[
    {
        "id": "/node/25569",
        "title": "Armatura LLC Armatura One",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01",
        "summary": "View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system. The following versions of Armatura LLC Armatura One are affected: Armatura One",
        "summary_is_html": false,
        "first_seen": "Thu, 01 Oct 26 12:00:00 +0000",
        "last_updated": "Thu, 01 Oct 26 12:00:00 +0000"
    },
    {
        "id": "/node/25575",
        "title": "Meari IoT Cloud Platform OpenAPI Service",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-06",
        "summary": "View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data without proper authorization. The following versions of Meari IoT Cloud Platform OpenAPI Service are affected: IoT Cloud Platform OpenAPI Service vers:all/* (CVE-2026-101104, CVE-2026-96613) CVSS Vendor Equipment Vulnerabilities v3 7.7 Meari Meari IoT Cloud Platform OpenAPI Service Missing Authorization Background Critical Infrastructure Sectors: Commercial Facilities, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-101104 The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors, without verifying ownership or permissions. View CVE Details Affected Products Meari IoT Cloud Platform OpenAPI Service Vendor: Meari Product Version: Meari IoT Cloud Platform OpenAPI Service: vers:all/* Product Status: known_affected Remediations No fix planned Meari did not respond to CISA's coordination attempts. IoT Cloud Platform OpenAPI users are advised to contact Meari for support https://www.meari.com/en/downLoadCenter. Relevant CWE: CWE-862 Missing Authorization Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.7 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N 4.0 6.3 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N CVE-2026-96613 The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shadow of any device by specifying its device ID. This vulnerability exposes sensitive information, such as device credentials, owner details, network data, and telemetry, without verifying any relationship between the requester and the target device. View CVE Details Affected Products Meari IoT Cloud Platform OpenAPI Service Vendor: Meari Product Version: Meari IoT Cloud Platform OpenAPI Service: vers:all/* Product Status: known_affected Remediations No fix planned Meari did not respond to CISA's coordination attempts. IoT Cloud Platform OpenAPI users are advised to contact Meari for support https://www.meari.com/en/downLoadCenter. Relevant CWE: CWE-862 Missing Authorization Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N 4.0 7.1 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Acknowledgments Gabriel Adams reported these vulnerabilities to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-10-01 Date Revision Summary 2026-10-01 1 Initial Publication Legal Notice and Terms of Use",
        "summary_is_html": false,
        "first_seen": "Thu, 01 Oct 26 12:00:00 +0000",
        "last_updated": "Thu, 01 Oct 26 12:00:00 +0000"
    },
    {
        "id": "/node/25570",
        "title": "Monta monta.app",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-02",
        "summary": "View CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks. The following versions of Monta monta.app are affected: monta.app vers:all/* (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474) CVSS Vendor Equipment Vulnerabilities v3 9.4 Monta Monta monta.app Missing Authentication for Critical Function, Improper Restriction of Excessive Authentication Attempts, Insufficient Session Expiration, Insufficiently Protected Credentials Background Critical Infrastructure Sectors: Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Netherlands Vulnerabilities Expand All + CVE-2026-95102 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system. View CVE Details Affected Products Monta monta.app Vendor: Monta Product Version: Monta monta.app: vers:all/* Product Status: known_affected Remediations Mitigation Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) and encourage operators to enable it. Mitigation Monta states that they have implemented rate limiting and automated connection throttling at the WebSocket layer. Connections exhibiting abusive patterns, including rapid reconnection, ID brute-forcing behavior, or excessive command volume, are automatically identified and blocked. Mitigation Monta states that their platform handles duplicate connection attempts per the OCPP specification, where a new authenticated connection supersedes an existing session for the same station ID. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.4 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L 4.0 9.3 CRITICAL https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N CVE-2026-97363 The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access. View CVE Details Affected Products Monta monta.app Vendor: Monta Product Version: Monta monta.app: vers:all/* Product Status: known_affected Remediations Mitigation Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) and encourage operators to enable it. Mitigation Monta states that they have implemented rate limiting and automated connection throttling at the WebSocket layer. Connections exhibiting abusive patterns, including rapid reconnection, ID brute-forcing behavior, or excessive command volume, are automatically identified and blocked. Mitigation Monta states that their platform handles duplicate connection attempts per the OCPP specification, where a new authenticated connection supersedes an existing session for the same station ID. Relevant CWE: CWE-307 Improper Restriction of Excessive Authentication Attempts Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 8.7 HIGH https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-97212 The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests. View CVE Details Affected Products Monta monta.app Vendor: Monta Product Version: Monta monta.app: vers:all/* Product Status: known_affected Remediations Mitigation Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) and encourage operators to enable it. Mitigation Monta states that they have implemented rate limiting and automated connection throttling at the WebSocket layer. Connections exhibiting abusive patterns, including rapid reconnection, ID brute-forcing behavior, or excessive command volume, are automatically identified and blocked. Mitigation Monta states that their platform handles duplicate connection attempts per the OCPP specification, where a new authenticated connection supersedes an existing session for the same station ID. Relevant CWE: CWE-613 Insufficient Session Expiration Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.3 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L 4.0 6.9 MEDIUM https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVE-2026-93474 Charging station authentication identifiers are publicly accessible via web-based mapping platforms. View CVE Details Affected Products Monta monta.app Vendor: Monta Product Version: Monta monta.app: vers:all/* Product Status: known_affected Remediations Mitigation Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) and encourage operators to enable it. Mitigation Monta states that they have implemented rate limiting and automated connection throttling at the WebSocket layer. Connections exhibiting abusive patterns, including rapid reconnection, ID brute-forcing behavior, or excessive command volume, are automatically identified and blocked. Mitigation Monta states that their platform handles duplicate connection attempts per the OCPP specification, where a new authenticated connection supersedes an existing session for the same station ID. Relevant CWE: CWE-522 Insufficiently Protected Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N 4.0 6.9 MEDIUM https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Acknowledgments An anonymous researcher reported these vulnerabilities to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-10-01 Date Revision Summary 2026-10-01 1 Initial Publication Legal Notice and Terms of Use",
        "summary_is_html": false,
        "first_seen": "Thu, 01 Oct 26 12:00:00 +0000",
        "last_updated": "Thu, 01 Oct 26 12:00:00 +0000"
    },
    {
        "id": "/node/25572",
        "title": "Johnson Controls EasyIO Neo Series EC and CW Controllers",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-04",
        "summary": "View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system. The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected: EasyIO Neo Series EC Controllers V3.3b63 (CVE-2026-64892) EasyIO Neo Series EC Controllers V3.3b62 (CVE-2026-64892) EasyIO Neo Series CW Controllers V3.3b25 (CVE-2026-64892) EasyIO Neo Series CW Controllers V3.3b24 (CVE-2026-64892) CVSS Vendor Equipment Vulnerabilities v3 3.5 Johnson Controls Johnson Controls EasyIO Neo Series EC and CW Controllers Exposure of Sensitive Information to an Unauthorized Actor Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-64892 Johnson Controls is aware of a vulnerability in EasyIO Neo Series EC and CW Controllers relating to an attacker gaining access to sensitive information that could be used to conduct further attacks against the system. The EC and CW are programmable edge controllers designed for building automation and control systems, used to manage and automate various building functions including HVAC, lighting, and energy management, supporting open protocols such as BACnet and Modbus for adaptable system connections. View CVE Details Affected Products Johnson Controls EasyIO Neo Series EC and CW Controllers Vendor: Johnson Controls Product Version: Johnson Controls EasyIO Neo Series EC Controllers: V3.3b63, Johnson Controls EasyIO Neo Series EC Controllers: V3.3b62, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b25, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b24 Product Status: known_affected Remediations Mitigation Johnson Controls released fixed versions for EasyIO Neo Series EC and CW Controllers. Users should upgrade to the fixed version or later as soon as operationally feasible. The fix is available in EC firmware V3.3b64 and CW firmware V3.3b26. Contact your Johnson Controls representative or authorized EasyIO distributor. Mitigation Before applying updates in production ICS/OT environments, users should review operational impact, backup relevant configurations, test updates in a non-production environment where feasible, and follow applicable change-management and safety procedures. Mitigation If immediate update is not possible, Johnson Controls recommends the following mitigations: Implement physical access controls to prevent unauthorized personnel from reaching device debug ports. Monitor network traffic to and from affected devices for unusual or unauthorized access attempts. Apply the principle of least privilege to all accounts and services that interact with the affected devices. Where possible, apply firmware updates that disable debug interfaces or require authentication before granting debug access. Implement intrusion detection/prevention systems to monitor for exploitation attempts. Refer to and follow all steps in the product hardening guide or the JCI universal hardening guide found here: https://www.johnsoncontrols.com/trust-center/cybersecurity/resources . These mitigations reduce risk but may not fully remediate the vulnerability. Users should update to the fixed versions when operationally feasible. Mitigation For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-20. https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories Relevant CWE: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor Metrics CVSS Version Base Score Base Severity Vector String 3.1 3.5 LOW CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:L 4.0 4.8 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N Acknowledgments Gabriele Gardois reported this vulnerability to Johnson Controls Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. The recommendations provided within Johnson Controls Hardening Guide should always be applied to minimize security risk. Visit the Johnson Controls Trust Center Cybersecurity website to access the latest Hardening Guidelines and cybersecurity best practices - https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories . CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-10-01 Date Revision Summary 2026-10-01 1 Initial Republication of Johnson Controls Product Security Advisory JCI-PSA-2026-20 Legal Notice and Terms of Use",
        "summary_is_html": false,
        "first_seen": "Thu, 01 Oct 26 12:00:00 +0000",
        "last_updated": "Thu, 01 Oct 26 12:00:00 +0000"
    },
    {
        "id": "/node/25579",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.",
        "summary_is_html": false,
        "first_seen": "Thu, 01 Oct 26 12:00:00 +0000",
        "last_updated": "Thu, 01 Oct 26 12:00:00 +0000"
    },
    {
        "id": "/node/25571",
        "title": "ABB Protection and Control IED Manager PCM600",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-03",
        "summary": "View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files. The following versions of ABB Protection and Control IED Manager PCM600 are affected: Protection and Control IED Manager PCM600",
        "summary_is_html": false,
        "first_seen": "Thu, 01 Oct 26 12:00:00 +0000",
        "last_updated": "Thu, 01 Oct 26 12:00:00 +0000"
    },
    {
        "id": "/node/25574",
        "title": "Johnson Controls EasyIO Neo Series EC and CW Controllers",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-05",
        "summary": "View CSAF Summary Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data. The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected: EasyIO Neo Series EC Controllers V3.3b62 (CVE-2026-64893) EasyIO Neo Series EC Controllers V3.3b63 (CVE-2026-64893) EasyIO Neo Series CW Controllers V3.3b24 (CVE-2026-64893) EasyIO Neo Series CW Controllers V3.3b25 (CVE-2026-64893) CVSS Vendor Equipment Vulnerabilities v3 5.4 Johnson Controls Johnson Controls EasyIO Neo Series EC and CW Controllers Cleartext Transmission of Sensitive Information Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-64893 Johnson Controls is aware of a vulnerability in EasyIO Neo which may allow an attacker to intercept and read sensitive information, including credentials and session data, transmitted in cleartext over the network. Successful exploitation could result in technical or operational impact. EasyIO Neo is a programmable building automation edge controller used to manage and automate HVAC, lighting, and energy systems in commercial buildings through a web-based interface. View CVE Details Affected Products Johnson Controls EasyIO Neo Series EC and CW Controllers Vendor: Johnson Controls Product Version: Johnson Controls EasyIO Neo Series EC Controllers: V3.3b62, Johnson Controls EasyIO Neo Series EC Controllers: V3.3b63, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b24, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b25 Product Status: known_affected Remediations Mitigation Johnson Controls released fixed versions for EasyIO Neo Series EC and CW Controllers. Users should upgrade to the fixed version or later as soon as operationally feasible. HTTP communication has been disabled by default in the latest version. The fix is available in EC firmware V3.3b64 andCW firmware V3.3b26. Contact your Johnson Controls representative or visitthe Johnson Controls Trust Center. Mitigation Before applying updates in production ICS/OT environments, users should review operational impact, backup relevant configurations, test updates in a non-production environment where feasible, and follow applicable change-management and safety procedures. Mitigation If immediate update is not possible, Johnson Controls recommends the following mitigations: Enable and enforce HTTPS/TLS for all web-based management access to the device. Disable HTTP access entirely. Place devices on an isolated, segmented network behind a firewall to limit exposure of management interfaces. Use a VPN when accessing devices remotely to encrypt all traffic in transit. Monitor network traffic for unencrypted sensitive data leaving the management interface. Restrict network access to management interfaces using access control lists (ACLs) to only trusted hosts. Refer to and follow all steps in the product hardening guide or the JCI universal hardening guide found here: https://www.johnsoncontrols.com/trust-center/cybersecurity/resources . These mitigations reduce risk but may not fully remediate the vulnerability. Users should update to the fixed versions when operationally feasible. Mitigation Users should review logs, network telemetry, device events, and security monitoring tools for activity involving EasyIO NEO versions EC and CW. Relevant detection information may include: Unencrypted HTTP traffic to or from the device management interface on port 80. Network captures showing cleartext credentials or session tokens in HTTP requests. Unexpected devices or IP addresses accessing the web management console. ARP spoofing or other man-in-the-middle indicators on the local network segment. Unauthorized configuration changes that may indicate credential interception. Mitigation The recommendations provided within Johnson Controls Hardening Guide should always be applied to minimize security risk. Visit the Johnson Controls Trust Center Cybersecurity website to access the latest Hardening Guidelines and cybersecurity best practices - https://www.johnsoncontrols.com/trust-center/cybersecurity/resources. https://www.johnsoncontrols.com/trust-center/cybersecurity/resources Mitigation For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-30. https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories Relevant CWE: CWE-319 Cleartext Transmission of Sensitive Information Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.4 MEDIUM CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N 4.0 5.9 MEDIUM CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N Acknowledgments Gabriele Gardois reported this vulnerability to Johnson Controls Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability has a high attack complexity. Revision History Initial Release Date: 2026-10-01 Date Revision Summary 2026-10-01 1 Initial Republication of Johnson Controls Product Security Advisory JCI-PSA-2026-30 Legal Notice and Terms of Use",
        "summary_is_html": false,
        "first_seen": "Thu, 01 Oct 26 12:00:00 +0000",
        "last_updated": "Thu, 01 Oct 26 12:00:00 +0000"
    },
    {
        "id": "/node/25576",
        "title": "CISA Malcolm",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-254-01",
        "summary": "View CSAF Summary The following versions of CISA Malcolm are affected: Malcolm CVSS Vendor Equipment Vulnerabilities v3 8.8 CISA CISA Malcolm Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Server-Side Request Forgery (SSRF), Authentication Bypass by Spoofing, Missing Authorization, Missing Authentication for Critical Function, Incorrect Authorization, Use of Default Credentials, Improper Certificate Validation, URL Redirection to Untrusted Site ('Open Redirect'), Dependency on Vulnerable Third-Party Component, Use of Password Hash With Insufficient Computational Effort Background Critical Infrastructure Sectors: Energy, Information Technology, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-90443 A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes arbitrary script in the context of the affected application and can redirect the user's browser to an arbitrary external site. Successful exploitation could allow an attacker to act with the compromised user's session privileges within the application. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm",
        "summary_is_html": false,
        "first_seen": "Thu, 01 Oct 26 12:00:00 +0000",
        "last_updated": "Thu, 01 Oct 26 12:00:00 +0000"
    },
    {
        "id": "/node/25568",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/09/30/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76504 Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.",
        "summary_is_html": false,
        "first_seen": "Wed, 30 Sep 26 12:00:00 +0000",
        "last_updated": "Wed, 30 Sep 26 12:00:00 +0000"
    },
    {
        "id": "/node/25563",
        "title": "MikroTik RouterOS",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06",
        "summary": "View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service. The following versions of MikroTik RouterOS are affected: RouterOS",
        "summary_is_html": false,
        "first_seen": "Tue, 29 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 29 Sep 26 12:00:00 +0000"
    },
    {
        "id": "/node/25558",
        "title": "Lantronix G520 Series Cellular Gateway",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-01",
        "summary": "View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to replace software and execute arbitrary code with root privileges. The following versions of Lantronix G520 Series Cellular Gateway are affected: G520 Series 2.6.0.4R6_stable (CVE-2026-84409, CVE-2026-91191) CVSS Vendor Equipment Vulnerabilities v3 7.5 Lantronix Lantronix G520 Series Cellular Gateway Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Verification of Cryptographic Signature Background Critical Infrastructure Sectors: Transportation Systems, Energy, Water and Wastewater Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-84409 The device's update mechanism retrieves metadata for software updates over an unencrypted HTTP connection and stores portions of that metadata for later use. A management interface subsequently returns this stored value in a JSON response, and the web interface responsible for displaying update information inserts that value directly into the page as HTML. This behavior allows attacker\u2011controlled metadata to be interpreted as script content. In addition, the same authenticated origin provides an interface capable of executing system\u2011level commands with root privileges. An attacker able to influence update metadata could exploit these conditions to execute arbitrary code within the administrative context of the device. View CVE Details Affected Products Lantronix G520 Series Cellular Gateway Vendor: Lantronix Product Version: Lantronix G520 Series: 2.6.0.4R6_stable Product Status: known_affected Remediations Mitigation Lantronix has addressed the reported issues with release version 2.6.0.7R6 which is available on their website. https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1889828865/Latest+firmware+for+the+G520+Series+G526+G526RP+G527+G528 Mitigation For more information, see the Lantronix Vulnerability Library. https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/ Mitigation For more information or technical assistance, contact Lantronix support: Support@lantronix.com mailto:Support@lantronix.com Relevant CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H 4.0 7.7 HIGH CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N CVE-2026-91191 The device's update mechanism includes conditions that allow unauthorized software packages to be accepted as authentic. During the boot process, the stock done function disables signature verification in the OPKG configuration before restoring optional packages from a writable, unsigned feed. Separately, the publicly distributed SDK contains the production private key whose corresponding public key is trusted by both stable and beta firmware builds. Either issue undermines package authenticity, and together they allow an attacker to provide packages that appear valid to the system. Even if signature enforcement is restored, the exposed production key enables an attacker to generate signatures that the device will continue to trust. An attacker who can supply a malicious package may be able to execute arbitrary code with root privileges during installation. View CVE Details Affected Products Lantronix G520 Series Cellular Gateway Vendor: Lantronix Product Version: Lantronix G520 Series: 2.6.0.4R6_stable Product Status: known_affected Remediations Mitigation Lantronix has addressed the reported issues with release version 2.6.0.7R6 which is available on their website. https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1889828865/Latest+firmware+for+the+G520+Series+G526+G526RP+G527+G528 Mitigation For more information, see the Lantronix Vulnerability Library. https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/ Mitigation For more information or technical assistance, contact Lantronix support: Support@lantronix.com mailto:Support@lantronix.com Relevant CWE: CWE-347 Improper Verification of Cryptographic Signature Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H 4.0 7.7 HIGH CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments Ievgen Bondarenko reported these vulnerabilities to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-09-29 Date Revision Summary 2026-09-29 1 Initial Publication Legal Notice and Terms of Use",
        "summary_is_html": false,
        "first_seen": "Tue, 29 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 29 Sep 26 12:00:00 +0000"
    },
    {
        "id": "/node/25566",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/09/29/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-86950 Apple Multiple Products Out-of-Bounds Write Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.",
        "summary_is_html": false,
        "first_seen": "Tue, 29 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 29 Sep 26 12:00:00 +0000"
    },
    {
        "id": "/node/25564",
        "title": "Viidure Dashcam Android Application",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-07",
        "summary": "View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to access, modify, or delete sensitive user data and critical system files, potentially compromising the operation of the entire platform. The following versions of Viidure Dashcam Android Application are affected: Dashcam Android Application",
        "summary_is_html": false,
        "first_seen": "Tue, 29 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 29 Sep 26 12:00:00 +0000"
    },
    {
        "id": "/node/25559",
        "title": "Toptech TMS7 and TopHAT",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02",
        "summary": "View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access critical data or execute arbitrary code. The following versions of Toptech TMS7 and TopHAT are affected: TMS7 7.6.3 (CVE-2026-71379, CVE-2026-70356, CVE-2026-72510, CVE-2026-63713, CVE-2026-68954, CVE-2026-68068, CVE-2026-72507, CVE-2026-71302, CVE-2026-69662, CVE-2026-71189) TopHAT 7.6.3 (CVE-2026-71379, CVE-2026-70356, CVE-2026-72510, CVE-2026-63713, CVE-2026-68954, CVE-2026-68068, CVE-2026-72507, CVE-2026-71302, CVE-2026-69662, CVE-2026-71189) CVSS Vendor Equipment Vulnerabilities v3 10 Toptech Systems Toptech TMS7 and TopHAT Files or Directories Accessible to External Parties, Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), Session Fixation, Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection'), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Background Critical Infrastructure Sectors: Energy, Chemical, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-71379 The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request. View CVE Details Affected Products Toptech TMS7 and TopHAT Vendor: Toptech Systems Product Version: Toptech Systems TMS7: 7.6.3, Toptech Systems TopHAT: 7.6.3 Product Status: known_affected Remediations Mitigation Toptech Systems sent a security advisory to their customers on July 20, 2026. The issues have been addressed in release 7.8. Users can get the latest release and more information on these issues, at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security Relevant CWE: CWE-552 Files or Directories Accessible to External Parties Metrics CVSS Version Base Score Base Severity Vector String 3.1 10 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 4.0 10 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVE-2026-70356 The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server. View CVE Details Affected Products Toptech TMS7 and TopHAT Vendor: Toptech Systems Product Version: Toptech Systems TMS7: 7.6.3, Toptech Systems TopHAT: 7.6.3 Product Status: known_affected Remediations Mitigation Toptech Systems sent a security advisory to their customers on July 20, 2026. The issues have been addressed in release 7.8. Users can get the latest release and more information on these issues, at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security Relevant CWE: CWE-434 Unrestricted Upload of File with Dangerous Type Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.1 CRITICAL CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H 4.0 9.4 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVE-2026-72510 The \"supplier_no\" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection. View CVE Details Affected Products Toptech TMS7 and TopHAT Vendor: Toptech Systems Product Version: Toptech Systems TMS7: 7.6.3, Toptech Systems TopHAT: 7.6.3 Product Status: known_affected Remediations Mitigation Toptech Systems sent a security advisory to their customers on July 20, 2026. The issues have been addressed in release 7.8. Users can get the latest release and more information on these issues, at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security Relevant CWE: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 9 CRITICAL CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H 4.0 8.5 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H CVE-2026-63713 The \"search\" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulnerability. View CVE Details Affected Products Toptech TMS7 and TopHAT Vendor: Toptech Systems Product Version: Toptech Systems TMS7: 7.6.3, Toptech Systems TopHAT: 7.6.3 Product Status: known_affected Remediations Mitigation Toptech Systems sent a security advisory to their customers on July 20, 2026. The issues have been addressed in release 7.8. Users can get the latest release and more information on these issues, at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security Relevant CWE: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 9 CRITICAL CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H 4.0 8.5 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H CVE-2026-68954 The \"pattern\" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability. View CVE Details Affected Products Toptech TMS7 and TopHAT Vendor: Toptech Systems Product Version: Toptech Systems TMS7: 7.6.3, Toptech Systems TopHAT: 7.6.3 Product Status: known_affected Remediations Mitigation Toptech Systems sent a security advisory to their customers on July 20, 2026. The issues have been addressed in release 7.8. Users can get the latest release and more information on these issues, at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security Relevant CWE: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 9 CRITICAL CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H 4.0 8.5 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H CVE-2026-68068 The \"screenID\" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability. View CVE Details Affected Products Toptech TMS7 and TopHAT Vendor: Toptech Systems Product Version: Toptech Systems TMS7: 7.6.3, Toptech Systems TopHAT: 7.6.3 Product Status: known_affected Remediations Mitigation Toptech Systems sent a security advisory to their customers on July 20, 2026. The issues have been addressed in release 7.8. Users can get the latest release and more information on these issues, at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security Relevant CWE: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 9 CRITICAL CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H 4.0 8.5 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H CVE-2026-72507 The \"reportType\" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability. View CVE Details Affected Products Toptech TMS7 and TopHAT Vendor: Toptech Systems Product Version: Toptech Systems TMS7: 7.6.3, Toptech Systems TopHAT: 7.6.3 Product Status: known_affected Remediations Mitigation Toptech Systems sent a security advisory to their customers on July 20, 2026. The issues have been addressed in release 7.8. Users can get the latest release and more information on these issues, at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security Relevant CWE: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 9 CRITICAL CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H 4.0 8.5 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H CVE-2026-71302 The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an attacker to predefine a session ID and reuse it after victim authentication, resulting in session takeover. View CVE Details Affected Products Toptech TMS7 and TopHAT Vendor: Toptech Systems Product Version: Toptech Systems TMS7: 7.6.3, Toptech Systems TopHAT: 7.6.3 Product Status: known_affected Remediations Mitigation Toptech Systems sent a security advisory to their customers on July 20, 2026. The issues have been addressed in release 7.8. Users can get the latest release and more information on these issues, at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security Relevant CWE: CWE-384 Session Fixation Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.1 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L 4.0 7.5 HIGH CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N CVE-2026-69662 The application uses unsafe functions that allow execution of inline scripts and string evaluation functions. View CVE Details Affected Products Toptech TMS7 and TopHAT Vendor: Toptech Systems Product Version: Toptech Systems TMS7: 7.6.3, Toptech Systems TopHAT: 7.6.3 Product Status: known_affected Remediations Mitigation Toptech Systems sent a security advisory to their customers on July 20, 2026. The issues have been addressed in release 7.8. Users can get the latest release and more information on these issues, at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security Relevant CWE: CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 3.7 LOW CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N 4.0 2.1 LOW CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVE-2026-71189 An attacker can construct a request that, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application. View CVE Details Affected Products Toptech TMS7 and TopHAT Vendor: Toptech Systems Product Version: Toptech Systems TMS7: 7.6.3, Toptech Systems TopHAT: 7.6.3 Product Status: known_affected Remediations Mitigation Toptech Systems sent a security advisory to their customers on July 20, 2026. The issues have been addressed in release 7.8. Users can get the latest release and more information on these issues, at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security Relevant CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Metrics CVSS Version Base Score Base Severity Vector String 3.1 3.5 LOW CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N 4.0 4.8 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Acknowledgments Sachin Shetty and Roy Duisters of Shell CyberDefence reported these vulnerabilities to Toptech and CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-09-29 Date Revision Summary 2026-09-29 1 Initial Publication Legal Notice and Terms of Use",
        "summary_is_html": false,
        "first_seen": "Tue, 29 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 29 Sep 26 12:00:00 +0000"
    },
    {
        "id": "/node/25562",
        "title": "Anjvision YSSD-RTMP-H5",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05",
        "summary": "View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information, access user accounts, execute OS-level commands, or take full control over the device. The following versions of Anjvision YSSD-RTMP-H5 are affected: YSSD-RTMP-H5 firmware 3.3.2.4_build_2024-12-26 (CVE-2026-100291, CVE-2026-100292, CVE-2026-100293, CVE-2026-100294, CVE-2026-100295, CVE-2026-100296, CVE-2026-100297, CVE-2026-100298, CVE-2026-100299) CVSS Vendor Equipment Vulnerabilities v3 9.8 Anjvision Anjvision YSSD-RTMP-H5 Initialization of a Resource with an Insecure Default, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Verification of Cryptographic Signature, Use of Hard-coded Credentials, Active Debug Code, Improper Check for Unusual or Exceptional Conditions, Server-Side Request Forgery (SSRF), Insufficiently Protected Credentials, Use of Weak Credentials Background Critical Infrastructure Sectors: Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-100291 In Anjvision YSSD\u2011RTMP\u2011H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations. View CVE Details Affected Products Anjvision YSSD-RTMP-H5 Vendor: Anjvision Product Version: Anjvision YSSD-RTMP-H5 firmware: 3.3.2.4_build_2024-12-26 Product Status: known_affected Remediations No fix planned Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of YSSD-RTMP-H5 are invited to contact Anjvision customer support for additional information http://www.anjvision.com/problem/list-129-cn.html . Relevant CWE: CWE-1188 Initialization of a Resource with an Insecure Default Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-100292 In Anjvision YSSD\u2011RTMP\u2011H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through an authenticated request, allowing additional commands to be sent to a backend service. Once active, this pathway can unintentionally expose system\u2011level functionality that could be misused if crafted inputs reach the underlying command handler. View CVE Details Affected Products Anjvision YSSD-RTMP-H5 Vendor: Anjvision Product Version: Anjvision YSSD-RTMP-H5 firmware: 3.3.2.4_build_2024-12-26 Product Status: known_affected Remediations No fix planned Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of YSSD-RTMP-H5 are invited to contact Anjvision customer support for additional information http://www.anjvision.com/problem/list-129-cn.html . Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-100293 In Anjvision YSSD\u2011RTMP\u2011H5 firmware version 3.3.2.4, both the local and cloud update mechanisms apply new firmware without any cryptographic verification, relying only on basic hashing. This design allows an attacker who can reach the update routine to introduce untrusted firmware images that the device will accept as valid. View CVE Details Affected Products Anjvision YSSD-RTMP-H5 Vendor: Anjvision Product Version: Anjvision YSSD-RTMP-H5 firmware: 3.3.2.4_build_2024-12-26 Product Status: known_affected Remediations No fix planned Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of YSSD-RTMP-H5 are invited to contact Anjvision customer support for additional information http://www.anjvision.com/problem/list-129-cn.html . Relevant CWE: CWE-347 Improper Verification of Cryptographic Signature Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-100294 In Anjvision YSSD\u2011RTMP\u2011H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud\u2011API credentials that are shared across deployed devices. Anyone obtaining the public firmware package can reuse these values to interact with the cloud service in ways not intended for normal operation. View CVE Details Affected Products Anjvision YSSD-RTMP-H5 Vendor: Anjvision Product Version: Anjvision YSSD-RTMP-H5 firmware: 3.3.2.4_build_2024-12-26 Product Status: known_affected Remediations No fix planned Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of YSSD-RTMP-H5 are invited to contact Anjvision customer support for additional information http://www.anjvision.com/problem/list-129-cn.html . Relevant CWE: CWE-798 Use of Hard-coded Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-100295 In Anjvision YSSD\u2011RTMP\u2011H5 firmware version 3.3.2.4, an internal debug interface can be enabled through an undocumented pathway, exposing functions not intended for normal operation. When activated, this interface allows actions that could unintentionally provide elevated system access. View CVE Details Affected Products Anjvision YSSD-RTMP-H5 Vendor: Anjvision Product Version: Anjvision YSSD-RTMP-H5 firmware: 3.3.2.4_build_2024-12-26 Product Status: known_affected Remediations No fix planned Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of YSSD-RTMP-H5 are invited to contact Anjvision customer support for additional information http://www.anjvision.com/problem/list-129-cn.html. Relevant CWE: CWE-489 Active Debug Code Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L 4.0 7.1 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-100296 In Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4, an empty-body POST to /setUserConfig, dispatched through the web server's SOAP-RPC handler, silently downgrades the administrator password to the default value and corrupts the in-memory authentication state until the device reloads. The handler does not verify the session's privilege level, so any authenticated user can trigger it. View CVE Details Affected Products Anjvision YSSD-RTMP-H5 Vendor: Anjvision Product Version: Anjvision YSSD-RTMP-H5 firmware: 3.3.2.4_build_2024-12-26 Product Status: known_affected Remediations No fix planned Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of YSSD-RTMP-H5 are invited to contact Anjvision customer support for additional information http://www.anjvision.com/problem/list-129-cn.html. Relevant CWE: CWE-754 Improper Check for Unusual or Exceptional Conditions Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.1 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H 4.0 7.2 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-100297 In Anjvision YSSD\u2011RTMP\u2011H5 firmware version 3.3.2.4, an unauthenticated network check function can be triggered to probe arbitrary hosts from the device's internal network. This may expose internal information or leak data via DNS queries. View CVE Details Affected Products Anjvision YSSD-RTMP-H5 Vendor: Anjvision Product Version: Anjvision YSSD-RTMP-H5 firmware: 3.3.2.4_build_2024-12-26 Product Status: known_affected Remediations No fix planned Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of YSSD-RTMP-H5 are invited to contact Anjvision customer support for additional information http://www.anjvision.com/problem/list-129-cn.html. Relevant CWE: CWE-918 Server-Side Request Forgery (SSRF) Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N 4.0 6.9 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-100298 In Anjvision YSSD\u2011RTMP\u2011H5 firmware version 3.3.2.4, two user\u2011information endpoints can reveal sensitive device and account details under conditions that are not intended for normal operation. View CVE Details Affected Products Anjvision YSSD-RTMP-H5 Vendor: Anjvision Product Version: Anjvision YSSD-RTMP-H5 firmware: 3.3.2.4_build_2024-12-26 Product Status: known_affected Remediations No fix planned Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of YSSD-RTMP-H5 are invited to contact Anjvision customer support for additional information http://www.anjvision.com/problem/list-129-cn.html. Relevant CWE: CWE-522 Insufficiently Protected Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-100299 In Anjvision YSSD\u2011RTMP\u2011H5 firmware version 3.3.2.4, the device includes a legacy password hash on the serial console that relies on a weak DES\u2011based encryption. View CVE Details Affected Products Anjvision YSSD-RTMP-H5 Vendor: Anjvision Product Version: Anjvision YSSD-RTMP-H5 firmware: 3.3.2.4_build_2024-12-26 Product Status: known_affected Remediations No fix planned Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of YSSD-RTMP-H5 are invited to contact Anjvision customer support for additional information http://www.anjvision.com/problem/list-129-cn.html. Relevant CWE: CWE-1391 Use of Weak Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.8 MEDIUM CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 7 HIGH CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments Andrew Lee reported these vulnerabilities to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional no_fix_planned guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and no_fix_planned Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-09-29 Date Revision Summary 2026-09-29 1 Initial Publication Legal Notice and Terms of Use",
        "summary_is_html": false,
        "first_seen": "Tue, 29 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 29 Sep 26 12:00:00 +0000"
    },
    {
        "id": "/node/25560",
        "title": "VIVOTEK Camera Firmware",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03",
        "summary": "View CSAF Summary Successful exploitation of this vulnerability may allow attackers to achieve remote command execution on affected devices, potentially with root privileges, leading to full compromise of the camera system. The following versions of VIVOTEK Camera Firmware are affected: V Series model_FD9187 (CVE-2026-22755) V Series model_FD9189 (CVE-2026-22755) V Series model_FD9365 (CVE-2026-22755) V Series model_FD9387 (CVE-2026-22755) V Series model_FD9389 (CVE-2026-22755) V Series model_FD9391 (CVE-2026-22755) C Series model_FE9180 (CVE-2026-22755) V Series model_FE9191 (CVE-2026-22755) V Series model_FE9382 (CVE-2026-22755) V Series model_FE9391 (CVE-2026-22755) V Series model_IB9365 (CVE-2026-22755) V Series model_IB9387 (CVE-2026-22755) V Series model_IB9389 (CVE-2026-22755) V Series model_IB939 (CVE-2026-22755) V Series model_IP9165 (CVE-2026-22755) V Series model_IP9171 (CVE-2026-22755) S Series model_IP9172 (CVE-2026-22755) V Series model_IP9181 (CVE-2026-22755) V Series model_IP9191 (CVE-2026-22755) V Series model_IT9389 (CVE-2026-22755) V Series model_MA9321 (CVE-2026-22755) V Series model_MA9322 (CVE-2026-22755) S Series model_MS9321 (CVE-2026-22755) V Series model_MS9390 (CVE-2026-22755) S Series model_TB9330 (CVE-2026-22755) Dome model_FD8365 (CVE-2026-22755) Dome model_FD8365v2 (CVE-2026-22755) Dome model_FD9165 (CVE-2026-22755) Dome model_FD9171 (CVE-2026-22755) Dome model_FD9371 (CVE-2026-22755) Dome model_FD9381 (CVE-2026-22755) Panoramic model_FE9181 (CVE-2026-22755) Panoramic model_FE9381 (CVE-2026-22755) VIVOTEK Camera model_FE9582 (CVE-2026-22755) VIVOTEK Camera model_IB93587LPR (CVE-2026-22755) Bullet model_IB9371 (CVE-2026-22755) Bullet model_IB9381 (CVE-2026-22755) CVSS Vendor Equipment Vulnerabilities v3 10 VIVOTEK VIVOTEK Camera Firmware Improper Neutralization of Special Elements used in a Command ('Command Injection') Background Critical Infrastructure Sectors: Government Services and Facilities, Transportation Systems, Commercial Facilities, Energy, Critical Manufacturing, Financial Services Countries/Areas Deployed: Worldwide Company Headquarters Location: Taiwan Vulnerabilities Expand All + CVE-2026-22755 A command injection vulnerability has been identified in firmware modules used by multiple network camera models from VIVOTEK. View CVE Details Affected Products VIVOTEK Camera Firmware Vendor: VIVOTEK Product Version: VIVOTEK V Series: model_FD9187, VIVOTEK V Series: model_FD9189, VIVOTEK V Series: model_FD9365, VIVOTEK V Series: model_FD9387, VIVOTEK V Series: model_FD9389, VIVOTEK V Series: model_FD9391, VIVOTEK C Series: model_FE9180, VIVOTEK V Series: model_FE9191, VIVOTEK V Series: model_FE9382, VIVOTEK V Series: model_FE9391, VIVOTEK V Series: model_IB9365, VIVOTEK V Series: model_IB9387, VIVOTEK V Series: model_IB9389, VIVOTEK V Series: model_IB939, VIVOTEK V Series: model_IP9165, VIVOTEK V Series: model_IP9171, VIVOTEK S Series: model_IP9172, VIVOTEK V Series: model_IP9181, VIVOTEK V Series: model_IP9191, VIVOTEK V Series: model_IT9389, VIVOTEK V Series: model_MA9321, VIVOTEK V Series: model_MA9322, VIVOTEK S Series: model_MS9321, VIVOTEK V Series: model_MS9390, VIVOTEK S Series: model_TB9330, VIVOTEK Dome: model_FD8365, VIVOTEK Dome: model_FD8365v2, VIVOTEK Dome: model_FD9165, VIVOTEK Dome: model_FD9171, VIVOTEK Dome: model_FD9371, VIVOTEK Dome: model_FD9381, VIVOTEK Panoramic: model_FE9181, VIVOTEK Panoramic: model_FE9381, VIVOTEK VIVOTEK Camera: model_FE9582, VIVOTEK VIVOTEK Camera: model_IB93587LPR, VIVOTEK Bullet: model_IB9371, VIVOTEK Bullet: model_IB9381 Product Status: known_affected Remediations Mitigation VIVOTEK has addressed this issue and encourages users to download and install the latest firmware available. https://www.vivotek.com/en-US/resource/download-center/software-app-vadp-package Relevant CWE: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 10 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 4.0 10 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H Acknowledgments CISA discovered a public proof of concept as authored by indoushka and reported it to VIVOTEK. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-09-29 Date Revision Summary 2026-09-29 1 Initial Publication Legal Notice and Terms of Use",
        "summary_is_html": false,
        "first_seen": "Tue, 29 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 29 Sep 26 12:00:00 +0000"
    },
    {
        "id": "/node/25561",
        "title": "Baicells Nova 430H",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-04",
        "summary": "View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to inject malformed messages which may lead to a denial-of-service condition. The following versions of Baicells Nova 430H are affected: Nova 430H eNodeB (model pBS3101SH)",
        "summary_is_html": false,
        "first_seen": "Tue, 29 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 29 Sep 26 12:00:00 +0000"
    },
    {
        "id": "/node/25553",
        "title": "CISA Adds Two Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "summary": "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-88771 Citrix NetScaler Improper Input Validation Vulnerability CVE-2026-88772 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.",
        "summary_is_html": false,
        "first_seen": "Sun, 27 Sep 26 12:00:00 +0000",
        "last_updated": "Sun, 27 Sep 26 12:00:00 +0000"
    },
    {
        "id": "/node/25552",
        "title": "Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway",
        "summary": "CISA is amplifying Citrix\u2019s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778. CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally. Because updating Citrix NetScaler deployments can be complex and may require downtime, CISA is issuing this Alert to help organizations assess exposure, prioritize mitigation, and account for these vulnerabilities into their risk-management activities. Given the potential consequences of successful exploitation and the fact that malicious actors are exploiting at least some of these vulnerabilities, CISA urges users and administrators to review Citrix\u2019s advisories. If possible, users are encouraged to check for indication of compromise prior to patching. Citrix has made indicators of compromise available through NetScaler Console and published additional guidance in their recent publication, Security Bulletin for CVE-2026-88771 through CVE-2026-88778, to support organizations in assessing potential compromise. Should your organization suspect compromise, it is important to preserve forensic evidence prior to applying updates, as updates may result in loss of forensic visibility. Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 - Security Updates - Citrix Community Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 Steps to Take if NetScaler ADC is Suspected to be Compromised Disclaimer The information in this report is being provided \u201cas is\u201d for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA.",
        "summary_is_html": false,
        "first_seen": "Sun, 27 Sep 26 12:00:00 +0000",
        "last_updated": "Sun, 27 Sep 26 12:00:00 +0000"
    },
    {
        "id": "/node/25551",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-87902 WordPress Core Remote File Inclusion Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.",
        "summary_is_html": false,
        "first_seen": "Fri, 25 Sep 26 12:00:00 +0000",
        "last_updated": "Fri, 25 Sep 26 12:00:00 +0000"
    },
    {
        "id": "/node/25549",
        "title": "CISA Adds Two Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "summary": "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.",
        "summary_is_html": false,
        "first_seen": "Fri, 25 Sep 26 12:00:00 +0000",
        "last_updated": "Fri, 25 Sep 26 12:00:00 +0000"
    },
    {
        "id": "/node/25229",
        "title": "Siemens Mendix Runtime (Update A)",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-02",
        "summary": "View CSAF Summary This advisory is revoked. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute. The following versions of Siemens Mendix Runtime are affected: Siemens Mendix Runtime vers:all/* (CVE-2026-7891) CVSS Vendor Equipment Vulnerabilities v3 9.1 Siemens Siemens Mendix Runtime Insecure Inherited Permissions Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-7891 This CVE has been retracted. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected application-specific attribute. View CVE Details Affected Products Siemens Mendix Runtime (Update A) Vendor: Siemens Product Version: Siemens Siemens Mendix Runtime: vers:all/* Product Status: not_affected Remediations Mitigation Vulnerability is rejected as re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected application-specific attribute (Vulnerable Code Not Present). Mitigation As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for industrial security and following recommendations in the product manuals. https://www.siemens.com/cert/operational-guidelines-industrial-security Mitigation Additional information on industrial security by Siemens can be found on the Siemens industrial security webpage https://www.siemens.com/industrialsecurity Mitigation For more information see the associated Siemens security advisory SSA-814963 in HTML. https://cert-portal.siemens.com/productcert/html/ssa-814963.html Mitigation For more information see the associated Siemens security advisory SSA-814963 in CSAF. https://cert-portal.siemens.com/productcert/csaf/ssa-814963.json Relevant CWE: CWE-277 Insecure Inherited Permissions Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.1 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N 4.0 9.1 CRITICAL CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N Acknowledgments Siemens ProductCERT reported this vulnerability to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-07-14 Date Revision Summary 2026-07-14 1 Initial Publication 2026-07-28 2 Initial Republication of Siemens ProductCERT SSA-814963 2026-09-22 3 Revoked advisory as the CVE is rejected 2026-09-24 4 Update A - Revoking advisory after Siemens revoked SSA-814963 and rejecting CVE-2026-7891 Legal Notice and Terms of Use",
        "summary_is_html": false,
        "first_seen": "Thu, 24 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 24 Sep 26 12:00:00 +0000"
    },
    {
        "id": "/node/25543",
        "title": "Eufy Omni C20, Omni X10 Pro",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-02",
        "summary": "View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to run system level commands or execute arbitrary code. The following versions of Eufy Omni C20, Omni X10 Pro are affected: Omni C20",
        "summary_is_html": false,
        "first_seen": "Thu, 24 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 24 Sep 26 12:00:00 +0000"
    },
    {
        "id": "/node/25542",
        "title": "Botslab G980H Dashcams",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01",
        "summary": "View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication controls, gain unauthorized access to sensitive data and privileged device functionality, modify device configuration, disrupt device operation. The following versions of Botslab G980H Dashcams are affected: G980H dash cam series 30010_QHG980HN5294SysFW+ (CVE-2026-84399, CVE-2026-82566, CVE-2026-85496, CVE-2026-77967, CVE-2026-88761, CVE-2026-82716, CVE-2026-84403, CVE-2026-75558, CVE-2026-81630, CVE-2026-87118, CVE-2026-82708, CVE-2026-79959, CVE-2026-82585) G980H dash cam series 58_QHG980HMCN5291SysFW+ (CVE-2026-84399, CVE-2026-82566, CVE-2026-85496, CVE-2026-77967, CVE-2026-88761, CVE-2026-88956, CVE-2026-82716, CVE-2026-84403, CVE-2026-75558, CVE-2026-81630, CVE-2026-87118, CVE-2026-82708, CVE-2026-82585) CVSS Vendor Equipment Vulnerabilities v3 8.8 Botslab Botslab G980H Dashcams Incorrect Authorization, Insufficient Session Expiration, Generation of Predictable Numbers or Identifiers, Authentication Bypass by Capture-replay, Use of Weak Credentials, Missing Authentication for Critical Function, Insertion of Sensitive Information into Log File, Use of Hard-coded Cryptographic Key, Insufficient Verification of Data Authenticity, Out-of-bounds Write, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Use of Hard-coded Credentials, Cleartext Transmission of Sensitive Information Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-84399 The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established it, and subsequent privileged operations rely on possession of a valid session identifier without adequately validating the requesting client's authenticated context. An unauthenticated attacker with adjacent network access could potentially use valid session state associated with another client to access privileged functionality. View CVE Details Affected Products Botslab G980H Dashcams Vendor: Botslab Product Version: Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+ Product Status: known_affected Remediations Mitigation Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab Relevant CWE: CWE-863 Incorrect Authorization Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-82566 The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions, a newly established connection can displace an existing client while previously established session state remains active until a separate expiration mechanism invalidates it. An unauthenticated attacker with adjacent network access could potentially take advantage of this residual authentication state to access functionality associated with another client's session. View CVE Details Affected Products Botslab G980H Dashcams Vendor: Botslab Product Version: Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+ Product Status: known_affected Remediations Mitigation Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab Relevant CWE: CWE-613 Insufficient Session Expiration Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-85496 The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active session exists could potentially determine a valid session identifier and use it to bypass intended authorization controls. View CVE Details Affected Products Botslab G980H Dashcams Vendor: Botslab Product Version: Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+ Product Status: known_affected Remediations Mitigation Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab Relevant CWE: CWE-340 Generation of Predictable Numbers or Identifiers Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 7.7 HIGH CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-77967 The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unauthenticated attacker with adjacent network access who captures a valid authentication value could replay it from another client to establish an authenticated session and access privileged device functionality. View CVE Details Affected Products Botslab G980H Dashcams Vendor: Botslab Product Version: Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+ Product Status: known_affected Remediations Mitigation Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab Relevant CWE: CWE-294 Authentication Bypass by Capture-replay Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.1 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N 4.0 8.6 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-88761 The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product. An unauthenticated attacker within WiFi range could potentially determine the remaining password characters through limited guessing and gain unauthorized access to the device network. View CVE Details Affected Products Botslab G980H Dashcams Vendor: Botslab Product Version: Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+ Product Status: known_affected Remediations Mitigation Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab Relevant CWE: CWE-1391 Use of Weak Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.3 MEDIUM CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 6 MEDIUM CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-88956 The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface. The affected account does not require a password before granting access to a privileged system interface, and the interface also displays the device's WiFi password during startup. An unauthenticated attacker with physical access to the device could connect to the UART interface, obtain root privileges, and recover the WiFi password. View CVE Details Affected Products Botslab G980H Dashcams Vendor: Botslab Product Version: Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+ Product Status: known_affected Remediations Mitigation Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.8 MEDIUM CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 7 HIGH CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-82716 The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process. These logs remain accessible on removable storage after the support operation has completed. An unauthenticated attacker with physical access to the storage media could retrieve the logs and obtain sensitive device information. View CVE Details Affected Products Botslab G980H Dashcams Vendor: Botslab Product Version: Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+ Product Status: known_affected Remediations Mitigation Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab Relevant CWE: CWE-532 Insertion of Sensitive Information into Log File Metrics CVSS Version Base Score Base Severity Vector String 3.1 4.6 MEDIUM CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 5.1 MEDIUM CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-84403 The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. An unauthenticated attacker within Bluetooth range could intercept or directly retrieve sensitive device information, including device identifiers, firmware information, and protected WiFi credentials. View CVE Details Affected Products Botslab G980H Dashcams Vendor: Botslab Product Version: Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+ Product Status: known_affected Remediations Mitigation Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.2 MEDIUM CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 6.9 MEDIUM CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-75558 The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who obtains the protected credential and extracts the cryptographic material from the firmware could recover the WiFi password and gain unauthorized access to the device network. View CVE Details Affected Products Botslab G980H Dashcams Vendor: Botslab Product Version: Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+ Product Status: known_affected Remediations Mitigation Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab Relevant CWE: CWE-321 Use of Hard-coded Cryptographic Key Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.3 MEDIUM CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 6 MEDIUM CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-81630 The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of a trusted cryptographic signature. A suitably positioned attacker who intercepts a firmware download, or an authenticated attacker who submits a crafted update, could install modified firmware and execute unauthorized code on the device. View CVE Details Affected Products Botslab G980H Dashcams Vendor: Botslab Product Version: Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+ Product Status: known_affected Remediations Mitigation Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab Relevant CWE: CWE-345 Insufficient Verification of Data Authenticity Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.1 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 9.2 CRITICAL CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-87118 The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality. An authenticated attacker with adjacent network access could submit crafted command data that corrupts memory, potentially disrupting authentication state or causing the affected process to terminate and the device to restart, resulting in a temporary denial of service. View CVE Details Affected Products Botslab G980H Dashcams Vendor: Botslab Product Version: Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+ Product Status: known_affected Remediations Mitigation Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab Relevant CWE: CWE-787 Out-of-bounds Write Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.7 MEDIUM CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H 4.0 6.9 MEDIUM CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-82708 The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a crafted request to access files within the device's removable storage that were not intended to be directly accessible through the web server. Exposed files could include recordings, images, diagnostic logs, or firmware files. View CVE Details Affected Products Botslab G980H Dashcams Vendor: Botslab Product Version: Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+ Product Status: known_affected Remediations Mitigation Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab Relevant CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-79959 The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical access to the device could recover the credential and use it to obtain root access through the UART interface. View CVE Details Affected Products Botslab G980H Dashcams Vendor: Botslab Product Version: Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+ Product Status: known_affected Remediations Mitigation Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab Relevant CWE: CWE-798 Use of Hard-coded Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.8 MEDIUM CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 7 HIGH CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-82585 The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network could obtain stored recordings, live video, location information, images, diagnostic logs, or other sensitive information exchanged between the device and its mobile application. View CVE Details Affected Products Botslab G980H Dashcams Vendor: Botslab Product Version: Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+ Product Status: known_affected Remediations Mitigation Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab Relevant CWE: CWE-319 Cleartext Transmission of Sensitive Information Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Acknowledgments Julian of Software Secured reported these vulnerabilities to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-09-24 Date Revision Summary 2026-09-24 1 Initial Publication Legal Notice and Terms of Use",
        "summary_is_html": false,
        "first_seen": "Thu, 24 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 24 Sep 26 12:00:00 +0000"
    },
    {
        "id": "/node/25545",
        "title": "CISA Adds Two Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/09/24/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "summary": "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-5430 WSO2 Multiple Products Path Traversal Vulnerability CVE-2026-71362 Adobe Commerce and Magento Incorrect Authorization Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA\u2019s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA\u2019s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.",
        "summary_is_html": false,
        "first_seen": "Thu, 24 Sep 26 12:00:00 +0000",
        "last_updated": "Thu, 24 Sep 26 12:00:00 +0000"
    },
    {
        "id": "/node/25428",
        "title": "Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/resources-tools/resources/considerations-critical-infrastructure-operators-working-third-party-ics-integrators",
        "summary": "Introduction The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA)\u2014hereafter referred to as the \u201cauthoring agencies\u201d\u2014have published this fact sheet to highlight considerations for critical infrastructure entities to reduce risk and minimize vulnerabilities when working with third-party industrial control system (ICS) integrators. ICS is an umbrella term referring to integrated networks of hardware and software designed to monitor and automate physical processes, encompassing specialized control systems and devices, such as supervisory control and data acquisition (SCADA) systems and programmable logic controllers. Third-party integrators provide varying types of services for ICS, such as control system design, installation, operational data analysis, device support and service, and daily operational control. Critical infrastructure owners and operators should maintain caution when granting third-party ICS integrators high levels of access or control over industrial processes, ensuring the principle of least privilege (PoLP), is applied. PoLP within OT environments lends itself to granting users, processes, and systems only the minimum access necessary to perform their assigned tasks, and no more. PoLP is designed to protect owners and operators. Not adopting principles such as PoLP could expose owners and operators to malicious cyber actors seeking to compromise critical infrastructure, possibly providing sensitive access to pathways that actors can exploit to cause disruptive and destructive effects to equipment and critical functions. Critical infrastructure owners and operators should action the recommendations in this fact sheet to work with integrators to ensure secure practices and frameworks are put in place to reduce the risk of malicious actors exploiting third-party accesses to compromise critical infrastructure operational environments. Examples of Risk and Exploitation Much like IT systems, using third-party ICS integrators in critical infrastructure may inadvertently introduce security issues to a customer environment by exposing systems and services not pre-configured to the customer\u2019s security requirements. Critical infrastructure owners and operators that rely on third-party integrators for system design face supply chain risks if integrators and owners and operators do not collectively enforce clear requirements for the secure procurement and handling of system components. Furthermore, third-party integrators that operate and host data outside of the United States may pose additional risks, as they may be subject to different data storage and management laws that do not meet the security needs of U.S. critical infrastructure entities. According to FBI technical analysis, between March and April 2025, malicious foreign cyber actors gained access to the network of a U.S. industrial automation solutions company that offered services\u2014such as system integration, engineering consulting, and SCADA programming\u2014for industrial customers, including power utilities and transportation entities. While on the network, threat actors searched terms, including \u201ccustomers\u201d and \u201cSCADA,\u201d and created nine .zip files consisting of approximately 800 files for presumed exfiltration, including customer SCADA information, ICS device details, and other schematics. Malicious cyber actors could leverage the exfiltrated information to later conduct disruptive attacks against operational environments and disrupt critical services. Recommendations to Assess Risk Critical infrastructure owners and operators should make risk-informed decisions when considering introducing third-party integrators into their networks and operations, guided by a robust understanding of the organizational risks posed by providing sensitive access to their systems. Organizations should routinely conduct risk assessments to evaluate contracts that involve access to industrial systems, to determine impacts to the organization\u2019s data autonomy and process controls. Risk assessments should address hardware and software supply chain vulnerabilities introduced by integrator equipment, as well as the IT and OT security of these devices and their associated networks. When considering implementing foreign-owned integrators, critical infrastructure owners and operators should also include geopolitical considerations in their risk assessments, such as how the critical infrastructure entity may be directly or indirectly targeted based on the geopolitical climate. Critical infrastructure owners and operators should consider the following questions in their risk assessments to safeguard the security of their operational systems when working with third-party ICS integrators: What organizational data does the integrator store or have access to? Critical infrastructure network designs, device specifications, logs, and other data can all be useful information for malicious cyber actors. When evaluating the risk of enabling integrators to store or access this data, consider the potential for a malicious cyber actor to access this data through the integrator\u2019s network. Where is the data stored? If the integrator is foreign-owned, consider whether the utility data is stored within the United States or internationally. If data is stored internationally, the laws of that respective country may govern it and may apply even if the integrator is a U.S. subsidiary. Does the integrator have remote access for operational support? If the integrator has remote access to the organization\u2019s ICS network, then there is a potential risk that a malicious cyber actor could gain access to the integrator\u2019s network and pivot into the utility\u2019s network to gain control of their systems. Consider the security of the organization\u2019s remote connections when evaluating the risk these potential access points pose to the organization\u2019s network. Can the organization operate independently if the integrator is compromised? Having redundancies in place and the ability to recover the system and operate without the integrator, especially for operationally critical processes, can reduce risk in the event of integrator compromise. Operators should maintain secure, offline backups of all software required to operate equipment to facilitate system recovery. Recommendations to Reduce Risk The authoring agencies recommend critical infrastructure owners and operators implement the following steps to reduce the risks associated with using third-party ICS integrators: Include cybersecurity and supply chain cybersecurity in contracts and service agreements. When preparing service agreements, include requirements on areas such as: Data storage locations, information protection agreements, and protection of ICS data and design documentation, Remote access capabilities, Basics of the integrator\u2019s cybersecurity program, Change management and patch management policies, Actions taken to secure deployed components (e.g., changing default passwords, disabling unused ports), Listing authorized personnel with access to systems, and Processes that enable local engineering support when necessary, limiting required integrator intervention. Evaluate devices with external internet exposure. Organizations should work with integrators to understand where devices are hosted and minimize exposure by disconnecting devices from the public-facing internet. Monitor and log remote access. Ensure integrators access equipment using routes you are able to monitor. Use on-demand remote access if possible, so operators have to proactively allow remote access. Request an inventory of all software and hardware supplied by the integrator, as well as documentation for how it connects to your infrastructure and how it will be updated. Practice procedures and maintain capabilities for manual operations, keeping in mind, and accounting for, where third parties fit into the environment and recovery procedures. Resources For guidance on asset inventories, see CISA\u2019s Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators. For additional information on SBOMs, see CISA\u2019s 2026 Minimum Elements for a Software Bill of Materials (SBOM). For guidance on supply chain risk management, see the Communications Sector Coordinating Council (CSCC) and IT Sector Coordinating Council\u2019s (SCC) Supplier, Products, and Services Threat Evaluation (to include Artificial Intelligence Risks and Mitigations), and NIST\u2019s Cybersecurity Supply Chain Risk Management. For additional information and resources concerning cyber threats to ICS, visit Industrial Control Systems for Cybersecurity Advisories and other cybersecurity guidance and best practices. Contact Information The authoring agencies strongly urge critical infrastructure operators to report suspicious cyber activity to the following entities: Report cyber activity to your local FBI field office or IC3, or contact CISA via CISA\u2019s 24/7 Operations Center at contact@cisa.dhs.gov or 1-844-Say-CISA (1-844-729-2472). Report any leads, threats, and suspected criminal activity by submitting an electronic tip, calling 1-800-CALL-FBI (1-800-225-5324), or contacting your local FBI field office. Note: This website cannot be used to report emergencies or immediate threat to life. For emergencies or immediate threat to life, please call 911. If you are a law enforcement entity, use the unclassified information-sharing system eGuardian (accessible via the Law Enforcement Enterprise Portal) for reporting suspicious activity reports to the FBI. Note: If the information is urgent, then contact your local FBI field office directly and follow up with an eGuardian report. Disclaimer CISA and the authoring agencies do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA and the authoring agencies. Version History September 23, 2026: Initial version.",
        "summary_is_html": false,
        "first_seen": "Wed, 23 Sep 26 12:00:00 +0000",
        "last_updated": "Wed, 23 Sep 26 12:00:00 +0000"
    },
    {
        "id": "/node/25524",
        "title": "Siemens SIPLUS and SIMATIC Products",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-04",
        "summary": "View CSAF Summary Multiple Siemens products are vulnerable to the \"Copy Fail\" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIPLUS and SIMATIC Products are affected: SIMATIC AX Runtime Core Linux Common Debian vers:all/* (CVE-2026-31431) SIMATIC AX Runtime Core Linux Common Debian arm64 vers:all/* (CVE-2026-31431) SIMATIC AX Runtime Core Linux Platform Container Common Debian Development vers:all/* (CVE-2026-31431) SIMATIC AX Runtime Core Linux VMWare Development vers:all/* (CVE-2026-31431) SIMATIC CN 4100 vers:intdot/",
        "summary_is_html": false,
        "first_seen": "Tue, 22 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 22 Sep 26 12:00:00 +0000"
    },
    {
        "id": "/node/25525",
        "title": "Siemens Desigo CC family",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-05",
        "summary": "View CSAF Summary A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization. The following versions of Siemens Desigo CC family are affected: Desigo CC family V6 vers:all/* (CVE-2026-34223) Desigo CC family V7 vers:all/* (CVE-2026-34223) CVSS Vendor Equipment Vulnerabilities v3 8.2 Siemens Siemens Desigo CC family Improper Control of Generation of Code ('Code Injection') Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-34223 The affected application is vulnerable to Client Code Execution (CCE) due to insufficient input validation when handling scripts embedded within user-defined graphics documents. Specifically, when the script within a graphics document is designed or modified by an attacker to include malicious commands. When a user opens a compromised graphics document, the embedded script is executed on the client application instance, allowing an attacker to write arbitrary files to the client's operating system. Successful exploitation requires an attacker to craft a malicious graphics document and entice a user with sufficient privileges to display it. This could lead to compromise of the client operating system and potential lateral movement within the organization. View CVE Details Affected Products Siemens Desigo CC family Vendor: Siemens Product Version: Desigo CC family V6, Desigo CC family V7 Product Status: known_affected Remediations Mitigation Evaluate authorization policy for Graphics application following Least Privilege principle, so only required users have access to the configuration. None available Currently no fix is available. Mitigation For more information see the associated Siemens security advisory SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family - CSAF Version, SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family - HTML Version. Relevant CWE: CWE-94 Improper Control of Generation of Code ('Code Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.2 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H Acknowledgments Michelin CERT reported this vulnerability to Siemens. General Recommendations As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity Additional Resources For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories Terms of Use The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Siemens ProductCERT SSA-330084 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory. Revision History Initial Release Date: 2026-09-08 Date Revision Summary 2026-09-08 1 Publication Date 2026-09-22 2 Initial CISA Republication of Siemens ProductCERT SSA-330084 advisory Legal Notice and Terms of Use",
        "summary_is_html": false,
        "first_seen": "Tue, 22 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 22 Sep 26 12:00:00 +0000"
    },
    {
        "id": "/node/25523",
        "title": "Siemens Siveillance Control",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-03",
        "summary": "View CSAF Summary A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server. Siemens has released patches and updates for Siveillance OIS to apply to the products that incorporate the OIS service, and recommends to update to the latest versions. The following versions of Siemens Siveillance Control are affected: Siveillance Control Pro V3.0 vers:intdot/",
        "summary_is_html": false,
        "first_seen": "Tue, 22 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 22 Sep 26 12:00:00 +0000"
    },
    {
        "id": "/node/25522",
        "title": "lwIP (Lightweight IP)",
        "source": "CISA Cybersecurity Advisories",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-02",
        "summary": "View CSAF Summary Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system. The following versions of lwIP (Lightweight IP) are affected: API >=2.0.1|=2.0.1|",
        "summary_is_html": false,
        "first_seen": "Tue, 22 Sep 26 12:00:00 +0000",
        "last_updated": "Tue, 22 Sep 26 12:00:00 +0000"
    }
]