[
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway",
        "title": "Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway",
        "summary": "<p>CISA is amplifying Citrix\u2019s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: <a href=\"https://www.cve.org/CVERecord?id=CVE-2026-88771\">CVE-2026-88771</a>, <a href=\"https://www.cve.org/CVERecord?id=CVE-2026-88772\">CVE-2026-88772</a>, <a href=\"https://www.cve.org/CVERecord?id=CVE-2026-88773\">CVE-2026-88773</a>, <a href=\"https://www.cve.org/CVERecord?id=CVE-2026-88774\">CVE-2026-88774</a>, <a href=\"https://www.cve.org/CVERecord?id=CVE-2026-88775\">CVE-2026-88775</a>, <a href=\"https://www.cve.org/CVERecord?id=CVE-2026-88776\">CVE-2026-88776</a>, <a href=\"https://www.cve.org/CVERecord?id=CVE-2026-88777\">CVE-2026-88777</a>, and <a href=\"https://www.cve.org/CVERecord?id=CVE-2026-88778\">CVE-2026-88778</a>.&nbsp;</p>\n<p>CISA has added CVE-2026-88771 and CVE-2026-88772 to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.</p>\n<p>Because updating Citrix NetScaler appliances can be complex and may require downtime, CISA is issuing this Alert to help organizations assess exposure, prioritize mitigation, and account for these vulnerabilities into their risk-management activities.&nbsp;</p>\n<p>Given the potential consequences of successful exploitation and the fact that malicious actors are exploiting at least some of these vulnerabilities, CISA urges users and administrators to review Citrix\u2019s advisories. If possible, users are encouraged to check for indication of compromise prior to patching. Citrix has made indicators of compromise available through NetScaler Console and published additional guidance in their recent publication, <em>Security Bulletin for CVE-2026-88771 through CVE-2026-88778</em>, to support organizations in assessing potential compromise. Should your organization suspect compromise, it is important to preserve forensic evidence prior to applying updates, as updates may result in loss of forensic visibility.&nbsp;</p>\n<ul type=\"square\">\n<li><a href=\"https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/?utm_id=cid2026-0806&amp;utm_source=facebook&amp;utm_medium=social%20media%20organic&amp;utm_campaign=citrix%20organic&amp;utm_content=1790523126\">Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 - Security Updates - Citrix Community</a></li>\n<li><a href=\"https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096\">Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778</a></li>\n<li><a href=\"https://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html\">Steps to Take if NetScaler ADC is Suspected to be Compromised</a></li>\n</ul>\n<h2><strong>Disclaimer</strong></h2>\n<p>The information in this report is being provided \u201cas is\u201d for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA.</p>",
        "summary_is_html": true,
        "first_seen": "Sun, 27 Sep 26 12:00:00 +0000",
        "last_updated": "Sun, 27 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Two Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "summary": "<p class=\"text-align-justify\">CISA has added two new vulnerabilities to its&nbsp;<a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>\n<ul type=\"disc\">\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-88771\" target=\"_blank\" title=\"https://www.cve.org/cverecord?id=cve-2026-88771\">CVE-2026-88771</a> Citrix NetScaler Improper Input Validation Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-88772\" target=\"_blank\" title=\"https://www.cve.org/cverecord?id=cve-2026-88772\">CVE-2026-88772</a> Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability</li>\n</ul>\n<p>These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.<br><br><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.<br><br>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of&nbsp;<a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the&nbsp;<a href=\"https://www.cisa.gov/known-exploited-vulnerabilities\">specified criteria</a>.<br><br>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s&nbsp;<a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.</p>",
        "summary_is_html": true,
        "first_seen": "Sun, 27 Sep 26 12:00:00 +0000",
        "last_updated": "Sun, 27 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Two Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added two new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-65660\" target=\"_blank\">CVE-2026-65660</a> Microsoft SharePoint Code Injection Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-67279\" target=\"_blank\">CVE-2026-67279</a> Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability</li>\n</ul>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.&nbsp;</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&nbsp;</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.&nbsp;</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.</p>",
        "summary_is_html": true,
        "first_seen": "Fri, 25 Sep 26 12:00:00 +0000",
        "last_updated": "Fri, 25 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-87902 \" target=\"_blank\">CVE-2026-87902</a> WordPress Core Remote File Inclusion Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.&nbsp;</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&nbsp;</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities\">specified criteria</a>.&nbsp;</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Fri, 25 Sep 26 12:00:00 +0000",
        "last_updated": "Fri, 25 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-02",
        "title": "Eufy Omni C20, Omni X10 Pro",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to run system level commands or execute arbitrary code.</strong></p>\n<p>The following versions of Eufy Omni C20, Omni X10 Pro are affected:</p>\n<ul>\n<li>Omni C20 &lt;1.6.4 (CVE-2026-93289, CVE-2026-93290, CVE-2026-93291)</li>\n<li>Omni X10 Pro &lt;1.6.4 (CVE-2026-93289)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.4</td>\n<td>Eufy</td>\n<td>Eufy Omni C20, Omni X10 Pro</td>\n<td>Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Use of Hard-coded Credentials, Improper Certificate Validation</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>China</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-93289</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-93289\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Eufy Omni C20, Omni X10 Pro</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Eufy</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Eufy Omni C20: &lt;1.6.4, Eufy Omni X10 Pro: &lt;1.6.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Eufy recommends users to upgrade to version 1.6.4 or later.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/78.html\">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H\">CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-93290</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access information like mapping data.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-93290\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Eufy Omni C20, Omni X10 Pro</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Eufy</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Eufy Omni C20: &lt;1.6.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Eufy recommends users to upgrade to version 1.6.4 or later.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/798.html\">CWE-798 Use of Hard-coded Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-93291</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-93291\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Eufy Omni C20, Omni X10 Pro</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Eufy</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Eufy Omni C20: &lt;1.6.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Eufy recommends users to upgrade to version 1.6.4 or later.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/295.html\">CWE-295 Improper Certificate Validation</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.4</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Jared of Somerset Recon reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (<a href=\"https://www.cisa.gov/privacy-policy\">https://www.cisa.gov/privacy-policy</a>).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<ul>\n<li>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</li>\n<li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li>\n<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li>\n</ul>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-24</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-24</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 24 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 24 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01",
        "title": "Botslab G980H Dashcams",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication controls, gain unauthorized access to sensitive data and privileged device functionality, modify device configuration, disrupt device operation.</strong></p>\n<p>The following versions of Botslab G980H Dashcams are affected:</p>\n<ul>\n<li>G980H dash cam series 30010_QHG980HN5294SysFW+ (CVE-2026-84399, CVE-2026-82566, CVE-2026-85496, CVE-2026-77967, CVE-2026-88761, CVE-2026-82716, CVE-2026-84403, CVE-2026-75558, CVE-2026-81630, CVE-2026-87118, CVE-2026-82708, CVE-2026-79959, CVE-2026-82585)</li>\n<li>G980H dash cam series 58_QHG980HMCN5291SysFW+ (CVE-2026-84399, CVE-2026-82566, CVE-2026-85496, CVE-2026-77967, CVE-2026-88761, CVE-2026-88956, CVE-2026-82716, CVE-2026-84403, CVE-2026-75558, CVE-2026-81630, CVE-2026-87118, CVE-2026-82708, CVE-2026-82585)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.8</td>\n<td>Botslab</td>\n<td>Botslab G980H Dashcams</td>\n<td>Incorrect Authorization, Insufficient Session Expiration, Generation of Predictable Numbers or Identifiers, Authentication Bypass by Capture-replay, Use of Weak Credentials, Missing Authentication for Critical Function, Insertion of Sensitive Information into Log File, Use of Hard-coded Cryptographic Key, Insufficient Verification of Data Authenticity, Out-of-bounds Write, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Use of Hard-coded Credentials, Cleartext Transmission of Sensitive Information</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>China</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-84399</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established it, and subsequent privileged operations rely on possession of a valid session identifier without adequately validating the requesting client's authenticated context. An unauthenticated attacker with adjacent network access could potentially use valid session state associated with another client to access privileged functionality.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-84399\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Botslab G980H Dashcams</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Botslab</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:&nbsp;<br><a href=\"https://www.botslab.com/pages/about-botslab\">https://www.botslab.com/pages/about-botslab</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/863.html\">CWE-863 Incorrect Authorization</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-82566</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions, a newly established connection can displace an existing client while previously established session state remains active until a separate expiration mechanism invalidates it. An unauthenticated attacker with adjacent network access could potentially take advantage of this residual authentication state to access functionality associated with another client's session.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-82566\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Botslab G980H Dashcams</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Botslab</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:&nbsp;<br><a href=\"https://www.botslab.com/pages/about-botslab\">https://www.botslab.com/pages/about-botslab</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/613.html\">CWE-613 Insufficient Session Expiration</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-85496</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active session exists could potentially determine a valid session identifier and use it to bypass intended authorization controls.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-85496\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Botslab G980H Dashcams</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Botslab</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:&nbsp;<br><a href=\"https://www.botslab.com/pages/about-botslab\">https://www.botslab.com/pages/about-botslab</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/340.html\">CWE-340 Generation of Predictable Numbers or Identifiers</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-77967</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unauthenticated attacker with adjacent network access who captures a valid authentication value could replay it from another client to establish an authenticated session and access privileged device functionality.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-77967\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Botslab G980H Dashcams</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Botslab</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:&nbsp;<br><a href=\"https://www.botslab.com/pages/about-botslab\">https://www.botslab.com/pages/about-botslab</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/294.html\">CWE-294 Authentication Bypass by Capture-replay</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-88761</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product. An unauthenticated attacker within WiFi range could potentially determine the remaining password characters through limited guessing and gain unauthorized access to the device network.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-88761\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Botslab G980H Dashcams</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Botslab</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:&nbsp;<br><a href=\"https://www.botslab.com/pages/about-botslab\">https://www.botslab.com/pages/about-botslab</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/1391.html\">CWE-1391 Use of Weak Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-88956</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface. The affected account does not require a password before granting access to a privileged system interface, and the interface also displays the device's WiFi password during startup. An unauthenticated attacker with physical access to the device could connect to the UART interface, obtain root privileges, and recover the WiFi password.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-88956\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Botslab G980H Dashcams</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Botslab</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:&nbsp;<br><a href=\"https://www.botslab.com/pages/about-botslab\">https://www.botslab.com/pages/about-botslab</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-82716</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process. These logs remain accessible on removable storage after the support operation has completed. An unauthenticated attacker with physical access to the storage media could retrieve the logs and obtain sensitive device information.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-82716\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Botslab G980H Dashcams</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Botslab</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:&nbsp;<br><a href=\"https://www.botslab.com/pages/about-botslab\">https://www.botslab.com/pages/about-botslab</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/532.html\">CWE-532 Insertion of Sensitive Information into Log File</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>4.6</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.1</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-84403</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. An unauthenticated attacker within Bluetooth range could intercept or directly retrieve sensitive device information, including device identifiers, firmware information, and protected WiFi credentials.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-84403\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Botslab G980H Dashcams</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Botslab</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:&nbsp;<br><a href=\"https://www.botslab.com/pages/about-botslab\">https://www.botslab.com/pages/about-botslab</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.2</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-75558</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who obtains the protected credential and extracts the cryptographic material from the firmware could recover the WiFi password and gain unauthorized access to the device network.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-75558\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Botslab G980H Dashcams</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Botslab</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:&nbsp;<br><a href=\"https://www.botslab.com/pages/about-botslab\">https://www.botslab.com/pages/about-botslab</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/321.html\">CWE-321 Use of Hard-coded Cryptographic Key</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-81630</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of a trusted cryptographic signature. A suitably positioned attacker who intercepts a firmware download, or an authenticated attacker who submits a crafted update, could install modified firmware and execute unauthorized code on the device.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-81630\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Botslab G980H Dashcams</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Botslab</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:&nbsp;<br><a href=\"https://www.botslab.com/pages/about-botslab\">https://www.botslab.com/pages/about-botslab</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/345.html\">CWE-345 Insufficient Verification of Data Authenticity</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.2</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-87118</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality. An authenticated attacker with adjacent network access could submit crafted command data that corrupts memory, potentially disrupting authentication state or causing the affected process to terminate and the device to restart, resulting in a temporary denial of service.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-87118\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Botslab G980H Dashcams</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Botslab</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:&nbsp;<br><a href=\"https://www.botslab.com/pages/about-botslab\">https://www.botslab.com/pages/about-botslab</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.7</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-82708</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a crafted request to access files within the device's removable storage that were not intended to be directly accessible through the web server. Exposed files could include recordings, images, diagnostic logs, or firmware files.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-82708\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Botslab G980H Dashcams</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Botslab</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:&nbsp;<br><a href=\"https://www.botslab.com/pages/about-botslab\">https://www.botslab.com/pages/about-botslab</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/22.html\">CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-79959</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical access to the device could recover the credential and use it to obtain root access through the UART interface.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-79959\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Botslab G980H Dashcams</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Botslab</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:&nbsp;<br><a href=\"https://www.botslab.com/pages/about-botslab\">https://www.botslab.com/pages/about-botslab</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/798.html\">CWE-798 Use of Hard-coded Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-82585</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network could obtain stored recordings, live video, location information, images, diagnostic logs, or other sensitive information exchanged between the device and its mobile application.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-82585\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Botslab G980H Dashcams</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Botslab</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:&nbsp;<br><a href=\"https://www.botslab.com/pages/about-botslab\">https://www.botslab.com/pages/about-botslab</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/319.html\">CWE-319 Cleartext Transmission of Sensitive Information</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Julian of Software Secured reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (<a href=\"https://www.cisa.gov/privacy-policy\">https://www.cisa.gov/privacy-policy</a>).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<ul>\n<li>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</li>\n<li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li>\n<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li>\n</ul>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<ul>\n<li>Do not click web links or open attachments in unsolicited email messages.</li>\n<li>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</li>\n<li>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</li>\n</ul>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-24</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-24</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 24 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 24 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/09/24/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Two Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/09/24/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "summary": "<p>&nbsp;CISA has added two new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-5430\" target=\"_blank\">CVE-2026-5430</a> WSO2 Multiple Products Path Traversal Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-71362\" target=\"_blank\">CVE-2026-71362</a> Adobe Commerce and Magento Incorrect Authorization Vulnerability</li>\n</ul>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.&nbsp;</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&nbsp;</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.&nbsp;</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Thu, 24 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 24 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-02",
        "title": "Siemens Mendix Runtime (Update A)",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>This advisory is revoked. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute.</strong></p>\n<p>The following versions of Siemens Mendix Runtime are affected:</p>\n<ul>\n<li>Siemens Mendix Runtime vers:all/* (CVE-2026-7891)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.1</td>\n<td>Siemens</td>\n<td>Siemens Mendix Runtime&nbsp;</td>\n<td>Insecure Inherited Permissions</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-7891</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>This CVE has been retracted. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected application-specific attribute.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-7891\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Mendix Runtime (Update A)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Siemens Siemens Mendix Runtime: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>not_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Vulnerability is rejected as re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected application-specific attribute (Vulnerable Code Not Present).</p>\n<p><strong>Mitigation</strong><br>As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for industrial security and following recommendations in the product manuals.<br><a href=\"https://www.siemens.com/cert/operational-guidelines-industrial-security\">https://www.siemens.com/cert/operational-guidelines-industrial-security</a></p>\n<p><strong>Mitigation</strong><br>Additional information on industrial security by Siemens can be found on the Siemens industrial security webpage<br><a href=\"https://www.siemens.com/industrialsecurity\">https://www.siemens.com/industrialsecurity</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated Siemens security advisory SSA-814963 in HTML.<br><a href=\"https://cert-portal.siemens.com/productcert/html/ssa-814963.html\">https://cert-portal.siemens.com/productcert/html/ssa-814963.html</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated Siemens security advisory SSA-814963 in CSAF.<br><a href=\"https://cert-portal.siemens.com/productcert/csaf/ssa-814963.json\">https://cert-portal.siemens.com/productcert/csaf/ssa-814963.json</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/277.html\">CWE-277 Insecure Inherited Permissions</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.1</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.1</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (<a href=\"https://www.cisa.gov/privacy-policy\">https://www.cisa.gov/privacy-policy</a>).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<ul>\n<li>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</li>\n<li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li>\n<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices.</li>\n</ul>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<ul>\n<li>Do not click web links or open attachments in unsolicited email messages.</li>\n<li>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</li>\n<li>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</li>\n</ul>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-14</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-14</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n<tr>\n<td>2026-07-28</td>\n<td>2</td>\n<td>Initial Republication of Siemens ProductCERT SSA-814963</td>\n</tr>\n<tr>\n<td>2026-09-22</td>\n<td>3</td>\n<td>Revoked advisory as the CVE is rejected</td>\n</tr>\n<tr>\n<td>2026-09-24</td>\n<td>4</td>\n<td>Update A - Revoking advisory after Siemens revoked SSA-814963 and rejecting CVE-2026-7891</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 24 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 24 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/resources-tools/resources/considerations-critical-infrastructure-operators-working-third-party-ics-integrators",
        "title": "Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/resources-tools/resources/considerations-critical-infrastructure-operators-working-third-party-ics-integrators",
        "summary": "<h2><strong>Introduction</strong></h2>\n<p>The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA)\u2014hereafter referred to as the \u201cauthoring agencies\u201d\u2014have published this fact sheet to highlight considerations for critical infrastructure entities to reduce risk and minimize vulnerabilities when working with third-party industrial control system (ICS) integrators.</p>\n<p>ICS is an umbrella term referring to integrated networks of hardware and software designed to monitor and automate physical processes, encompassing specialized control systems and devices, such as supervisory control and data acquisition (SCADA) systems and programmable logic controllers. Third-party integrators provide varying types of services for ICS, such as control system design, installation, operational data analysis, device support and service, and daily operational control.</p>\n<p>Critical infrastructure owners and operators should maintain caution when granting third-party ICS integrators high levels of access or control over industrial processes, ensuring the&nbsp;principle of least privilege (PoLP), is applied. PoLP<strong>&nbsp;</strong>within OT environments lends itself to granting users, processes, and systems&nbsp;only the minimum access necessary&nbsp;to perform their assigned tasks, and no more. PoLP is designed to protect owners and operators. Not adopting principles such as PoLP could expose owners and operators to malicious cyber actors seeking to compromise critical infrastructure, possibly providing sensitive access to pathways that actors can exploit to cause disruptive and destructive effects to equipment and critical functions.&nbsp;</p>\n<p>Critical infrastructure owners and operators should action the recommendations in this fact sheet to work with integrators to ensure secure practices and frameworks are put in place to reduce the risk of malicious actors exploiting third-party accesses to compromise critical infrastructure operational environments.</p>\n<h2><strong>Examples of Risk and Exploitation</strong></h2>\n<p>Much like IT systems, using third-party ICS integrators in critical infrastructure may inadvertently introduce security issues to a customer environment by exposing systems and services not pre-configured to the customer\u2019s security requirements. Critical infrastructure owners and operators that rely on third-party integrators for system design face supply chain risks if integrators and owners and operators do not collectively enforce clear requirements for the secure procurement and handling of system components. Furthermore, third-party integrators that operate and host data outside of the United States may pose additional risks, as they may be subject to different data storage and management laws that do not meet the security needs of U.S. critical infrastructure entities.</p>\n<p>According to FBI technical analysis, between March and April 2025, malicious foreign cyber actors gained access to the network of a U.S. industrial automation solutions company that offered services\u2014such as system integration, engineering consulting, and SCADA programming\u2014for industrial customers, including power utilities and transportation entities. While on the network, threat actors searched terms, including \u201ccustomers\u201d and \u201cSCADA,\u201d and created nine <code>.zip</code> files consisting of approximately 800 files for presumed exfiltration, including customer SCADA information, ICS device details, and other schematics. Malicious cyber actors could leverage the exfiltrated information to later conduct disruptive attacks against operational environments and disrupt critical services.</p>\n<h2><strong>Recommendations to Assess Risk</strong></h2>\n<p>Critical infrastructure owners and operators should make risk-informed decisions when considering introducing third-party integrators into their networks and operations, guided by a robust understanding of the organizational risks posed by providing sensitive access to their systems.</p>\n<p>Organizations should routinely conduct risk assessments to evaluate contracts that involve access to industrial systems, to determine impacts to the organization\u2019s data autonomy and process controls. Risk assessments should address hardware and software supply chain vulnerabilities introduced by integrator equipment, as well as the IT and OT security of these devices and their associated networks. When considering implementing foreign-owned integrators, critical infrastructure owners and operators should also include geopolitical considerations in their risk assessments, such as how the critical infrastructure entity may be directly or indirectly targeted based on the geopolitical climate.</p>\n<p>Critical infrastructure owners and operators should consider the following questions in their risk assessments to safeguard the security of their operational systems when working with third-party ICS integrators:</p>\n<h3><strong>What organizational data does the integrator store or have access to?</strong></h3>\n<p>Critical infrastructure network designs, device specifications, logs, and other data can all be useful information for malicious cyber actors. When evaluating the risk of enabling integrators to store or access this data, consider the potential for a malicious cyber actor to access this data through the integrator\u2019s network.</p>\n<h3><strong>Where is the data stored?</strong></h3>\n<p>If the integrator is foreign-owned, consider whether the utility data is stored within the United States or internationally. If data is stored internationally, the laws of that respective country may govern it and may apply even if the integrator is a U.S. subsidiary.</p>\n<h3><strong>Does the integrator have remote access for operational support?</strong></h3>\n<p>If the integrator has remote access to the organization\u2019s ICS network, then there is a potential risk that a malicious cyber actor could gain access to the integrator\u2019s network and pivot into the utility\u2019s network to gain control of their systems. Consider the security of the organization\u2019s remote connections when evaluating the risk these potential access points pose to the organization\u2019s network.&nbsp;</p>\n<h3><strong>Can the organization operate independently if the integrator is compromised?</strong></h3>\n<p>Having redundancies in place and the ability to recover the system and operate without the integrator, especially for operationally critical processes, can reduce risk in the event of integrator compromise. Operators should maintain secure, offline backups of all software required to operate equipment to facilitate system recovery.&nbsp;</p>\n<h2><strong>Recommendations to Reduce Risk</strong></h2>\n<p>The authoring agencies recommend critical infrastructure owners and operators implement the following steps to reduce the risks associated with using third-party ICS integrators:</p>\n<ul type=\"square\">\n<li><strong>Include cybersecurity and supply chain cybersecurity in contracts and service agreements.&nbsp;</strong>When preparing service agreements, include requirements on areas such as:<br>\n<ul type=\"circle\">\n<li>Data storage locations, information protection agreements, and protection of ICS data and design documentation,</li>\n<li>Remote access capabilities,</li>\n<li>Basics of the integrator\u2019s cybersecurity program,</li>\n<li>Change management and patch management policies,</li>\n<li>Actions taken to secure deployed components (e.g., changing default passwords, disabling unused ports),</li>\n<li>Listing authorized personnel with access to systems, and</li>\n<li>Processes that enable local engineering support when necessary, limiting required integrator intervention.</li>\n</ul>\n</li>\n<li><strong>Evaluate devices with external internet exposure.</strong> Organizations should work with integrators to understand where devices are hosted and minimize exposure by disconnecting devices from the public-facing internet.</li>\n<li><strong>Monitor and log remote access. </strong>Ensure integrators access equipment using routes you are able to monitor. Use on-demand remote access if possible, so operators have to proactively allow remote access.</li>\n<li><strong>Request an inventory of all software and hardware supplied by the integrator</strong>, as well as documentation for how it connects to your infrastructure and how it will be updated.</li>\n<li><strong>Practice procedures and maintain capabilities for manual operations</strong>, keeping in mind, and accounting for, where third parties fit into the environment and recovery procedures.</li>\n</ul>\n<h2><strong>Resources</strong></h2>\n<ul type=\"square\">\n<li>For guidance on asset inventories, see CISA\u2019s <a href=\"https://www.cisa.gov/resources-tools/resources/foundations-ot-cybersecurity-asset-inventory-guidance-owners-and-operators\" title=\"Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators\">Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators</a>.</li>\n<li>For additional information on SBOMs, see CISA\u2019s <a href=\"https://www.cisa.gov/resources-tools/resources/2026-minimum-elements-software-bill-materials-sbom\" title=\"2026 Minimum Elements for a Software Bill of Materials (SBOM)\">2026 Minimum Elements for a Software Bill of Materials (SBOM)</a>.</li>\n<li>For guidance on supply chain risk management, see the Communications Sector Coordinating Council (CSCC) and IT Sector Coordinating Council\u2019s (SCC)&nbsp;<a href=\"https://www.comms-scc.org/wp-content/uploads/2025/07/ICTSCRMTaskForce_SupplierProductsandServicesThreatEvaluationReport_July2025.pdf\" title=\"Supplier, Products, and Services Threat Evaluation (to include Impact Analysis and Mitigation)\" target=\"_blank\">Supplier, Products, and Services Threat Evaluation (to include Artificial Intelligence Risks and Mitigations)</a>, and NIST\u2019s&nbsp;<a href=\"https://csrc.nist.gov/Projects/cyber-supply-chain-risk-management\" title=\"Cybersecurity Supply Chain Risk Management\" target=\"_blank\">Cybersecurity Supply Chain Risk Management</a>.</li>\n<li>For additional information and resources concerning cyber threats to ICS, visit <a href=\"https://www.cisa.gov/ics\" title=\"Industrial Control Systems\">Industrial Control Systems</a> for Cybersecurity Advisories and other cybersecurity guidance and best practices.</li>\n</ul>\n<h2><strong>Contact Information</strong></h2>\n<p>The authoring agencies strongly urge critical infrastructure operators to report suspicious cyber activity to the following entities:</p>\n<ul type=\"square\">\n<li>Report cyber activity to <a href=\"https://www.fbi.gov/contact-us/field-offices\" title=\"your local FBI field office\" target=\"_blank\">your local FBI field office</a> or <a href=\"http://www.ic3.gov/\" title=\"IC3\" target=\"_blank\">IC3</a>, or contact CISA via CISA\u2019s 24/7 Operations Center at <a href=\"mailto:contact@cisa.dhs.gov\" title=\"contact@cisa.dhs.gov\">contact@cisa.dhs.gov</a> or 1-844-Say-CISA (1-844-729-2472).</li>\n<li>Report any leads, threats, and suspected criminal activity by submitting an <a href=\"https://tips.fbi.gov/\" title=\"electronic tip\" target=\"_blank\">electronic tip</a>, calling 1-800-CALL-FBI (1-800-225-5324), or contacting <a href=\"https://www.fbi.gov/contact-us/field-offices\" title=\"your local FBI field office\" target=\"_blank\">your local FBI field office</a>.<br><strong>Note:</strong> This website cannot be used to report emergencies or immediate threat to life. For emergencies or immediate threat to life, please call 911.</li>\n<li>If you are a law enforcement entity, use the unclassified information-sharing system eGuardian (accessible via the <a href=\"https://www.cjis.gov/\" title=\"Law Enforcement Enterprise Portal\" target=\"_blank\">Law Enforcement Enterprise Portal</a>) for reporting suspicious activity reports to the FBI. <strong>Note: </strong>If the information is urgent, then contact <a href=\"https://www.fbi.gov/contact-us/field-offices\" title=\"your local FBI field office\" target=\"_blank\">your local FBI&nbsp;field office</a> directly and follow up with an eGuardian report.</li>\n</ul>\n<h2><strong>Disclaimer</strong></h2>\n<p>CISA and the authoring agencies do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA and the authoring agencies.</p>\n<h2><strong>Version History</strong></h2>\n<p><strong>September 23, 2026</strong>: Initial version.</p>",
        "summary_is_html": true,
        "first_seen": "Wed, 23 Sep 26 12:00:00 +0000",
        "last_updated": "Wed, 23 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-08",
        "title": "Siemens WTV676 and WTV776",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-08",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-08.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices. Siemens has released new versions for the affected products and recommends to update to the latest versions.</strong></p>\n<p>The following versions of Siemens WTV676 and WTV776 are affected:</p>\n<ul>\n<li>WTV676-HB6035 Web Interface vers:intdot/&lt;3.94 (CVE-2026-89207)</li>\n<li>WTV776-HB6035 Web Interface vers:intdot/&lt;4.17 (CVE-2026-89207)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 6.5</td>\n<td>Siemens</td>\n<td>Siemens WTV676 and WTV776</td>\n<td>Improper Validation of Specified Type of Input</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-89207</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Affected devices do not properly validate input received from backend services. This could allow an unauthenticated remote attacker to force the device into protection mode, which results in losing remote connectivity functions (Web Access).</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-89207\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens WTV676 and WTV776</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>WTV676-HB6035 Web Interface &lt; V3.94, WTV776-HB6035 Web Interface &lt; V4.17</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V3.94 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109480838/\">https://support.industry.siemens.com/cs/ww/en/view/109480838/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V4.17 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109480838/\">https://support.industry.siemens.com/cs/ww/en/view/109480838/</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated Siemens security advisory SSA-823812 in <a href=\"https://cert-portal.siemens.com/productcert/html/ssa-823812.html\">HTML</a> and <a href=\"https://cert-portal.siemens.com/productcert/csaf/ssa-823812.json\">CSAF</a>.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/1287.html\">CWE-1287 Improper Validation of Specified Type of Input</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure Siemens strongly recommends protecting network access to affected products with appropriate mechanisms. It is advised to follow recommended security practices in order to run the devices in a protected IT environment.</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: <a href=\"https://www.siemens.com/cert/advisories\">https://www.siemens.com/cert/advisories</a>&nbsp;</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: <a href=\"https://www.siemens.com/productcert/terms-of-use\">https://www.siemens.com/productcert/terms-of-use</a>.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (<a href=\"https://www.cisa.gov/privacy-policy\">https://www.cisa.gov/privacy-policy</a>).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<ul>\n<li>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</li>\n<li>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</li>\n<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</li>\n</ul>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT <a href=\"https://cert-portal.siemens.com/productcert/html/ssa-823812.html\">SSA-823812</a> from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-16</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-16</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-09-22</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-823812 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 22 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 22 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-01",
        "title": "lwIP TCP/IP Stack MQTT Client Application",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to gain full code execution on the device.</strong></p>\n<p>The following versions of lwIP TCP/IP Stack MQTT Client Application are affected:</p>\n<ul>\n<li>MQTT Client Application &gt;=2.0.1|&lt;=2.2.1 (CVE-2026-87121)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.8</td>\n<td>lwIP</td>\n<td>lwIP TCP/IP Stack MQTT Client Application</td>\n<td>Out-of-bounds Write</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Communications, Critical Manufacturing, Energy, Financial Services, Healthcare and Public Health, Transportation Systems, Water and Wastewater Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Sweden</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-87121</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-87121\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>lwIP TCP/IP Stack MQTT Client Application</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>lwIP</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>lwIP MQTT Client Application: &gt;=2.0.1|&lt;=2.2.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users of lwIP are encouraged to update their version of lwIP using the repository found at <a href=\"https://savannah.nongnu.org/projects/lwip\">https://savannah.nongnu.org/projects/lwip</a>. The commit identifier that contains the fix is f89407ea711879c04d91c92b35d67be78bbaf0f1.<br>&nbsp;</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/787.html\">CWE-787 Out-of-bounds Write</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Shahriyar Jalayeri of ByteRay Ltd. reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (<a href=\"https://www.cisa.gov/privacy-policy\">https://www.cisa.gov/privacy-policy</a>).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<ul>\n<li>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</li>\n<li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li>\n<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li>\n</ul>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<ul>\n<li>Do not click web links or open attachments in unsolicited email messages.</li>\n<li>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</li>\n<li>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</li>\n</ul>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-22</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-22</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 22 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 22 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/09/22/cisa-adds-four-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Four Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/09/22/cisa-adds-four-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added four new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-85102\" target=\"_blank\">CVE-2026-85102</a> Check Point Multiple Products Improper Certificate Validation Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-93616\">CVE-2026-93616</a> Check Point Multiple Products Path Traversal Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-93952\">CVE-2026-93952</a> Arista VeloCloud Orchestrator Improper Input Validation Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-94127\">CVE-2026-94127</a> F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability</li>\n</ul>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.&nbsp;</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&nbsp;</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities\">specified criteria</a>.&nbsp;</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.</p>",
        "summary_is_html": true,
        "first_seen": "Tue, 22 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 22 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-04",
        "title": "Siemens SIPLUS and SIMATIC Products",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-04",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-04.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Multiple Siemens products are vulnerable to the \"Copy Fail\" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</strong></p>\n<p>The following versions of Siemens SIPLUS and SIMATIC Products are affected:</p>\n<ul>\n<li>SIMATIC AX Runtime Core Linux Common Debian vers:all/* (CVE-2026-31431)</li>\n<li>SIMATIC AX Runtime Core Linux Common Debian arm64 vers:all/* (CVE-2026-31431)</li>\n<li>SIMATIC AX Runtime Core Linux Platform Container Common Debian Development vers:all/* (CVE-2026-31431)</li>\n<li>SIMATIC AX Runtime Core Linux VMWare Development vers:all/* (CVE-2026-31431)</li>\n<li>SIMATIC CN 4100 vers:intdot/&lt;6.0 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1000 Unified Basic (6AV2123-3KB32-0AW0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1000 Unified Comfort Panel (6AV2128-3KB06-0AX1) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1000 Unified Comfort Panel hygienic (6AV2128-3KB40-0AX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1000 Unified Comfort Panel hygienic neutral design (6AV2128-3KB70-0AX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1000, Unified Comfort Panel neutral (6AV2128-3KB36-0AX1) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1200 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3MB27-1BX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1200 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3MB27-0BX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1200 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3MB27-0AX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1200 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3MB57-1BX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3MB57-0BX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3MB57-0AX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1200 Unified Basic (6AV2123-3MB32-0AW0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1200 Unified Comfort Panel (6AV2128-3MB06-0AX1) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1200 Unified Comfort Panel hygienic (6AV2128-3MB40-0AX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1200 Unified Comfort Panel hygienic neutral design (6AV2128-3MB70-0AX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1200 Unified Comfort Panel neutral design (6AV2128-3MB36-0AX1) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1500 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3QB27-1BX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1500 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3QB27-0BX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1500 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3QB27-0AX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1500 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3QB57-1BX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1500 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3QB57-0BX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1500 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3QB57-0AX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1500 Unified Comfort Panel (6AV2128-3QB06-0AX1) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1500 Unified Comfort Panel hygienic (6AV2128-3QB40-0AX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1500 Unified Comfort Panel hygienic neutral design (6AV2128-3QB70-0AX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1500 Unified Comfort Panel neutral design (6AV2128-3QB36-0AX1) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1900 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3UB27-1BX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1900 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3UB27-0BX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1900 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3UB27-0AX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1900 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3UB57-1BX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1900 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3UB57-0BX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1900 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3UB57-0AX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1900 Unified Comfort Panel (6AV2128-3UB06-0AX1) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1900 Unified Comfort Panel hygienic (6AV2128-3UB40-0AX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1900 Unified Comfort Panel hygienic neutral design (6AV2128-3UB70-0AX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP1900 Unified Comfort Panel neutral design (6AV2128-3UB36-0AX1) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP2200 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3XB27-1BX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP2200 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3XB27-0BX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP2200 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3XB27-0AX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP2200 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3XB57-1BX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3XB57-0BX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3XB57-0AX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP2200 Unified Comfort Hygienic (6AV2128-3XB40-0AX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP2200 Unified Comfort Hygienic neutral design (6AV2128-3XB70-0AX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP2200 Unified Comfort Panel (6AV2128-3XB06-0AX1) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP2200 Unified Comfort Panel neutral design (6AV2128-3XB36-0AX1) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP400 Unified Basic (6AV2123-3DB32-0AW0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP700 Unified Basic (6AV2123-3GB32-0AW0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP700&nbsp;Unified Comfort Panel (6AV2128-3GB06-0AX1) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP700 Unified Comfort Panel hygienic neutral design (6AV2128-3GB40-0AX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP700 Unified Comfort Panel hygienic neutral design (6AV2128-3GB70-0AX0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC HMI MTP700, Unified Comfort Panel neutral design (6AV2128-3GB36-0AX1) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) vers:all/* (CVE-2026-31431)</li>\n<li>SIMATIC IPC Industrial Edge Device OS (IED-OS) vers:all/* (CVE-2026-31431)</li>\n<li>SIMATIC S7-1500 TM MFP (6ES7558-1AA00-0AB0) vers:all/* (CVE-2026-31431)</li>\n<li>SIPLUS HMI MTP1000 Unified Basic (6AG1123-3KB32-2AW0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIPLUS HMI MTP1000 Unified Comfort (6AG1128-3KB06-4AX1) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIPLUS HMI MTP1200 Unified Basic (6AG1123-3MB32-2AW0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIPLUS HMI MTP1200 Unified Comfort (6AG1128-3MB06-4AX1) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIPLUS HMI MTP400 Unified Basic (6AG1123-3DB32-2AW0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIPLUS HMI MTP700 Unified Basic (6AG1123-3GB32-2AW0) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n<li>SIPLUS HMI MTP700 Unified Comfort (6AG1128-3GB06-4AX1) vers:intdot/&lt;21.0.2.1 (CVE-2026-31431)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.8</td>\n<td>Siemens</td>\n<td>Siemens SIPLUS and SIMATIC Products</td>\n<td>Incorrect Resource Transfer Between Spheres</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, Commercial Facilities</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-31431</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-31431\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SIPLUS and SIMATIC Products</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SIMATIC AX Runtime Core Linux Common Debian, SIMATIC HMI MTP1000, Unified Comfort Panel neutral (6AV2128-3KB36-0AX1) &lt; V21.2.1, SIMATIC HMI MTP1200 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3MB27-1BX0) &lt; V21.2.1, SIMATIC HMI MTP1200 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3MB27-0BX0) &lt; V21.2.1, SIMATIC HMI MTP1200 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3MB27-0AX0) &lt; V21.2.1, SIMATIC HMI MTP1200 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3MB57-1BX0) &lt; V21.2.1, SIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3MB57-0BX0) &lt; V21.2.1, SIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3MB57-0AX0) &lt; V21.2.1, SIMATIC HMI MTP1200 Unified Basic (6AV2123-3MB32-0AW0) &lt; V21.2.1, SIMATIC HMI MTP1200 Unified Comfort Panel (6AV2128-3MB06-0AX1) &lt; V21.2.1, SIMATIC HMI MTP1200 Unified Comfort Panel hygienic (6AV2128-3MB40-0AX0) &lt; V21.2.1, SIMATIC AX Runtime Core Linux Common Debian arm64, SIMATIC HMI MTP1200 Unified Comfort Panel hygienic neutral design (6AV2128-3MB70-0AX0) &lt; V21.2.1, SIMATIC HMI MTP1200 Unified Comfort Panel neutral design (6AV2128-3MB36-0AX1) &lt; V21.2.1, SIMATIC HMI MTP1500 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3QB27-1BX0) &lt; V21.2.1, SIMATIC HMI MTP1500 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3QB27-0BX0) &lt; V21.2.1, SIMATIC HMI MTP1500 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3QB27-0AX0) &lt; V21.2.1, SIMATIC HMI MTP1500 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3QB57-1BX0) &lt; V21.2.1, SIMATIC HMI MTP1500 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3QB57-0BX0) &lt; V21.2.1, SIMATIC HMI MTP1500 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3QB57-0AX0) &lt; V21.2.1, SIMATIC HMI MTP1500 Unified Comfort Panel (6AV2128-3QB06-0AX1) &lt; V21.2.1, SIMATIC HMI MTP1500 Unified Comfort Panel hygienic (6AV2128-3QB40-0AX0) &lt; V21.2.1, SIMATIC AX Runtime Core Linux Platform Container Common Debian Development, SIMATIC HMI MTP1500 Unified Comfort Panel hygienic neutral design (6AV2128-3QB70-0AX0) &lt; V21.2.1, SIMATIC HMI MTP1500 Unified Comfort Panel neutral design (6AV2128-3QB36-0AX1) &lt; V21.2.1, SIMATIC HMI MTP1900 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3UB27-1BX0) &lt; V21.2.1, SIMATIC HMI MTP1900 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3UB27-0BX0) &lt; V21.2.1, SIMATIC HMI MTP1900 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3UB27-0AX0) &lt; V21.2.1, SIMATIC HMI MTP1900 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3UB57-1BX0) &lt; V21.2.1, SIMATIC HMI MTP1900 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3UB57-0BX0) &lt; V21.2.1, SIMATIC HMI MTP1900 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3UB57-0AX0) &lt; V21.2.1, SIMATIC HMI MTP1900 Unified Comfort Panel (6AV2128-3UB06-0AX1) &lt; V21.2.1, SIMATIC HMI MTP1900 Unified Comfort Panel hygienic (6AV2128-3UB40-0AX0) &lt; V21.2.1, SIMATIC AX Runtime Core Linux VMWare Development, SIMATIC HMI MTP1900 Unified Comfort Panel hygienic neutral design (6AV2128-3UB70-0AX0) &lt; V21.2.1, SIMATIC HMI MTP1900 Unified Comfort Panel neutral design (6AV2128-3UB36-0AX1) &lt; V21.2.1, SIMATIC HMI MTP2200 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3XB27-1BX0) &lt; V21.2.1, SIMATIC HMI MTP2200 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3XB27-0BX0) &lt; V21.2.1, SIMATIC HMI MTP2200 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3XB27-0AX0) &lt; V21.2.1, SIMATIC HMI MTP2200 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3XB57-1BX0) &lt; V21.2.1, SIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3XB57-0BX0) &lt; V21.2.1, SIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3XB57-0AX0) &lt; V21.2.1, SIMATIC HMI MTP2200 Unified Comfort Hygienic (6AV2128-3XB40-0AX0) &lt; V21.2.1, SIMATIC HMI MTP2200 Unified Comfort Hygienic neutral design (6AV2128-3XB70-0AX0) &lt; V21.2.1, SIMATIC CN 4100 &lt; V6.0, SIMATIC HMI MTP2200 Unified Comfort Panel (6AV2128-3XB06-0AX1) &lt; V21.2.1, SIMATIC HMI MTP2200 Unified Comfort Panel neutral design (6AV2128-3XB36-0AX1) &lt; V21.2.1, SIMATIC HMI MTP400 Unified Basic (6AV2123-3DB32-0AW0) &lt; V21.2.1, SIMATIC HMI MTP700 Unified Basic (6AV2123-3GB32-0AW0) &lt; V21.2.1, SIMATIC HMI MTP700&nbsp;Unified Comfort Panel (6AV2128-3GB06-0AX1) &lt; V21.2.1, SIMATIC HMI MTP700 Unified Comfort Panel hygienic neutral design (6AV2128-3GB40-0AX0) &lt; V21.2.1, SIMATIC HMI MTP700 Unified Comfort Panel hygienic neutral design (6AV2128-3GB70-0AX0) &lt; V21.2.1, SIMATIC HMI MTP700, Unified Comfort Panel neutral design (6AV2128-3GB36-0AX1) &lt; V21.2.1, SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2), SIMATIC IPC Industrial Edge Device OS (IED-OS), SIMATIC HMI MTP1000 Unified Basic (6AV2123-3KB32-0AW0) &lt; V21.2.1, SIMATIC S7-1500 TM MFP (6ES7558-1AA00-0AB0), SIPLUS HMI MTP1000 Unified Basic (6AG1123-3KB32-2AW0) &lt; V21.2.1, SIPLUS HMI MTP1000 Unified Comfort (6AG1128-3KB06-4AX1) &lt; V21.2.1, SIPLUS HMI MTP1200 Unified Basic (6AG1123-3MB32-2AW0) &lt; V21.2.1, SIPLUS HMI MTP1200 Unified Comfort (6AG1128-3MB06-4AX1) &lt; V21.2.1, SIPLUS HMI MTP400 Unified Basic (6AG1123-3DB32-2AW0) &lt; V21.2.1, SIPLUS HMI MTP700 Unified Basic (6AG1123-3GB32-2AW0) &lt; V21.2.1, SIPLUS HMI MTP700 Unified Comfort (6AG1128-3GB06-4AX1) &lt; V21.2.1, SIMATIC HMI MTP1000 Unified Comfort Panel (6AV2128-3KB06-0AX1) &lt; V21.2.1, SIMATIC HMI MTP1000 Unified Comfort Panel hygienic (6AV2128-3KB40-0AX0) &lt; V21.2.1, SIMATIC HMI MTP1000 Unified Comfort Panel hygienic neutral design (6AV2128-3KB70-0AX0) &lt; V21.2.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only.</p>\n<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>\n<p><strong>None available</strong><br>Currently no fix is available</p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825897/\">https://support.industry.siemens.com/cs/ww/en/view/109825897/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825897/\">https://support.industry.siemens.com/cs/ww/en/view/109825897/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825897/\">https://support.industry.siemens.com/cs/ww/en/view/109825897/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825897/\">https://support.industry.siemens.com/cs/ww/en/view/109825897/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 SP2 Update 1 or later version TODO: download link missing</p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V21 Update 2 SR1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109825605/\">https://support.industry.siemens.com/cs/ww/en/view/109825605/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V6.0 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109814144/\">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>\n<p><strong>Vendor fix</strong><br>For more information see the associated Siemens security advisory <a href=\"https://cert-portal.siemens.com/productcert/csaf/ssa-328642.json\">SSA-328642: \"Copy Fail\" Vulnerability in Multiple Industrial Products - CSAF Version</a>, <a href=\"https://cert-portal.siemens.com/productcert/html/ssa-328642.html\">SSA-328642: \"Copy Fail\" Vulnerability in Multiple Industrial Products - HTML Version</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/669.html\">CWE-669 Incorrect Resource Transfer Between Spheres</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security (Download: <a href=\"https://www.siemens.com/cert/operational-guidelines-industrial-security\">https://www.siemens.com/cert/operational-guidelines-industrial-security</a>), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: <a href=\"https://www.siemens.com/industrialsecurity\">https://www.siemens.com/industrialsecurity</a>&nbsp;</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: <a href=\"https://www.siemens.com/cert/advisories\">https://www.siemens.com/cert/advisories</a>&nbsp;</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: <a href=\"https://www.siemens.com/productcert/terms-of-use\">https://www.siemens.com/productcert/terms-of-use</a>.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (<a href=\"https://www.cisa.gov/privacy-policy\">https://www.cisa.gov/privacy-policy</a>).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<ul>\n<li>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</li>\n<li>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</li>\n<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</li>\n</ul>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT <a href=\"https://cert-portal.siemens.com/productcert/html/ssa-328642.html\">SSA-328642 </a>from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-08</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-08</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-09-22</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-328642 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 22 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 22 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-07",
        "title": "Siemens SIMOVE Fleetmanager and SIPLANT",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-07",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-07.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope. Siemens has released new versions for the affected products and recommends to update to the latest versions.</strong></p>\n<p>The following versions of Siemens SIMOVE Fleetmanager and SIPLANT are affected:</p>\n<ul>\n<li>SIMOVE Fleetmanager V3.1 vers:intdot/&lt;3.1.13 (CVE-2026-67367)</li>\n<li>SIMOVE Fleetmanager V3.2 vers:intdot/&lt;3.2.4 (CVE-2026-67367)</li>\n<li>SIMOVE Fleetmanager V3.3 vers:intdot/&lt;3.3.2 (CVE-2026-67367)</li>\n<li>SIMOVE Fleetmanager V4.0 vers:intdot/&lt;4.0.1 (CVE-2026-67367)</li>\n<li>SIPLANT V1.7 vers:all/* (CVE-2026-67367)</li>\n<li>SIPLANT V2.2 vers:all/* (CVE-2026-67367)</li>\n<li>SIPLANT V3.0 vers:all/* (CVE-2026-67367)</li>\n<li>SIPLANT V3.1 vers:intdot/&lt;3.1.4 (CVE-2026-67367)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.6</td>\n<td>Siemens</td>\n<td>Siemens SIMOVE Fleetmanager and SIPLANT</td>\n<td>Relative Path Traversal</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-67367</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Affected devices do not properly validate and neutralize directory traversal sequences in the file-serving endpoint of the embedded HTTP server. This could allow an unauthenticated remote attacker to read arbitrary files from the underlying operating system without any credentials, potentially exposing sensitive data such as credential stores, private keys, and configuration secrets.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-67367\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SIMOVE Fleetmanager and SIPLANT</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SIMOVE Fleetmanager V3.1 &lt; V3.1.13, SIMOVE Fleetmanager V3.2 &lt; V3.2.4, SIMOVE Fleetmanager V3.3 &lt; V3.3.2, SIMOVE Fleetmanager V4.0 &lt; V4.0.1, SIPLANT V1.7, SIPLANT V2.2, SIPLANT V3.0, SIPLANT V3.1 &lt; V3.1.4</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Configure appropriate user management by restricting services' access rights to project files.</p>\n<p><strong>Mitigation</strong><br>Restrict network access to affected devices.</p>\n<p><strong>Vendor fix</strong><br>Update to V3.1.13 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109813191/\">https://support.industry.siemens.com/cs/ww/en/view/109813191/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V3.1.4 or later version Contact customer support siplant-support.de@siemens.com</p>\n<p><strong>Vendor fix</strong><br>Update to V3.2.4 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109813191/\">https://support.industry.siemens.com/cs/ww/en/view/109813191/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V3.3.2 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109813191/\">https://support.industry.siemens.com/cs/ww/en/view/109813191/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V4.0.1 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/110004946/\">https://support.industry.siemens.com/cs/ww/en/view/110004946/</a></p>\n<p><strong>Vendor fix</strong><br>Contact customer support <a href=\"mailto:siplant-support.de@siemens.com\">siplant-support.de@siemens.com</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated Siemens security advisory <a href=\"https://cert-portal.siemens.com/productcert/csaf/ssa-517424.json\">SSA-517424: Path Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT - CSAF Version</a>, <a href=\"https://cert-portal.siemens.com/productcert/html/ssa-517424.html\">SSA-517424: Path Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT - HTML Version</a>.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/23.html\">CWE-23 Relative Path Traversal</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security (Download: <a href=\"https://www.siemens.com/cert/operational-guidelines-industrial-security\">https://www.siemens.com/cert/operational-guidelines-industrial-security</a>), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: <a href=\"https://www.siemens.com/industrialsecurity\">https://www.siemens.com/industrialsecurity</a>&nbsp;</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: <a href=\"https://www.siemens.com/cert/advisories\">https://www.siemens.com/cert/advisories</a>&nbsp;</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: <a href=\"https://www.siemens.com/productcert/terms-of-use\">https://www.siemens.com/productcert/terms-of-use</a>.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (<a href=\"https://www.cisa.gov/privacy-policy\">https://www.cisa.gov/privacy-policy</a>).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<ul>\n<li>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</li>\n<li>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</li>\n<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</li>\n</ul>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT <a href=\"https://cert-portal.siemens.com/productcert/html/ssa-517424.html\">SSA-517424</a> from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-08</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-08</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-09-22</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-517424 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 22 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 22 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-05",
        "title": "Siemens Desigo CC family",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-05",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-05.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization.</strong></p>\n<p>The following versions of Siemens Desigo CC family are affected:</p>\n<ul>\n<li>Desigo CC family V6 vers:all/* (CVE-2026-34223)</li>\n<li>Desigo CC family V7 vers:all/* (CVE-2026-34223)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.2</td>\n<td>Siemens</td>\n<td>Siemens Desigo CC family</td>\n<td>Improper Control of Generation of Code ('Code Injection')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Commercial Facilities</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-34223</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected application is vulnerable to Client Code Execution (CCE) due to insufficient input validation when handling scripts embedded within user-defined graphics documents. Specifically, when the script within a graphics document is designed or modified by an attacker to include malicious commands. When a user opens a compromised graphics document, the embedded script is executed on the client application instance, allowing an attacker to write arbitrary files to the client's operating system. Successful exploitation requires an attacker to craft a malicious graphics document and entice a user with sufficient privileges to display it. This could lead to compromise of the client operating system and potential lateral movement within the organization.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-34223\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Desigo CC family</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Desigo CC family V6, Desigo CC family V7</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Evaluate authorization policy for Graphics application following Least Privilege principle, so only required users have access to the configuration.</p>\n<p><strong>None available</strong><br>Currently no fix is available.</p>\n<p><strong>Mitigation</strong><br>For more information see the associated Siemens security advisory <a href=\"https://cert-portal.siemens.com/productcert/csaf/ssa-330084.json\">SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family - CSAF Version</a>, <a href=\"https://cert-portal.siemens.com/productcert/html/ssa-330084.html\">SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family - HTML Version</a>.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/94.html\">CWE-94 Improper Control of Generation of Code ('Code Injection')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Michelin CERT reported this vulnerability to Siemens.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security (Download: <a href=\"https://www.siemens.com/cert/operational-guidelines-industrial-security\">https://www.siemens.com/cert/operational-guidelines-industrial-security</a>), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: <a href=\"https://www.siemens.com/industrialsecurity\">https://www.siemens.com/industrialsecurity</a>&nbsp;</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: <a href=\"https://www.siemens.com/cert/advisories\">https://www.siemens.com/cert/advisories</a>&nbsp;</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: <a href=\"https://www.siemens.com/productcert/terms-of-use\">https://www.siemens.com/productcert/terms-of-use</a>.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (<a href=\"https://www.cisa.gov/privacy-policy\">https://www.cisa.gov/privacy-policy</a>).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<ul>\n<li>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</li>\n<li>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</li>\n<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</li>\n</ul>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT <a href=\"https://cert-portal.siemens.com/productcert/html/ssa-330084.html\">SSA-330084</a> from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-08</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-08</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-09-22</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-330084 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 22 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 22 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-03",
        "title": "Siemens Siveillance Control",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-03",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-03.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server. Siemens has released patches and updates for Siveillance OIS to apply to the products that incorporate the OIS service, and recommends to update to the latest versions.</strong></p>\n<p>The following versions of Siemens Siveillance Control are affected:</p>\n<ul>\n<li>Siveillance Control Pro V3.0 vers:intdot/&lt;3.0.12.2173 (CVE-2026-50093)</li>\n<li>Siveillance Control Pro V4.0 vers:intdot/&lt;4.0.9.2178 (CVE-2026-50093)</li>\n<li>Siveillance Control V3.0 vers:intdot/&lt;3.0.22.2177 (CVE-2026-50093)</li>\n<li>Siveillance Control V4.0 vers:intdot/&lt;4.0.11.2177 (CVE-2026-50093)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9</td>\n<td>Siemens</td>\n<td>Siemens Siveillance Control</td>\n<td>Unrestricted Upload of File with Dangerous Type</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Communications, Commercial Facilities</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-50093</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A vulnerability in the OIS web module allows an attacker to upload arbitrary files to the server. Successful exploitation of this vulnerability could allow an attacker to gain root access on the host system, potentially leading to a full compromise of the affected OIS environment.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-50093\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Siveillance Control</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Siveillance Control Pro V3.0 &lt; V3.0.12.2173, Siveillance Control Pro V4.0 &lt; V4.0.9.2178, Siveillance Control V3.0 &lt; V3.0.22.2177, Siveillance Control V4.0 &lt; V4.0.11.2177</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V3.0.12.2173 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/110004860/\">https://support.industry.siemens.com/cs/ww/en/view/110004860/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V3.0.22.2177 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/110004859/\">https://support.industry.siemens.com/cs/ww/en/view/110004859/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V4.0.11.2177 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/110004859/\">https://support.industry.siemens.com/cs/ww/en/view/110004859/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V4.0.9.2178 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/110004860/\">https://support.industry.siemens.com/cs/ww/en/view/110004860/</a></p>\n<p><strong>Vendor fix</strong><br>For more information see the associated Siemens security advisory <a href=\"https://cert-portal.siemens.com/productcert/csaf/ssa-254516.json\">SSA-254516: Arbitrary File Upload in OIS Web Module - CSAF Version</a>, <a href=\"https://cert-portal.siemens.com/productcert/html/ssa-254516.html\">SSA-254516: Arbitrary File Upload in OIS Web Module - HTML Version</a>.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/434.html\">CWE-434 Unrestricted Upload of File with Dangerous Type</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure Siemens strongly recommends to protect network access to affected products with appropriate mechanisms. It is advised to follow recommended security practices in order to run the devices in a protected IT environment.</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: <a href=\"https://www.siemens.com/cert/advisories\">https://www.siemens.com/cert/advisories</a>&nbsp;</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: <a href=\"https://www.siemens.com/productcert/terms-of-use\">https://www.siemens.com/productcert/terms-of-use</a>.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (<a href=\"https://www.cisa.gov/privacy-policy\">https://www.cisa.gov/privacy-policy</a>).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<ul>\n<li>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</li>\n<li>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</li>\n<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</li>\n</ul>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT <a href=\"https://cert-portal.siemens.com/productcert/html/ssa-254516.html\">SSA-254516</a> from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-08</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-08</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-09-22</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-254516 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 22 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 22 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-06",
        "title": "Siemens Industrial Edge Management",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-06",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-06.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification. Siemens has released new versions for the affected products and recommends to update to the latest versions.</strong></p>\n<p>The following versions of Siemens Industrial Edge Management are affected:</p>\n<ul>\n<li>Industrial Edge Management Cloud vers:all/* (CVE-2026-18963)</li>\n<li>Industrial Edge Management Pro V1 vers:intdot/&gt;=1.14.9|&lt;1.15.20 (CVE-2026-18963)</li>\n<li>Industrial Edge Management Pro V2 vers:intdot/&gt;=2.2.0|&lt;2.2.2 (CVE-2026-18963)</li>\n<li>Industrial Edge Management Virtual vers:intdot/&gt;=2.6.0|&lt;2.9.1 (CVE-2026-18963)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.1</td>\n<td>Siemens</td>\n<td>Siemens Industrial Edge Management</td>\n<td>Weak Password Recovery Mechanism for Forgotten Password</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-18963</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-18963\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens Industrial Edge Management</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Industrial Edge Management Cloud, Industrial Edge Management Pro V1 &gt;= V1.14.9 &lt; V1.15.20, Industrial Edge Management Pro V2 &gt;= V2.2.0 &lt; V2.2.2, Industrial Edge Management Virtual &gt;= V2.6.0 &lt; V2.9.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Block direct internet access to IEM Pro / IEM Virtual The most effective immediate measure is to block direct internet access to your IEM Pro or IEM V instance. This ensures that no external attacks can occur via this vulnerability.</p>\n<p><strong>Mitigation</strong><br>Configure a Web Application Firewall (WAF) or Reverse Proxy If complete blocking of internet access is not immediately feasible, you can use a Web Application Firewall (WAF) or a Reverse Proxy to block the affected path. Please configure your WAF or Reverse Proxy to block the following path: /auth/realms/customer/login-actions/reset-credentials Please note that by blocking this path, the password reset functionality will be unavailable.</p>\n<p><strong>Mitigation</strong><br>Deactivate Password Reset in Keycloak Realm Settings Deactivate the password reset functionality directly within the Keycloak realm settings. To do this, navigate to: Identity &amp; access management &gt; realm settings &gt; Login &gt; Forgot password &gt; Off Please note that by deactivating this setting, the password reset functionality will be unavailable.</p>\n<p><strong>Vendor fix</strong><br>Update to V1.15.20 or later version<br><a href=\"https://iehub.eu1.edge.siemens.cloud/\">https://iehub.eu1.edge.siemens.cloud/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V2.2.2 or later version<br><a href=\"https://iehub.eu1.edge.siemens.cloud/\">https://iehub.eu1.edge.siemens.cloud/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V2.9.1 or later version<br><a href=\"https://iehub.eu1.edge.siemens.cloud/\">https://iehub.eu1.edge.siemens.cloud/</a></p>\n<p><strong>Vendor fix</strong><br>Vulnerability mitigated with firewall rules on 2026-08-26 and fixed with update on 2026-09-02; no user actions necessary.</p>\n<p><strong>Mitigation</strong><br>For more information see the associated Siemens security advisory <a href=\"https://cert-portal.siemens.com/productcert/csaf/ssa-503852.json\">SSA-503852: Authentication Bypass Vulnerability in Industrial Edge Management - CSAF Version</a>, <a href=\"https://cert-portal.siemens.com/productcert/html/ssa-503852.html\">SSA-503852: Authentication Bypass Vulnerability in Industrial Edge Management - HTML Version</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/640.html\">CWE-640 Weak Password Recovery Mechanism for Forgotten Password</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.1</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security (Download: <a href=\"https://www.siemens.com/cert/operational-guidelines-industrial-security\">https://www.siemens.com/cert/operational-guidelines-industrial-security</a>), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: <a href=\"https://www.siemens.com/industrialsecurity\">https://www.siemens.com/industrialsecurity</a>&nbsp;</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: <a href=\"https://www.siemens.com/cert/advisories\">https://www.siemens.com/cert/advisories</a>&nbsp;</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: <a href=\"https://www.siemens.com/productcert/terms-of-use\">https://www.siemens.com/productcert/terms-of-use</a>.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (<a href=\"https://www.cisa.gov/privacy-policy\">https://www.cisa.gov/privacy-policy</a>).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<ul>\n<li>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</li>\n<li>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</li>\n<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</li>\n</ul>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT <a href=\"https://cert-portal.siemens.com/productcert/html/ssa-503852.html\">SSA-503852</a> from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-08</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-08</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-09-22</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-503852 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 22 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 22 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-02",
        "title": "lwIP (Lightweight IP)",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system.</strong></p>\n<p>The following versions of lwIP (Lightweight IP) are affected:</p>\n<ul>\n<li>API &gt;=2.0.1|&lt;=2.2.1 (CVE-2026-91018)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.8</td>\n<td>lwIP</td>\n<td>lwIP (Lightweight IP)</td>\n<td>Double Free</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Communications, Critical Manufacturing, Energy, Financial Services, Healthcare and Public Health, Transportation Systems, Water and Wastewater Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Sweden</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-91018</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-91018\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>lwIP (Lightweight IP)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>lwIP</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>lwIP API: &gt;=2.0.1|&lt;=2.2.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Users of lwIP are encouraged to update their version of lwIP using the repository found at <a href=\"https://cgit.git.savannah.gnu.org/cgit/lwip.git\">https://cgit.git.savannah.gnu.org/cgit/lwip.git</a>. The commit identifier that contains the fix is f873b6295933e4149a2132adf3e9a2d2a676a5ec.<br>&nbsp;</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/415.html\">CWE-415 Double Free</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Eric Evenchick of Tetrel Security reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (<a href=\"https://www.cisa.gov/privacy-policy\">https://www.cisa.gov/privacy-policy</a>).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<ul>\n<li>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</li>\n<li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li>\n<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li>\n</ul>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<ul>\n<li>Do not click web links or open attachments in unsolicited email messages.</li>\n<li>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</li>\n<li>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</li>\n</ul>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-22</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-22</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 22 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 22 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-09",
        "title": "OpenPLC Runtime v3",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-09",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-09.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives.</strong></p>\n<p>The following versions of OpenPLC Runtime v3 are affected:</p>\n<ul>\n<li>OpenPLC 3 (CVE-2026-88020)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 6.1</td>\n<td>Autonomy Logic</td>\n<td>OpenPLC Runtime v3</td>\n<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy, Transportation Systems, Water and Wastewater Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-88020</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-88020\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>OpenPLC Runtime v3</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Autonomy Logic</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Autonomy Logic OpenPLC: 3</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Autonomy Logic recommends users upgrade to OpenPLC v4 as OpenPLC v3 is end-of-life and is no longer receiving patches, bug fixes, or security updates.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/79.html\">CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.1</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rajivarnan R. and Shirshak of Secnora reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<ul>\n<li>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</li>\n<li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li>\n<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li>\n</ul>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<ul>\n<li>Do not click web links or open attachments in unsolicited email messages.</li>\n<li>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</li>\n<li>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</li>\n</ul>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-22</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-22</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 22 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 22 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/09/21/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/09/21/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-7273\" target=\"_blank\">CVE-2026-7273</a> Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.&nbsp;</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&nbsp;</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities\">specified criteria</a>.&nbsp;</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Mon, 21 Sep 26 12:00:00 +0000",
        "last_updated": "Mon, 21 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Two Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added two new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-39964\" target=\"_blank\">CVE-2025-39964</a> Linux Kernel Race Condition Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-53266\" target=\"_blank\">CVE-2026-53266</a> Linux Kernel Out-of-Bounds Write Vulnerability</li>\n</ul>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.&nbsp;</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&nbsp;</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.&nbsp;</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Fri, 18 Sep 26 12:00:00 +0000",
        "last_updated": "Fri, 18 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-39682\" target=\"_blank\">CVE-2025-39682</a> Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s <a class=\"ext\" href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.</p>",
        "summary_is_html": true,
        "first_seen": "Fri, 18 Sep 26 12:00:00 +0000",
        "last_updated": "Fri, 18 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-04",
        "title": "Schneider Electric Modicon M340 Controller and Communication Modules",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-04",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-260-04.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Schneider Electric is aware of a vulnerability in its Modicon M340</strong><a href=\"https://www.cisa.gov//www.se.com/ww/en/product-range/1468-modicon-m340-pac/\"><strong> https://www.se.com/ww/en/product-range/1468-modicon-m340-pac/</strong></a><strong>, BMXNOR0200H </strong><a href=\"https://www.se.com/us/en/product/bmxnor0200h/communication-module-modicon-m340-iec-608705101-104-dnp3-for-severe-environments/\"><strong>https://www.se.com/us/en/product/BMXNOR0200H/communication-module-modicon-m340-iec-608705101-104-dnp3-for-severe-environments/</strong></a><strong>: Modicon M340 X80 Ethernet Communication Modules, BMXNGD0100 </strong><a href=\"https://www.se.com/us/en/product/bmxngd0100/communication-module-modicon-m580-global-data-service/\"><strong>https://www.se.com/us/en/product/BMXNGD0100/communication-module-modicon-m580-global-data-service/</strong></a><strong>: M580 Global Data module, BMXNOC0401 </strong><a href=\"https://www.se.com/us/en/product/bmxnoc0401/network-module-modicon-m340-ethernet-ip-and-modbus-tcp-4-x-rj45/?pagetype=product&amp;sourceid=bmxnoc0401\"><strong>https://www.se.com/us/en/product/BMXNOC0401/network-module-modicon-m340-ethernet-ip-and-modbus-tcp-4-x-rj45/?pageType=product&amp;sourceId=BMXNOC0401</strong></a><strong>: Modicon M340 X80 Ethernet Communication modules, BMXNOE0100 </strong><a href=\"https://www.se.com/ww/en/product/bmxnoe0100/network-module-modicon-m340-modbus-tcp-1-x-rj45-flash-memory-card/?pagetype=product&amp;sourceid=bmxnoe0100\"><strong>https://www.se.com/ww/en/product/BMXNOE0100/network-module-modicon-m340-modbus-tcp-1-x-rj45-flash-memory-card/?pageType=product&amp;sourceId=BMXNOE0100</strong></a><strong>: Modbus/TCP Ethernet Modicon M340 module, BMXNOE0110 </strong><a href=\"https://www.se.com/ww/en/product/bmxnoe0110/ethernet-tcp-ip-network-module-modicon-m340-automation-platform-flash-memory-card-internal-ram-16-mb-1-x-rj45-10-100/\"><strong>https://www.se.com/ww/en/product/BMXNOE0110/ethernet-tcp-ip-network-module-modicon-m340-automation-platform-flash-memory-card-internal-ram-16-mb-1-x-rj45-10-100/</strong></a><strong>: Modbus/TCP Ethernet Modicon M340 FactoryCast module product(s). Failure to apply the fix provided below may risk Denial Of Service attack, which could result in the unavailability of the devices.</strong></p>\n<p>The following versions of Schneider Electric Modicon M340 Controller and Communication Modules are affected:</p>\n<ul>\n<li>Schneider Electric Ethernet/Serial RTU Module: vers:generic/&lt;SV1.7_IR27</li>\n<li>Schneider Electric M580 Global Data module: vers:all/*</li>\n<li>Schneider Electric Ethernet / Serial RTU Module: vers:all/*</li>\n<li>Schneider Electric Modbus/TCP Ethernet Modicon M340 module: vers:intdot/&lt;3.60</li>\n<li>Schneider Electric Modbus/TCP Ethernet Modicon M340 FactoryCast module: vers:intdot/&lt;6.80</li>\n<li>Schneider Electric Modicon M340 Firmware Versions prior to SV3.70 installed on Modicon M340 Controller: All versions</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>Schneider Electric</td>\n<td>Schneider Electric Modicon M340 Controller and Communication Modules</td>\n<td>Improper Input Validation</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Commercial Facilities, Critical Manufacturing, Energy, Water and Wastewater</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>France</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-6625</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>CWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific crafted FTP command is sent to the device.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-6625\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Schneider Electric Modicon M340 Controller and Communication Modules</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Schneider Electric</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Ethernet / Serial RTU Module All versions, M580 Global Data module All versions, Modicon M340 X80 Ethernet Communication modules All versions, Modbus/TCP Ethernet Modicon M340 module Versions prior to 3.60, Modbus/TCP Ethernet Modicon M340 FactoryCast module Versions prior to 6.80</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>fixed, known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Version 3.60 of BMXNOE0100 includes a fix for this vulnerability and is available for download here: <a href=\"https://www.se.com/ww/en/product/BMXNOE0100/network-module-modicon-m340-modbus-tcp-1-x-rj45-flash-memory-card/\">https://www.se.com/ww/en/product/BMXNOE0100/network-module-modicon-m340-modbus-tcp-1-x-rj45-flash-memory-card/</a>&nbsp;</p>\n<p>Reboot is needed to complete the firmware upgrade<br>&nbsp;</p>\n<p><strong>Vendor fix</strong><br>Version 6.80 of BMXNOE0110 includes a fix for this vulnerability and is available for download here: <a href=\"https://www.se.com/ww/en/product/BMXNOE0110/ethernet-tcp-ip-network-module-modicon-m340-automation-platform-flash-memory-card-internal-ram-16-mb-1-x-rj45-10-100/\">https://www.se.com/ww/en/product/BMXNOE0110/ethernet-tcp-ip-network-module-modicon-m340-automation-platform-flash-memory-card-internal-ram-16-mb-1-x-rj45-10-100/</a>&nbsp;</p>\n<p>Reboot is needed to complete the firmware upgrade<br>&nbsp;</p>\n<p><strong>Vendor fix</strong><br>Version SV3.70 of Modicon M340 includes a fix for this vulnerability and is available for download here:&nbsp;<br><a href=\"https://www.se.com/ww/en/product-range/1468-modicon-m340/#software-and-firmware\">https://www.se.com/ww/en/product-range/1468-modicon-m340/#software-and-firmware</a></p>\n<p><strong>Vendor fix</strong><br>Version SV1.7 IR27 of BMXNOR0200H includes a fix for this vulnerability and is available for download here:&nbsp;<br><a href=\"https://www.se.com/ww/en/product/BMXNOR0200H/ethernet-serial-rtu-module-2-x-rj45/\">https://www.se.com/ww/en/product/BMXNOR0200H/ethernet-serial-rtu-module-2-x-rj45/</a></p>\n<p><strong>Mitigation</strong><br>If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit:&nbsp;</p>\n<ul>\n<li>FTP service is disabled by default.</li>\n<li>Ensure to disable FTP service when not in use.</li>\n<li>Setup network segmentation and implement a firewall to block all unauthorized access to ports 21/FTP.</li>\n<li>Use VPN (Virtual Private Networks) tunnels if remote access is required.</li>\n</ul>\n<p><strong>Mitigation</strong><br>Schneider Electric is establishing a remediation plan for all future versions of:</p>\n<ul>\n<li>Modicon M340</li>\n<li>BMXNOR0200H</li>\n<li>BMXNGD0100</li>\n<li>\n<p>BMXNOC401&nbsp;</p>\n<p>Schneider Electric will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit:&nbsp;</p>\n</li>\n<li>FTP service is disabled by default.</li>\n<li>Ensure to disable FTP service when not in use.</li>\n<li>Setup network segmentation and implement a firewall to block all unauthorized access to ports 21/FTP.</li>\n<li>Use VPN (Virtual Private Networks) tunnels if remote access is required.</li>\n</ul>\n</div>\n<p><strong>Mitigation</strong></p>\n<p>For more information see the associated Schneider Electric security advisory <a href=\"https://download.schneider-electric.com/files?p_doc_ref=sevd-2025-224-05&amp;p_endoctype=security+and+safety+notice&amp;p_file_name=sevd-2025-224-05.json\">Modicon M340 Controller and Communication Modules - SEVD-2025-224-05 CSAF Version</a>, <a href=\"https://download.schneider-electric.com/files?p_doc_ref=sevd-2025-224-05&amp;p_endoctype=security+and+safety+notice&amp;p_file_name=sevd-2025-224-05.pdf\">Modicon M340 Controller and Communication Modules - SEVD-2025-224-05 PDF Version</a>.</p>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/20.html\">CWE-20 Improper Input Validation</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Schneider Electric CPCERT reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>General Security Recommendations</h2>\n<p>We strongly recommend the following industry cybersecurity best practices.&nbsp;</p>\n<ul>\n<li>Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.&nbsp;</li>\n<li>Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.&nbsp;</li>\n<li>Place all controllers in locked cabinets and never leave them in the \u201cProgram\u201d mode.&nbsp;</li>\n<li>Never connect programming software to any network other than the network intended for that device.&nbsp;</li>\n<li>Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.&nbsp;</li>\n<li>Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.&nbsp;</li>\n<li>Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.&nbsp;</li>\n<li>When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). &nbsp;Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.&nbsp;</li>\n</ul>\n<p>For more information refer to the <a href=\"https://www.se.com/us/en/download/document/7en52-0390/\">Schneider Electric Recommended Cybersecurity Best Practices</a> document.</p>\n<hr>\n<h2>For More Information</h2>\n<p>This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: <a href=\"https://www.se.com/ww/en/work/solutions/cybersecurity/\">https://www.se.com/ww/en/work/solutions/cybersecurity/</a>. These organizations will be fully aware of this situation and can support you through the process. For further information related to cybersecurity in Schneider Electric's products, visit the company's cybersecurity support portal page: <a href=\"https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp\">https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp</a></p>\n<hr>\n<h2>LEGAL DISCLAIMER</h2>\n<p>THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS \u201cNOTIFICATION\u201d) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN \u201cAS-IS\u201d BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION</p>\n<hr>\n<h2>About Schneider Electric</h2>\n<p>Schneider's purpose is to create Impact by empowering all to make the most of our energy and resources, bridging progress and sustainability for all. We call this Life Is On. Our mission is to be the trusted partner in Sustainability and Efficiency. We are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart industries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep domain expertise, we provide integrated end-to-end lifecycle AI enabled Industrial IoT solutions with connected products, automation, software and services, delivering digital twins to enable profitable growth for our customers. We are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries to ensure proximity to our customers and stakeholders. We embrace diversity and inclusion in everything we do, guided by our meaningful purpose of a sustainable future for all. www.se.com</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (<a href=\"https://www.cisa.gov/privacy-policy\">https://www.cisa.gov/privacy-policy</a>).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<ul>\n<li>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</li>\n<li>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</li>\n<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</li>\n</ul>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Schneider Electric CPCERT <a href=\"https://download.schneider-electric.com/files?p_doc_ref=sevd-2025-224-05&amp;p_endoctype=security+and+safety+notice&amp;p_file_name=sevd-2025-224-05.pdf\">SEVD-2025-224-05</a> from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2025-08-12</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2025-08-12</td>\n<td>1</td>\n<td>Original Release</td>\n</tr>\n<tr>\n<td>2026-04-14</td>\n<td>2</td>\n<td>Remediation is available for Modicon M340</td>\n</tr>\n<tr>\n<td>2026-08-11</td>\n<td>3</td>\n<td>Remediation is available for BMXNOR0200H.</td>\n</tr>\n<tr>\n<td>2026-09-17</td>\n<td>4</td>\n<td>Initial CISA Republication of Schneider Electric CPCERT SEVD-2025-224-05 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 17 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 17 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-05",
        "title": "Schneider Electric NetBotz 5 750/755",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-05",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-260-05.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 \u2013 750/755 products.The NetBotz 5 \u2013 750/755 products are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capabilities. Failure to apply the remediation provided below may risk arbitrary or remote code execution over the local network, which could result in device manipulation and unauthorized data access.</strong></p>\n<p>The following versions of Schneider Electric NetBotz 5 750/755 are affected:</p>\n<ul>\n<li>NetBotz 5 750 vers:intdot/&lt;=5.5.2 (CVE-2026-13336, CVE-2026-13337)</li>\n<li>NetBotz 5 755 vers:intdot/&lt;=5.5.2 (CVE-2026-13336, CVE-2026-13337)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 6.4</td>\n<td>Schneider Electric</td>\n<td>Schneider Electric NetBotz 5 750/755</td>\n<td>Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), SQL Injection: Hibernate</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Commercial Facilities, Critical Manufacturing, Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>France</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-13336</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause execution of Linux Operating system commands when a system back up is restored that has been maliciously modified.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-13336\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Schneider Electric NetBotz 5 750/755</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Schneider Electric</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>NetBotz 5 750 versions 5.5.2 and prior, NetBotz 5 755 Versions 5.5.2 and prior</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>fixed, known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Version 5.6.0 of NetBotz 5 750/755 includes a fix for these vulnerabilities and is available for download here: <a href=\"https://www.se.com/ww/en/product-range/61830-netbotz/#software-and-firmware\">https://www.se.com/ww/en/product-range/61830-netbotz/#software-and-firmware</a> Reboot needed: Upon install, the offer will automatically restart. A customer can validate a successful install by logging into the GUI and selecting the \u2018About NetBotz\u2019 option. This will indicate the <a href=\"https://www.se.com/ww/en/product-range/61830-netbotz/#software-and-firmware\">installed version.</a><br>&nbsp;</p>\n<p>For more information see the associated Schneider Electric security advisory <a href=\"https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-223-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=sevd-2026-223-02.json\">Multiple Vulnerabilities on NetBotz 5 750/755 Products - SEVD-2026-223-02 CSAF Version</a>, <a href=\"https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-223-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-223-02.pdf\">Multiple Vulnerabilities on NetBotz 5 750/755 Products - SEVD-2026-223-02 PDF Version</a>.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/78.html\">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.4</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-13337</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>CWE-564:SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is logged into the NetBotz via the web-service interface or web-ui.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-13337\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Schneider Electric NetBotz 5 750/755</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Schneider Electric</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>NetBotz 5 750 versions 5.5.2 and prior, NetBotz 5 755 Versions 5.5.2 and prior</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>fixed, known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Version 5.6.0 of NetBotz 5 750/755 includes a fix for these vulnerabilities and is available for download here: <a href=\"https://www.se.com/ww/en/product-range/61830-netbotz/#software-and-firmware\">https://www.se.com/ww/en/product-range/61830-netbotz/#software-and-firmware</a> Reboot needed: Upon install, the offer will automatically restart. A customer can validate a successful install by logging into the GUI and selecting the \u2018About NetBotz\u2019 option. This will indicate the <a href=\"https://www.se.com/ww/en/product-range/61830-netbotz/#software-and-firmware\"><u>installed version.</u></a><br>&nbsp;</p>\n<p>For more information see the associated Schneider Electric security advisory <a href=\"https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-223-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=sevd-2026-223-02.json\">Multiple Vulnerabilities on NetBotz 5 750/755 Products - SEVD-2026-223-02 CSAF Version</a>, <a href=\"https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-223-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-223-02.pdf\">Multiple Vulnerabilities on NetBotz 5 750/755 Products - SEVD-2026-223-02 PDF Version</a>.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/564.html\">CWE-564 SQL Injection: Hibernate</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>4.6</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N\">CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Schneider Electric CPCERT reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>General Security Recommendations</h2>\n<p>Schneider Electric strongly recommends the following industry cybersecurity best practices.&nbsp;</p>\n<ul>\n<li>Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.&nbsp;</li>\n<li>Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.&nbsp;</li>\n<li>Place all controllers in locked cabinets and never leave them in the \u201cProgram\u201d mode.&nbsp;</li>\n<li>Never connect programming software to any network other than the network intended for that device.&nbsp;</li>\n<li>Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.&nbsp;</li>\n<li>Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.&nbsp;</li>\n<li>Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.&nbsp;</li>\n<li>* When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.&nbsp;</li>\n</ul>\n<p>For more information refer to the <a href=\"https://www.se.com/us/en/download/document/7EN52-0390/%20\">Schneider Electric Recommended Cybersecurity Best Practices document</a>.</p>\n<hr>\n<h2>For More Information</h2>\n<p>This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: <a href=\"https://www.se.com/ww/en/work/solutions/cybersecurity/\">https://www.se.com/ww/en/work/solutions/cybersecurity/</a>. These organizations will be fully aware of this situation and can support you through the process. For further information related to cybersecurity in Schneider Electric\u2019s products, visit the company\u2019s cybersecurity support portal page: <a href=\"https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp\">https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp</a></p>\n<hr>\n<h2>LEGAL DISCLAIMER</h2>\n<p>THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS \u201cNOTIFICATION\u201d) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN \u201cAS-IS\u201d BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION</p>\n<hr>\n<h2>About Schneider Electric</h2>\n<p>Schneider's purpose is to create Impact by empowering all to make the most of our energy and resources, bridging progress and sustainability for all. We call this Life Is On. Our mission is to be the trusted partner in Sustainability and Efficiency. We are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart industries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep domain expertise, we provide integrated end-to-end lifecycle AI enabled Industrial IoT solutions with connected products, automation, software and services, delivering digital twins to enable profitable growth for our customers. We are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries to ensure proximity to our customers and stakeholders. We embrace diversity and inclusion in everything we do, guided by our meaningful purpose of a sustainable future for all. www.se.com</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (<a href=\"https://www.cisa.gov/privacy-policy\">https://www.cisa.gov/privacy-policy</a>).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>\n<ul>\n<li>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</li>\n<li>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</li>\n<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</li>\n</ul>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Schneider Electric CPCERT <a href=\"https://download.schneider-electric.com/files?p_doc_ref=sevd-2026-223-02&amp;p_endoctype=security+and+safety+notice&amp;p_file_name=sevd-2026-223-02.pdf\">SEVD-2026-223-02</a> from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-11</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-11</td>\n<td>1</td>\n<td>Original Release</td>\n</tr>\n<tr>\n<td>2026-09-17</td>\n<td>2</td>\n<td>Initial CISA Republication of Schneider Electric CPCERT SEVD-2026-223-02 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 17 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 17 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-01",
        "title": "Bransys ELD",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-260-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware.</strong></p>\n<p>The following versions of Bransys ELD are affected:</p>\n<ul>\n<li>Android &lt;11.00.00 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960)</li>\n<li>iOS &lt;1.1.54 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>Bransys</td>\n<td>Bransys ELD</td>\n<td>Use of Hard-coded Credentials, Cleartext Transmission of Sensitive Information</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>United States</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-86520</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-86520\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Bransys ELD</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Bransys</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Bransys Android: &lt;11.00.00, Bransys iOS: &lt;1.1.54</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Bransys recommends that users update their system through the app store. Android users should be on version 11.00.00 or newer. iOS users should be on version 1.1.54 or newer.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/798.html\">CWE-798 Use of Hard-coded Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-86689</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product is susceptible to cleartext transmission of sensitive information, which could allow an attacker to connect to the broker and read all data.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-86689\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Bransys ELD</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Bransys</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Bransys Android: &lt;11.00.00, Bransys iOS: &lt;1.1.54</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Bransys recommends that users update their system through the app store. Android users should be on version 11.00.00 or newer. iOS users should be on version 1.1.54 or newer.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/319.html\">CWE-319 Cleartext Transmission of Sensitive Information</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-77960</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected product ships with hardcoded FTP credentials which could allow an attacker to connect to the server and read data.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-77960\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Bransys ELD</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Bransys</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Bransys Android: &lt;11.00.00, Bransys iOS: &lt;1.1.54</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Bransys recommends that users update their system through the app store. Android users should be on version 11.00.00 or newer. iOS users should be on version 1.1.54 or newer.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/798.html\">CWE-798 Use of Hard-coded Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Jaime Lightfoot reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (<a href=\"https://www.cisa.gov/privacy-policy\">https://www.cisa.gov/privacy-policy</a>).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<ul>\n<li>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</li>\n<li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li>\n<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li>\n</ul>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<ul>\n<li>Do not click web links or open attachments in unsolicited email messages.</li>\n<li>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</li>\n<li>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</li>\n</ul>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-17</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-17</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 17 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 17 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-03",
        "title": "Hitachi Energy FACTS Control Platform (FCP)",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-03",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-260-03.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Hitachi Energy is aware of vulnerabilities that affect the FACTS Control systems with GWS component listed in this document. An attacker exploiting these vulnerabilities can cause impact on confidentiality, integrity and availability of the product. Following FACTS Control systems with GWS component deployed from year 2020 onwards are likely affected by the above vulnerabilities. Product deployments without GWS component are not affected. \u2022 SVC Light (STATCOM) \u2022 Fixed Series Capacitor \u2022 Thyristor Controlled Series Capacitor \u2022 Static Var Compensator \u2022 Static Watt Compensator \u2022 Hybrid Synchronous Condensers Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The affected FCP versions are only applicable if GWS component is present.</strong></p>\n<p>The following versions of Hitachi Energy FACTS Control Platform (FCP) are affected:</p>\n<ul>\n<li>FACTS Control Platform (FCP) 3.4.0, 3.7.0, 3.8.0, 3.10.0, 3.12.0, 3.14.0, 3.15.0, 4.0.0, 4.0.1, 4.1.0, 4.1.1 (CVE-2024-4872, CVE-2024-3980, CVE-2024-3982, CVE-2024-7940, CVE-2024-7941)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.9</td>\n<td>Hitachi Energy</td>\n<td>Hitachi Energy FACTS Control Platform (FCP)</td>\n<td>Improper Neutralization of Special Elements in Data Query Logic, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Authentication Bypass by Capture-replay, Missing Authentication for Critical Function, URL Redirection to Untrusted Site ('Open Redirect')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Switzerland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2024-4872</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A vulnerability exists in the query validation of the FACTS Control system with GWS component. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability an attacker must have a valid credential.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2024-4872\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Hitachi Energy FACTS Control Platform (FCP)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Hitachi Energy</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>FACTS Control Platform (FCP) version 3.4.0, FACTS Control Platform (FCP) version 3.7.0, FACTS Control Platform (FCP) version 3.8.0, FACTS Control Platform (FCP) version 3.10.0, FACTS Control Platform (FCP) version 3.12.0, FACTS Control Platform (FCP) version 3.14.0, FACTS Control Platform (FCP) version 3.15.0, FACTS Control Platform (FCP) version 4.0.0, FACTS Control Platform (FCP) version 4.0.1, FACTS Control Platform (FCP) version 4.1.0, FACTS Control Platform (FCP) version 4.1.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Follow general mitigation factors.</p>\n<p>For more information see the associated Hitachi Energy security advisory <a href=\"https://publisher.hitachienergy.com/preview?DocumentID=8DBD000229&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=launch\">8DBD000229</a>.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/943.html\">CWE-943 Improper Neutralization of Special Elements in Data Query Logic</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.9</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2024-3980</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The FACTS Control system with GWS allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files or other files that are critical to the application.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2024-3980\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Hitachi Energy FACTS Control Platform (FCP)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Hitachi Energy</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>FACTS Control Platform (FCP) version 3.4.0, FACTS Control Platform (FCP) version 3.7.0, FACTS Control Platform (FCP) version 3.8.0, FACTS Control Platform (FCP) version 3.10.0, FACTS Control Platform (FCP) version 3.12.0, FACTS Control Platform (FCP) version 3.14.0, FACTS Control Platform (FCP) version 3.15.0, FACTS Control Platform (FCP) version 4.0.0, FACTS Control Platform (FCP) version 4.0.1, FACTS Control Platform (FCP) version 4.1.0, FACTS Control Platform (FCP) version 4.1.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Follow general mitigation factors.</p>\n<p>For more information see the associated Hitachi Energy security advisory <a href=\"https://publisher.hitachienergy.com/preview?DocumentID=8DBD000229&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=launch\">8DBD000229</a>.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/22.html\">CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.9</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2024-3982</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An attacker with local access to machine where FACTS Control system with GWS is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. Note: By default, the session logging level is not enabled and only users with administrator rights can enable it.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2024-3982\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Hitachi Energy FACTS Control Platform (FCP)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Hitachi Energy</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>FACTS Control Platform (FCP) version 3.10.0, FACTS Control Platform (FCP) version 3.12.0, FACTS Control Platform (FCP) version 3.14.0, FACTS Control Platform (FCP) version 3.15.0, FACTS Control Platform (FCP) version 4.0.0, FACTS Control Platform (FCP) version 4.0.1, FACTS Control Platform (FCP) version 4.1.0, FACTS Control Platform (FCP) version 4.1.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Follow general mitigation factors.</p>\n<p>For more information see the associated Hitachi Energy security advisory <a href=\"https://publisher.hitachienergy.com/preview?DocumentID=8DBD000229&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=launch\">8DBD000229</a>.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/294.html\">CWE-294 Authentication Bypass by Capture-replay</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2024-7940</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The FACTS Control system with GWS product exposes a service that is intended for local only to all network interfaces without any authentication.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2024-7940\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Hitachi Energy FACTS Control Platform (FCP)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Hitachi Energy</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>FACTS Control Platform (FCP) version 3.14.0, FACTS Control Platform (FCP) version 3.15.0, FACTS Control Platform (FCP) version 4.0.0, FACTS Control Platform (FCP) version 4.0.1, FACTS Control Platform (FCP) version 4.1.0, FACTS Control Platform (FCP) version 4.1.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Follow general mitigation factors.</p>\n<p>For more information see the associated Hitachi Energy security advisory <a href=\"https://publisher.hitachienergy.com/preview?DocumentID=8DBD000229&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=launch\">8DBD000229</a>.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2024-7941</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A vulnerability exists in FACTS Control system with GWS where a HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2024-7941\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Hitachi Energy FACTS Control Platform (FCP)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Hitachi Energy</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>FACTS Control Platform (FCP) version 3.15.0, FACTS Control Platform (FCP) version 4.1.0, FACTS Control Platform (FCP) version 4.1.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Follow general mitigation factors.</p>\n<p>For more information see the associated Hitachi Energy security advisory <a href=\"https://publisher.hitachienergy.com/preview?DocumentID=8DBD000229&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=launch\">8DBD000229</a>.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/601.html\">CWE-601 URL Redirection to Untrusted Site ('Open Redirect')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>4.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Hitachi Energy reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>Notice</h2>\n<p>The information in this document is subject to change without notice and should not be construed as a commitment by Hitachi Energy. Hitachi Energy provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall Hitachi Energy or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if Hitachi Energy or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from Hitachi Energy and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners.</p>\n<hr>\n<h2>Support</h2>\n<p>For additional information and support please contact your product provider or Hitachi Energy service organization. For contact information, see <a href=\"https://www.hitachienergy.com/contact-us/\">https://www.hitachienergy.com/contact-us/</a> for Hitachi Energy contact-centers.</p>\n<hr>\n<h2>General Mitigation Factors</h2>\n<p>Recommended security practices and firewall configurations can help protect a process control network from attacks that originate from outside the network. Such practices include that process control systems are physically protected from direct access by unauthorized personnel, have no direct connections to the Internet, and are separated from other networks by means of a firewall system that has a minimal number of ports exposed, and others that have to be evaluated case by case. Process control systems should not be used for Internet surfing, instant messaging, or receiving e-mails. Portable computers and removable storage media should be carefully scanned for viruses before they are connected to a control system. Proper password policies and processes should be followed. Additional information on Industrial Control Systems Cybersecurity Best Practices can be found in the Hitachi Energy \u201cIndustrial Control Systems Cybersecurity Best Practices\u201d Cybersecurity Notification. [1]</p>\n<hr>\n<h2>SSVC</h2>\n<p>SSVCv2/E:N/A:N/2026-07-24T09:43:32Z/</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (<a href=\"https://www.cisa.gov/privacy-policy\">https://www.cisa.gov/privacy-policy</a>).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>\n<ul>\n<li>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</li>\n<li>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</li>\n<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</li>\n</ul>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Hitachi Energy PSIRT <a href=\"https://publisher.hitachienergy.com/preview?documentid=8dbd000229&amp;languagecode=en&amp;documentpartid=&amp;action=launch\">8DBD000229 </a>from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Hitachi Energy PSIRT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-28</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-28</td>\n<td>1</td>\n<td>Initial public release</td>\n</tr>\n<tr>\n<td>2026-09-17</td>\n<td>2</td>\n<td>Initial CISA Republication of Hitachi Energy PSIRT 8DBD000229 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 17 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 17 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-02",
        "title": "Mitsubishi Electric GX Works3 and Motion Control Setting",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-260-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, destroy, or delete control programs.</strong></p>\n<p>The following versions of Mitsubishi Electric GX Works3 and Motion Control Setting are affected:</p>\n<ul>\n<li>Mitsubishi Electric GX Works3 vers:all/* (CVE-2026-15688)</li>\n<li>Mitsubishi Electric Motion Control Setting (Software packaged with GX Works3) vers:all/* (CVE-2026-15688)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.8</td>\n<td>Mitsubishi Electric</td>\n<td>Mitsubishi Electric GX Works3 and Motion Control Setting</td>\n<td>Incorrect Implementation of Authentication Algorithm</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Japan</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-15688</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Incorrect Implementation of Authentication Algorithm (CWE-303) vulnerability in the affected products allows a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, destroy, or delete control programs.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-15688\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Mitsubishi Electric GX Works3 and Motion Control Setting</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Mitsubishi Electric</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Mitsubishi Electric GX Works3: vers:all/*, Mitsubishi Electric Motion Control Setting (Software packaged with GX Works3): vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Workaround</strong><br>For customers using GX Works3, please download version 1.096A or later from the link https://www.mitsubishielectric.com/fa/download/software/detailsearch.page?mode=software&amp;kisyu=/plceng&amp;shiryoid=1000001411&amp;lang=2&amp;select=0&amp;softid=1&amp;infostatus=1_2_1&amp;viewradio=0&amp;viewstatus=&amp;viewpos=, install it, and set the security version for projects to \"2\". Please refer to \u201c15.9 Preventing Illegal Access to/Falsification of Data (Security Version)\u201d in \u201cGX Works3 Operating Manual\u201d for details. For more information about the workaround, refer to the Mitsubishi Electric security advisory available at \"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-007_en.pdf\".<br><a href=\"https://www.mitsubishielectric.com/fa/download/software/detailsearch.page?mode=software&amp;kisyu=/plceng&amp;shiryoid=1000001411&amp;lang=2&amp;select=0&amp;softid=1&amp;infostatus=1_2_1&amp;viewradio=0&amp;viewstatus=&amp;viewpos=\">https://www.mitsubishielectric.com/fa/download/software/detailsearch.page?mode=software&amp;kisyu=/plceng&amp;shiryoid=1000001411&amp;lang=2&amp;select=0&amp;softid=1&amp;infostatus=1_2_1&amp;viewradio=0&amp;viewstatus=&amp;viewpos=</a></p>\n<p><strong>Workaround</strong><br>For customers using Motion Control Setting (Software packaged with GX Works3), Please download version 1.070Y or later from the link \"https://www.mitsubishielectric.com/fa/download/software/detailsearch.page?mode=software&amp;kisyu=/ssc&amp;shiryoid=1000000803&amp;lang=2&amp;select=0&amp;softid=1&amp;infostatus=1_8_1&amp;viewradio=0&amp;viewstatus=&amp;viewpos=\", install it, and set the security version for projects to \"2\". Please refer to \u201c12.5 Preventing Illegal Access to/Falsification of Data (Security Version)\u201d in \u201cMotion Control Setting Function Help\u201d for details. For more information about the workaround, refer to the Mitsubishi Electric security advisory at \"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-007_en.pdf\".<br><a href=\"https://www.mitsubishielectric.com/fa/download/software/detailsearch.page?mode=software&amp;kisyu=/ssc&amp;shiryoid=1000000803&amp;lang=2&amp;select=0&amp;softid=1&amp;infostatus=1_8_1&amp;viewradio=0&amp;viewstatus=&amp;viewpos=\">https://www.mitsubishielectric.com/fa/download/software/detailsearch.page?mode=software&amp;kisyu=/ssc&amp;shiryoid=1000000803&amp;lang=2&amp;select=0&amp;softid=1&amp;infostatus=1_8_1&amp;viewradio=0&amp;viewstatus=&amp;viewpos=</a></p>\n<p><strong>Mitigation</strong><br>For customers of the affected products, Mitsubishi Electric recommends using a computer with the affected product within a LAN and blocking remote logins from untrusted networks, hosts, and users, to minimize the risk of exploiting this vulnerability.</p>\n<p><strong>Mitigation</strong><br>For customers of the affected products, Mitsubishi Electric recommends using a firewall, virtual private network (VPN), etc., to prevent unauthorized access, and allowing remote login only to trusted users when connecting a computer with the affected product to the Internet, to minimize the risk of exploiting this vulnerability.</p>\n<p><strong>Mitigation</strong><br>For customers of the affected products, Mitsubishi Electric recommends preventing the user from clicking on web links contained in emails or other messages from untrusted sources, or from opening attachments in untrusted emails, to minimize the risk of exploiting this vulnerability.</p>\n<p><strong>Mitigation</strong><br>For customers of the affected products, Mitsubishi Electric recommends installing antivirus software on a computer running the affected product, to minimize the risk of exploiting this vulnerability.</p>\n<p><strong>Mitigation</strong><br>For customers of the affected products, Mitsubishi Electric recommends restricting physical access to a computer on which the affected product is installed, as well as to computers and network devices that can communicate with it, to minimize the risk of exploiting this vulnerability.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/303.html\">CWE-303 Incorrect Implementation of Authentication Algorithm</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.2</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:H/SA:H\">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:H/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Mayeul Fargier, Erwan Cordier, and No\u00e9 Flatreaud reported this vulnerability to Mitsubishi Electric</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Mitsubishi Electric 2026-007 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Mitsubishi Electric directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-17</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-17</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n<tr>\n<td>2026-09-17</td>\n<td>2</td>\n<td>Initial CISA Republication of Mitsubishi Electric 2026-007 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 17 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 17 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-06",
        "title": "ABB Ability Edgenius",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-06",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-260-06.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>ABB is aware of public reports of a vulnerability CVE\u20112026\u201131431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE\u20112026\u201131431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete control of the system</strong></p>\n<p>The following versions of ABB Ability Edgenius are affected:</p>\n<ul>\n<li>Ability Edgenius &gt;=3.2.0.0|&lt;3.2.4.1, 3.2.4.1 (CVE-2026-31431)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.8</td>\n<td>ABB</td>\n<td>ABB Ability Edgenius</td>\n<td>Incorrect Resource Transfer Between Spheres</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy, Water and Wastewater, Chemical</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Switzerland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-31431</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. The issue originates in the Linux kernel\u2019s cryptographic subsystem and impacts kernels used by most major Linux distributions released since 2017.Successful exploitation requires local code execution, however, in shared, containerized, or multi\u2011tenant environments this may increase the security risk.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-31431\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB Ability Edgenius</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB Ability Edgenius &gt;=3.2.0.0|&lt;3.2.4.1 installed on ABB Ability Edgenius Gateway - bE100</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>fixed, known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>The problem is corrected in the following product versions: - Edgenius 3.2.4.1 ABB recommends that customers apply the update at earliest convenience.</p>\n<p><strong>Mitigation</strong><br>Mitigating factors describe conditions and circumstances that make an attack that exploits the vulnerability difficult or less likely to succeed. Refer to section General security recommendations for further advise on how to keep your system secure. Recommended mitigation factors - Limit access to ssh or cockpit - By default, no additional lower privilege users are present on Edgenius installations.</p>\n<p><strong>Mitigation</strong></p>\n<p>For more information see the associated ABB PSIRT security advisory 7PAA024620 <a href=\"https://search.abb.com/library/Download.aspx?DocumentID=7PAA024620&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB CYBERSECURITY ADVISORY - PDF Version </a>, <a href=\"https://psirt.abb.com/csaf/2026/7paa024620.json\">ABB CYBERSECURITY ADVISORY - CSAF Version </a>.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/669.html\">CWE-669 Incorrect Resource Transfer Between Spheres</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>ABB PSIRT reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>Notice</h2>\n<p>The information in this document is subject to change without notice, and should not be construed as a commitment by ABB. ABB provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall ABB or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if ABB or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from ABB, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners.</p>\n<hr>\n<h2>Frequently Asked Questions</h2>\n<p>What causes the vulnerability? - A flaw was found in the Linux kernel's algif_aead cryptographic algorithm interface. An incorrect 'in-place operation' was introduced, where the source and destination data mappings were different. This could lead to unexpected behavior or data integrity issues during cryptographic operations, potentially impacting the reliability of encrypted communications. What is Edgenius? - ABB Ability\u2122 Edgenius is an edge computing platform that - Connects to control systems, devices, and equipment - Collects and contextualizes operational data - Hosts applications that deliver real-time insights and AI-driven recommendations What might an attacker use the vulnerability to do? - Successful exploitation could enable a local user attacker to gain administrative control of the system node, execute arbitrary code, or cause the node to become unavailable. How could an attacker exploit the vulnerability? - An attacker could exploit this vulnerability after obtaining local access to the system. By invoking the Linux kernel\u2019s affected cryptographic interface (algif_aead), the attacker can trigger incorrect memory handling in the kernel. This allows the attacker to escalate privileges from a normal user to full administrative (root) access on the affected system node Could the vulnerability be exploited remotely? - No, to exploit this vulnerability an attacker would need to have local access (physical access or through valid SSH credentials) to an affected system node. What does the update do? - The update resolves the issue by incorporating the security update of the Linux kernel. When this security advisory was issued, had this vulnerability been publicly disclosed? - Yes, this vulnerability has been publicly disclosed. When this security advisory was issued, had ABB received any reports that this vulnerability was being exploited? - No, ABB had not received any information indicating that this vulnerability had been exploited for Edgenius when this security advisory was originally issued.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<ul>\n<li>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</li>\n<li>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</li>\n<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</li>\n</ul>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of ABB PSIRT <a href=\"https://search.abb.com/library/download.aspx?documentid=7paa024620&amp;languagecode=en&amp;documentpartid=&amp;action=launch\">7PAA024620</a> from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-06-25</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-06-25</td>\n<td>1</td>\n<td>Initial version.</td>\n</tr>\n<tr>\n<td>2026-09-17</td>\n<td>2</td>\n<td>Initial CISA Republication of ABB PSIRT 7PAA024620 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 17 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 17 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-07",
        "title": "Schneider Electric PowerChute Serial Shutdown",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-07",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-260-07.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Schneider Electric is aware of vulnerabilities in its PowerChute Serial Shutdown product. The PowerChute Serial Shutdown product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktops, servers and workstations. Failure to apply the remediation provided below may risk improper authentication validation which could result in disruption of operations and access to system data.</strong></p>\n<p>The following versions of Schneider Electric PowerChute Serial Shutdown are affected:</p>\n<ul>\n<li>PowerChute Serial Shutdown vers:intdot/&lt;=1.5, 1.6 (CVE-2026-13348)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 5.3</td>\n<td>Schneider Electric</td>\n<td>Schneider Electric PowerChute Serial Shutdown</td>\n<td>Improper Restriction of Excessive Authentication Attempts</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Commercial Facilities, Critical Manufacturing, Energy, Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>France</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-13348</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an arbitrary number of authentication attempts when redirect handling is disabled.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-13348\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Schneider Electric PowerChute Serial Shutdown</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Schneider Electric</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>PowerChute Serial Shutdown Version 1.5 and prior</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>fixed, known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Version v1.6 of PowerChute Serial Shutdown includes a fix for these vulnerabilities and is available for download here: \u2022 Windows: <a href=\"https://www.se.com/ww/en/download/document/spd-pcss_win_en/\">https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/</a> Reboot needed: Upon installation, the service is automatically restarted. A customer can validate a successful install by checking the version information in the Control Panel or on the About page within PCSS after logging in. Specific instructions and hardening guidelines for these remediations can be found in the <a href=\"https://www.se.com/ww/en/download/document/spd-pcss_win_en/\">Security Handbook</a>.<br>&nbsp;</p>\n<p><strong>Vendor fix</strong><br>Version v1.6 of PowerChute Serial Shutdown includes a fix for these vulnerabilities and is available for download here: \u2022 Linux: <a href=\"https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/\">https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/</a> Reboot needed: Upon installation, the service is automatically restarted. A customer can validate a successful install by checking the version information in the Control Panel or on the About page within PCSS after logging in. Specific instructions and hardening guidelines for these remediations can be found in the <a href=\"https://www.se.com/ww/en/download/document/spd-pcss_win_en/\">Security Handbook</a>.</p>\n<p>For more information see the associated Schneider Electric security advisory <a href=\"https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-223-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=sevd-2026-223-01.json\">Improper Restriction of Excessive Authentication Attempts vulnerability on PowerChute Serial Shutdown - SEVD-2026-223-01 CSAF Version</a>, <a href=\"https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-223-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-223-01.pdf\">Improper Restriction of Excessive Authentication Attempts vulnerability on PowerChute Serial Shutdown - SEVD-2026-223-01 PDF Version</a>.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/307.html\">CWE-307 Improper Restriction of Excessive Authentication Attempts</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Schneider Electric CPCERT reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>General Security Recommendations</h2>\n<p>Schneider Electric strongly recommends the following industry cybersecurity best practices.&nbsp;</p>\n<ul>\n<li>Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.&nbsp;</li>\n<li>Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.&nbsp;</li>\n<li>Place all controllers in locked cabinets and never leave them in the \u201cProgram\u201d mode.&nbsp;</li>\n<li>Never connect programming software to any network other than the network intended for that device.&nbsp;</li>\n<li>Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.&nbsp;</li>\n<li>Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.&nbsp;</li>\n<li>Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.&nbsp;</li>\n<li>When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.&nbsp;</li>\n</ul>\n<p>For more information refer to the <a href=\"https://www.se.com/us/en/download/document/7EN52-0390/%20\">Schneider Electric Recommended Cybersecurity Best Practices document</a>.</p>\n<hr>\n<h2>For More Information</h2>\n<p>This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: <a href=\"https://www.se.com/ww/en/work/solutions/cybersecurity/\">https://www.se.com/ww/en/work/solutions/cybersecurity/</a>. These organizations will be fully aware of this situation and can support you through the process. For further information related to cybersecurity in Schneider Electric\u2019s products, visit the company\u2019s cybersecurity support portal page: <a href=\"https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp\">https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp</a></p>\n<hr>\n<h2>LEGAL DISCLAIMER</h2>\n<p>THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS \u201cNOTIFICATION\u201d) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN \u201cAS-IS\u201d BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION</p>\n<hr>\n<h2>About Schneider Electric</h2>\n<p>Schneider's purpose is to create Impact by empowering all to make the most of our energy and resources, bridging progress and sustainability for all. We call this Life Is On. Our mission is to be the trusted partner in Sustainability and Efficiency. We are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart industries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep domain expertise, we provide integrated end-to-end lifecycle AI enabled Industrial IoT solutions with connected products, automation, software and services, delivering digital twins to enable profitable growth for our customers. We are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries to ensure proximity to our customers and stakeholders. We embrace diversity and inclusion in everything we do, guided by our meaningful purpose of a sustainable future for all. www.se.com</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (<a href=\"https://www.cisa.gov/privacy-policy\">https://www.cisa.gov/privacy-policy</a>).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<ul>\n<li>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</li>\n<li>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</li>\n<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</li>\n</ul>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Schneider Electric CPCERT <a href=\"https://download.schneider-electric.com/files?p_doc_ref=sevd-2026-223-01&amp;p_endoctype=security+and+safety+notice&amp;p_file_name=sevd-2026-223-01.pdf\">SEVD-2026-223-01</a> from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-11</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-11</td>\n<td>1</td>\n<td>Original Release</td>\n</tr>\n<tr>\n<td>2026-09-17</td>\n<td>2</td>\n<td>Initial CISA Republication of Schneider Electric CPCERT SEVD-2026-223-01 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 17 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 17 Sep 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-07",
        "title": "Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-07",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-07.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly.</strong></p>\n<p>The following versions of Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A) are affected:</p>\n<ul>\n<li>Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-16 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-32 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-64 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-128 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-256 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-N32 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-P32 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-N32 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-P32 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-N32 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-P32 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-8-N32 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-8-P32 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-16-N32 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-16-P32 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Master/local module RJ71GN11-T2 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Master/local module RJ71GN11-SX vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Master/local module RJ71GN11-EIP vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Master/local module FX5-CCLGN-MS vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric CC-Link IE TSN interface board NZ81GN11-SX vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric CC-Link IE TSN interface board NZ81GN11-T2 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Motion module RD78G4 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Motion module RD78G8 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Motion module RD78G16 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Motion module RD78G64 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Motion module RD78GHV vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Motion module RD78GHW vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Motion module FX5-40SSC-G vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Motion module FX5-80SSC-G vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC iQ-L Series Motion Module LD78G4 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric MELSEC iQ-L Series Motion Module LD78G16 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Motion Control Board MR-EM441G vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2S1-32D vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2S1-32T vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2S1-32TE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2S1-32DT vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2S1-32DTE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2B1-32D vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2B1-32T vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2B1-32TE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2B1-32DT vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2B1-32DTE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GNCF1-32D vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GNCF1-32T vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GNCE3-32D vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GNCE3-32DT vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN12A4-16D vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN12A4-16DE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN12A2-16T vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN12A2-16TE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN12A42-16DT vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN12A42-16DTE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2S1-16D vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2S1-16T vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2S1-16TE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2B1-16D vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2B1-16T vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module NZ2GN2B1-16TE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8D vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8D-K vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8TE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8TE-K vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-16DTE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-16DTE-K vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module with safety functions NZ2GNS12A2-14DT vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Block-type remote module with safety functions NZ2GNS12A2-16DTE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Analog-Digital converter module NZ2GN2S-60AD4 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Analog-Digital converter module NZ2GN2B-60AD4 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Digital-Analog converter module NZ2GN2S-60DA4 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Digital-Analog converter module NZ2GN2B-60DA4 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric CC-Link IE TSN compatible coupler NZ2FT-GN vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric FPGA module NZ2GN2S-D41P01 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric FPGA module NZ2GN2S-D41D01 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric FPGA module NZ2GN2S-D41PD02 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Tension meter LM7-1LG vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Tension meter LM7-2LG vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5W-G vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-HS vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-RJ vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-LL vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5D-G4 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric AC Servo MELSERVO-J5 MR-MD333G vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric AC Servo MELSERVO-JET MR-JET-G vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric AC Servo MELSERVO-JET MR-JET-G4-HS vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Liner Track System MTR-S series Linear track control module MTR-SCU00-4G vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Liner Track System MTR-S series Linear track control module MTR-SCU00-PG vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A8NCG vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A8NCG-S vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A800-GN vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-E800-E vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-E800-SCE vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Industrial Robot CR800-D series controller Network Base Card 2F-DQ535-TSN vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric CC-Link IE TSN expansion unit FCU8-EX569 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric CC-Link IE TSN-CC-Link IE Field Network bridge module NZ2GN-GFB vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric CC-Link IE TSN-AnyWireASLINK bridge module NZ2AW1GNAL vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Energy Measuring Unit CC-Link IE TSN Communication Unit EMU4-CM-TSN vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric GOT3000 Series GT3715-FHCBD vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric GOT3000 Series GT3712-WXCBD vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric GOT3000 Series GT3715-XRBA vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric GOT3000 Series GT3715-XRBD vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric GOT3000 Series GT3712-XRBA vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric GOT3000 Series GT3712-XRBD vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric GOT3000 Series GT3710-XRBA vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric GOT3000 Series GT3710-XRBD vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric GOT3000 Series GT3708-XRBA vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric GOT3000 Series GT3708-XRBD vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Communication Unit GT25-J71GN13-T2 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Motion Control Software SWM-G vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Motion Control Software SWM-G-N1 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Communication Software for Windows SW1DND-CCIETCT-M vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Analysis Support Software MELSOFT VIMA SW1DNN-VIMA-M vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Master/Local module Designated communication LSI DeviceKit NZ2KT-NPETNG51 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP620-60 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP620-300 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP621-90 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP621-720 vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric CC-Link IE TSN Master/Local module Designated communication LSI SDK SW1DNN-GN610SRC-M vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Remote station software development kit SW1DNC-GNSDK1S-M vers:all/* (CVE-2026-13584)</li>\n<li>Mitsubishi Electric Remote station software development kit SW1DNC-GNSDK2S-M vers:all/* (CVE-2026-13584)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.1</td>\n<td>Mitsubishi Electric</td>\n<td>Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)</td>\n<td>Improper Enforcement of Message Integrity During Transmission in a Communication Channel</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Japan</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-13584</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Improper Enforcement of Message Integrity During Transmission in a Communication Channel (CWE-924) vulnerability exists in the CC-Link IE TSN communication protocol. This vulnerability could allow an attacker with access to the same network segment to tamper with communication data, such as control input and output values, by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-13584\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Mitsubishi Electric</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-16: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-64: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-128: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-256: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-N32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-P32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-N32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-P32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-N32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-P32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-8-N32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-8-P32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-16-N32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-16-P32: vers:all/*, Mitsubishi Electric Master/local module RJ71GN11-T2: vers:all/*, Mitsubishi Electric Master/local module RJ71GN11-SX: vers:all/*, Mitsubishi Electric Master/local module RJ71GN11-EIP: vers:all/*, Mitsubishi Electric Master/local module FX5-CCLGN-MS: vers:all/*, Mitsubishi Electric CC-Link IE TSN interface board NZ81GN11-SX: vers:all/*, Mitsubishi Electric CC-Link IE TSN interface board NZ81GN11-T2: vers:all/*, Mitsubishi Electric Motion module RD78G4: vers:all/*, Mitsubishi Electric Motion module RD78G8: vers:all/*, Mitsubishi Electric Motion module RD78G16: vers:all/*, Mitsubishi Electric Motion module RD78G64: vers:all/*, Mitsubishi Electric Motion module RD78GHV: vers:all/*, Mitsubishi Electric Motion module RD78GHW: vers:all/*, Mitsubishi Electric Motion module FX5-40SSC-G: vers:all/*, Mitsubishi Electric Motion module FX5-80SSC-G: vers:all/*, Mitsubishi Electric MELSEC iQ-L Series Motion Module LD78G4: vers:all/*, Mitsubishi Electric MELSEC iQ-L Series Motion Module LD78G16: vers:all/*, Mitsubishi Electric Motion Control Board MR-EM441G: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-32D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-32T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-32TE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-32DT: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-32DTE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-32D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-32T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-32TE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-32DT: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-32DTE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GNCF1-32D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GNCF1-32T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GNCE3-32D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GNCE3-32DT: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A4-16D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A4-16DE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A2-16T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A2-16TE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A42-16DT: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A42-16DTE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-16D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-16T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-16TE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-16D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-16T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-16TE: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8D: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8D-K: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8TE: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8TE-K: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-16DTE: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-16DTE-K: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNS12A2-14DT: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNS12A2-16DTE: vers:all/*, Mitsubishi Electric Analog-Digital converter module NZ2GN2S-60AD4: vers:all/*, Mitsubishi Electric Analog-Digital converter module NZ2GN2B-60AD4: vers:all/*, Mitsubishi Electric Digital-Analog converter module NZ2GN2S-60DA4: vers:all/*, Mitsubishi Electric Digital-Analog converter module NZ2GN2B-60DA4: vers:all/*, Mitsubishi Electric CC-Link IE TSN compatible coupler NZ2FT-GN: vers:all/*, Mitsubishi Electric FPGA module NZ2GN2S-D41P01: vers:all/*, Mitsubishi Electric FPGA module NZ2GN2S-D41D01: vers:all/*, Mitsubishi Electric FPGA module NZ2GN2S-D41PD02: vers:all/*, Mitsubishi Electric Tension meter LM7-1LG: vers:all/*, Mitsubishi Electric Tension meter LM7-2LG: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5W-G: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-HS: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-RJ: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-LL: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5D-G4 : vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-MD333G: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-JET MR-JET-G: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-JET MR-JET-G4-HS: vers:all/*, Mitsubishi Electric Liner Track System MTR-S series Linear track control module MTR-SCU00-4G: vers:all/*, Mitsubishi Electric Liner Track System MTR-S series Linear track control module MTR-SCU00-PG: vers:all/*, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A8NCG: vers:all/*, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A8NCG-S: vers:all/*, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A800-GN: vers:all/*, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-E800-E: vers:all/*, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-E800-SCE: vers:all/*, Mitsubishi Electric Industrial Robot CR800-D series controller Network Base Card 2F-DQ535-TSN: vers:all/*, Mitsubishi Electric CC-Link IE TSN expansion unit FCU8-EX569: vers:all/*, Mitsubishi Electric CC-Link IE TSN-CC-Link IE Field Network bridge module NZ2GN-GFB: vers:all/*, Mitsubishi Electric CC-Link IE TSN-AnyWireASLINK bridge module NZ2AW1GNAL: vers:all/*, Mitsubishi Electric Energy Measuring Unit CC-Link IE TSN Communication Unit EMU4-CM-TSN: vers:all/*, Mitsubishi Electric GOT3000 Series GT3715-FHCBD: vers:all/*, Mitsubishi Electric GOT3000 Series GT3712-WXCBD: vers:all/*, Mitsubishi Electric GOT3000 Series GT3715-XRBA: vers:all/*, Mitsubishi Electric GOT3000 Series GT3715-XRBD: vers:all/*, Mitsubishi Electric GOT3000 Series GT3712-XRBA: vers:all/*, Mitsubishi Electric GOT3000 Series GT3712-XRBD: vers:all/*, Mitsubishi Electric GOT3000 Series GT3710-XRBA: vers:all/*, Mitsubishi Electric GOT3000 Series GT3710-XRBD: vers:all/*, Mitsubishi Electric GOT3000 Series GT3708-XRBA: vers:all/*, Mitsubishi Electric GOT3000 Series GT3708-XRBD: vers:all/*, Mitsubishi Electric CC-Link IE TSN Communication Unit GT25-J71GN13-T2: vers:all/*, Mitsubishi Electric Motion Control Software SWM-G: vers:all/*, Mitsubishi Electric Motion Control Software SWM-G-N1: vers:all/*, Mitsubishi Electric CC-Link IE TSN Communication Software for Windows SW1DND-CCIETCT-M: vers:all/*, Mitsubishi Electric Analysis Support Software MELSOFT VIMA SW1DNN-VIMA-M: vers:all/*, Mitsubishi Electric Master/Local module Designated communication LSI DeviceKit NZ2KT-NPETNG51: vers:all/*, Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP620-60: vers:all/*, Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP620-300: vers:all/*, Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP621-90: vers:all/*, Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP621-720: vers:all/*, Mitsubishi Electric CC-Link IE TSN Master/Local module Designated communication LSI SDK SW1DNN-GN610SRC-M: vers:all/*, Mitsubishi Electric Remote station software development kit SW1DNC-GNSDK1S-M: vers:all/*, Mitsubishi Electric Remote station software development kit SW1DNC-GNSDK2S-M: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>No fix planned</strong><br>For customers using the affected products, please refer to Mitsubishi Electric's security advisory, \"<a href=\"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-005_en.pdf\">https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-005_en.pdf</a>\" and take the measures described there.<br>&nbsp;</p>\n<p><strong>Mitigation</strong><br>For customers of the affected products, Mitsubishi Electric recommends restricting physical access to the affected products and the CC-Link IE TSN network to which the affected products are connected by taking measures such as the following: (a) managing access to and from the site where the affected products are installed, (b) locking the control panel in which the affected products and/or the network devices are installed, and (c) locking the Ethernet ports such as with port lock accessories, to minimize the risk of exploitation of this vulnerability.</p>\n<p><strong>Mitigation</strong><br>For customers of the affected products, Mitsubishi Electric recommends using the affected products within a trusted network where communication with untrusted networks and hosts is blocked by a firewall or similar measures, to minimize the risk of exploitation of this vulnerability.</p>\n<p><strong>Mitigation</strong><br>For customers of the affected products, Mitsubishi Electric recommends appropriately configuring credentials and access privileges for network devices installed at the boundary between trusted networks and external networks, to minimize the risk of exploitation of this vulnerability.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/924.html\">CWE-924 Improper Enforcement of Message Integrity During Transmission in a Communication Channel</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Alessandro Di Pinto, Giovanni Dini Gentilini, Luca Cremona, Gabriele Quagliarella of Nozomi Networks, Inc. reported this vulnerability to Mitsubishi Electric.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (<a href=\"https://www.cisa.gov/privacy-policy\">https://www.cisa.gov/privacy-policy</a>).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<ul>\n<li>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</li>\n<li>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</li>\n<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</li>\n</ul>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Mitsubishi Electric <a href=\"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-005_en.pdf\">2026-005</a> from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Mitsubishi Electric directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-30</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-30</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n<tr>\n<td>2026-07-30</td>\n<td>2</td>\n<td>CISA Republication - Initial CISA Republication of Mitsubishi Electric 2026-005 advisory</td>\n</tr>\n<tr>\n<td>2026-09-17</td>\n<td>3</td>\n<td>MXF100S-N32, MXF100S-P32, MXF100S-8-N32, MXF100S-8-P32, MXF100S-16-N32, MXF100S-16-P32, LD78G4, and LD78G16 have been added as affected products and MI2532-W, MI2332-W, and NZ2GACP610-60 have been removed from affected products.</td>\n</tr>\n<tr>\n<td>2026-09-17</td>\n<td>4</td>\n<td>CISA Republication update based on Mitsubishi Electric 2026-005 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 17 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 17 Sep 26 12:00:00 +0000"
    }
]