[
    {
        "id": "https://www.cisa.gov/resources-tools/resources/cisa-vulnerability-review",
        "title": "CISA Vulnerability Review",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/resources-tools/resources/cisa-vulnerability-review",
        "summary": "<p>Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and organizations can reduce their risk by addressing these underlying weaknesses and prioritizing vulnerabilities for action based on the risk they pose.</p>\n<p>The <a href=\"https://www.cisa.gov/sites/default/files/2026-08/cisa-vulnerability-review-fy-2024-2025.pdf\"><em>CISA Vulnerability Review</em></a><em>&nbsp;</em>provides organizations with critical insights into the root causes of insecure software and practical steps they can take to address these flaws to prevent exploitation. Analyzing CISA and open source data from fiscal years 2024 and 2025, the review establishes a baseline of today\u2019s vulnerability landscape before AI-enabled vulnerability discovery becomes more widespread. The review demonstrates the importance of&nbsp;<a href=\"https://www.cisa.gov/securebydesign\">Secure by Design</a> principles in shifting cybersecurity efforts from reacting to threat actors to proactively fixing preventable software flaws.</p>\n<p>The review also identifies common software weaknesses that contribute to exploitable vulnerabilities and details practices software producers can use to prevent these weaknesses from recurring. By examining the patterns across vulnerability data, the review helps organizations focus on systemic improvements that can reduce entire classes of vulnerabilities rather than addressing individual vulnerabilities only after they are discovered.</p>\n<p>Additionally, the review shows organizations how to prioritize vulnerabilities for action using the framework outlined in&nbsp;<a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk\">Binding Operational Directive 26-04: <em>Prioritizing Security Based on Risk</em></a>. This framework evaluates vulnerabilities using four key criteria: exposure status,&nbsp;<a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">Known Exploited Vulnerability (KEV) Catalog</a> status, potential for automated exploitation, and technical impact.</p>",
        "summary_is_html": true,
        "first_seen": "Wed, 26 Aug 26 12:00:00 +0000",
        "last_updated": "Wed, 26 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Six Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added six new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>\n<div class=\"ListContainerWrapper SCXW183571888 BCX8\">\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2015-3246\" target=\"_blank\">CVE-2015-3246</a> Red Hat Libuser Race Condition Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2015-5287\" target=\"_blank\">CVE-2015-5287</a> Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2019-1068\" target=\"_blank\">CVE-2019-1068</a> Microsoft SQL Server Remote Code Execution Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2021-23758\" target=\"_blank\">CVE-2021-23758</a> Ajax.NET Professional Deserialization of Untrusted Data Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2022-0995\" target=\"_blank\">CVE-2022-0995</a> Linux Kernel Out-of-Bounds Write Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-8452\" target=\"_blank\">CVE-2026-8452</a> Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability</li>\n</ul>\n</div>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a class=\"ext\" href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Wed, 26 Aug 26 12:00:00 +0000",
        "last_updated": "Wed, 26 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-04",
        "title": "PayRange API",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-04",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-04.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify the device to cause a denial of service, or alter a devices displayed image.</strong></p>\n<p>The following versions of PayRange API are affected:</p>\n<ul>\n<li>PayRange API vers:all/*</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.8</td>\n<td>PayRange</td>\n<td>PayRange API</td>\n<td>Missing Authorization</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Commercial Facilities</li>\n<li><strong>Countries/Areas Deployed: </strong>United States, Canada</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-18965</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-18965\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>PayRange API</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>PayRange</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>PayRange PayRange API: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>PayRange has not responded to requests to work with CISA to mitigate this vulnerability. Users of PayRange devices are invited to contact PayRange customer support at support@payrange.com for additional information.<br><a href=\"mailto:support@payrange.com\">mailto:support@payrange.com</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/862.html\">CWE-862 Missing Authorization</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Tahi Wilton Geary reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-25</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-25</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 25 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 25 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-01",
        "title": "Rently Smart Home",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to access sensitive information and override user permissions.</strong></p>\n<p>The following versions of Rently Smart Home are affected:</p>\n<ul>\n<li>Smart Home &lt;=20.1.0</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.1</td>\n<td>Rently</td>\n<td>Rently Smart Home</td>\n<td>Insufficiently Protected Credentials</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Commercial Facilities, Communications, Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>United States, India</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-75960</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-75960\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rently Smart Home</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rently</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rently Smart Home: &lt;=20.1.0</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Rently has patched this vulnerability in late June. No user action is required.</p>\n<p><strong>Mitigation</strong><br>For more information, contact Rently (support@rently.com).<br><a href=\"mailto:support@rently.com\">mailto:support@rently.com</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/522.html\">CWE-522 Insufficiently Protected Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Berk Dusunur reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-25</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-25</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 25 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 25 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a",
        "title": "A Tale of Two SOCs: Insights From Two Red Team Assessments",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a",
        "summary": "<h2><strong>Advisory at a Glance</strong></h2>\n<table>\n<tbody>\n<tr>\n<th>Title</th>\n<td>A Tale of Two SOCs: Insights From Two Red Team Assessments</td>\n</tr>\n<tr>\n<th>Original Publication&nbsp;</th>\n<td><strong>August 25, 2026</strong></td>\n</tr>\n<tr>\n<th>Executive Summary</th>\n<td>\n<p>The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A failed to detect or contain the activity, but Organization B rapidly identified initial compromise attempts, isolated affected systems, and forced the red team into an assume breach model.</p>\n<p>This advisory details the red team\u2019s activity and organizations\u2019 defensive actions, offering lessons learned and mitigations to help critical infrastructure organizations strengthen detection, response, and protections in IT, cloud, and operational technology (OT) environments.</p>\n</td>\n</tr>\n<tr>\n<th>Lessons Learned</th>\n<td>\n<ul type=\"square\">\n<li><strong>Untuned detection tools lead to missed threats</strong>. Without well-defined baselines and alert filtering, false positives and routine alerts overwhelm network defenders.</li>\n<li><strong>Organizational silos and bureaucratic hurdles prevent effective incident response</strong>. Detection tools are only as effective as the people, processes, and procedures supporting them; fragmented communication, unclear responsibilities, and limited defender authority hinder effective incident response.</li>\n<li><strong>Cloud environments are often an underestimated risk</strong>. Organizations often lack security controls for cloud environments and processes for responding to a cloud compromise.</li>\n</ul>\n</td>\n</tr>\n<tr>\n<th>Key Actions</th>\n<td>\n<ul type=\"square\">\n<li><strong>Establish and continuously maintain a baseline and reduce alert noise</strong> by fine tuning.</li>\n<li><strong>Break down silos and empower network defenders</strong>.</li>\n<li><strong>Implement Conditional Access policies for workload identities</strong> and monitor for excessive or unused permissions.</li>\n<li><strong>Establish and regularly review comprehensive procedures for detecting, remediating, and revoking access/refresh tokens</strong> in the event of a cloud compromise.</li>\n</ul>\n</td>\n</tr>\n<tr>\n<th>Intended Audience</th>\n<td>\n<p><strong>Organizations:</strong> Federal Civilian Executive Branch agencies; state, local, tribal, and territorial governments; critical infrastructure.</p>\n<p><strong>Roles:</strong> <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/systems-administration\" target=\"_blank\" title=\"System administrators\">System administrators</a>, <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/incident-response\" target=\"_blank\" title=\"incident responders\">incident responders</a>, <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/defensive-cybersecurity\" target=\"_blank\" title=\"defensive cybersecurity analysts\">defensive cybersecurity analysts</a>, <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/vulnerability-analysis\" target=\"_blank\" title=\"vulnerability analysts\">vulnerability analysts</a>, <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/network-operations\" target=\"_blank\" title=\"network operators\">network operators</a>, <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/systems-security-management\" target=\"_blank\" title=\"security systems managers\">security systems managers</a>, and all network defenders.</p>\n</td>\n</tr>\n</tbody>\n</table>\n<h2><strong>Introduction</strong></h2>\n<p>The Cybersecurity and Infrastructure Security Agency\u2019s (CISA\u2019s) red team simulates real\u2011world malicious cyber operations to assess an organization\u2019s ability to detect, investigate, and respond to malicious cyber activity. Emulating cyber threat actor tradecraft, the red team attempts to gain and maintain persistent access to an organization\u2019s network and sensitive business systems (SBSs) while avoiding detection.</p>\n<p>CISA conducted two simultaneous red team assessments using similar tradecraft but observed different defensive responses. In one organization (Organization A), the team gained initial access to multiple workstations, gained elevated privileges over the domain, and moved laterally to SBSs and cloud resources undetected. In the second organization (Organization B), network defenders quickly detected the initial compromise and quarantined the affected systems.</p>\n<p>Because Organization B detected the initial compromise, the red team moved to an assume breach model, where Organization B trusted agents (TAs) provided access to a host that replicated the level of access the red team would have had if defenders had not detected their activity. From there, the red team escalated privileges and moved laterally to SBSs, cloud resources, and a bastion host in the OT demilitarized zone (DMZ), where defenders again detected activity and isolated the system.</p>\n<p>In coordination with the assessed organizations, CISA is releasing this Cybersecurity Advisory to describe the red team\u2019s activity and the organization\u2019s defensive responses and to share lessons learned that critical infrastructure organizations can use to strengthen their IT, cloud, and OT cybersecurity posture.</p>\n<p>CISA encourages critical infrastructure organizations to implement the recommendations in the <a href=\"#Mitigations\"><strong>Mitigations</strong></a><strong> </strong>section of this advisory to reduce the likelihood and impact of malicious cyber incidents.</p>\n<p>Download the PDF version of this report:</p>\n\n\n\n\n\n<div class=\"c-file\">\n    <div class=\"c-file__download\">\n    <a href=\"/sites/default/files/2026-08/aa26-237a-tale-of-two-SOCs-insights-two-red-team-assessments-508c.pdf\" class=\"c-file__link\" target=\"_blank\">A Tale of Two SOCs: Insights From Two Red Team Assessments</a>\n    <span class=\"c-file__size\">(PDF,       937.09 KB\n  )</span>\n  </div>\n</div>\n<h2><strong>Technical Details</strong></h2>\n<p><strong>Note:</strong> This advisory uses the <a href=\"https://attack.mitre.org/versions/v19/matrices/enterprise/\" target=\"_blank\" title=\"MITRE ATTACK Matrix for Enterprise\">MITRE ATT&amp;CK<sup>\u00ae</sup> Matrix for Enterprise</a> framework, version 19.&nbsp;See the <a href=\"#MITRE\"><strong>MITRE ATT&amp;CK Tactics and Techniques</strong></a> section of this advisory for a table of the red team\u2019s activity mapped to MITRE ATT&amp;CK tactics and techniques.</p>\n<h3><strong>Overview</strong></h3>\n<p>CISA is authorized\u2014upon request\u2014to provide analyses, expertise, and other technical assistance to critical infrastructure owners and operators and to provide operational and timely technical assistance to federal and non-federal entities, with respect to cybersecurity risks (see generally 6 U.S.C. \u00a7\u00a7 652[c][5], 659[c][6]). CISA conducted two concurrent red team assessments: one at a <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/government-services-facilities-sector\">Government Services and Facilities Sector</a> organization (Organization A), and one at a <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/water-and-wastewater-sector\">Water and Wastewater Systems Sector</a> organization (Organization B).</p>\n<p>During CISA\u2019s red team assessments, the red team simulates malicious cyber operations to assess an organization\u2019s threat detection and response capabilities. The red team attempts to gain and maintain persistent access to an organization\u2019s enterprise network, avoid detection, evade defenses, and access SBSs (applications, data stores, or infrastructure components where compromise would materially impact the organization's operations, finances, or customer data) selected by the organization. For the assessments described in this advisory, the team also attempted to gain access to cloud resources and to demonstrate their ability to access Organization B\u2019s OT systems without actually doing so.</p>\n<h3><strong>Organization A</strong></h3>\n<h4><strong>Red Team Cyber Threat Activity</strong></h4>\n<h5><em><strong>Initial Access and Active Directory Discovery</strong></em></h5>\n<p>During reconnaissance, CISA\u2019s red team identified a web application with default credentials [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1589/001/\" target=\"_blank\" title=\"T1589.001\">T1589.001</a>] for multiple built-in user accounts that allowed the team to send emails from an internal email address. The team used the internal email address to send phishing emails [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1566/\" target=\"_blank\" title=\"T1566\">T1566</a>] and gained initial access to four workstations.</p>\n<p>From the workstations, the red team leveraged a modified BloodHound<a href=\"#Note1\"><sup>1</sup></a> collector, customized to avoid static endpoint detection and response (EDR) signatures, to query and scrape Active Directory (AD) information. This information included AD users [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1087/002/\" target=\"_blank\" title=\"T1087.002\">T1087.002</a>], computers [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1018/\" target=\"_blank\" title=\"T1018\">T1018</a>], groups [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1069/002\" target=\"_blank\" title=\"T1069.002\">T1069.002</a>], access control lists, organizational units, and group policy objects (GPOs) [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1615/\" target=\"_blank\" title=\"T1615\">T1615</a>]. The team found that one compromised workstation had the default Machine Account Quota (MAQ) of 10, allowing unprivileged users to add up to 10 computer accounts to the domain.</p>\n<p>The red team also queried the organization\u2019s Active Directory Certificate Service (ADCS) certificate templates. Misconfigured ADCS templates are common and can allow low-privileged accounts to request a certificate on behalf of other users and computers, including highly privileged accounts. The team identified multiple templates with an ESC1 misconfiguration, which allows any user to request certificates for all users and computer accounts (see scenario ESC1 in SpecterOp\u2019s <a href=\"https://specterops.io/wp-content/uploads/sites/3/2022/06/Certified_Pre-Owned.pdf\" target=\"_blank\">Certified Pre-Owned: Abusing Active Directory Certificate Services</a>). The red team exploited the misconfigured MAQ to create a machine account [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1136/002/\" target=\"_blank\">T1136.002</a>] and then exploited a misconfigured ADCS template to request a certificate for the newly created machine account [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1649/\" target=\"_blank\">T1649</a>]. They could then obtain certificates for any user account, providing means for lateral movement.</p>\n<h5><em><strong>Post Exploitation: Privilege Escalation and Lateral Movement</strong></em></h5>\n<h6>Sensitive Business Systems</h6>\n<p>After the red team gained elevated privileges over the domain, they began post-exploitation activities and attempted to access SBSs. To access the SBSs, the team needed to identify their network location and security controls.</p>\n<p>The team\u2019s plan to achieve SBS access included the following steps:</p>\n<ol>\n<li>Use previously acquired AD data to identify users and groups related to the SBS.</li>\n<li>Query system center configuration manager (SCCM) servers to enumerate user-device relationships and identify the workstations assigned to each user [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1033/\" target=\"_blank\" title=\"T1033\">T1033</a>].</li>\n<li>Move laterally from the SCCM server to the target users\u2019 workstations.</li>\n<li>Find credential material on the target user\u2019s workstation to access the SBS.</li>\n<li>Verify administrative access to the SBS would allow compromise of the availability, integrity, and/or confidentiality of the system and its data.</li>\n</ol>\n<p>For each SBS, the red team used similar discovery and initial access techniques but unique credential retrieval methods. For SBS 1, a database, the team located cleartext credentials on an administrative user\u2019s workstation providing access to the system [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1552/\" target=\"_blank\" title=\"T1552\">T1552</a>]. For SBS 2, also a database, the red team searched the targeted user\u2019s workstations for <code>connections.json</code> and <code>product-preferences.xml</code> files for a Structured Query Language (SQL) developer tool. The team decrypted these files to obtain the cleartext password to the database [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1552/001/\" target=\"_blank\" title=\"T1552.001\">T1552.001</a>]. For SBS 3, an automated processing system, the red team acquired long-lived static Amazon Web Service (AWS) identity and access management (IAM) user credentials saved in configuration files in targeted users\u2019 home directories. These credentials do not expire because the organization had not configured credential expiration or rotation.</p>\n<p>For SBS 2 and 3, the red team expanded access beyond users\u2019 physical workstations to include their virtual desktops, which limited their access to the active, interactive sessions held by users. While virtual workstations add security controls, such as segmenting networks of sensitive systems to only allow virtual hosts, they are generally synchronized with a root drive of the distributed file system (DFS). The red team compromised the root DFS drive, granting them access to local files of all users\u2019 virtual desktops, regardless of the existence of an active session. This allowed the team to quickly search for cloud configuration files containing credentials and database connection files for thousands of users.</p>\n<p>The red team obtained administrative access to all targeted SBSs without defensive intervention by proxying tools [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1090/001/\" target=\"_blank\" title=\"T1090.001\">T1090.001</a>] through compromised workstations and using the collected credentials.</p>\n<h6>Microsoft Entra Systems</h6>\n<p>After compromising the target SBSs, the red team attempted to compromise Organization A\u2019s Microsoft cloud environment by compromising Organization A\u2019s Microsoft Entra ID (formerly Azure AD) through applications. The team targeted Entra ID applications with Application permissions, which allow applications to access data without user consent (compared to Delegated permissions, which allow applications to access data with user consent). By compromising an application that had elevated Application permissions, the red team would gain the same permissions as the application because these applications operate outside the scope of traditional conditional access policies (CAPs) that provide controls for user access and activity.</p>\n<p><strong>Note:</strong> Microsoft\u2019s <a href=\"https://learn.microsoft.com/en-us/entra/identity/conditional-access/workload-identity\" target=\"_blank\" title=\"Conditional Access for workload identities\">Conditional Access for workload identities</a> extends traditional CAPs to service principals (SPs) used by applications and governs Application permissions by allowing organizations to broadly apply access policies to applications. Implementing Conditional Access for workload identities would have protected against red team exploiting use of Application permissions; however, the red team never observed an organization using Conditional Access for workload identities.</p>\n<p>The team compromised applications and used their permissions by:</p>\n<ol>\n<li>Enumerating the organization\u2019s cloud resources using the publicly available tools, including AzureHound<a href=\"#Note2\"><sup>2</sup></a> and ROADrecon,<a href=\"#Note3\"><sup>3</sup></a> to gather information about applications, their permissions, and their owners [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1526/\" target=\"_blank\" title=\"T1526\">T1526</a>] [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1588/002/\" target=\"_blank\" title=\"T1588.002\">T1588.002</a>].</li>\n<li>Identifying applications with elevated permissions to the Microsoft Graph Resource application programming interface (API), including the following:<br>\n<ol type=\"a\">\n<li><code>Mail.Read</code> \u2013 Read Outlook emails.</li>\n<li><code>Mail.ReadWrite</code> \u2013 Read and write Outlook emails.</li>\n<li><code>Chat.Read.All</code> \u2013 Access Teams messages.</li>\n<li><code>Files.Read.All</code> \u2013 Access OneDrive.</li>\n<li><code>Application.ReadWrite.All</code> \u2013 Add Client Secrets to any application or SP.</li>\n<li><code>AppRoleAssignment.ReadWrite.All</code> \u2013 Lets an SP grant itself powerful Graph application permissions such as <code>Chat.Read.All</code> or <code>RoleManagement.ReadWrite.Directory</code>.</li>\n</ol>\n</li>\n<li>Identifying the owner of an application with <code>Mail.ReadWrite</code> permissions.</li>\n<li>Moving laterally to the owner\u2019s machine.</li>\n<li>Obtaining access to the user\u2019s primary refresh token (PRT).<br>\n<ol type=\"a\">\n<li>A PRT is a secure artifact specifically issued to Microsoft first-party token brokers to enable single sign-on (SSO) across the applications used on those devices. For more information about PRT, see Microsoft\u2019s <a href=\"https://learn.microsoft.com/en-us/entra/identity/devices/concept-primary-refresh-token?tabs=windows-prt-issued%2Cbrowser-behavior-windows%2Cwindows-prt-used%2Cwindows-prt-renewal%2Cwindows-prt-protection%2Cwindows-apptokens%2Cwindows-browsercookies%2Cwindows-mfa\" target=\"_blank\" title=\"Understanding Primary Refresh Token (PRT) in Microsoft Entra ID\">Understanding Primary Refresh Token (PRT) in Microsoft Entra ID</a>.</li>\n</ol>\n</li>\n<li>Using the PRT to request access and refresh tokens for the targeted application\u2019s owner.<br>\n<ol type=\"a\">\n<li><strong>Access tokens</strong> are short-lived tokens issued by Entra ID that grant a client permission to access specific resources or APIs on behalf of a user.</li>\n<li><strong>Refresh tokens</strong> are longer-lived tokens issued by Entra ID that allow a client to silently request new access tokens without requiring the user to sign in again.</li>\n</ol>\n</li>\n<li>Using the access token to add a new client secret to the target application.<br>\n<ol type=\"a\">\n<li>A <strong>client secret</strong> is a confidential string used by the application to authenticate itself to Entra ID during token requests.</li>\n</ol>\n</li>\n<li>Using the new client secret to request a new access token for the target application.</li>\n<li>Impersonating the application by using the access token [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1550/001/\" target=\"_blank\" title=\"T1550.001\">T1550.001</a>] to retrieve and review target emails [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1114/\" target=\"_blank\" title=\"T1114\">T1114</a>] via the Microsoft Graph API.</li>\n</ol>\n<p>This allowed the red team to review security operations center (SOC) staff emails to see if SOC staff were aware of the compromise.</p>\n<h4><strong>Organization A\u2019s Response</strong></h4>\n<p>The organization did not respond effectively to red team activity. The red team observed this during their engagement by accessing SOC personnel emails and moving laterally to SOC workstations where they captured screenshots [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1113/\" target=\"_blank\" title=\"T1113\">T1113</a>], used keyloggers [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1056/001/\" target=\"_blank\" title=\"T1056.001\">T1056.001</a>], and retrieved Microsoft Teams messages [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1213/005/\" target=\"_blank\" title=\"T1213.005\">T1213.005</a>].</p>\n<p>The red team observed that the SOC received medium- and low-severity EDR alerts related to the red team activity but did not respond to them. Thousands of false positive alerts corresponding to normal business operations, many with a higher severity, obscured the alerts triggered by red team activity.</p>\n<p>Organizational silos further hindered detection and response. The organization had multiple SOCs and multiple EDR solutions. Staff did not communicate with staff from other SOCs or have visibility on their detection tools. SOC staff and system owners also did not communicate with each other.</p>\n<p>This led to SOC staff not actioning alerts from red team activity. For example, red team members noted chat exchanges regarding an SCCM in which defenders tried and failed to identify the system owner, its function, and its typical use. The SOC team eventually flagged the alert as a false positive.</p>\n<p>The red team believes this was because the SOC staff lacked standard operating procedures for escalating alerts and had limited personnel authority.</p>\n<h3><strong>Organization B</strong></h3>\n<h4><strong>Red Team Cyber Threat Activity</strong></h4>\n<h5><em><strong>Initial Access</strong></em></h5>\n<p>The CISA red team gained initial access to Organization B\u2019s environment through a spearphishing campaign. The team gathered email addresses from public websites [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1589/002/\" target=\"_blank\" title=\"T1589.002\">T1589.002</a>] and sent phishing emails that eventually led to three users clicking [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1204/\" target=\"_blank\" title=\"T1204\">T1204</a>] on a malicious link, giving the red team access to three workstations.</p>\n<p>Each payload execution generated a medium-severity alert: \u201cAn executable file loaded an unexpected DLL file.\u201d SOC staff triaged these alerts and manually isolated all three workstations within 10, 2, and 20 minutes. This effectively terminated the team\u2019s command and control (C2) communications with the workstations. Before staff isolated one workstation, the red team enumerated Organization B\u2019s domain\u2019s AD structure by executing various Lightweight Directory Access Protocol (LDAP) queries through the callback. The data gathered included all users, groups, computers, domains, GPO, and subsequent relationships for the entire domain.</p>\n<p>Because the defenders removed their initial foothold, the red team switched to an assume breach model. Organization B\u2019s TAs (organization IT staff who knew of the assessment and were in contact with the red team) executed a red-team-provided payload on a designated internal host. This host was associated with a standard user account with no administrative privileges, replicating the same level of access the red team would have maintained if Organization B\u2019s defenders had not detected them.</p>\n<h5><em><strong>Domain Compromise</strong></em></h5>\n<p>With persistent access to the internal network, the red team searched for ways to escalate their privileges over the domain to facilitate lateral movement and access SBSs. The red team used the assume breach account to query the MAQ attribute of Organization B\u2019s domain and discovered that all domain users were able to add accounts to the domain.</p>\n<p>The red team created a new machine account with a hostname designed to resemble a legitimate host. The creation of the machine account provided the red team with a domain account and a password that they controlled. This allowed them to execute standalone tools from a red-team-controlled Linux workstation. The tool\u2019s traffic was proxied through the assume breach host, circumventing restrictions imposed by host-based EDR.</p>\n<p>The red team did not identify any escalation paths from the AD data; however, enumeration of SCCM distribution points led to the discovery of an XML file with cleartext credentials for a domain service account. AD data showed that the newly acquired service account had outbound object control over almost 1,000 accounts within the domain due to its group membership. Most notably, the service account had <code>AllExtendedRights</code> permission over a domain controller, which enabled the team to conduct a resource-based constrained delegation attack, granting them DCSync privileges [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1003/006/\" target=\"_blank\" title=\"T1003.006\">T1003.006</a>] and the ability to obtain AD account credentials. The team used these credentials throughout the remainder of their assessment to access servers and workstations. One of the first accounts the red team DCSynced was the <code>krbtgt</code> account, which a malicious cyber actor could use to forge Golden Tickets that allow for impersonation of any user in Organization B\u2019s domain.</p>\n<h5><em><strong>Post Exploitation</strong></em></h5>\n<h6>Sensitive Business Systems</h6>\n<p>The TAs provided the names of two SBSs, one of which the red team successfully compromised. To do this, the team reviewed previously collected BloodHound data and identified a user account with access to an SBS web server that allowed Kerberos authentication. Because the red team had already compromised the on-premises (on-prem) AD environment, they could impersonate this user to access the server.</p>\n<p>The team:</p>\n<ol>\n<li>Used DCSync to acquire the user\u2019s AES256 password hash.</li>\n<li>Used the password hash to request a Kerberos ticket-granting ticket (TGT) for the user.</li>\n<li>Used the TGT to request a Kerberos service ticket [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1558/\" target=\"_blank\" title=\"T1558\">T1558</a>] for the web server\u2019s service principal name (SPN).</li>\n</ol>\n<p>After requesting the Kerberos service ticket, the red team imported it into a Windows virtual machine (VM) on their infrastructure. The red team configured their VM to proxy any traffic to Organization B\u2019s network through a SOCKS proxy that tunneled traffic through a compromised host.</p>\n<h6>Operational Technology Network</h6>\n<p>The red team wanted to gain visibility of the OT network and identify OT network subnets. To do this, they first identified an IT workstation with Remote Desktop Protocol (RDP) files, including a file named <code>ics-[redacted]-org</code>, signifying that the user likely had remote access to the OT network. The red team identified that the workstation had remote access to a bastion host. A bastion host\u2014sometimes referred to as a jump box or jump server\u2014is a specialized, highly secured system (often a server or dedicated workstation) that serves as the sole access point between a network segment (such as an internal IT network) and a protected internal network (like an OT environment).</p>\n<p>The red team gained access to this bastion host using File Transfer Protocol (FTP) credentials to log in over Secure Shell (SSH) [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1021/004/\" target=\"_blank\" title=\"T1021.004\">T1021.004</a>]. At this point, they had visibility over the OT network.</p>\n<p>They attempted to gain a C2 session on the server by dropping several payload files on the host and executing them. However, the callback never reached red team infrastructure because the host blocked outbound internet connections. The payload execution triggered an alert that led SOC staff to quarantine the host.</p>\n<h6>Microsoft Entra Systems</h6>\n<p>The red team attempted to access Organization B\u2019s cloud-based Entra ID infrastructure to find a way to move from on-prem AD to the cloud. Organization B had a hybrid environment, and user credentials automatically synchronized between on-prem AD and cloud Entra ID. Given this, the red team looked for the on-prem server responsible for synchronization.</p>\n<p>Entra ID Connect (formerly Azure AD Connect) sets up an on-prem account with the prefix&nbsp;<code>MSOL_</code> to synchronize credentials with Entra ID. The red team used the open source tool ADConnectDump<a href=\"#Note4\"><sup>4</sup></a><sup>&nbsp;</sup> to obtain cleartext credentials for the on-prem Microsoft Online (MSOL) account and the Entra ID account&nbsp;<code>Sync_[redacted]</code> [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1003\" target=\"_blank\" title=\"T1003\">T1003</a>]. With cleartext credentials for&nbsp;<code>Sync_[redacted]</code>, the red team logged into the Azure portal.&nbsp;<code>Sync_[redacted]</code> was not intended for interactive logins and, in this case, did not have multifactor authentication (MFA) enabled. However, the red team used this account to obtain access tokens for use with AzureHound and ROADrecon to gather Entra ID data for Organization B\u2019s tenant.</p>\n<p><strong>Note:</strong> The red team obtained cleartext MSOL credentials and logged into the Azure portal because MSOL accounts used to have a large number of permissions; Microsoft has since removed these permissions. See Microsoft\u2019s <a href=\"https://techcommunity.microsoft.com/blog/microsoft-entra-blog/action-required-msonline-and-azuread-powershell-retirement---2025-info-and-resou/4364991\" target=\"_blank\" title=\"Action required: MSOnline and AzureAD PowerShell retirement - 2025 info and resources\">Action required: MSOnline and AzureAD PowerShell retirement - 2025 info and resources</a> and <a href=\"https://techcommunity.microsoft.com/blog/microsoft-entra-blog/important-update-deprecation-of-azure-ad-powershell-and-msonline-powershell-modu/4094536\" target=\"_blank\" title=\"Important update: Deprecation of Azure AD PowerShell and MSOnline PowerShell modules\">Important update: Deprecation of Azure AD PowerShell and MSOnline PowerShell modules</a> for more information.</p>\n<p>The interactive login from <code>Sync_[redacted]</code> triggered an automated alert from Microsoft, which sent the information to Organization B\u2019s SOC staff, who then blocked the suspicious activity.</p>\n<p>The red team identified a computer account containing <code>AZURESSO</code> in its name, located in the on-prem AD environment. This account is part of the Seamless SSO implementation and allows users to use Kerberos tickets as the first step in authenticating to Entra ID. To abuse Seamless SSO, the red team acquired encrypted credentials of a target user via DCSync and then used the Rubeus \u201casktgs\u201d module to request service tickets used for SSO. The red team imported the service tickets to their workstation and proxied their traffic through Organization B\u2019s network using a SOCKS proxy. This allowed them to browse to https://portal[.]azure[.]com, while using legitimate Kerberos tickets, and the traffic appeared to originate from a trusted IP address.</p>\n<p>This approach allowed the red team to gain access to Entra ID as any user synced to AD without the user\u2019s cleartext password. However, they could only use Kerberos tickets for the first phase of the sign-in process. If a user was set up to use MFA, then Entra ID would prompt the red team for a second factor during the sign-in process. Therefore, the red team was only able to log into any Entra ID account that did not have MFA enabled, which seemed limited to service accounts. They reviewed the previously obtained Entra ID data and looked for applications that had excessive permissions and were accessible to AD-synced service accounts.</p>\n<p>The red team identified an application that had permission to read, write, and send emails for all users within Organization B\u2019s tenant. The application was owned by an AD-Synced account that was disabled in AD. Using a compromised host in the on-prem environment, they re-enabled this account, DCSynced its credentials, and used the AES256 hash to request Kerberos tickets. The red team used the tickets to authenticate to Entra ID and were then able to add a client secret to the application. This gave them the ability to retrieve the emails of every user within Organization B\u2019s environment from the public internet.</p>\n<h4><strong>Organization B\u2019s Response</strong></h4>\n<p>Organization B quickly triaged and responded to alerts after the red team gained initial access, effectively terminating the team\u2019s C2 communications with the workstations and leading the red team to move to an assume breach model. These actions demonstrated a mature, proactive security posture and helped prevent wider compromise.</p>\n<p>When the red team gained access to a bastion host in the OT DMZ, Organization B had defensive controls that blocked outbound connections to red team infrastructure, and SOC staff quickly triaged and responded to an alert by isolating the host.</p>\n<p>When the red team logged into the organization\u2019s Azure portal via a compromised account, it triggered an automated alert from Microsoft, which led the staff to block the suspicious account. In addition, Organization B had custom detections Entra ID Risky User Alerts for \u201cUnfamiliar sign-in properties\u201d and \u201cSuspicious API traffic\u201d that alerted to the AzureHound user agent and to accounts exceeding predefined request thresholds to the Microsoft Graph API.</p>\n<p>See <a href=\"#Table1\"><strong>Table 1</strong></a> for Organization B\u2019s defensive measures and associated response.</p>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table1\"><em><strong>Table 1</strong></em></a><em><strong>. Red Team Activity and Organization B SOC Response</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Red Team Activity</th>\n<th role=\"columnheader\">Defensive Measure</th>\n<th role=\"columnheader\">SOC Response</th>\n<th role=\"columnheader\">Outcome</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>C2 payload executed on a workstation.</td>\n<td>Payload execution generated a medium-severity alert.</td>\n<td>Staff quarantined workstation; staff analyzed and reimaged before putting workstation back online.</td>\n<td>Red team lost access to a workstation.</td>\n</tr>\n<tr>\n<td>C2 payload executed on a second workstation.</td>\n<td>Payload execution generated a medium-severity alert.</td>\n<td>Staff quarantined workstation; staff analyzed and reimaged before putting workstation back online.</td>\n<td>Red team lost access to a workstation.</td>\n</tr>\n<tr>\n<td>C2 payload executed on a third workstation.</td>\n<td>Payload execution generated a medium-severity alert.</td>\n<td>Staff quarantined workstation; staff analyzed and reimaged before putting workstation back online.</td>\n<td>Red team lost access to a workstation.</td>\n</tr>\n<tr>\n<td>C2 payload executed on bastion host in the OT DMZ.</td>\n<td>Payload execution generated alerts.</td>\n<td>Staff quarantined the host.</td>\n<td>Red team lost access to the host.</td>\n</tr>\n<tr>\n<td>Used compromised Entra ID account to log into Azure.</td>\n<td>Automated alert from Microsoft.</td>\n<td>Staff blocked the account.</td>\n<td>Red team compromised a different account and accessed Entra ID by abusing Seamless SSO.</td>\n</tr>\n</tbody>\n</table>\n<p>Despite these strengths, Organization B had areas for improvement. The red team was eventually able to access Entra ID through a computer account that was part of the organization\u2019s Seamless SSO implementation. The account did not have MFA and had overly permissive application permissions, indicating the need for more mature cloud security processes.</p>\n<p>Additionally, Organization B had excessive permissions and misconfigurations in AD and service accounts, which the red team leveraged for privilege escalation. This highlights the importance of regular audits and strict enforcement of least privilege principles. Organization B could improve credential hygiene, as the red team found credentials for OT systems stored in plaintext on jump servers. Finally, while segmentation and egress controls were effective, ongoing review and tightening of IT/OT connectivity and access architectures would reduce opportunities for lateral movement.</p>\n<h2><a class=\"ck-anchor\" id=\"Lessons\"><strong>Lessons Learned</strong></a></h2>\n<p>The red team identified lessons learned based on each organization\u2019s response. Organization A and Organization B contrasted significantly in their ability to quickly identify and respond to red team activity. However, similar gaps in both organizations contributed to the red team\u2019s compromise of their cloud systems.</p>\n<h3><strong>Untuned Detection Tools Lead to Missed Threats</strong></h3>\n<p>Organization A did not tune their detection tools to reduce alert noise, leading to an unmanageable level of alerts for SOC staff to review and action. The same red team activity that triggered alerts and action for Organization B led to no response for Organization A because SOC staff did not identify the activity as potentially malicious amid the overwhelming volume of alerts. Organization B had an established baseline and a fine-tuned alert system, allowing defenders to effectively filter out routine business activity and false positives. As a result, anomalies stood out, enabling the SOC staff to quickly detect and respond to red team activity.</p>\n<p>Without well-defined baselines and alert filtering, false positives and routine alerts overwhelm defenders, obscuring real threats. Organizations that tune alerts to highlight anomalies and filter out normal business activity enable defenders to focus on genuine incidents and respond rapidly.</p>\n<h3><strong>Organizational Silos and Bureaucratic Hurdles Prevent Effective Incident Response</strong></h3>\n<p>In Organization A, lack of communication and visibility created by organizational silos (among multiple SOCs and between SOC staff and system owners) hindered effective incident response, resulting in missed opportunities for identification of a major breach.</p>\n<p>Bureaucratic barriers arose because SOC staff managed systems without understanding their authorities as responsibilities and authorities varied across network segments. They had no escalation procedures and so defaulted to a \u201cwait and see\u201d approach.</p>\n<p>In contrast, Organization B empowered its defenders to act decisively. Staff quickly triaged alerts, investigated root causes, identified misconfigurations, and coordinated remediation with engineering.</p>\n<p>Detection tools are only as effective as the people, processes, and procedures supporting them. SOC staff should not operate in silos and should have clear authority unhindered by bureaucracy to effectively contain and resolve incidents.</p>\n<h3><strong>Organizations Underestimate Risks in Cloud Environments</strong></h3>\n<p>Both organizations underestimated the risks associated with cloud environments. They granted excessive permissions to cloud applications, allowing the red team to access cloud systems. They also lacked fully mature, defined processes for detecting and remediating compromise of cloud environments, allowing the red team to maintain access to cloud resources.</p>\n<h4><strong>Use of Long-Lived User Identity and Access Management Credentials</strong></h4>\n<p>Organization A used long-lived static IAM user credentials that were set to never expire. If a malicious actor obtains them, they will have all the user permissions, potentially enabling persistent, unrestricted access to the cloud environment.</p>\n<h4><strong>Excessive Permissions</strong></h4>\n<p>Both organizations lacked Conditional Access for workload identities. This feature extends Conditional Access beyond user accounts, covering non-human identities, such as applications. It allows organizations to broadly apply access policies to applications that control how and when the application is used to access resources. Instead, both organizations used broad application permissions for most apps, which the team was able to exploit for access to the environment. In both organizations, the team was able to exploit excessive permissions to read emails.</p>\n<h4><strong>Lack of Mature Remediation Processes for Tokens</strong></h4>\n<p>Both organizations lacked processes for revoking compromised access/refresh tokens. Without a well-defined, efficient process for remediating and revoking access/refresh tokens following a cloud compromise, malicious cyber actors evicted from on-prem environments may still leverage cloud access to regain entry. Organizations should establish mature procedures to detect and remediate compromises of cloud environments to prevent malicious cyber actors from reestablishing access.</p>\n<h2><a class=\"ck-anchor\" id=\"Issues\"><strong>Issues</strong></a></h2>\n<p>The red team identified the following issues that contributed to their ability to maintain persistent access to Organization A and/or B and escalate privileges or move laterally:</p>\n<ul type=\"square\">\n<li><strong>Misconfigured ADCS templates</strong>.<br>\n<ul type=\"circle\">\n<li>In Organization A, the red team identified and exploited a certificate template with common template misconfiguration known as ESC1, an overly permissive certificate template where the <code>CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT</code> flag is enabled and low-privileged users can request certificates. This allows malicious actors to impersonate users. See SpecterOp\u2019s <a href=\"https://specterops.io/wp-content/uploads/sites/3/2022/06/Certified_Pre-Owned.pdf\" target=\"_blank\" title=\"Certified Pre-Owned: Abusing Active Directory Certificate Services\">Certified Pre-Owned: Abusing Active Directory Certificate Services</a> for information about the ESC1 misconfiguration.</li>\n</ul>\n</li>\n<li><strong>Workstations where MAQ was misconfigured</strong>.<br>\n<ul type=\"circle\">\n<li>In Organization A, the team gained access to a workstation where the MAQ was set to the default value of 10. This meant that unprivileged users could add up to 10 computer accounts to the domain.</li>\n<li>In Organization B, the MAQ was set to 1,000 for all domain users, allowing any user to create a large number of machine accounts.</li>\n</ul>\n</li>\n<li><strong>Service accounts with excessive permissions</strong>.<br>\n<ul type=\"circle\">\n<li>In Organization B, the red team identified a domain service account with <code>AllExtendedRights</code> permission over a domain controller. <code>AllExtendedRights</code> enables malicious cyber actors to perform DCsync attacks and potentially impersonate any account in the domain, leading to full domain compromise.</li>\n</ul>\n</li>\n<li><strong>Cleartext credentials.</strong><br>\n<ul type=\"circle\">\n<li>In Organization A, the red team found and used cleartext credentials to obtain administrative access to SBSs.</li>\n<li>In Organization B, the red team identified a cleartext password in an XML file for a domain service account.</li>\n</ul>\n</li>\n<li><strong>Endpoint management systems that lacked additional security controls</strong>.<br>\n<ul type=\"circle\">\n<li>In Organization A, the red team moved laterally from the SCCM server to users\u2019 workstations. SCCM and other endpoint configuration managers (e.g., Jamf, BigFix) have broad administrative reach and are Tier 0 assets. If compromised, Tier 0 assets provide malicious actors with powerful escalation paths and control over the enterprise.</li>\n</ul>\n</li>\n</ul>\n<p>The red team identified an additional issue that was not exploited during the assessment but could be exploited by malicious cyber actors:</p>\n<ul>\n<li><strong>AD misconfigurations and user accounts with excessive permissions.</strong><br>\n<ul type=\"circle\">\n<li>In Organization B, the red team discovered that standard user accounts were improperly assigned to privileged administrative groups within the AD.</li>\n</ul>\n</li>\n</ul>\n<h2><a class=\"ck-anchor\" id=\"MITRE\"><strong>MITRE </strong></a><strong>ATT&amp;CK Tactics and Techniques</strong></h2>\n<p>See <a href=\"#Table2\"><strong>Table 2</strong></a> to <a href=\"#Table11\"><strong>Table 11</strong></a> for all referenced threat actor tactics and techniques in this advisory. &nbsp;For assistance with mapping malicious cyber activity to the MITRE ATT&amp;CK framework, see CISA and MITRE ATT&amp;CK\u2019s <a href=\"https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping\" title=\"Best Practices for MITRE ATT&amp;CK Mapping\">Best Practices for MITRE ATT&amp;CK Mapping</a> and CISA\u2019s <a href=\"https://github.com/cisagov/Decider/\" target=\"_blank\" title=\"Decider Tool\">Decider Tool</a>.</p>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table2\"><em><strong>Table 2</strong></em></a><em><strong>. Reconnaissance</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Gather Victim Identity Information: Credentials</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1589/001/\" target=\"_blank\" title=\"T1589.001\">T1589.001</a></td>\n<td>The red team performed reconnaissance and identified a web application with default credentials.</td>\n</tr>\n<tr>\n<td>Gather Victim Identity Information: Email Addresses</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1589/002/\" target=\"_blank\" title=\"T1589.002\">T1589.002</a></td>\n<td>The red team performed reconnaissance and gathered employee email addresses from public websites.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 3. Resource Development</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Obtain Capabilities: Tool</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1588/002/\" target=\"_blank\" title=\"T1588.002\">T1588.002</a></td>\n<td>The red team used publicly available tools, including AzureHound and ROADrecon.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 4. Initial Access</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Phishing</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1566/\" target=\"_blank\" title=\"T1566\">T1566</a></td>\n<td>\n<p>The red team gained initial access to four Organization A workstations by sending phishing emails from an internal email address.</p>\n<p>The red team gained initial access to three Organization B workstations via spearphishing emails that eventually led users to click on a malicious payload.</p>\n</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 5. Execution</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>User Execution</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1204/\" target=\"_blank\" title=\"T1204\">T1204</a></td>\n<td>The red team\u2019s spearphishing emails eventually led to users clicking on a malicious payload.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 6. Persistence</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Create Account: Domain Account</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1136/002/\" target=\"_blank\">T1136.002</a></td>\n<td>The red team exploited misconfigured MAQs to create machine accounts on a workstation.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 7. Credential Access</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Unsecured Credentials</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1552/\" target=\"_blank\" title=\"T1552\">T1552</a></td>\n<td>\n<p>The red team located cleartext credentials on an administrative user\u2019s workstation.</p>\n<p>The red team used the open source tool ADConnectDump to obtain cleartext credentials for cloud accounts.</p>\n</td>\n</tr>\n<tr>\n<td>Unsecured Credentials: Credentials In Files</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1552/001/\" target=\"_blank\" title=\"T1552.001\">T1552.001</a></td>\n<td>\n<p>The red team searched a targeted user\u2019s workstations for <code>connections.json</code> and <code>product-preferences.xml</code> files for a SQL Developer tool. They then decrypted these files to obtain cleartext password to the database.</p>\n<p>The red team acquired long-lived static AWS IAM user credentials in configuration files in users\u2019 home directories.</p>\n</td>\n</tr>\n<tr>\n<td>OS Credential Dumping</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1003/\" target=\"_blank\" title=\"T1003\">T1003</a></td>\n<td>The red team obtained cleartext credentials for an on-prem MSOL account and Entra account.</td>\n</tr>\n<tr>\n<td>OS Credential Dumping: DCSync</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1003/006/\" target=\"_blank\" title=\"T1003.006\">T1003.006</a></td>\n<td>The red team used DCSync to obtain AD account credentials.</td>\n</tr>\n<tr>\n<td>Steal or Forge Authentication Certificates</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1649/\" target=\"_blank\">T1649</a></td>\n<td>The red team could obtain certificates for any Organization A user account. This provided the means for lateral movement.</td>\n</tr>\n<tr>\n<td>Steal or Forge Kerberos Tickets</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1558/\" target=\"_blank\" title=\"T1558\">T1558</a></td>\n<td>\n<p>The red team used a Kerberos TGT to request a Kerberos service ticket for a web server\u2019s SPN.</p>\n<p>The red team used the Rubeus \u201casktgs\u201d module to request service tickets used for SSO.</p>\n</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 8. Discovery</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Account Discovery: Domain Account</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1087/002/\" target=\"_blank\" title=\"T1087.002\">T1087.002</a></td>\n<td>The red team used a BloodHound collector to query and scrape AD information, including AD users.</td>\n</tr>\n<tr>\n<td>Remote System Discovery</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1018/\" target=\"_blank\" title=\"T1018\">T1018</a></td>\n<td>The red team used a BloodHound collector to query and scrape AD information, including computers.</td>\n</tr>\n<tr>\n<td>Permission Groups Discovery: Domain Groups</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1069/002\" target=\"_blank\" title=\"T1069.002\">T1069.002</a></td>\n<td>The red team used a BloodHound collector to query and scrape AD information, including groups.</td>\n</tr>\n<tr>\n<td>Group Policy Discovery</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1615/\" target=\"_blank\" title=\"T1615\">T1615</a></td>\n<td>The red team used a BloodHound collector to query and scrape AD information, including GPOs.</td>\n</tr>\n<tr>\n<td>System Owner/User Discovery</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1033/\" target=\"_blank\" title=\"T1033\">T1033</a></td>\n<td>The red team queried SCCM servers to enumerate user-device relationships and identify the workstations assigned to users.</td>\n</tr>\n<tr>\n<td>Cloud Service Discovery</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1526/\" target=\"_blank\" title=\"T1526\">T1526</a></td>\n<td>The red team used publicly available tools to obtain a list of Entra applications, their permissions, and their owners.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 9. Lateral Movement</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Use Alternate Authentication Material: Application Access Token</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1550/001/\" target=\"_blank\" title=\"T1550.001\">T1550.001</a></td>\n<td>The red team used an application access token to access and review cloud emails.</td>\n</tr>\n<tr>\n<td>Remote Services: SSH</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1021/004/\" target=\"_blank\" title=\"T1021.004\">T1021.004</a></td>\n<td>The red team used FTP credentials to log into a bastion host over SSH.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 10. Collection</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Email Collection</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1114/\" target=\"_blank\" title=\"T1114\">T1114</a></td>\n<td>\n<p>The red team reviewed Organization A SOC staff cloud emails to see if SOC staff were aware of the compromise.</p>\n<p>The red team&nbsp;had the ability to retrieve the emails of every user within Organization B\u2019s environment from the public internet.</p>\n</td>\n</tr>\n<tr>\n<td>Screen Capture</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1113/\" target=\"_blank\" title=\"T1113\">T1113</a></td>\n<td>The red team took screenshots of SOC staff workstations.</td>\n</tr>\n<tr>\n<td>Input Capture: Keylogging</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1056/001/\" target=\"_blank\" title=\"T1056.001\">T1056.001</a></td>\n<td>The red team used keyloggers on SOC staff workstations.</td>\n</tr>\n<tr>\n<td>Data from Information Repositories: Messaging Applications</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1213/005/\" target=\"_blank\" title=\"T1213.005\">T1213.005</a></td>\n<td>The red team pulled Microsoft Teams messages from SOC staff workstations.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table11\"><em><strong>Table 11</strong></em></a><em><strong>. Command and Control</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Proxy: Internal Proxy</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1090/001/\" target=\"_blank\" title=\"T1090.001\">T1090.001</a></td>\n<td>The red team proxied through compromised workstations.</td>\n</tr>\n</tbody>\n</table>\n<h2><a class=\"ck-anchor\" id=\"Mitigations\"><strong>Mitigations</strong></a></h2>\n<p>CISA recommends that organizations implement the mitigations below to strengthen their cybersecurity posture based on the <a href=\"#Lessons\"><strong>Lessons Learned</strong></a> and identified <a href=\"#Issues\"><strong>Issues</strong></a>. These mitigations align with the <a href=\"https://www.cisa.gov/cpg\">Cross-Sector Cybersecurity Performance Goals (CPGs)</a> developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats, tactics, techniques, and procedures. Visit CISA\u2019s <a href=\"https://www.cisa.gov/cpg\">CPGs webpage</a> for more information on the CPGs, including additional recommended baseline protections.</p>\n<h3><strong>Establish Baselines and Improve Monitoring</strong></h3>\n<ul type=\"square\">\n<li><strong>Establish and continuously maintain a baseline of installed tools and software, account behavior, and network traffic</strong>.</li>\n<li><strong>Reduce alert noise</strong> by refining monitoring tools and alerting mechanisms to differentiate between typical administrative actions and potential threat behavior.<br>\n<ul type=\"circle\">\n<li>For information on establishing a baseline and reducing alert noise, see CISA\u2019s joint Guidance&nbsp;<a href=\"https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques\" title=\"Identifying and Mitigating Living Off the Land Techniques\">Identifying and Mitigating Living Off the Land Techniques</a>.</li>\n</ul>\n</li>\n</ul>\n<h3><strong>Eliminate Silos and Bureaucratic Hurdles</strong></h3>\n<ul type=\"square\">\n<li><strong>Break down silos</strong> by encouraging regular communication and collaboration between IT, security, and business units.<br>\n<ul type=\"circle\">\n<li>Consider using joint exercises, shared tools, and creating cross-functional teams.</li>\n<li>Integrate detection with incident response workflows to enable rapid containment and remediation.</li>\n</ul>\n</li>\n<li><strong>Empower network defenders</strong>.<br>\n<ul type=\"circle\">\n<li>Develop and communicate policies [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#EstablishCybersecurityResponsibilities1A\" title=\"CPG 1.A\">CPG 1.A</a>, <a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ManageCybersecurityOversight1B\" title=\"CPG 1.B\">CPG 1.B</a>] that support rapid, coordinated response and clarify when defenders can act independently versus when escalation is required.<br>\n<ul type=\"disc\">\n<li>Define clear roles and responsibilities so defenders know their authorities and escalation paths (if needed) during incidents.</li>\n<li>Grant defenders the authority to take necessary actions (e.g., isolating systems, blocking traffic) without excessive approvals.</li>\n</ul>\n</li>\n<li>Conduct training and simulated incident response exercises to reinforce roles, improve coordination, and identify gaps in authorities or communication [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#IncidentPlanningandPreparedness6A\" title=\"CPG 6.A\">CPG 6.A</a>].</li>\n</ul>\n</li>\n</ul>\n<h3><strong>Enhance Cloud Security Controls</strong></h3>\n<p><strong>Note:</strong> While both organizations used Microsoft Entra ID and Organization B also used AWS, many of the techniques used by the red team are applicable across identity providers and cloud environments and not necessarily unique to Microsoft and AWS. CISA encourages all organizations using cloud environments to implement the recommendations below.</p>\n<ul type=\"square\">\n<li><strong>Secure and monitor access/refresh tokens and&nbsp;establish and regularly review comprehensive procedures for detecting, remediating, and revoking access/refresh tokens</strong> in the event of a cloud compromise.<br>\n<ul type=\"circle\">\n<li>Implement automated token revocation and access reviews and conduct periodic incident response exercises to validate the effectiveness of these processes.</li>\n<li>Restrict access based on trusted network locations, device compliance, and risk signals (such as unusual activity or sign-in patterns).</li>\n<li>Monitor sign-in logs and policy evaluation results for workload identities to detect suspicious activity.</li>\n<li>Regularly check application permissions; make a risk-informed decision to identify and remove any that are not necessary, so each application only has the access it needs to function.</li>\n<li>Regularly audit SP credentials and rotate secrets or certificates to reduce exposure.</li>\n</ul>\n</li>\n<li><strong>Identify and disable legacy accounts.</strong></li>\n<li><strong>Enable phishing-resistant MFA&nbsp;</strong>for all user, administrative, and privileged accounts in cloud platforms [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementMultifactorAuthentication3F\" title=\"CPG 3.F\">CPG 3.F</a>].</li>\n<li><strong>Protect keys and secrets by storing them securely&nbsp;</strong>and enforcing mandatory rotation schedules; apply cryptographic boundary controls to internal and third-party credentials.</li>\n<li><strong>Set up automated alerts for suspicious cloud application activity</strong>, such as abnormal API calls, and credential activity, such as login attempts from unusual locations.</li>\n<li><strong>Leverage user and entity behavior analytics</strong> to analyze and correlate activities across multiple data sources and identify unusual credential or token usage.</li>\n<li><strong>Continuously audit authentication and access logs</strong> for signs of replay or unauthorized access.</li>\n<li><strong>Implement just-in-time (JIT) access</strong> for privileged accounts, replacing standing administrative rights with temporary, time-bound privilege elevations.</li>\n</ul>\n<p>For organizations using Entra ID:</p>\n<ul type=\"square\">\n<li>Monitor and control who has access to application identities.<br>\n<ul type=\"circle\">\n<li><strong>Implement CAPs for workload identities</strong> and monitor for excessive or unused permissions.</li>\n<li><strong>Use Microsoft\u2019s app governance to detect and manage risky SPs</strong>, which are special accounts used by applications and services. See Microsoft\u2019s <a href=\"https://learn.microsoft.com/en-us/defender-cloud-apps/app-governance-visibility-insights-overview\" target=\"_blank\" title=\"OAuth app visibility and insights with app governance - Microsoft Defender for Cloud Apps\">OAuth app visibility and insights with app governance - Microsoft Defender for Cloud Apps</a> for more information.</li>\n</ul>\n</li>\n<li><strong>Integrate Entra ID tenant monitoring with on-prem security operations</strong> to promptly identify suspicious activity.</li>\n<li><strong>Regularly review and restrict application permissions</strong> (e.g., <code>Mail.Read</code>, <code>Files.Read.All</code>).<br>\n<ul type=\"circle\">\n<li>For guidance, see CISA\u2019s <a href=\"https://www.cisa.gov/resources-tools/services/secure-cloud-business-applications-scuba-project\" title=\"Secure Cloud Business Applications (SCuBA) Project\">Secure Cloud Business Applications (SCuBA) Project</a>, which provides secure configuration baselines for Microsoft 365 (M365), including Microsoft Entra ID.</li>\n<li>Use CISA\u2019s <a href=\"https://github.com/cisagov/ScubaGear\" target=\"_blank\" title=\"ScubaGear\">ScubaGear</a>, a no-cost assessment tool that verifies M365 tenant configuration alignment to the policies described in SCuBA\u2019s secure configuration baselines.</li>\n</ul>\n</li>\n<li><strong>Use certificate-based authentication certificates for application authentication</strong> instead of client secrets, when possible. See Microsoft\u2019s <a href=\"https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-certificate-based-authentication\" target=\"_blank\" title=\"Set Up Microsoft Entra CBA - Microsoft Entra ID\">Set Up Microsoft Entra CBA - Microsoft Entra ID</a>.</li>\n<li><strong>Review newly created secrets and/or certificates</strong> on existing applications.</li>\n<li><strong>Limit secret lifetimes to a reasonable lifetime</strong>.</li>\n</ul>\n<p>In AWS environments:</p>\n<ul>\n<li><strong>Mitigate the risks of long-lived IAM user credentials.</strong><br>\n<ul type=\"circle\">\n<li>Identify and audit all existing access keys and disable/delete unused or unnecessary keys.</li>\n</ul>\n</li>\n<li><strong>Require human users to use temporary AWS credentials through SSO.</strong><br>\n<ul type=\"circle\">\n<li>Users will assume an IAM role for AWS access and receive temporary credentials that expire within an hour.</li>\n<li>For more information on accessing AWS using temporary credentials, see Amazon\u2019s documentation <a href=\"https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html\" target=\"_blank\" title=\"Security best practices in IAM\">Security best practices in IAM</a> and <a href=\"https://docs.aws.amazon.com/IAM/latest/UserGuide/introduction_identity-management.html\" target=\"_blank\" title=\"Compare IAM identities and credentials\">Compare IAM identities and credentials</a>.</li>\n</ul>\n</li>\n<li><strong>Regularly review the environment to verify no long-lived credentials remain.</strong></li>\n</ul>\n<h3><strong>Secure Active Directory and Manage Credentials</strong></h3>\n<ul type=\"square\">\n<li><strong>Apply secure configurations to ADCS implementations.</strong><br>\n<ul type=\"circle\">\n<li>Disable the <code>CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT</code> flag from templates to prevent users from supplying and editing sensitive security settings within these templates.</li>\n<li>Restrict accounts that can enroll in all certificate templates to only those necessary, especially templates with the <code>CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT</code> flag.</li>\n<li>Remove <code>FullControl</code>, <code>WriteDacl</code>, and <code>Write</code> property permissions from low-privileged groups, such as domain users, to certificate template objects, where such permissions are not needed.</li>\n<li>Enforce manager approval for requested certificates.</li>\n<li>Apply additional guidance from CISA\u2019s joint Guidance <a href=\"https://www.cisa.gov/resources-tools/resources/detecting-and-mitigating-active-directory-compromises\" title=\"Detecting and Mitigating Active Directory Compromises\">Detecting and Mitigating Active Directory Compromises</a> (see Mitigating AD CS compromise, pages 15\u201316).</li>\n</ul>\n</li>\n<li><strong>Configure the MAQ to zero unless there is a specific operational need for non-administrative users to create computer accounts</strong>;&nbsp;this prevents standard user accounts from creating new machine accounts, reducing opportunities for malicious cyber actors to abuse this privilege.<br>\n<ul type=\"circle\">\n<li>If some standard user accounts need to create computer accounts, set MAQ to the lowest possible value and restrict this capability to only users or groups with a business justification.</li>\n</ul>\n</li>\n<li><strong>Improve credential hygiene</strong>.<br>\n<ul type=\"circle\">\n<li>Scan network shares and workstations for plaintext credentials and remove any found.</li>\n<li>Train staff on secure password storage practices and enforce policies prohibiting plaintext password storage.</li>\n<li>Use encrypted password vaults for storing credentials and limit access to only those who require it.</li>\n<li>Periodically audit credential stores and access logs for signs of misuse.</li>\n</ul>\n</li>\n<li><strong>Periodically audit AD permissions&nbsp;</strong>for misconfigurations and excessively privileged groups and accounts.<br>\n<ul type=\"circle\">\n<li>Implement the principle of least privilege [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementthePrinciplesofLeastPrivilege3H\" title=\"CPG 3.H\">CPG 3.H</a>].</li>\n<li>Grant standard user rights for standard user tasks such as email, web browsing, and using line-of-business applications.</li>\n<li>Periodically audit standard user accounts and minimize privileged access.</li>\n<li>Periodically audit AD permissions to verify that standard user accounts do not have excessive permissions and have not been added to admin groups.</li>\n<li>Evaluate which administrative groups should administer specific servers and workstations.</li>\n<li>Separate administrator accounts from standard user accounts [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#AdministratorsMaintainSeparateUserandPrivilegedAccounts3G\" title=\"CPG 3.G\">CPG 3.G</a>].<br>\n<ul type=\"disc\">\n<li>Use designated workstations for administrators and standard users and prevent administrators from using admin workstations for non-admin purposes; this would reduce impact of credential theft from a user workstation.</li>\n<li>Use designated administrative accounts exclusively for admin purposes.</li>\n<li>If a standard user account needs administrative rights over their workstation, use a separate account that does not have administrative access to other hosts, such as servers.</li>\n</ul>\n</li>\n<li>Consider using a privileged access management (PAM) solution to manage access to privileged accounts and resources.<br>\n<ul type=\"disc\">\n<li>PAM solutions can log and alert usage to detect unusual activity, which could have alerted the assessed organizations when the red team accessed resources with admin accounts.</li>\n<li><strong>Note:</strong> Treat password vaults associated with PAM solutions as high value assets (HVAs) with additional restrictions and monitoring.</li>\n</ul>\n</li>\n<li>Configure time-based access for accounts set at the admin level and higher.<br>\n<ul type=\"disc\">\n<li>The just-in-time access method provisions privileged access when needed and can support enforcement of the principle of least privilege, as well as the zero trust model. A network-wide policy automatically disables administrator accounts at the AD level when the account is not needed. When standard user accounts need administrative access, they submit their requests through an automated process that enables access to a system, but only for a set timeframe to support task completion.</li>\n</ul>\n</li>\n</ul>\n</li>\n</ul>\n<h3><strong>Secure Endpoint Configuration Managers</strong></h3>\n<ul type=\"square\">\n<li>Treat endpoint management systems (such as SCCM) as HVAs with additional restrictions and monitoring because they provide elevated access to thousands of hosts.</li>\n</ul>\n<h3><strong>Segment Operational Technology Networks</strong></h3>\n<ul type=\"square\">\n<li>Implement strict firewall rules and access controls between IT and OT environments [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementLogicalPhysicalNetworkSegmentation3I\" title=\"CPG 3.I\">CPG 3.I</a>].</li>\n<li>Limit jump server access to OT networks and require MFA for all connections.</li>\n<li>Regularly review OT network architecture and access paths to minimize unnecessary connectivity.</li>\n<li>Monitor OT network traffic for signs of lateral movement or unauthorized access.</li>\n<li>Implement change management solutions to track and restrict modifications to OT components.</li>\n</ul>\n<h2><strong>Validate Security Controls</strong></h2>\n<p>In addition to applying mitigations, CISA recommends exercising, testing, and validating your organization's security program against the threat behaviors mapped to the MITRE ATT&amp;CK Matrix for Enterprise framework in this advisory. CISA recommends testing your existing security controls inventory to assess how they perform against the ATT&amp;CK techniques described in this advisory.</p>\n<p>To get started:</p>\n<ol>\n<li>Select an ATT&amp;CK technique described in this advisory (see <a href=\"#Table2\"><strong>Table 2</strong></a> to <a href=\"#Table11\"><strong>Table 11</strong></a>).</li>\n<li>Align your security technologies against the technique.</li>\n<li>Test your technologies against the technique.</li>\n<li>Analyze your detection and prevention technologies\u2019 performance.</li>\n<li>Repeat the process for all security technologies to obtain a set of comprehensive performance data.</li>\n<li>Tune your security program, including people, processes, and technologies, based on the data generated by this process.</li>\n</ol>\n<p>CISA recommends continually testing your security program, at scale, in a production environment to ensure optimal performance against the MITRE ATT&amp;CK techniques identified in this advisory.</p>\n<h2><strong>Resources</strong></h2>\n<ul type=\"square\">\n<li>Microsoft: <a href=\"https://learn.microsoft.com/en-us/entra/identity/devices/concept-primary-refresh-token?tabs=windows-prt-issued%2Cbrowser-behavior-windows%2Cwindows-prt-used%2Cwindows-prt-renewal%2Cwindows-prt-protection%2Cwindows-apptokens%2Cwindows-browsercookies%2Cwindows-mfa\" target=\"_blank\" title=\"Understanding primary refresh token (PRT)\">Understanding primary refresh token (PRT)</a></li>\n<li>SpecterOps: <a href=\"https://specterops.io/wp-content/uploads/sites/3/2022/06/Certified_Pre-Owned.pdf\" target=\"_blank\" title=\"Certified pre-owned: Abusing Active Directory Certificate Services\">Certified pre-owned: Abusing Active Directory Certificate Services</a></li>\n</ul>\n<h2><strong>Contact Information</strong></h2>\n<p>Organizations are encouraged to report suspicious or criminal activity related to information in this advisory to CISA via CISA\u2019s 24/7 Operations Center at <a href=\"mailto:contact@cisa.dhs.gov\">contact@cisa.dhs.gov</a> or 1-844-Say-CISA (1-844-729-2472). When available, please include the following information regarding the incident:</p>\n<ul type=\"square\">\n<li>Date, time, and location of the incident;</li>\n<li>Type of activity;</li>\n<li>Number of people affected;</li>\n<li>Type of equipment used for the activity; and</li>\n<li>Name of the submitting company or organization, and a designated point of contact.</li>\n</ul>\n<h2><strong>Disclaimer</strong></h2>\n<p>The information in this report is being provided \u201cas is\u201d for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA.</p>\n<h2><strong>Version History</strong></h2>\n<p><strong>August 25, 2026</strong>: Initial version.</p>\n<h2><strong>Notes</strong></h2>\n<p><a class=\"ck-anchor\" id=\"Note1\"><sup>1</sup></a> \u201cSpecterOps&nbsp;/ Bloodhound,\u201d GitHub, last modified July 15, 2026, <a href=\"https://github.com/SpecterOps/BloodHound\" target=\"_blank\">https://github.com/SpecterOps/BloodHound</a>.</p>\n<p><a class=\"ck-anchor\" id=\"Note2\"><sup>2</sup></a> \u201cSpecterOps&nbsp;/&nbsp;AzureHound,\u201d GitHub, last modified June 4, 2026, <a href=\"https://github.com/SpecterOps/AzureHound\" target=\"_blank\">https://github.com/SpecterOps/AzureHound</a>.</p>\n<p><a class=\"ck-anchor\" id=\"Note3\"><sup>3</sup></a> \u201cROADrecon,\u201d GitHub, <a href=\"https://github.com/dirkjanm/ROADtools/tree/master/roadrecon\" target=\"_blank\">https://github.com/dirkjanm/ROADtools/tree/master/roadrecon</a>.</p>\n<p><a class=\"ck-anchor\" id=\"Note4\"><sup>4</sup></a> \u201cdirkjanm/adconnectdumb,\u201d GitHub, last modified August 25, 2026, <a href=\"https://github.com/dirkjanm/adconnectdump\" target=\"_blank\">https://github.com/dirkjanm/adconnectdump</a>.</p>",
        "summary_is_html": true,
        "first_seen": "Tue, 25 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 25 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/25/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/25/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a class=\"fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn\" href=\"https://www.cve.org/CVERecord?id=CVE-2026-60004\" target=\"_blank\" title=\"https://www.cve.org/cverecord?id=cve-2026-60004\" id=\"menur1m61\" rel=\"noreferrer noopener\">CVE-2026-60004</a> Gitea Code Injection Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://edit.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a class=\"ext\" href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Tue, 25 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 25 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-02",
        "title": "Zoneminder",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could result in full Remote Code Execution (RCE) as the web server user.</strong></p>\n<p>The following versions of Zoneminder are affected:</p>\n<ul>\n<li>Zoneminder 1.37.48|1.38.3&nbsp;</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.8</td>\n<td>Zoneminder</td>\n<td>Zoneminder</td>\n<td>Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-76060</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An authenticated OS Command Injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-76060\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Zoneminder</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Zoneminder</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Zoneminder Zoneminder: 1.37.48|1.38.3</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Zoneminder recommends upgrading to version 1.38.3 or later by downloading the installer for your system at: https://zoneminder.com/downloads.<br><a href=\"https://zoneminder.com/downloads\">https://zoneminder.com/downloads</a></p>\n<p><strong>Vendor fix</strong><br>Users may also get the source code from Zoneminder's Github: https://github.com/ZoneMinder/zoneminder.<br><a href=\"https://github.com/ZoneMinder/zoneminder\">https://github.com/ZoneMinder/zoneminder</a></p>\n<p><strong>Vendor fix</strong><br>For more details refer to Zoneminder's security advisories at: https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-88m4-hrgp-m9v3.<br><a href=\"https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-88m4-hrgp-m9v3\">https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-88m4-hrgp-m9v3</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/78.html\">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>CISA discovered a public Proof of Concept (PoC) as authored by Scriptkittens and reported it to Zoneminder</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-25</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-25</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 25 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 25 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-03",
        "title": "Siemens SIMATIC IoT2050 Advanced",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-03",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-03.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released a new version for SIMATIC IoT2050 Advanced and strongly recommends to update to the latest version.</strong></p>\n<p>The following versions of Siemens SIMATIC IoT2050 Advanced are affected:</p>\n<ul>\n<li>SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) vers:intdot/&lt;4.3.4.1</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 10</td>\n<td>Siemens</td>\n<td>Siemens SIMATIC IoT2050 Advanced</td>\n<td>Missing Authentication for Critical Function</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Critical Manufacturing, Energy, Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-58115</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-58115\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SIMATIC IoT2050 Advanced</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) &lt; V4.3.4.1 running Industrial OS with Node-RED installed</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Harden the Node-RED installation (see Node-RED User Guide)</p>\n<p><strong>Mitigation</strong><br>Uninstall Node-RED</p>\n<p><strong>Vendor fix</strong><br>Update to V4.3.4.1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109741799/\">https://support.industry.siemens.com/cs/ww/en/view/109741799/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>10</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-834709 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-11</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-11</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-08-25</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-834709 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 25 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 25 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-07",
        "title": "FURUNO FA-50 Class B AIS Transponder",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-07",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-07.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to alter device settings.</strong></p>\n<p>The following versions of FURUNO FA-50 Class B AIS Transponder are affected:</p>\n<ul>\n<li>FURUNO FA-50 Class B AIS Transponder vers:all/*</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.1</td>\n<td>FURUNO ELECTRIC CO.,LTD.</td>\n<td>FURUNO FA-50 Class B AIS Transponder</td>\n<td>Use of Hard-coded Credentials, Missing Authentication for Critical Function</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Japan</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-59769</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An attacker, who knows the credentials and has access to the in-vessel network to which the device is connected to, may operate the settings screen using that credentials to alter the settings of the device.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-59769\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>FURUNO FA-50 Class B AIS Transponder</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>FURUNO ELECTRIC CO.,LTD.</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>FURUNO FA-50 Class B AIS Transponder: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>FURUNO ELECTRIC CO.,LTD. notes that production of this product ended in October 2020, and software updates will no longer be provided. FURUNO recommends users do not connect the product directly to the internet. To prevent unauthorized access, the vessel on which the product is installed should be properly locked and managed.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/798.html\">CWE-798 Use of Hard-coded Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.1</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-67578</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Some configurations may be changed on the management screen without authentication.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-67578\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>FURUNO FA-50 Class B AIS Transponder</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>FURUNO ELECTRIC CO.,LTD.</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>FURUNO FA-50 Class B AIS Transponder: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>FURUNO ELECTRIC CO.,LTD. notes that production of this product ended in October 2020, and software updates will no longer be provided. FURUNO recommends users do not connect the product directly to the internet. To prevent unauthorized access, the vessel on which the product is installed should be properly locked and managed.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Souvik Kandar reported these vulnerabilities to CISA</li>\n<li>JPCERT/CC coordinated with Furuno Electric and CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-25</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-25</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 25 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 25 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-05",
        "title": "Bendix EC80 Brake ECU",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-05",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-05.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to cause the loss of ABS functions, steering assist, speedometer, shifting capabilities, or disable automatic traction control.</strong></p>\n<p>The following versions of Bendix EC80 Brake ECU are affected:</p>\n<ul>\n<li>EC80ESP+ J1708 Z228999</li>\n<li>EC80ESP+ 6S/6M Z228999</li>\n<li>EC80ESP+ PLC Z228999&nbsp;</li>\n<li>EC80ESP+ 2nd CAN Z228999</li>\n<li>EC80ESP+ Integrated TPMS Z228999</li>\n<li>EC80ESP 6S/6M Z266494&nbsp;</li>\n<li>EC80ESP PLC Z266494&nbsp;</li>\n<li>EC80ESP 2nd CAN Z266494</li>\n<li>EC80ESP CAN Gateway Z266494&nbsp;</li>\n<li>EC80ESP 4S/4M Z286098&nbsp;</li>\n<li>EC80ESP PLC Z286098&nbsp;</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>Bendix</td>\n<td>Bendix EC80 Brake ECU</td>\n<td>Stack-based Buffer Overflow, Out-of-bounds Write, Use of Hard-coded Credentials</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>United States, Canada</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-67560</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering assist, speedometer, and shifting.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-67560\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Bendix EC80 Brake ECU</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Bendix</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Bendix EC80ESP+ J1708: Z228999, Bendix EC80ESP+ 6S/6M: Z228999, Bendix EC80ESP+ PLC: Z228999, Bendix EC80ESP+ 2nd CAN: Z228999, Bendix EC80ESP+ Integrated TPMS: Z228999, Bendix EC80ESP 6S/6M: Z266494, Bendix EC80ESP PLC: Z266494, Bendix EC80ESP 2nd CAN: Z266494, Bendix EC80ESP CAN Gateway: Z266494, Bendix EC80ESP 4S/4M: Z286098, Bendix EC80ESP PLC: Z286098</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Bendix recommends users update their firmware to the most recent firmware version releases. Users that need more help should contact Bendix directly at info@Bendix.com.<br><a href=\"mailto:info@Bendix.com\">mailto:info@Bendix.com</a></p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ J1708: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ 6S/6M: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ PLC: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ 2nd CAN: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ Integrated TPMS: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP 6S/6M: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP PLC: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP 2nd CAN: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP CAN Gateway: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP 4S/4M: Z286098 users should update their firmware to version Z302579.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP PLC: Z286098 users should update their firmware to version Z302579.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/121.html\">CWE-121 Stack-based Buffer Overflow</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-68967</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that could establish an arbitrary write primitive, which could crash the ECU.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-68967\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Bendix EC80 Brake ECU</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Bendix</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Bendix EC80ESP+ J1708: Z228999, Bendix EC80ESP+ 6S/6M: Z228999, Bendix EC80ESP+ PLC: Z228999, Bendix EC80ESP+ 2nd CAN: Z228999, Bendix EC80ESP+ Integrated TPMS: Z228999, Bendix EC80ESP 6S/6M: Z266494, Bendix EC80ESP PLC: Z266494, Bendix EC80ESP 2nd CAN: Z266494, Bendix EC80ESP CAN Gateway: Z266494, Bendix EC80ESP 4S/4M: Z286098, Bendix EC80ESP PLC: Z286098</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Bendix recommends users update their firmware to the most recent firmware version releases. Users that need more help should contact Bendix directly at info@Bendix.com.<br><a href=\"mailto:info@Bendix.com\">mailto:info@Bendix.com</a></p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ J1708: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ 6S/6M: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ PLC: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ 2nd CAN: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ Integrated TPMS: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP 6S/6M: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP PLC: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP 2nd CAN: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP CAN Gateway: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP 4S/4M: Z286098 users should update their firmware to version Z302579.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP PLC: Z286098 users should update their firmware to version Z302579.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-71396</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product uses hard-coded credentials, which could allow an attacker to disable automatic traction control.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-71396\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Bendix EC80 Brake ECU</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Bendix</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Bendix EC80ESP+ J1708: Z228999, Bendix EC80ESP+ 6S/6M: Z228999, Bendix EC80ESP+ PLC: Z228999, Bendix EC80ESP+ 2nd CAN: Z228999, Bendix EC80ESP+ Integrated TPMS: Z228999, Bendix EC80ESP 6S/6M: Z266494, Bendix EC80ESP PLC: Z266494, Bendix EC80ESP 2nd CAN: Z266494, Bendix EC80ESP CAN Gateway: Z266494, Bendix EC80ESP 4S/4M: Z286098, Bendix EC80ESP PLC: Z286098</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Bendix recommends users update their firmware to the most recent firmware version releases. Users that need more help should contact Bendix directly at info@Bendix.com.<br><a href=\"mailto:info@Bendix.com\">mailto:info@Bendix.com</a></p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ J1708: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ 6S/6M: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ PLC: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ 2nd CAN: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ Integrated TPMS: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP 6S/6M: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP PLC: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP 2nd CAN: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP CAN Gateway: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP 4S/4M: Z286098 users should update their firmware to version Z302579.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP PLC: Z286098 users should update their firmware to version Z302579.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/798.html\">CWE-798 Use of Hard-coded Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.4</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Ben Gardiner of NMFTA reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-25</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-25</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 25 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 25 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06",
        "title": "Ebyte NE2-D11",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized administrative access, disclose sensitive information, modify device configuration, hijack authenticated sessions, and disrupt device operation.</strong></p>\n<p>The following versions of Ebyte NE2-D11 are affected:</p>\n<ul>\n<li>NE2-D11 Firmware FW-9167-0-11</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.8</td>\n<td>Ebyte</td>\n<td>Ebyte NE2-D11</td>\n<td>Missing Authentication for Critical Function, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials, Use of Client-Side Authentication, Use of GET Request Method With Sensitive Query Strings, Cross-Site Request Forgery (CSRF), Improper Restriction of Excessive Authentication Attempts, Improper Restriction of Rendered UI Layers or Frames, Missing Authorization</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>China</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-73125</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-73125\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NE2-D11</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NE2-D11 Firmware: FW-9167-0-11</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-73809</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web management interface does not adequately protect sensitive communications using transport-layer encryption. An attacker with access to network traffic could intercept authentication or session-related information transmitted between a user and the affected device. Successful exploitation could result in disclosure of sensitive information and unauthorized access to device management functionality.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-73809\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NE2-D11</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NE2-D11 Firmware: FW-9167-0-11</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/319.html\">CWE-319 Cleartext Transmission of Sensitive Information</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-73839</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Administrative credentials may be exposed in plaintext within the Ebyte device's management interface, increasing the risk of credential compromise through visual or remote observation. This undermines the confidentiality of device access.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-73839\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NE2-D11</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NE2-D11 Firmware: FW-9167-0-11</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/522.html\">CWE-522 Insufficiently Protected Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>4.6</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.1</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-71187</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtain administrative access to the device.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-71187\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NE2-D11</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NE2-D11 Firmware: FW-9167-0-11</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/603.html\">CWE-603 Use of Client-Side Authentication</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-76179</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during client-side session handling, which may allow an attacker with access to exposed session information to obtain and reuse a valid token. Successful exploitation could allow an attacker to impersonate an authenticated user and gain unauthorized access to device management functionality.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-76179\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NE2-D11</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NE2-D11 Firmware: FW-9167-0-11</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/598.html\">CWE-598 Use of GET Request Method With Sensitive Query Strings</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-75814</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management interface. An unauthenticated remote attacker could persuade an authenticated administrator to visit a crafted page, causing unauthorized configuration changes or a disruption of device availability.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-75814\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NE2-D11</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NE2-D11 Firmware: FW-9167-0-11</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/352.html\">CWE-352 Cross-Site Request Forgery (CSRF)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-76940</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected Ebyte device does not restrict repeated authentication attempts through rate limiting or account lockout mechanisms. This could allow an attacker to perform automated authentication attacks against deployments that rely on password based authentication.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-76940\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NE2-D11</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NE2-D11 Firmware: FW-9167-0-11</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/307.html\">CWE-307 Improper Restriction of Excessive Authentication Attempts</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-75548</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected Ebyte device web management interface does not restrict the interface from being rendered within an external frame. An unauthenticated remote attacker could use a crafted webpage to mislead an authenticated administrator into initiating unintended configuration changes or disruptive actions.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-75548\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NE2-D11</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NE2-D11 Firmware: FW-9167-0-11</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/1021.html\">CWE-1021 Improper Restriction of Rendered UI Layers or Frames</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.4</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-75813</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthorized users to access or modify sensitive device settings. This could result in full compromise of device functionality.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-75813\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NE2-D11</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NE2-D11 Firmware: FW-9167-0-11</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/862.html\">CWE-862 Missing Authorization</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-76945</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected Ebyte device relies on client-managed authentication tokens without sufficient server-side validation. An attacker may replay or manipulate authentication tokens to gain unauthorized access to administrative functionality.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-76945\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NE2-D11</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NE2-D11 Firmware: FW-9167-0-11</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/603.html\">CWE-603 Use of Client-Side Authentication</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-69658</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device impersonation and disruption of messaging functions.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-69658\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NE2-D11</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NE2-D11 Firmware: FW-9167-0-11</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/319.html\">CWE-319 Cleartext Transmission of Sensitive Information</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Jithin Nambiar reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-25</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-25</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 25 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 25 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/24/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/24/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://edit.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-21962\" target=\"_blank\">CVE-2026-21962</a> Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://edit.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://edit.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://edit.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a class=\"ext\" href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Mon, 24 Aug 26 12:00:00 +0000",
        "last_updated": "Mon, 24 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/21/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/21/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-73570\" target=\"_blank\">CVE-2026-73570</a> Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Fri, 21 Aug 26 12:00:00 +0000",
        "last_updated": "Fri, 21 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-232-01",
        "title": "Johnson Controls Simplex Incident Manager",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-232-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-232-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems.</strong></p>\n<p>The following versions of Johnson Controls Simplex Incident Manager are affected:</p>\n<ul>\n<li>Simplex Incident Manager &lt;=V2.01 (CVE-2026-27875)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 5.8</td>\n<td>Johnson Controls Inc.</td>\n<td>Johnson Controls Simplex Incident Manager</td>\n<td>Cleartext Storage of Sensitive Information in Memory</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Ireland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-27875</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Simplex Incident Manager application stores user credentials (such as passwords and authentication tokens) in an unencrypted form within system memory while running. This exposes sensitive information to potential extraction by anyone with local access to the system, including attackers leveraging memory-dumping tools or insiders with elevated privileges.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-27875\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls Simplex Incident Manager</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls Inc.</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls Simplex Incident Manager: &lt;=V2.01</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Johnson Controls has released a patched version (v2.01.01) to address this vulnerability. To help reduce the risk of exploitation, Johnson Controls suggests considering the following defensive measures: Upgrade the Simplex Incident Manager to version v1.01.05 or later. Restrict local access to systems running the Simplex Incident Manager to authorized personnel only. Implement endpoint protection and monitoring to detect memory-dumping tools or suspicious processes. Enforce strong access control policies and the principle of least privilege on host systems. Utilize full-disk encryption and secure boot to reduce the risk of offline memory analysis. Monitor for unauthorized local access attempts and implement audit logging.</p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-28.<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories\">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>\n<p><strong>Mitigation</strong><br>Aligning with CISA recommendations, Johnson Controls recommends taking steps to minimize risks to all building automation systems.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/316.html\">CWE-316 Cleartext Storage of Sensitive Information in Memory</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L\">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Johnson Controls reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely. This vulnerability has a high attack complexity.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-20</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-20</td>\n<td>1</td>\n<td>Initial Republication of Johnson Controls Product Security Advisory JCI-PSA-2026-28</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 20 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 20 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/20/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Two Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/20/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added two new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-72529\" target=\"_blank\">CVE-2026-72529</a> TrueConf Server Missing Authentication for Critical Function Vulnerability &nbsp;</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-72530\" target=\"_blank\">CVE-2026-72530</a> TrueConf Server Code Injection Vulnerability</li>\n</ul>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Thu, 20 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 20 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/19/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/19/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-64849\" target=\"_blank\">CVE-2026-64849</a> MLflow Server-Side Request Forgery Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Wed, 19 Aug 26 12:00:00 +0000",
        "last_updated": "Wed, 19 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a",
        "title": "Defending Against an Active Threat to Siemens S7 Series PLCs",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a",
        "summary": "<h2><strong>Executive summary</strong></h2>\n<p><em><strong>Note:</strong> This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape.</em></p>\n<p><strong>Top Mitigations</strong></p>\n<ul type=\"disc\">\n<li><strong>Inventory&nbsp;</strong>all Siemens S7 Series programmable logic controllers (PLCs)</li>\n<li><strong>Apply&nbsp;</strong>critical security patches<strong>&nbsp;</strong></li>\n<li><strong>Ensure&nbsp;</strong>PLCs are <strong>not&nbsp;</strong>accessible<strong>&nbsp;</strong>from the Internet</li>\n<li><strong>Strengthen&nbsp;</strong>access controls</li>\n<li><strong>Monitor&nbsp;</strong>for unauthorized activity</li>\n<li><strong>Harden&nbsp;</strong>PLC services, protocols, and ladder logic integrity<strong>&nbsp;</strong></li>\n<li><strong>Hunt&nbsp;</strong>for anomalies that may indicate a compromise</li>\n</ul>\n<p>The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA)\u2014hereafter referred to as the authoring agencies\u2014are releasing this Cybersecurity Advisory to warn owners and operators of industrial control systems (ICSs) of an active cyber threat to Siemens S7 Series PLCs and provide relevant mitigations to protect and defend them.&nbsp;</p>\n<p>The threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools. The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected. The U.S. critical infrastructure sectors most targeted by this threat activity include <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/critical-manufacturing-sector\">Critical Manufacturing</a>, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/energy-sector\">Energy</a>, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/water-and-wastewater-sector\">Water and Wastewater</a>, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/chemical-sector\">Chemical</a>, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/food-and-agriculture-sector\">Food and Agriculture</a>, and <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/commercial-facilities-sector\">Commercial Facilities</a>. This is not a theoretical risk\u2014it is an active threat. Depending on the specific circumstances, exploitation of poorly protected PLCs&nbsp;could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems.&nbsp;</p>\n<p>The authoring agencies urge all owners and operators of operational technology (OT) systems using Siemens S7 Series and other PLC devices to proactively check their systems:</p>\n<ul type=\"disc\">\n<li>are properly protected with all applicable security patches and updates,&nbsp;</li>\n<li>are isolated from the Internet wherever possible,&nbsp;</li>\n<li>have strong access controls, and&nbsp;</li>\n<li>employ security tooling to monitor ICS environments for anomalous or malicious activity.</li>\n</ul>\n<p>These mitigations are particularly important for owners and operators who work with third-party service providers or system integrators who may have remote access to PLCs, as the asset owners may not realize that their systems are exposed and at risk.</p>\n<h2><strong>Technical details</strong></h2>\n<p><strong>Note:</strong>&nbsp;This advisory uses the <a href=\"https://attack.mitre.org/versions/v19/matrices/ics/\" target=\"_blank\">MITRE ATT&amp;CK<sup>\u00ae</sup>&nbsp;Matrix for ICS</a><a href=\"#Note1\"><strong><sup>1</sup></strong></a> framework, version 19, and the&nbsp;<a href=\"https://attack.mitre.org/versions/v19/matrices/enterprise/\" target=\"_blank\" title=\"MITRE ATTACK Matrix for Enterprise\">MITRE ATT&amp;CK&nbsp;Matrix for Enterprise</a>&nbsp;framework, version 19.&nbsp;This advisory also uses <a href=\"https://d3fend.mitre.org/\" target=\"_blank\">MITRE D3FEND<sup>TM</sup></a>, version 1.5.0. See <a href=\"#AppA\"><strong>Appendix A</strong></a> and <a href=\"#AppB\"><strong>Appendix B</strong></a> for tables of the activity mapped to MITRE ATT&amp;CK and MITRE D3FEND tactics, techniques, and countermeasures.</p>\n<h3><em><strong>Threat actor targeting</strong></em></h3>\n<p>Threat actors are actively targeting the following Siemens PLC models:</p>\n<ul type=\"disc\">\n<li><strong>S7-200 Series</strong>&nbsp;(all CPU variants)</li>\n<li><strong>S7-300 Series</strong>&nbsp;(all CPU variants including 314, 315, 317 models)</li>\n<li><strong>S7-400 Series</strong>&nbsp;(all CPU variants)</li>\n<li><strong>S7-1200 Series</strong>&nbsp;(CPU 1211C, 1212C, 1214C, 1215C, 1217C variants)</li>\n<li><strong>S7-1500 Series</strong>&nbsp;(all CPU variants, including F-series safety controllers)</li>\n</ul>\n<p>Threat actors are using AI assistance to generate exploitation scripts using publicly available information on these Siemens S7 Series PLCs for initial access, credential access, denial of service, and other objectives. If these PLCs are exposed to the Internet or insufficiently segmented, then threat actors can exploit various critical and high severity known vulnerabilities in these PLCs.</p>\n<p><strong>Note:</strong>&nbsp;Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools. In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures. Threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploitable PLCs, and use AI-generated scripts to act on that information. If PLCs are exposed to the Internet, they are at high risk for exploitation.&nbsp;</p>\n<p>Threat actors are leveraging open source industrial automation libraries\u2014specifically <code>snap7.dll</code>/<code>python-snap7</code>\u2014combined with AI-assisted scripting to create custom tools that mimic legitimate OT monitoring solutions. These tools provide read/write access to Siemens S7 Series PLC memory, configuration data, and ladder logic programs via the S7comm protocol.</p>\n<h3><em><strong>Threat actor techniques</strong></em></h3>\n<p>Threat actors are:</p>\n<ul type=\"disc\">\n<li><strong>Using Internet scanning services</strong>&nbsp;(e.g., Censys, ZoomEye) to identify Internet-exposed or insufficiently segmented Siemens S7 Series PLCs [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1596/005/\" target=\"_blank\">T1596.005</a>]</li>\n<li><strong>Rapidly iterating exploit code</strong>&nbsp;through AI-assisted development, lowering technical barriers to ICS attacks [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1587/004/\" target=\"_blank\">T1587.004</a>, <a href=\"https://attack.mitre.org/versions/v19/techniques/T1588/007/\" target=\"_blank\">T1588.007</a>]</li>\n<li><strong>Taking advantage of insecure credentials</strong> to access exposed devices that have unconfigured (default) or minimally configured authentication [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1694/\" target=\"_blank\">T1694</a>]</li>\n<li><strong>Deploying AI-generated Python scripts</strong>&nbsp;that incorporate the <code>snap7.dll</code> library from public repositories [<a href=\"https://attack.mitre.org/versions/v19/techniques/T0834/\" target=\"_blank\">T0834</a>] to gain read/write access to the PLC and mimic legitimate tools</li>\n<li><strong>Masquerading malicious scripts as legitimate monitoring tools</strong>&nbsp;to evade detection by security teams [<a href=\"https://attack.mitre.org/versions/v19/techniques/T0849/\" target=\"_blank\">T0849</a>]</li>\n<li><strong>Conducting read/write operations</strong>&nbsp;on data blocks, potentially for reconnaissance, capability testing, or pre-positioning for effects operations [<a href=\"https://attack.mitre.org/versions/v19/techniques/T0893/\" target=\"_blank\">T0893</a>, <a href=\"https://attack.mitre.org/versions/v19/techniques/T0821/\" target=\"_blank\">T0821</a>]</li>\n</ul>\n<p>The authoring agencies assess this activity pattern is likely intended as persistent reconnaissance in targeted sectors and facilities to develop capabilities and prepare to cause operational effects against critical infrastructure. For capability development, actors are testing and refining their exploitation techniques against specific PLC models to improve their ability to compromise the PLCs. To prepare for operational effects, actors are leveraging read access to understand target environments, enabling preparation and positioning for future write operations to cause disruption or other operational impacts.</p>\n<h3><em><strong>Potential operational impacts</strong></em></h3>\n<p>The U.S. critical infrastructure sectors most targeted by this threat activity include <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/critical-manufacturing-sector\">Critical Manufacturing</a>, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/energy-sector\">Energy</a>, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/water-and-wastewater-sector\">Water and Wastewater</a>, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/chemical-sector\">Chemical</a>, <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/food-and-agriculture-sector\">Food and Agriculture</a>, and <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/commercial-facilities-sector\">Commercial Facilities</a>. Additionally, Siemens S7 Series PLCs are used in other sectors, including the <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/defense-industrial-base-sector\">Defense Industrial Base (DIB)</a>, and could be targeted there as well. Unauthorized access to PLCs could result in:</p>\n<ul type=\"disc\">\n<li><strong>Disruption of critical industrial processes</strong>&nbsp;affecting production throughput, product quality, and public services</li>\n<li><strong>Safety incidents affecting personnel</strong>&nbsp;through manipulation of safety interlocks, emergency shutdown systems, or process parameters</li>\n<li><strong>Equipment damage and extended operational downtime</strong>&nbsp;from process upsets, improper sequencing, or forced equipment operation outside design parameters</li>\n<li><strong>Compromise of sensitive operational data</strong>,&nbsp;including proprietary process recipes, control strategies, and facility configurations</li>\n<li><strong>Cascading impacts across interconnected systems</strong>&nbsp;affecting supply chains, dependent facilities, and integrated business operations</li>\n<li><strong>Regulatory compliance violations</strong>&nbsp;and potential liability from process safety management failures</li>\n</ul>\n<h2><strong>Mitigation actions</strong></h2>\n<p>Since threat actors are developing capabilities using AI to compromise PLCs using known vulnerabilities, misconfigurations, and other weaknesses and then may use compromised PLCs to interfere with normal operations, the authoring agencies urge organizations to implement comprehensive defense-in-depth strategies, in addition to Common Vulnerabilities and Exposures (CVE) remediation, to protect and defend their PLCs.</p>\n<h3><em><strong>Detection opportunities</strong></em></h3>\n<p>Organizations should implement detection strategies and hunt for anomalies that may indicate a compromise, focusing on [<a href=\"https://d3fend.mitre.org/technique/d3f:PlatformMonitoring/\" target=\"_blank\">D3-PM</a>]:</p>\n<ul type=\"disc\">\n<li><strong>Anomalous S7comm behavior:</strong>&nbsp;Connections from non-engineering workstations, unusual data block access patterns, or write operations outside change windows</li>\n<li><strong>Reconnaissance indicators:</strong>&nbsp;Sequential IP scanning on port <code>102</code>, repeated connection attempts with varying parameters, or enumeration of CPU properties</li>\n<li><strong>Tool artifacts:</strong>&nbsp;<code>Snap7.dll</code> library usage outside approved engineering workstations, Python scripts with S7comm functionality, or unauthorized monitoring software installations</li>\n<li><strong>Temporal anomalies:</strong>&nbsp;S7comm activity during off-hours, unexpected connection patterns consistent with automated scripting rather than human operators, or configuration changes without corresponding work orders or change tickets</li>\n<li><strong>Geographic anomalies:</strong>&nbsp;Connections originating from unexpected countries or IP ranges not associated with vendors or integrators</li>\n</ul>\n<h3><em><strong>Preventative hardening actions</strong></em></h3>\n<p>To counter threats to PLCs, the authoring agencies recommend all PLC owners and operators follow the mitigations in joint guidance <a href=\"https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology\">Primary Mitigations to Reduce Cyber Threats to Operational Technology</a>.</p>\n<p>To harden Siemens S7 Series PLCs, the authoring agencies strongly urge all owners implement the hardening steps below. Entities that rely on systems integrators or third-party managed service providers should share this advisory with those parties and request implementation of the following mitigations:</p>\n<h4><strong>1. Conduct an immediate inventory of all Siemens S7 Series PLCs in your environment [</strong><a href=\"https://d3fend.mitre.org/technique/d3f:HardwareComponentInventory/\" target=\"_blank\"><strong>D3-HCI</strong></a><strong>]:</strong></h4>\n<ul type=\"disc\">\n<li>Verify current firmware versions for all S7-200, S7-300, S7-400, S7-1200, and S7-1500 controllers against backup gold copy</li>\n<li>Identify any systems directly or indirectly accessible from untrusted networks</li>\n<li>Map all engineering workstations with Totally Integrated Automation (TIA) Portal, STEP 7, or S7 programming access</li>\n</ul>\n<h4><strong>2. Apply critical security patches as soon as possible [</strong><a href=\"https://d3fend.mitre.org/technique/d3f:SoftwareUpdate/\"><strong>D3-SU</strong></a><strong>]:</strong></h4>\n<ul type=\"disc\">\n<li>Update Siemens S7 Series PLC firmware to the latest versions that address known vulnerabilities</li>\n<li>Prioritize Internet-facing or demilitarized zone (DMZ)-resident controllers</li>\n<li>Update TIA Portal and STEP 7 software to current versions</li>\n<li>Consult <a href=\"https://www.siemens.com/en-us/content/cert-services/#6cOXgBJ3xa94mcOefayaUh\" target=\"_blank\">Siemens ProductCERT advisories</a> for information on known vulnerabilities, along with relevant workarounds and mitigations</li>\n<li>Test all updates in a development environment before production deployment</li>\n</ul>\n<h4><strong>3. Verify network segmentation and ensure PLCs are NOT accessible from the Internet [</strong><a href=\"https://d3fend.mitre.org/technique/d3f:NetworkIsolation/\" target=\"_blank\"><strong>D3-NI</strong></a><strong>]:</strong></h4>\n<ul type=\"disc\">\n<li>Audit firewall rules for any exposed S7comm services (Transmission Control Protocol [TCP] port <code>102</code>)</li>\n<li>Block TCP port <code>102</code> at perimeter firewalls entirely</li>\n<li>Implement a DMZ architecture that separates OT and IT networks</li>\n<li>Deploy unidirectional gateways for data historian connections where appropriate</li>\n<li>Verify there is no unauthorized routing between corporate and industrial networks</li>\n</ul>\n<h4><strong>4. Review and strengthen access controls [</strong><a href=\"https://d3fend.mitre.org/technique/d3f:NetworkAccessMediation/\" target=\"_blank\"><strong>D3-NAM</strong></a><strong>, </strong><a href=\"https://d3fend.mitre.org/technique/d3f:CredentialHardening/\" target=\"_blank\"><strong>D3-CH</strong></a><strong>]:</strong></h4>\n<ul type=\"disc\">\n<li>Restrict TIA Portal/STEP 7 access to authorized engineering workstations only by MAC/IP allowlisting on PLCs</li>\n<li>Enable PLC password protection on all Siemens S7 Series controllers&nbsp;</li>\n<li>Configure protection levels (such as write protection and read/write protection) on Siemens S7 Series devices</li>\n<li>Remove or change default SNMP community strings</li>\n<li>Implement application allowlisting on all engineering workstations</li>\n<li>Enable multi-factor authentication for all remote access to OT networks</li>\n</ul>\n<h4><strong>5. Enable comprehensive logging and monitoring [</strong><a href=\"https://d3fend.mitre.org/technique/d3f:PlatformMonitoring/\" target=\"_blank\"><strong>D3-PM</strong></a><strong>, </strong><a href=\"https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis/\" target=\"_blank\"><strong>D3-NTA</strong></a><strong>]:</strong></h4>\n<ul type=\"disc\">\n<li>Deploy ICS-aware intrusion detection&nbsp;(e.g., Claroty, Dragos Platform, Nozomi Networks, or similar)</li>\n<li>Monitor all S7comm traffic on TCP port <code>102</code>&nbsp;for connections outside maintenance windows</li>\n<li>Alert on unauthorized PUT/GET operations, especially write commands to data blocks or configuration areas of memory</li>\n<li>Log all TIA Portal/STEP 7 connections to PLCs with timestamps and source IPs</li>\n<li>Establish a baseline for legitimate behavior and configure monitoring tools to alert on deviations</li>\n<li>Monitor for Python processes with <code>snap7.dll</code> library imports on engineering workstations</li>\n<li>Watch for sequential IP scanning patterns or block reads of configuration data</li>\n</ul>\n<h4><strong>6. Implement S7-specific hardening measures [</strong><a href=\"https://d3fend.mitre.org/technique/d3f:ApplicationConfigurationHardening/\" target=\"_blank\"><strong>D3-ACH</strong></a><strong>]:</strong></h4>\n<ul type=\"disc\">\n<li>Disable web servers on Siemens S7 Series devices if not operationally required</li>\n<li>Disable unused communication protocols (such as Modbus TCP and PROFINET, if they are not required)</li>\n<li>Configure connection resources to limit simultaneous S7comm sessions</li>\n<li>Enable TIA Portal/STEP 7 \u201ccomplete restart protection\u201d and \u201cknow-how protection\u201d features where available</li>\n<li>Evaluate for ladder logic changes in online/offline modes</li>\n</ul>\n<h4><strong>7. Contact Siemens for model-specific guidance:</strong></h4>\n<ul type=\"disc\">\n<li>Engage Siemens Technical Support for hardening recommendations specific to your CPU models and firmware versions</li>\n<li>Verify patch compatibility with your specific operational environment and third-party integrations</li>\n<li>Request assistance with protection level configuration and access control implementation</li>\n</ul>\n<h2><strong>Conclusion</strong></h2>\n<p>There is an active threat targeting Internet-exposed Siemens S7 Series PLCs. The combination of known vulnerabilities, accessible exploitation libraries, and AI-assisted development creates a high-probability attack scenario against inadequately protected PLC installations. Organizations should treat this Cybersecurity Advisory with urgency and coordinate response efforts across security, engineering, executive leadership, plant operations, and vendor support teams to implement the recommended detection and hardening actions.</p>\n<h2><strong>Resources</strong></h2>\n<ul>\n<li><a href=\"https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology\">Primary Mitigations to Reduce Cyber Threats to Operational Technology</a></li>\n<li><a href=\"https://www.ic3.gov/CSA/2026/260114.pdf\" target=\"_blank\">Secure connectivity principles for Operational Technology (OT): How organisations should design, secure, and manage connectivity in OT</a></li>\n<li><a href=\"https://media.defense.gov/2022/Sep/22/2003083007/-1/-1/0/CSA_ICS_Know_the_Opponent_.PDF\" target=\"_blank\">Control System Defense: Know the Opponent</a></li>\n</ul>\n<h2><strong>Incident reporting&nbsp;</strong></h2>\n<p>U.S. organizations are encouraged to report suspicious or criminal activity related to information in this advisory to CISA and/or the FBI. Contact CISA via CISA\u2019s 24/7 Operations Center at <a href=\"mailto:contact@cisa.dhs.gov\">contact@cisa.dhs.gov</a> or 1-844-Say-CISA (1-844-729-2472). File a claim with FBI\u2019s <a href=\"https://ic3.gov/\" target=\"_blank\">Internet Crime Complaint Center</a> (IC3) or contact your local <a href=\"https://www.fbi.gov/contact-us/field-offices\" target=\"_blank\">FBI field office</a>. When available, please include the following information regarding the incident:&nbsp;</p>\n<ul type=\"disc\">\n<li>Date, time, and location of the incident;</li>\n<li>Type of activity;</li>\n<li>Number of people affected;</li>\n<li>Type of equipment used for the activity; and</li>\n<li>Name of the submitting company or organization, and a designated point of contact.</li>\n</ul>\n<p>Entities required to report incidents to DOE should follow established reporting requirements, as appropriate. For other energy sector inquiries, contact <a href=\"mailto:EnergySRMA@hq.doe.gov\">EnergySRMA@hq.doe.gov</a>.</p>\n<p>In addition, consider contacting Siemens ProductCERT via <a href=\"https://www.siemens.com/cert\" target=\"_blank\">https://www.siemens.com/cert</a>&nbsp;or email&nbsp;<a href=\"mailto:productcert@siemens.com\">productcert@siemens.com</a>.&nbsp;</p>\n<p><em><strong>Disclaimer of endorsement</strong></em><br>The information and opinions contained in this document are provided \"as is\" and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes.</p>\n<p><em><strong>Purpose</strong></em><br>This document was developed in furtherance of the authoring agencies\u2019 cybersecurity missions, including their responsibilities to identify and disseminate threats and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.</p>\n<p><em><strong>Contact</strong></em><br>Cybersecurity Report Feedback:&nbsp;<a href=\"mailto:CybersecurityReports@nsa.gov\">CybersecurityReports@nsa.gov</a></p>\n<p>Defense Industrial Base Inquiries and Cybersecurity Services:&nbsp;<a href=\"mailto:DIB_Defense@cyber.nsa.gov\">DIB_Defense@cyber.nsa.gov</a></p>\n<p>Media Inquiries / Press Desk: NSA Media Relations: 443-634-0721,&nbsp;<a href=\"mailto:MediaRelations@nsa.gov\">MediaRelations@nsa.gov</a></p>\n<p>Contact Siemens ProductCERT for up-to-date information about the security of Siemens products or to report cybersecurity vulnerabilities at&nbsp;<a href=\"mailto:productcert@siemens.com\">productcert@siemens.com</a>. For support with increasing the security of installed Siemens PLCs, contact Siemens Industrial Cybersecurity Services at&nbsp;<a href=\"mailto:services.automation@siemens.com\">services.automation@siemens.com</a>. See&nbsp;<a href=\"https://www.siemens.com/en-us/content/cert-services/\" target=\"_blank\">Siemens ProductCERT and Siemens CERT</a> for more information.</p>\n<h2><a class=\"ck-anchor\" id=\"AppA\"><strong>Appendix A</strong></a><strong>: MITRE ATT&amp;CK tactics and techniques</strong></h2>\n<p>See <a href=\"#Table1\"><strong>Table 1</strong></a><strong> </strong>for the threat actor tactics and techniques referenced in this advisory.</p>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table1\"></a><em><strong>Table 1: MITRE ATT&amp;CK tactics and techniques</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<p class=\"text-align-center\"><strong>Tactic</strong></p>\n</th>\n<th role=\"columnheader\">\n<p class=\"text-align-center\"><strong>Technique Title</strong></p>\n</th>\n<th role=\"columnheader\">\n<p class=\"text-align-center\"><strong>ID</strong></p>\n</th>\n<th role=\"columnheader\">\n<p class=\"text-align-center\"><strong>Use</strong></p>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Reconnaissance</td>\n<td>Search Open Technical Databases: Scan Databases</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1596/005/\" target=\"_blank\">T1596.005</a></td>\n<td>Using Internet scanning services&nbsp;to identify Internet-exposed or poorly segmented Siemens S7 Series PLCs</td>\n</tr>\n<tr>\n<td>Resource Development</td>\n<td>Develop Capabilities: Exploits</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1587/004/\" target=\"_blank\">T1587.004</a></td>\n<td>Developing exploits for known Siemens S7 Series PLC vulnerabilities</td>\n</tr>\n<tr>\n<td>Resource Development</td>\n<td>Obtain Capabilities: Artificial Intelligence</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1588/007/\" target=\"_blank\">T1588.007</a></td>\n<td>Rapidly iterating exploit code&nbsp;through AI-assisted development</td>\n</tr>\n<tr>\n<td>Execution</td>\n<td>Native API</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T0834/\" target=\"_blank\">T0834</a></td>\n<td>Deploying AI-generated Python scripts&nbsp;incorporating the <code>snap7.dll</code> library</td>\n</tr>\n<tr>\n<td>Execution</td>\n<td>Modify Controller Tasking</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T0821/\" target=\"_blank\">T0821</a></td>\n<td>Conducting write operations&nbsp;on data blocks, potentially for pre-positioning for effects operations</td>\n</tr>\n<tr>\n<td>Evasion</td>\n<td>Masquerading</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T0849/\" target=\"_blank\">T0849</a></td>\n<td>Masquerading as legitimate monitoring tools&nbsp;to evade detection</td>\n</tr>\n<tr>\n<td>Lateral Movement</td>\n<td>Insecure Credentials</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1694/\" target=\"_blank\">T1694</a></td>\n<td>Accessing exposed devices that have unconfigured (default) or minimally configured authentication</td>\n</tr>\n<tr>\n<td>Collection</td>\n<td>Data from Local System</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T0893/\" target=\"_blank\">T0893</a></td>\n<td>Conducting read operations&nbsp;on data blocks, potentially for reconnaissance</td>\n</tr>\n</tbody>\n</table>\n<h2><a class=\"ck-anchor\" id=\"AppB\"><strong>Appendix B</strong></a><strong>: MITRE D3FEND countermeasures</strong></h2>\n<p>See <a href=\"#Table2\"><strong>Table 2</strong></a> for a mapping of several of the cybersecurity countermeasures mentioned in this advisory.</p>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table2\"></a><em><strong>Table 2: MITRE D3FEND Countermeasures</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<p class=\"text-align-center\"><strong>Countermeasure Title</strong></p>\n</th>\n<th role=\"columnheader\">\n<p class=\"text-align-center\"><strong>ID</strong></p>\n</th>\n<th role=\"columnheader\">\n<p class=\"text-align-center\"><strong>Description</strong></p>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Hardware Component Inventory</td>\n<td><a href=\"https://d3fend.mitre.org/technique/d3f:HardwareComponentInventory/\" target=\"_blank\">D3-HCI</a></td>\n<td>Conduct an immediate inventory of all Siemens S7 Series PLCs</td>\n</tr>\n<tr>\n<td>Software Update</td>\n<td><a href=\"https://d3fend.mitre.org/technique/d3f:SoftwareUpdate/\" target=\"_blank\">D3-SU</a></td>\n<td>Apply critical security patches as soon as possible</td>\n</tr>\n<tr>\n<td>Network Isolation</td>\n<td><a href=\"https://d3fend.mitre.org/technique/d3f:NetworkIsolation/\" target=\"_blank\">D3-NI</a></td>\n<td>Verify network segmentation and ensure PLCs are <strong>not</strong> accessible from the Internet</td>\n</tr>\n<tr>\n<td>Network Access Mediation</td>\n<td><a href=\"https://d3fend.mitre.org/technique/d3f:NetworkAccessMediation/\" target=\"_blank\">D3-NAM</a></td>\n<td>Restrict TIA Portal/STEP 7 access to authorized engineering workstations only via MAC/IP allowlisting on PLCs</td>\n</tr>\n<tr>\n<td>Credential Hardening</td>\n<td><a href=\"https://d3fend.mitre.org/technique/d3f:CredentialHardening/\" target=\"_blank\">D3-CH</a></td>\n<td>\n<ul type=\"disc\">\n<li>Enable PLC password protection on all S7 controllers</li>\n<li>Enable multi-factor authentication for all remote access to OT networks</li>\n</ul>\n</td>\n</tr>\n<tr>\n<td>Platform Monitoring</td>\n<td><a href=\"https://d3fend.mitre.org/technique/d3f:PlatformMonitoring/\" target=\"_blank\">D3-PM</a></td>\n<td>\n<ul type=\"disc\">\n<li>Deploy ICS-aware intrusion detection</li>\n<li>Alert on unauthorized PUT/GET operations</li>\n<li>Monitor for unexpected behavior deviations</li>\n<li>Monitor for <code>snap7.dll library</code> imports</li>\n<li>Hunt for indicators of compromise</li>\n</ul>\n</td>\n</tr>\n<tr>\n<td>Network Traffic Analysis</td>\n<td><a href=\"https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis/\" target=\"_blank\">D3-NTA</a></td>\n<td>\n<ul type=\"disc\">\n<li>Alert on unexpected S7comm traffic on TCP port <code>102</code>&nbsp;</li>\n<li>Watch for sequential IP scanning patterns</li>\n</ul>\n</td>\n</tr>\n<tr>\n<td>Application Configuration Hardening</td>\n<td><a href=\"https://d3fend.mitre.org/technique/d3f:ApplicationConfigurationHardening/\" target=\"_blank\">D3-ACH</a></td>\n<td>\n<ul type=\"disc\">\n<li>Disable unused web servers and protocols</li>\n<li>Remove SNMP community strings</li>\n<li>Watch for ladder logic changes</li>\n</ul>\n</td>\n</tr>\n</tbody>\n</table>\n<h2><strong>Notes</strong></h2>\n<p><a class=\"ck-anchor\" id=\"Note1\"><sup>1</sup></a> MITRE and ATT&amp;CK are registered trademarks of The MITRE Corporation. MITRE D3FEND is a trademark of the MITRE Corporation.</p>",
        "summary_is_html": true,
        "first_seen": "Wed, 19 Aug 26 12:00:00 +0000",
        "last_updated": "Wed, 19 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-230-02",
        "title": "Siemens Simcenter Nastran",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-230-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-230-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions for the affected products and recommends to update to the latest versions.</strong></p>\n<p>The following versions of Siemens Simcenter Nastran are affected:</p>\n<ul>\n<li>Simcenter Femap vers:intdot/&lt;2606 (CVE-2026-59086)</li>\n<li>Simcenter Nastran vers:intdot/&lt;2606 (CVE-2026-59086)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.8</td>\n<td>Siemens</td>\n<td>Siemens Simcenter Nastran</td>\n<td>Stack-based Buffer Overflow</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Defense Industrial Base, Energy, Healthcare and Public Health, Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-59086</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-59086\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Simcenter Nastran</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Simcenter Femap &lt; V2606, Simcenter Nastran &lt; V2606</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V2606 or later version<br><a href=\"https://support.sw.siemens.com/product/275652363/\">https://support.sw.siemens.com/product/275652363/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/121.html\">CWE-121 Stack-based Buffer Overflow</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Michael Heinzl reported this vulnerability to Siemens ProductCERT.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-069220 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-11</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-11</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-08-13</td>\n<td>2</td>\n<td>Added Simcenter Femap with fix</td>\n</tr>\n<tr>\n<td>2026-08-18</td>\n<td>3</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-069220 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 18 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 18 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-230-01",
        "title": "CISA Malcolm",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-230-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-230-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code.</strong></p>\n<p>The following versions of CISA Malcolm are affected:</p>\n<ul>\n<li>Malcolm &lt;26.06.1 (CVE-2026-55676)</li>\n<li>Malcolm &lt;26.07.0 (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177)</li>\n<li>Malcolm &lt;=26.07.1 (CVE-2026-19670, CVE-2026-19671)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.8</td>\n<td>CISA</td>\n<td>CISA Malcolm</td>\n<td>Allocation of Resources Without Limits or Throttling, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangerous Type, Incorrect Authorization, Improper Handling of Highly Compressed Data (Data Amplification)</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-63133</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, safe-extract.py extracts uploaded archives with no limit on entry count, directory depth, total entries, or output size. A small malicious archive containing a large number of directory or file entries causes the filebeat processing container to create an unbounded number of filesystem objects, exhausting inodes or filesystem metadata and denying service to the processing pipeline and any service sharing the same mount. Version 26.07.0 fixes the issue.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-63133\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>CISA Malcolm</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>CISA</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CISA Malcolm: &lt;26.07.0</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Malcolm version 26.07.0 addresses these issues. For more information, see https://github.com/cisagov/Malcolm/pull/1043. (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177)<br><a href=\"https://github.com/cisagov/Malcolm/pull/1043\">https://github.com/cisagov/Malcolm/pull/1043</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/770.html\">CWE-770 Allocation of Resources Without Limits or Throttling</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-63134</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, safe-extract.py protects file extraction with libarchive's secure flags, but creates directory entries with a raw os.makedirs(os.path.join(dest, entry.pathname)) that has no traversal protection. An uploaded malicious archive containing a directory entry with a ../ sequence or an absolute path causes the filebeat processing container to create directories outside the intended extraction directory. Version 26.07.0 fixes the issue.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-63134\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>CISA Malcolm</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>CISA</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CISA Malcolm: &lt;26.07.0</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Malcolm version 26.07.0 addresses these issues. For more information, see https://github.com/cisagov/Malcolm/pull/1043. (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177)<br><a href=\"https://github.com/cisagov/Malcolm/pull/1043\">https://github.com/cisagov/Malcolm/pull/1043</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/22.html\">CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.4</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-55676</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at POST /server/php/submit.php and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that should restrict accepted file types is an empty array by default (file-upload/php/config.php:16), so the type check is a no-op and every extension is accepted. The filename sanitizer keeps the .php extension intact. Committed files land in /var/www/upload/server/php/files (file-upload/php/config.php:7), and the component's nginx routes any URL ending in .php to php-fpm. An authenticated GET /server/php/files/.php then executes the uploaded code as www-data. Prior to version 26.06.1, in RBAC mode, the upload endpoint is reachable by the granular ROLE_UPLOAD role (nginx/lua/nginx_auth_helpers.lua:71), a role intended only for submitting capture files. As a result, a user holding the upload-only role runs arbitrary PHP as www-data inside the file-upload container. Version 26.06.1 fixes the issue.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-55676\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>CISA Malcolm</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>CISA</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CISA Malcolm: &lt;26.06.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Malcolm version 26.06.1 addresses this issue. For more information, see https://github.com/cisagov/Malcolm/pull/1026. (CVE-2026-55676)<br><a href=\"https://github.com/cisagov/Malcolm/pull/1026\">https://github.com/cisagov/Malcolm/pull/1026</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/434.html\">CWE-434 Unrestricted Upload of File with Dangerous Type</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-63177</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized ngx.var.request_uri, while Nginx itself routes requests using the normalized path. An authenticated low-privilege user can prepend a traversal segment (for example /x/../upload/...) so that Nginx routes the request to a restricted backend while the Lua role check fails to match any rule and falls open, granting access it should deny. Version 26.07.0 fixes the issue.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-63177\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>CISA Malcolm</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>CISA</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CISA Malcolm: &lt;26.07.0</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Malcolm version 26.07.0 addresses these issues. For more information, see https://github.com/cisagov/Malcolm/pull/1043. (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177)<br><a href=\"https://github.com/cisagov/Malcolm/pull/1043\">https://github.com/cisagov/Malcolm/pull/1043</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/863.html\">CWE-863 Incorrect Authorization</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:L/SI:L/SA:L\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:L/SI:L/SA:L</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-19670</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /auth, /admin_login, /arkime/api/esadmin, NetBox, upload endpoints) by pattern-matching the raw, percent-encoded request URI. Nginx itself, however, selects which location block actually serves the request using the percent-decoded, normalized URI. Because the RBAC check never percent-decodes its input, an authenticated low-privilege user can request an admin-only path using percent-encoding (e.g. /%68tadmin.php) and have nginx route it to the restricted location while the Lua RBAC gate evaluating the un-decoded raw string finds no matching restriction and grants access.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-19670\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>CISA Malcolm</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>CISA</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CISA Malcolm: &lt;=26.07.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Malcolm version 26.08.0 addresses this issue. For more information, see https://github.com/cisagov/Malcolm/security/advisories/GHSA-jr6p-63pg-hr6g. (CVE-2026-19670)<br><a href=\"https://github.com/cisagov/Malcolm/security/advisories/GHSA-jr6p-63pg-hr6g\">https://github.com/cisagov/Malcolm/security/advisories/GHSA-jr6p-63pg-hr6g</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/863.html\">CWE-863 Incorrect Authorization</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.4</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-19671</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extracting container archives (zip/tar/rar/7z via libarchive), but those limits are not applied when the uploaded file is a single-stream compressed format (.gz, .bz2, .xz, .lzma, .lz) that isn't a .tar.*-style archive. Any authenticated user permitted to upload PCAP/log files can upload a small, highly compressible file (e.g. a gzip bomb) that decompresses to an effectively unbounded size on disk, exhausting the shared Docker volume used by OpenSearch, Logstash, Arkime, and Zeek, and disrupting the platform for all users.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-19671\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>CISA Malcolm</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>CISA</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CISA Malcolm: &lt;=26.07.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Malcolm version 26.08.0 addresses this issue. For more information, see https://github.com/cisagov/Malcolm/security/advisories/GHSA-f2v6-8cj4-mhr6. (CVE-2026-19671)<br><a href=\"https://github.com/cisagov/Malcolm/security/advisories/GHSA-f2v6-8cj4-mhr6\">https://github.com/cisagov/Malcolm/security/advisories/GHSA-f2v6-8cj4-mhr6</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/409.html\">CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>pavanchow reported CVE-2026-63133, CVE-2026-63134, and CVE-2026-63177 to CISA.</li>\n<li>kah-ja, DeathRipper21 reported CVE-2026-55676 to CISA.</li>\n<li>tinyb0y reported CVE-2026-19670 and CVE-2026-19671 to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-18</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-18</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 18 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 18 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/18/cisa-adds-four-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Four Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/18/cisa-adds-four-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added four new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-33824\" target=\"_blank\">CVE-2026-33824</a> Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-55040\" target=\"_blank\">CVE-2026-55040</a> Microsoft SharePoint Weak Authentication Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-59310\" target=\"_blank\">CVE-2026-59310</a> Broadcom VMware vCenter Path Traversal Vulnerability &nbsp;</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-65400\" target=\"_blank\">CVE-2026-65400</a> Apple macOS Improper Authentication Vulnerability</li>\n</ul>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.</p>",
        "summary_is_html": true,
        "first_seen": "Tue, 18 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 18 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/17/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog\u00a0",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/17/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-62593\" target=\"_blank\">CVE-2025-62593</a> Ray-Project Ray Code Injection Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Mon, 17 Aug 26 12:00:00 +0000",
        "last_updated": "Mon, 17 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-13",
        "title": "Siemens LOGO! Soft Comfort",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-13",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-13.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt project data or remove project passwords. The lack of password salting enables offline dictionary or brute-force attacks against the password hashes. Successful exploitation could result in unauthorized access to, or modification of, sensitive project logic and configurations. Siemens has released a new version for LOGO! Soft Comfort and recommends to update to the latest version.</strong></p>\n<p>The following versions of Siemens LOGO! Soft Comfort are affected:</p>\n<ul>\n<li>LOGO! Soft Comfort vers:intdot/&lt;9 (CVE-2026-57262, CVE-2026-57263)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 6.8</td>\n<td>Siemens</td>\n<td>Siemens LOGO! Soft Comfort</td>\n<td>Use of Hard-coded Cryptographic Key, Use of a One-Way Hash without a Salt</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Commercial Facilities, Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-57262</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Affected products use a static, hardcoded AES master key to encrypt project files. This could allow a local attacker to extract the master key from the application files or memory and use it to decrypt project files or remove project passwords entirely without knowing the actual user-defined password.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-57262\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens LOGO! Soft Comfort</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>LOGO! Soft Comfort &lt; V9</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V9 or later version Note: A hardware upgrade to LOGO! V9 BM or later is also required to avoid compatibility mode, in which the vulnerabilities addressed by this advisory remain present.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/321.html\">CWE-321 Use of Hard-coded Cryptographic Key</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N\">CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-57263</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The project password feature in the affected products stores the password as an unsalted SHA-256 hash. This could allow an attacker who has obtained the project file to perform efficient offline dictionary or brute-force attacks against the unsalted hash.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-57263\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens LOGO! Soft Comfort</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>LOGO! Soft Comfort &lt; V9</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V9 or later version Note: A hardware upgrade to LOGO! V9 BM or later is also required to avoid compatibility mode, in which the vulnerabilities addressed by this advisory remain present.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/759.html\">CWE-759 Use of a One-Way Hash without a Salt</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N\">CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-751328 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-11</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-11</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-08-13</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-751328 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-225-01",
        "title": "Flow Neuroscience FL-100",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-225-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-225-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to manipulate brain stimulation parameters and override safety limits.</strong></p>\n<p>The following versions of Flow Neuroscience FL-100 are affected:</p>\n<ul>\n<li>Flow Neuroscience FL-100</li>\n<li>Halo Neuroscience FL-100</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.1</td>\n<td>Flow Neuroscience</td>\n<td>Flow Neuroscience FL-100</td>\n<td>Use of Hard-coded Credentials</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Healthcare and Public Health</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Sweden</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-18164</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth range to arbitrarilymanipulate brain stimulation parameters and state.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-18164\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Flow Neuroscience FL-100</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Flow Neuroscience</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Flow Neuroscience Flow Neuroscience FL-100: &lt;July_2026, Flow Neuroscience Halo Neuroscience FL-100: &lt;July_2026</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users are encouraged to install the latest firmware updates provided by Flow Neuroscience via the Flow app.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/798.html\">CWE-798 Use of Hard-coded Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>A.C. Buglione reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-13</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-13</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-12",
        "title": "Siemens Solid Edge",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-12",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-12.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.</strong></p>\n<p>The following versions of Siemens Solid Edge are affected:</p>\n<ul>\n<li>Solid Edge SE2025 vers:intdot/&lt;225.0.15 (CVE-2026-50058, CVE-2026-50059, CVE-2026-50060, CVE-2026-50061, CVE-2026-50062, CVE-2026-50063, CVE-2026-50064)</li>\n<li>Solid Edge SE2026 vers:intdot/&lt;226.0.7 (CVE-2026-50058, CVE-2026-50059, CVE-2026-50060, CVE-2026-50061, CVE-2026-50062, CVE-2026-50063, CVE-2026-50064)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.8</td>\n<td>Siemens</td>\n<td>Siemens Solid Edge</td>\n<td>Out-of-bounds Read, Out-of-bounds Write, Use After Free</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-50058</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected applications contains an out of bounds read vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-50058\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Solid Edge</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Solid Edge SE2025 &lt; V225.0.15, Solid Edge SE2026 &lt; V226.0.7</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V225.0 Update 15 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V226.0 Update 7 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-50059</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected applications contains an out of bounds write vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-50059\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Solid Edge</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Solid Edge SE2025 &lt; V225.0.15, Solid Edge SE2026 &lt; V226.0.7</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V225.0 Update 15 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V226.0 Update 7 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-50060</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-50060\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Solid Edge</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Solid Edge SE2025 &lt; V225.0.15, Solid Edge SE2026 &lt; V226.0.7</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V225.0 Update 15 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V226.0 Update 7 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/416.html\">CWE-416 Use After Free</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-50061</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-50061\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Solid Edge</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Solid Edge SE2025 &lt; V225.0.15, Solid Edge SE2026 &lt; V226.0.7</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V225.0 Update 15 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V226.0 Update 7 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/416.html\">CWE-416 Use After Free</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-50062</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected applications contains an out of bounds read vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-50062\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Solid Edge</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Solid Edge SE2025 &lt; V225.0.15, Solid Edge SE2026 &lt; V226.0.7</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V225.0 Update 15 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V226.0 Update 7 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-50063</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected applications contains an out of bounds read vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-50063\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Solid Edge</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Solid Edge SE2025 &lt; V225.0.15, Solid Edge SE2026 &lt; V226.0.7</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V225.0 Update 15 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V226.0 Update 7 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-50064</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected applications contains an out of bounds write vulnerability while parsing specially crafted PSM files. This could allow an attacker to execute code in the context of the current process.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-50064\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Solid Edge</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Solid Edge SE2025 &lt; V225.0.15, Solid Edge SE2026 &lt; V226.0.7</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V225.0 Update 15 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V226.0 Update 7 or later version<br><a href=\"https://support.sw.siemens.com/product/246738425/\">https://support.sw.siemens.com/product/246738425/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-621657 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-11</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-11</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-08-13</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-621657 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-14",
        "title": "Johnson Controls Metasys",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-14",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-14.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access.</strong></p>\n<p>The following versions of Johnson Controls Metasys are affected:</p>\n<ul>\n<li>Metasys 12 vers:all/* (CVE-2026-34491)</li>\n<li>Metasys 13 vers:all/* (CVE-2026-34491)</li>\n<li>Metasys 14</li>\n<li>Metasys 15</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8</td>\n<td>Johnson Controls Inc</td>\n<td>Johnson Controls Metasys</td>\n<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Ireland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-34491</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A low-privilege user can inject a malicious XSS payload into the Metasys UI via a crafted URL. The payload persists across logins and executes in the browser context of other users, including administrators.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-34491\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls Metasys</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls Inc</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls Inc Metasys 12: vers:all/*, Johnson Controls Inc Metasys 13: vers:all/*, Johnson Controls Inc Metasys 14: &lt;v14.1.5, Johnson Controls Inc Metasys 15: &lt;v15.0.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Johnson Controls recommends the following actions:</p>\n<p><strong>Mitigation</strong><br>User are recommended to apply the latest available patches for affected Metasys versions</p>\n<p><strong>Mitigation</strong><br>Metasys 16.0: Not impacted, fixed prior to release</p>\n<p><strong>Vendor fix</strong><br>Metasys 15.0: Patch released 2026-03-25</p>\n<p><strong>Vendor fix</strong><br>Metasys 14.1.5: Forecast release 2026-07-15</p>\n<p><strong>Vendor fix</strong><br>Metasys 13: End of support, update to later version</p>\n<p><strong>Vendor fix</strong><br>Metasys 12: End of support, update to later version</p>\n<p><strong>Mitigation</strong><br>Metasys 11 &amp; prior: Not affected (vulnerability introduced at version 12)</p>\n<p><strong>Mitigation</strong><br>To help reduce the risk of exploitation, we suggest considering the following defensive measures:</p>\n<p><strong>Mitigation</strong><br>Upgrade to Metasys version 16.0 or apply the latest available patch for your version (15.0.1 or 14.1.5 when available)</p>\n<p><strong>Mitigation</strong><br>Restrict network access to the Metasys UI to trusted networks and users only; do not expose the interface directly to the internet</p>\n<p><strong>Mitigation</strong><br>Implement network segmentation to isolate building automation systems from the corporate IT network</p>\n<p><strong>Mitigation</strong><br>Enforce least-privilege access controls \u2013 limit user accounts to the minimum permissions necessary</p>\n<p><strong>Mitigation</strong><br>Implement Content Security Policy (CSP) headers and other HTTP security headers where possible at the network/proxy level</p>\n<p><strong>Mitigation</strong><br>Monitor for suspicious URL patterns and unexpected script execution in Metasys UI access logs</p>\n<p><strong>Mitigation</strong><br>Use a web application firewall (WAF) in front of the Metasys UI to detect and block common XSS payloads</p>\n<p><strong>Mitigation</strong><br>Educate users to avoid clicking on untrusted or unexpected links that target the Metasys UI</p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-11 at the following location: Security Advisories.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/79.html\">CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>An anonymous researcher reported this vulnerability to Johnson Controls</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-13</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-13</td>\n<td>1</td>\n<td>Initial Publication.</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-01",
        "title": "AVEVA Enterprise SCADA",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization.</strong></p>\n<p>The following versions of AVEVA Enterprise SCADA are affected:</p>\n<ul>\n<li>Enterprise SCADA 2025 (CVE-2025-7639)</li>\n<li>Enterprise SCADA &gt;=2024|&lt;=2024_SP1_P01 (CVE-2025-7639)</li>\n<li>Enterprise SCADA &gt;=2023|&lt;=2023_SP1 (CVE-2025-7639)</li>\n<li>Enterprise SCADA &gt;=2022|&lt;=2022_SP2_P2 (CVE-2025-7639)</li>\n<li>Enterprise SCADA &lt;=2021_SP2_P5 (CVE-2025-7639)</li>\n<li>Enterprise SCADA HMI 2024|2024|R2 (CVE-2025-7639)</li>\n<li>Enterprise SCADA HMI &lt;=2023_P1 (CVE-2025-7639)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.1</td>\n<td>AVEVA</td>\n<td>AVEVA Enterprise SCADA</td>\n<td>Deserialization of Untrusted Data</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United Kingdom</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-7639</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The vulnerability, if exploited, could allow an authenticated miscreant with \"DNA Authority - Operator\" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of Enterprise SCADA security group \"DNA Apps\".</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-7639\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>AVEVA Enterprise SCADA</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>AVEVA</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>AVEVA Enterprise SCADA: 2025, AVEVA Enterprise SCADA: &gt;=2024|&lt;=2024_SP1_P01, AVEVA Enterprise SCADA: &gt;=2023|&lt;=2023_SP1, AVEVA Enterprise SCADA: &gt;=2022|&lt;=2022_SP2_P2, AVEVA Enterprise SCADA: &lt;=2021_SP2_P5, AVEVA Enterprise SCADA HMI: 2024|2024_R2, AVEVA Enterprise SCADA HMI: &lt;=2023_P1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>AVEVA recommends that customers using affected product versions should perform the following to mitigate the risk of exploit: 1. Evaluate the impact of these vulnerabilities based on your operational environment, architecture, and product implementation. 2. Plan an upgrade of Servers and Clients to one of the available fixed versions listed in this document. 3. Configure Servers and Clients as described in this document.</p>\n<p><strong>Mitigation</strong><br>Contact your AVEVA Technical Support representative, Customer Success Manager, Account Manager, or Solution Integrator to obtain the security update best applicable to the product version currently deployed in your environment: Servers: AVEVA Enterprise SCADA v2025 P1 or higher, AVEVA Enterprise SCADA v2024 SP1 P2, AVEVA Enterprise SCADA v2023 SP1 P1, AVEVA Enterprise SCADA v2022 SP2 P3, AVEVA Enterprise SCADA v2021 SP2 P6, AVEVA Pipeline Operations for Gas/Liquids v2025 P1 or higher, AVEVA Pipeline Operations for Gas/Liquids v2024 SP1 P2, AVEVA Pipeline Operations for Gas/Liquids v2023 SP1 P1, AVEVA Pipeline Operations for Gas/Liquids v2022 SP2 P3, AVEVA Pipeline Operations for Gas/Liquids v2021 SP2 P6 Clients: AVEVA Enterprise SCADA HMI v2024 R2 HF7 or higher, AVEVA Enterprise SCADA HMI v2024 P1, AVEVA Enterprise SCADA HMI v2023 P2 HF1, AVEVA Pipeline Integrity Monitor (delivered on Pipeline Simulation media) v2025 SP1 P2 or higher, AVEVA Pipeline Training Simulator (delivered on Pipeline Simulation media) v2025 SP1 P2 or higher, Measurement Advisor 2025 P1 or higher, Measurement Advisor 2021 SP1 HF16</p>\n<p><strong>Mitigation</strong><br>To fully mitigate the risk of exploit, the following configuration changes must be implemented after all server and client nodes have been upgraded to compatible versions that support the fix:Server Components: Change \"BinarySerializer\" -&gt; \"Mode\" setting from 'Binary Formatter' to 'Json'. Change \"BinarySerializer\" -&gt; \"AcceptBinaryFormattedData\" setting from 'true' to 'false'. Re-cache the XOS Event Handlers assembly</p>\n<p><strong>Mitigation</strong><br>Client Components: Configure clients/products that interface with Enterprise SCADA to only use JSON serialization.</p>\n<p><strong>Mitigation</strong><br>HMI: Migrate HMI displays</p>\n<p><strong>Mitigation</strong><br>For step-by-step instructions on where and how to apply these configuration settings, how to migrate HMI displays, compatible server-client versions list, and additional details please refer to KB117814 \"AVEVA Midstream Product Bulletin - Removal of Binary Formatter\"<br><a href=\"https://softwaresupportsp.aveva.com/en-US/knowledge/details/000117814?lang=en_US\">https://softwaresupportsp.aveva.com/en-US/knowledge/details/000117814?lang=en_US</a></p>\n<p><strong>Mitigation</strong><br>AVEVA recommends the following general defensive measures: Audit devices, network topology, and perimeter defences to ensure all applicable security best practices from AVEVA's Enterprise SCADA Reference System Architecture are adhered to. Audit assigned permissions to ensure that only trusted users are given \"DNA Authority - Operator\" rights: https://docs.aveva.com/bundle/scada-ent-2025/page/651008.html Disallow BLT Test clients in production environmentsFor additional details on defensive measures, refer to Section 5 of KB117814 \"AVEVA Midstream Product Bulletin - Removal of Binary Formatter<br><a href=\"https://docs.aveva.com/bundle/scada-ent-2025/page/651008.html\">https://docs.aveva.com/bundle/scada-ent-2025/page/651008.html</a></p>\n<p><strong>Mitigation</strong><br>For more information on this vulnerability, including security updates, users should see the security bulletin AVEVA-2026-005.<br><a href=\"https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-005.pdf\">https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-005.pdf</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/502.html\">CWE-502 Deserialization of Untrusted Data</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H\">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.1</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>AVEVA reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks. Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability has a high attack complexity.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-13</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-13</td>\n<td>1</td>\n<td>Initial Republication of AVEVA security bulletin AVEVA-2026-005</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-02",
        "title": "Haiwell IoT Cloud HMI Gateway",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges.</strong></p>\n<p>The following versions of Haiwell IoT Cloud HMI Gateway are affected:</p>\n<ul>\n<li>Haiwell IoT Cloud HMI Gateway 3.40.1.12 (CVE-2026-19188)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 10</td>\n<td>Haiwell</td>\n<td>Haiwell IoT Cloud HMI Gateway</td>\n<td>Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Energy, Critical Manufacturing, Water and Wastewater</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>China</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-19188</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-19188\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Haiwell IoT Cloud HMI Gateway</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Haiwell</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Haiwell Haiwell IoT Cloud HMI Gateway: 3.40.1.12</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Haiwell has addressed the issue in patch version number Scada-v3.50.1.19, which is available for download on their website: https://en.haiwell.com/app/system/entrance.php?m=include&amp;c=access&amp;a=dodown&amp;lang=en&amp;id=361<br><a href=\"https://en.haiwell.com/app/system/entrance.php?m=include&amp;c=access&amp;a=dodown&amp;lang=en&amp;id=361\">https://en.haiwell.com/app/system/entrance.php?m=include&amp;c=access&amp;a=dodown&amp;lang=en&amp;id=361</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/78.html\">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>10</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>10</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Fiqram Akmal reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-13</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-13</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-03",
        "title": "Johnson Controls Inc. Airwall",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-03",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-03.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized access to protected system resources.</strong></p>\n<p>The following versions of Johnson Controls Inc. Airwall are affected:</p>\n<ul>\n<li>Airwall &lt;=4.0.4 (CVE-2026-64887, CVE-2026-34492)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 6.8</td>\n<td>Johnson Controls Inc.</td>\n<td>Johnson Controls Inc. Airwall</td>\n<td>Use of Hard-coded Cryptographic Key, External Control of File Name or Path</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Ireland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-64887</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A hardcoded password or cryptographic key was identified in the Airwall application. A hardcoded credential leads to a significant authentication failure that can be difficult for system or application administrators to detect. Once discovered, it is difficult to remediate without manually modifying or patching the software. The hardcoded key is identical across all installations of the product and across all customer organizations, meaning a single disclosure of the key - common on the internet - grants any knowledgeable attacker access to all affected deployments. An attacker with access to application code or binary files can use the hardcoded key to decrypt sensitive application data stored in configuration and database files, enabling further data disclosure or compromise of application infrastructure.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-64887\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls Inc. Airwall</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls Inc.</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls Inc. Airwall: &lt;=4.0.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>To help reduce risk of exploitation, Johnson Controls recommends the following defensive measures: Apply v4.1.0 or later patches for all Airwalls.</p>\n<p><strong>Mitigation</strong><br>Store all cryptographic keys in a secure key management system (KMS) or hardware security module (HSM) rather than embedding them in source code or configuration files. (CVE-2026-64887)</p>\n<p><strong>Mitigation</strong><br>Implement a regular key rotation policy to limit the exposure window if a key is compromised. (CVE-2026-64887)</p>\n<p><strong>Mitigation</strong><br>Use unique cryptographic keys per device, installation, or deployment instance to prevent a single compromised key from affecting all installations. (CVE-2026-64887)</p>\n<p><strong>Mitigation</strong><br>Remove any hard-coded keys from source code repositories and binaries, replacing them with references to secure external key stores. (CVE-2026-64887)Apply the principle of least privilege to key access, ensuring only authorized processes and personnel can retrieve cryptographic material. (CVE-2026-64887)</p>\n<p><strong>Mitigation</strong><br>Use static analysis and secrets-scanning tools in CI/CD pipelines to detect and prevent hard-coded keys from being committed to source control. (CVE-2026-64887)</p>\n<p><strong>Mitigation</strong><br>Encrypt keys at rest and in transit and ensure key-wrapping mechanisms are in place for any keys stored on disk. (CVE-2026-64887)</p>\n<p><strong>Mitigation</strong><br>Audit and monitor access to cryptographic keys, logging all retrieval and usage events for anomaly detection. (CVE-2026-64887)</p>\n<p><strong>Mitigation</strong><br>Refer to and follow all steps in the product hardening guide or the JCI universal hardening guide found here https://www.johnsoncontrols.com/trust-center/cybersecurity/resources (CVE-2026-64887)<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/resources\">https://www.johnsoncontrols.com/trust-center/cybersecurity/resources</a></p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-25 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories (CVE-2026-64887)<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories\">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/321.html\">CWE-321 Use of Hard-coded Cryptographic Key</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N\">CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-34492</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An arbitrary file read vulnerability was identified in the Airwall application. This issue occurs when user-supplied input is directly incorporated into filesystem access functions without adequate validation or sanitization. As a result, an attacker can request and obtain the contents of arbitrary files on the server, including sensitive configuration files, source code, credential stores, and private keys, provided the application process has permission to read them. The vulnerability is commonly exploited through path traversal sequences (e.g., ../) or absolute file paths (e.g., /etc/passwd). Encoding variations of traversal sequences (e.g., %2e%2e%2f) can also bypass basic filters.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-34492\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls Inc. Airwall</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls Inc.</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls Inc. Airwall: &lt;=4.0.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>To help reduce risk of exploitation, Johnson Controls recommends the following defensive measures: Apply v4.1.0 or later patches for all Airwalls.</p>\n<p><strong>Mitigation</strong><br>Validate and sanitize all user-supplied input before using it in file system operations (CVE-2026-34492)</p>\n<p><strong>Mitigation</strong><br>Implement strict allowlists for permitted file paths, file names, and directories (CVE-2026-34492)</p>\n<p><strong>Mitigation</strong><br>Use canonicalization to resolve path traversal sequences before validation (CVE-2026-34492)</p>\n<p><strong>Mitigation</strong><br>Apply the principle of least privilege to the application file system access permissions (CVE-2026-34492)</p>\n<p><strong>Mitigation</strong><br>Deploy sandboxing or chroot jails to restrict the application's file system scope (CVE-2026-34492)</p>\n<p><strong>Mitigation</strong><br>Avoid passing user-controlled data directly to file system APIs (CVE-2026-34492)</p>\n<p><strong>Mitigation</strong><br>Refer to and follow all steps in the product hardening guide or the JCI universal hardening guide found here https://www.johnsoncontrols.com/trust-center/cybersecurity/resources (CVE-2026-34492)<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/resources\">https://www.johnsoncontrols.com/trust-center/cybersecurity/resources</a></p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-18 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories (CVE-2026-34492)<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories\">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/73.html\">CWE-73 External Control of File Name or Path</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.4</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L\">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Johnson Controls reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this (these) vulnerability(ies) has been reported to CISA at this time. This (these) vulnerability(ies) is (are) not exploitable remotely. This (these) vulnerability(ies) has (have) a high attack complexity.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-13</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-13</td>\n<td>1</td>\n<td>Initial Republication of Johnson Controls JCI-PSA-2026-18 and JCI-PSA-2026-25</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-08",
        "title": "Siemens Desigo DXR and PXC Controllers",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-08",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-08.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions.</strong></p>\n<p>The following versions of Siemens Desigo DXR and PXC Controllers are affected:</p>\n<ul>\n<li>Desigo DXR2 vers:intdot/&lt;01.21.233.16-7862 (CVE-2026-59693)</li>\n<li>Desigo PXC3 vers:intdot/&lt;01.21.233.16-7862 (CVE-2026-59693)</li>\n<li>Desigo PXC4 vers:intdot/&lt;02.21.194.36-2715 (CVE-2026-59693)</li>\n<li>Desigo PXC5.E003 vers:intdot/&lt;02.21.194.36-2715 (CVE-2026-59693)</li>\n<li>Desigo PXC5.E24 vers:intdot/&lt;02.21.194.36-2715 (CVE-2026-59693)</li>\n<li>Desigo PXC7 vers:intdot/&lt;02.21.194.36-2715 (CVE-2026-59693)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 4.3</td>\n<td>Siemens</td>\n<td>Siemens Desigo DXR and PXC Controllers</td>\n<td>Improper Check for Unusual or Exceptional Conditions</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Commercial Facilities, Critical Manufacturing, Energy, Healthcare and Public Health, Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-59693</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected devices are vulnerable to a denial-of-service (DoS) vulnerability. An attacker can exploit this issue by sending a malformed BACnet packet, causing the device to stop responding to BACnet queries. Recovery requires a device reset or reboot to restore normal functionality.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-59693\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Desigo DXR and PXC Controllers</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Desigo DXR2 &lt; V01.21.233.16-7862, Desigo PXC3 &lt; V01.21.233.16-7862, Desigo PXC4 &lt; V02.21.194.36-2715, Desigo PXC5.E003 &lt; V02.21.194.36-2715, Desigo PXC5.E24 &lt; V02.21.194.36-2715, Desigo PXC7 &lt; V02.21.194.36-2715</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V01.21.233.16-7862 or later version Please contact your local Siemens office for additional support in obtaining the update.</p>\n<p><strong>Vendor fix</strong><br>Update to V02.21.194.36-2715 or later version Please contact your local Siemens office for additional support in obtaining the update.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/754.html\">CWE-754 Improper Check for Unusual or Exceptional Conditions</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>4.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Thomas EBI of Sauter reported this vulnerability to Siemens</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and following the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens SSA-781903 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-11</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-11</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-08-13</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens SSA-781903 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-07",
        "title": "Siemens License Server (SLS)",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-07",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-07.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version.</strong></p>\n<p>The following versions of Siemens License Server (SLS) are affected:</p>\n<ul>\n<li>Siemens License Server (SLS) vers:intdot/&lt;5.1, vers:intdot/&lt;5.3 (CVE-2026-69108, CVE-2026-69109)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>Siemens</td>\n<td>Siemens License Server (SLS)</td>\n<td>Incorrect Permission Assignment for Critical Resource, Path Traversal: '.../...//'</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-69108</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and plant malicious files as root, leading to full system compromise.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-69108\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens License Server (SLS)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Siemens License Server (SLS) &lt; V5.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V5.1 or later version<br><a href=\"https://support.sw.siemens.com/product/1586485382/\">https://support.sw.siemens.com/product/1586485382/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/732.html\">CWE-732 Incorrect Permission Assignment for Critical Resource</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N\">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-69109</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the application.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-69109\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens License Server (SLS)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Siemens License Server (SLS) &lt; V5.3</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V5.3 or later version<br><a href=\"https://support.sw.siemens.com/product/1586485382/\">https://support.sw.siemens.com/product/1586485382/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/35.html\">CWE-35 Path Traversal: '.../...//'</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-077553 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-11</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-11</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-08-13</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-077553 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 13 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 13 Aug 26 12:00:00 +0000"
    }
]