[
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-01",
        "title": "Rockwell Automation RSLinx Classic",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-244-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product.</strong></p>\n<p>The following versions of Rockwell Automation RSLinx Classic are affected:</p>\n<ul>\n<li>RSLinx Classic &lt;=4.50 (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.6</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation RSLinx Classic</td>\n<td>Integer Overflow or Wraparound, Integer Underflow (Wrap or Wraparound), Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-9621</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service security issue exists within RSLinx Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx Classic service to crash, requiring a restart of the service to recover.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9621\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation RSLinx Classic</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation RSLinx Classic: &lt;=4.50</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation has corrected the vulnerabilities in RSLinx Classic version 4.60.</p>\n<p><strong>Mitigation</strong><br>Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/190.html\">CWE-190 Integer Overflow or Wraparound</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.2</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-9622</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service security issue exists within RSLinx Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx Classic service to crash, requiring a restart of the service to recover.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9622\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation RSLinx Classic</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation RSLinx Classic: &lt;=4.50</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation has corrected the vulnerabilities in RSLinx Classic version 4.60.</p>\n<p><strong>Mitigation</strong><br>Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/191.html\">CWE-191 Integer Underflow (Wrap or Wraparound)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.2</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-9624</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service security issue exists within RSLinx Classic. A crafted CIP packet can cause the RSLinx Classic service to crash due to insufficient data length validation, requiring a restart of the service to recover.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9624\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation RSLinx Classic</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation RSLinx Classic: &lt;=4.50</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation has corrected the vulnerabilities in RSLinx Classic version 4.60.</p>\n<p><strong>Mitigation</strong><br>Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/191.html\">CWE-191 Integer Underflow (Wrap or Wraparound)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-9625</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service security issue exists within RSLinx Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx Classic service to crash, requiring a restart of the service to recover.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9625\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation RSLinx Classic</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation RSLinx Classic: &lt;=4.50</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation has corrected the vulnerabilities in RSLinx Classic version 4.60.</p>\n<p><strong>Mitigation</strong><br>Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/120.html\">CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-01</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-01</td>\n<td>1</td>\n<td>Initial Republication of Rockwell Automation Advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 01 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 01 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-06",
        "title": "Rockwell Automation Historian ME",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-06",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-244-06.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution.</strong></p>\n<p>The following versions of Rockwell Automation Historian ME are affected:</p>\n<ul>\n<li>Series B 5.202 (CVE-2025-12768, CVE-2026-12661)</li>\n<li>Series C 7.101 (CVE-2025-12768, CVE-2026-12661)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation Historian ME</td>\n<td>Out-of-bounds Write, Stack-based Buffer Overflow</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Critical Manufacturing, Food and Agriculture, Healthcare and Public Health, Water and Wastewater Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-12768</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A security issue exists within FactoryTalk\u00ae Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieveremote code execution on the affected device.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-12768\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation Historian ME</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation Series B: 5.202, Rockwell Automation Series C: 7.101</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automations security best practices found at https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>If you have any questions regarding the security issue(s) above and how to mitigate them, contact TechConnect for help. More information can be found at https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html.<br><a href=\"https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html\">https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html</a></p>\n<p><strong>Mitigation</strong><br>If you have any questions regarding this disclosure, please contact PSIRT Email: rasecure@ra.rockwell.com<br><a href=\"mailto:rasecure@ra.rockwell.com\">mailto:rasecure@ra.rockwell.com</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-12661</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service security issue exists within FactoryTalk\u00ae Historian Machine Edition. A network adjacent attacker who is authenticated could send craftedrequests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-12661\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation Historian ME</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation Series B: 5.202, Rockwell Automation Series C: 7.101</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automations security best practices found at https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>If you have any questions regarding the security issue(s) above and how to mitigate them, contact TechConnect for help. More information can be found at https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html.<br><a href=\"https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html\">https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html</a></p>\n<p><strong>Mitigation</strong><br>If you have any questions regarding this disclosure, please contact PSIRT Email: rasecure@ra.rockwell.com<br><a href=\"mailto:rasecure@ra.rockwell.com\">mailto:rasecure@ra.rockwell.com</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/121.html\">CWE-121 Stack-based Buffer Overflow</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>4.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>4.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-01</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-01</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 01 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 01 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-05",
        "title": "Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-05",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-244-05.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p>The following versions of Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix are affected:</p>\n<ul>\n<li>ControlLogix 5580 &lt;34.015, &lt;35.014, &lt;36.013, &lt;37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)</li>\n<li>GuardLogix 5580 &lt;34.015, &lt;35.014, &lt;36.013, &lt;37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)</li>\n<li>CompactLogix 5380 &lt;34.015, &lt;35.014, &lt;36.013, &lt;37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)</li>\n<li>Compact GuardLogix 5380 &lt;34.015, &lt;35.014, &lt;36.013, &lt;37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)</li>\n<li>CompactLogix 5480 &lt;34.015, &lt;35.014, &lt;36.013, &lt;37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix</td>\n<td>Loop with Unreachable Exit Condition ('Infinite Loop')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2021-42260</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A potential denial of service vulnerability exists in the affected products and can be triggered via corrupt crafted data. This could result in a major nonrecoverable fault (MNRF). A program download is required to recover safety controllers. For non-safety controllers, a stage 2 reset is required to recover.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2021-42260\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation ControlLogix 5580 &lt;34.015, Rockwell Automation ControlLogix 5580 &lt;35.014, Rockwell Automation ControlLogix 5580 &lt;36.013, Rockwell Automation ControlLogix 5580 &lt;37.011, Rockwell Automation GuardLogix 5580 &lt;34.015, Rockwell Automation GuardLogix 5580 &lt;35.014, Rockwell Automation GuardLogix 5580 &lt;36.013, Rockwell Automation GuardLogix 5580 &lt;37.011, Rockwell Automation CompactLogix 5380 &lt;34.015, Rockwell Automation CompactLogix 5380 &lt;35.014, Rockwell Automation CompactLogix 5380 &lt;36.013, Rockwell Automation CompactLogix 5380 &lt;37.011, Rockwell Automation Compact GuardLogix 5380 &lt;34.015, Rockwell Automation Compact GuardLogix 5380 &lt;35.014, Rockwell Automation Compact GuardLogix 5380 &lt;36.013, Rockwell Automation Compact GuardLogix 5380 &lt;37.011, Rockwell Automation CompactLogix 5480 &lt;34.015, Rockwell Automation CompactLogix 5480 &lt;35.014, Rockwell Automation CompactLogix 5480 &lt;36.013, Rockwell Automation CompactLogix 5480 &lt;37.011</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users update to firmware version 34.015 and later.</p>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users update to firmware version 35.014 and later.</p>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users update to firmware version 36.013 and later.</p>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users update to firmware version 37.011 and later.</p>\n<p><strong>Mitigation</strong><br>Customers using the affected software who are not able to upgrade to one of the corrected versions should use Rockwell Automation's security best practices.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/835.html\">CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-01</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-01</td>\n<td>1</td>\n<td>Initial republication of Rockwell Automation advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 01 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 01 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-03",
        "title": "Rockwell Automation Logix Platform",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-03",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-244-03.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p>The following versions of Rockwell Automation Logix Platform are affected:</p>\n<ul>\n<li>ControlLogix 5580 &lt;=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)</li>\n<li>CompactLogix 5380 &lt;=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)</li>\n<li>GuardLogix 5580 &lt;=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)</li>\n<li>Compact GuardLogix 5380 &lt;=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation Logix Platform</td>\n<td>Improper Restriction of Operations within the Bounds of a Memory Buffer</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-9637</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service vulnerability exists in the affected Logix platforms due to improper validation of input length during CIP message processing. This can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9637\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation Logix Platform</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation ControlLogix 5580 &lt;=V33, Rockwell Automation ControlLogix 5580 V34.011-V34.014, Rockwell Automation ControlLogix 5580 V35.011-V35.013, Rockwell Automation ControlLogix 5580 V36.011-V36.012, Rockwell Automation CompactLogix 5380 &lt;=V33, Rockwell Automation CompactLogix 5380 V34.011-V34.014, Rockwell Automation CompactLogix 5380 V35.011-V35.013, Rockwell Automation CompactLogix 5380 V36.011-V36.012, Rockwell Automation GuardLogix 5580 &lt;=V33, Rockwell Automation GuardLogix 5580 V34.011-V34.014, Rockwell Automation GuardLogix 5580 V35.011-V35.013, Rockwell Automation GuardLogix 5580 V36.011-V36.012, Rockwell Automation Compact GuardLogix 5380 &lt;=V33, Rockwell Automation Compact GuardLogix 5380 V34.011-V34.014, Rockwell Automation Compact GuardLogix 5380 V35.011-V35.013, Rockwell Automation Compact GuardLogix 5380 V36.011-V36.012</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users update to firmware version V37.011.</p>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users update to firmware version 34.015.</p>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users update to firmware version 35.014.</p>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users update to firmware version 36.013.</p>\n<p><strong>Mitigation</strong><br>Customers using the affected software who are not able to upgrade to one of the corrected versions should use Rockwell Automation's security best practices.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/119.html\">CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-01</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-01</td>\n<td>1</td>\n<td>Initial republication of Rockwell Automation advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 01 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 01 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-02",
        "title": "Rockwell Automation Redundancy Module Configuration Tool",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-244-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges.</strong></p>\n<p>The following versions of Rockwell Automation Redundancy Module Configuration Tool are affected:</p>\n<ul>\n<li>Redundancy Module Configuration Tool 10.00.00 (CVE-2026-9633)</li>\n<li>Redundancy Module Configuration Tool &gt;=9.00.00|&lt;=10.00.00 (CVE-2026-9634)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.3</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation Redundancy Module Configuration Tool</td>\n<td>Incorrect Default Permissions</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-9633</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non administrator) users due to incorrect default permissions. If a local attacker places a malicious DLL in such a directory and an administrator subsequently runs the tool, the malicious DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9633\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation Redundancy Module Configuration Tool</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation Redundancy Module Configuration Tool: 10.00.00</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation has released Redundancy Module Configuration Tool version 10.01.00 for users to install.</p>\n<p><strong>Mitigation</strong><br>Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight).<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/276.html\">CWE-276 Incorrect Default Permissions</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-9634</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users due to incorrect default permissions. If a local attacker places a malicious DLL in such a directory and an administrator subsequently runs the tool, the malicious DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9634\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation Redundancy Module Configuration Tool</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation Redundancy Module Configuration Tool: &gt;=9.00.00|&lt;=10.00.00</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation has released Redundancy Module Configuration Tool version 10.01.00 for users to install.</p>\n<p><strong>Mitigation</strong><br>Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight).<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/276.html\">CWE-276 Incorrect Default Permissions</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-01</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-01</td>\n<td>1</td>\n<td>Initial Republication of Rockwell Automation Security Advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 01 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 01 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-04",
        "title": "Rockwell Automation FactoryTalk Activation Manager",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-04",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-244-04.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p>The following versions of Rockwell Automation FactoryTalk Activation Manager are affected:</p>\n<ul>\n<li>FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.8</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation FactoryTalk Activation Manager</td>\n<td>Improper Restriction of Excessive Authentication Attempts</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-16675</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A privilege escalation vulnerability exists within FactoryTalk Activation Manager. The vulnerability stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack these console windows to obtain a SYSTEM-level command prompt, allowing full access to all files, processes, and system resources.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-16675\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation FactoryTalk Activation Manager</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation FactoryTalk Activation Manager V5.02_and_below</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users update to software version V5.03.</p>\n<p><strong>Mitigation</strong><br>Customers using the affected software who are not able to upgrade to one of the corrected versions should use Rockwell Automation's security best practices.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/307.html\">CWE-307 Improper Restriction of Excessive Authentication Attempts</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>An anonymous security researcher reported this vulnerability to Rockwell Automation, who reported it to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-01</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-01</td>\n<td>1</td>\n<td>Initial republication of Rockwell Automation advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 01 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 01 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Two Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added two new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-81578\" target=\"_blank\"><u>CVE-2026-81578</u></a> PaperCut NG/MF Missing Authentication for Critical Function Vulnerability&nbsp;</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-82078\" target=\"_blank\"><u>CVE-2026-82078</u></a> PaperCut NG/MF Unsafe Reflection Vulnerability&nbsp;</li>\n</ul>\n<div class=\"OutlineElement Ltr SCXW211148847 BCX8\">\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW211148847 BCX8\">\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\"><u>Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</u></a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW211148847 BCX8\">\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\"><u>KEV Catalog vulnerabilities</u></a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities\" target=\"_blank\"><u>specified criteria</u></a>.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW211148847 BCX8\">\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\"><u>KEV Nomination Form</u></a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>\n</div>",
        "summary_is_html": true,
        "first_seen": "Mon, 31 Aug 26 12:00:00 +0000",
        "last_updated": "Mon, 31 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-078-05",
        "title": "Mitsubishi Electric CNC Series (Update A)",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-078-05",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-078-05.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products.</strong></p>\n<p>The following versions of Mitsubishi Electric CNC Series (Update A) are affected:</p>\n<ul>\n<li>Mitsubishi Electric M800VW (BND-2051W000) &lt;=BB (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M800VS (BND-2052W000) &lt;=BB (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M80V (BND-2053W000) &lt;=BB (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M80VW (BND-2054W000) &lt;=BB (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M800W (BND-2005W000) &lt;=FM (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M800S (BND-2006W000) &lt;=FM (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M80 (BND-2007W000) &lt;=FM (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M80W (BND-2008W000) &lt;=FM (CVE-2025-2399)</li>\n<li>Mitsubishi Electric E80 (BND-2009W000) &lt;=FM (CVE-2025-2399)</li>\n<li>Mitsubishi Electric C80 (BND-2036W000) vers:all/* (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M750VW (BND-1015W002) &lt;=LJ (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M730VW (BND-1015W000) &lt;=LJ (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M720VW (BND-1015W000) &lt;=LJ (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M750VS (BND-1012W002) &lt;=LJ (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M730VS (BND-1012W000) &lt;=LJ (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M720VS (BND-1012W000) &lt;=LJ (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M70V (BND-1018W000) &lt;=LJ (CVE-2025-2399)</li>\n<li>Mitsubishi Electric E70 (BND-1022W000) &lt;=LJ (CVE-2025-2399)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 5.9</td>\n<td>Mitsubishi Electric</td>\n<td>Mitsubishi Electric CNC Series (Update A)</td>\n<td>Improper Validation of Specified Index, Position, or Offset in Input</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Japan</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-2399</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) vulnerability in the affected products allows a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products by sending specially crafted packets to TCP port 683.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-2399\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Mitsubishi Electric CNC Series (Update A)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Mitsubishi Electric</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Mitsubishi Electric M800VW (BND-2051W000): &lt;=BB, Mitsubishi Electric M800VS (BND-2052W000): &lt;=BB, Mitsubishi Electric M80V (BND-2053W000): &lt;=BB, Mitsubishi Electric M80VW (BND-2054W000): &lt;=BB, Mitsubishi Electric M800W (BND-2005W000): &lt;=FM, Mitsubishi Electric M800S (BND-2006W000): &lt;=FM, Mitsubishi Electric M80 (BND-2007W000): &lt;=FM, Mitsubishi Electric M80W (BND-2008W000): &lt;=FM, Mitsubishi Electric E80 (BND-2009W000): &lt;=FM, Mitsubishi Electric C80 (BND-2036W000): vers:all/*, Mitsubishi Electric M750VW (BND-1015W002): &lt;=LJ, Mitsubishi Electric M730VW (BND-1015W000): &lt;=LJ, Mitsubishi Electric M720VW (BND-1015W000): &lt;=LJ, Mitsubishi Electric M750VS (BND-1012W002): &lt;=LJ, Mitsubishi Electric M730VS (BND-1012W000): &lt;=LJ, Mitsubishi Electric M720VS (BND-1012W000): &lt;=LJ, Mitsubishi Electric M70V (BND-1018W000): &lt;=LJ, Mitsubishi Electric E70 (BND-1022W000): &lt;=LJ</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Please apply the fixed version (BC or later) for Mitsubishi Electric M800VW (BND-2051W000), M800VS (BND-2052W000), M80V (BND-2053W000), and M80VW (BND-2054W000). For instructions on how to apply it, please consult your Mitsubishi Electric representative.</p>\n<p><strong>Vendor fix</strong><br>Please apply the fixed version (FN or later) for Mitsubishi Electric M800W (BND-2005W000), M800S (BND-2006W000), M80 (BND-2007W000), M80W (BND-2008W000), and E80 (BND-2009W000). For instructions on how to apply it, please consult your Mitsubishi Electric representative.</p>\n<p><strong>Vendor fix</strong><br>Please apply the fixed version (LK or later) for Mitsubishi Electric M750VW (BND-1015W002), M730VW (BND-1015W000), M720VW (BND-1015W000), M750VS (BND-1012W002), M730VS (BND-1012W000), M720VS (BND-1012W000), M70V (BND-1018W000), and E70 (BND-1022W000). For instructions on how to apply it, please consult your Mitsubishi Electric representative.</p>\n<p><strong>Mitigation</strong><br>For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric recommends using a firewall or virtual private network (VPN) to prevent unauthorized access, when internet access is required, to minimize the risk of exploiting this vulnerability.</p>\n<p><strong>Mitigation</strong><br>For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric recommends using the product within a LAN and blocking access from untrusted networks and hosts through a firewall, to minimize the risk of exploiting this vulnerability.</p>\n<p><strong>Mitigation</strong><br>For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric recommends using IP filters to prevent unauthorized access, when internet access is required, to minimize the risk of exploiting this vulnerability. IP filter function is available for M800V/M80V Series and M800/M80/E80 Series. For details about the IP filter function, refer to the following manual for each product which can be downloaded from the link \"https://www.mitsubishielectric.com/fa/download/index.html \": M800V/M80V Series Instruction Manual \"16. Appendix 3 IP Address Filter Setting Function\", M800/M80/E80 Series Instruction Manual \"15. Appendix 2 IP Address Filter Setting Function\".<br><a href=\"https://www.mitsubishielectric.com/fa/download/index.html\">https://www.mitsubishielectric.com/fa/download/index.html</a></p>\n<p><strong>Mitigation</strong><br>For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric recommends restricting physical access to the affected product and to all computers and network devices to which the products are connected, to minimize the risk of exploiting this vulnerability.</p>\n<p><strong>Mitigation</strong><br>For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric recommends installing anti-virus software on PCs that can access the affected product, to minimize the risk of exploiting this vulnerability.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/1285.html\">CWE-1285 Improper Validation of Specified Index, Position, or Offset in Input</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Mitsubishi Electric reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Mitsubishi Electric 2025-022 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Mitsubishi Electric directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-03-10</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-03-10</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n<tr>\n<td>2026-03-19</td>\n<td>2</td>\n<td>CISA Republication - Initial CISA Republication of Mitsubishi Electric V20250121-001#02 advisory</td>\n</tr>\n<tr>\n<td>2026-08-27</td>\n<td>3</td>\n<td>Removed Software Tools NC Trainer2 and Software Tools NC Trainer2 plus, from affected products. And added M700V/M70V/E70 Series as fixed products.</td>\n</tr>\n<tr>\n<td>2026-08-27</td>\n<td>4</td>\n<td>CISA Republication update based on Mitsubishi Electric 2025-022 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 27 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 27 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-05",
        "title": "Ebyte NA111-M",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-05",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-05.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to fully compromise the device.</strong></p>\n<p>The following versions of Ebyte NA111-M are affected:</p>\n<ul>\n<li>NA111-M Firmware 9013-2-17 (CVE-2026-73125, CVE-2026-76179, CVE-2026-75814, CVE-2026-76940, CVE-2026-77966, CVE-2026-73809, CVE-2026-71187, CVE-2026-75548, CVE-2026-69658, CVE-2026-76133, CVE-2026-73819, CVE-2026-77975, CVE-2026-77977)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.8</td>\n<td>Ebyte</td>\n<td>Ebyte NA111-M</td>\n<td>Missing Authentication for Critical Function, Use of GET Request Method With Sensitive Query Strings, Cross-Site Request Forgery (CSRF), Improper Restriction of Excessive Authentication Attempts, Missing Authorization, Cleartext Transmission of Sensitive Information, Use of Client-Side Authentication, Improper Restriction of Rendered UI Layers or Frames, Use of a Broken or Risky Cryptographic Algorithm, Weak Authentication, Cleartext Storage of Sensitive Information</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>China</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-73125</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-73125\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-76179</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during client-side session handling, which may allow an attacker with access to exposed session information to obtain and reuse a valid token. Successful exploitation could allow an attacker to impersonate an authenticated user and gain unauthorized access to device management functionality.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-76179\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/598.html\">CWE-598 Use of GET Request Method With Sensitive Query Strings</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-75814</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management interface. An unauthenticated remote attacker could persuade an authenticated administrator to visit a crafted page, causing unauthorized configuration changes or a disruption of device availability.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-75814\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/352.html\">CWE-352 Cross-Site Request Forgery (CSRF)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-76940</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected Ebyte device does not restrict repeated authentication attempts through rate limiting or account lockout mechanisms. This could allow an attacker to perform automated authentication attacks against deployments that rely on password based authentication.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-76940\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/307.html\">CWE-307 Improper Restriction of Excessive Authentication Attempts</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-77966</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product does not provide separation between limited and administrative management functions. A low privileged authenticated attacker could access security sensitive configuration functions and modify settings that affect the confidentiality, integrity, or availability of the device.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-77966\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/862.html\">CWE-862 Missing Authorization</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-73809</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web management interface does not adequately protect sensitive communications using transport-layer encryption. An attacker with access to network traffic could intercept authentication or session-related information transmitted between a user and the affected device. Successful exploitation could result in disclosure of sensitive information and unauthorized access to device management functionality.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-73809\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/319.html\">CWE-319 Cleartext Transmission of Sensitive Information</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-71187</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtain administrative access to the device.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-71187\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/603.html\">CWE-603 Use of Client-Side Authentication</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-75548</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected Ebyte device web management interface does not restrict the interface from being rendered within an external frame. An unauthenticated remote attacker could use a crafted webpage to mislead an authenticated administrator into initiating unintended configuration changes or disruptive actions.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-75548\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/1021.html\">CWE-1021 Improper Restriction of Rendered UI Layers or Frames</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.4</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.1</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-69658</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device impersonation and disruption of messaging functions.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-69658\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/319.html\">CWE-319 Cleartext Transmission of Sensitive Information</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-76133</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product uses a deprecated hashing algorithm in an authentication-related operation. Under conditions where an attacker can manipulate or predict the authentication exchange, the weak construction may reduce the assurance provided by the authentication mechanism and facilitate unauthorized access.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-76133\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/327.html\">CWE-327 Use of a Broken or Risky Cryptographic Algorithm</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-73819</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product's vendor configuration utility permits access to administrative functions without verifying the operator's identity under certain credential conditions. An unauthenticated attacker on the adjacent network could modify critical settings or change access credentials, potentially preventing legitimate administrators from managing the device.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-73819\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/1390.html\">CWE-1390 Weak Authentication</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-77975</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product exports administrative credentials and other sensitive configuration information without adequate protection. An unauthenticated attacker on the adjacent network who can obtain an exported configuration file could recover valid credentials and use them to access the device or similarly configured systems.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-77975\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/312.html\">CWE-312 Cleartext Storage of Sensitive Information</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-77977</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product's vendor configuration utility does not require authentication before allowing certain disruptive administrative actions when default credentials remain configured. An unauthenticated attacker on the adjacent network could reboot the device or restore factory settings, resulting in a loss of configuration and service availability.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-77977\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Jithin Nambiar J reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-27</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-27</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 27 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 27 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-128-03",
        "title": "Mitsubishi Electric Multiple FA Products (Update D)",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-128-03",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-128-03.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition, a timeout error, or a communication delay by sending a specially crafted UDP packet to the product.</strong></p>\n<p>The following versions of Mitsubishi Electric Multiple FA Products (Update D) are affected:</p>\n<ul>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32D &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32T &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32TE &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32DT &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32DTE &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32D &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32T &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32TE &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32DT &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32DTE &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCF1-32D &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCF1-32T &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCE3-32D &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCE3-32DT &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A4-16D &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A4-16DE &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A2-16T &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A2-16TE &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A42-16DT &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A42-16DTE &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-16D &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-16T &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-16TE &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-16D &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-16T &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-16TE &lt;=09 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Analog-Digital Converter module NZ2GN2S-60AD4 &lt;=07 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Analog-Digital Converter module NZ2GN2B-60AD4 &lt;=07 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Digital-Analog Converter module NZ2GN2S-60DA4 &lt;=07 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Digital-Analog Converter module NZ2GN2B-60DA4 &lt;=07 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN FPGA module NZ2GN2S-D41P01 01 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN FPGA module NZ2GN2S-D41D01 01 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN FPGA module NZ2GN2S-D41PD02 01 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY NZ2GACP620-300 &lt;=1.08J (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY NZ2GACP620-60 &lt;=1.08J (CVE-2025-3511)</li>\n<li>Mitsubishi Electric MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-T2 &lt;=26 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-EIP &lt;=10 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-SX &lt;=05 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric MELSEC iQ-R Series Ethernet Interface Module RJ71EN71 &lt;=85 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN master/local Station Communication LSI CP610 NZ2GACP610-60 &lt;=05 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric CC-Link IE TSN master/local Station Communication LSI CP610 NZ2KT-NPETNG51 &lt;=05 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric MELSEC iQ-F Series FX5 CC-Link IE TSN Master/Local Module FX5-CCLGN-MS &lt;=1.020 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric MELSEC iQ-F Series FX5 Ethernet Module FX5-ENET &lt;=1.200 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP &lt;=1.106 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric MELSEC iQ-R Series CPU module R04ENCPU (Network Part) &lt;=85 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric MELSEC iQ-R Series CPU module R08ENCPU (Network Part) &lt;=85 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric MELSEC iQ-R Series CPU module R16ENCPU (Network Part) &lt;=85 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric MELSEC iQ-R Series CPU module R32ENCPU (Network Part) &lt;=85 (CVE-2025-3511)</li>\n<li>Mitsubishi Electric MELSEC iQ-R Series CPU module R120ENCPU (Network Part) &lt;=85 (CVE-2025-3511)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>Mitsubishi Electric</td>\n<td>Mitsubishi Electric Multiple FA Products (Update D)</td>\n<td>Improper Validation of Specified Quantity in Input</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Japan</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-3511</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service (DoS) vulnerability due to Improper Validation of Specified Quantity in Input (CWE-1284) exists in the Ethernet function of multiple FA products. This vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted UDP packet if CC-Link IE TSN Remote I/O modules NZ2GN2S1-32D, NZ2GN2S1-32T, NZ2GN2S1-32TE, NZ2GN2S1-32DT, NZ2GN2S1-32DTE, NZ2GN2B1-32D, NZ2GN2B1-32T, NZ2GN2B1-32TE, NZ2GN2B1-32DT, NZ2GN2B1-32DTE, NZ2GNCF1-32D, NZ2GNCF1-32T, NZ2GNCE3-32D, NZ2GNCE3-32DT, NZ2GN12A4-16D, NZ2GN12A4-16DE, NZ2GN12A2-16T, NZ2GN12A2-16TE, NZ2GN12A42-16DT, NZ2GN12A42-16DTE, NZ2GN2S1-16D, NZ2GN2S1-16T, NZ2GN2S1-16TE, NZ2GN2B1-16D, NZ2GN2B1-16T, NZ2GN2B1-16TE, CC-Link IE TSN Analog-Digital Converter modules NZ2GN2S-60AD4, NZ2GN2B-60AD4, CC-Link IE TSN Digital-Analog Converter modules NZ2GN2S-60DA4 and NZ2GN2B-60DA4, CC-Link IE TSN FPGA modules NZ2GN2S-D41P01, NZ2GN2S-D41D01, NZ2GN2S-D41PD02, CC-Link IE TSN Remote Station Communication LSIs CP620 with GbE-PHY NZ2GACP620-300, and NZ2GACP620-60 does not receive a valid UDP packet within 3 seconds. This vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition on MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-T2, RJ71GN11-EIP, RJ71GN11-SX, MELSEC iQ-R Series Ethernet Interface Module RJ71EN71, CC-Link IE TSN master/local Station Communication LSIs CP610 NZ2GACP610-60, NZ2KT-NPETNG51, MELSEC iQ-F Series FX5 CC-Link IE TSN Master/Local Module FX5-CCLGN-MS, MELSEC iQ-R Series CPU module R04ENCPU (Network part), R08ENCPU (Network part), R16ENCPU (Network part), R32ENCPU (Network part), and R120ENCPU (Network part), by sending a specially crafted UDP packet. Or this vulnerability could allow a remote attacker to cause a communication delay in Simple CPU communication on MELSEC iQ-F Series FX5 Ethernet Module FX5-ENET and FX5-ENET/IP Ethernet Module FX5-ENET/IP, by sending a specially crafted UDP packet. A system reset of the product is required for recovery in all cases above. Additionally, this vulnerability could allow a remote attacker to cause a timeout error in CC-Link IEF Basic communication on MELSEC iQ-F Series FX5 Ethernet Module FX5-ENET and FX5-ENET/IP Ethernet Module FX5-ENET/IP, by sending a specially crafted UDP packet. Even if a timeout error occurs, communication will be restored once the affected product starts receiving valid UDP packets.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-3511\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Mitsubishi Electric Multiple FA Products (Update D)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Mitsubishi Electric</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32D: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32T: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32TE: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32DT: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32DTE: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32D: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32T: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32TE: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32DT: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32DTE: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCF1-32D: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCF1-32T: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCE3-32D: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCE3-32DT: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A4-16D: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A4-16DE: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A2-16T: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A2-16TE: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A42-16DT: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A42-16DTE: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-16D: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-16T: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-16TE: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-16D: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-16T: &lt;=09, Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-16TE: &lt;=09, Mitsubishi Electric CC-Link IE TSN Analog-Digital Converter module NZ2GN2S-60AD4: &lt;=07, Mitsubishi Electric CC-Link IE TSN Analog-Digital Converter module NZ2GN2B-60AD4: &lt;=07, Mitsubishi Electric CC-Link IE TSN Digital-Analog Converter module NZ2GN2S-60DA4: &lt;=07, Mitsubishi Electric CC-Link IE TSN Digital-Analog Converter module NZ2GN2B-60DA4: &lt;=07, Mitsubishi Electric CC-Link IE TSN FPGA module NZ2GN2S-D41P01: 01, Mitsubishi Electric CC-Link IE TSN FPGA module NZ2GN2S-D41D01: 01, Mitsubishi Electric CC-Link IE TSN FPGA module NZ2GN2S-D41PD02: 01, Mitsubishi Electric CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY NZ2GACP620-300: &lt;=1.08J, Mitsubishi Electric CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY NZ2GACP620-60: &lt;=1.08J, Mitsubishi Electric MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-T2: &lt;=26, Mitsubishi Electric MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-EIP: &lt;=10, Mitsubishi Electric MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-SX: &lt;=05, Mitsubishi Electric MELSEC iQ-R Series Ethernet Interface Module RJ71EN71: &lt;=85, Mitsubishi Electric CC-Link IE TSN master/local Station Communication LSI CP610 NZ2GACP610-60: &lt;=05, Mitsubishi Electric CC-Link IE TSN master/local Station Communication LSI CP610 NZ2KT-NPETNG51: &lt;=05, Mitsubishi Electric MELSEC iQ-F Series FX5 CC-Link IE TSN Master/Local Module FX5-CCLGN-MS: &lt;=1.020, Mitsubishi Electric MELSEC iQ-F Series FX5 Ethernet Module FX5-ENET: &lt;=1.200, Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP: &lt;=1.106, Mitsubishi Electric MELSEC iQ-R Series CPU module R04ENCPU (Network Part): &lt;=85, Mitsubishi Electric MELSEC iQ-R Series CPU module R08ENCPU (Network Part): &lt;=85, Mitsubishi Electric MELSEC iQ-R Series CPU module R16ENCPU (Network Part): &lt;=85, Mitsubishi Electric MELSEC iQ-R Series CPU module R32ENCPU (Network Part): &lt;=85, Mitsubishi Electric MELSEC iQ-R Series CPU module R120ENCPU (Network Part): &lt;=85</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Mitsubishi Electric is releasing fixed version 10 or later for CC-Link IE TSN Remote I/O modules NZ2GN2S1-32D, NZ2GN2S1-32T, NZ2GN2S1-32TE, NZ2GN2S1-32DT, NZ2GN2S1-32DTE, NZ2GN2B1-32D, NZ2GN2B1-32T, NZ2GN2B1-32TE, NZ2GN2B1-32DT, NZ2GN2B1-32DTE, NZ2GNCF1-32D, NZ2GNCF1-32T, NZ2GNCE3-32D, NZ2GNCE3-32DT, NZ2GN12A4-16D, NZ2GN12A4-16DE, NZ2GN12A2-16T, NZ2GN12A2-16TE, NZ2GN12A42-16DT, NZ2GN12A42-16DTE, NZ2GN2S1-16D, NZ2GN2S1-16T, NZ2GN2S1-16TE, NZ2GN2B1-16D, NZ2GN2B1-16T, and NZ2GN2B1-16TE. Please download the fixed update file from the link \"https://www.mitsubishielectric.com/fa/download/index.html\" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at \"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf.\"<br><a href=\"https://www.mitsubishielectric.com/fa/download/index.html\">https://www.mitsubishielectric.com/fa/download/index.html</a></p>\n<p><strong>Vendor fix</strong><br>Mitsubishi Electric is releasing fixed version 08 or later for CC-Link IE TSN Analog-Digital Converter modules NZ2GN2S-60AD4 and NZ2GN2B-60AD4. Please download the fixed update file from the link \"https://www.mitsubishielectric.com/fa/download/index.html\" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at \"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf\".<br><a href=\"https://www.mitsubishielectric.com/fa/download/index.html\">https://www.mitsubishielectric.com/fa/download/index.html</a></p>\n<p><strong>Vendor fix</strong><br>Mitsubishi Electric is releasing fixed version 08 or later for CC-Link IE TSN Digital-Analog Converter modules NZ2GN2S-60DA4 and NZ2GN2B-60DA4. Please download the fixed update file from the link \"https://www.mitsubishielectric.com/fa/download/index.html\" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at \"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf\".<br><a href=\"https://www.mitsubishielectric.com/fa/download/index.html\">https://www.mitsubishielectric.com/fa/download/index.html</a></p>\n<p><strong>Vendor fix</strong><br>Mitsubishi Electric is releasing fixed version 02 or later for CC-Link IE TSN FPGA modules NZ2GN2S-D41P01, NZ2GN2S-D41D01, and NZ2GN2S-D41PD02. Please download the fixed update file from the link \"https://www.mitsubishielectric.com/fa/download/index.html\" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at \"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf\".<br><a href=\"https://www.mitsubishielectric.com/fa/download/index.html\">https://www.mitsubishielectric.com/fa/download/index.html</a></p>\n<p><strong>Vendor fix</strong><br>Mitsubishi Electric is releasing fixed version 1.09K or later for CC-Link IE TSN Remote Station Communication LSIs CP620 with GbE-PHY NZ2GACP620-300 or NZ2GACP620-60. Please download the CP620 sample code from the link \"https://www.mitsubishielectric.com/fa/download/index.html\" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at \"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf\".<br><a href=\"https://www.mitsubishielectric.com/fa/download/index.html\">https://www.mitsubishielectric.com/fa/download/index.html</a></p>\n<p><strong>Vendor fix</strong><br>Mitsubishi Electric is releasing fixed version 28 or later for MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-T2. Please download the fixed update file from the link \"https://www.mitsubishielectric.com/fa/download/index.html\" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at \"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf\".<br><a href=\"https://www.mitsubishielectric.com/fa/download/index.html\">https://www.mitsubishielectric.com/fa/download/index.html</a></p>\n<p><strong>Vendor fix</strong><br>Mitsubishi Electric is releasing fixed version 13 or later for MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-EIP. Please download the fixed update file from the link \"https://www.mitsubishielectric.com/fa/download/index.html\" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at \"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf\".<br><a href=\"https://www.mitsubishielectric.com/fa/download/index.html\">https://www.mitsubishielectric.com/fa/download/index.html</a></p>\n<p><strong>Vendor fix</strong><br>Mitsubishi Electric is releasing fixed version 07 or later for MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-SX. Please download the fixed update file from the link \"https://www.mitsubishielectric.com/fa/download/index.html\" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at \"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf\".<br><a href=\"https://www.mitsubishielectric.com/fa/download/index.html\">https://www.mitsubishielectric.com/fa/download/index.html</a></p>\n<p><strong>Vendor fix</strong><br>Mitsubishi Electric is releasing fixed version 86 or later for MELSEC iQ-R Series Ethernet Interface Module RJ71EN71. Please download the fixed update file from the link \"https://www.mitsubishielectric.com/fa/download/index.html\" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at \"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf\".<br><a href=\"https://www.mitsubishielectric.com/fa/download/index.html\">https://www.mitsubishielectric.com/fa/download/index.html</a></p>\n<p><strong>Vendor fix</strong><br>Mitsubishi Electric is releasing fixed version 06 or later for CC-Link IE TSN master/local Station Communication LSIs CP610 NZ2GACP610-60 and NZ2KT-NPETNG51. Please download the fixed update file from the link \"https://www.mitsubishielectric.com/fa/download/index.html\" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at \"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf\".<br><a href=\"https://www.mitsubishielectric.com/fa/download/index.html\">https://www.mitsubishielectric.com/fa/download/index.html</a></p>\n<p><strong>Vendor fix</strong><br>Mitsubishi Electric is releasing fixed version 1.030 or later for MELSEC iQ-F Series FX5 CC-Link IE TSN Master/Local Module FX5-CCLGN-MS. Please download the fixed update file from the link \"https://www.mitsubishielectric.com/fa/download/index.html\" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at \"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf\".<br><a href=\"https://www.mitsubishielectric.com/fa/download/index.html\">https://www.mitsubishielectric.com/fa/download/index.html</a></p>\n<p><strong>Vendor fix</strong><br>Mitsubishi Electric is releasing fixed version 1.210 or later for MELSEC iQ-F Series FX5 Ethernet Module FX5-ENET. Please download the fixed update file from the link \"https://www.mitsubishielectric.com/fa/download/index.html\" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at \"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf\".<br><a href=\"https://www.mitsubishielectric.com/fa/download/index.html\">https://www.mitsubishielectric.com/fa/download/index.html</a></p>\n<p><strong>Vendor fix</strong><br>Mitsubishi Electric is releasing fixed version 1.107 or later for MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP. Please download the fixed update file from the link \"https://www.mitsubishielectric.com/fa/download/index.html\" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at \"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf\".<br><a href=\"https://www.mitsubishielectric.com/fa/download/index.html\">https://www.mitsubishielectric.com/fa/download/index.html</a></p>\n<p><strong>Vendor fix</strong><br>Mitsubishi Electric is releasing fixed network part firmware version 86 or later for MELSEC iQ-R Series CPU module R04ENCPU (Network part), R08ENCPU (Network part), R16ENCPU (Network part), R32ENCPU (Network part), and R120ENCPU (Network part). Please download the fixed update file from the link \"https://www.mitsubishielectric.com/fa/download/index.html\" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at \"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-001_en.pdf\".<br><a href=\"https://www.mitsubishielectric.com/fa/download/index.html\">https://www.mitsubishielectric.com/fa/download/index.html</a></p>\n<p><strong>Mitigation</strong><br>For customers of the affected products, Mitsubishi Electric recommends using a firewall, virtual private network (VPN), etc. to prevent unauthorized access when internet access is required, to minimize the risk of exploiting this vulnerability.</p>\n<p><strong>Mitigation</strong><br>For customers of the affected products, Mitsubishi Electric recommends using within a LAN and blocking access from untrusted networks and hosts through firewalls, to minimize the risk of exploiting this vulnerability.</p>\n<p><strong>Mitigation</strong><br>For customers of the affected products, Mitsubishi Electric recommends restricting physical access to the products and the LAN to which they are connected, to minimize the risk of exploiting this vulnerability.</p>\n<p><strong>Mitigation</strong><br>For customers of the affected products, Mitsubishi Electric recommends installing anti-virus software on your PC that can access the affected product, to minimize the risk of exploiting this vulnerability.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/1284.html\">CWE-1284 Improper Validation of Specified Quantity in Input</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Mitsubishi Electric discovering this vulnerability</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Mitsubishi Electric 2025-001 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Mitsubishi Electric directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2025-04-25</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2025-04-25</td>\n<td>1</td>\n<td>CISA Republication - Initial Republication</td>\n</tr>\n<tr>\n<td>2025-04-25</td>\n<td>2</td>\n<td>Initial Publication</td>\n</tr>\n<tr>\n<td>2025-10-09</td>\n<td>3</td>\n<td>RJ71GN11-T2, RJ71GN11-EIP, RJ71GN11-SX, RJ71EN71, NZ2GACP610-60, and NZ2KT-NPETNG51 have been added as affected products and fixed products, and the \"remediations\" was revised.</td>\n</tr>\n<tr>\n<td>2025-10-09</td>\n<td>4</td>\n<td>CISA Republication - Update A - Update to Affected products, Impact, Countermeasures for Customers, Countermeasures for Products have been revised. The affected products RJ71GN11-T2, RJ71GN11-EIP, RJ71GN11-SX, RJ71EN71, NZ2GACP610-60 and NZ2KT-NPETNG51 have been added.</td>\n</tr>\n<tr>\n<td>2026-02-03</td>\n<td>5</td>\n<td>CISA Republication - Update B - Update to Summary, Affected products, and Remediations have been revised. The affected products FX5-CCLGN-MS, FX5-ENET, and FX5-ENET/IP have been added.</td>\n</tr>\n<tr>\n<td>2026-02-03</td>\n<td>6</td>\n<td>FX5-CCLGN-MS, AFX5-ENET, and AFX5-ENET/IP have been added as affected products and fixed products, and the \"remediations\" was revised.</td>\n</tr>\n<tr>\n<td>2026-04-23</td>\n<td>7</td>\n<td>Added FX5-CCLGN-MS and FX5-ENET/IP have been added as fixed products, and the \"remediations\" was revised.</td>\n</tr>\n<tr>\n<td>2026-04-30</td>\n<td>8</td>\n<td>CISA Republication - Update C - Added FX5-CCLGN-MS and FX5-ENET/IP that have been fixed to Countermeasures for Products. Affected products, Countermeasures for Customers, and Countermeasures for Products have been revised.</td>\n</tr>\n<tr>\n<td>2026-08-27</td>\n<td>9</td>\n<td>R04ENCPU (Network Part), R08RNCPU (Network Part), R16ENCPU (Network Part), R32ENCPU (Network Part), and R12ENCPU (Network Part) have been added as affected products and fixed products, and the \"remediations\" was revised.</td>\n</tr>\n<tr>\n<td>2026-08-27</td>\n<td>10</td>\n<td>CISA Republication update based on Mitsubishi Electric 2025-001 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 27 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 27 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-01",
        "title": "Xiiaozet LK100W",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to take control over the device.</strong></p>\n<p>The following versions of Xiiaozet LK100W are affected:</p>\n<ul>\n<li>LK100W &lt;2.1.240 (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.8</td>\n<td>Xiiaozet</td>\n<td>Xiiaozet LK100W</td>\n<td>Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Missing Authentication for Critical Function, Authentication Bypass Using an Alternate Path or Channel</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>China</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-78037</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-78037\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Xiiaozet LK100W</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Xiiaozet</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Xiiaozet LK100W: &lt;2.1.240</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Xiiaozet recommends users update to v2.1.240.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/78.html\">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-78239</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. Successful exploitation may permit unauthorized access to the device.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-78239\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Xiiaozet LK100W</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Xiiaozet</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Xiiaozet LK100W: &lt;2.1.240</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Xiiaozet recommends users update to v2.1.240.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-76943</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-76943\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Xiiaozet LK100W</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Xiiaozet</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Xiiaozet LK100W: &lt;2.1.240</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Xiiaozet recommends users update to v2.1.240.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/288.html\">CWE-288 Authentication Bypass Using an Alternate Path or Channel</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Byron Guernsey of Okachobi, LLC reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-27</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-27</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 27 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 27 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/27/cisa-adds-three-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Three Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/27/cisa-adds-three-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added three new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>\n<div class=\"ListContainerWrapper SCXW183571888 BCX8\">\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2023-49105\" target=\"_blank\">CVE-2023-49105</a> ownCloud Improper Authentication Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-53362\" target=\"_blank\">CVE-2026-53362</a> Linux Kernel Unspecified Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-66384\" target=\"_blank\">CVE-2026-66384</a> JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability&nbsp;</li>\n</ul>\n</div>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a class=\"ext\" href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Thu, 27 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 27 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-04",
        "title": "Applied Systems Engineering ASE2000 V2 Communications Test Set",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-04",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-04.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications.</strong></p>\n<p>The following versions of Applied Systems Engineering ASE2000 V2 Communications Test Set are affected:</p>\n<ul>\n<li>ASE2000 &gt;=2.25|&lt;=2.37 (CVE-2018-1285, CVE-2026-18717)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.8</td>\n<td>Applied Systems Engineering</td>\n<td>Applied Systems Engineering ASE2000 V2 Communications Test Set</td>\n<td>Improper Restriction of XML External Entity Reference, Improper Certificate Validation</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Critical Manufacturing, Energy, Water and Wastewater</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2018-1285</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>ASE2000 versions 2.25 through 2.37 is vulnerable to Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE based attacks in applications that accept attacker controlled log4net configuration files.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2018-1285\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Applied Systems Engineering ASE2000 V2 Communications Test Set</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Applied Systems Engineering</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Applied Systems Engineering ASE2000: &gt;=2.25|&lt;=2.37</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>ASE/Kalkitech provides an upgraded version 2.38 that fixes both vulnerabilities and customers are advised to upgrade to version 2.38. In version 2.38 the bundled log4net library is upgraded to version 3.3.1.0, and the IEC 60870-5-104 TLS client certificate validation logic is corrected to ensure proper validation of certificate error conditions.</p>\n<p><strong>Vendor fix</strong><br>All customers running ASE2000 versions 2.25 through 2.37 are affected by this issue and are required to upgrade to version 2.38 or later to apply the security fix. Upgrade instructions and user documentation are available at www.ase-systems.com. For detailed, step-by-step guidance on upgrading to the latest version and patching the impacted components, please contact our support team at support@ase-systems.com.<br><a href=\"http://www.ase-systems.com\">http://www.ase-systems.com</a></p>\n<p><strong>Vendor fix</strong><br>All customers running ASE2000 versions 2.25 through 2.37 are affected by this issue and are required to upgrade to version 2.38 or later to apply the security fix. Upgrade instructions and user documentation are available at www.ase-systems.com. For detailed, step-by-step guidance on upgrading to the latest version and patching the impacted components, please contact our support team at support@ase-systems.com.<br><a href=\"mailto:support@ase-systems.com\">mailto:support@ase-systems.com</a></p>\n<p><strong>Mitigation</strong><br>Until the upgrade can be applied, the following interim measures reduce exposure:</p>\n<p><strong>Vendor fix</strong><br>Restrict write access to the ASE2000 installation directory and its configuration files to trusted administrators only.</p>\n<p><strong>Vendor fix</strong><br>Avoid using IEC 60870-5-104 over TLS across untrusted or shared networks; place ASE2000 hosts on an isolated, segmented network reachable only by intended peers.</p>\n<p><strong>Mitigation</strong><br>Ensure the host is protected by a network firewall.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/611.html\">CWE-611 Improper Restriction of XML External Entity Reference</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.2</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-18717</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability, which may allow an attacker to impersonate the trusted peer, complete the TLS handshake, and read or modify protected communications.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-18717\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Applied Systems Engineering ASE2000 V2 Communications Test Set</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Applied Systems Engineering</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Applied Systems Engineering ASE2000: &gt;=2.25|&lt;=2.37</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>ASE/Kalkitech provides an upgraded version 2.38 that fixes both vulnerabilities and customers are advised to upgrade to version 2.38. In version 2.38 the bundled log4net library is upgraded to version 3.3.1.0, and the IEC 60870-5-104 TLS client certificate validation logic is corrected to ensure proper validation of certificate error conditions.</p>\n<p><strong>Vendor fix</strong><br>All customers running ASE2000 versions 2.25 through 2.37 are affected by this issue and are required to upgrade to version 2.38 or later to apply the security fix. Upgrade instructions and user documentation are available at www.ase-systems.com. For detailed, step-by-step guidance on upgrading to the latest version and patching the impacted components, please contact our support team at support@ase-systems.com.<br><a href=\"http://www.ase-systems.com\">http://www.ase-systems.com</a></p>\n<p><strong>Vendor fix</strong><br>All customers running ASE2000 versions 2.25 through 2.37 are affected by this issue and are required to upgrade to version 2.38 or later to apply the security fix. Upgrade instructions and user documentation are available at www.ase-systems.com. For detailed, step-by-step guidance on upgrading to the latest version and patching the impacted components, please contact our support team at support@ase-systems.com.<br><a href=\"mailto:support@ase-systems.com\">mailto:support@ase-systems.com</a></p>\n<p><strong>Mitigation</strong><br>Until the upgrade can be applied, the following interim measures reduce exposure:</p>\n<p><strong>Vendor fix</strong><br>Restrict write access to the ASE2000 installation directory and its configuration files to trusted administrators only.</p>\n<p><strong>Vendor fix</strong><br>Avoid using IEC 60870-5-104 over TLS across untrusted or shared networks; place ASE2000 hosts on an isolated, segmented network reachable only by intended peers.</p>\n<p><strong>Mitigation</strong><br>Ensure the host is protected by a network firewall.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/295.html\">CWE-295 Improper Certificate Validation</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.4</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N\">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.1</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Enoch Wang reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-27</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-27</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 27 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 27 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-03",
        "title": "Rockwell Automation OTTO Fleet Manager",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-03",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-03.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes.</strong></p>\n<p>The following versions of Rockwell Automation OTTO Fleet Manager are affected:</p>\n<ul>\n<li>OTTO Fleet Manager &lt;=V2.36.2 (CVE-2026-75112)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 6.8</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation OTTO Fleet Manager</td>\n<td>Use of Password Hash With Insufficient Computational Effort</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-75112</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A security issue exists within OTTO Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. If an attacker gains access to an unencrypted system backup, the weakly hashed credentials could be more easily compromised.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-75112\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation OTTO Fleet Manager</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation OTTO Fleet Manager: &lt;=V2.36.2</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Rockwell Automation has addressed this vulnerability in software version 2.36.3.<br><a href=\"https://file-share.ottomotors.com/login\">https://file-share.ottomotors.com/login</a></p>\n<p><strong>Mitigation</strong><br>Users of the affected software who are not able to upgrade to the corrected version or apply the mitigations should use Rockwell Automation's security best practices.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Vendor fix</strong><br>See Rockwell Automation security advisory SD1791 for more information about this issue and instructions to enable encrypted system backup in OTTO Fleet Manager.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1791.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1791.html</a></p>\n<p><strong>Mitigation</strong><br>If you have any questions regarding the security issue(s) above and how to mitigate them, contact Rockwell Automation support.<br><a href=\"https://ottomotors.com/otto-care/\">https://ottomotors.com/otto-care/</a></p>\n<p><strong>Mitigation</strong><br>If you have any questions regarding this disclosure, please email Rockwell Automation PSIRT: rasecure@ra.rockwell.com<br><a href=\"mailto:rasecure@ra.rockwell.com\">mailto:rasecure@ra.rockwell.com</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/916.html\">CWE-916 Use of Password Hash With Insufficient Computational Effort</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N\">CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-27</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-27</td>\n<td>1</td>\n<td>Initial Republication of Rockwell Automation SD1791.</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 27 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 27 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-02",
        "title": "All-Line Equipment Company Fuel-Boss",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems.</strong></p>\n<p>The following versions of All-Line Equipment Company Fuel-Boss are affected:</p>\n<ul>\n<li>Fuel-Boss V1 Standard &gt;=|&lt;=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)</li>\n<li>Fuel-Boss V1 Portal &gt;=|&lt;=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)</li>\n<li>Fuel-Boss V1 Master/Slave &gt;=|&lt;=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)</li>\n<li>Fuel-Boss V1 Backflush Systems &gt;=|&lt;=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.7</td>\n<td>All-Line Equipment Company</td>\n<td>All-Line Equipment Company Fuel-Boss</td>\n<td>Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'), Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Defense Industrial Base, Emergency Services, Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2018-19518</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Fuel-Boss is vulnerable to the University of Washington IMAP Toolkit 2007f on UNIX, used in imap_open() in PHP and other products, launching an rsh command via the imap_rimap and tcp_aopen functions without preventing argument injection, which can allow remote attackers to execute arbitrary OS commands when an untrusted IMAP server name is supplied and rsh has been replaced by a program with different argument semantics such as ssh. This enables attacks through IMAP server names containing a \"-oProxyCommand\" argument, as well as a stack-based buffer overflow that may allow an attacker to remotely execute arbitrary code.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2018-19518\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>All-Line Equipment Company Fuel-Boss</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>All-Line Equipment Company</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>All-Line Equipment Company Fuel-Boss V1 Standard: &gt;=|&lt;=PHP_7.1.5_7.1.5, All-Line Equipment Company Fuel-Boss V1 Portal: &gt;=|&lt;=PHP_7.1.5_7.1.5, All-Line Equipment Company Fuel-Boss V1 Master/Slave: &gt;=|&lt;=PHP_7.1.5_7.1.5, All-Line Equipment Company Fuel-Boss V1 Backflush Systems: &gt;=|&lt;=PHP_7.1.5_7.1.5</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Fixes are available for the Fuel-Boss V1 Standard and Fuel-Boss V1 Portal. Please contact All-Line Equipment Company (866-356-3336) for instructions on how to receive these fixes.</p>\n<p><strong>Vendor fix</strong><br>Fixes are not yet available for the Fuel-Boss V1 Master/Slave.</p>\n<p><strong>Vendor fix</strong><br>No fix is planned for Fuel-Boss V1 Backflush Systems.</p>\n<p><strong>Mitigation</strong><br>All-Line Equipment Company recommends either taking products that are not fixed off the Internet or restricting the IP addresses that can access them at the router level.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/88.html\">CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2019-11043</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Fuel-Boss running versions up to and including PHP 7.1.5 is vulnerable because certain FPM configurations allow the FPM module to write past allocated buffers into space reserved for FCGI protocol data, thereby creating a possible remote code execution condition.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2019-11043\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>All-Line Equipment Company Fuel-Boss</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>All-Line Equipment Company</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>All-Line Equipment Company Fuel-Boss V1 Standard: &gt;=|&lt;=PHP_7.1.5_7.1.5, All-Line Equipment Company Fuel-Boss V1 Portal: &gt;=|&lt;=PHP_7.1.5_7.1.5, All-Line Equipment Company Fuel-Boss V1 Master/Slave: &gt;=|&lt;=PHP_7.1.5_7.1.5, All-Line Equipment Company Fuel-Boss V1 Backflush Systems: &gt;=|&lt;=PHP_7.1.5_7.1.5</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Fixes are available for the Fuel-Boss V1 Standard and Fuel-Boss V1 Portal. Please contact All-Line Equipment Company (866-356-3336) for instructions on how to receive these fixes.</p>\n<p><strong>Vendor fix</strong><br>Fixes are not yet available for the Fuel-Boss V1 Master/Slave.</p>\n<p><strong>Vendor fix</strong><br>No fix is planned for Fuel-Boss V1 Backflush Systems.</p>\n<p><strong>Mitigation</strong><br>All-Line Equipment Company recommends either taking products that are not fixed off the Internet or restricting the IP addresses that can access them at the router level.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/120.html\">CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N\">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.4</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N\">CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>These vulnerabilities were anonymously reported to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>These vulnerabilities have a high attack complexity.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-27</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-27</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 27 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 27 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Six Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added six new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>\n<div class=\"ListContainerWrapper SCXW183571888 BCX8\">\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2015-3246\" target=\"_blank\">CVE-2015-3246</a> Red Hat Libuser Race Condition Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2015-5287\" target=\"_blank\">CVE-2015-5287</a> Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2019-1068\" target=\"_blank\">CVE-2019-1068</a> Microsoft SQL Server Remote Code Execution Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2021-23758\" target=\"_blank\">CVE-2021-23758</a> Ajax.NET Professional Deserialization of Untrusted Data Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2022-0995\" target=\"_blank\">CVE-2022-0995</a> Linux Kernel Out-of-Bounds Write Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-8452\" target=\"_blank\">CVE-2026-8452</a> Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability</li>\n</ul>\n</div>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a class=\"ext\" href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Wed, 26 Aug 26 12:00:00 +0000",
        "last_updated": "Wed, 26 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/resources-tools/resources/cisa-vulnerability-review",
        "title": "CISA Vulnerability Review",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/resources-tools/resources/cisa-vulnerability-review",
        "summary": "<p>Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and organizations can reduce their risk by addressing these underlying weaknesses and prioritizing vulnerabilities for action based on the risk they pose.</p>\n<p>The <a href=\"https://www.cisa.gov/sites/default/files/2026-08/cisa-vulnerability-review-fy-2024-2025-508.pdf\"><em>CISA Vulnerability Review</em></a><em>&nbsp;</em>provides organizations with critical insights into the root causes of insecure software and practical steps they can take to address these flaws to prevent exploitation. Analyzing CISA and open source data from fiscal years 2024 and 2025, the review establishes a baseline of today\u2019s vulnerability landscape before AI-enabled vulnerability discovery becomes more widespread. The review demonstrates the importance of&nbsp;<a href=\"https://www.cisa.gov/securebydesign\">Secure by Design</a> principles in shifting cybersecurity efforts from reacting to threat actors to proactively fixing preventable software flaws.</p>\n<p>The review also identifies common software weaknesses that contribute to exploitable vulnerabilities and details practices software producers can use to prevent these weaknesses from recurring. By examining the patterns across vulnerability data, the review helps organizations focus on systemic improvements that can reduce entire classes of vulnerabilities rather than addressing individual vulnerabilities only after they are discovered.</p>\n<p>Additionally, the review shows organizations how to prioritize vulnerabilities for action using the framework outlined in&nbsp;<a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk\">Binding Operational Directive 26-04: <em>Prioritizing Security Based on Risk</em></a>. This framework evaluates vulnerabilities using four key criteria: exposure status,&nbsp;<a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">Known Exploited Vulnerability (KEV) Catalog</a> status, potential for automated exploitation, and technical impact.</p>",
        "summary_is_html": true,
        "first_seen": "Wed, 26 Aug 26 12:00:00 +0000",
        "last_updated": "Wed, 26 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-04",
        "title": "PayRange API",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-04",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-04.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify the device to cause a denial of service, or alter a devices displayed image.</strong></p>\n<p>The following versions of PayRange API are affected:</p>\n<ul>\n<li>PayRange API vers:all/*</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.8</td>\n<td>PayRange</td>\n<td>PayRange API</td>\n<td>Missing Authorization</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Commercial Facilities</li>\n<li><strong>Countries/Areas Deployed: </strong>United States, Canada</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-18965</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-18965\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>PayRange API</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>PayRange</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>PayRange PayRange API: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>PayRange has not responded to requests to work with CISA to mitigate this vulnerability. Users of PayRange devices are invited to contact PayRange customer support at support@payrange.com for additional information.<br><a href=\"mailto:support@payrange.com\">mailto:support@payrange.com</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/862.html\">CWE-862 Missing Authorization</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Tahi Wilton Geary reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-25</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-25</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 25 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 25 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-07",
        "title": "FURUNO FA-50 Class B AIS Transponder",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-07",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-07.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to alter device settings.</strong></p>\n<p>The following versions of FURUNO FA-50 Class B AIS Transponder are affected:</p>\n<ul>\n<li>FURUNO FA-50 Class B AIS Transponder vers:all/*</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.1</td>\n<td>FURUNO ELECTRIC CO.,LTD.</td>\n<td>FURUNO FA-50 Class B AIS Transponder</td>\n<td>Use of Hard-coded Credentials, Missing Authentication for Critical Function</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Japan</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-59769</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An attacker, who knows the credentials and has access to the in-vessel network to which the device is connected to, may operate the settings screen using that credentials to alter the settings of the device.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-59769\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>FURUNO FA-50 Class B AIS Transponder</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>FURUNO ELECTRIC CO.,LTD.</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>FURUNO FA-50 Class B AIS Transponder: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>FURUNO ELECTRIC CO.,LTD. notes that production of this product ended in October 2020, and software updates will no longer be provided. FURUNO recommends users do not connect the product directly to the internet. To prevent unauthorized access, the vessel on which the product is installed should be properly locked and managed.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/798.html\">CWE-798 Use of Hard-coded Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.1</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-67578</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Some configurations may be changed on the management screen without authentication.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-67578\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>FURUNO FA-50 Class B AIS Transponder</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>FURUNO ELECTRIC CO.,LTD.</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>FURUNO FA-50 Class B AIS Transponder: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>FURUNO ELECTRIC CO.,LTD. notes that production of this product ended in October 2020, and software updates will no longer be provided. FURUNO recommends users do not connect the product directly to the internet. To prevent unauthorized access, the vessel on which the product is installed should be properly locked and managed.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Souvik Kandar reported these vulnerabilities to CISA</li>\n<li>JPCERT/CC coordinated with Furuno Electric and CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-25</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-25</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 25 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 25 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-01",
        "title": "Rently Smart Home",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to access sensitive information and override user permissions.</strong></p>\n<p>The following versions of Rently Smart Home are affected:</p>\n<ul>\n<li>Smart Home &lt;=20.1.0</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.1</td>\n<td>Rently</td>\n<td>Rently Smart Home</td>\n<td>Insufficiently Protected Credentials</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Commercial Facilities, Communications, Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>United States, India</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-75960</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-75960\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rently Smart Home</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rently</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rently Smart Home: &lt;=20.1.0</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Rently has patched this vulnerability in late June. No user action is required.</p>\n<p><strong>Mitigation</strong><br>For more information, contact Rently (support@rently.com).<br><a href=\"mailto:support@rently.com\">mailto:support@rently.com</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/522.html\">CWE-522 Insufficiently Protected Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Berk Dusunur reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-25</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-25</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 25 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 25 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-03",
        "title": "Siemens SIMATIC IoT2050 Advanced",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-03",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-03.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released a new version for SIMATIC IoT2050 Advanced and strongly recommends to update to the latest version.</strong></p>\n<p>The following versions of Siemens SIMATIC IoT2050 Advanced are affected:</p>\n<ul>\n<li>SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) vers:intdot/&lt;4.3.4.1</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 10</td>\n<td>Siemens</td>\n<td>Siemens SIMATIC IoT2050 Advanced</td>\n<td>Missing Authentication for Critical Function</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Critical Manufacturing, Energy, Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-58115</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-58115\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SIMATIC IoT2050 Advanced</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) &lt; V4.3.4.1 running Industrial OS with Node-RED installed</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Harden the Node-RED installation (see Node-RED User Guide)</p>\n<p><strong>Mitigation</strong><br>Uninstall Node-RED</p>\n<p><strong>Vendor fix</strong><br>Update to V4.3.4.1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109741799/\">https://support.industry.siemens.com/cs/ww/en/view/109741799/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>10</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-834709 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-11</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-11</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-08-25</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-834709 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 25 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 25 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/25/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/25/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a class=\"fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn\" href=\"https://www.cve.org/CVERecord?id=CVE-2026-60004\" target=\"_blank\" title=\"https://www.cve.org/cverecord?id=cve-2026-60004\" id=\"menur1m61\" rel=\"noreferrer noopener\">CVE-2026-60004</a> Gitea Code Injection Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://edit.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a class=\"ext\" href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Tue, 25 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 25 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a",
        "title": "A Tale of Two SOCs: Insights From Two Red Team Assessments",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a",
        "summary": "<h2><strong>Advisory at a Glance</strong></h2>\n<table>\n<tbody>\n<tr>\n<th>Title</th>\n<td>A Tale of Two SOCs: Insights From Two Red Team Assessments</td>\n</tr>\n<tr>\n<th>Original Publication&nbsp;</th>\n<td><strong>August 25, 2026</strong></td>\n</tr>\n<tr>\n<th>Executive Summary</th>\n<td>\n<p>The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A failed to detect or contain the activity, but Organization B rapidly identified initial compromise attempts, isolated affected systems, and forced the red team into an assume breach model.</p>\n<p>This advisory details the red team\u2019s activity and organizations\u2019 defensive actions, offering lessons learned and mitigations to help critical infrastructure organizations strengthen detection, response, and protections in IT, cloud, and operational technology (OT) environments.</p>\n</td>\n</tr>\n<tr>\n<th>Lessons Learned</th>\n<td>\n<ul type=\"square\">\n<li><strong>Untuned detection tools lead to missed threats</strong>. Without well-defined baselines and alert filtering, false positives and routine alerts overwhelm network defenders.</li>\n<li><strong>Organizational silos and bureaucratic hurdles prevent effective incident response</strong>. Detection tools are only as effective as the people, processes, and procedures supporting them; fragmented communication, unclear responsibilities, and limited defender authority hinder effective incident response.</li>\n<li><strong>Cloud environments are often an underestimated risk</strong>. Organizations often lack security controls for cloud environments and processes for responding to a cloud compromise.</li>\n</ul>\n</td>\n</tr>\n<tr>\n<th>Key Actions</th>\n<td>\n<ul type=\"square\">\n<li><strong>Establish and continuously maintain a baseline and reduce alert noise</strong> by fine tuning.</li>\n<li><strong>Break down silos and empower network defenders</strong>.</li>\n<li><strong>Implement Conditional Access policies for workload identities</strong> and monitor for excessive or unused permissions.</li>\n<li><strong>Establish and regularly review comprehensive procedures for detecting, remediating, and revoking access/refresh tokens</strong> in the event of a cloud compromise.</li>\n</ul>\n</td>\n</tr>\n<tr>\n<th>Intended Audience</th>\n<td>\n<p><strong>Organizations:</strong> Federal Civilian Executive Branch agencies; state, local, tribal, and territorial governments; critical infrastructure.</p>\n<p><strong>Roles:</strong> <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/systems-administration\" target=\"_blank\" title=\"System administrators\">System administrators</a>, <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/incident-response\" target=\"_blank\" title=\"incident responders\">incident responders</a>, <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/defensive-cybersecurity\" target=\"_blank\" title=\"defensive cybersecurity analysts\">defensive cybersecurity analysts</a>, <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/vulnerability-analysis\" target=\"_blank\" title=\"vulnerability analysts\">vulnerability analysts</a>, <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/network-operations\" target=\"_blank\" title=\"network operators\">network operators</a>, <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/systems-security-management\" target=\"_blank\" title=\"security systems managers\">security systems managers</a>, and all network defenders.</p>\n</td>\n</tr>\n</tbody>\n</table>\n<h2><strong>Introduction</strong></h2>\n<p>The Cybersecurity and Infrastructure Security Agency\u2019s (CISA\u2019s) red team simulates real\u2011world malicious cyber operations to assess an organization\u2019s ability to detect, investigate, and respond to malicious cyber activity. Emulating cyber threat actor tradecraft, the red team attempts to gain and maintain persistent access to an organization\u2019s network and sensitive business systems (SBSs) while avoiding detection.</p>\n<p>CISA conducted two simultaneous red team assessments using similar tradecraft but observed different defensive responses. In one organization (Organization A), the team gained initial access to multiple workstations, gained elevated privileges over the domain, and moved laterally to SBSs and cloud resources undetected. In the second organization (Organization B), network defenders quickly detected the initial compromise and quarantined the affected systems.</p>\n<p>Because Organization B detected the initial compromise, the red team moved to an assume breach model, where Organization B trusted agents (TAs) provided access to a host that replicated the level of access the red team would have had if defenders had not detected their activity. From there, the red team escalated privileges and moved laterally to SBSs, cloud resources, and a bastion host in the OT demilitarized zone (DMZ), where defenders again detected activity and isolated the system.</p>\n<p>In coordination with the assessed organizations, CISA is releasing this Cybersecurity Advisory to describe the red team\u2019s activity and the organization\u2019s defensive responses and to share lessons learned that critical infrastructure organizations can use to strengthen their IT, cloud, and OT cybersecurity posture.</p>\n<p>CISA encourages critical infrastructure organizations to implement the recommendations in the <a href=\"#Mitigations\"><strong>Mitigations</strong></a><strong> </strong>section of this advisory to reduce the likelihood and impact of malicious cyber incidents.</p>\n<p>Download the PDF version of this report:</p>\n\n\n\n\n\n<div class=\"c-file\">\n    <div class=\"c-file__download\">\n    <a href=\"/sites/default/files/2026-08/aa26-237a-tale-of-two-SOCs-insights-two-red-team-assessments-508c.pdf\" class=\"c-file__link\" target=\"_blank\">A Tale of Two SOCs: Insights From Two Red Team Assessments</a>\n    <span class=\"c-file__size\">(PDF,       937.09 KB\n  )</span>\n  </div>\n</div>\n<h2><strong>Technical Details</strong></h2>\n<p><strong>Note:</strong> This advisory uses the <a href=\"https://attack.mitre.org/versions/v19/matrices/enterprise/\" target=\"_blank\" title=\"MITRE ATTACK Matrix for Enterprise\">MITRE ATT&amp;CK<sup>\u00ae</sup> Matrix for Enterprise</a> framework, version 19.&nbsp;See the <a href=\"#MITRE\"><strong>MITRE ATT&amp;CK Tactics and Techniques</strong></a> section of this advisory for a table of the red team\u2019s activity mapped to MITRE ATT&amp;CK tactics and techniques.</p>\n<h3><strong>Overview</strong></h3>\n<p>CISA is authorized\u2014upon request\u2014to provide analyses, expertise, and other technical assistance to critical infrastructure owners and operators and to provide operational and timely technical assistance to federal and non-federal entities, with respect to cybersecurity risks (see generally 6 U.S.C. \u00a7\u00a7 652[c][5], 659[c][6]). CISA conducted two concurrent red team assessments: one at a <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/government-services-facilities-sector\">Government Services and Facilities Sector</a> organization (Organization A), and one at a <a href=\"https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/water-and-wastewater-sector\">Water and Wastewater Systems Sector</a> organization (Organization B).</p>\n<p>During CISA\u2019s red team assessments, the red team simulates malicious cyber operations to assess an organization\u2019s threat detection and response capabilities. The red team attempts to gain and maintain persistent access to an organization\u2019s enterprise network, avoid detection, evade defenses, and access SBSs (applications, data stores, or infrastructure components where compromise would materially impact the organization's operations, finances, or customer data) selected by the organization. For the assessments described in this advisory, the team also attempted to gain access to cloud resources and to demonstrate their ability to access Organization B\u2019s OT systems without actually doing so.</p>\n<h3><strong>Organization A</strong></h3>\n<h4><strong>Red Team Cyber Threat Activity</strong></h4>\n<h5><em><strong>Initial Access and Active Directory Discovery</strong></em></h5>\n<p>During reconnaissance, CISA\u2019s red team identified a web application with default credentials [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1589/001/\" target=\"_blank\" title=\"T1589.001\">T1589.001</a>] for multiple built-in user accounts that allowed the team to send emails from an internal email address. The team used the internal email address to send phishing emails [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1566/\" target=\"_blank\" title=\"T1566\">T1566</a>] and gained initial access to four workstations.</p>\n<p>From the workstations, the red team leveraged a modified BloodHound<a href=\"#Note1\"><sup>1</sup></a> collector, customized to avoid static endpoint detection and response (EDR) signatures, to query and scrape Active Directory (AD) information. This information included AD users [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1087/002/\" target=\"_blank\" title=\"T1087.002\">T1087.002</a>], computers [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1018/\" target=\"_blank\" title=\"T1018\">T1018</a>], groups [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1069/002\" target=\"_blank\" title=\"T1069.002\">T1069.002</a>], access control lists, organizational units, and group policy objects (GPOs) [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1615/\" target=\"_blank\" title=\"T1615\">T1615</a>]. The team found that one compromised workstation had the default Machine Account Quota (MAQ) of 10, allowing unprivileged users to add up to 10 computer accounts to the domain.</p>\n<p>The red team also queried the organization\u2019s Active Directory Certificate Service (ADCS) certificate templates. Misconfigured ADCS templates are common and can allow low-privileged accounts to request a certificate on behalf of other users and computers, including highly privileged accounts. The team identified multiple templates with an ESC1 misconfiguration, which allows any user to request certificates for all users and computer accounts (see scenario ESC1 in SpecterOp\u2019s <a href=\"https://specterops.io/wp-content/uploads/sites/3/2022/06/Certified_Pre-Owned.pdf\" target=\"_blank\">Certified Pre-Owned: Abusing Active Directory Certificate Services</a>). The red team exploited the misconfigured MAQ to create a machine account [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1136/002/\" target=\"_blank\">T1136.002</a>] and then exploited a misconfigured ADCS template to request a certificate for the newly created machine account [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1649/\" target=\"_blank\">T1649</a>]. They could then obtain certificates for any user account, providing means for lateral movement.</p>\n<h5><em><strong>Post Exploitation: Privilege Escalation and Lateral Movement</strong></em></h5>\n<h6>Sensitive Business Systems</h6>\n<p>After the red team gained elevated privileges over the domain, they began post-exploitation activities and attempted to access SBSs. To access the SBSs, the team needed to identify their network location and security controls.</p>\n<p>The team\u2019s plan to achieve SBS access included the following steps:</p>\n<ol>\n<li>Use previously acquired AD data to identify users and groups related to the SBS.</li>\n<li>Query system center configuration manager (SCCM) servers to enumerate user-device relationships and identify the workstations assigned to each user [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1033/\" target=\"_blank\" title=\"T1033\">T1033</a>].</li>\n<li>Move laterally from the SCCM server to the target users\u2019 workstations.</li>\n<li>Find credential material on the target user\u2019s workstation to access the SBS.</li>\n<li>Verify administrative access to the SBS would allow compromise of the availability, integrity, and/or confidentiality of the system and its data.</li>\n</ol>\n<p>For each SBS, the red team used similar discovery and initial access techniques but unique credential retrieval methods. For SBS 1, a database, the team located cleartext credentials on an administrative user\u2019s workstation providing access to the system [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1552/\" target=\"_blank\" title=\"T1552\">T1552</a>]. For SBS 2, also a database, the red team searched the targeted user\u2019s workstations for <code>connections.json</code> and <code>product-preferences.xml</code> files for a Structured Query Language (SQL) developer tool. The team decrypted these files to obtain the cleartext password to the database [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1552/001/\" target=\"_blank\" title=\"T1552.001\">T1552.001</a>]. For SBS 3, an automated processing system, the red team acquired long-lived static Amazon Web Service (AWS) identity and access management (IAM) user credentials saved in configuration files in targeted users\u2019 home directories. These credentials do not expire because the organization had not configured credential expiration or rotation.</p>\n<p>For SBS 2 and 3, the red team expanded access beyond users\u2019 physical workstations to include their virtual desktops, which limited their access to the active, interactive sessions held by users. While virtual workstations add security controls, such as segmenting networks of sensitive systems to only allow virtual hosts, they are generally synchronized with a root drive of the distributed file system (DFS). The red team compromised the root DFS drive, granting them access to local files of all users\u2019 virtual desktops, regardless of the existence of an active session. This allowed the team to quickly search for cloud configuration files containing credentials and database connection files for thousands of users.</p>\n<p>The red team obtained administrative access to all targeted SBSs without defensive intervention by proxying tools [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1090/001/\" target=\"_blank\" title=\"T1090.001\">T1090.001</a>] through compromised workstations and using the collected credentials.</p>\n<h6>Microsoft Entra Systems</h6>\n<p>After compromising the target SBSs, the red team attempted to compromise Organization A\u2019s Microsoft cloud environment by compromising Organization A\u2019s Microsoft Entra ID (formerly Azure AD) through applications. The team targeted Entra ID applications with Application permissions, which allow applications to access data without user consent (compared to Delegated permissions, which allow applications to access data with user consent). By compromising an application that had elevated Application permissions, the red team would gain the same permissions as the application because these applications operate outside the scope of traditional conditional access policies (CAPs) that provide controls for user access and activity.</p>\n<p><strong>Note:</strong> Microsoft\u2019s <a href=\"https://learn.microsoft.com/en-us/entra/identity/conditional-access/workload-identity\" target=\"_blank\" title=\"Conditional Access for workload identities\">Conditional Access for workload identities</a> extends traditional CAPs to service principals (SPs) used by applications and governs Application permissions by allowing organizations to broadly apply access policies to applications. Implementing Conditional Access for workload identities would have protected against red team exploiting use of Application permissions; however, the red team never observed an organization using Conditional Access for workload identities.</p>\n<p>The team compromised applications and used their permissions by:</p>\n<ol>\n<li>Enumerating the organization\u2019s cloud resources using the publicly available tools, including AzureHound<a href=\"#Note2\"><sup>2</sup></a> and ROADrecon,<a href=\"#Note3\"><sup>3</sup></a> to gather information about applications, their permissions, and their owners [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1526/\" target=\"_blank\" title=\"T1526\">T1526</a>] [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1588/002/\" target=\"_blank\" title=\"T1588.002\">T1588.002</a>].</li>\n<li>Identifying applications with elevated permissions to the Microsoft Graph Resource application programming interface (API), including the following:<br>\n<ol type=\"a\">\n<li><code>Mail.Read</code> \u2013 Read Outlook emails.</li>\n<li><code>Mail.ReadWrite</code> \u2013 Read and write Outlook emails.</li>\n<li><code>Chat.Read.All</code> \u2013 Access Teams messages.</li>\n<li><code>Files.Read.All</code> \u2013 Access OneDrive.</li>\n<li><code>Application.ReadWrite.All</code> \u2013 Add Client Secrets to any application or SP.</li>\n<li><code>AppRoleAssignment.ReadWrite.All</code> \u2013 Lets an SP grant itself powerful Graph application permissions such as <code>Chat.Read.All</code> or <code>RoleManagement.ReadWrite.Directory</code>.</li>\n</ol>\n</li>\n<li>Identifying the owner of an application with <code>Mail.ReadWrite</code> permissions.</li>\n<li>Moving laterally to the owner\u2019s machine.</li>\n<li>Obtaining access to the user\u2019s primary refresh token (PRT).<br>\n<ol type=\"a\">\n<li>A PRT is a secure artifact specifically issued to Microsoft first-party token brokers to enable single sign-on (SSO) across the applications used on those devices. For more information about PRT, see Microsoft\u2019s <a href=\"https://learn.microsoft.com/en-us/entra/identity/devices/concept-primary-refresh-token?tabs=windows-prt-issued%2Cbrowser-behavior-windows%2Cwindows-prt-used%2Cwindows-prt-renewal%2Cwindows-prt-protection%2Cwindows-apptokens%2Cwindows-browsercookies%2Cwindows-mfa\" target=\"_blank\" title=\"Understanding Primary Refresh Token (PRT) in Microsoft Entra ID\">Understanding Primary Refresh Token (PRT) in Microsoft Entra ID</a>.</li>\n</ol>\n</li>\n<li>Using the PRT to request access and refresh tokens for the targeted application\u2019s owner.<br>\n<ol type=\"a\">\n<li><strong>Access tokens</strong> are short-lived tokens issued by Entra ID that grant a client permission to access specific resources or APIs on behalf of a user.</li>\n<li><strong>Refresh tokens</strong> are longer-lived tokens issued by Entra ID that allow a client to silently request new access tokens without requiring the user to sign in again.</li>\n</ol>\n</li>\n<li>Using the access token to add a new client secret to the target application.<br>\n<ol type=\"a\">\n<li>A <strong>client secret</strong> is a confidential string used by the application to authenticate itself to Entra ID during token requests.</li>\n</ol>\n</li>\n<li>Using the new client secret to request a new access token for the target application.</li>\n<li>Impersonating the application by using the access token [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1550/001/\" target=\"_blank\" title=\"T1550.001\">T1550.001</a>] to retrieve and review target emails [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1114/\" target=\"_blank\" title=\"T1114\">T1114</a>] via the Microsoft Graph API.</li>\n</ol>\n<p>This allowed the red team to review security operations center (SOC) staff emails to see if SOC staff were aware of the compromise.</p>\n<h4><strong>Organization A\u2019s Response</strong></h4>\n<p>The organization did not respond effectively to red team activity. The red team observed this during their engagement by accessing SOC personnel emails and moving laterally to SOC workstations where they captured screenshots [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1113/\" target=\"_blank\" title=\"T1113\">T1113</a>], used keyloggers [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1056/001/\" target=\"_blank\" title=\"T1056.001\">T1056.001</a>], and retrieved Microsoft Teams messages [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1213/005/\" target=\"_blank\" title=\"T1213.005\">T1213.005</a>].</p>\n<p>The red team observed that the SOC received medium- and low-severity EDR alerts related to the red team activity but did not respond to them. Thousands of false positive alerts corresponding to normal business operations, many with a higher severity, obscured the alerts triggered by red team activity.</p>\n<p>Organizational silos further hindered detection and response. The organization had multiple SOCs and multiple EDR solutions. Staff did not communicate with staff from other SOCs or have visibility on their detection tools. SOC staff and system owners also did not communicate with each other.</p>\n<p>This led to SOC staff not actioning alerts from red team activity. For example, red team members noted chat exchanges regarding an SCCM in which defenders tried and failed to identify the system owner, its function, and its typical use. The SOC team eventually flagged the alert as a false positive.</p>\n<p>The red team believes this was because the SOC staff lacked standard operating procedures for escalating alerts and had limited personnel authority.</p>\n<h3><strong>Organization B</strong></h3>\n<h4><strong>Red Team Cyber Threat Activity</strong></h4>\n<h5><em><strong>Initial Access</strong></em></h5>\n<p>The CISA red team gained initial access to Organization B\u2019s environment through a spearphishing campaign. The team gathered email addresses from public websites [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1589/002/\" target=\"_blank\" title=\"T1589.002\">T1589.002</a>] and sent phishing emails that eventually led to three users clicking [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1204/\" target=\"_blank\" title=\"T1204\">T1204</a>] on a malicious link, giving the red team access to three workstations.</p>\n<p>Each payload execution generated a medium-severity alert: \u201cAn executable file loaded an unexpected DLL file.\u201d SOC staff triaged these alerts and manually isolated all three workstations within 10, 2, and 20 minutes. This effectively terminated the team\u2019s command and control (C2) communications with the workstations. Before staff isolated one workstation, the red team enumerated Organization B\u2019s domain\u2019s AD structure by executing various Lightweight Directory Access Protocol (LDAP) queries through the callback. The data gathered included all users, groups, computers, domains, GPO, and subsequent relationships for the entire domain.</p>\n<p>Because the defenders removed their initial foothold, the red team switched to an assume breach model. Organization B\u2019s TAs (organization IT staff who knew of the assessment and were in contact with the red team) executed a red-team-provided payload on a designated internal host. This host was associated with a standard user account with no administrative privileges, replicating the same level of access the red team would have maintained if Organization B\u2019s defenders had not detected them.</p>\n<h5><em><strong>Domain Compromise</strong></em></h5>\n<p>With persistent access to the internal network, the red team searched for ways to escalate their privileges over the domain to facilitate lateral movement and access SBSs. The red team used the assume breach account to query the MAQ attribute of Organization B\u2019s domain and discovered that all domain users were able to add accounts to the domain.</p>\n<p>The red team created a new machine account with a hostname designed to resemble a legitimate host. The creation of the machine account provided the red team with a domain account and a password that they controlled. This allowed them to execute standalone tools from a red-team-controlled Linux workstation. The tool\u2019s traffic was proxied through the assume breach host, circumventing restrictions imposed by host-based EDR.</p>\n<p>The red team did not identify any escalation paths from the AD data; however, enumeration of SCCM distribution points led to the discovery of an XML file with cleartext credentials for a domain service account. AD data showed that the newly acquired service account had outbound object control over almost 1,000 accounts within the domain due to its group membership. Most notably, the service account had <code>AllExtendedRights</code> permission over a domain controller, which enabled the team to conduct a resource-based constrained delegation attack, granting them DCSync privileges [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1003/006/\" target=\"_blank\" title=\"T1003.006\">T1003.006</a>] and the ability to obtain AD account credentials. The team used these credentials throughout the remainder of their assessment to access servers and workstations. One of the first accounts the red team DCSynced was the <code>krbtgt</code> account, which a malicious cyber actor could use to forge Golden Tickets that allow for impersonation of any user in Organization B\u2019s domain.</p>\n<h5><em><strong>Post Exploitation</strong></em></h5>\n<h6>Sensitive Business Systems</h6>\n<p>The TAs provided the names of two SBSs, one of which the red team successfully compromised. To do this, the team reviewed previously collected BloodHound data and identified a user account with access to an SBS web server that allowed Kerberos authentication. Because the red team had already compromised the on-premises (on-prem) AD environment, they could impersonate this user to access the server.</p>\n<p>The team:</p>\n<ol>\n<li>Used DCSync to acquire the user\u2019s AES256 password hash.</li>\n<li>Used the password hash to request a Kerberos ticket-granting ticket (TGT) for the user.</li>\n<li>Used the TGT to request a Kerberos service ticket [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1558/\" target=\"_blank\" title=\"T1558\">T1558</a>] for the web server\u2019s service principal name (SPN).</li>\n</ol>\n<p>After requesting the Kerberos service ticket, the red team imported it into a Windows virtual machine (VM) on their infrastructure. The red team configured their VM to proxy any traffic to Organization B\u2019s network through a SOCKS proxy that tunneled traffic through a compromised host.</p>\n<h6>Operational Technology Network</h6>\n<p>The red team wanted to gain visibility of the OT network and identify OT network subnets. To do this, they first identified an IT workstation with Remote Desktop Protocol (RDP) files, including a file named <code>ics-[redacted]-org</code>, signifying that the user likely had remote access to the OT network. The red team identified that the workstation had remote access to a bastion host. A bastion host\u2014sometimes referred to as a jump box or jump server\u2014is a specialized, highly secured system (often a server or dedicated workstation) that serves as the sole access point between a network segment (such as an internal IT network) and a protected internal network (like an OT environment).</p>\n<p>The red team gained access to this bastion host using File Transfer Protocol (FTP) credentials to log in over Secure Shell (SSH) [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1021/004/\" target=\"_blank\" title=\"T1021.004\">T1021.004</a>]. At this point, they had visibility over the OT network.</p>\n<p>They attempted to gain a C2 session on the server by dropping several payload files on the host and executing them. However, the callback never reached red team infrastructure because the host blocked outbound internet connections. The payload execution triggered an alert that led SOC staff to quarantine the host.</p>\n<h6>Microsoft Entra Systems</h6>\n<p>The red team attempted to access Organization B\u2019s cloud-based Entra ID infrastructure to find a way to move from on-prem AD to the cloud. Organization B had a hybrid environment, and user credentials automatically synchronized between on-prem AD and cloud Entra ID. Given this, the red team looked for the on-prem server responsible for synchronization.</p>\n<p>Entra ID Connect (formerly Azure AD Connect) sets up an on-prem account with the prefix&nbsp;<code>MSOL_</code> to synchronize credentials with Entra ID. The red team used the open source tool ADConnectDump<a href=\"#Note4\"><sup>4</sup></a><sup>&nbsp;</sup> to obtain cleartext credentials for the on-prem Microsoft Online (MSOL) account and the Entra ID account&nbsp;<code>Sync_[redacted]</code> [<a href=\"https://attack.mitre.org/versions/v19/techniques/T1003\" target=\"_blank\" title=\"T1003\">T1003</a>]. With cleartext credentials for&nbsp;<code>Sync_[redacted]</code>, the red team logged into the Azure portal.&nbsp;<code>Sync_[redacted]</code> was not intended for interactive logins and, in this case, did not have multifactor authentication (MFA) enabled. However, the red team used this account to obtain access tokens for use with AzureHound and ROADrecon to gather Entra ID data for Organization B\u2019s tenant.</p>\n<p><strong>Note:</strong> The red team obtained cleartext MSOL credentials and logged into the Azure portal because MSOL accounts used to have a large number of permissions; Microsoft has since removed these permissions. See Microsoft\u2019s <a href=\"https://techcommunity.microsoft.com/blog/microsoft-entra-blog/action-required-msonline-and-azuread-powershell-retirement---2025-info-and-resou/4364991\" target=\"_blank\" title=\"Action required: MSOnline and AzureAD PowerShell retirement - 2025 info and resources\">Action required: MSOnline and AzureAD PowerShell retirement - 2025 info and resources</a> and <a href=\"https://techcommunity.microsoft.com/blog/microsoft-entra-blog/important-update-deprecation-of-azure-ad-powershell-and-msonline-powershell-modu/4094536\" target=\"_blank\" title=\"Important update: Deprecation of Azure AD PowerShell and MSOnline PowerShell modules\">Important update: Deprecation of Azure AD PowerShell and MSOnline PowerShell modules</a> for more information.</p>\n<p>The interactive login from <code>Sync_[redacted]</code> triggered an automated alert from Microsoft, which sent the information to Organization B\u2019s SOC staff, who then blocked the suspicious activity.</p>\n<p>The red team identified a computer account containing <code>AZURESSO</code> in its name, located in the on-prem AD environment. This account is part of the Seamless SSO implementation and allows users to use Kerberos tickets as the first step in authenticating to Entra ID. To abuse Seamless SSO, the red team acquired encrypted credentials of a target user via DCSync and then used the Rubeus \u201casktgs\u201d module to request service tickets used for SSO. The red team imported the service tickets to their workstation and proxied their traffic through Organization B\u2019s network using a SOCKS proxy. This allowed them to browse to https://portal[.]azure[.]com, while using legitimate Kerberos tickets, and the traffic appeared to originate from a trusted IP address.</p>\n<p>This approach allowed the red team to gain access to Entra ID as any user synced to AD without the user\u2019s cleartext password. However, they could only use Kerberos tickets for the first phase of the sign-in process. If a user was set up to use MFA, then Entra ID would prompt the red team for a second factor during the sign-in process. Therefore, the red team was only able to log into any Entra ID account that did not have MFA enabled, which seemed limited to service accounts. They reviewed the previously obtained Entra ID data and looked for applications that had excessive permissions and were accessible to AD-synced service accounts.</p>\n<p>The red team identified an application that had permission to read, write, and send emails for all users within Organization B\u2019s tenant. The application was owned by an AD-Synced account that was disabled in AD. Using a compromised host in the on-prem environment, they re-enabled this account, DCSynced its credentials, and used the AES256 hash to request Kerberos tickets. The red team used the tickets to authenticate to Entra ID and were then able to add a client secret to the application. This gave them the ability to retrieve the emails of every user within Organization B\u2019s environment from the public internet.</p>\n<h4><strong>Organization B\u2019s Response</strong></h4>\n<p>Organization B quickly triaged and responded to alerts after the red team gained initial access, effectively terminating the team\u2019s C2 communications with the workstations and leading the red team to move to an assume breach model. These actions demonstrated a mature, proactive security posture and helped prevent wider compromise.</p>\n<p>When the red team gained access to a bastion host in the OT DMZ, Organization B had defensive controls that blocked outbound connections to red team infrastructure, and SOC staff quickly triaged and responded to an alert by isolating the host.</p>\n<p>When the red team logged into the organization\u2019s Azure portal via a compromised account, it triggered an automated alert from Microsoft, which led the staff to block the suspicious account. In addition, Organization B had custom detections Entra ID Risky User Alerts for \u201cUnfamiliar sign-in properties\u201d and \u201cSuspicious API traffic\u201d that alerted to the AzureHound user agent and to accounts exceeding predefined request thresholds to the Microsoft Graph API.</p>\n<p>See <a href=\"#Table1\"><strong>Table 1</strong></a> for Organization B\u2019s defensive measures and associated response.</p>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table1\"><em><strong>Table 1</strong></em></a><em><strong>. Red Team Activity and Organization B SOC Response</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Red Team Activity</th>\n<th role=\"columnheader\">Defensive Measure</th>\n<th role=\"columnheader\">SOC Response</th>\n<th role=\"columnheader\">Outcome</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>C2 payload executed on a workstation.</td>\n<td>Payload execution generated a medium-severity alert.</td>\n<td>Staff quarantined workstation; staff analyzed and reimaged before putting workstation back online.</td>\n<td>Red team lost access to a workstation.</td>\n</tr>\n<tr>\n<td>C2 payload executed on a second workstation.</td>\n<td>Payload execution generated a medium-severity alert.</td>\n<td>Staff quarantined workstation; staff analyzed and reimaged before putting workstation back online.</td>\n<td>Red team lost access to a workstation.</td>\n</tr>\n<tr>\n<td>C2 payload executed on a third workstation.</td>\n<td>Payload execution generated a medium-severity alert.</td>\n<td>Staff quarantined workstation; staff analyzed and reimaged before putting workstation back online.</td>\n<td>Red team lost access to a workstation.</td>\n</tr>\n<tr>\n<td>C2 payload executed on bastion host in the OT DMZ.</td>\n<td>Payload execution generated alerts.</td>\n<td>Staff quarantined the host.</td>\n<td>Red team lost access to the host.</td>\n</tr>\n<tr>\n<td>Used compromised Entra ID account to log into Azure.</td>\n<td>Automated alert from Microsoft.</td>\n<td>Staff blocked the account.</td>\n<td>Red team compromised a different account and accessed Entra ID by abusing Seamless SSO.</td>\n</tr>\n</tbody>\n</table>\n<p>Despite these strengths, Organization B had areas for improvement. The red team was eventually able to access Entra ID through a computer account that was part of the organization\u2019s Seamless SSO implementation. The account did not have MFA and had overly permissive application permissions, indicating the need for more mature cloud security processes.</p>\n<p>Additionally, Organization B had excessive permissions and misconfigurations in AD and service accounts, which the red team leveraged for privilege escalation. This highlights the importance of regular audits and strict enforcement of least privilege principles. Organization B could improve credential hygiene, as the red team found credentials for OT systems stored in plaintext on jump servers. Finally, while segmentation and egress controls were effective, ongoing review and tightening of IT/OT connectivity and access architectures would reduce opportunities for lateral movement.</p>\n<h2><a class=\"ck-anchor\" id=\"Lessons\"><strong>Lessons Learned</strong></a></h2>\n<p>The red team identified lessons learned based on each organization\u2019s response. Organization A and Organization B contrasted significantly in their ability to quickly identify and respond to red team activity. However, similar gaps in both organizations contributed to the red team\u2019s compromise of their cloud systems.</p>\n<h3><strong>Untuned Detection Tools Lead to Missed Threats</strong></h3>\n<p>Organization A did not tune their detection tools to reduce alert noise, leading to an unmanageable level of alerts for SOC staff to review and action. The same red team activity that triggered alerts and action for Organization B led to no response for Organization A because SOC staff did not identify the activity as potentially malicious amid the overwhelming volume of alerts. Organization B had an established baseline and a fine-tuned alert system, allowing defenders to effectively filter out routine business activity and false positives. As a result, anomalies stood out, enabling the SOC staff to quickly detect and respond to red team activity.</p>\n<p>Without well-defined baselines and alert filtering, false positives and routine alerts overwhelm defenders, obscuring real threats. Organizations that tune alerts to highlight anomalies and filter out normal business activity enable defenders to focus on genuine incidents and respond rapidly.</p>\n<h3><strong>Organizational Silos and Bureaucratic Hurdles Prevent Effective Incident Response</strong></h3>\n<p>In Organization A, lack of communication and visibility created by organizational silos (among multiple SOCs and between SOC staff and system owners) hindered effective incident response, resulting in missed opportunities for identification of a major breach.</p>\n<p>Bureaucratic barriers arose because SOC staff managed systems without understanding their authorities as responsibilities and authorities varied across network segments. They had no escalation procedures and so defaulted to a \u201cwait and see\u201d approach.</p>\n<p>In contrast, Organization B empowered its defenders to act decisively. Staff quickly triaged alerts, investigated root causes, identified misconfigurations, and coordinated remediation with engineering.</p>\n<p>Detection tools are only as effective as the people, processes, and procedures supporting them. SOC staff should not operate in silos and should have clear authority unhindered by bureaucracy to effectively contain and resolve incidents.</p>\n<h3><strong>Organizations Underestimate Risks in Cloud Environments</strong></h3>\n<p>Both organizations underestimated the risks associated with cloud environments. They granted excessive permissions to cloud applications, allowing the red team to access cloud systems. They also lacked fully mature, defined processes for detecting and remediating compromise of cloud environments, allowing the red team to maintain access to cloud resources.</p>\n<h4><strong>Use of Long-Lived User Identity and Access Management Credentials</strong></h4>\n<p>Organization A used long-lived static IAM user credentials that were set to never expire. If a malicious actor obtains them, they will have all the user permissions, potentially enabling persistent, unrestricted access to the cloud environment.</p>\n<h4><strong>Excessive Permissions</strong></h4>\n<p>Both organizations lacked Conditional Access for workload identities. This feature extends Conditional Access beyond user accounts, covering non-human identities, such as applications. It allows organizations to broadly apply access policies to applications that control how and when the application is used to access resources. Instead, both organizations used broad application permissions for most apps, which the team was able to exploit for access to the environment. In both organizations, the team was able to exploit excessive permissions to read emails.</p>\n<h4><strong>Lack of Mature Remediation Processes for Tokens</strong></h4>\n<p>Both organizations lacked processes for revoking compromised access/refresh tokens. Without a well-defined, efficient process for remediating and revoking access/refresh tokens following a cloud compromise, malicious cyber actors evicted from on-prem environments may still leverage cloud access to regain entry. Organizations should establish mature procedures to detect and remediate compromises of cloud environments to prevent malicious cyber actors from reestablishing access.</p>\n<h2><a class=\"ck-anchor\" id=\"Issues\"><strong>Issues</strong></a></h2>\n<p>The red team identified the following issues that contributed to their ability to maintain persistent access to Organization A and/or B and escalate privileges or move laterally:</p>\n<ul type=\"square\">\n<li><strong>Misconfigured ADCS templates</strong>.<br>\n<ul type=\"circle\">\n<li>In Organization A, the red team identified and exploited a certificate template with common template misconfiguration known as ESC1, an overly permissive certificate template where the <code>CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT</code> flag is enabled and low-privileged users can request certificates. This allows malicious actors to impersonate users. See SpecterOp\u2019s <a href=\"https://specterops.io/wp-content/uploads/sites/3/2022/06/Certified_Pre-Owned.pdf\" target=\"_blank\" title=\"Certified Pre-Owned: Abusing Active Directory Certificate Services\">Certified Pre-Owned: Abusing Active Directory Certificate Services</a> for information about the ESC1 misconfiguration.</li>\n</ul>\n</li>\n<li><strong>Workstations where MAQ was misconfigured</strong>.<br>\n<ul type=\"circle\">\n<li>In Organization A, the team gained access to a workstation where the MAQ was set to the default value of 10. This meant that unprivileged users could add up to 10 computer accounts to the domain.</li>\n<li>In Organization B, the MAQ was set to 1,000 for all domain users, allowing any user to create a large number of machine accounts.</li>\n</ul>\n</li>\n<li><strong>Service accounts with excessive permissions</strong>.<br>\n<ul type=\"circle\">\n<li>In Organization B, the red team identified a domain service account with <code>AllExtendedRights</code> permission over a domain controller. <code>AllExtendedRights</code> enables malicious cyber actors to perform DCsync attacks and potentially impersonate any account in the domain, leading to full domain compromise.</li>\n</ul>\n</li>\n<li><strong>Cleartext credentials.</strong><br>\n<ul type=\"circle\">\n<li>In Organization A, the red team found and used cleartext credentials to obtain administrative access to SBSs.</li>\n<li>In Organization B, the red team identified a cleartext password in an XML file for a domain service account.</li>\n</ul>\n</li>\n<li><strong>Endpoint management systems that lacked additional security controls</strong>.<br>\n<ul type=\"circle\">\n<li>In Organization A, the red team moved laterally from the SCCM server to users\u2019 workstations. SCCM and other endpoint configuration managers (e.g., Jamf, BigFix) have broad administrative reach and are Tier 0 assets. If compromised, Tier 0 assets provide malicious actors with powerful escalation paths and control over the enterprise.</li>\n</ul>\n</li>\n</ul>\n<p>The red team identified an additional issue that was not exploited during the assessment but could be exploited by malicious cyber actors:</p>\n<ul>\n<li><strong>AD misconfigurations and user accounts with excessive permissions.</strong><br>\n<ul type=\"circle\">\n<li>In Organization B, the red team discovered that standard user accounts were improperly assigned to privileged administrative groups within the AD.</li>\n</ul>\n</li>\n</ul>\n<h2><a class=\"ck-anchor\" id=\"MITRE\"><strong>MITRE </strong></a><strong>ATT&amp;CK Tactics and Techniques</strong></h2>\n<p>See <a href=\"#Table2\"><strong>Table 2</strong></a> to <a href=\"#Table11\"><strong>Table 11</strong></a> for all referenced threat actor tactics and techniques in this advisory. &nbsp;For assistance with mapping malicious cyber activity to the MITRE ATT&amp;CK framework, see CISA and MITRE ATT&amp;CK\u2019s <a href=\"https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping\" title=\"Best Practices for MITRE ATT&amp;CK Mapping\">Best Practices for MITRE ATT&amp;CK Mapping</a> and CISA\u2019s <a href=\"https://github.com/cisagov/Decider/\" target=\"_blank\" title=\"Decider Tool\">Decider Tool</a>.</p>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table2\"><em><strong>Table 2</strong></em></a><em><strong>. Reconnaissance</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Gather Victim Identity Information: Credentials</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1589/001/\" target=\"_blank\" title=\"T1589.001\">T1589.001</a></td>\n<td>The red team performed reconnaissance and identified a web application with default credentials.</td>\n</tr>\n<tr>\n<td>Gather Victim Identity Information: Email Addresses</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1589/002/\" target=\"_blank\" title=\"T1589.002\">T1589.002</a></td>\n<td>The red team performed reconnaissance and gathered employee email addresses from public websites.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 3. Resource Development</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Obtain Capabilities: Tool</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1588/002/\" target=\"_blank\" title=\"T1588.002\">T1588.002</a></td>\n<td>The red team used publicly available tools, including AzureHound and ROADrecon.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 4. Initial Access</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Phishing</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1566/\" target=\"_blank\" title=\"T1566\">T1566</a></td>\n<td>\n<p>The red team gained initial access to four Organization A workstations by sending phishing emails from an internal email address.</p>\n<p>The red team gained initial access to three Organization B workstations via spearphishing emails that eventually led users to click on a malicious payload.</p>\n</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 5. Execution</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>User Execution</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1204/\" target=\"_blank\" title=\"T1204\">T1204</a></td>\n<td>The red team\u2019s spearphishing emails eventually led to users clicking on a malicious payload.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 6. Persistence</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Create Account: Domain Account</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1136/002/\" target=\"_blank\">T1136.002</a></td>\n<td>The red team exploited misconfigured MAQs to create machine accounts on a workstation.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 7. Credential Access</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Unsecured Credentials</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1552/\" target=\"_blank\" title=\"T1552\">T1552</a></td>\n<td>\n<p>The red team located cleartext credentials on an administrative user\u2019s workstation.</p>\n<p>The red team used the open source tool ADConnectDump to obtain cleartext credentials for cloud accounts.</p>\n</td>\n</tr>\n<tr>\n<td>Unsecured Credentials: Credentials In Files</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1552/001/\" target=\"_blank\" title=\"T1552.001\">T1552.001</a></td>\n<td>\n<p>The red team searched a targeted user\u2019s workstations for <code>connections.json</code> and <code>product-preferences.xml</code> files for a SQL Developer tool. They then decrypted these files to obtain cleartext password to the database.</p>\n<p>The red team acquired long-lived static AWS IAM user credentials in configuration files in users\u2019 home directories.</p>\n</td>\n</tr>\n<tr>\n<td>OS Credential Dumping</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1003/\" target=\"_blank\" title=\"T1003\">T1003</a></td>\n<td>The red team obtained cleartext credentials for an on-prem MSOL account and Entra account.</td>\n</tr>\n<tr>\n<td>OS Credential Dumping: DCSync</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1003/006/\" target=\"_blank\" title=\"T1003.006\">T1003.006</a></td>\n<td>The red team used DCSync to obtain AD account credentials.</td>\n</tr>\n<tr>\n<td>Steal or Forge Authentication Certificates</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1649/\" target=\"_blank\">T1649</a></td>\n<td>The red team could obtain certificates for any Organization A user account. This provided the means for lateral movement.</td>\n</tr>\n<tr>\n<td>Steal or Forge Kerberos Tickets</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1558/\" target=\"_blank\" title=\"T1558\">T1558</a></td>\n<td>\n<p>The red team used a Kerberos TGT to request a Kerberos service ticket for a web server\u2019s SPN.</p>\n<p>The red team used the Rubeus \u201casktgs\u201d module to request service tickets used for SSO.</p>\n</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 8. Discovery</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Account Discovery: Domain Account</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1087/002/\" target=\"_blank\" title=\"T1087.002\">T1087.002</a></td>\n<td>The red team used a BloodHound collector to query and scrape AD information, including AD users.</td>\n</tr>\n<tr>\n<td>Remote System Discovery</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1018/\" target=\"_blank\" title=\"T1018\">T1018</a></td>\n<td>The red team used a BloodHound collector to query and scrape AD information, including computers.</td>\n</tr>\n<tr>\n<td>Permission Groups Discovery: Domain Groups</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1069/002\" target=\"_blank\" title=\"T1069.002\">T1069.002</a></td>\n<td>The red team used a BloodHound collector to query and scrape AD information, including groups.</td>\n</tr>\n<tr>\n<td>Group Policy Discovery</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1615/\" target=\"_blank\" title=\"T1615\">T1615</a></td>\n<td>The red team used a BloodHound collector to query and scrape AD information, including GPOs.</td>\n</tr>\n<tr>\n<td>System Owner/User Discovery</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1033/\" target=\"_blank\" title=\"T1033\">T1033</a></td>\n<td>The red team queried SCCM servers to enumerate user-device relationships and identify the workstations assigned to users.</td>\n</tr>\n<tr>\n<td>Cloud Service Discovery</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1526/\" target=\"_blank\" title=\"T1526\">T1526</a></td>\n<td>The red team used publicly available tools to obtain a list of Entra applications, their permissions, and their owners.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 9. Lateral Movement</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Use Alternate Authentication Material: Application Access Token</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1550/001/\" target=\"_blank\" title=\"T1550.001\">T1550.001</a></td>\n<td>The red team used an application access token to access and review cloud emails.</td>\n</tr>\n<tr>\n<td>Remote Services: SSH</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1021/004/\" target=\"_blank\" title=\"T1021.004\">T1021.004</a></td>\n<td>The red team used FTP credentials to log into a bastion host over SSH.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><em><strong>Table 10. Collection</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Email Collection</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1114/\" target=\"_blank\" title=\"T1114\">T1114</a></td>\n<td>\n<p>The red team reviewed Organization A SOC staff cloud emails to see if SOC staff were aware of the compromise.</p>\n<p>The red team&nbsp;had the ability to retrieve the emails of every user within Organization B\u2019s environment from the public internet.</p>\n</td>\n</tr>\n<tr>\n<td>Screen Capture</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1113/\" target=\"_blank\" title=\"T1113\">T1113</a></td>\n<td>The red team took screenshots of SOC staff workstations.</td>\n</tr>\n<tr>\n<td>Input Capture: Keylogging</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1056/001/\" target=\"_blank\" title=\"T1056.001\">T1056.001</a></td>\n<td>The red team used keyloggers on SOC staff workstations.</td>\n</tr>\n<tr>\n<td>Data from Information Repositories: Messaging Applications</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1213/005/\" target=\"_blank\" title=\"T1213.005\">T1213.005</a></td>\n<td>The red team pulled Microsoft Teams messages from SOC staff workstations.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"Table11\"><em><strong>Table 11</strong></em></a><em><strong>. Command and Control</strong></em></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Proxy: Internal Proxy</td>\n<td><a href=\"https://attack.mitre.org/versions/v19/techniques/T1090/001/\" target=\"_blank\" title=\"T1090.001\">T1090.001</a></td>\n<td>The red team proxied through compromised workstations.</td>\n</tr>\n</tbody>\n</table>\n<h2><a class=\"ck-anchor\" id=\"Mitigations\"><strong>Mitigations</strong></a></h2>\n<p>CISA recommends that organizations implement the mitigations below to strengthen their cybersecurity posture based on the <a href=\"#Lessons\"><strong>Lessons Learned</strong></a> and identified <a href=\"#Issues\"><strong>Issues</strong></a>. These mitigations align with the <a href=\"https://www.cisa.gov/cpg\">Cross-Sector Cybersecurity Performance Goals (CPGs)</a> developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats, tactics, techniques, and procedures. Visit CISA\u2019s <a href=\"https://www.cisa.gov/cpg\">CPGs webpage</a> for more information on the CPGs, including additional recommended baseline protections.</p>\n<h3><strong>Establish Baselines and Improve Monitoring</strong></h3>\n<ul type=\"square\">\n<li><strong>Establish and continuously maintain a baseline of installed tools and software, account behavior, and network traffic</strong>.</li>\n<li><strong>Reduce alert noise</strong> by refining monitoring tools and alerting mechanisms to differentiate between typical administrative actions and potential threat behavior.<br>\n<ul type=\"circle\">\n<li>For information on establishing a baseline and reducing alert noise, see CISA\u2019s joint Guidance&nbsp;<a href=\"https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques\" title=\"Identifying and Mitigating Living Off the Land Techniques\">Identifying and Mitigating Living Off the Land Techniques</a>.</li>\n</ul>\n</li>\n</ul>\n<h3><strong>Eliminate Silos and Bureaucratic Hurdles</strong></h3>\n<ul type=\"square\">\n<li><strong>Break down silos</strong> by encouraging regular communication and collaboration between IT, security, and business units.<br>\n<ul type=\"circle\">\n<li>Consider using joint exercises, shared tools, and creating cross-functional teams.</li>\n<li>Integrate detection with incident response workflows to enable rapid containment and remediation.</li>\n</ul>\n</li>\n<li><strong>Empower network defenders</strong>.<br>\n<ul type=\"circle\">\n<li>Develop and communicate policies [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#EstablishCybersecurityResponsibilities1A\" title=\"CPG 1.A\">CPG 1.A</a>, <a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ManageCybersecurityOversight1B\" title=\"CPG 1.B\">CPG 1.B</a>] that support rapid, coordinated response and clarify when defenders can act independently versus when escalation is required.<br>\n<ul type=\"disc\">\n<li>Define clear roles and responsibilities so defenders know their authorities and escalation paths (if needed) during incidents.</li>\n<li>Grant defenders the authority to take necessary actions (e.g., isolating systems, blocking traffic) without excessive approvals.</li>\n</ul>\n</li>\n<li>Conduct training and simulated incident response exercises to reinforce roles, improve coordination, and identify gaps in authorities or communication [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#IncidentPlanningandPreparedness6A\" title=\"CPG 6.A\">CPG 6.A</a>].</li>\n</ul>\n</li>\n</ul>\n<h3><strong>Enhance Cloud Security Controls</strong></h3>\n<p><strong>Note:</strong> While both organizations used Microsoft Entra ID and Organization B also used AWS, many of the techniques used by the red team are applicable across identity providers and cloud environments and not necessarily unique to Microsoft and AWS. CISA encourages all organizations using cloud environments to implement the recommendations below.</p>\n<ul type=\"square\">\n<li><strong>Secure and monitor access/refresh tokens and&nbsp;establish and regularly review comprehensive procedures for detecting, remediating, and revoking access/refresh tokens</strong> in the event of a cloud compromise.<br>\n<ul type=\"circle\">\n<li>Implement automated token revocation and access reviews and conduct periodic incident response exercises to validate the effectiveness of these processes.</li>\n<li>Restrict access based on trusted network locations, device compliance, and risk signals (such as unusual activity or sign-in patterns).</li>\n<li>Monitor sign-in logs and policy evaluation results for workload identities to detect suspicious activity.</li>\n<li>Regularly check application permissions; make a risk-informed decision to identify and remove any that are not necessary, so each application only has the access it needs to function.</li>\n<li>Regularly audit SP credentials and rotate secrets or certificates to reduce exposure.</li>\n</ul>\n</li>\n<li><strong>Identify and disable legacy accounts.</strong></li>\n<li><strong>Enable phishing-resistant MFA&nbsp;</strong>for all user, administrative, and privileged accounts in cloud platforms [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementMultifactorAuthentication3F\" title=\"CPG 3.F\">CPG 3.F</a>].</li>\n<li><strong>Protect keys and secrets by storing them securely&nbsp;</strong>and enforcing mandatory rotation schedules; apply cryptographic boundary controls to internal and third-party credentials.</li>\n<li><strong>Set up automated alerts for suspicious cloud application activity</strong>, such as abnormal API calls, and credential activity, such as login attempts from unusual locations.</li>\n<li><strong>Leverage user and entity behavior analytics</strong> to analyze and correlate activities across multiple data sources and identify unusual credential or token usage.</li>\n<li><strong>Continuously audit authentication and access logs</strong> for signs of replay or unauthorized access.</li>\n<li><strong>Implement just-in-time (JIT) access</strong> for privileged accounts, replacing standing administrative rights with temporary, time-bound privilege elevations.</li>\n</ul>\n<p>For organizations using Entra ID:</p>\n<ul type=\"square\">\n<li>Monitor and control who has access to application identities.<br>\n<ul type=\"circle\">\n<li><strong>Implement CAPs for workload identities</strong> and monitor for excessive or unused permissions.</li>\n<li><strong>Use Microsoft\u2019s app governance to detect and manage risky SPs</strong>, which are special accounts used by applications and services. See Microsoft\u2019s <a href=\"https://learn.microsoft.com/en-us/defender-cloud-apps/app-governance-visibility-insights-overview\" target=\"_blank\" title=\"OAuth app visibility and insights with app governance - Microsoft Defender for Cloud Apps\">OAuth app visibility and insights with app governance - Microsoft Defender for Cloud Apps</a> for more information.</li>\n</ul>\n</li>\n<li><strong>Integrate Entra ID tenant monitoring with on-prem security operations</strong> to promptly identify suspicious activity.</li>\n<li><strong>Regularly review and restrict application permissions</strong> (e.g., <code>Mail.Read</code>, <code>Files.Read.All</code>).<br>\n<ul type=\"circle\">\n<li>For guidance, see CISA\u2019s <a href=\"https://www.cisa.gov/resources-tools/services/secure-cloud-business-applications-scuba-project\" title=\"Secure Cloud Business Applications (SCuBA) Project\">Secure Cloud Business Applications (SCuBA) Project</a>, which provides secure configuration baselines for Microsoft 365 (M365), including Microsoft Entra ID.</li>\n<li>Use CISA\u2019s <a href=\"https://github.com/cisagov/ScubaGear\" target=\"_blank\" title=\"ScubaGear\">ScubaGear</a>, a no-cost assessment tool that verifies M365 tenant configuration alignment to the policies described in SCuBA\u2019s secure configuration baselines.</li>\n</ul>\n</li>\n<li><strong>Use certificate-based authentication certificates for application authentication</strong> instead of client secrets, when possible. See Microsoft\u2019s <a href=\"https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-certificate-based-authentication\" target=\"_blank\" title=\"Set Up Microsoft Entra CBA - Microsoft Entra ID\">Set Up Microsoft Entra CBA - Microsoft Entra ID</a>.</li>\n<li><strong>Review newly created secrets and/or certificates</strong> on existing applications.</li>\n<li><strong>Limit secret lifetimes to a reasonable lifetime</strong>.</li>\n</ul>\n<p>In AWS environments:</p>\n<ul>\n<li><strong>Mitigate the risks of long-lived IAM user credentials.</strong><br>\n<ul type=\"circle\">\n<li>Identify and audit all existing access keys and disable/delete unused or unnecessary keys.</li>\n</ul>\n</li>\n<li><strong>Require human users to use temporary AWS credentials through SSO.</strong><br>\n<ul type=\"circle\">\n<li>Users will assume an IAM role for AWS access and receive temporary credentials that expire within an hour.</li>\n<li>For more information on accessing AWS using temporary credentials, see Amazon\u2019s documentation <a href=\"https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html\" target=\"_blank\" title=\"Security best practices in IAM\">Security best practices in IAM</a> and <a href=\"https://docs.aws.amazon.com/IAM/latest/UserGuide/introduction_identity-management.html\" target=\"_blank\" title=\"Compare IAM identities and credentials\">Compare IAM identities and credentials</a>.</li>\n</ul>\n</li>\n<li><strong>Regularly review the environment to verify no long-lived credentials remain.</strong></li>\n</ul>\n<h3><strong>Secure Active Directory and Manage Credentials</strong></h3>\n<ul type=\"square\">\n<li><strong>Apply secure configurations to ADCS implementations.</strong><br>\n<ul type=\"circle\">\n<li>Disable the <code>CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT</code> flag from templates to prevent users from supplying and editing sensitive security settings within these templates.</li>\n<li>Restrict accounts that can enroll in all certificate templates to only those necessary, especially templates with the <code>CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT</code> flag.</li>\n<li>Remove <code>FullControl</code>, <code>WriteDacl</code>, and <code>Write</code> property permissions from low-privileged groups, such as domain users, to certificate template objects, where such permissions are not needed.</li>\n<li>Enforce manager approval for requested certificates.</li>\n<li>Apply additional guidance from CISA\u2019s joint Guidance <a href=\"https://www.cisa.gov/resources-tools/resources/detecting-and-mitigating-active-directory-compromises\" title=\"Detecting and Mitigating Active Directory Compromises\">Detecting and Mitigating Active Directory Compromises</a> (see Mitigating AD CS compromise, pages 15\u201316).</li>\n</ul>\n</li>\n<li><strong>Configure the MAQ to zero unless there is a specific operational need for non-administrative users to create computer accounts</strong>;&nbsp;this prevents standard user accounts from creating new machine accounts, reducing opportunities for malicious cyber actors to abuse this privilege.<br>\n<ul type=\"circle\">\n<li>If some standard user accounts need to create computer accounts, set MAQ to the lowest possible value and restrict this capability to only users or groups with a business justification.</li>\n</ul>\n</li>\n<li><strong>Improve credential hygiene</strong>.<br>\n<ul type=\"circle\">\n<li>Scan network shares and workstations for plaintext credentials and remove any found.</li>\n<li>Train staff on secure password storage practices and enforce policies prohibiting plaintext password storage.</li>\n<li>Use encrypted password vaults for storing credentials and limit access to only those who require it.</li>\n<li>Periodically audit credential stores and access logs for signs of misuse.</li>\n</ul>\n</li>\n<li><strong>Periodically audit AD permissions&nbsp;</strong>for misconfigurations and excessively privileged groups and accounts.<br>\n<ul type=\"circle\">\n<li>Implement the principle of least privilege [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementthePrinciplesofLeastPrivilege3H\" title=\"CPG 3.H\">CPG 3.H</a>].</li>\n<li>Grant standard user rights for standard user tasks such as email, web browsing, and using line-of-business applications.</li>\n<li>Periodically audit standard user accounts and minimize privileged access.</li>\n<li>Periodically audit AD permissions to verify that standard user accounts do not have excessive permissions and have not been added to admin groups.</li>\n<li>Evaluate which administrative groups should administer specific servers and workstations.</li>\n<li>Separate administrator accounts from standard user accounts [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#AdministratorsMaintainSeparateUserandPrivilegedAccounts3G\" title=\"CPG 3.G\">CPG 3.G</a>].<br>\n<ul type=\"disc\">\n<li>Use designated workstations for administrators and standard users and prevent administrators from using admin workstations for non-admin purposes; this would reduce impact of credential theft from a user workstation.</li>\n<li>Use designated administrative accounts exclusively for admin purposes.</li>\n<li>If a standard user account needs administrative rights over their workstation, use a separate account that does not have administrative access to other hosts, such as servers.</li>\n</ul>\n</li>\n<li>Consider using a privileged access management (PAM) solution to manage access to privileged accounts and resources.<br>\n<ul type=\"disc\">\n<li>PAM solutions can log and alert usage to detect unusual activity, which could have alerted the assessed organizations when the red team accessed resources with admin accounts.</li>\n<li><strong>Note:</strong> Treat password vaults associated with PAM solutions as high value assets (HVAs) with additional restrictions and monitoring.</li>\n</ul>\n</li>\n<li>Configure time-based access for accounts set at the admin level and higher.<br>\n<ul type=\"disc\">\n<li>The just-in-time access method provisions privileged access when needed and can support enforcement of the principle of least privilege, as well as the zero trust model. A network-wide policy automatically disables administrator accounts at the AD level when the account is not needed. When standard user accounts need administrative access, they submit their requests through an automated process that enables access to a system, but only for a set timeframe to support task completion.</li>\n</ul>\n</li>\n</ul>\n</li>\n</ul>\n<h3><strong>Secure Endpoint Configuration Managers</strong></h3>\n<ul type=\"square\">\n<li>Treat endpoint management systems (such as SCCM) as HVAs with additional restrictions and monitoring because they provide elevated access to thousands of hosts.</li>\n</ul>\n<h3><strong>Segment Operational Technology Networks</strong></h3>\n<ul type=\"square\">\n<li>Implement strict firewall rules and access controls between IT and OT environments [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementLogicalPhysicalNetworkSegmentation3I\" title=\"CPG 3.I\">CPG 3.I</a>].</li>\n<li>Limit jump server access to OT networks and require MFA for all connections.</li>\n<li>Regularly review OT network architecture and access paths to minimize unnecessary connectivity.</li>\n<li>Monitor OT network traffic for signs of lateral movement or unauthorized access.</li>\n<li>Implement change management solutions to track and restrict modifications to OT components.</li>\n</ul>\n<h2><strong>Validate Security Controls</strong></h2>\n<p>In addition to applying mitigations, CISA recommends exercising, testing, and validating your organization's security program against the threat behaviors mapped to the MITRE ATT&amp;CK Matrix for Enterprise framework in this advisory. CISA recommends testing your existing security controls inventory to assess how they perform against the ATT&amp;CK techniques described in this advisory.</p>\n<p>To get started:</p>\n<ol>\n<li>Select an ATT&amp;CK technique described in this advisory (see <a href=\"#Table2\"><strong>Table 2</strong></a> to <a href=\"#Table11\"><strong>Table 11</strong></a>).</li>\n<li>Align your security technologies against the technique.</li>\n<li>Test your technologies against the technique.</li>\n<li>Analyze your detection and prevention technologies\u2019 performance.</li>\n<li>Repeat the process for all security technologies to obtain a set of comprehensive performance data.</li>\n<li>Tune your security program, including people, processes, and technologies, based on the data generated by this process.</li>\n</ol>\n<p>CISA recommends continually testing your security program, at scale, in a production environment to ensure optimal performance against the MITRE ATT&amp;CK techniques identified in this advisory.</p>\n<h2><strong>Resources</strong></h2>\n<ul type=\"square\">\n<li>Microsoft: <a href=\"https://learn.microsoft.com/en-us/entra/identity/devices/concept-primary-refresh-token?tabs=windows-prt-issued%2Cbrowser-behavior-windows%2Cwindows-prt-used%2Cwindows-prt-renewal%2Cwindows-prt-protection%2Cwindows-apptokens%2Cwindows-browsercookies%2Cwindows-mfa\" target=\"_blank\" title=\"Understanding primary refresh token (PRT)\">Understanding primary refresh token (PRT)</a></li>\n<li>SpecterOps: <a href=\"https://specterops.io/wp-content/uploads/sites/3/2022/06/Certified_Pre-Owned.pdf\" target=\"_blank\" title=\"Certified pre-owned: Abusing Active Directory Certificate Services\">Certified pre-owned: Abusing Active Directory Certificate Services</a></li>\n</ul>\n<h2><strong>Contact Information</strong></h2>\n<p>Organizations are encouraged to report suspicious or criminal activity related to information in this advisory to CISA via CISA\u2019s 24/7 Operations Center at <a href=\"mailto:contact@cisa.dhs.gov\">contact@cisa.dhs.gov</a> or 1-844-Say-CISA (1-844-729-2472). When available, please include the following information regarding the incident:</p>\n<ul type=\"square\">\n<li>Date, time, and location of the incident;</li>\n<li>Type of activity;</li>\n<li>Number of people affected;</li>\n<li>Type of equipment used for the activity; and</li>\n<li>Name of the submitting company or organization, and a designated point of contact.</li>\n</ul>\n<h2><strong>Disclaimer</strong></h2>\n<p>The information in this report is being provided \u201cas is\u201d for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA.</p>\n<h2><strong>Version History</strong></h2>\n<p><strong>August 25, 2026</strong>: Initial version.</p>\n<h2><strong>Notes</strong></h2>\n<p><a class=\"ck-anchor\" id=\"Note1\"><sup>1</sup></a> \u201cSpecterOps&nbsp;/ Bloodhound,\u201d GitHub, last modified July 15, 2026, <a href=\"https://github.com/SpecterOps/BloodHound\" target=\"_blank\">https://github.com/SpecterOps/BloodHound</a>.</p>\n<p><a class=\"ck-anchor\" id=\"Note2\"><sup>2</sup></a> \u201cSpecterOps&nbsp;/&nbsp;AzureHound,\u201d GitHub, last modified June 4, 2026, <a href=\"https://github.com/SpecterOps/AzureHound\" target=\"_blank\">https://github.com/SpecterOps/AzureHound</a>.</p>\n<p><a class=\"ck-anchor\" id=\"Note3\"><sup>3</sup></a> \u201cROADrecon,\u201d GitHub, <a href=\"https://github.com/dirkjanm/ROADtools/tree/master/roadrecon\" target=\"_blank\">https://github.com/dirkjanm/ROADtools/tree/master/roadrecon</a>.</p>\n<p><a class=\"ck-anchor\" id=\"Note4\"><sup>4</sup></a> \u201cdirkjanm/adconnectdumb,\u201d GitHub, last modified August 25, 2026, <a href=\"https://github.com/dirkjanm/adconnectdump\" target=\"_blank\">https://github.com/dirkjanm/adconnectdump</a>.</p>",
        "summary_is_html": true,
        "first_seen": "Tue, 25 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 25 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06",
        "title": "Ebyte NE2-D11",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized administrative access, disclose sensitive information, modify device configuration, hijack authenticated sessions, and disrupt device operation.</strong></p>\n<p>The following versions of Ebyte NE2-D11 are affected:</p>\n<ul>\n<li>NE2-D11 Firmware FW-9167-0-11</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.8</td>\n<td>Ebyte</td>\n<td>Ebyte NE2-D11</td>\n<td>Missing Authentication for Critical Function, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials, Use of Client-Side Authentication, Use of GET Request Method With Sensitive Query Strings, Cross-Site Request Forgery (CSRF), Improper Restriction of Excessive Authentication Attempts, Improper Restriction of Rendered UI Layers or Frames, Missing Authorization</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>China</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-73125</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-73125\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NE2-D11</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NE2-D11 Firmware: FW-9167-0-11</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-73809</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web management interface does not adequately protect sensitive communications using transport-layer encryption. An attacker with access to network traffic could intercept authentication or session-related information transmitted between a user and the affected device. Successful exploitation could result in disclosure of sensitive information and unauthorized access to device management functionality.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-73809\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NE2-D11</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NE2-D11 Firmware: FW-9167-0-11</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/319.html\">CWE-319 Cleartext Transmission of Sensitive Information</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-73839</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Administrative credentials may be exposed in plaintext within the Ebyte device's management interface, increasing the risk of credential compromise through visual or remote observation. This undermines the confidentiality of device access.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-73839\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NE2-D11</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NE2-D11 Firmware: FW-9167-0-11</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/522.html\">CWE-522 Insufficiently Protected Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>4.6</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.1</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-71187</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtain administrative access to the device.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-71187\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NE2-D11</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NE2-D11 Firmware: FW-9167-0-11</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/603.html\">CWE-603 Use of Client-Side Authentication</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-76179</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during client-side session handling, which may allow an attacker with access to exposed session information to obtain and reuse a valid token. Successful exploitation could allow an attacker to impersonate an authenticated user and gain unauthorized access to device management functionality.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-76179\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NE2-D11</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NE2-D11 Firmware: FW-9167-0-11</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/598.html\">CWE-598 Use of GET Request Method With Sensitive Query Strings</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-75814</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management interface. An unauthenticated remote attacker could persuade an authenticated administrator to visit a crafted page, causing unauthorized configuration changes or a disruption of device availability.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-75814\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NE2-D11</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NE2-D11 Firmware: FW-9167-0-11</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/352.html\">CWE-352 Cross-Site Request Forgery (CSRF)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-76940</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected Ebyte device does not restrict repeated authentication attempts through rate limiting or account lockout mechanisms. This could allow an attacker to perform automated authentication attacks against deployments that rely on password based authentication.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-76940\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NE2-D11</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NE2-D11 Firmware: FW-9167-0-11</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/307.html\">CWE-307 Improper Restriction of Excessive Authentication Attempts</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-75548</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected Ebyte device web management interface does not restrict the interface from being rendered within an external frame. An unauthenticated remote attacker could use a crafted webpage to mislead an authenticated administrator into initiating unintended configuration changes or disruptive actions.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-75548\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NE2-D11</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NE2-D11 Firmware: FW-9167-0-11</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/1021.html\">CWE-1021 Improper Restriction of Rendered UI Layers or Frames</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.4</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-75813</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthorized users to access or modify sensitive device settings. This could result in full compromise of device functionality.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-75813\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NE2-D11</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NE2-D11 Firmware: FW-9167-0-11</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/862.html\">CWE-862 Missing Authorization</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-76945</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected Ebyte device relies on client-managed authentication tokens without sufficient server-side validation. An attacker may replay or manipulate authentication tokens to gain unauthorized access to administrative functionality.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-76945\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NE2-D11</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NE2-D11 Firmware: FW-9167-0-11</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/603.html\">CWE-603 Use of Client-Side Authentication</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-69658</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device impersonation and disruption of messaging functions.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-69658\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NE2-D11</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NE2-D11 Firmware: FW-9167-0-11</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/319.html\">CWE-319 Cleartext Transmission of Sensitive Information</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Jithin Nambiar reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-25</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-25</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 25 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 25 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-05",
        "title": "Bendix EC80 Brake ECU",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-05",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-05.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to cause the loss of ABS functions, steering assist, speedometer, shifting capabilities, or disable automatic traction control.</strong></p>\n<p>The following versions of Bendix EC80 Brake ECU are affected:</p>\n<ul>\n<li>EC80ESP+ J1708 Z228999</li>\n<li>EC80ESP+ 6S/6M Z228999</li>\n<li>EC80ESP+ PLC Z228999&nbsp;</li>\n<li>EC80ESP+ 2nd CAN Z228999</li>\n<li>EC80ESP+ Integrated TPMS Z228999</li>\n<li>EC80ESP 6S/6M Z266494&nbsp;</li>\n<li>EC80ESP PLC Z266494&nbsp;</li>\n<li>EC80ESP 2nd CAN Z266494</li>\n<li>EC80ESP CAN Gateway Z266494&nbsp;</li>\n<li>EC80ESP 4S/4M Z286098&nbsp;</li>\n<li>EC80ESP PLC Z286098&nbsp;</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>Bendix</td>\n<td>Bendix EC80 Brake ECU</td>\n<td>Stack-based Buffer Overflow, Out-of-bounds Write, Use of Hard-coded Credentials</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>United States, Canada</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-67560</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering assist, speedometer, and shifting.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-67560\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Bendix EC80 Brake ECU</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Bendix</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Bendix EC80ESP+ J1708: Z228999, Bendix EC80ESP+ 6S/6M: Z228999, Bendix EC80ESP+ PLC: Z228999, Bendix EC80ESP+ 2nd CAN: Z228999, Bendix EC80ESP+ Integrated TPMS: Z228999, Bendix EC80ESP 6S/6M: Z266494, Bendix EC80ESP PLC: Z266494, Bendix EC80ESP 2nd CAN: Z266494, Bendix EC80ESP CAN Gateway: Z266494, Bendix EC80ESP 4S/4M: Z286098, Bendix EC80ESP PLC: Z286098</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Bendix recommends users update their firmware to the most recent firmware version releases. Users that need more help should contact Bendix directly at info@Bendix.com.<br><a href=\"mailto:info@Bendix.com\">mailto:info@Bendix.com</a></p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ J1708: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ 6S/6M: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ PLC: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ 2nd CAN: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ Integrated TPMS: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP 6S/6M: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP PLC: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP 2nd CAN: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP CAN Gateway: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP 4S/4M: Z286098 users should update their firmware to version Z302579.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP PLC: Z286098 users should update their firmware to version Z302579.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/121.html\">CWE-121 Stack-based Buffer Overflow</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-68967</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that could establish an arbitrary write primitive, which could crash the ECU.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-68967\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Bendix EC80 Brake ECU</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Bendix</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Bendix EC80ESP+ J1708: Z228999, Bendix EC80ESP+ 6S/6M: Z228999, Bendix EC80ESP+ PLC: Z228999, Bendix EC80ESP+ 2nd CAN: Z228999, Bendix EC80ESP+ Integrated TPMS: Z228999, Bendix EC80ESP 6S/6M: Z266494, Bendix EC80ESP PLC: Z266494, Bendix EC80ESP 2nd CAN: Z266494, Bendix EC80ESP CAN Gateway: Z266494, Bendix EC80ESP 4S/4M: Z286098, Bendix EC80ESP PLC: Z286098</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Bendix recommends users update their firmware to the most recent firmware version releases. Users that need more help should contact Bendix directly at info@Bendix.com.<br><a href=\"mailto:info@Bendix.com\">mailto:info@Bendix.com</a></p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ J1708: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ 6S/6M: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ PLC: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ 2nd CAN: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ Integrated TPMS: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP 6S/6M: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP PLC: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP 2nd CAN: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP CAN Gateway: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP 4S/4M: Z286098 users should update their firmware to version Z302579.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP PLC: Z286098 users should update their firmware to version Z302579.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-71396</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product uses hard-coded credentials, which could allow an attacker to disable automatic traction control.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-71396\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Bendix EC80 Brake ECU</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Bendix</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Bendix EC80ESP+ J1708: Z228999, Bendix EC80ESP+ 6S/6M: Z228999, Bendix EC80ESP+ PLC: Z228999, Bendix EC80ESP+ 2nd CAN: Z228999, Bendix EC80ESP+ Integrated TPMS: Z228999, Bendix EC80ESP 6S/6M: Z266494, Bendix EC80ESP PLC: Z266494, Bendix EC80ESP 2nd CAN: Z266494, Bendix EC80ESP CAN Gateway: Z266494, Bendix EC80ESP 4S/4M: Z286098, Bendix EC80ESP PLC: Z286098</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Bendix recommends users update their firmware to the most recent firmware version releases. Users that need more help should contact Bendix directly at info@Bendix.com.<br><a href=\"mailto:info@Bendix.com\">mailto:info@Bendix.com</a></p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ J1708: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ 6S/6M: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ PLC: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ 2nd CAN: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP+ Integrated TPMS: Z228999 users should update their firmware to version Z300822.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP 6S/6M: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP PLC: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP 2nd CAN: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP CAN Gateway: Z266494 users should update their firmware to version Z302578.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP 4S/4M: Z286098 users should update their firmware to version Z302579.</p>\n<p><strong>Vendor fix</strong><br>EC80ESP PLC: Z286098 users should update their firmware to version Z302579.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/798.html\">CWE-798 Use of Hard-coded Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.4</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Ben Gardiner of NMFTA reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-25</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-25</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 25 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 25 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-02",
        "title": "Zoneminder",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could result in full Remote Code Execution (RCE) as the web server user.</strong></p>\n<p>The following versions of Zoneminder are affected:</p>\n<ul>\n<li>Zoneminder 1.37.48|1.38.3&nbsp;</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.8</td>\n<td>Zoneminder</td>\n<td>Zoneminder</td>\n<td>Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-76060</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An authenticated OS Command Injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-76060\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Zoneminder</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Zoneminder</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Zoneminder Zoneminder: 1.37.48|1.38.3</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Zoneminder recommends upgrading to version 1.38.3 or later by downloading the installer for your system at: https://zoneminder.com/downloads.<br><a href=\"https://zoneminder.com/downloads\">https://zoneminder.com/downloads</a></p>\n<p><strong>Vendor fix</strong><br>Users may also get the source code from Zoneminder's Github: https://github.com/ZoneMinder/zoneminder.<br><a href=\"https://github.com/ZoneMinder/zoneminder\">https://github.com/ZoneMinder/zoneminder</a></p>\n<p><strong>Vendor fix</strong><br>For more details refer to Zoneminder's security advisories at: https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-88m4-hrgp-m9v3.<br><a href=\"https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-88m4-hrgp-m9v3\">https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-88m4-hrgp-m9v3</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/78.html\">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>CISA discovered a public Proof of Concept (PoC) as authored by Scriptkittens and reported it to Zoneminder</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-25</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-25</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 25 Aug 26 12:00:00 +0000",
        "last_updated": "Tue, 25 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/24/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/24/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://edit.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-21962\" target=\"_blank\">CVE-2026-21962</a> Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://edit.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://edit.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://edit.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a class=\"ext\" href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Mon, 24 Aug 26 12:00:00 +0000",
        "last_updated": "Mon, 24 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/21/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/21/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-73570\" target=\"_blank\">CVE-2026-73570</a> Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Fri, 21 Aug 26 12:00:00 +0000",
        "last_updated": "Fri, 21 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/20/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Two Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/20/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added two new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-72529\" target=\"_blank\">CVE-2026-72529</a> TrueConf Server Missing Authentication for Critical Function Vulnerability &nbsp;</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-72530\" target=\"_blank\">CVE-2026-72530</a> TrueConf Server Code Injection Vulnerability</li>\n</ul>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Thu, 20 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 20 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-232-01",
        "title": "Johnson Controls Simplex Incident Manager",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-232-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-232-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems.</strong></p>\n<p>The following versions of Johnson Controls Simplex Incident Manager are affected:</p>\n<ul>\n<li>Simplex Incident Manager &lt;=V2.01 (CVE-2026-27875)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 5.8</td>\n<td>Johnson Controls Inc.</td>\n<td>Johnson Controls Simplex Incident Manager</td>\n<td>Cleartext Storage of Sensitive Information in Memory</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Ireland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-27875</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Simplex Incident Manager application stores user credentials (such as passwords and authentication tokens) in an unencrypted form within system memory while running. This exposes sensitive information to potential extraction by anyone with local access to the system, including attackers leveraging memory-dumping tools or insiders with elevated privileges.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-27875\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Johnson Controls Simplex Incident Manager</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Johnson Controls Inc.</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Johnson Controls Simplex Incident Manager: &lt;=V2.01</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Johnson Controls has released a patched version (v2.01.01) to address this vulnerability. To help reduce the risk of exploitation, Johnson Controls suggests considering the following defensive measures: Upgrade the Simplex Incident Manager to version v1.01.05 or later. Restrict local access to systems running the Simplex Incident Manager to authorized personnel only. Implement endpoint protection and monitoring to detect memory-dumping tools or suspicious processes. Enforce strong access control policies and the principle of least privilege on host systems. Utilize full-disk encryption and secure boot to reduce the risk of offline memory analysis. Monitor for unauthorized local access attempts and implement audit logging.</p>\n<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-28.<br><a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories\">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>\n<p><strong>Mitigation</strong><br>Aligning with CISA recommendations, Johnson Controls recommends taking steps to minimize risks to all building automation systems.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/316.html\">CWE-316 Cleartext Storage of Sensitive Information in Memory</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L\">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Johnson Controls reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely. This vulnerability has a high attack complexity.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-20</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-20</td>\n<td>1</td>\n<td>Initial Republication of Johnson Controls Product Security Advisory JCI-PSA-2026-28</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 20 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 20 Aug 26 12:00:00 +0000"
    }
]