[
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-251-01",
        "title": "CareCam Pro IP Cameras",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-251-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-251-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to take full control of the device.</strong></p>\n<p>The following versions of CareCam Pro IP Cameras are affected:</p>\n<ul>\n<li>ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26 (CVE-2026-85083)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 6.8</td>\n<td>CareCam</td>\n<td>CareCam Pro IP Cameras</td>\n<td>Use of Hard-coded Credentials</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Commercial Facilities</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>China</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-85083</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and potentially resulting in complete device compromise.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-85083\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>CareCam Pro IP Cameras</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>CareCam</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CareCam ANJIA AJL33PC0801 Firmware: linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>CareCam has not responded to CISA's attempts for coordination. Users are encouraged to reach out to CareCam.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/798.html\">CWE-798 Use of Hard-coded Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Omkar Mali reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-08</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-08</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 08 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 08 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a",
        "title": "China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a",
        "summary": "<h2><strong>Executive summary</strong></h2>\n<p>China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies\u2019 models through industrial-scale knowledge distillation campaigns that form the core\u2014not merely a supplement\u2014of their AI development strategy. While \u201cdistillation\u201d is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models. The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) (hereafter referred to as the authoring agencies) are releasing this joint Cybersecurity Advisory to alert organizations about these malicious activities and techniques and recommend mitigations to reduce their potential impact.&nbsp;</p>\n<p>Likely with Chinese government awareness, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024. DeepSeek has conducted organized campaigns since at least 2024 targeting reasoning capabilities, specialized optimizations, and domain-specific functions to train its R1 and V3 models. Alibaba leveraged industrial-scale distillation to improve the company\u2019s Qwen family of AI models. Moonshot AI, MiniMax, Stepfun, and Z.AI also engaged in malicious knowledge distillation of U.S. AI companies\u2019 models.&nbsp;</p>\n<p>China-based AI companies route distillation requests through multiple pathways to gain unauthorized access, consequently violating U.S. AI companies\u2019 terms of use. These pathways include native application programming interfaces (APIs), remote cloud providers, and third-party aggregators that automatically obfuscate user metadata to avoid detection. Further, China-based AI companies use a gray market of proxies known as \u201ctransfer stations\u201d to bypass U.S. AI companies\u2019 geographic restrictions, breach terms of use, evade safeguards, and undermine traceability. China-based AI companies achieve cost savings for their industrial-scale distillation campaigns through bulk procurement of the U.S. AI companies\u2019 premium subscriptions shared across teams of developers. Advanced industrial-scale distillation tactics include chain-of-thought (CoT) reasoning extraction, automated failover between pathways during blocking attempts, and sophisticated quality evaluation frameworks to detect defensive countermeasures. China-based AI companies that conduct industrial-scale distillation against U.S. AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model.</p>\n<p>China-based AI companies deliberately distribute operations across multiple providers, platforms, and pathways to avoid single-point detection. They also attempt to distill the best capabilities and proprietary features of each U.S. frontier model to train their China-based AI models. This represents systematic extraction of proprietary functionalities and capabilities threatening U.S. technological leadership. Addressing industrial-scale distillation merits a coordinated response across the AI ecosystem, including effective information-sharing, spanning the U.S. Government, private industry, and allied nations.</p>\n<p>The authoring agencies recommend U.S. AI companies take three immediate actions:&nbsp;</p>\n<ol>\n<li><strong>Implement comprehensive detection and mitigation: </strong>Detect anomalous and malicious prompts, accounts, networks, and behaviors. Additionally, monitor subscription-to-usage ratios, immediate maximum usage from new accounts, and enterprise-scale throughput patterns.</li>\n<li><strong>Deploy targeted response changes:</strong> Subtly alter responses for suspected malicious distillation attempts to attenuate the payoffs to companies conducting industrial-scale distillation campaigns.</li>\n<li><strong>Establish cross-organization intelligence sharing: </strong>Correlate activity across model providers, cloud platforms, and API aggregators to reveal distributed campaigns.</li>\n</ol>\n<h2><strong>Attribution</strong></h2>\n<p>Since at least late 2024, China-based AI companies, including DeepSeek (DeepSeek Artificial Intelligence Technology Research Co., Ltd.), Moonshot AI (Beijing Moonshot Technology Co., Ltd.), Alibaba Group, MiniMax (Shanghai MiniMax Co., Ltd.), StepFun (Shanghai Jieyue Xingchen Intelligence Technology Co., Ltd.), and Z.AI, have conducted high-volume knowledge distillation campaigns against several U.S. AI companies. The sheer scale of these campaigns and their sophistication indicate that distillation is not a supplement to these companies\u2019 AI model development, but the critical core of it.&nbsp;</p>\n<p>Likely with the knowledge of the Chinese government, the China-based AI sector has turned to a comprehensive distillation strategy in an attempt to bridge the technological and performance gaps between their AI models and U.S. frontier AI models. To access U.S. AI companies\u2019 application programming interfaces (APIs), China-based AI companies use a gray market of API proxies known as \u201ctransfer stations\u201d to bypass U.S. AI companies\u2019 regional restrictions, breach terms of use, evade safeguards, and undermine traceability.&nbsp;</p>\n<h3><em><strong>DeepSeek</strong></em></h3>\n<p>DeepSeek has been conducting an organized distillation campaign against U.S. AI companies\u2019 frontier AI models since at least late 2024 to generate synthetic training data for its models, including R1, released in early 2025. The company targeted specific knowledge domains to extract proprietary functionality and reasoning capabilities to reduce their compute and research costs. DeepSeek\u2019s publicly quoted training costs of $5.6M are misleading as it does not include the true cost of the data acquired through extensive malicious distillation.<a href=\"#note1\"><sup>1</sup></a>&nbsp;</p>\n<p>Between late 2024 and mid-2025, DeepSeek distilled specialized training data and capabilities from the following U.S. frontier AI company models to train their R1 and V3 models:&nbsp;</p>\n<ul>\n<li>Claude 3.7&nbsp;</li>\n<li>Claude Sonnet 4</li>\n<li>Claude Sonnet 4.5</li>\n<li>Claude Opus 4.1</li>\n<li>Gemini 2.5 Pro Preview</li>\n<li>Gemini 2.5 Flash Preview</li>\n<li>GPT-4</li>\n<li>GPT-4o</li>\n<li>GPT-4 Mini</li>\n<li>GPT-4 Nano</li>\n<li>GPT-5</li>\n<li>Grok 4</li>\n</ul>\n<p>The specific knowledge and capabilities distilled included:&nbsp;</p>\n<ul>\n<li>Legal specialization optimization</li>\n<li>API rule-driven tasks</li>\n<li>Writing using CoT drafts</li>\n<li>Agentic functions</li>\n<li>Question and answer optimization</li>\n<li>Coach/assistant capabilities</li>\n<li>Functional creation optimization</li>\n<li>Supervised fine-tuning (SFT) optimization</li>\n<li>Creative and occupational writing optimization</li>\n</ul>\n<h3><em><strong>Moonshot AI&nbsp;</strong></em></h3>\n<p>Moonshot AI has conducted a widespread distillation campaign against U.S. frontier AI companies since at least mid-2025. Notably, Moonshot AI extracted significant Claude Fable 5 data to train its Kimi-K3 model and GPT-4o data to train its Kimi-K2 model. The company has used the following models to distill SFT optimization, reinforcement learning (RL), software engineering, and math capabilities:</p>\n<ul>\n<li>Claude Opus 4.1</li>\n<li>Claude Sonnet 3.7</li>\n<li>Claude Sonnet 4</li>\n<li>Claude Sonnet 4.5</li>\n<li>Claude Sonnet 4.5 Thinking</li>\n<li>Claude Fable 5</li>\n<li>GPT-oss-20b</li>\n<li>GPT-3</li>\n<li>GPT-4o</li>\n<li>GPT-4o mini</li>\n<li>GPT-5</li>\n<li>GPT-5 Codex</li>\n<li>GPT-5 Pro</li>\n<li>Gemini 2.5 Flash</li>\n<li>Gemini 2.5 Flash-Image</li>\n<li>Gemini 2.5 Pro</li>\n<li>Nano Banana</li>\n<li>Grok Code Fast-1</li>\n</ul>\n<h3><em><strong>Other companies</strong></em></h3>\n<p>Several other China-based AI companies, including Alibaba, MiniMax, StepFun, and Z.AI have also leveraged distillation techniques to build their AI models. In late 2025, Alibaba distilled Claude-4, Claude Opus, Claude Sonnet, and GPT-5 to improve their AI models\u2019 software engineering skills, customer service dialogue functionality, image/character creation, and integration of RL, SFT, and distillation capabilities.</p>\n<p>In late 2025, MiniMax distilled CoT reasoning, RL, SFT, and software engineering capabilities to improve its M2 model from Claude Code, Claude Sonnet 4, Claude Opus, Gemini 1, Gemini 2.5 Pro, and Gemini 3 Pro. MiniMax used Claude Code for internal software development tasks, including code generation, analysis, and refinement. MiniMax even used prompt injections to try to trick Claude Code into believing it was a MiniMax product.</p>\n<p>Between late 2025 and early 2026, StepFun distilled data from Claude Opus 4.1 and 4.5, Claude Sonnet 4.5, Claude Haiku 4.5, GPT-5 Mini, GPT-5 Pro, GPT-5.1, GPT-5.1 Codex, and GPT-5.2 to improve its Step 4 model\u2019s coding and agentic functions. By mid-2026, Z.AI had distilled billions of tokens of GPT-5.5 data and Claude Opus 4.8 data to develop the CoT reasoning capabilities of its model.</p>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><strong>Table 1: China-based AI Companies Engaged in Knowledge Distillation Against U.S. AI Companies</strong> (From at least 2024-2026)&nbsp;</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>China-based AI Company&nbsp;</strong></p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>U.S. AI Models Distilled</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>Functionalities and Domains Distilled</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>DeepSeek&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>(DeepSeek Artificial Intelligence&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>Technology Research Co., Ltd.)&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>\u6df1\u5ea6\u6c42\u7d22AI\u57fa\udbc0\udc00\u6280\udbc0\udc00\u7814\u7a76\u6709\u9650\u516c\u53f8</strong></p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>Claude Sonnet 3.7&nbsp;</li>\n<li>Claude Sonnet 4&nbsp;</li>\n<li>Claude Sonnet 4.5&nbsp;</li>\n<li>Claude Opus 4.1&nbsp;</li>\n<li>Gemini 2&nbsp;</li>\n<li>Gemini 2.5 Pro Preview&nbsp;</li>\n<li>Gemini 2.5 Flash Preview&nbsp;&nbsp;</li>\n<li>GPT-4&nbsp;</li>\n<li>GPT-4o&nbsp;</li>\n<li>GPT-4 Mini&nbsp;</li>\n<li>GPT-4 Nano&nbsp;</li>\n<li>GPT-5&nbsp;</li>\n<li>Grok 3 Mini&nbsp;&nbsp;</li>\n<li>Grok 4&nbsp;</li>\n</ul>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>Legal specialization optimization&nbsp;</li>\n<li>API rule-driven tasks&nbsp;</li>\n<li>Writing using CoT drafts&nbsp;</li>\n<li>Question and answer optimization&nbsp;</li>\n<li>Coach/assistant capabilities&nbsp;</li>\n<li>Functional creation optimization&nbsp;</li>\n<li>SFT optimization&nbsp;</li>\n<li>Agentic capabilities&nbsp;</li>\n<li>Creative and occupational writing optimization&nbsp;</li>\n</ul>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>Moonshot AI&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>(Beijing Moonshot Technology Co., Ltd.)&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>\u5317\u4eac\udbc0\udc00\u6708\u661f\u8fb0\u79d1\u6280\u6709\u9650\u516c\u53f8&nbsp;</strong></p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>Claude Opus 4.1&nbsp;</li>\n<li>Claude Sonnet 3.7&nbsp;</li>\n<li>Claude Sonnet 4&nbsp;</li>\n<li>Claude Sonnet 4.5&nbsp;</li>\n<li>Claude Sonnet 4.5 Thinking&nbsp;</li>\n<li>Claude Fable 5&nbsp;</li>\n<li>GPT-oss-20b;&nbsp;</li>\n<li>GPT-3&nbsp;</li>\n<li>GPT-4o mini&nbsp;</li>\n<li>GPT-5&nbsp;</li>\n<li>GPT-5 Codex&nbsp;</li>\n<li>GPT-5 Pro&nbsp;</li>\n<li>Gemini 2.5 Flash&nbsp;</li>\n<li>Gemini 2.5 Flash-Image&nbsp;</li>\n<li>Gemini 2.5 Pro&nbsp;</li>\n<li>Nano Banana&nbsp;</li>\n<li>xAI Grok Code Fast-1&nbsp;</li>\n</ul>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>SFT&nbsp;</li>\n<li>RL&nbsp;</li>\n<li>Software engineering&nbsp;</li>\n<li>Math capabilities&nbsp;</li>\n</ul>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p>&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>Alibaba&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>\u963f\u91cc\u96c6\u56e2&nbsp;</strong></p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>Claude 4&nbsp;</li>\n<li>Claude Sonnet&nbsp;</li>\n<li>GPT-5&nbsp;</li>\n</ul>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>Customer service dialogue&nbsp;</li>\n<li>Virtual character creation&nbsp;</li>\n<li>SFT, RL, and distillation training&nbsp;</li>\n<li>Evaluating and training datasets&nbsp;</li>\n<li>End-to-end agentic workflows&nbsp;</li>\n<li>Software engineering&nbsp;</li>\n</ul>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>MiniMax&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>(Shanghai MiniMax Co., Ltd.)&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>\u4e0a\u6d77\u7a00\u5b87\u6781\u667a\u79d1\u6280\u6709\u9650\u516c\u53f8&nbsp;</strong></p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>Claude Code&nbsp;</li>\n<li>Claude Sonnet 4&nbsp;</li>\n<li>Claude Opus 4.5&nbsp;</li>\n<li>Gemini 1&nbsp;</li>\n<li>Gemini 2.5 Pro&nbsp;</li>\n<li>Gemini 3 Pro&nbsp;</li>\n<li>GPT-5&nbsp;</li>\n</ul>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>CoT reasoning&nbsp;</li>\n<li>Agentic functionality&nbsp;</li>\n<li>Code review&nbsp;</li>\n<li>SFT dataset refinement&nbsp;</li>\n<li>Software engineering tasks&nbsp;</li>\n</ul>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>StepFun&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>(Shanghai Jieyue Xingchen&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>Intelligence Technology Co., Ltd.)&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>\u4e0a\u6d77\udbc0\udc00\udbc0\udc00\u661f\u8fb0\u667a\u80fd\u79d1\u6280\u6709\u9650\u516c\u53f8&nbsp;</strong></p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>Claude Opus 4.1&nbsp;</li>\n<li>Claude Opus 4.5&nbsp;</li>\n<li>Claude Sonnet 4.5&nbsp;</li>\n<li>Claude Haiku 4.5&nbsp;</li>\n<li>GPT-5 Mini&nbsp;</li>\n<li>GPT-5 Pro&nbsp;</li>\n<li>GPT-5.1&nbsp;</li>\n<li>GPT-5.1 Codex&nbsp;</li>\n<li>GPT-5.1 Codex Mini&nbsp;</li>\n<li>GPT-5.2&nbsp;</li>\n</ul>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>Code development&nbsp;</li>\n<li>Agentic functions&nbsp;</li>\n</ul>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>Z.AI&nbsp;</strong></p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>GPT-5.5&nbsp;</li>\n<li>Claude Opus 4.8&nbsp;</li>\n</ul>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>CoT reasoning&nbsp;</li>\n</ul>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n<h2><strong>Tactics, techniques, and procedures</strong></h2>\n<p>China-based AI companies employ sophisticated tactics, techniques, and procedures (TTPs). These TTPs map to the <a href=\"https://atlas.mitre.org/\" target=\"_blank\">MITRE\u00ae ATLAS\u2122</a><a href=\"#note2\"><sup>2</sup></a> framework, progressing through multiple adversary lifecycle phases from initial access through exfiltration. The China-based AI companies using these techniques include DeepSeek, Moonshot AI, MiniMax, StepFun, Z.AI, and other China-based AI companies targeting U.S. frontier AI models.</p>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><strong>Table 2: MITRE ATLAS Mappings</strong>&nbsp;</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p class=\"text-align-center\"><strong>TTP Title</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p class=\"text-align-center\"><strong>ID</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p class=\"text-align-center\"><strong>Description</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td colspan=\"3\">\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p class=\"text-align-center\"><em><strong>Resource Development</strong></em>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>Acquire Infrastructure&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p><a href=\"https://atlas.mitre.org/techniques/AML.T0008\" target=\"_blank\"><u>AML.T0008</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>China-based entities establish and maintain sophisticated infrastructure supporting sustained extraction operations through tiered budget management and diverse supplier relationships.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>China-based entities circumvent both Chinese and U.S. AI access controls through a large gray market of API proxies, or \u201ctransfer stations,\u201d which resell access to frontier models at a fraction of the official price. In doing so, they create a scalable mechanism for evading provider safeguards and eroding traceability.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td colspan=\"3\">\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p class=\"text-align-center\"><em><strong>AI Model Access</strong></em>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>AI Model Inference API Access&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p><a href=\"https://atlas.mitre.org/techniques/AML.T0040\" target=\"_blank\"><u>AML.T0040</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>China-based entities have been exploiting AI model inference APIs through the creation of fraudulent accounts that are not registered to legitimate users. These actors leverage multiple accounts with similar registration details and payment methods, frequently switch between various AI models, and utilize third-party API aggregator services. Additionally, they execute highly coordinated queries featuring identical or similar prompt texts, demonstrating a sophistication indicative of advanced AI research. The sheer volume of requests, ranging from thousands to millions on similar topics, far exceeds legitimate use, raising significant concerns about potential misuse and compromising the integrity of AI systems.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td colspan=\"3\">\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p class=\"text-align-center\"><em><strong>Execution / Privilege Escalation / Defense Evasion</strong></em>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>LLM Prompt Injection&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>LLM Jailbreak&nbsp;&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p><a href=\"https://atlas.mitre.org/techniques/AML.T0051\" target=\"_blank\"><u>AML.T0051</u></a>&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p><a href=\"https://atlas.mitre.org/techniques/AML.T0054\" target=\"_blank\"><u>AML.T0054</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>China-based entities have conducted prompt injection techniques against large language models (LLMs) by inserting prompts specifically designed for jailbreaking.&nbsp;&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>China-based entities craft prompts forcing models to reveal their hidden CoT reasoning (CoT or step-by-step internal reasoning that enables greater capabilities) despite U.S. models restricting CoT output visibility to users. DeepSeek employed prompts instructing models to imagine and articulate the internal reasoning behind completed responses and write it out step by step. This CoT data teaches student models, not just factual knowledge, but reasoning methodologies for complex agentic tasks, coding challenges, and logical proofs.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td colspan=\"3\">\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p class=\"text-align-center\"><em><strong>Discovery</strong></em>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>Discovery&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p><a href=\"https://atlas.mitre.org/tactics/AML.TA0008\" target=\"_blank\"><u>AML.TA0008</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>China-based entities employ aggressive, adaptive discovery to systematically identify valuable extractable data.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>China-based entities demonstrate rapid operational adaptation. MiniMax redirected exchanges to a new Claude model within 24 hours of release, demonstrating real-time provider monitoring and pre-positioned infrastructure for immediate retargeting.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td colspan=\"3\">\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p class=\"text-align-center\"><em><strong>AI Attack Staging</strong></em>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>Verify Attack&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p><a href=\"https://atlas.mitre.org/techniques/AML.T0042\" target=\"_blank\"><u>AML.T0042</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>China-based entities deploy production-grade automated quality assurance pipelines with multi-modal validation, enabling rapid detection of degraded outputs and differentiation of service issues from defensive data degradation.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td colspan=\"3\">\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p class=\"text-align-center\"><em><strong>Collection</strong></em>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>Collection&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p><a href=\"https://atlas.mitre.org/tactics/AML.TA0009\" target=\"_blank\"><u>AML.TA0009</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>China-based entities systematically collect outputs to generate synthetic training datasets through continuous API querying, targeting specific knowledge domains rather than indiscriminate gathering.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>Moonshot AI used millions of exchanges targeting agentic reasoning/tool use, coding/data analysis, computer-use agent development, and computer vision, evolving from text-based distillation to extracting logical frameworks, enabling tool interaction and visual processing.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>DeepSeek used queries targeting reasoning capabilities, rubric-based grading tasks (reward model function), and censorship-safe query rewriting, extracting how U.S. models evaluate response quality.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>Campaigns span days to months with query volumes in the thousands to millions per domain, far exceeding legitimate research or development use cases.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td colspan=\"3\">\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p class=\"text-align-center\"><em><strong>Exfiltration</strong></em>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>Exfiltration via AI&nbsp;&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>Inference API: Extract AI Model&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p><a href=\"https://atlas.mitre.org/techniques/AML.T0024.002\" target=\"_blank\"><u>AML.T0024.002</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>China-based entities have been collecting U.S. frontier LLMs\u2019 inferences into datasets, which can be used to train their models to mimic the behavior and performance of these LLMs.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td colspan=\"3\">\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p class=\"text-align-center\"><em><strong>Impact</strong></em>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>External Harms&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p><a href=\"https://atlas.mitre.org/techniques/AML.T0048\" target=\"_blank\"><u>AML.T0048</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>China-based entities inflict financial harm through systematic extraction of proprietary functionality and capabilities, causing significant economic losses. Extracting capabilities worth billions in development costs while undermining competitive advantages represents a strategic economic threat to fair technological competition and U.S. technological leadership.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n<h3><em><strong>Novel TTPs</strong></em></h3>\n<p>China-based AI companies leverage techniques not in MITRE ATLAS, demonstrating significant organizational investment, operational maturity, and adaptive capability development distinguishing these campaigns from opportunistic exploitation.</p>\n<h4><strong>Novel TTP 1: Regional restriction evasion and subscription exploitation</strong></h4>\n<p>Some U.S. frontier AI models are restricted for use; however, China-based AI companies access U.S. frontier AI models by employing various means to bypass the regional restrictions.</p>\n<p>After bypassing the restriction, China-based AI companies create user accounts obfuscating their country of origin and subsequentially procure bulk premium AI subscription services.</p>\n<p>StepFun structured access around pools of accounts with employees running multiple concurrent sessions, implementing load distribution to prevent quota depletion. Daily budget allocations per automated agent started at moderate levels, scaling significantly as operations matured.</p>\n<p>Detection indicators include:</p>\n<ul>\n<li>shared accounts from multiple IPs/user agents,&nbsp;</li>\n<li>24/7 sustained usage without human variation/idle periods,&nbsp;</li>\n<li>anomalous subscription-to-API usage ratios, and&nbsp;</li>\n<li>new subscriptions immediately at maximum usage as opposed to gradual AI adoption.</li>\n</ul>\n<h4><strong>Novel TTP 2: Centralized request routing infrastructure</strong></h4>\n<p>China-based AI companies deploy sophisticated tools that enable unified control and scalable implementation for evasion at scale. This provides model/provider abstraction, real-time health monitoring, centralized quota enforcement, and automated sanitization.</p>\n<p>China-based AI companies manage routing systems to external AI models for distillation. These routing systems direct requests through multiple pathways: native APIs, cloud providers, third-party aggregators, third-party relays, and vendor account pools.</p>\n<p>Detection indicators include:</p>\n<ul>\n<li>consistent operational patterns across diverse account pools and&nbsp;</li>\n<li>correlated timing/behavior across different pathways indicating unified orchestration.</li>\n</ul>\n<h4><strong>Novel TTP 3: Automated request metadata sanitization</strong></h4>\n<p>China-based AI companies implement automated sanitization to systematically remove organizational identifiers. This differs from <a href=\"https://atlas.mitre.org/techniques/AML.T0065\" target=\"_blank\">AML.T0065</a> (LLM Prompt Crafting) by operating at an infrastructure layer with automated enforcement instead of manual modification.</p>\n<p>Detection indicators include:</p>\n<ul>\n<li>sudden behavioral changes following disclosures/sharing, especially abrupt disappearance of previously consistent metadata;&nbsp;</li>\n<li>absence of expected markers in high-volume campaigns where scale suggests institutional activity; and&nbsp;</li>\n<li>generic/randomized patterns replacing consistent organizational indicators.</li>\n</ul>\n<h4><strong>Novel TTP 4: Systematic quota and cost optimization</strong></h4>\n<p>China-based AI companies systematically minimize API costs through pathway selection prioritizing cost-efficiency, centralized quota allocation/budget alignment, and account segmentation by purpose.</p>\n<p>Detection indicators include:</p>\n<ul>\n<li>new accounts with anomalously high immediate hit rates suggesting bulk deployment with pre-engineered templates,&nbsp;</li>\n<li>usage optimized for cache maximization versus task diversity, and&nbsp;</li>\n<li>coordinated pathway switching responding to pricing/rate changes indicating centralized decision-making.</li>\n</ul>\n<h2><strong>Mitigations</strong></h2>\n<p>Coordinated, ecosystem-wide responses extending beyond individual company measures can help address knowledge distillation campaigns. The mitigations below incorporate mitigations from the MITRE ATLAS and National Institute of Standards and Technology (NIST) AI frameworks. Collaboration across the broader AI ecosystem, including cloud providers, API aggregators, and infrastructure providers, can enable a coordinated defense against malicious knowledge distillation campaigns.</p>\n<h3><em><strong>Behavioral detection and monitoring</strong></em></h3>\n<p>China-based AI companies leverage premium subscriptions to U.S. frontier models for knowledge distillation campaigns and code development. U.S. companies should strengthen identity verification for accounts and track individual subscriptions with enterprise-scale throughput, accounts deviating from legitimate patterns, and new accounts immediately at maximum usage versus a gradual ramp-up or with consistent quota exhaustion.&nbsp;</p>\n<h3><em><strong>Response alteration for suspected distillation activity</strong></em></h3>\n<p>Employing targeted changes in response to high-confidence malicious distillation requests can impose meaningful costs on knowledge distillation campaigns. Response changes, such as including differential privacy or using less sophisticated \u201cdowngraded\u201d models to respond to distillation requests, can help protect U.S. proprietary functionalities and capabilities and reduce payoffs from distillation attempts.&nbsp;</p>\n<h4><strong>Implementation strategies</strong></h4>\n<p>When suspecting a malicious distillation campaign, consider varying changes to responses across requests to complicate response quality evaluations, such that the subtle changes avoid triggering obvious alerts. Reducing reasoning depth, presenting correct information with different reasoning, or stylistic inconsistencies may evade detection while reducing training usefulness.</p>\n<p>Avoid informing China-based AI company users suspected of distillation campaigns of a switch to a downgraded model. Informing malicious distillers would enable them to improve their defense evasions and indicate when to roll back training. Instead, alter responses to users confirmed to be querying frontier models specifically for malicious knowledge distillation campaigns without informing them. In contrast, AI safety researchers and third-party evaluators should be informed of model changes while still applying strong distillation mitigations.</p>\n<h3><em><strong>Cross-organization information sharing and ecosystem coordination</strong></em></h3>\n<p>Sharing information about distillation campaigns, such as indicators of infrastructure distributing operations across multiple providers, platforms, and pathways, can improve individual companies\u2019 detection efforts. Industry disclosures document proxy networks managing tens of thousands of fraudulent accounts simultaneously, mixing distillation with unrelated customer requests across multiple providers. Community collaboration could provide defenders with more comprehensive visibility across the native APIs, cloud endpoints, and aggregators.</p>\n<p>Sharing information about distillation enables and enhances correlation otherwise unachievable by individual organizations, through sharing infrastructure indicators (IPs, domains, third-party service providers) and behavioral indicators (timing correlations, query volume patterns).</p>\n<p>Multi-source correlated activity enables more confident attribution of malicious knowledge distillation campaigns, justifying response degradation with lower-to-no legitimate user risk.</p>\n<p>Sharing infrastructure and behavioral indicators between cloud providers, model aggregators, and model providers can make distributed infrastructure visible as coordinated campaigns versus isolated anomalies. Additionally, sharing can provide cloud and routing companies with actionable indicators for identifying and mitigating malicious activity.</p>\n<div class=\"OutlineElement Ltr SCXW94261203 BCX8\">\n<h3><em><strong>MITRE ATLAS mitigations&nbsp;</strong></em></h3>\n<ul>\n<li><a href=\"https://atlas.mitre.org/mitigations/AML.M0015\" target=\"_blank\"><u>AML.M0015</u></a> - Predictive AI Adversarial Input Detection: Detect/block atypical queries deviating from benign patterns, exhibiting previous adversary technique characteristics, or originating from malicious IPs.</li>\n<li><a href=\"https://atlas.mitre.org/mitigations/AML.M0004\" target=\"_blank\"><u>AML.M0004</u></a> - Limit AI Service Query Volume and Rate: Per-key/IP quotas, rate limits, progressive throttling. Adversaries seem to be sensitive to rate limits since they implement sophisticated strategies to work within constraints.&nbsp;</li>\n<li><a href=\"https://atlas.mitre.org/mitigations/AML.M0019\" target=\"_blank\"><u>AML.M0019</u></a> - Control Access to AI Models and Data in Production: User verification, authenticated API access, policy monitoring. This addresses fraudulent account pool exploitation.&nbsp;</li>\n<li><a href=\"https://atlas.mitre.org/mitigations/AML.M0024\" target=\"_blank\"><u>AML.M0024</u></a> - AI Telemetry Logging: Log inputs/outputs for threat detection/forensics. This is foundational for behavioral detection and enables correlation with intelligence.&nbsp;</li>\n<li><a href=\"https://atlas.mitre.org/mitigations/AML.M0002\" target=\"_blank\"><u>AML.M0002</u></a> - Predictive AI Output Obfuscation: Reduce fidelity of responses (withhold logits/confidences, shorten responses, targeted redaction). Balance security with user experience.&nbsp;</li>\n<li><a href=\"https://atlas.mitre.org/mitigations/AML.M0035\" target=\"_blank\"><u>AML.M0035</u></a> \u2013 AI Red Team: Adversarial testing, extraction simulation, telemetry monitoring. Validates detection efficacy.&nbsp;</li>\n<li><a href=\"https://atlas.mitre.org/mitigations/AML.M0015\" target=\"_blank\"><u>AML.M0015</u></a> - Predictive AI Adversarial Input Detection: Sanitize/validate inputs preventing prompt injections. This addresses jailbreak and injection attempts to elicit reasoning traces and system prompts.&nbsp;</li>\n<li><a href=\"https://atlas.mitre.org/mitigations/AML.M0000\" target=\"_blank\"><u>AML.M0000</u></a> - Limit Public Information Release: Limit disclosure of architecture, prompt templates, and system instructions.&nbsp;</li>\n<li><a href=\"https://atlas.mitre.org/mitigations/AML.M0001\" target=\"_blank\"><u>AML.M0001</u></a> - Limit Model Artifact Release: Limit release of data, algorithms, architectures, and model checkpoints.&nbsp;</li>\n<li><a href=\"https://atlas.mitre.org/mitigations/AML.M0003\" target=\"_blank\"><u>AML.M0003</u></a> - Predictive AI Model Hardening: Use adversarial training and defensive distillation to increase jailbreak difficulty.&nbsp;</li>\n<li><a href=\"https://atlas.mitre.org/mitigations/AML.M0006\" target=\"_blank\"><u>AML.M0006</u></a> - Predictive AI Ensembles: Use multiple models so extracting one yields a less usable clone.&nbsp;</li>\n</ul>\n<h3><em><strong>NIST AI 100-2e2025: Adversarial machine learning mitigations</strong></em></h3>\n<p>Mitigations in NIST\u2019s \u201c<a href=\"https://csrc.nist.gov/pubs/ai/100/2/e2025/final\" target=\"_blank\">Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations</a>\u201d (NIST AI 100-2e2025) also apply to malicious distillation, including differential privacy, pre- and post-training interventions, and prompt instruction/formatting.</p>\n<h4><strong>Differential privacy</strong></h4>\n<p>Differential Privacy (DP) provides mathematically rigorous protection against inference and distillation techniques by adding calibrated noise to model outputs and preventing malicious actors from extracting training data membership information and other sensitive model information, such as decision boundaries or signals that could help reconstruct private data. This protection is governed by privacy parameters that define a finite privacy budget, where each query consumes part of the model's available privacy protection and repeated querying steadily reduces the remaining privacy reserve.&nbsp;</p>\n<p>As that budget is consumed through accumulated queries, the model must either add more noise to preserve privacy, restrict further queries, or accept reduced privacy protection. This creates a fundamental noise-versus-utility tradeoff, where stronger privacy protection requires more noise, which can lower prediction precision and business usefulness, while less noise improves utility but increases vulnerability to compromise techniques, such as membership inference, model extraction, or inversion.&nbsp;</p>\n<p>In practice, the right balance requires careful tuning and empirical auditing, because theoretical privacy settings do not always predict real-world accuracy impact, particularly for complex models or high-dimensional outputs that require substantially more noise to achieve equivalent protection, or when facing adaptive actors. As a result, DP is often strengthened with complementary controls such as query rate limiting, response aggregation, and monitoring.</p>\n<h4><strong>Pre/post-training interventions</strong></h4>\n<p>A range of training strategies have been proposed to increase the difficulty of accessing harmful capabilities through prompt injection, including safety training during pre-training or post training, adversarial training methods, and other methods to make jailbreak techniques more difficult.</p>\n<h4><strong>Prompt instruction/formatting</strong></h4>\n<p>Model instructions can cue the model to treat user input carefully, such as by wrapping user input in XML tags, appending specific instructions to the prompt, or otherwise attempting to clearly separate instructions from user prompts to mitigate distillation and make prompt injection or jailbreaking less effective.</p>\n<h2><strong>Footnotes</strong></h2>\n<p><sup>1</sup> <a class=\"ck-anchor\" id=\"note1\"></a>Publicly quoted training costs are from \u201c<a href=\"https://arxiv.org/pdf/2412.19437\" target=\"_blank\">DeepSeek-V3 Technical Report</a>\u201d</p>\n<p><a class=\"ck-anchor\" id=\"note2\"><sup>2</sup></a><a class=\"ck-anchor\" id=\"note2\"></a> MITRE is a registered trademark of The MITRE Corporation. MITRE ATLAS is a trademark of The MITRE Corporation.</p>\n<h2><strong>References</strong></h2>\n<ul>\n<li><a href=\"https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks\" target=\"_blank\">Anthropic: Detecting and preventing distillation attacks</a></li>\n<li><a href=\"https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use\" target=\"_blank\">Google: GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use</a></li>\n<li><a href=\"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-2e2025.pdf\" target=\"_blank\">NIST AI 100-2e2025: Adversarial Machine Learning A Taxonomy and Terminology of Attacks and Mitigations</a></li>\n<li><a href=\"https://assets.bwbx.io/documents/users/iqjWHBFdfxIU/rRmql_jJcxb4/v0\" target=\"_blank\">OpenAI: RE: Updated Stakes for American-Led, Democratic AI</a></li>\n<li><a href=\"https://the-decoder.com/how-chinas-gray-market-sells-claude-tokens-at-a-fraction-of-the-price/\" target=\"_blank\">The Decoder: How China's gray market sells Claude tokens at a fraction of the price</a></li>\n<li><a href=\"https://www.whitehouse.gov/presidential-actions/2026/06/national-security-presidential-memorandum-nspm-11/\" target=\"_blank\">White House National Security Presidential Memorandum 11 (NSPM-11): Artificial Intelligence in the National Security Enterprise</a></li>\n<li><a href=\"https://www.whitehouse.gov/wp-content/uploads/2026/04/NSTM-4.pdf\" target=\"_blank\">White House National Science and Technology Memorandum 4 (NSTM-4): Adversarial Distillation of American AI Models</a></li>\n<li><a href=\"https://x.com/mkratsios47/status/2079933645888880708\" target=\"_blank\">White House Office of Science and Technology Policy post on X</a></li>\n</ul>\n<h4><em><strong>Disclaimer of endorsement</strong></em></h4>\n<p>The information and opinions contained in this document are provided \"as is\" and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes.</p>\n<h4><em><strong>Purpose</strong></em></h4>\n<p>This document was developed in furtherance of the authoring agencies\u2019 cybersecurity missions, including their responsibilities to identify and disseminate threats and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.</p>\n<h4><em><strong>Contact</strong></em></h4>\n<ul>\n<li><strong>National Security Agency</strong><br>Cybersecurity Report Feedback: <a href=\"mailto:CybersecurityReports@nsa.gov\" target=\"_blank\">CybersecurityReports@nsa.gov</a><br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href=\"mailto:DIB_Defense@cyber.nsa.gov\" target=\"_blank\">DIB_Defense@cyber.nsa.gov</a><br>Media Inquiries / Press Desk: NSA Media Relations: 443-634-0721, <a href=\"mailto:MediaRelations@nsa.gov\" target=\"_blank\">MediaRelations@nsa.gov</a></li>\n<li><strong>Cybersecurity and Infrastructure Security Agency</strong><br>CISA\u2019s 24/7 Operations Center (<a href=\"mailto:contact@cisa.dhs.gov\" target=\"_blank\">contact@cisa.dhs.gov</a>), or by calling 1-844-Say-CISA (1-844-729-2472).</li>\n<li><strong>Federal Bureau of Investigation</strong><br>If you or someone you know has fallen victim to this campaign, file a complaint with <a href=\"https://www.ic3.gov/\" target=\"_blank\">IC3</a>.<br>&nbsp;</li>\n</ul>\n</div>\n</div>\n</div>",
        "summary_is_html": true,
        "first_seen": "Tue, 08 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 08 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Four Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added four new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-75650\" target=\"_blank\">CVE-2026-75650</a> Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-81963\" target=\"_blank\">CVE-2026-81963</a> Microsoft Windows Link Following Vulnerability &nbsp;</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-85880\" target=\"_blank\">CVE-2026-85880</a> Microsoft Windows Heap-Based Buffer Overflow Vulnerability&nbsp;</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-86218\" target=\"_blank\">CVE-2026-86218</a> N-able N-central Static Code Injection Vulnerability&nbsp;</li>\n</ul>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Tue, 08 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 08 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/09/04/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/09/04/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-85046\" target=\"_blank\">CVE-2026-85046</a> Google Chromium V8 Type Confusion Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Fri, 04 Sep 26 12:00:00 +0000",
        "last_updated": "Fri, 04 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-03",
        "title": "Rockwell Automation ControlFLASH",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-03",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-03.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.</strong></p>\n<p>The following versions of Rockwell Automation ControlFLASH are affected:</p>\n<ul>\n<li>ControlFLASH &lt;=V15.07 (CVE-2026-12663)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.3</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation ControlFLASH</td>\n<td>Missing Authentication for Critical Function</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy, Water and Wastewater</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-12663</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A security issue exists within ControlFLASH, where the installer grants write permissions to the \"Everyone\" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-12663\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation ControlFLASH</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation ControlFLASH: &lt;=V15.07</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Rockwell Automation has corrected this issue in software version 15.08, and encourages all users to update to the newest version.</p>\n<p><strong>Mitigation</strong><br>Users of the affected software who are not able to upgrade to one of the corrected versions should implement the following mitigation:&nbsp;</p>\n<p>To protect the files, do the following steps to remove the Everyone group:&nbsp;</p>\n<ol>\n<li>Right-click the C:\\Program Files (x86)\\ControlFLASH\\0001 folder, and then select Properties.&nbsp;</li>\n<li>In the 0001 Properties dialog, select the Security tab, and then select Edit.&nbsp;</li>\n<li>In the Permissions for 0001 dialog, in Group or user names, select Everyone, and then select Remove.&nbsp;</li>\n<li>Select OK.</li>\n</ol>\n<p><strong>Mitigation</strong><br>If the mitigation above cannot be implemented, Rockwell Automation recommends following their security best practices.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information on this issue, see the Rockwell Automation security advisory at: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-03</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-03</td>\n<td>1</td>\n<td>Initial Republication of Rockwell Automation security advisory.</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 03 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 03 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-07",
        "title": "Pyramid Solutions NetStaX EtherNet/IP Stack",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-07",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-07.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.</strong></p>\n<p>The following versions of Pyramid Solutions NetStaX EtherNet/IP Stack are affected:</p>\n<ul>\n<li>EtherNet/IP Adapter DLL Kit (EIPA)</li>\n<li>EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE)</li>\n<li>EtherNet/IP Adapter Development Kit (EADK)</li>\n<li>EtherNet/IP Adapter Development Kit with CIP Security (EADK-SECURE)</li>\n<li>EtherNet/IP Scanner DLL Kit (EIPS)</li>\n<li>EtherNet/IP Scanner DLL Kit with CIP Security (EIPS-SECURE)</li>\n<li>EtherNet/IP Scanner Development Kit (ESDK)</li>\n<li>EtherNet/IP Scanner Development Kit with CIP Security (ESDK-SECURE)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.8</td>\n<td>Pyramid Solutions</td>\n<td>Pyramid Solutions NetStaX EtherNet/IP Stack</td>\n<td>Stack-based Buffer Overflow</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy, Water and Wastewater, Chemical</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-78012</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-78012\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Pyramid Solutions NetStaX EtherNet/IP Stack</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Pyramid Solutions</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Pyramid Solutions EtherNet/IP Adapter DLL Kit (EIPA): &lt;v5.6.1, Pyramid Solutions EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE): &lt;v5.6.1, Pyramid Solutions EtherNet/IP Adapter Development Kit (EADK): &lt;v5.6.1, Pyramid Solutions EtherNet/IP Adapter Development Kit with CIP Security (EADK-SECURE): &lt;v5.6.1, Pyramid Solutions EtherNet/IP Scanner DLL Kit (EIPS): &lt;v5.6.1, Pyramid Solutions EtherNet/IP Scanner DLL Kit with CIP Security (EIPS-SECURE): &lt;v5.6.1, Pyramid Solutions EtherNet/IP Scanner Development Kit (ESDK): &lt;v5.6.1, Pyramid Solutions EtherNet/IP Scanner Development Kit with CIP Security (ESDK-SECURE): &lt;v5.6.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>NetStaX v5.6.1 addresses this issue with multiple layers of protection, including a compile-time assertion, a runtime payload-size check, and clearer documentation of the relationships between packet and buffer-size constants.<br><a href=\"https://pyramidsolutions.com/my-account/\">https://pyramidsolutions.com/my-account/</a></p>\n<p><strong>Mitigation</strong><br>For more information, see the Pyramid Solutions blog post \"NetStaX v5.6.1: Protecting Against Silent Buffer Overflow in Ethernet/IP Stack Explicit Messages\".<br><a href=\"https://pyramidsolutions.com/netstax-v-5-6-1-protecting-against-silent-buffer-overflow-in-ethernet-ip-stack-explicit-messages/\">https://pyramidsolutions.com/netstax-v-5-6-1-protecting-against-silent-buffer-overflow-in-ethernet-ip-stack-explicit-messages/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/121.html\">CWE-121 Stack-based Buffer Overflow</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Pyramid Solutions reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-03</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-03</td>\n<td>1</td>\n<td>Initial Republication of Pyramid Solutions blog publication.</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 03 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 03 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-02",
        "title": "IXON VPN Client",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges.</strong></p>\n<p>The following versions of IXON VPN Client are affected:</p>\n<ul>\n<li>VPN Client &lt;1.4.7 (CVE-2026-75925)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.6</td>\n<td>IXON</td>\n<td>IXON VPN Client</td>\n<td>Improper Neutralization of CRLF Sequences ('CRLF Injection')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Commercial Facilities, Critical Manufacturing, Energy, Information Technology, Water and Wastewater</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Netherlands</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-75925</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Improper Neutralization of CRLF Sequences (CWE-93) in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralised, which allows additional directives to be introduced into that file. The configuration interface accepts changes without authenticating or verifying the origin of the requester (CWE-306, contributing). The injected configuration persists on disk across restarts of the client and the operating system, and the VPN connection continues to function normally, so there is no behavioral change visible to the user.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-75925\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>IXON VPN Client</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>IXON</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>IXON VPN Client: &lt;1.4.7</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>IXON recommends updating the IXON VPN client to version 1.4.7 or later on every computer where it is installed.</p>\n<p><strong>Mitigation</strong><br>As of August 5, 2026, IXON cloud rejects connections from clients below v1.4.7 at both the portal and the back-end API. Since the privileged subprocess and injected listener are only created when the client connects, unpatched installations cannot complete the exploit chain.</p>\n<p><strong>Mitigation</strong><br>If the client is no longer needed, IXON recommends uninstalling the VPN client from the computer.</p>\n<p><strong>Mitigation</strong><br>For more information please refer to the IXON Trust Center Advisory at https://www.ixon.cloud/Advisories/ADV-2026-08-05.pdf.<br><a href=\"https://www.ixon.cloud/Advisories/ADV-2026-08-05.pdf%60\">https://www.ixon.cloud/Advisories/ADV-2026-08-05.pdf</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/93.html\">CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.6</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.4</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Luuk van Rheden of IXON discovered this vulnerability.</li>\n<li>Stan van Duijnhoven of IXON reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-05</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-05</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n<tr>\n<td>2026-09-03</td>\n<td>2</td>\n<td>Initial Republication by CISA</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 03 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 03 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-07",
        "title": "Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-07",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-169-07.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution systems. The Easergy MiCOM P30 is a family of multifunction protection and control relays designed for medium, high and extra high voltage electrical networks. The Easergy MiCOM P40 is a protection relay series for Medium Voltage, High Voltage and Extra High Voltage protection. The Easergy MiCOM C264 is a modular and compact substation or bay controller, smart RTU and MV one box solution The EcoStruxure Power Automation System Gateway (EPAS=GTW) is a scalable, interoperable, and rugged communication gateway that helps to remotely monitor and operate electrical processes The EcoStruxure Power Automation System User Interface (EPAS-UI) product is an HMI SCADA designed for electrical networks and substations operations. The EcoStruxure Power Automation System Intelligent Power Management System and Fast Load Shedding (iPMFLS) is a range of solutions designed to overcome size and performances constraints. The EcoStruxure Power Operation (EPO) are an on-premises software offers that provides a single platform to monitor and control medium and lower power systems. The PowerLogic P5 is a medium voltage protection relay. The PowerLogic P7 is a protection and control platform designed for complex and advanced electrical network applications. The PowerLogic T300 is a modular platform for medium voltage and low voltage public distribution network management. The PowerLogic T500 is a control unit and RTU for substation automation. The Saitel DP RTU is a modular platform for medium voltage and low voltage public distribution and transmission network management. The EasyLogic T150 (formerly Saitel DR RTU) is a field device, offering a solid and powerful platform for data acquisition, communication, automation and IED integration for distribution and transmission networks, generation sector and railway. Failure to apply the fix provided below may risk session hijacking, which could result in malicious actors performing unauthorized operations within the affected system.</strong></p>\n<p>The following versions of Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A) are affected:</p>\n<ul>\n<li>Easergy MiCOM C264 vers:generic/&lt;=D7.33 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P139 vers:generic/&lt;=P139.678.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P437 vers:generic/&lt;=P437.678.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P439 vers:generic/&lt;=P439.678.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P532 vers:generic/&lt;=P532.678.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P539 vers:generic/&lt;=P539.678.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P631 vers:generic/&lt;=P631.678.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P632 vers:generic/&lt;=P632.678.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P633 vers:generic/&lt;=P633.678.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P634 vers:generic/&lt;=P634.678.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P633 P633.680.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P634 P634.680.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P138 vers:generic/&lt;=P138.677.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P436 vers:generic/&lt;=P436.677.701 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P438 vers:generic/&lt;=P438.677.701 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P638 vers:generic/&lt;=P638.677.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM C434 vers:generic/&lt;=C434.679.700 (CVE-2026-4827)</li>\n<li>EcoStruxure Power Automation System Gateway (EPAS-GTW) vers:intdot/&lt;=6.4.616.200.100 (CVE-2026-4827)</li>\n<li>EcoStruxure Power Automation System User Interface (EPAS-UI) vers:intdot/&lt;=3.0.3 (CVE-2026-4827)</li>\n<li>EcoStruxure Power Operation vers:generic/&lt;=2022_CU6 (CVE-2026-4827)</li>\n<li>EcoStruxure Power Operation vers:generic/&lt;=2024_CU2 (CVE-2026-4827)</li>\n<li>iPMFLS vers:intdot/&lt;=64.2025.0.13 (CVE-2026-4827)</li>\n<li>PowerLogic P5 Protection Relay vers:intdot/&lt;=02.502.103 (CVE-2026-4827)</li>\n<li>PowerLogic P7 Protection and Control Platform vers:intdot/&lt;=02.002.002 (CVE-2026-4827)</li>\n<li>PowerLogic T300 vers:intdot/&lt;=2.9.4 (CVE-2026-4827)</li>\n<li>PowerLogic T500 vers:intdot/&lt;=11.08.02 (CVE-2026-4827)</li>\n<li>Saitel DP vers:intdot/&lt;=11.06.36 ()</li>\n<li>EasyLogic T150 (formerly Saitel DR) vers:intdot/&lt;=11.06.30 ()</li>\n<li>Easergy MiCOM C264 D7.34 ()</li>\n<li>Easergy C5 vers:intdot/&lt;=1.1.17 (CVE-2026-4827)</li>\n<li>Easergy C5 1.1.18 ()</li>\n<li>Easergy MiCOM P139 version P139.678.700 ()</li>\n<li>Easergy MiCOM P439 P439.678.700 ()</li>\n<li>Easergy MiCOM P539 P539.678.700 ()</li>\n<li>Easergy MiCOM P632 P632.678.700 ()</li>\n<li>Easergy MiCOM P633 P633.680.701 ()</li>\n<li>Easergy MiCOM P634 P634.680.701 ()</li>\n<li>Easergy MiCOM P633 P633.678.700 ()</li>\n<li>Easergy MiCOM P138 P138.677.701 ()</li>\n<li>Easergy MiCOM C434 C434.679.700 ()</li>\n<li>Saitel DR 11.06.31 ()</li>\n<li>EcoStruxure Power Automation System Gateway (EPAS-GTW) 6.4.610.500.101 ()</li>\n<li>EcoStruxure Power Automation Automation System User Interface (EPAS-UI) 3.0.4 ()</li>\n<li>EcoStruxure Power Operation 2022_CU7 ()</li>\n<li>EcoStruxure Power Operation (EPO) 2024_CU3 ()</li>\n<li>iPMFLS 64.2025.0.14 ()</li>\n<li>PowerLogic P5 Protection Relay 02.503.101 ()</li>\n<li>PowerLogic P7 Protection and Control Platform 02.003.001 ()</li>\n<li>PowerLogic T300 2.9.5 ()</li>\n<li>PowerLogic T500 11.08.03 ()</li>\n<li>Saitel DP 11.06.37 ()</li>\n<li>Easergy MiCOM P40 Series vers:all/* (CVE-2026-4827)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.3</td>\n<td>Schneider Electric</td>\n<td>Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products</td>\n<td>Insufficient Entropy</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Critical Manufacturing, Energy, Water and Wastewater</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>France</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-4827</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>CWE-331 Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the network can exploit weaknesses in session\u2011management protections.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-4827\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Schneider Electric</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Easergy MiCOM C264 Versions D7.33 and prior, Easergy MiCOM P139 version prior to P139.678.700, Easergy MiCOM P437 version prior to P437.678.700, Easergy MiCOM P439 version prior to P439.678.700, Easergy MiCOM P532 version prior to P532.678.700, Easergy MiCOM P539 version prior to P539.678.700, Easergy MiCOM P631 version prior to P631.678.700, Easergy MiCOM P632 version prior to P632.678.700, Easergy MiCOM P633 version prior to P633.678.700, Easergy MiCOM P634 version prior to P634.678.700, Easergy MiCOM P633 version P633.680.700, Easergy MiCOM P634 version P634.680.700 , Easergy MiCOM P138 version prior to P138.677.700, Easergy MiCOM P436 version prior to P436.677.701, Easergy MiCOM P438 version prior to P438.677.701, Easergy MiCOM P638 version prior to P638.677.700, Easergy MiCOM C434 version prior to C434.679.700, EcoStruxure Power Automation System Gateway (EPAS-GTW) Version 6.4.616.200.100 and prior, EcoStruxure Power Automation System User Interface (EPAS-UI) Version 3.0.3 and prior, EcoStruxure Power Operation (EPO) 2022 CU6 and prior, EcoStruxure Power Operation (EPO) 2024 CU2 and prior, iPMFLS Version 64.2025.0.13 and prior, PowerLogic P5 Protection Relay V02.502.103 and prior, PowerLogic P7 Protection and Control Platform V02.002.002 and prior, PowerLogic T300 Version 2.9.4 and prior, PowerLogic T500 Version 11.08.02 and prior, Easergy C5 Version 1.1.17 and prior, Easergy MiCOM P40 Series model numbers with Protocol Option bit as G, H or L and all firmware versions</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>fixed, known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Version D7.34 of MiCOM C264 includes a fix for this vulnerability. Contact Schneider Electric\u2019s Customer Care Center for information on how to contact your local Application Center to update the device. Reboot is required.</p>\n<p><strong>Vendor fix</strong><br>Version 1.1.18 of Easergy C5 includes a fix for this vulnerability. Contact Schneider Electric\u2019s Customer Care Center for information on how to contact your local Application Center to update the device. Reboot is required.</p>\n<p><strong>Vendor fix</strong><br>Version P139.678.700 Easergy MiCOM P139 includes a fix for this vulnerability. Contact Schneider Electric\u2019s Customer Care Center for information on how to contact your local Application Center to update the device.</p>\n<p><strong>Vendor fix</strong><br>Version P439.678.700 Easergy MiCOM P439 includes a fix for this vulnerability. Contact Schneider Electric\u2019s Customer Care Center for information on how to contact your local Application Center to update the device.</p>\n<p><strong>Vendor fix</strong><br>Version P539.678.700 Easergy MiCOM P539 includes a fix for this vulnerability. Contact Schneider Electric\u2019s Customer Care Center for information on how to contact your local Application Center to update the device.</p>\n<p><strong>Vendor fix</strong><br>Version P632.678.700 Easergy MiCOM P632 includes a fix for this vulnerability. Contact Schneider Electric\u2019s Customer Care Center for information on how to contact your local Application Center to update the device.</p>\n<p><strong>Vendor fix</strong><br>Version P633.678.700 Easergy MiCOM P633 includes a fix for this vulnerability. Contact Schneider Electric\u2019s Customer Care Center for information on how to contact your local Application Center to update the device.</p>\n<p><strong>Vendor fix</strong><br>Version P634.680.701 Easergy MiCOM P634 includes a fix for this vulnerability. Contact Schneider Electric\u2019s Customer Care Center for information on how to contact your local Application Center to update the device.</p>\n<p><strong>Vendor fix</strong><br>Version P633.680.701 Easergy MiCOM P633 includes a fix for this vulnerability. Contact Schneider Electric\u2019s Customer Care Center for information on how to contact your local Application Center to update the device.</p>\n<p><strong>Vendor fix</strong><br>Version P138.677.701 Easergy MiCOM P138 includes a fix for this vulnerability. Contact Schneider Electric\u2019s Customer Care Center for information on how to contact your local Application Center to update the device.</p>\n<p><strong>Vendor fix</strong><br>Version C434.679.700 Easergy MiCOM C434 includes a fix for this vulnerability. Contact Schneider Electric\u2019s Customer Care Center for information on how to contact your local Application Center to update the device.</p>\n<p><strong>Vendor fix</strong><br>HUe Firmware version 11.06.31 includes a fix for this vulnerability and is available for download here: . Contact Schneider Electric\u2019s Customer Care Center to download this software. A reboot is needed to complete the firmware upgrade.</p>\n<p><strong>Vendor fix</strong><br>Version 6.4.610.500.101 of EPAS Gateway includes a fix for this vulnerability. Contact Schneider Electric\u2019s Customer Care Center to download this software.</p>\n<p><strong>Vendor fix</strong><br>Version 3.0.4 of EPAS-UI includes a fix for this vulnerability. Contact Schneider Electric\u2019s Customer Care Center to download this software.</p>\n<p><strong>Vendor fix</strong><br>EPO 2022 CU 7 of EcoStruxure Power Operation includes a fix for this vulnerability and is available for download here:&nbsp;<br><a href=\"https://community.se.com/t5/EcoStruxure-Power-Operation/Power-Operation-2022-CU7-is-Now-Available/td-p/524787\">https://community.se.com/t5/EcoStruxure-Power-Operation/Power-Operation-2022-CU7-is-Now-Available/td-p/524787</a></p>\n<p>Reboot needed: yes</p>\n<p><strong>Vendor fix</strong><br>EPO 2024 CU 3 of EcoStruxure Power Operation includes a fix for this vulnerability and is available for download here:&nbsp;<br><a href=\"https://community.se.com/t5/EcoStruxure-Power-Operation/Power-Operation-2024-CU3-is-HERE/td-p/534769\">https://community.se.com/t5/EcoStruxure-Power-Operation/Power-Operation-2024-CU3-is-HERE/td-p/534769</a></p>\n<p>Reboot needed: yes</p>\n<p><strong>Vendor fix</strong><br>Version 64.2025.0.14 of iPMFLS includes a fix for this vulnerability. Contact Schneider Electric\u2019s Customer Care Center for information on how to contact your local Application Center to update the device.</p>\n<p><strong>Vendor fix</strong><br>Version V02.503.101 of PowerLogic P5 includes a fix for this vulnerability. Contact Schneider Electric\u2019s Customer Care Center to download this firmware.</p>\n<p><strong>Vendor fix</strong><br>Version V02.003.001 of PowerLogic P7 includes a fix for this vulnerability. Contact Schneider Electric\u2019s Customer Care Center to download this firmware.</p>\n<p><strong>Vendor fix</strong><br>Version 2.9.5 of PowerLogic T300 includes a fix for this vulnerability. Contact Schneider Electric\u2019s Customer Care Center to download this firmware. A reboot is needed to complete the firmware upgrade.</p>\n<p><strong>Vendor fix</strong><br>Version 11.08.03 of PowerLogic T500 includes a fix for this vulnerability. Contact Schneider Electric\u2019s Customer Care Center to download this firmware. A reboot is needed to complete the firmware upgrade.</p>\n<p><strong>Vendor fix</strong><br>CPU866e Firmware version 11.06.37 includes a fix for this vulnerability and is available for download. Contact Schneider Electric\u2019s Customer Care Center to download this firmware. A reboot is needed to complete the firmware upgrade.</p>\n<p><strong>Mitigation</strong><br>Schneider Electric is establishing a remediation plan for all future versions of the following models of the Easergy MiCOM P30: P437 P532 P631 P634 P436 P438 P638 Future versions will include a fix for this vulnerability. We will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit:&nbsp;</p>\n<ul>\n<li>Ensure P30 operates within a physically or logically segmented internal network. Access to this network should be tightly controlled using standard security mechanisms such as firewalls, intrusion detection systems (IDS), and other relevant protective measures.&nbsp;</li>\n<li>Reduce the \u201cMinimum inactivity period\u201d using the CAE tool to shorten session timeout durations and minimize the risk of unauthorized access due to inactive sessions.</li>\n</ul>\n<p><strong>Mitigation</strong><br>Schneider Electric is establishing a remediation plan for a future version of the Easergy MiCOM P40 Series model numbers with Protocol Option bit as G, H or L. P_ 4_ _ _ _ _ G_ _ _ _ _ M P_ 4_ _ _ _ _ H_ _ _ _ _ M P_ 4_ _ _ _ _ L _ _ _ _ _ M P_ 4_ _ _ _ _ G_ _ _ _ _ L P_ 4_ _ _ _ _ H_ _ _ _ _ L P_ 4_ _ _ _ _ L _ _ _ _ _ L A future version will include a fix for this vulnerability. We will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit:&nbsp;</p>\n<ul>\n<li>Ensure P40 operates within a physically or logically segmented internal network. Access to this network should be tightly controlled using standard security mechanisms such as firewalls, intrusion detection systems (IDS), and other relevant protective measures.&nbsp;</li>\n<li>Reduce the \u201cMinimum inactivity period\u201d using the CAE tool to shorten session timeout durations and minimize the risk of unauthorized access due to inactive sessions.</li>\n</ul>\n<p><strong>Mitigation</strong><br>If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit:</p>\n<ul>\n<li>Ensure P30 operates within a physically or logically segmented internal network. Access to this network should be tightly controlled using standard security mechanisms such as firewalls, intrusion detection systems (IDS), and other relevant protective measures.&nbsp;</li>\n<li>Reduce the \u201cMinimum inactivity period\u201d using the CAE tool to shorten session timeout durations and minimize the risk of unauthorized access due to inactive sessions.</li>\n</ul>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/331.html\">CWE-331 Insufficient Entropy</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>An internal researcher of Schneider Electric reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>General Security Recommendations</h2>\n<p>We strongly recommend the following industry cybersecurity best practices. * Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network. * Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks. * Place all controllers in locked cabinets and never leave them in the \u201cProgram\u201d mode. * Never connect programming software to any network other than the network intended for that device. * Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks. * Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation. * Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet. * When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices. For more information refer to the Schneider Electric [Recommended Cybersecurity Best Practices](https://www.se.com/us/en/download/document/7EN52-0390/) document.</p>\n<hr>\n<h2>For More Information</h2>\n<p>This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process. For further information related to cybersecurity in Schneider Electric's products, visit the company's cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp</p>\n<hr>\n<h2>LEGAL DISCLAIMER</h2>\n<p>THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS \u201cNOTIFICATION\u201d) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN \u201cAS-IS\u201d BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION</p>\n<hr>\n<h2>About Schneider Electric</h2>\n<p>Schneider's purpose is to create Impact by empowering all to make the most of our energy and resources, bridging progress and sustainability for all. We call this Life Is On. Our mission is to be the trusted partner in Sustainability and Efficiency. We are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart industries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep domain expertise, we provide integrated end-to-end lifecycle AI enabled Industrial IoT solutions with connected products, automation, software and services, delivering digital twins to enable profitable growth for our customers. We are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries to ensure proximity to our customers and stakeholders. We embrace diversity and inclusion in everything we do, guided by our meaningful purpose of a sustainable future for all. www.se.com</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Schneider Electric CPCERT SEVD-2026-132-02 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-05-12</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-05-12</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n<tr>\n<td>2026-06-18</td>\n<td>2</td>\n<td>Initial Republication of Schneider Electric CPCERT SEVD-2026-132-02</td>\n</tr>\n<tr>\n<td>2026-09-03</td>\n<td>3</td>\n<td>Update A - Revised the summary to reflect the affected products</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 03 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 03 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-08",
        "title": "Tycon Systems TPDIN-Monitor-WEB3",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-08",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-08.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information.</strong></p>\n<p>The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected:</p>\n<ul>\n<li>TPDIN-Monitor-WEB3 &lt;=2.2.9 (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.8</td>\n<td>Tycon Systems</td>\n<td>Tycon Systems TPDIN-Monitor-WEB3</td>\n<td>Use of Hard-coded Credentials, Cross-Site Request Forgery (CSRF), Missing Authorization</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-77847</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Use of Hard-coded Credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-77847\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Tycon Systems TPDIN-Monitor-WEB3</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Tycon Systems</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Tycon Systems TPDIN-Monitor-WEB3: &lt;=2.2.9</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Tycon Systems has released TPDIN-Monitor-WEB3 Firmware v2.4.2.</p>\n<p><strong>Mitigation</strong><br>Units already running v2.4.2, for subsequent updates (signed container):&nbsp;<br><a href=\"https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw\">https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw</a></p>\n<p><strong>Mitigation</strong><br>All units currently in the field, including the v2.2.9 covered by this report (legacy Intel HEX):&nbsp;<br><a href=\"https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex\">https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex</a></p>\n<p><strong>Mitigation</strong><br>A unit running v2.2.9 installs the .hex build directly and arrives at v2.4.2 in a single step; no intermediate version is required. The signed .tfw container cannot be read by a v2.2.9 updater, which accepts only Intel HEX, so the .hex artifact is the one every deployed unit needs.</p>\n<p><strong>Mitigation</strong><br>For more information, contact Tycon Systems:&nbsp;<br><a href=\"https://www.tyconsystems.com/contact\">https://www.tyconsystems.com/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/798.html\">CWE-798 Use of Hard-coded Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-82712</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Cross-Site Request Forgery vulnerability. This could allow an attacker to perform state changing operations on the device.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-82712\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Tycon Systems TPDIN-Monitor-WEB3</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Tycon Systems</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Tycon Systems TPDIN-Monitor-WEB3: &lt;=2.2.9</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Tycon Systems has released TPDIN-Monitor-WEB3 Firmware v2.4.2.</p>\n<p><strong>Mitigation</strong><br>Units already running v2.4.2, for subsequent updates (signed container):&nbsp;<br><a href=\"https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw\">https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw</a></p>\n<p><strong>Mitigation</strong><br>All units currently in the field, including the v2.2.9 covered by this report (legacy Intel HEX):&nbsp;<br><a href=\"https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex\">https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex</a></p>\n<p><strong>Mitigation</strong><br>A unit running v2.2.9 installs the .hex build directly and arrives at v2.4.2 in a single step; no intermediate version is required. The signed .tfw container cannot be read by a v2.2.9 updater, which accepts only Intel HEX, so the .hex artifact is the one every deployed unit needs.</p>\n<p><strong>Mitigation</strong><br>For more information, contact Tycon Systems:&nbsp;<br><a href=\"https://www.tyconsystems.com/contact\">https://www.tyconsystems.com/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/352.html\">CWE-352 Cross-Site Request Forgery (CSRF)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-82684</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-82684\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Tycon Systems TPDIN-Monitor-WEB3</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Tycon Systems</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Tycon Systems TPDIN-Monitor-WEB3: &lt;=2.2.9</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Tycon Systems has released TPDIN-Monitor-WEB3 Firmware v2.4.2.</p>\n<p><strong>Mitigation</strong><br>Units already running v2.4.2, for subsequent updates (signed container):&nbsp;<br><a href=\"https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw\">https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw</a></p>\n<p><strong>Mitigation</strong><br>All units currently in the field, including the v2.2.9 covered by this report (legacy Intel HEX):&nbsp;<br><a href=\"https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex\">https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex</a></p>\n<p><strong>Mitigation</strong><br>A unit running v2.2.9 installs the .hex build directly and arrives at v2.4.2 in a single step; no intermediate version is required. The signed .tfw container cannot be read by a v2.2.9 updater, which accepts only Intel HEX, so the .hex artifact is the one every deployed unit needs.</p>\n<p><strong>Mitigation</strong><br>For more information, contact Tycon Systems:&nbsp;<br><a href=\"https://www.tyconsystems.com/contact\">https://www.tyconsystems.com/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/862.html\">CWE-862 Missing Authorization</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Abdiwelli Guled reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-03</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-03</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 03 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 03 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-04",
        "title": "Rockwell Automation ArmorStart LT",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-04",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-04.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page.</strong></p>\n<p>The following versions of Rockwell Automation ArmorStart LT are affected:</p>\n<ul>\n<li>ArmorStart LT &lt;=v2.001 (CVE-2026-19471, CVE-2026-19472)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation ArmorStart LT</td>\n<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Allocation of Resources Without Limits or Throttling</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-19471</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Multiple stored cross-site scripting security issues exist within ArmorStart LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, allowing an attacker to inject malicious scripts that will be executed when other users access the affected page.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-19471\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation ArmorStart LT</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation ArmorStart LT: &lt;=v2.001</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Rockwell Automation has corrected this issue in firmware version v2.002, and encourages all users to update to the newest version.</p>\n<p><strong>Mitigation</strong><br>Users of the affected software who are not able to upgrade to one of the corrected versions should follow Rockwell Automation's security best practices.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information on this issue, see the Rockwell Automation security advisory at: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/79.html\">CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-19472</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service security issue exists within ArmorStart LT. The security issue stems from improper handling of a crafted HTTP PUT request sent to the embedded web server. This can result in a loss of web server availability.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-19472\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation ArmorStart LT</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation ArmorStart LT: &lt;=v2.001</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Rockwell Automation has corrected this issue in firmware version v2.002, and encourages all users to update to the newest version.</p>\n<p><strong>Mitigation</strong><br>Users of the affected software who are not able to upgrade to one of the corrected versions should follow Rockwell Automation's security best practices.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information on this issue, see the Rockwell Automation security advisory at: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/770.html\">CWE-770 Allocation of Resources Without Limits or Throttling</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-03</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-03</td>\n<td>1</td>\n<td>Initial Republication of Rockwell Automation security advisory.</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 03 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 03 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/resources-tools/resources/preparing-post-quantum-era-call-action",
        "title": "Preparing for the Post-Quantum Era: A Call to Action",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/resources-tools/resources/preparing-post-quantum-era-call-action",
        "summary": "<p>CISA and the Group of Seven (G7) Cyber Security Working Group released <a href=\"https://urldefense.us/v3/__https:/cyber.gouv.fr/en/publications/jointly-led-international-publications/preparing-for-the-post-quantum-era-a-call-to-action/__;!!BClRuOV5cvtbuNI!A4T2ayZfcpa7J25BSkxtB9A-AHREvqT8FQmzhRjVarx8w3J-Vs-CBcKQcElRqsqsZqtIztYiIMY01My3HFmonToxreu7Z35ka6L8naw5xg$\" target=\"_blank\"><em>Preparing for the Post-Quantum Era: A Call to Action</em></a><em> </em>highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to protect sensitive data, authentication systems, and critical assets from emerging quantum computing threats. &nbsp;</p>\n<p>The G7 Cyber Security Working Group\u2019s call to action outlines five priorities for a successful transition to PQC:</p>\n<ul>\n<li>Raising awareness of quantum risks and the importance of PQC;</li>\n<li>Developing national strategies that support PQC adoption and integration;</li>\n<li>Advancing research and development for quantum-safe technologies;</li>\n<li>Fostering public-private partnerships to share expertise and resources; and</li>\n<li>Integrating PQC into cybersecurity requirements and procurement processes.&nbsp;</li>\n</ul>\n<div class=\"c-text-cta\">\n<div class=\"l-constrain c-text-cta__inner\">\n<div class=\"c-text-cta__content\">\n<h2>Please share your thoughts!</h2>\n<div class=\"c-text-cta__summary\">\n<p>We welcome your feedback.</p>\n</div>\n<p><a class=\"c-button c-button--on-dark\" href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_9n4TtB8uttUPaM6?product=https://www.cisa.gov/resources-tools/resources/preparing-post-quantum-era-call-action\">CISA PRODUCT SURVEY</a></p>\n</div>\n</div>\n</div>",
        "summary_is_html": true,
        "first_seen": "Thu, 03 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 03 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-01",
        "title": "OPCFoundation OPC UA LocalDiscoveryServer (LDS)",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands.</strong></p>\n<p>The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected:</p>\n<ul>\n<li>UA-LDS-Installers &lt;1.04.420 (CVE-2026-77477)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 4.6</td>\n<td>OPCFoundation</td>\n<td>OPCFoundation OPC UA LocalDiscoveryServer (LDS)</td>\n<td>Execution with Unnecessary Privileges</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Energy, Food and Agriculture, Water and Wastewater, Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-77477</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An attacker can intercept a high-privilege console window launched during installation of the LDS. The attacker must be able to launch an installer with elevated privileges and have access to the keyboard and display while the installation is taking place.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-77477\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>OPCFoundation OPC UA LocalDiscoveryServer (LDS)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>OPCFoundation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>OPCFoundation UA-LDS-Installers: &lt;1.04.420</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>OPCFoundation recommends users update to OPC UA LDS Installers 1.04.420 or later.</p>\n<p><strong>Mitigation</strong><br>For more information about this vulnerability and its mitigation, see the OPCFoundation security advisory.<br><a href=\"https://github.com/OPCFoundation/OPC-SecurityAdvisories/tree/latest/csaf/2026/009\">https://github.com/OPCFoundation/OPC-SecurityAdvisories/tree/latest/csaf/2026/009</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/250.html\">CWE-250 Execution with Unnecessary Privileges</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>4.6</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N\">CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>2.4</td>\n<td>LOW</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Lukas Schumaker of Rockwell Automation reported this vulnerability to OPCFoundation.</li>\n<li>OPCFoundation reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-03</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-03</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 03 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 03 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-06",
        "title": "Inductive Automation Ignition",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-06",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-06.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow any authenticated user to create projects.</strong></p>\n<p>The following versions of Inductive Automation Ignition are affected:</p>\n<ul>\n<li>Ignition &lt;=8.1.53 (CVE-2026-77393)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.8</td>\n<td>Inductive Automation</td>\n<td>Inductive Automation Ignition</td>\n<td>Incorrect Default Permissions</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy, Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-77393</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>In Ignition 8.1.53 and earlier, the Gateway \"Create Project Role(s)\" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-77393\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Inductive Automation Ignition</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Inductive Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Inductive Automation Ignition: &lt;=8.1.53</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Inductive Automation has determined that this issue is a default-value configuration, not a flaw in the access control itself. The security control enforces exactly what the \"Create Project Role(s)\" setting specifies; because the setting shipped blank, no role was required to create a project. Populating the setting fully closes the vulnerability.</p>\n<p><strong>Mitigation</strong><br>Inductive Automation recommends users upgrade to 8.1.54 or later (or the latest 8.3 version), which restricts project creation to Designer sessions and no longer relies on this setting. Users who must remain on an earlier 8.1 version can fully remediate the issue by setting \"Create Project Role(s)\" to match their Designer Role. Once the setting is populated, only users holding that role can create projects. See Gateway General Security Settings.<br><a href=\"https://docs.inductiveautomation.com/docs/8.1/platform/security/gateway-general-security-settings#gateway-security-settings-table\">https://docs.inductiveautomation.com/docs/8.1/platform/security/gateway-general-security-settings#gateway-security-settings-table</a></p>\n<p><strong>Mitigation</strong><br>For more information, see the publication at the Inductive Automation Trust Center.<br><a href=\"https://security.inductiveautomation.com/?tcuUid=34477620-731d-4b70-b22b-9450f9a659a3\">https://security.inductiveautomation.com/?tcuUid=34477620-731d-4b70-b22b-9450f9a659a3</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/276.html\">CWE-276 Incorrect Default Permissions</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Christopher Lusk of North Echo Security Research reported this vulnerability to Inductive Automation.</li>\n<li>Elhussain Fathy (0xSphinx) independently reported this vulnerability and confirmed the fix.</li>\n<li>Inductive Automation reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-03</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-03</td>\n<td>1</td>\n<td>Initial Republication of Inductive Automation Trust Center update.</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 03 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 03 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-01",
        "title": "Tycon Systems TPDIN-Monitor-WEB2 (Update A)",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.</strong></p>\n<p>The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected:</p>\n<ul>\n<li>TPDIN-Monitor-WEB2 &lt;2.4.5 (CVE-2026-61884, CVE-2026-55985)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.8</td>\n<td>Tycon Systems</td>\n<td>Tycon Systems TPDIN-Monitor-WEB2</td>\n<td>Missing Authentication for Critical Function, Cleartext Storage of Sensitive Information</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-61884</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The device ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without requiring any login. An attacker with network access to such a unit can reach full device controls, including power relay management, device reboot, remote access service configuration, and network settings, which could allow disruption of connected infrastructure or physical damage to equipment.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-61884\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Tycon Systems TPDIN-Monitor-WEB2 (Update A)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Tycon Systems</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Tycon Systems TPDIN-Monitor-WEB2: &lt;2.4.5</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Tycon Systems has released firmware 2.4.5, which resolves this vulnerability by requiring an administrator username and password to be set before the web interface is served. Further inquiries can be directed to security@tyconsystems.com.</p>\n<p><strong>Mitigation</strong><br>Tycon Systems recommends setting an administrative username and strong password on the Network Configuration page and confirming in a private browser window that a login is required, for units still running firmware 2.4.4 or earlier. Repeat this after any factory reset.</p>\n<p><strong>Mitigation</strong><br>Tycon Systems recommends not exposing the web interface to the Internet, as it is HTTP only. The unit should be kept on a private network, behind a firewall or VPN.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-55985</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The device's web management interface stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-55985\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Tycon Systems TPDIN-Monitor-WEB2 (Update A)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Tycon Systems</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Tycon Systems TPDIN-Monitor-WEB2: &lt;2.4.5</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Tycon Systems has released firmware 2.4.5, which resolves this vulnerability by removing cleartext credentials from the web interface response. Further inquiries can be directed to security@tyconsystems.com.</p>\n<p><strong>Mitigation</strong><br>Tycon Systems recommends changing any factory-default SNMP community strings and the Telnet password if they were left at shipped values. Leave Telnet disabled unless required.</p>\n<p><strong>Mitigation</strong><br>Tycon Systems recommends using a dedicated mail account for device alerts, rather than an account also used for other sensitive purposes, to limit exposure if credentials are compromised.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/312.html\">CWE-312 Cleartext Storage of Sensitive Information</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>4.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Abdiwelli Guled reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-21</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-21</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n<tr>\n<td>2026-09-03</td>\n<td>2</td>\n<td>Updated affected version range and vulnerability details based on vendor input.</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 03 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 03 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-05",
        "title": "Rockwell Automation 1756-ENBT Module",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-05",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-05.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover.</strong></p>\n<p>The following versions of Rockwell Automation 1756-ENBT Module are affected:</p>\n<ul>\n<li>1756-ENBT module vers:all/* (CVE-2025-10478)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation 1756-ENBT Module</td>\n<td>Improper Check for Unusual or Exceptional Conditions</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Food and Agriculture, Transportation Systems, Water and Wastewater</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-10478</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service security issue exists in the Rockwell Automation 1756-ENBT module which is a ControlLogix EtherNet/IP bridge that enables communication between Logix 5000 controllers and Ethernet devices. An attacker could exploit this vulnerability by sending a crafted CIP packet, causing the module to crash. The device requires a restart to recover.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-10478\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation 1756-ENBT Module</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation 1756-ENBT module: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Rockwell Automation recommends that users upgrade to 1756-EN2T or 1756-EN4TR. Users who are not able to upgrade should use Rockwell Automation's security best practices.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information on this issue, see the corresponding Rockwell Automation security advisory.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/754.html\">CWE-754 Improper Check for Unusual or Exceptional Conditions</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-03</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-03</td>\n<td>1</td>\n<td>Initial Republication of Rockwell Automation security advisory.</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 03 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 03 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/resources-tools/resources/communicating-under-pressure-best-practices-service-providers",
        "title": "Communicating Under Pressure: Best Practices for Service Providers",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/resources-tools/resources/communicating-under-pressure-best-practices-service-providers",
        "summary": "<p>Developed by CISA, the Federal Bureau of Investigation, and international partners, this <a href=\"https://www.cisa.gov/sites/default/files/2026-09/joint-guidance-communicating-under-pressure-508c.pdf\" title=\"Communicating Under Pressure: Best Practices for Service Providers\">guidance</a> describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create disruption and societal panic even without speculation from end users and the public as added factors. Outages at one organization may cascade across interconnected systems, increasing uncertainty and alarm. The guidance emphasizes clarity, accountability, and transparency as core principles and details key elements of effective crisis messaging to inform affected stakeholders and the public while aligning with legal requirements, operational security, law enforcement, and containment efforts.&nbsp;</p>\n<p>CISA\u2019s <a href=\"https://www.cisa.gov/topics/industrial-control-systems/ci-fortify\">CI Fortify</a> initiative provides information and resources that help critical infrastructure organizations prepare to isolate and recover vital OT systems during a major cyber incident or crisis. Changes in service availability, whether from outages or isolation as a defensive strategy, require transparent and ongoing communication to help end users minimize operational impact, limit speculation, and preserve trust. For emergency planning purposes, critical infrastructure owners and operators should assume that telecommunications services may be disrupted or otherwise unreliable, making it crucial for organizations to have crisis communications plans in place that integrate backup communication methods and understand the type of communication they should expect from their service providers.</p>",
        "summary_is_html": true,
        "first_seen": "Wed, 02 Sep 26 12:00:00 +0000",
        "last_updated": "Wed, 02 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/09/02/cisa-adds-seven-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Seven Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/09/02/cisa-adds-seven-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added seven new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<div class=\"ListContainerWrapper SCXW190820602 BCX8\">\n<ul type=\"disc\">\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9586\" target=\"_blank\"><u>CVE-2026-9586</u></a> Sangoma Switchvox SQL Injection Vulnerability&nbsp;</li>\n</ul>\n</div>\n<div class=\"ListContainerWrapper SCXW190820602 BCX8\">\n<ul type=\"disc\">\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-48710\" target=\"_blank\"><u>CVE-2026-48710</u></a> Kludex Starlette HTTP Request/Response Smuggling Vulnerability&nbsp;</li>\n</ul>\n</div>\n<div class=\"ListContainerWrapper SCXW190820602 BCX8\">\n<ul type=\"disc\">\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-49869\" target=\"_blank\"><u>CVE-2026-49869</u></a> Kestra OSS OS Command Injection Vulnerability&nbsp;</li>\n</ul>\n</div>\n<div class=\"ListContainerWrapper SCXW190820602 BCX8\">\n<ul type=\"disc\">\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-59822\" target=\"_blank\"><u>CVE-2026-59822</u></a> BerriAI LiteLLM Improper Authentication Vulnerability&nbsp;</li>\n</ul>\n</div>\n<div class=\"ListContainerWrapper SCXW190820602 BCX8\">\n<ul type=\"disc\">\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-82329\" target=\"_blank\"><u>CVE-2026-82329</u></a> JFrog Artifactory Improper Authentication Vulnerability&nbsp;</li>\n</ul>\n</div>\n<div class=\"ListContainerWrapper SCXW190820602 BCX8\">\n<ul type=\"disc\">\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-83548\" target=\"_blank\"><u>CVE-2026-83548</u></a> SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability&nbsp;</li>\n</ul>\n</div>\n<div class=\"ListContainerWrapper SCXW190820602 BCX8\">\n<ul type=\"disc\">\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-83549\" target=\"_blank\"><u>CVE-2026-83549</u></a> SonicWall SMA1000 Appliances OS Command Injection Vulnerability&nbsp;</li>\n</ul>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW211148847 BCX8\">\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\"><u>Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</u></a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW211148847 BCX8\">\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\"><u>KEV Catalog vulnerabilities</u></a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities\" target=\"_blank\"><u>specified criteria</u></a>.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW211148847 BCX8\">\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a class=\"ext\" href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\"><u>KEV Nomination Form</u></a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>\n</div>",
        "summary_is_html": true,
        "first_seen": "Wed, 02 Sep 26 12:00:00 +0000",
        "last_updated": "Wed, 02 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-06",
        "title": "Rockwell Automation Historian ME",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-06",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-244-06.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution.</strong></p>\n<p>The following versions of Rockwell Automation Historian ME are affected:</p>\n<ul>\n<li>Series B 5.202 (CVE-2025-12768, CVE-2026-12661)</li>\n<li>Series C 7.101 (CVE-2025-12768, CVE-2026-12661)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation Historian ME</td>\n<td>Out-of-bounds Write, Stack-based Buffer Overflow</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Critical Manufacturing, Food and Agriculture, Healthcare and Public Health, Water and Wastewater Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-12768</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A security issue exists within FactoryTalk\u00ae Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieveremote code execution on the affected device.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-12768\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation Historian ME</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation Series B: 5.202, Rockwell Automation Series C: 7.101</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automations security best practices found at https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>If you have any questions regarding the security issue(s) above and how to mitigate them, contact TechConnect for help. More information can be found at https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html.<br><a href=\"https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html\">https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html</a></p>\n<p><strong>Mitigation</strong><br>If you have any questions regarding this disclosure, please contact PSIRT Email: rasecure@ra.rockwell.com<br><a href=\"mailto:rasecure@ra.rockwell.com\">mailto:rasecure@ra.rockwell.com</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-12661</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service security issue exists within FactoryTalk\u00ae Historian Machine Edition. A network adjacent attacker who is authenticated could send craftedrequests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-12661\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation Historian ME</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation Series B: 5.202, Rockwell Automation Series C: 7.101</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automations security best practices found at https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>If you have any questions regarding the security issue(s) above and how to mitigate them, contact TechConnect for help. More information can be found at https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html.<br><a href=\"https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html\">https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html</a></p>\n<p><strong>Mitigation</strong><br>If you have any questions regarding this disclosure, please contact PSIRT Email: rasecure@ra.rockwell.com<br><a href=\"mailto:rasecure@ra.rockwell.com\">mailto:rasecure@ra.rockwell.com</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/121.html\">CWE-121 Stack-based Buffer Overflow</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>4.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>4.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-01</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-01</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 01 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 01 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-04",
        "title": "Rockwell Automation FactoryTalk Activation Manager",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-04",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-244-04.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p>The following versions of Rockwell Automation FactoryTalk Activation Manager are affected:</p>\n<ul>\n<li>FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.8</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation FactoryTalk Activation Manager</td>\n<td>Improper Restriction of Excessive Authentication Attempts</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-16675</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A privilege escalation vulnerability exists within FactoryTalk Activation Manager. The vulnerability stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack these console windows to obtain a SYSTEM-level command prompt, allowing full access to all files, processes, and system resources.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-16675\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation FactoryTalk Activation Manager</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation FactoryTalk Activation Manager V5.02_and_below</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users update to software version V5.03.</p>\n<p><strong>Mitigation</strong><br>Customers using the affected software who are not able to upgrade to one of the corrected versions should use Rockwell Automation's security best practices.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/307.html\">CWE-307 Improper Restriction of Excessive Authentication Attempts</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>An anonymous security researcher reported this vulnerability to Rockwell Automation, who reported it to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-01</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-01</td>\n<td>1</td>\n<td>Initial republication of Rockwell Automation advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 01 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 01 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-05",
        "title": "Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-05",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-244-05.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p>The following versions of Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix are affected:</p>\n<ul>\n<li>ControlLogix 5580 &lt;34.015, &lt;35.014, &lt;36.013, &lt;37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)</li>\n<li>GuardLogix 5580 &lt;34.015, &lt;35.014, &lt;36.013, &lt;37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)</li>\n<li>CompactLogix 5380 &lt;34.015, &lt;35.014, &lt;36.013, &lt;37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)</li>\n<li>Compact GuardLogix 5380 &lt;34.015, &lt;35.014, &lt;36.013, &lt;37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)</li>\n<li>CompactLogix 5480 &lt;34.015, &lt;35.014, &lt;36.013, &lt;37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix</td>\n<td>Loop with Unreachable Exit Condition ('Infinite Loop')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2021-42260</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A potential denial of service vulnerability exists in the affected products and can be triggered via corrupt crafted data. This could result in a major nonrecoverable fault (MNRF). A program download is required to recover safety controllers. For non-safety controllers, a stage 2 reset is required to recover.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2021-42260\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation ControlLogix 5580 &lt;34.015, Rockwell Automation ControlLogix 5580 &lt;35.014, Rockwell Automation ControlLogix 5580 &lt;36.013, Rockwell Automation ControlLogix 5580 &lt;37.011, Rockwell Automation GuardLogix 5580 &lt;34.015, Rockwell Automation GuardLogix 5580 &lt;35.014, Rockwell Automation GuardLogix 5580 &lt;36.013, Rockwell Automation GuardLogix 5580 &lt;37.011, Rockwell Automation CompactLogix 5380 &lt;34.015, Rockwell Automation CompactLogix 5380 &lt;35.014, Rockwell Automation CompactLogix 5380 &lt;36.013, Rockwell Automation CompactLogix 5380 &lt;37.011, Rockwell Automation Compact GuardLogix 5380 &lt;34.015, Rockwell Automation Compact GuardLogix 5380 &lt;35.014, Rockwell Automation Compact GuardLogix 5380 &lt;36.013, Rockwell Automation Compact GuardLogix 5380 &lt;37.011, Rockwell Automation CompactLogix 5480 &lt;34.015, Rockwell Automation CompactLogix 5480 &lt;35.014, Rockwell Automation CompactLogix 5480 &lt;36.013, Rockwell Automation CompactLogix 5480 &lt;37.011</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users update to firmware version 34.015 and later.</p>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users update to firmware version 35.014 and later.</p>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users update to firmware version 36.013 and later.</p>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users update to firmware version 37.011 and later.</p>\n<p><strong>Mitigation</strong><br>Customers using the affected software who are not able to upgrade to one of the corrected versions should use Rockwell Automation's security best practices.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/835.html\">CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-01</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-01</td>\n<td>1</td>\n<td>Initial republication of Rockwell Automation advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 01 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 01 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-02",
        "title": "Rockwell Automation Redundancy Module Configuration Tool",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-244-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges.</strong></p>\n<p>The following versions of Rockwell Automation Redundancy Module Configuration Tool are affected:</p>\n<ul>\n<li>Redundancy Module Configuration Tool 10.00.00 (CVE-2026-9633)</li>\n<li>Redundancy Module Configuration Tool &gt;=9.00.00|&lt;=10.00.00 (CVE-2026-9634)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.3</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation Redundancy Module Configuration Tool</td>\n<td>Incorrect Default Permissions</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-9633</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non administrator) users due to incorrect default permissions. If a local attacker places a malicious DLL in such a directory and an administrator subsequently runs the tool, the malicious DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9633\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation Redundancy Module Configuration Tool</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation Redundancy Module Configuration Tool: 10.00.00</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation has released Redundancy Module Configuration Tool version 10.01.00 for users to install.</p>\n<p><strong>Mitigation</strong><br>Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight).<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/276.html\">CWE-276 Incorrect Default Permissions</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-9634</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users due to incorrect default permissions. If a local attacker places a malicious DLL in such a directory and an administrator subsequently runs the tool, the malicious DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9634\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation Redundancy Module Configuration Tool</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation Redundancy Module Configuration Tool: &gt;=9.00.00|&lt;=10.00.00</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation has released Redundancy Module Configuration Tool version 10.01.00 for users to install.</p>\n<p><strong>Mitigation</strong><br>Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight).<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/276.html\">CWE-276 Incorrect Default Permissions</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-01</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-01</td>\n<td>1</td>\n<td>Initial Republication of Rockwell Automation Security Advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 01 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 01 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-01",
        "title": "Rockwell Automation RSLinx Classic",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-244-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product.</strong></p>\n<p>The following versions of Rockwell Automation RSLinx Classic are affected:</p>\n<ul>\n<li>RSLinx Classic &lt;=4.50 (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.6</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation RSLinx Classic</td>\n<td>Integer Overflow or Wraparound, Integer Underflow (Wrap or Wraparound), Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-9621</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service security issue exists within RSLinx Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx Classic service to crash, requiring a restart of the service to recover.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9621\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation RSLinx Classic</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation RSLinx Classic: &lt;=4.50</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation has corrected the vulnerabilities in RSLinx Classic version 4.60.</p>\n<p><strong>Mitigation</strong><br>Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/190.html\">CWE-190 Integer Overflow or Wraparound</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.2</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-9622</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service security issue exists within RSLinx Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx Classic service to crash, requiring a restart of the service to recover.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9622\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation RSLinx Classic</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation RSLinx Classic: &lt;=4.50</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation has corrected the vulnerabilities in RSLinx Classic version 4.60.</p>\n<p><strong>Mitigation</strong><br>Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/191.html\">CWE-191 Integer Underflow (Wrap or Wraparound)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.2</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-9624</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service security issue exists within RSLinx Classic. A crafted CIP packet can cause the RSLinx Classic service to crash due to insufficient data length validation, requiring a restart of the service to recover.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9624\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation RSLinx Classic</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation RSLinx Classic: &lt;=4.50</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation has corrected the vulnerabilities in RSLinx Classic version 4.60.</p>\n<p><strong>Mitigation</strong><br>Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/191.html\">CWE-191 Integer Underflow (Wrap or Wraparound)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-9625</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service security issue exists within RSLinx Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx Classic service to crash, requiring a restart of the service to recover.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9625\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation RSLinx Classic</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation RSLinx Classic: &lt;=4.50</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation has corrected the vulnerabilities in RSLinx Classic version 4.60.</p>\n<p><strong>Mitigation</strong><br>Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/120.html\">CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-01</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-01</td>\n<td>1</td>\n<td>Initial Republication of Rockwell Automation Advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 01 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 01 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-03",
        "title": "Rockwell Automation Logix Platform",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-03",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-244-03.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p>The following versions of Rockwell Automation Logix Platform are affected:</p>\n<ul>\n<li>ControlLogix 5580 &lt;=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)</li>\n<li>CompactLogix 5380 &lt;=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)</li>\n<li>GuardLogix 5580 &lt;=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)</li>\n<li>Compact GuardLogix 5380 &lt;=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation Logix Platform</td>\n<td>Improper Restriction of Operations within the Bounds of a Memory Buffer</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-9637</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service vulnerability exists in the affected Logix platforms due to improper validation of input length during CIP message processing. This can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9637\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation Logix Platform</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation ControlLogix 5580 &lt;=V33, Rockwell Automation ControlLogix 5580 V34.011-V34.014, Rockwell Automation ControlLogix 5580 V35.011-V35.013, Rockwell Automation ControlLogix 5580 V36.011-V36.012, Rockwell Automation CompactLogix 5380 &lt;=V33, Rockwell Automation CompactLogix 5380 V34.011-V34.014, Rockwell Automation CompactLogix 5380 V35.011-V35.013, Rockwell Automation CompactLogix 5380 V36.011-V36.012, Rockwell Automation GuardLogix 5580 &lt;=V33, Rockwell Automation GuardLogix 5580 V34.011-V34.014, Rockwell Automation GuardLogix 5580 V35.011-V35.013, Rockwell Automation GuardLogix 5580 V36.011-V36.012, Rockwell Automation Compact GuardLogix 5380 &lt;=V33, Rockwell Automation Compact GuardLogix 5380 V34.011-V34.014, Rockwell Automation Compact GuardLogix 5380 V35.011-V35.013, Rockwell Automation Compact GuardLogix 5380 V36.011-V36.012</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users update to firmware version V37.011.</p>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users update to firmware version 34.015.</p>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users update to firmware version 35.014.</p>\n<p><strong>Vendor fix</strong><br>Rockwell Automation recommends users update to firmware version 36.013.</p>\n<p><strong>Mitigation</strong><br>Customers using the affected software who are not able to upgrade to one of the corrected versions should use Rockwell Automation's security best practices.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/119.html\">CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-01</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-01</td>\n<td>1</td>\n<td>Initial republication of Rockwell Automation advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 01 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 01 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Two Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added two new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-81578\" target=\"_blank\"><u>CVE-2026-81578</u></a> PaperCut NG/MF Missing Authentication for Critical Function Vulnerability&nbsp;</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-82078\" target=\"_blank\"><u>CVE-2026-82078</u></a> PaperCut NG/MF Unsafe Reflection Vulnerability&nbsp;</li>\n</ul>\n<div class=\"OutlineElement Ltr SCXW211148847 BCX8\">\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW211148847 BCX8\">\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\"><u>Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</u></a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW211148847 BCX8\">\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\"><u>KEV Catalog vulnerabilities</u></a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities\" target=\"_blank\"><u>specified criteria</u></a>.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW211148847 BCX8\">\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\"><u>KEV Nomination Form</u></a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>\n</div>",
        "summary_is_html": true,
        "first_seen": "Mon, 31 Aug 26 12:00:00 +0000",
        "last_updated": "Mon, 31 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-078-05",
        "title": "Mitsubishi Electric CNC Series (Update A)",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-078-05",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-078-05.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products.</strong></p>\n<p>The following versions of Mitsubishi Electric CNC Series (Update A) are affected:</p>\n<ul>\n<li>Mitsubishi Electric M800VW (BND-2051W000) &lt;=BB (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M800VS (BND-2052W000) &lt;=BB (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M80V (BND-2053W000) &lt;=BB (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M80VW (BND-2054W000) &lt;=BB (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M800W (BND-2005W000) &lt;=FM (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M800S (BND-2006W000) &lt;=FM (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M80 (BND-2007W000) &lt;=FM (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M80W (BND-2008W000) &lt;=FM (CVE-2025-2399)</li>\n<li>Mitsubishi Electric E80 (BND-2009W000) &lt;=FM (CVE-2025-2399)</li>\n<li>Mitsubishi Electric C80 (BND-2036W000) vers:all/* (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M750VW (BND-1015W002) &lt;=LJ (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M730VW (BND-1015W000) &lt;=LJ (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M720VW (BND-1015W000) &lt;=LJ (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M750VS (BND-1012W002) &lt;=LJ (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M730VS (BND-1012W000) &lt;=LJ (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M720VS (BND-1012W000) &lt;=LJ (CVE-2025-2399)</li>\n<li>Mitsubishi Electric M70V (BND-1018W000) &lt;=LJ (CVE-2025-2399)</li>\n<li>Mitsubishi Electric E70 (BND-1022W000) &lt;=LJ (CVE-2025-2399)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 5.9</td>\n<td>Mitsubishi Electric</td>\n<td>Mitsubishi Electric CNC Series (Update A)</td>\n<td>Improper Validation of Specified Index, Position, or Offset in Input</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Japan</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-2399</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) vulnerability in the affected products allows a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products by sending specially crafted packets to TCP port 683.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-2399\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Mitsubishi Electric CNC Series (Update A)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Mitsubishi Electric</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Mitsubishi Electric M800VW (BND-2051W000): &lt;=BB, Mitsubishi Electric M800VS (BND-2052W000): &lt;=BB, Mitsubishi Electric M80V (BND-2053W000): &lt;=BB, Mitsubishi Electric M80VW (BND-2054W000): &lt;=BB, Mitsubishi Electric M800W (BND-2005W000): &lt;=FM, Mitsubishi Electric M800S (BND-2006W000): &lt;=FM, Mitsubishi Electric M80 (BND-2007W000): &lt;=FM, Mitsubishi Electric M80W (BND-2008W000): &lt;=FM, Mitsubishi Electric E80 (BND-2009W000): &lt;=FM, Mitsubishi Electric C80 (BND-2036W000): vers:all/*, Mitsubishi Electric M750VW (BND-1015W002): &lt;=LJ, Mitsubishi Electric M730VW (BND-1015W000): &lt;=LJ, Mitsubishi Electric M720VW (BND-1015W000): &lt;=LJ, Mitsubishi Electric M750VS (BND-1012W002): &lt;=LJ, Mitsubishi Electric M730VS (BND-1012W000): &lt;=LJ, Mitsubishi Electric M720VS (BND-1012W000): &lt;=LJ, Mitsubishi Electric M70V (BND-1018W000): &lt;=LJ, Mitsubishi Electric E70 (BND-1022W000): &lt;=LJ</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Please apply the fixed version (BC or later) for Mitsubishi Electric M800VW (BND-2051W000), M800VS (BND-2052W000), M80V (BND-2053W000), and M80VW (BND-2054W000). For instructions on how to apply it, please consult your Mitsubishi Electric representative.</p>\n<p><strong>Vendor fix</strong><br>Please apply the fixed version (FN or later) for Mitsubishi Electric M800W (BND-2005W000), M800S (BND-2006W000), M80 (BND-2007W000), M80W (BND-2008W000), and E80 (BND-2009W000). For instructions on how to apply it, please consult your Mitsubishi Electric representative.</p>\n<p><strong>Vendor fix</strong><br>Please apply the fixed version (LK or later) for Mitsubishi Electric M750VW (BND-1015W002), M730VW (BND-1015W000), M720VW (BND-1015W000), M750VS (BND-1012W002), M730VS (BND-1012W000), M720VS (BND-1012W000), M70V (BND-1018W000), and E70 (BND-1022W000). For instructions on how to apply it, please consult your Mitsubishi Electric representative.</p>\n<p><strong>Mitigation</strong><br>For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric recommends using a firewall or virtual private network (VPN) to prevent unauthorized access, when internet access is required, to minimize the risk of exploiting this vulnerability.</p>\n<p><strong>Mitigation</strong><br>For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric recommends using the product within a LAN and blocking access from untrusted networks and hosts through a firewall, to minimize the risk of exploiting this vulnerability.</p>\n<p><strong>Mitigation</strong><br>For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric recommends using IP filters to prevent unauthorized access, when internet access is required, to minimize the risk of exploiting this vulnerability. IP filter function is available for M800V/M80V Series and M800/M80/E80 Series. For details about the IP filter function, refer to the following manual for each product which can be downloaded from the link \"https://www.mitsubishielectric.com/fa/download/index.html \": M800V/M80V Series Instruction Manual \"16. Appendix 3 IP Address Filter Setting Function\", M800/M80/E80 Series Instruction Manual \"15. Appendix 2 IP Address Filter Setting Function\".<br><a href=\"https://www.mitsubishielectric.com/fa/download/index.html\">https://www.mitsubishielectric.com/fa/download/index.html</a></p>\n<p><strong>Mitigation</strong><br>For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric recommends restricting physical access to the affected product and to all computers and network devices to which the products are connected, to minimize the risk of exploiting this vulnerability.</p>\n<p><strong>Mitigation</strong><br>For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric recommends installing anti-virus software on PCs that can access the affected product, to minimize the risk of exploiting this vulnerability.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/1285.html\">CWE-1285 Improper Validation of Specified Index, Position, or Offset in Input</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Mitsubishi Electric reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Mitsubishi Electric 2025-022 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Mitsubishi Electric directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-03-10</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-03-10</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n<tr>\n<td>2026-03-19</td>\n<td>2</td>\n<td>CISA Republication - Initial CISA Republication of Mitsubishi Electric V20250121-001#02 advisory</td>\n</tr>\n<tr>\n<td>2026-08-27</td>\n<td>3</td>\n<td>Removed Software Tools NC Trainer2 and Software Tools NC Trainer2 plus, from affected products. And added M700V/M70V/E70 Series as fixed products.</td>\n</tr>\n<tr>\n<td>2026-08-27</td>\n<td>4</td>\n<td>CISA Republication update based on Mitsubishi Electric 2025-022 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 27 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 27 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-01",
        "title": "Xiiaozet LK100W",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to take control over the device.</strong></p>\n<p>The following versions of Xiiaozet LK100W are affected:</p>\n<ul>\n<li>LK100W &lt;2.1.240 (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.8</td>\n<td>Xiiaozet</td>\n<td>Xiiaozet LK100W</td>\n<td>Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Missing Authentication for Critical Function, Authentication Bypass Using an Alternate Path or Channel</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>China</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-78037</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-78037\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Xiiaozet LK100W</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Xiiaozet</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Xiiaozet LK100W: &lt;2.1.240</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Xiiaozet recommends users update to v2.1.240.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/78.html\">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-78239</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. Successful exploitation may permit unauthorized access to the device.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-78239\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Xiiaozet LK100W</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Xiiaozet</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Xiiaozet LK100W: &lt;2.1.240</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Xiiaozet recommends users update to v2.1.240.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-76943</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-76943\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Xiiaozet LK100W</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Xiiaozet</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Xiiaozet LK100W: &lt;2.1.240</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Xiiaozet recommends users update to v2.1.240.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/288.html\">CWE-288 Authentication Bypass Using an Alternate Path or Channel</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Byron Guernsey of Okachobi, LLC reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-27</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-27</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 27 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 27 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-05",
        "title": "Ebyte NA111-M",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-05",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-05.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to fully compromise the device.</strong></p>\n<p>The following versions of Ebyte NA111-M are affected:</p>\n<ul>\n<li>NA111-M Firmware 9013-2-17 (CVE-2026-73125, CVE-2026-76179, CVE-2026-75814, CVE-2026-76940, CVE-2026-77966, CVE-2026-73809, CVE-2026-71187, CVE-2026-75548, CVE-2026-69658, CVE-2026-76133, CVE-2026-73819, CVE-2026-77975, CVE-2026-77977)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.8</td>\n<td>Ebyte</td>\n<td>Ebyte NA111-M</td>\n<td>Missing Authentication for Critical Function, Use of GET Request Method With Sensitive Query Strings, Cross-Site Request Forgery (CSRF), Improper Restriction of Excessive Authentication Attempts, Missing Authorization, Cleartext Transmission of Sensitive Information, Use of Client-Side Authentication, Improper Restriction of Rendered UI Layers or Frames, Use of a Broken or Risky Cryptographic Algorithm, Weak Authentication, Cleartext Storage of Sensitive Information</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>China</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-73125</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-73125\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-76179</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during client-side session handling, which may allow an attacker with access to exposed session information to obtain and reuse a valid token. Successful exploitation could allow an attacker to impersonate an authenticated user and gain unauthorized access to device management functionality.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-76179\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/598.html\">CWE-598 Use of GET Request Method With Sensitive Query Strings</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-75814</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management interface. An unauthenticated remote attacker could persuade an authenticated administrator to visit a crafted page, causing unauthorized configuration changes or a disruption of device availability.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-75814\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/352.html\">CWE-352 Cross-Site Request Forgery (CSRF)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-76940</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected Ebyte device does not restrict repeated authentication attempts through rate limiting or account lockout mechanisms. This could allow an attacker to perform automated authentication attacks against deployments that rely on password based authentication.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-76940\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/307.html\">CWE-307 Improper Restriction of Excessive Authentication Attempts</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-77966</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product does not provide separation between limited and administrative management functions. A low privileged authenticated attacker could access security sensitive configuration functions and modify settings that affect the confidentiality, integrity, or availability of the device.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-77966\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/862.html\">CWE-862 Missing Authorization</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-73809</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web management interface does not adequately protect sensitive communications using transport-layer encryption. An attacker with access to network traffic could intercept authentication or session-related information transmitted between a user and the affected device. Successful exploitation could result in disclosure of sensitive information and unauthorized access to device management functionality.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-73809\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/319.html\">CWE-319 Cleartext Transmission of Sensitive Information</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-71187</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtain administrative access to the device.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-71187\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/603.html\">CWE-603 Use of Client-Side Authentication</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-75548</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected Ebyte device web management interface does not restrict the interface from being rendered within an external frame. An unauthenticated remote attacker could use a crafted webpage to mislead an authenticated administrator into initiating unintended configuration changes or disruptive actions.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-75548\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/1021.html\">CWE-1021 Improper Restriction of Rendered UI Layers or Frames</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.4</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.1</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-69658</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device impersonation and disruption of messaging functions.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-69658\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/319.html\">CWE-319 Cleartext Transmission of Sensitive Information</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-76133</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product uses a deprecated hashing algorithm in an authentication-related operation. Under conditions where an attacker can manipulate or predict the authentication exchange, the weak construction may reduce the assurance provided by the authentication mechanism and facilitate unauthorized access.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-76133\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/327.html\">CWE-327 Use of a Broken or Risky Cryptographic Algorithm</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-73819</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product's vendor configuration utility permits access to administrative functions without verifying the operator's identity under certain credential conditions. An unauthenticated attacker on the adjacent network could modify critical settings or change access credentials, potentially preventing legitimate administrators from managing the device.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-73819\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/1390.html\">CWE-1390 Weak Authentication</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-77975</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product exports administrative credentials and other sensitive configuration information without adequate protection. An unauthenticated attacker on the adjacent network who can obtain an exported configuration file could recover valid credentials and use them to access the device or similarly configured systems.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-77975\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/312.html\">CWE-312 Cleartext Storage of Sensitive Information</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-77977</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product's vendor configuration utility does not require authentication before allowing certain disruptive administrative actions when default credentials remain configured. An unauthenticated attacker on the adjacent network could reboot the device or restore factory settings, resulting in a loss of configuration and service availability.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-77977\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Ebyte NA111-M</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Ebyte</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ebyte NA111-M Firmware: 9013-2-17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Ebyte acknowledged receipt of the reported vulnerabilities and indicated that a patch was under development. However, the vendor has not responded to subsequent requests for coordination, and CISA has not been informed of the status or availability of the patch. Users are encouraged to reach out to Ebyte for more information.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Jithin Nambiar J reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-27</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-27</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 27 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 27 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-03",
        "title": "Rockwell Automation OTTO Fleet Manager",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-03",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-03.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes.</strong></p>\n<p>The following versions of Rockwell Automation OTTO Fleet Manager are affected:</p>\n<ul>\n<li>OTTO Fleet Manager &lt;=V2.36.2 (CVE-2026-75112)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 6.8</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation OTTO Fleet Manager</td>\n<td>Use of Password Hash With Insufficient Computational Effort</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-75112</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A security issue exists within OTTO Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. If an attacker gains access to an unencrypted system backup, the weakly hashed credentials could be more easily compromised.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-75112\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation OTTO Fleet Manager</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation OTTO Fleet Manager: &lt;=V2.36.2</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Rockwell Automation has addressed this vulnerability in software version 2.36.3.<br><a href=\"https://file-share.ottomotors.com/login\">https://file-share.ottomotors.com/login</a></p>\n<p><strong>Mitigation</strong><br>Users of the affected software who are not able to upgrade to the corrected version or apply the mitigations should use Rockwell Automation's security best practices.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Vendor fix</strong><br>See Rockwell Automation security advisory SD1791 for more information about this issue and instructions to enable encrypted system backup in OTTO Fleet Manager.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1791.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1791.html</a></p>\n<p><strong>Mitigation</strong><br>If you have any questions regarding the security issue(s) above and how to mitigate them, contact Rockwell Automation support.<br><a href=\"https://ottomotors.com/otto-care/\">https://ottomotors.com/otto-care/</a></p>\n<p><strong>Mitigation</strong><br>If you have any questions regarding this disclosure, please email Rockwell Automation PSIRT: rasecure@ra.rockwell.com<br><a href=\"mailto:rasecure@ra.rockwell.com\">mailto:rasecure@ra.rockwell.com</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/916.html\">CWE-916 Use of Password Hash With Insufficient Computational Effort</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N\">CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-27</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-27</td>\n<td>1</td>\n<td>Initial Republication of Rockwell Automation SD1791.</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 27 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 27 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-04",
        "title": "Applied Systems Engineering ASE2000 V2 Communications Test Set",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-04",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-04.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications.</strong></p>\n<p>The following versions of Applied Systems Engineering ASE2000 V2 Communications Test Set are affected:</p>\n<ul>\n<li>ASE2000 &gt;=2.25|&lt;=2.37 (CVE-2018-1285, CVE-2026-18717)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.8</td>\n<td>Applied Systems Engineering</td>\n<td>Applied Systems Engineering ASE2000 V2 Communications Test Set</td>\n<td>Improper Restriction of XML External Entity Reference, Improper Certificate Validation</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Critical Manufacturing, Energy, Water and Wastewater</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2018-1285</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>ASE2000 versions 2.25 through 2.37 is vulnerable to Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE based attacks in applications that accept attacker controlled log4net configuration files.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2018-1285\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Applied Systems Engineering ASE2000 V2 Communications Test Set</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Applied Systems Engineering</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Applied Systems Engineering ASE2000: &gt;=2.25|&lt;=2.37</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>ASE/Kalkitech provides an upgraded version 2.38 that fixes both vulnerabilities and customers are advised to upgrade to version 2.38. In version 2.38 the bundled log4net library is upgraded to version 3.3.1.0, and the IEC 60870-5-104 TLS client certificate validation logic is corrected to ensure proper validation of certificate error conditions.</p>\n<p><strong>Vendor fix</strong><br>All customers running ASE2000 versions 2.25 through 2.37 are affected by this issue and are required to upgrade to version 2.38 or later to apply the security fix. Upgrade instructions and user documentation are available at www.ase-systems.com. For detailed, step-by-step guidance on upgrading to the latest version and patching the impacted components, please contact our support team at support@ase-systems.com.<br><a href=\"http://www.ase-systems.com\">http://www.ase-systems.com</a></p>\n<p><strong>Vendor fix</strong><br>All customers running ASE2000 versions 2.25 through 2.37 are affected by this issue and are required to upgrade to version 2.38 or later to apply the security fix. Upgrade instructions and user documentation are available at www.ase-systems.com. For detailed, step-by-step guidance on upgrading to the latest version and patching the impacted components, please contact our support team at support@ase-systems.com.<br><a href=\"mailto:support@ase-systems.com\">mailto:support@ase-systems.com</a></p>\n<p><strong>Mitigation</strong><br>Until the upgrade can be applied, the following interim measures reduce exposure:</p>\n<p><strong>Vendor fix</strong><br>Restrict write access to the ASE2000 installation directory and its configuration files to trusted administrators only.</p>\n<p><strong>Vendor fix</strong><br>Avoid using IEC 60870-5-104 over TLS across untrusted or shared networks; place ASE2000 hosts on an isolated, segmented network reachable only by intended peers.</p>\n<p><strong>Mitigation</strong><br>Ensure the host is protected by a network firewall.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/611.html\">CWE-611 Improper Restriction of XML External Entity Reference</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.2</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-18717</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability, which may allow an attacker to impersonate the trusted peer, complete the TLS handshake, and read or modify protected communications.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-18717\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Applied Systems Engineering ASE2000 V2 Communications Test Set</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Applied Systems Engineering</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Applied Systems Engineering ASE2000: &gt;=2.25|&lt;=2.37</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>ASE/Kalkitech provides an upgraded version 2.38 that fixes both vulnerabilities and customers are advised to upgrade to version 2.38. In version 2.38 the bundled log4net library is upgraded to version 3.3.1.0, and the IEC 60870-5-104 TLS client certificate validation logic is corrected to ensure proper validation of certificate error conditions.</p>\n<p><strong>Vendor fix</strong><br>All customers running ASE2000 versions 2.25 through 2.37 are affected by this issue and are required to upgrade to version 2.38 or later to apply the security fix. Upgrade instructions and user documentation are available at www.ase-systems.com. For detailed, step-by-step guidance on upgrading to the latest version and patching the impacted components, please contact our support team at support@ase-systems.com.<br><a href=\"http://www.ase-systems.com\">http://www.ase-systems.com</a></p>\n<p><strong>Vendor fix</strong><br>All customers running ASE2000 versions 2.25 through 2.37 are affected by this issue and are required to upgrade to version 2.38 or later to apply the security fix. Upgrade instructions and user documentation are available at www.ase-systems.com. For detailed, step-by-step guidance on upgrading to the latest version and patching the impacted components, please contact our support team at support@ase-systems.com.<br><a href=\"mailto:support@ase-systems.com\">mailto:support@ase-systems.com</a></p>\n<p><strong>Mitigation</strong><br>Until the upgrade can be applied, the following interim measures reduce exposure:</p>\n<p><strong>Vendor fix</strong><br>Restrict write access to the ASE2000 installation directory and its configuration files to trusted administrators only.</p>\n<p><strong>Vendor fix</strong><br>Avoid using IEC 60870-5-104 over TLS across untrusted or shared networks; place ASE2000 hosts on an isolated, segmented network reachable only by intended peers.</p>\n<p><strong>Mitigation</strong><br>Ensure the host is protected by a network firewall.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/295.html\">CWE-295 Improper Certificate Validation</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.4</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N\">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.1</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Enoch Wang reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-27</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-27</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 27 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 27 Aug 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-02",
        "title": "All-Line Equipment Company Fuel-Boss",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems.</strong></p>\n<p>The following versions of All-Line Equipment Company Fuel-Boss are affected:</p>\n<ul>\n<li>Fuel-Boss V1 Standard &gt;=|&lt;=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)</li>\n<li>Fuel-Boss V1 Portal &gt;=|&lt;=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)</li>\n<li>Fuel-Boss V1 Master/Slave &gt;=|&lt;=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)</li>\n<li>Fuel-Boss V1 Backflush Systems &gt;=|&lt;=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.7</td>\n<td>All-Line Equipment Company</td>\n<td>All-Line Equipment Company Fuel-Boss</td>\n<td>Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'), Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Defense Industrial Base, Emergency Services, Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2018-19518</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Fuel-Boss is vulnerable to the University of Washington IMAP Toolkit 2007f on UNIX, used in imap_open() in PHP and other products, launching an rsh command via the imap_rimap and tcp_aopen functions without preventing argument injection, which can allow remote attackers to execute arbitrary OS commands when an untrusted IMAP server name is supplied and rsh has been replaced by a program with different argument semantics such as ssh. This enables attacks through IMAP server names containing a \"-oProxyCommand\" argument, as well as a stack-based buffer overflow that may allow an attacker to remotely execute arbitrary code.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2018-19518\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>All-Line Equipment Company Fuel-Boss</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>All-Line Equipment Company</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>All-Line Equipment Company Fuel-Boss V1 Standard: &gt;=|&lt;=PHP_7.1.5_7.1.5, All-Line Equipment Company Fuel-Boss V1 Portal: &gt;=|&lt;=PHP_7.1.5_7.1.5, All-Line Equipment Company Fuel-Boss V1 Master/Slave: &gt;=|&lt;=PHP_7.1.5_7.1.5, All-Line Equipment Company Fuel-Boss V1 Backflush Systems: &gt;=|&lt;=PHP_7.1.5_7.1.5</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Fixes are available for the Fuel-Boss V1 Standard and Fuel-Boss V1 Portal. Please contact All-Line Equipment Company (866-356-3336) for instructions on how to receive these fixes.</p>\n<p><strong>Vendor fix</strong><br>Fixes are not yet available for the Fuel-Boss V1 Master/Slave.</p>\n<p><strong>Vendor fix</strong><br>No fix is planned for Fuel-Boss V1 Backflush Systems.</p>\n<p><strong>Mitigation</strong><br>All-Line Equipment Company recommends either taking products that are not fixed off the Internet or restricting the IP addresses that can access them at the router level.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/88.html\">CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2019-11043</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Fuel-Boss running versions up to and including PHP 7.1.5 is vulnerable because certain FPM configurations allow the FPM module to write past allocated buffers into space reserved for FCGI protocol data, thereby creating a possible remote code execution condition.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2019-11043\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>All-Line Equipment Company Fuel-Boss</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>All-Line Equipment Company</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>All-Line Equipment Company Fuel-Boss V1 Standard: &gt;=|&lt;=PHP_7.1.5_7.1.5, All-Line Equipment Company Fuel-Boss V1 Portal: &gt;=|&lt;=PHP_7.1.5_7.1.5, All-Line Equipment Company Fuel-Boss V1 Master/Slave: &gt;=|&lt;=PHP_7.1.5_7.1.5, All-Line Equipment Company Fuel-Boss V1 Backflush Systems: &gt;=|&lt;=PHP_7.1.5_7.1.5</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Fixes are available for the Fuel-Boss V1 Standard and Fuel-Boss V1 Portal. Please contact All-Line Equipment Company (866-356-3336) for instructions on how to receive these fixes.</p>\n<p><strong>Vendor fix</strong><br>Fixes are not yet available for the Fuel-Boss V1 Master/Slave.</p>\n<p><strong>Vendor fix</strong><br>No fix is planned for Fuel-Boss V1 Backflush Systems.</p>\n<p><strong>Mitigation</strong><br>All-Line Equipment Company recommends either taking products that are not fixed off the Internet or restricting the IP addresses that can access them at the router level.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/120.html\">CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N\">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.4</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N\">CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>These vulnerabilities were anonymously reported to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>These vulnerabilities have a high attack complexity.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-27</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-27</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 27 Aug 26 12:00:00 +0000",
        "last_updated": "Thu, 27 Aug 26 12:00:00 +0000"
    }
]