensitive Information in Memory Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-27875 The Simplex Incident Manager application stores user credentials (such as passwords and authentication tokens) in an unencrypted form within system memory while running. This exposes sensitive information to potential extraction by anyone with local access to the system, including attackers leveraging memory-dumping tools or insiders with elevated privileges. View CVE Details Affected Products Johnson Controls Simplex Incident Manager Vendor: Johnson Controls Inc. Product Version: Johnson Controls Simplex Incident Manager: <=V2.01 Product Status: known_affected Remediations Mitigation Johnson Controls has released a patched version (v2.01.01) to address this vulnerability. To help reduce the risk of exploitation, Johnson Controls suggests considering the following defensive measures: Upgrade the Simplex Incident Manager to version v1.01.05 or later. Restrict local access to systems running the Simplex Incident Manager to authorized personnel only. Implement endpoint protection and monitoring to detect memory-dumping tools or suspicious processes. Enforce strong access control policies and the principle of least privilege on host systems. Utilize full-disk encryption and secure boot to reduce the risk of offline memory analysis. Monitor for unauthorized local access attempts and implement audit logging. Mitigation For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-28. https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories Mitigation Aligning with CISA recommendations, Johnson Controls recommends taking steps to minimize risks to all building automation systems. Relevant CWE: CWE-316 Cleartext Storage of Sensitive Information in Memory Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.8 MEDIUM CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L 4.0 5.8 MEDIUM CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N Acknowledgments Johnson Controls reported this vulnerability to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely. This vulnerability has a high attack complexity. Revision History Initial Release Date: 2026-08-20 Date Revision Summary 2026-08-20 1 Initial Republication of Johnson Controls Product Security Advisory JCI-PSA-2026-28 Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability CVE-2026-72530 TrueConf Server Code Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal…
Read full source summary
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability CVE-2026-72530 TrueConf Server Code Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
· CISA Cybersecurity Advisory

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-64849 MLflow Server-Side Request Forgery Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on…
Read full source summary
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-64849 MLflow Server-Side Request Forgery Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
· CISA Cybersecurity Advisory

Defending Against an Active Threat to Siemens S7 Series PLCs

Executive summary Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider…
Read full source summary
Executive summary Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape. Top Mitigations Inventory all Siemens S7 Series programmable logic controllers (PLCs) Apply critical security patches Ensure PLCs are not accessible from the Internet Strengthen access controls Monitor for unauthorized activity Harden PLC services, protocols, and ladder logic integrity Hunt for anomalies that may indicate a compromise The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA)—hereafter referred to as the authoring agencies—are releasing this Cybersecurity Advisory to warn owners and operators of industrial control systems (ICSs) of an active cyber threat to Siemens S7 Series PLCs and provide relevant mitigations to protect and defend them. The threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools. The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected. The U.S. critical infrastructure sectors most targeted by this threat activity include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. This is not a theoretical risk—it is an active threat. Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems. The authoring agencies urge all owners and operators of operational technology (OT) systems using Siemens S7 Series and other PLC devices to proactively check their systems: are properly protected with all applicable security patches and updates, are isolated from the Internet wherever possible, have strong access controls, and employ security tooling to monitor ICS environments for anomalous or malicious activity. These mitigations are particularly important for owners and operators who work with third-party service providers or system integrators who may have remote access to PLCs, as the asset owners may not realize that their systems are exposed and at risk. Technical details Note: This advisory uses the MITRE ATT&CK® Matrix for ICS1 framework, version 19, and the MITRE ATT&CK Matrix for Enterprise framework, version 19. This advisory also uses MITRE D3FENDTM, version 1.5.0. See Appendix A and Appendix B for tables of the activity mapped to MITRE ATT&CK and MITRE D3FEND tactics, techniques, and countermeasures. Threat actor targeting Threat actors are actively targeting the following Siemens PLC models: S7-200 Series (all CPU variants) S7-300 Series (all CPU variants including 314, 315, 317 models) S7-400 Series (all CPU variants) S7-1200 Series (CPU 1211C, 1212C, 1214C, 1215C, 1217C variants) S7-1500 Series (all CPU variants, including F-series safety controllers) Threat actors are using AI assistance to generate exploitation scripts using publicly available information on these Siemens S7 Series PLCs for initial access, credential access, denial of service, and other objectives. If these PLCs are exposed to the Internet or insufficiently segmented, then threat actors can exploit various critical and high severity known vulnerabilities in these PLCs. Note: Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools. In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures. Threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploitable PLCs, and use AI-generated scripts to act on that information. If PLCs are exposed to the Internet, they are at high risk for exploitation. Threat actors are leveraging open source industrial automation libraries—specifically snap7.dll/python-snap7—combined with AI-assisted scripting to create custom tools that mimic legitimate OT monitoring solutions. These tools provide read/write access to Siemens S7 Series PLC memory, configuration data, and ladder logic programs via the S7comm protocol. Threat actor techniques Threat actors are: Using Internet scanning services (e.g., Censys, ZoomEye) to identify Internet-exposed or insufficiently segmented Siemens S7 Series PLCs [T1596.005] Rapidly iterating exploit code through AI-assisted development, lowering technical barriers to ICS attacks [T1587.004, T1588.007] Taking advantage of insecure credentials to access exposed devices that have unconfigured (default) or minimally configured authentication [T1694] Deploying AI-generated Python scripts that incorporate the snap7.dll library from public repositories [T0834] to gain read/write access to the PLC and mimic legitimate tools Masquerading malicious scripts as legitimate monitoring tools to evade detection by security teams [T0849] Conducting read/write operations on data blocks, potentially for reconnaissance, capability testing, or pre-positioning for effects operations [T0893, T0821] The authoring agencies assess this activity pattern is likely intended as persistent reconnaissance in targeted sectors and facilities to develop capabilities and prepare to cause operational effects against critical infrastructure. For capability development, actors are testing and refining their exploitation techniques against specific PLC models to improve their ability to compromise the PLCs. To prepare for operational effects, actors are leveraging read access to understand target environments, enabling preparation and positioning for future write operations to cause disruption or other operational impacts. Potential operational impacts The U.S. critical infrastructure sectors most targeted by this threat activity include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. Additionally, Siemens S7 Series PLCs are used in other sectors, including the Defense Industrial Base (DIB), and could be targeted there as well. Unauthorized access to PLCs could result in: Disruption of critical industrial processes affecting production throughput, product quality, and public services Safety incidents affecting personnel through manipulation of safety interlocks, emergency shutdown systems, or process parameters Equipment damage and extended operational downtime from process upsets, improper sequencing, or forced equipment operation outside design parameters Compromise of sensitive operational data, including proprietary process recipes, control strategies, and facility configurations Cascading impacts across interconnected systems affecting supply chains, dependent facilities, and integrated business operations Regulatory compliance violations and potential liability from process safety management failures Mitigation actions Since threat actors are developing capabilities using AI to compromise PLCs using known vulnerabilities, misconfigurations, and other weaknesses and then may use compromised PLCs to interfere with normal operations, the authoring agencies urge organizations to implement comprehensive defense-in-depth strategies, in addition to Common Vulnerabilities and Exposures (CVE) remediation, to protect and defend their PLCs. Detection opportunities Organizations should implement detection strategies and hunt for anomalies that may indicate a compromise, focusing on [D3-PM]: Anomalous S7comm behavior: Connections from non-engineering workstations, unusual data block access patterns, or write operations outside change windows Reconnaissance indicators: Sequential IP scanning on port 102, repeated connection attempts with varying parameters, or enumeration of CPU properties Tool artifacts: Snap7.dll library usage outside approved engineering workstations, Python scripts with S7comm functionality, or unauthorized monitoring software installations Temporal anomalies: S7comm activity during off-hours, unexpected connection patterns consistent with automated scripting rather than human operators, or configuration changes without corresponding work orders or change tickets Geographic anomalies: Connections originating from unexpected countries or IP ranges not associated with vendors or integrators Preventative hardening actions To counter threats to PLCs, the authoring agencies recommend all PLC owners and operators follow the mitigations in joint guidance Primary Mitigations to Reduce Cyber Threats to Operational Technology. To harden Siemens S7 Series PLCs, the authoring agencies strongly urge all owners implement the hardening steps below. Entities that rely on systems integrators or third-party managed service providers should share this advisory with those parties and request implementation of the following mitigations: 1. Conduct an immediate inventory of all Siemens S7 Series PLCs in your environment [D3-HCI]: Verify current firmware versions for all S7-200, S7-300, S7-400, S7-1200, and S7-1500 controllers against backup gold copy Identify any systems directly or indirectly accessible from untrusted networks Map all engineering workstations with Totally Integrated Automation (TIA) Portal, STEP 7, or S7 programming access 2. Apply critical security patches as soon as possible [D3-SU]: Update Siemens S7 Series PLC firmware to the latest versions that address known vulnerabilities Prioritize Internet-facing or demilitarized zone (DMZ)-resident controllers Update TIA Portal and STEP 7 software to current versions Consult Siemens ProductCERT advisories for information on known vulnerabilities, along with relevant workarounds and mitigations Test all updates in a development environment before production deployment 3. Verify network segmentation and ensure PLCs are NOT accessible from the Internet [D3-NI]: Audit firewall rules for any exposed S7comm services (Transmission Control Protocol [TCP] port 102) Block TCP port 102 at perimeter firewalls entirely Implement a DMZ architecture that separates OT and IT networks Deploy unidirectional gateways for data historian connections where appropriate Verify there is no unauthorized routing between corporate and industrial networks 4. Review and strengthen access controls [D3-NAM, D3-CH]: Restrict TIA Portal/STEP 7 access to authorized engineering workstations only by MAC/IP allowlisting on PLCs Enable PLC password protection on all Siemens S7 Series controllers Configure protection levels (such as write protection and read/write protection) on Siemens S7 Series devices Remove or change default SNMP community strings Implement application allowlisting on all engineering workstations Enable multi-factor authentication for all remote access to OT networks 5. Enable comprehensive logging and monitoring [D3-PM, D3-NTA]: Deploy ICS-aware intrusion detection (e.g., Claroty, Dragos Platform, Nozomi Networks, or similar) Monitor all S7comm traffic on TCP port 102 for connections outside maintenance windows Alert on unauthorized PUT/GET operations, especially write commands to data blocks or configuration areas of memory Log all TIA Portal/STEP 7 connections to PLCs with timestamps and source IPs Establish a baseline for legitimate behavior and configure monitoring tools to alert on deviations Monitor for Python processes with snap7.dll library imports on engineering workstations Watch for sequential IP scanning patterns or block reads of configuration data 6. Implement S7-specific hardening measures [D3-ACH]: Disable web servers on Siemens S7 Series devices if not operationally required Disable unused communication protocols (such as Modbus TCP and PROFINET, if they are not required) Configure connection resources to limit simultaneous S7comm sessions Enable TIA Portal/STEP 7 “complete restart protection” and “know-how protection” features where available Evaluate for ladder logic changes in online/offline modes 7. Contact Siemens for model-specific guidance: Engage Siemens Technical Support for hardening recommendations specific to your CPU models and firmware versions Verify patch compatibility with your specific operational environment and third-party integrations Request assistance with protection level configuration and access control implementation Conclusion There is an active threat targeting Internet-exposed Siemens S7 Series PLCs. The combination of known vulnerabilities, accessible exploitation libraries, and AI-assisted development creates a high-probability attack scenario against inadequately protected PLC installations. Organizations should treat this Cybersecurity Advisory with urgency and coordinate response efforts across security, engineering, executive leadership, plant operations, and vendor support teams to implement the recommended detection and hardening actions. Resources Primary Mitigations to Reduce Cyber Threats to Operational Technology Secure connectivity principles for Operational Technology (OT): How organisations should design, secure, and manage connectivity in OT Control System Defense: Know the Opponent Incident reporting U.S. organizations are encouraged to report suspicious or criminal activity related to information in this advisory to CISA and/or the FBI. Contact CISA via CISA’s 24/7 Operations Center at contact@cisa.dhs.gov or 1-844-Say-CISA (1-844-729-2472). File a claim with FBI’s Internet Crime Complaint Center (IC3) or contact your local FBI field office. When available, please include the following information regarding the incident: Date, time, and location of the incident; Type of activity; Number of people affected; Type of equipment used for the activity; and Name of the submitting company or organization, and a designated point of contact. Entities required to report incidents to DOE should follow established reporting requirements, as appropriate. For other energy sector inquiries, contact EnergySRMA@hq.doe.gov. In addition, consider contacting Siemens ProductCERT via https://www.siemens.com/cert or email productcert@siemens.com. Disclaimer of endorsement The information and opinions contained in this document are provided "as is" and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes. Purpose This document was developed in furtherance of the authoring agencies’ cybersecurity missions, including their responsibilities to identify and disseminate threats and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders. Contact Cybersecurity Report Feedback: CybersecurityReports@nsa.gov Defense Industrial Base Inquiries and Cybersecurity Services: DIB_Defense@cyber.nsa.gov Media Inquiries / Press Desk: NSA Media Relations: 443-634-0721, MediaRelations@nsa.gov Contact Siemens ProductCERT for up-to-date information about the security of Siemens products or to report cybersecurity vulnerabilities at productcert@siemens.com. For support with increasing the security of installed Siemens PLCs, contact Siemens Industrial Cybersecurity Services at services.automation@siemens.com. See Siemens ProductCERT and Siemens CERT for more information. Appendix A: MITRE ATT&CK tactics and techniques See Table 1 for the threat actor tactics and techniques referenced in this advisory. Table 1: MITRE ATT&CK tactics and techniques Tactic Technique Title ID Use Reconnaissance Search Open Technical Databases: Scan Databases T1596.005 Using Internet scanning services to identify Internet-exposed or poorly segmented Siemens S7 Series PLCs Resource Development Develop Capabilities: Exploits T1587.004 Developing exploits for known Siemens S7 Series PLC vulnerabilities Resource Development Obtain Capabilities: Artificial Intelligence T1588.007 Rapidly iterating exploit code through AI-assisted development Execution Native API T0834 Deploying AI-generated Python scripts incorporating the snap7.dll library Execution Modify Controller Tasking T0821 Conducting write operations on data blocks, potentially for pre-positioning for effects operations Evasion Masquerading T0849 Masquerading as legitimate monitoring tools to evade detection Lateral Movement Insecure Credentials T1694 Accessing exposed devices that have unconfigured (default) or minimally configured authentication Collection Data from Local System T0893 Conducting read operations on data blocks, potentially for reconnaissance Appendix B: MITRE D3FEND countermeasures See Table 2 for a mapping of several of the cybersecurity countermeasures mentioned in this advisory. Table 2: MITRE D3FEND Countermeasures Countermeasure Title ID Description Hardware Component Inventory D3-HCI Conduct an immediate inventory of all Siemens S7 Series PLCs Software Update D3-SU Apply critical security patches as soon as possible Network Isolation D3-NI Verify network segmentation and ensure PLCs are not accessible from the Internet Network Access Mediation D3-NAM Restrict TIA Portal/STEP 7 access to authorized engineering workstations only via MAC/IP allowlisting on PLCs Credential Hardening D3-CH Enable PLC password protection on all S7 controllers Enable multi-factor authentication for all remote access to OT networks Platform Monitoring D3-PM Deploy ICS-aware intrusion detection Alert on unauthorized PUT/GET operations Monitor for unexpected behavior deviations Monitor for snap7.dll library imports Hunt for indicators of compromise Network Traffic Analysis D3-NTA Alert on unexpected S7comm traffic on TCP port 102 Watch for sequential IP scanning patterns Application Configuration Hardening D3-ACH Disable unused web servers and protocols Remove SNMP community strings Watch for ladder logic changes Notes 1 MITRE and ATT&CK are registered trademarks of The MITRE Corporation. MITRE D3FEND is a trademark of the MITRE Corporation.
· CISA Cybersecurity Advisory

Siemens Simcenter Nastran

View CSAF Summary Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions…
Read full source summary
View CSAF Summary Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Simcenter Nastran are affected: Simcenter Femap vers:intdot/<2606 (CVE-2026-59086) Simcenter Nastran vers:intdot/<2606 (CVE-2026-59086) CVSS Vendor Equipment Vulnerabilities v3 7.8 Siemens Siemens Simcenter Nastran Stack-based Buffer Overflow Background Critical Infrastructure Sectors: Critical Manufacturing, Defense Industrial Base, Energy, Healthcare and Public Health, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-59086 The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process. View CVE Details Affected Products Siemens Simcenter Nastran Vendor: Siemens Product Version: Simcenter Femap < V2606, Simcenter Nastran < V2606 Product Status: known_affected Remediations Vendor fix Update to V2606 or later version https://support.sw.siemens.com/product/275652363/ Relevant CWE: CWE-121 Stack-based Buffer Overflow Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Acknowledgments Michael Heinzl reported this vulnerability to Siemens ProductCERT. General Recommendations As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity Additional Resources For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories Terms of Use The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Siemens ProductCERT SSA-069220 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory. Revision History Initial Release Date: 2026-08-11 Date Revision Summary 2026-08-11 1 Publication Date 2026-08-13 2 Added Simcenter Femap with fix 2026-08-18 3 Initial CISA Republication of Siemens ProductCERT SSA-069220 advisory Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

CISA Malcolm

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code. The following versions of CISA Malcolm are affected: Malcolm <26.06.1 (CVE-2026-55676) Malcolm <26.07.0 (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177) Malcolm <=26.07.1 (CVE-2026-19670, CVE-2026-19671) CVSS Vendor Equipment Vulnerabilities v3 8.8 CISA CISA…
Read full source summary
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code. The following versions of CISA Malcolm are affected: Malcolm <26.06.1 (CVE-2026-55676) Malcolm <26.07.0 (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177) Malcolm <=26.07.1 (CVE-2026-19670, CVE-2026-19671) CVSS Vendor Equipment Vulnerabilities v3 8.8 CISA CISA Malcolm Allocation of Resources Without Limits or Throttling, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangerous Type, Incorrect Authorization, Improper Handling of Highly Compressed Data (Data Amplification) Background Critical Infrastructure Sectors: Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-63133 Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, safe-extract.py extracts uploaded archives with no limit on entry count, directory depth, total entries, or output size. A small malicious archive containing a large number of directory or file entries causes the filebeat processing container to create an unbounded number of filesystem objects, exhausting inodes or filesystem metadata and denying service to the processing pipeline and any service sharing the same mount. Version 26.07.0 fixes the issue. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm: <26.07.0 Product Status: known_affected Remediations Vendor fix Malcolm version 26.07.0 addresses these issues. For more information, see https://github.com/cisagov/Malcolm/pull/1043. (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177) https://github.com/cisagov/Malcolm/pull/1043 Relevant CWE: CWE-770 Allocation of Resources Without Limits or Throttling Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H 4.0 7.1 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-63134 Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, safe-extract.py protects file extraction with libarchive's secure flags, but creates directory entries with a raw os.makedirs(os.path.join(dest, entry.pathname)) that has no traversal protection. An uploaded malicious archive containing a directory entry with a ../ sequence or an absolute path causes the filebeat processing container to create directories outside the intended extraction directory. Version 26.07.0 fixes the issue. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm: <26.07.0 Product Status: known_affected Remediations Vendor fix Malcolm version 26.07.0 addresses these issues. For more information, see https://github.com/cisagov/Malcolm/pull/1043. (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177) https://github.com/cisagov/Malcolm/pull/1043 Relevant CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L 4.0 5.3 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N CVE-2026-55676 Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at POST /server/php/submit.php and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that should restrict accepted file types is an empty array by default (file-upload/php/config.php:16), so the type check is a no-op and every extension is accepted. The filename sanitizer keeps the .php extension intact. Committed files land in /var/www/upload/server/php/files (file-upload/php/config.php:7), and the component's nginx routes any URL ending in .php to php-fpm. An authenticated GET /server/php/files/.php then executes the uploaded code as www-data. Prior to version 26.06.1, in RBAC mode, the upload endpoint is reachable by the granular ROLE_UPLOAD role (nginx/lua/nginx_auth_helpers.lua:71), a role intended only for submitting capture files. As a result, a user holding the upload-only role runs arbitrary PHP as www-data inside the file-upload container. Version 26.06.1 fixes the issue. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm: <26.06.1 Product Status: known_affected Remediations Vendor fix Malcolm version 26.06.1 addresses this issue. For more information, see https://github.com/cisagov/Malcolm/pull/1026. (CVE-2026-55676) https://github.com/cisagov/Malcolm/pull/1026 Relevant CWE: CWE-434 Unrestricted Upload of File with Dangerous Type Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-63177 Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized ngx.var.request_uri, while Nginx itself routes requests using the normalized path. An authenticated low-privilege user can prepend a traversal segment (for example /x/../upload/...) so that Nginx routes the request to a restricted backend while the Lua role check fails to match any rule and falls open, granting access it should deny. Version 26.07.0 fixes the issue. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm: <26.07.0 Product Status: known_affected Remediations Vendor fix Malcolm version 26.07.0 addresses these issues. For more information, see https://github.com/cisagov/Malcolm/pull/1043. (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177) https://github.com/cisagov/Malcolm/pull/1043 Relevant CWE: CWE-863 Incorrect Authorization Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.1 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N 4.0 7.1 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:L/SI:L/SA:L CVE-2026-19670 Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /auth, /admin_login, /arkime/api/esadmin, NetBox, upload endpoints) by pattern-matching the raw, percent-encoded request URI. Nginx itself, however, selects which location block actually serves the request using the percent-decoded, normalized URI. Because the RBAC check never percent-decodes its input, an authenticated low-privilege user can request an admin-only path using percent-encoding (e.g. /%68tadmin.php) and have nginx route it to the restricted location while the Lua RBAC gate evaluating the un-decoded raw string finds no matching restriction and grants access. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm: <=26.07.1 Product Status: known_affected Remediations Vendor fix Malcolm version 26.08.0 addresses this issue. For more information, see https://github.com/cisagov/Malcolm/security/advisories/GHSA-jr6p-63pg-hr6g. (CVE-2026-19670) https://github.com/cisagov/Malcolm/security/advisories/GHSA-jr6p-63pg-hr6g Relevant CWE: CWE-863 Incorrect Authorization Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N 4.0 5.3 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVE-2026-19671 Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extracting container archives (zip/tar/rar/7z via libarchive), but those limits are not applied when the uploaded file is a single-stream compressed format (.gz, .bz2, .xz, .lzma, .lz) that isn't a .tar.*-style archive. Any authenticated user permitted to upload PCAP/log files can upload a small, highly compressible file (e.g. a gzip bomb) that decompresses to an effectively unbounded size on disk, exhausting the shared Docker volume used by OpenSearch, Logstash, Arkime, and Zeek, and disrupting the platform for all users. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm: <=26.07.1 Product Status: known_affected Remediations Vendor fix Malcolm version 26.08.0 addresses this issue. For more information, see https://github.com/cisagov/Malcolm/security/advisories/GHSA-f2v6-8cj4-mhr6. (CVE-2026-19671) https://github.com/cisagov/Malcolm/security/advisories/GHSA-f2v6-8cj4-mhr6 Relevant CWE: CWE-409 Improper Handling of Highly Compressed Data (Data Amplification) Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H 4.0 7.1 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Acknowledgments pavanchow reported CVE-2026-63133, CVE-2026-63134, and CVE-2026-63177 to CISA. kah-ja, DeathRipper21 reported CVE-2026-55676 to CISA. tinyb0y reported CVE-2026-19670 and CVE-2026-19671 to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-08-18 Date Revision Summary 2026-08-18 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability CVE-2026-55040 Microsoft SharePoint Weak Authentication Vulnerability CVE-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerability CVE-2026-65400 Apple macOS Improper…
Read full source summary
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability CVE-2026-55040 Microsoft SharePoint Weak Authentication Vulnerability CVE-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerability CVE-2026-65400 Apple macOS Improper Authentication Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
Browse saved snapshots