View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system. The following versions of Armatura LLC Armatura One are affected: Armatura One <4.7.2 (CVE-2023-46604, CVE-2026-94591, CVE-2026-94592, CVE-2026-94593,…
Read full source summary
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system. The following versions of Armatura LLC Armatura One are affected: Armatura One <4.7.2 (CVE-2023-46604, CVE-2026-94591, CVE-2026-94592, CVE-2026-94593, CVE-2026-94594) Armatura One (USA) <4.6.1 (CVE-2023-46604, CVE-2026-94591, CVE-2026-94592, CVE-2026-94593, CVE-2026-94594) CVSS Vendor Equipment Vulnerabilities v3 9.8 Armatura LLC Armatura LLC Armatura One Deserialization of Untrusted Data, Use of Hard-coded Cryptographic Key, Use of Hard-coded Credentials, Insertion of Sensitive Information into Log File Background Critical Infrastructure Sectors: Communications, Critical Manufacturing, Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2023-46604 Armatura One embeds Apache ActiveMQ, exposing its OpenWire protocol listener on the network by default. This embedded version is affected by CVE-2023-46604, a deserialization flaw in the OpenWire marshaller that allows an unauthenticated network attacker to trigger deserialization of an arbitrary object graph before authentication is checked. This can result in arbitrary code execution with the highest level of privilege on the host operating system. View CVE Details Affected Products Armatura LLC Armatura One Vendor: Armatura LLC Product Version: Armatura LLC Armatura One: <4.7.2, Armatura LLC Armatura One (USA): <4.6.1 Product Status: known_affected Remediations Vendor fix Armatura LLC Armatura One vers:all/<4.7.2: Armatura LLC has released Armatura One V4.7.2, which resolves this issue. Users should upgrade from V4.7.1 or earlier to V4.7.2. Vendor fix Armatura LLC Armatura One (USA) vers:all/<4.6.1: Armatura LLC has released Armatura One V4.6.1_USA, which resolves this issue. Users of the USA release line should upgrade from V4.3.1_USA or earlier to V4.6.1_USA. Vendor fix Armatura LLC recommends contacting official technical support for guidance on obtaining and applying the upgrade. Mitigation For more information see the associated CISA security advisory ICSA-26-274-01 JSON. https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-274-01.json Relevant CWE: CWE-502 Deserialization of Untrusted Data Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-94591 Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across every installation. An attacker with a copy of the installation package can recover this key and initialization vector, and can then decrypt the stored credentials of any specific installation to which the attacker separately obtains the encrypted configuration file. View CVE Details Affected Products Armatura LLC Armatura One Vendor: Armatura LLC Product Version: Armatura LLC Armatura One: <4.7.2, Armatura LLC Armatura One (USA): <4.6.1 Product Status: known_affected Remediations Vendor fix Armatura LLC Armatura One vers:all/<4.7.2: Armatura LLC has released Armatura One V4.7.2, which resolves this issue. Users should upgrade from V4.7.1 or earlier to V4.7.2. Vendor fix Armatura LLC Armatura One (USA) vers:all/<4.6.1: Armatura LLC has released Armatura One V4.6.1_USA, which resolves this issue. Users of the USA release line should upgrade from V4.3.1_USA or earlier to V4.6.1_USA. Vendor fix Armatura LLC recommends contacting official technical support for guidance on obtaining and applying the upgrade. Mitigation For more information see the associated CISA security advisory ICSA-26-274-01 JSON. https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-274-01.json Relevant CWE: CWE-321 Use of Hard-coded Cryptographic Key Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.4 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 8.6 HIGH CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-94592 Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where it has not been changed. View CVE Details Affected Products Armatura LLC Armatura One Vendor: Armatura LLC Product Version: Armatura LLC Armatura One: <4.7.2, Armatura LLC Armatura One (USA): <4.6.1 Product Status: known_affected Remediations Vendor fix Armatura LLC Armatura One vers:all/<4.7.2: Armatura LLC has released Armatura One V4.7.2, which resolves this issue. Users should upgrade from V4.7.1 or earlier to V4.7.2. Vendor fix Armatura LLC Armatura One (USA) vers:all/<4.6.1: Armatura LLC has released Armatura One V4.6.1_USA, which resolves this issue. Users of the USA release line should upgrade from V4.3.1_USA or earlier to V4.6.1_USA. Vendor fix Armatura LLC recommends contacting official technical support for guidance on obtaining and applying the upgrade. Mitigation For more information see the associated CISA security advisory ICSA-26-274-01 JSON. https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-274-01.json Relevant CWE: CWE-798 Use of Hard-coded Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.4 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 8.6 HIGH CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-94593 Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access to the server operating system is available. View CVE Details Affected Products Armatura LLC Armatura One Vendor: Armatura LLC Product Version: Armatura LLC Armatura One: <4.7.2, Armatura LLC Armatura One (USA): <4.6.1 Product Status: known_affected Remediations Vendor fix Armatura LLC Armatura One vers:all/<4.7.2: Armatura LLC has released Armatura One V4.7.2, which resolves this issue. Users should upgrade from V4.7.1 or earlier to V4.7.2. Vendor fix Armatura LLC Armatura One (USA) vers:all/<4.6.1: Armatura LLC has released Armatura One V4.6.1_USA, which resolves this issue. Users of the USA release line should upgrade from V4.3.1_USA or earlier to V4.6.1_USA. Vendor fix Armatura LLC recommends contacting official technical support for guidance on obtaining and applying the upgrade. Mitigation For more information see the associated CISA security advisory ICSA-26-274-01 JSON. https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-274-01.json Relevant CWE: CWE-532 Insertion of Sensitive Information into Log File Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.5 HIGH CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-94594 Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the logged credential. View CVE Details Affected Products Armatura LLC Armatura One Vendor: Armatura LLC Product Version: Armatura LLC Armatura One: <4.7.2, Armatura LLC Armatura One (USA): <4.6.1 Product Status: known_affected Remediations Vendor fix Armatura LLC Armatura One vers:all/<4.7.2: Armatura LLC has released Armatura One V4.7.2, which resolves this issue. Users should upgrade from V4.7.1 or earlier to V4.7.2. Vendor fix Armatura LLC Armatura One (USA) vers:all/<4.6.1: Armatura LLC has released Armatura One V4.6.1_USA, which resolves this issue. Users of the USA release line should upgrade from V4.3.1_USA or earlier to V4.6.1_USA. Vendor fix Armatura LLC recommends contacting official technical support for guidance on obtaining and applying the upgrade. Mitigation For more information see the associated CISA security advisory ICSA-26-274-01 JSON. https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-274-01.json Relevant CWE: CWE-532 Insertion of Sensitive Information into Log File Metrics CVSS Version Base Score Base Severity Vector String 3.1 4 MEDIUM CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N 4.0 5.1 MEDIUM CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Acknowledgments Andrew Capobianco of RewCon.co reported these vulnerabilities to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. CISA is not aware of exploitation specifically targeting Armatura One in relation to these vulnerabilities. CVE-2023-46604 is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog and has been used in ransomware campaigns against other Apache ActiveMQ deployments. Revision History Initial Release Date: 2026-10-01 Date Revision Summary 2026-10-01 1 Initial Publication Legal Notice and Terms of Use
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data without proper authorization. The following versions of Meari IoT Cloud Platform OpenAPI Service are affected: IoT Cloud Platform OpenAPI Service vers:all/*…
Read full source summary
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data without proper authorization. The following versions of Meari IoT Cloud Platform OpenAPI Service are affected: IoT Cloud Platform OpenAPI Service vers:all/* (CVE-2026-101104, CVE-2026-96613) CVSS Vendor Equipment Vulnerabilities v3 7.7 Meari Meari IoT Cloud Platform OpenAPI Service Missing Authorization Background Critical Infrastructure Sectors: Commercial Facilities, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-101104 The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors, without verifying ownership or permissions. View CVE Details Affected Products Meari IoT Cloud Platform OpenAPI Service Vendor: Meari Product Version: Meari IoT Cloud Platform OpenAPI Service: vers:all/* Product Status: known_affected Remediations No fix planned Meari did not respond to CISA's coordination attempts. IoT Cloud Platform OpenAPI users are advised to contact Meari for support https://www.meari.com/en/downLoadCenter. Relevant CWE: CWE-862 Missing Authorization Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.7 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N 4.0 6.3 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N CVE-2026-96613 The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shadow of any device by specifying its device ID. This vulnerability exposes sensitive information, such as device credentials, owner details, network data, and telemetry, without verifying any relationship between the requester and the target device. View CVE Details Affected Products Meari IoT Cloud Platform OpenAPI Service Vendor: Meari Product Version: Meari IoT Cloud Platform OpenAPI Service: vers:all/* Product Status: known_affected Remediations No fix planned Meari did not respond to CISA's coordination attempts. IoT Cloud Platform OpenAPI users are advised to contact Meari for support https://www.meari.com/en/downLoadCenter. Relevant CWE: CWE-862 Missing Authorization Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N 4.0 7.1 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Acknowledgments Gabriel Adams reported these vulnerabilities to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-10-01 Date Revision Summary 2026-10-01 1 Initial Publication Legal Notice and Terms of Use
View CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks. The following versions of Monta monta.app are affected: monta.app vers:all/* (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474) CVSS Vendor Equipment Vulnerabilities v3 9.4…
Read full source summary
View CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks. The following versions of Monta monta.app are affected: monta.app vers:all/* (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474) CVSS Vendor Equipment Vulnerabilities v3 9.4 Monta Monta monta.app Missing Authentication for Critical Function, Improper Restriction of Excessive Authentication Attempts, Insufficient Session Expiration, Insufficiently Protected Credentials Background Critical Infrastructure Sectors: Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Netherlands Vulnerabilities Expand All + CVE-2026-95102 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system. View CVE Details Affected Products Monta monta.app Vendor: Monta Product Version: Monta monta.app: vers:all/* Product Status: known_affected Remediations Mitigation Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) and encourage operators to enable it. Mitigation Monta states that they have implemented rate limiting and automated connection throttling at the WebSocket layer. Connections exhibiting abusive patterns, including rapid reconnection, ID brute-forcing behavior, or excessive command volume, are automatically identified and blocked. Mitigation Monta states that their platform handles duplicate connection attempts per the OCPP specification, where a new authenticated connection supersedes an existing session for the same station ID. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.4 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L 4.0 9.3 CRITICAL https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N CVE-2026-97363 The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access. View CVE Details Affected Products Monta monta.app Vendor: Monta Product Version: Monta monta.app: vers:all/* Product Status: known_affected Remediations Mitigation Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) and encourage operators to enable it. Mitigation Monta states that they have implemented rate limiting and automated connection throttling at the WebSocket layer. Connections exhibiting abusive patterns, including rapid reconnection, ID brute-forcing behavior, or excessive command volume, are automatically identified and blocked. Mitigation Monta states that their platform handles duplicate connection attempts per the OCPP specification, where a new authenticated connection supersedes an existing session for the same station ID. Relevant CWE: CWE-307 Improper Restriction of Excessive Authentication Attempts Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 8.7 HIGH https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-97212 The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests. View CVE Details Affected Products Monta monta.app Vendor: Monta Product Version: Monta monta.app: vers:all/* Product Status: known_affected Remediations Mitigation Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) and encourage operators to enable it. Mitigation Monta states that they have implemented rate limiting and automated connection throttling at the WebSocket layer. Connections exhibiting abusive patterns, including rapid reconnection, ID brute-forcing behavior, or excessive command volume, are automatically identified and blocked. Mitigation Monta states that their platform handles duplicate connection attempts per the OCPP specification, where a new authenticated connection supersedes an existing session for the same station ID. Relevant CWE: CWE-613 Insufficient Session Expiration Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.3 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L 4.0 6.9 MEDIUM https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVE-2026-93474 Charging station authentication identifiers are publicly accessible via web-based mapping platforms. View CVE Details Affected Products Monta monta.app Vendor: Monta Product Version: Monta monta.app: vers:all/* Product Status: known_affected Remediations Mitigation Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) and encourage operators to enable it. Mitigation Monta states that they have implemented rate limiting and automated connection throttling at the WebSocket layer. Connections exhibiting abusive patterns, including rapid reconnection, ID brute-forcing behavior, or excessive command volume, are automatically identified and blocked. Mitigation Monta states that their platform handles duplicate connection attempts per the OCPP specification, where a new authenticated connection supersedes an existing session for the same station ID. Relevant CWE: CWE-522 Insufficiently Protected Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N 4.0 6.9 MEDIUM https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Acknowledgments An anonymous researcher reported these vulnerabilities to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-10-01 Date Revision Summary 2026-10-01 1 Initial Publication Legal Notice and Terms of Use
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system. The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected: EasyIO Neo Series EC Controllers V3.3b63 (CVE-2026-64892) EasyIO Neo Series EC Controllers V3.3b62 (CVE-2026-64892) EasyIO Neo…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system. The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected: EasyIO Neo Series EC Controllers V3.3b63 (CVE-2026-64892) EasyIO Neo Series EC Controllers V3.3b62 (CVE-2026-64892) EasyIO Neo Series CW Controllers V3.3b25 (CVE-2026-64892) EasyIO Neo Series CW Controllers V3.3b24 (CVE-2026-64892) CVSS Vendor Equipment Vulnerabilities v3 3.5 Johnson Controls Johnson Controls EasyIO Neo Series EC and CW Controllers Exposure of Sensitive Information to an Unauthorized Actor Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-64892 Johnson Controls is aware of a vulnerability in EasyIO Neo Series EC and CW Controllers relating to an attacker gaining access to sensitive information that could be used to conduct further attacks against the system. The EC and CW are programmable edge controllers designed for building automation and control systems, used to manage and automate various building functions including HVAC, lighting, and energy management, supporting open protocols such as BACnet and Modbus for adaptable system connections. View CVE Details Affected Products Johnson Controls EasyIO Neo Series EC and CW Controllers Vendor: Johnson Controls Product Version: Johnson Controls EasyIO Neo Series EC Controllers: V3.3b63, Johnson Controls EasyIO Neo Series EC Controllers: V3.3b62, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b25, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b24 Product Status: known_affected Remediations Mitigation Johnson Controls released fixed versions for EasyIO Neo Series EC and CW Controllers. Users should upgrade to the fixed version or later as soon as operationally feasible. The fix is available in EC firmware V3.3b64 and CW firmware V3.3b26. Contact your Johnson Controls representative or authorized EasyIO distributor. Mitigation Before applying updates in production ICS/OT environments, users should review operational impact, backup relevant configurations, test updates in a non-production environment where feasible, and follow applicable change-management and safety procedures. Mitigation If immediate update is not possible, Johnson Controls recommends the following mitigations: Implement physical access controls to prevent unauthorized personnel from reaching device debug ports. Monitor network traffic to and from affected devices for unusual or unauthorized access attempts. Apply the principle of least privilege to all accounts and services that interact with the affected devices. Where possible, apply firmware updates that disable debug interfaces or require authentication before granting debug access. Implement intrusion detection/prevention systems to monitor for exploitation attempts. Refer to and follow all steps in the product hardening guide or the JCI universal hardening guide found here: https://www.johnsoncontrols.com/trust-center/cybersecurity/resources . These mitigations reduce risk but may not fully remediate the vulnerability. Users should update to the fixed versions when operationally feasible. Mitigation For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-20. https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories Relevant CWE: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor Metrics CVSS Version Base Score Base Severity Vector String 3.1 3.5 LOW CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:L 4.0 4.8 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N Acknowledgments Gabriele Gardois reported this vulnerability to Johnson Controls Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. The recommendations provided within Johnson Controls Hardening Guide should always be applied to minimize security risk. Visit the Johnson Controls Trust Center Cybersecurity website to access the latest Hardening Guidelines and cybersecurity best practices - https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories . CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-10-01 Date Revision Summary 2026-10-01 1 Initial Republication of Johnson Controls Product Security Advisory JCI-PSA-2026-20 Legal Notice and Terms of Use
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on…
Read full source summary
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files. The following versions of ABB Protection and Control IED Manager PCM600 are affected: Protection and Control IED Manager PCM600 <=2.14 (CVE-2026-15952, CVE-2026-15953) CVSS Vendor Equipment Vulnerabilities v3 6.4 ABB ABB Protection and Control IED Manager PCM600 Incorrect Permission…
Read full source summary
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files. The following versions of ABB Protection and Control IED Manager PCM600 are affected: Protection and Control IED Manager PCM600 <=2.14 (CVE-2026-15952, CVE-2026-15953) CVSS Vendor Equipment Vulnerabilities v3 6.4 ABB ABB Protection and Control IED Manager PCM600 Incorrect Permission Assignment for Critical Resource, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2026-15952 A vulnerability exists in the Scheduler Service installed with PCM600. The service executes under the LocalSystem account while permissions are granted to standard PCM600 users through membership in the local users group. An attacker with local access and valid user credentials may exploit this vulnerability to elevate privileges and obtain control of the affected host. View CVE Details Affected Products ABB Protection and Control IED Manager PCM600 Vendor: ABB Product Version: ABB Protection and Control IED Manager PCM600: <=2.14 Product Status: known_affected Remediations Mitigation ABB recommends the following workaround. Although this workaround does not correct the underlying vulnerability, it reduces the risk of privilege escalation. Mitigation Configure the appropriate ABBPCMSchedulerService instance to run using the same Windows account that is used to operate PCM600: Open Services.msc. Locate the ABBPCMSchedulerService corresponding to the installed PCM600 version. Open Properties and select the Log On tab. The service should be configured to log on with the same Windows user account that is used for the PCM600 application. Ensure that this account has the required "Log on as a service" privilege. Mitigation When authentication is enabled for the IED, the Scheduler tool must be used with the same Windows account configured as the Scheduler Service logon account. Mitigation For installations using IED security certificates, the PCM600 setting Always trust IED security certifcates must be enabled only when PCM600-to-IED communication takes place in a secure and trusted environment. Mitigation For more information, see ABB security advisory 2NGA003170 and 2NGA003179. Relevant CWE: CWE-732 Incorrect Permission Assignment for Critical Resource Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.4 MEDIUM CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H 4.0 7.1 HIGH CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-15953 A vulnerability exists in the processing of PCM600 project archives files. Insufficient validation of archive entry paths may permit path traversal during extraction, potentially allowing files to be written to loca tions outside the intended extraction directory. View CVE Details Affected Products ABB Protection and Control IED Manager PCM600 Vendor: ABB Product Version: ABB Protection and Control IED Manager PCM600: <=2.14 Product Status: known_affected Remediations Mitigation Configure the appropriate ABBPCMSchedulerService instance to run using the same Windows account that is used to operate PCM600: Open Services.msc. Locate the ABBPCMSchedulerService corresponding to the installed PCM600 version. Open Properties and select the Log On tab. The service should be configured to log on with the same Windows user account that is used for the PCM600 application. Ensure that this account has the required "Log on as a service" privilege. Mitigation When authentication is enabled for the IED, the Scheduler tool must be used with the same Windows account configured as the Scheduler Service logon account. Mitigation For installations using IED security certificates, the PCM600 setting Always trust IED security certifcates must be enabled only when PCM600-to-IED communication takes place in a secure and trusted environment. Mitigation For more information, see ABB security advisory 2NGA003170 and 2NGA003179. Relevant CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Metrics CVSS Version Base Score Base Severity Vector String 3.1 5 MEDIUM CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N 4.0 5.6 MEDIUM CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N Acknowledgments Abhinav Agarwal reported these vulnerabilities to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-10-01 Date Revision Summary 2026-10-01 1 Initial Publication Legal Notice and Terms of Use
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data. The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected: EasyIO Neo Series EC Controllers V3.3b62 (CVE-2026-64893) EasyIO Neo Series EC Controllers V3.3b63 (CVE-2026-64893) EasyIO Neo Series CW Controllers…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data. The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected: EasyIO Neo Series EC Controllers V3.3b62 (CVE-2026-64893) EasyIO Neo Series EC Controllers V3.3b63 (CVE-2026-64893) EasyIO Neo Series CW Controllers V3.3b24 (CVE-2026-64893) EasyIO Neo Series CW Controllers V3.3b25 (CVE-2026-64893) CVSS Vendor Equipment Vulnerabilities v3 5.4 Johnson Controls Johnson Controls EasyIO Neo Series EC and CW Controllers Cleartext Transmission of Sensitive Information Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-64893 Johnson Controls is aware of a vulnerability in EasyIO Neo which may allow an attacker to intercept and read sensitive information, including credentials and session data, transmitted in cleartext over the network. Successful exploitation could result in technical or operational impact. EasyIO Neo is a programmable building automation edge controller used to manage and automate HVAC, lighting, and energy systems in commercial buildings through a web-based interface. View CVE Details Affected Products Johnson Controls EasyIO Neo Series EC and CW Controllers Vendor: Johnson Controls Product Version: Johnson Controls EasyIO Neo Series EC Controllers: V3.3b62, Johnson Controls EasyIO Neo Series EC Controllers: V3.3b63, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b24, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b25 Product Status: known_affected Remediations Mitigation Johnson Controls released fixed versions for EasyIO Neo Series EC and CW Controllers. Users should upgrade to the fixed version or later as soon as operationally feasible. HTTP communication has been disabled by default in the latest version. The fix is available in EC firmware V3.3b64 andCW firmware V3.3b26. Contact your Johnson Controls representative or visitthe Johnson Controls Trust Center. Mitigation Before applying updates in production ICS/OT environments, users should review operational impact, backup relevant configurations, test updates in a non-production environment where feasible, and follow applicable change-management and safety procedures. Mitigation If immediate update is not possible, Johnson Controls recommends the following mitigations: Enable and enforce HTTPS/TLS for all web-based management access to the device. Disable HTTP access entirely. Place devices on an isolated, segmented network behind a firewall to limit exposure of management interfaces. Use a VPN when accessing devices remotely to encrypt all traffic in transit. Monitor network traffic for unencrypted sensitive data leaving the management interface. Restrict network access to management interfaces using access control lists (ACLs) to only trusted hosts. Refer to and follow all steps in the product hardening guide or the JCI universal hardening guide found here: https://www.johnsoncontrols.com/trust-center/cybersecurity/resources . These mitigations reduce risk but may not fully remediate the vulnerability. Users should update to the fixed versions when operationally feasible. Mitigation Users should review logs, network telemetry, device events, and security monitoring tools for activity involving EasyIO NEO versions EC and CW. Relevant detection information may include: Unencrypted HTTP traffic to or from the device management interface on port 80. Network captures showing cleartext credentials or session tokens in HTTP requests. Unexpected devices or IP addresses accessing the web management console. ARP spoofing or other man-in-the-middle indicators on the local network segment. Unauthorized configuration changes that may indicate credential interception. Mitigation The recommendations provided within Johnson Controls Hardening Guide should always be applied to minimize security risk. Visit the Johnson Controls Trust Center Cybersecurity website to access the latest Hardening Guidelines and cybersecurity best practices - https://www.johnsoncontrols.com/trust-center/cybersecurity/resources. https://www.johnsoncontrols.com/trust-center/cybersecurity/resources Mitigation For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-30. https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories Relevant CWE: CWE-319 Cleartext Transmission of Sensitive Information Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.4 MEDIUM CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N 4.0 5.9 MEDIUM CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N Acknowledgments Gabriele Gardois reported this vulnerability to Johnson Controls Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability has a high attack complexity. Revision History Initial Release Date: 2026-10-01 Date Revision Summary 2026-10-01 1 Initial Republication of Johnson Controls Product Security Advisory JCI-PSA-2026-30 Legal Notice and Terms of Use
View CSAF Summary The following versions of CISA Malcolm are affected: Malcolm CVSS Vendor Equipment Vulnerabilities v3 8.8 CISA CISA Malcolm Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Server-Side Request…
Read full source summary
View CSAF Summary The following versions of CISA Malcolm are affected: Malcolm CVSS Vendor Equipment Vulnerabilities v3 8.8 CISA CISA Malcolm Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Server-Side Request Forgery (SSRF), Authentication Bypass by Spoofing, Missing Authorization, Missing Authentication for Critical Function, Incorrect Authorization, Use of Default Credentials, Improper Certificate Validation, URL Redirection to Untrusted Site ('Open Redirect'), Dependency on Vulnerable Third-Party Component, Use of Password Hash With Insufficient Computational Effort Background Critical Infrastructure Sectors: Energy, Information Technology, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-90443 A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes arbitrary script in the context of the affected application and can redirect the user's browser to an arbitrary external site. Successful exploitation could allow an attacker to act with the compromised user's session privileges within the application. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm <v26.06.0 Product Status: known_affected Remediations Vendor fix The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version. Relevant CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N 4.0 5.3 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVE-2026-90444 A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file's name, allowing an authenticated attacker to embed and execute arbitrary operating system commands with the privileges of that process. This allows an attacker to read and modify ingested log data, and could provide a foothold for further movement within the internal network. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm <v26.06.0 Product Status: known_affected Remediations Vendor fix The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version. Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-90445 An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attacker to craft an archive whose entries traverse outside the destination directory, causing the extraction process to write files to arbitrary locations with the privileges of that process. This could allow an attacker to inject fabricated records into the system's stored data or tamper with application configuration. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm <v26.06.0 Product Status: known_affected Remediations Vendor fix The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version. Relevant CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N 4.0 7.1 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-90446 An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents. This allows an authenticated attacker to substitute an arbitrary backend path, causing the application's own elevated service credentials to be used against unintended internal endpoints. This could allow an attacker to enumerate or read internal configuration and administrative data from the backend data store that would otherwise be restricted. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm <v26.06.0 Product Status: known_affected Remediations Vendor fix The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version. Relevant CWE: CWE-918 Server-Side Request Forgery (SSRF) Metrics CVSS Version Base Score Base Severity Vector String 3.1 4.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N 4.0 5.3 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-90447 A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user in possession of a shared service credential can set this header to route around the primary role-based authorization check and reach the alternate path's fixed, elevated role instead. This allows a low-privileged authenticated attacker who knows the shared credential to perform actions reserved for a higher-privileged role. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm <v26.06.0 Product Status: known_affected Remediations Vendor fix The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version. Relevant CWE: CWE-290 Authentication Bypass by Spoofing Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N 4.0 7.1 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-90448 A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed. One such route accepts a request that creates or overwrites a stored record, including an attacker-chosen identifier, using the application's own elevated backend credentials. This allows an authenticated user on a deployment intended to be read-only to forge or overwrite stored records that should not be modifiable in that deployment mode. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm <v26.06.0 Product Status: known_affected Remediations Vendor fix The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version. Relevant CWE: CWE-862 Missing Authorization Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N 4.0 7.1 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-90449 When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first. All access control for this administrative interface, which manages the credential store used to gate every other service in the deployment, is delegated entirely to that third-party interface's own login mechanism. Any authentication weakness in that bundled interface would compromise the credential store protecting the rest of the deployment. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm <v26.06.0 Product Status: known_affected Remediations Vendor fix The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N 4.0 6.9 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVE-2026-90450 The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request handler that is not explicitly registered in this table is reachable by any authenticated user regardless of their assigned role, and any newly added handler is fail-open by default until explicitly added to the table. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm <v26.06.0 Product Status: known_affected Remediations Vendor fix The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version. Relevant CWE: CWE-863 Incorrect Authorization Metrics CVSS Version Base Score Base Severity Vector String 3.1 4.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N 4.0 5.3 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-90451 An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration without running the setup routine that regenerates the value will use the known default, allowing an attacker aware of the default to forge valid authentication cookies for that component. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm <v26.06.0 Product Status: known_affected Remediations Vendor fix The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version. Relevant CWE: CWE-1392 Use of Default Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.9 MEDIUM CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N 4.0 8.2 HIGH CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-90452 Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker positioned on the network path between the proxy and the identity provider could impersonate the identity provider and issue forged authentication tokens accepted by the deployment. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm <v26.06.0 Product Status: known_affected Remediations Vendor fix The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version. Mitigation The fix for this issue introduces a KEYCLOAK_SSL_VERIFY configuration variable but does not enable certificate validation by default. In addition to updating to the latest version of Malcolm, affected users should explicitly set KEYCLOAK_SSL_VERIFY to enable certificate validation, particularly in deployments where the identity provider is not co-located on a fully trusted network segment. Relevant CWE: CWE-295 Improper Certificate Validation Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.3 MEDIUM CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N 4.0 6 MEDIUM CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-90453 A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. This allows an authenticated attacker to craft a request that causes another user's browser to be redirected to an arbitrary external destination after completing an upload. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm <v26.06.0 Product Status: known_affected Remediations Vendor fix The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version. Relevant CWE: CWE-601 URL Redirection to Untrusted Site ('Open Redirect') Metrics CVSS Version Base Score Base Severity Vector String 3.1 3.5 LOW CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N 4.0 5.1 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVE-2026-90454 A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tags attached to stored session records, and the proxy configuration otherwise permits the request method those routes use. This allows an authenticated user on a deployment intended to be read-only to add or remove tags on stored session records. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm <v26.06.0 Product Status: known_affected Remediations Vendor fix The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version. Relevant CWE: CWE-862 Missing Authorization Metrics CVSS Version Base Score Base Severity Vector String 3.1 4.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N 4.0 5.3 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVE-2026-90455 A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a single fixed, trusted vendor URL at initialization and does not process attacker-controlled input through the library, limiting practical exploitability of the reintroduced version in this context. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm <v26.06.0 Product Status: known_affected Remediations Vendor fix The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version. Relevant CWE: CWE-1395 Dependency on Vulnerable Third-Party Component Metrics CVSS Version Base Score Base Severity Vector String 3.1 3.7 LOW CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N 4.0 6.3 MEDIUM CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-90456 An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm <v26.06.0 Product Status: known_affected Remediations Vendor fix The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version. Relevant CWE: CWE-1392 Use of Default Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.1 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 9.2 CRITICAL CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-90457 The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash is written with permissions allowing it to be read by any local user. This is inconsistent with a separate, stronger hashing algorithm used for the same password on another authentication path. A party able to read this file, including a local user or a party with access to a configuration backup, could feasibly recover the underlying password through offline computation, compromising the administrative credential across every path that accepts it. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm <v26.06.0 Product Status: known_affected Remediations Vendor fix The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version. Relevant CWE: CWE-916 Use of Password Hash With Insufficient Computational Effort Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.2 MEDIUM CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 6.9 MEDIUM CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Acknowledgments CISA reported these vulnerabilities. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-09-11 Date Revision Summary 2026-09-11 1 Initial Publication 2026-10-01 2 Update A - Including self-reference to Web version Legal Notice and Terms of Use
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76504 Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates…
Read full source summary
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76504 Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service. The following versions of MikroTik RouterOS are affected: RouterOS <7.24 (CVE-2026-84411) CVSS Vendor Equipment Vulnerabilities v3 9.8 MikroTik MikroTik RouterOS Integer Underflow (Wrap or Wraparound) Background Critical Infrastructure Sectors: Communications,…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service. The following versions of MikroTik RouterOS are affected: RouterOS <7.24 (CVE-2026-84411) CVSS Vendor Equipment Vulnerabilities v3 9.8 MikroTik MikroTik RouterOS Integer Underflow (Wrap or Wraparound) Background Critical Infrastructure Sectors: Communications, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: Latvia Vulnerabilities Expand All + CVE-2026-84411 The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request. View CVE Details Affected Products MikroTik RouterOS Vendor: MikroTik Product Version: MikroTik RouterOS: <7.24 Product Status: known_affected Remediations Vendor fix MikroTik recommends users update RouterOS to version 7.24 or later. The upgrade can be downloaded from the MikroTik website. https://mikrotik.com/download Relevant CWE: CWE-191 Integer Underflow (Wrap or Wraparound) Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments An anonymous researcher reported this vulnerability to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-09-29 Date Revision Summary 2026-09-29 1 Initial Publication Legal Notice and Terms of Use
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to replace software and execute arbitrary code with root privileges. The following versions of Lantronix G520 Series Cellular Gateway are affected: G520 Series 2.6.0.4R6_stable (CVE-2026-84409, CVE-2026-91191) CVSS Vendor Equipment Vulnerabilities v3 7.5 Lantronix Lantronix G520 Series Cellular Gateway Improper Neutralization…
Read full source summary
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to replace software and execute arbitrary code with root privileges. The following versions of Lantronix G520 Series Cellular Gateway are affected: G520 Series 2.6.0.4R6_stable (CVE-2026-84409, CVE-2026-91191) CVSS Vendor Equipment Vulnerabilities v3 7.5 Lantronix Lantronix G520 Series Cellular Gateway Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Verification of Cryptographic Signature Background Critical Infrastructure Sectors: Transportation Systems, Energy, Water and Wastewater Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-84409 The device's update mechanism retrieves metadata for software updates over an unencrypted HTTP connection and stores portions of that metadata for later use. A management interface subsequently returns this stored value in a JSON response, and the web interface responsible for displaying update information inserts that value directly into the page as HTML. This behavior allows attacker‑controlled metadata to be interpreted as script content. In addition, the same authenticated origin provides an interface capable of executing system‑level commands with root privileges. An attacker able to influence update metadata could exploit these conditions to execute arbitrary code within the administrative context of the device. View CVE Details Affected Products Lantronix G520 Series Cellular Gateway Vendor: Lantronix Product Version: Lantronix G520 Series: 2.6.0.4R6_stable Product Status: known_affected Remediations Mitigation Lantronix has addressed the reported issues with release version 2.6.0.7R6 which is available on their website. https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1889828865/Latest+firmware+for+the+G520+Series+G526+G526RP+G527+G528 Mitigation For more information, see the Lantronix Vulnerability Library. https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/ Mitigation For more information or technical assistance, contact Lantronix support: Support@lantronix.com mailto:Support@lantronix.com Relevant CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H 4.0 7.7 HIGH CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N CVE-2026-91191 The device's update mechanism includes conditions that allow unauthorized software packages to be accepted as authentic. During the boot process, the stock done function disables signature verification in the OPKG configuration before restoring optional packages from a writable, unsigned feed. Separately, the publicly distributed SDK contains the production private key whose corresponding public key is trusted by both stable and beta firmware builds. Either issue undermines package authenticity, and together they allow an attacker to provide packages that appear valid to the system. Even if signature enforcement is restored, the exposed production key enables an attacker to generate signatures that the device will continue to trust. An attacker who can supply a malicious package may be able to execute arbitrary code with root privileges during installation. View CVE Details Affected Products Lantronix G520 Series Cellular Gateway Vendor: Lantronix Product Version: Lantronix G520 Series: 2.6.0.4R6_stable Product Status: known_affected Remediations Mitigation Lantronix has addressed the reported issues with release version 2.6.0.7R6 which is available on their website. https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1889828865/Latest+firmware+for+the+G520+Series+G526+G526RP+G527+G528 Mitigation For more information, see the Lantronix Vulnerability Library. https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/ Mitigation For more information or technical assistance, contact Lantronix support: Support@lantronix.com mailto:Support@lantronix.com Relevant CWE: CWE-347 Improper Verification of Cryptographic Signature Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H 4.0 7.7 HIGH CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments Ievgen Bondarenko reported these vulnerabilities to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-09-29 Date Revision Summary 2026-09-29 1 Initial Publication Legal Notice and Terms of Use
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-86950 Apple Multiple Products Out-of-Bounds Write Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates…
Read full source summary
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-86950 Apple Multiple Products Out-of-Bounds Write Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to access, modify, or delete sensitive user data and critical system files, potentially compromising the operation of the entire platform. The following versions of Viidure Dashcam Android Application are affected: Dashcam Android Application <=3.3.1.260403 (CVE-2026-94204, CVE-2026-96587) CVSS Vendor Equipment Vulnerabilities…
Read full source summary
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to access, modify, or delete sensitive user data and critical system files, potentially compromising the operation of the entire platform. The following versions of Viidure Dashcam Android Application are affected: Dashcam Android Application <=3.3.1.260403 (CVE-2026-94204, CVE-2026-96587) CVSS Vendor Equipment Vulnerabilities v3 10 Viidure Viidure Dashcam Android Application Incorrect Permission Assignment for Critical Resource, Use of Hard-coded Credentials Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-94204 The central cloud storage backend for the entire dashcam platform is misconfigured with public‑read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive user records, live dashcam footage, application packages, and firmware files are exposed to anyone on the internet. View CVE Details Affected Products Viidure Dashcam Android Application Vendor: Viidure Product Version: Viidure Dashcam Android Application: <=3.3.1.260403 Product Status: known_affected Remediations No fix planned Viidure did not respond to CISA's coordination attempts. Users of affected versions of the Viidure Dashcam Android Application are advised to contact Viidure customer support for additional information https://viidure.app/. Relevant CWE: CWE-732 Incorrect Permission Assignment for Critical Resource Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-96587 The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries. View CVE Details Affected Products Viidure Dashcam Android Application Vendor: Viidure Product Version: Viidure Dashcam Android Application: <=3.3.1.260403 Product Status: known_affected Remediations No fix planned Viidure did not respond to CISA's coordination attempts. Users of affected versions of the Viidure Dashcam Android Application are advised to contact Viidure customer support for additional information https://viidure.app/. Relevant CWE: CWE-798 Use of Hard-coded Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 10 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 4.0 10 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H Acknowledgments Bugrahan Karahan reported these vulnerabilities to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-09-29 Date Revision Summary 2026-09-29 1 Initial Publication Legal Notice and Terms of Use
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access critical data or execute arbitrary code. The following versions of Toptech TMS7 and TopHAT are affected: TMS7 7.6.3 (CVE-2026-71379, CVE-2026-70356, CVE-2026-72510, CVE-2026-63713, CVE-2026-68954, CVE-2026-68068, CVE-2026-72507, CVE-2026-71302, CVE-2026-69662, CVE-2026-71189) TopHAT 7.6.3 (CVE-2026-71379,…
Read full source summary
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access critical data or execute arbitrary code. The following versions of Toptech TMS7 and TopHAT are affected: TMS7 7.6.3 (CVE-2026-71379, CVE-2026-70356, CVE-2026-72510, CVE-2026-63713, CVE-2026-68954, CVE-2026-68068, CVE-2026-72507, CVE-2026-71302, CVE-2026-69662, CVE-2026-71189) TopHAT 7.6.3 (CVE-2026-71379, CVE-2026-70356, CVE-2026-72510, CVE-2026-63713, CVE-2026-68954, CVE-2026-68068, CVE-2026-72507, CVE-2026-71302, CVE-2026-69662, CVE-2026-71189) CVSS Vendor Equipment Vulnerabilities v3 10 Toptech Systems Toptech TMS7 and TopHAT Files or Directories Accessible to External Parties, Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), Session Fixation, Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection'), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Background Critical Infrastructure Sectors: Energy, Chemical, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-71379 The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request. View CVE Details Affected Products Toptech TMS7 and TopHAT Vendor: Toptech Systems Product Version: Toptech Systems TMS7: 7.6.3, Toptech Systems TopHAT: 7.6.3 Product Status: known_affected Remediations Mitigation Toptech Systems sent a security advisory to their customers on July 20, 2026. The issues have been addressed in release 7.8. Users can get the latest release and more information on these issues, at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security Relevant CWE: CWE-552 Files or Directories Accessible to External Parties Metrics CVSS Version Base Score Base Severity Vector String 3.1 10 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 4.0 10 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVE-2026-70356 The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server. View CVE Details Affected Products Toptech TMS7 and TopHAT Vendor: Toptech Systems Product Version: Toptech Systems TMS7: 7.6.3, Toptech Systems TopHAT: 7.6.3 Product Status: known_affected Remediations Mitigation Toptech Systems sent a security advisory to their customers on July 20, 2026. The issues have been addressed in release 7.8. Users can get the latest release and more information on these issues, at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security Relevant CWE: CWE-434 Unrestricted Upload of File with Dangerous Type Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.1 CRITICAL CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H 4.0 9.4 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVE-2026-72510 The "supplier_no" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection. View CVE Details Affected Products Toptech TMS7 and TopHAT Vendor: Toptech Systems Product Version: Toptech Systems TMS7: 7.6.3, Toptech Systems TopHAT: 7.6.3 Product Status: known_affected Remediations Mitigation Toptech Systems sent a security advisory to their customers on July 20, 2026. The issues have been addressed in release 7.8. Users can get the latest release and more information on these issues, at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security Relevant CWE: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 9 CRITICAL CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H 4.0 8.5 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H CVE-2026-63713 The "search" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulnerability. View CVE Details Affected Products Toptech TMS7 and TopHAT Vendor: Toptech Systems Product Version: Toptech Systems TMS7: 7.6.3, Toptech Systems TopHAT: 7.6.3 Product Status: known_affected Remediations Mitigation Toptech Systems sent a security advisory to their customers on July 20, 2026. The issues have been addressed in release 7.8. Users can get the latest release and more information on these issues, at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security Relevant CWE: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 9 CRITICAL CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H 4.0 8.5 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H CVE-2026-68954 The "pattern" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability. View CVE Details Affected Products Toptech TMS7 and TopHAT Vendor: Toptech Systems Product Version: Toptech Systems TMS7: 7.6.3, Toptech Systems TopHAT: 7.6.3 Product Status: known_affected Remediations Mitigation Toptech Systems sent a security advisory to their customers on July 20, 2026. The issues have been addressed in release 7.8. Users can get the latest release and more information on these issues, at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security Relevant CWE: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 9 CRITICAL CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H 4.0 8.5 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H CVE-2026-68068 The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability. View CVE Details Affected Products Toptech TMS7 and TopHAT Vendor: Toptech Systems Product Version: Toptech Systems TMS7: 7.6.3, Toptech Systems TopHAT: 7.6.3 Product Status: known_affected Remediations Mitigation Toptech Systems sent a security advisory to their customers on July 20, 2026. The issues have been addressed in release 7.8. Users can get the latest release and more information on these issues, at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security Relevant CWE: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 9 CRITICAL CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H 4.0 8.5 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H CVE-2026-72507 The "reportType" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability. View CVE Details Affected Products Toptech TMS7 and TopHAT Vendor: Toptech Systems Product Version: Toptech Systems TMS7: 7.6.3, Toptech Systems TopHAT: 7.6.3 Product Status: known_affected Remediations Mitigation Toptech Systems sent a security advisory to their customers on July 20, 2026. The issues have been addressed in release 7.8. Users can get the latest release and more information on these issues, at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security Relevant CWE: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 9 CRITICAL CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H 4.0 8.5 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H CVE-2026-71302 The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an attacker to predefine a session ID and reuse it after victim authentication, resulting in session takeover. View CVE Details Affected Products Toptech TMS7 and TopHAT Vendor: Toptech Systems Product Version: Toptech Systems TMS7: 7.6.3, Toptech Systems TopHAT: 7.6.3 Product Status: known_affected Remediations Mitigation Toptech Systems sent a security advisory to their customers on July 20, 2026. The issues have been addressed in release 7.8. Users can get the latest release and more information on these issues, at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security Relevant CWE: CWE-384 Session Fixation Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.1 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L 4.0 7.5 HIGH CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N CVE-2026-69662 The application uses unsafe functions that allow execution of inline scripts and string evaluation functions. View CVE Details Affected Products Toptech TMS7 and TopHAT Vendor: Toptech Systems Product Version: Toptech Systems TMS7: 7.6.3, Toptech Systems TopHAT: 7.6.3 Product Status: known_affected Remediations Mitigation Toptech Systems sent a security advisory to their customers on July 20, 2026. The issues have been addressed in release 7.8. Users can get the latest release and more information on these issues, at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security Relevant CWE: CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 3.7 LOW CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N 4.0 2.1 LOW CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVE-2026-71189 An attacker can construct a request that, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application. View CVE Details Affected Products Toptech TMS7 and TopHAT Vendor: Toptech Systems Product Version: Toptech Systems TMS7: 7.6.3, Toptech Systems TopHAT: 7.6.3 Product Status: known_affected Remediations Mitigation Toptech Systems sent a security advisory to their customers on July 20, 2026. The issues have been addressed in release 7.8. Users can get the latest release and more information on these issues, at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security Relevant CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Metrics CVSS Version Base Score Base Severity Vector String 3.1 3.5 LOW CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N 4.0 4.8 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Acknowledgments Sachin Shetty and Roy Duisters of Shell CyberDefence reported these vulnerabilities to Toptech and CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-09-29 Date Revision Summary 2026-09-29 1 Initial Publication Legal Notice and Terms of Use
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information, access user accounts, execute OS-level commands, or take full control over the device. The following versions of Anjvision YSSD-RTMP-H5 are affected: YSSD-RTMP-H5 firmware 3.3.2.4_build_2024-12-26 (CVE-2026-100291, CVE-2026-100292, CVE-2026-100293, CVE-2026-100294, CVE-2026-100295,…
Read full source summary
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information, access user accounts, execute OS-level commands, or take full control over the device. The following versions of Anjvision YSSD-RTMP-H5 are affected: YSSD-RTMP-H5 firmware 3.3.2.4_build_2024-12-26 (CVE-2026-100291, CVE-2026-100292, CVE-2026-100293, CVE-2026-100294, CVE-2026-100295, CVE-2026-100296, CVE-2026-100297, CVE-2026-100298, CVE-2026-100299) CVSS Vendor Equipment Vulnerabilities v3 9.8 Anjvision Anjvision YSSD-RTMP-H5 Initialization of a Resource with an Insecure Default, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Verification of Cryptographic Signature, Use of Hard-coded Credentials, Active Debug Code, Improper Check for Unusual or Exceptional Conditions, Server-Side Request Forgery (SSRF), Insufficiently Protected Credentials, Use of Weak Credentials Background Critical Infrastructure Sectors: Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-100291 In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations. View CVE Details Affected Products Anjvision YSSD-RTMP-H5 Vendor: Anjvision Product Version: Anjvision YSSD-RTMP-H5 firmware: 3.3.2.4_build_2024-12-26 Product Status: known_affected Remediations No fix planned Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of YSSD-RTMP-H5 are invited to contact Anjvision customer support for additional information http://www.anjvision.com/problem/list-129-cn.html . Relevant CWE: CWE-1188 Initialization of a Resource with an Insecure Default Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-100292 In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through an authenticated request, allowing additional commands to be sent to a backend service. Once active, this pathway can unintentionally expose system‑level functionality that could be misused if crafted inputs reach the underlying command handler. View CVE Details Affected Products Anjvision YSSD-RTMP-H5 Vendor: Anjvision Product Version: Anjvision YSSD-RTMP-H5 firmware: 3.3.2.4_build_2024-12-26 Product Status: known_affected Remediations No fix planned Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of YSSD-RTMP-H5 are invited to contact Anjvision customer support for additional information http://www.anjvision.com/problem/list-129-cn.html . Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-100293 In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud update mechanisms apply new firmware without any cryptographic verification, relying only on basic hashing. This design allows an attacker who can reach the update routine to introduce untrusted firmware images that the device will accept as valid. View CVE Details Affected Products Anjvision YSSD-RTMP-H5 Vendor: Anjvision Product Version: Anjvision YSSD-RTMP-H5 firmware: 3.3.2.4_build_2024-12-26 Product Status: known_affected Remediations No fix planned Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of YSSD-RTMP-H5 are invited to contact Anjvision customer support for additional information http://www.anjvision.com/problem/list-129-cn.html . Relevant CWE: CWE-347 Improper Verification of Cryptographic Signature Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-100294 In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed devices. Anyone obtaining the public firmware package can reuse these values to interact with the cloud service in ways not intended for normal operation. View CVE Details Affected Products Anjvision YSSD-RTMP-H5 Vendor: Anjvision Product Version: Anjvision YSSD-RTMP-H5 firmware: 3.3.2.4_build_2024-12-26 Product Status: known_affected Remediations No fix planned Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of YSSD-RTMP-H5 are invited to contact Anjvision customer support for additional information http://www.anjvision.com/problem/list-129-cn.html . Relevant CWE: CWE-798 Use of Hard-coded Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-100295 In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an internal debug interface can be enabled through an undocumented pathway, exposing functions not intended for normal operation. When activated, this interface allows actions that could unintentionally provide elevated system access. View CVE Details Affected Products Anjvision YSSD-RTMP-H5 Vendor: Anjvision Product Version: Anjvision YSSD-RTMP-H5 firmware: 3.3.2.4_build_2024-12-26 Product Status: known_affected Remediations No fix planned Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of YSSD-RTMP-H5 are invited to contact Anjvision customer support for additional information http://www.anjvision.com/problem/list-129-cn.html. Relevant CWE: CWE-489 Active Debug Code Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L 4.0 7.1 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-100296 In Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4, an empty-body POST to /setUserConfig, dispatched through the web server's SOAP-RPC handler, silently downgrades the administrator password to the default value and corrupts the in-memory authentication state until the device reloads. The handler does not verify the session's privilege level, so any authenticated user can trigger it. View CVE Details Affected Products Anjvision YSSD-RTMP-H5 Vendor: Anjvision Product Version: Anjvision YSSD-RTMP-H5 firmware: 3.3.2.4_build_2024-12-26 Product Status: known_affected Remediations No fix planned Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of YSSD-RTMP-H5 are invited to contact Anjvision customer support for additional information http://www.anjvision.com/problem/list-129-cn.html. Relevant CWE: CWE-754 Improper Check for Unusual or Exceptional Conditions Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.1 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H 4.0 7.2 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-100297 In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an unauthenticated network check function can be triggered to probe arbitrary hosts from the device's internal network. This may expose internal information or leak data via DNS queries. View CVE Details Affected Products Anjvision YSSD-RTMP-H5 Vendor: Anjvision Product Version: Anjvision YSSD-RTMP-H5 firmware: 3.3.2.4_build_2024-12-26 Product Status: known_affected Remediations No fix planned Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of YSSD-RTMP-H5 are invited to contact Anjvision customer support for additional information http://www.anjvision.com/problem/list-129-cn.html. Relevant CWE: CWE-918 Server-Side Request Forgery (SSRF) Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N 4.0 6.9 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-100298 In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, two user‑information endpoints can reveal sensitive device and account details under conditions that are not intended for normal operation. View CVE Details Affected Products Anjvision YSSD-RTMP-H5 Vendor: Anjvision Product Version: Anjvision YSSD-RTMP-H5 firmware: 3.3.2.4_build_2024-12-26 Product Status: known_affected Remediations No fix planned Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of YSSD-RTMP-H5 are invited to contact Anjvision customer support for additional information http://www.anjvision.com/problem/list-129-cn.html. Relevant CWE: CWE-522 Insufficiently Protected Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-100299 In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the device includes a legacy password hash on the serial console that relies on a weak DES‑based encryption. View CVE Details Affected Products Anjvision YSSD-RTMP-H5 Vendor: Anjvision Product Version: Anjvision YSSD-RTMP-H5 firmware: 3.3.2.4_build_2024-12-26 Product Status: known_affected Remediations No fix planned Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of YSSD-RTMP-H5 are invited to contact Anjvision customer support for additional information http://www.anjvision.com/problem/list-129-cn.html. Relevant CWE: CWE-1391 Use of Weak Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.8 MEDIUM CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 7 HIGH CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments Andrew Lee reported these vulnerabilities to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional no_fix_planned guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and no_fix_planned Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-09-29 Date Revision Summary 2026-09-29 1 Initial Publication Legal Notice and Terms of Use
View CSAF Summary Successful exploitation of this vulnerability may allow attackers to achieve remote command execution on affected devices, potentially with root privileges, leading to full compromise of the camera system. The following versions of VIVOTEK Camera Firmware are affected: V Series model_FD9187 (CVE-2026-22755) V Series model_FD9189 (CVE-2026-22755) V Series model_FD9365 (CVE-2026-22755) V Series…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability may allow attackers to achieve remote command execution on affected devices, potentially with root privileges, leading to full compromise of the camera system. The following versions of VIVOTEK Camera Firmware are affected: V Series model_FD9187 (CVE-2026-22755) V Series model_FD9189 (CVE-2026-22755) V Series model_FD9365 (CVE-2026-22755) V Series model_FD9387 (CVE-2026-22755) V Series model_FD9389 (CVE-2026-22755) V Series model_FD9391 (CVE-2026-22755) C Series model_FE9180 (CVE-2026-22755) V Series model_FE9191 (CVE-2026-22755) V Series model_FE9382 (CVE-2026-22755) V Series model_FE9391 (CVE-2026-22755) V Series model_IB9365 (CVE-2026-22755) V Series model_IB9387 (CVE-2026-22755) V Series model_IB9389 (CVE-2026-22755) V Series model_IB939 (CVE-2026-22755) V Series model_IP9165 (CVE-2026-22755) V Series model_IP9171 (CVE-2026-22755) S Series model_IP9172 (CVE-2026-22755) V Series model_IP9181 (CVE-2026-22755) V Series model_IP9191 (CVE-2026-22755) V Series model_IT9389 (CVE-2026-22755) V Series model_MA9321 (CVE-2026-22755) V Series model_MA9322 (CVE-2026-22755) S Series model_MS9321 (CVE-2026-22755) V Series model_MS9390 (CVE-2026-22755) S Series model_TB9330 (CVE-2026-22755) Dome model_FD8365 (CVE-2026-22755) Dome model_FD8365v2 (CVE-2026-22755) Dome model_FD9165 (CVE-2026-22755) Dome model_FD9171 (CVE-2026-22755) Dome model_FD9371 (CVE-2026-22755) Dome model_FD9381 (CVE-2026-22755) Panoramic model_FE9181 (CVE-2026-22755) Panoramic model_FE9381 (CVE-2026-22755) VIVOTEK Camera model_FE9582 (CVE-2026-22755) VIVOTEK Camera model_IB93587LPR (CVE-2026-22755) Bullet model_IB9371 (CVE-2026-22755) Bullet model_IB9381 (CVE-2026-22755) CVSS Vendor Equipment Vulnerabilities v3 10 VIVOTEK VIVOTEK Camera Firmware Improper Neutralization of Special Elements used in a Command ('Command Injection') Background Critical Infrastructure Sectors: Government Services and Facilities, Transportation Systems, Commercial Facilities, Energy, Critical Manufacturing, Financial Services Countries/Areas Deployed: Worldwide Company Headquarters Location: Taiwan Vulnerabilities Expand All + CVE-2026-22755 A command injection vulnerability has been identified in firmware modules used by multiple network camera models from VIVOTEK. View CVE Details Affected Products VIVOTEK Camera Firmware Vendor: VIVOTEK Product Version: VIVOTEK V Series: model_FD9187, VIVOTEK V Series: model_FD9189, VIVOTEK V Series: model_FD9365, VIVOTEK V Series: model_FD9387, VIVOTEK V Series: model_FD9389, VIVOTEK V Series: model_FD9391, VIVOTEK C Series: model_FE9180, VIVOTEK V Series: model_FE9191, VIVOTEK V Series: model_FE9382, VIVOTEK V Series: model_FE9391, VIVOTEK V Series: model_IB9365, VIVOTEK V Series: model_IB9387, VIVOTEK V Series: model_IB9389, VIVOTEK V Series: model_IB939, VIVOTEK V Series: model_IP9165, VIVOTEK V Series: model_IP9171, VIVOTEK S Series: model_IP9172, VIVOTEK V Series: model_IP9181, VIVOTEK V Series: model_IP9191, VIVOTEK V Series: model_IT9389, VIVOTEK V Series: model_MA9321, VIVOTEK V Series: model_MA9322, VIVOTEK S Series: model_MS9321, VIVOTEK V Series: model_MS9390, VIVOTEK S Series: model_TB9330, VIVOTEK Dome: model_FD8365, VIVOTEK Dome: model_FD8365v2, VIVOTEK Dome: model_FD9165, VIVOTEK Dome: model_FD9171, VIVOTEK Dome: model_FD9371, VIVOTEK Dome: model_FD9381, VIVOTEK Panoramic: model_FE9181, VIVOTEK Panoramic: model_FE9381, VIVOTEK VIVOTEK Camera: model_FE9582, VIVOTEK VIVOTEK Camera: model_IB93587LPR, VIVOTEK Bullet: model_IB9371, VIVOTEK Bullet: model_IB9381 Product Status: known_affected Remediations Mitigation VIVOTEK has addressed this issue and encourages users to download and install the latest firmware available. https://www.vivotek.com/en-US/resource/download-center/software-app-vadp-package Relevant CWE: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 10 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 4.0 10 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H Acknowledgments CISA discovered a public proof of concept as authored by indoushka and reported it to VIVOTEK. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-09-29 Date Revision Summary 2026-09-29 1 Initial Publication Legal Notice and Terms of Use
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to inject malformed messages which may lead to a denial-of-service condition. The following versions of Baicells Nova 430H are affected: Nova 430H eNodeB (model pBS3101SH) <=BaiBLQ_3.0.12 (CVE-2026-96274) CVSS Vendor Equipment Vulnerabilities v3 7.4 Baicells Technologies Baicells Nova 430H Uncaught Exception Background Critical…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to inject malformed messages which may lead to a denial-of-service condition. The following versions of Baicells Nova 430H are affected: Nova 430H eNodeB (model pBS3101SH) <=BaiBLQ_3.0.12 (CVE-2026-96274) CVSS Vendor Equipment Vulnerabilities v3 7.4 Baicells Technologies Baicells Nova 430H Uncaught Exception Background Critical Infrastructure Sectors: Communications, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-96274 In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS payload. Because the eNodeB does not properly validate this payload, it forwards the message to the core network, which can trigger a shutdown of the signaling association for the cell. This results in a temporary service disruption until the eNodeB and core network re-establish connectivity. View CVE Details Affected Products Baicells Nova 430H Vendor: Baicells Technologies Product Version: Baicells Technologies Nova 430H eNodeB (model pBS3101SH): <=BaiBLQ_3.0.12 Product Status: known_affected Remediations No fix planned Baicells has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of Nova 430H eNodeB are invited to contact Baicells customer support for additional information (https://www.baicells.com/contact-us). Relevant CWE: CWE-248 Uncaught Exception Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.4 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H 4.0 8.3 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H Acknowledgments Qiqing Huang reported this vulnerability to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. This vulnerability is not exploitable remotely. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-09-29 Date Revision Summary 2026-09-29 1 Initial Publication Legal Notice and Terms of Use
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-88771 Citrix NetScaler Improper Input Validation Vulnerability CVE-2026-88772 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose…
Read full source summary
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-88771 Citrix NetScaler Improper Input Validation Vulnerability CVE-2026-88772 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778. CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities…
Read full source summary
CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778. CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally. Because updating Citrix NetScaler deployments can be complex and may require downtime, CISA is issuing this Alert to help organizations assess exposure, prioritize mitigation, and account for these vulnerabilities into their risk-management activities. Given the potential consequences of successful exploitation and the fact that malicious actors are exploiting at least some of these vulnerabilities, CISA urges users and administrators to review Citrix’s advisories. If possible, users are encouraged to check for indication of compromise prior to patching. Citrix has made indicators of compromise available through NetScaler Console and published additional guidance in their recent publication, Security Bulletin for CVE-2026-88771 through CVE-2026-88778, to support organizations in assessing potential compromise. Should your organization suspect compromise, it is important to preserve forensic evidence prior to applying updates, as updates may result in loss of forensic visibility. Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 - Security Updates - Citrix Community Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 Steps to Take if NetScaler ADC is Suspected to be Compromised Disclaimer The information in this report is being provided “as is” for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA.
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-87902 WordPress Core Remote File Inclusion Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on…
Read full source summary
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-87902 WordPress Core Remote File Inclusion Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.