Historical snapshot · Cybersecurity

CISA Advisories

Cybersecurity advisories and mitigation guidance for networks and critical infrastructure.

This page is an archived snapshot of the CISA Advisories feed collected on Feb 11, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
30 recordsOfficial source · JSON
· CISA Cybersecurity Advisory

Avation Light Engine Pro

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take full control of the device. The following versions of Avation Light Engine Pro are affected: Light Engine Pro vers:all/* (CVE-2026-1341) CVSS Vendor Equipment Vulnerabilities v3 9.8 Avation Avation Light Engine Pro Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Commercial…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take full control of the device. The following versions of Avation Light Engine Pro are affected: Light Engine Pro vers:all/* (CVE-2026-1341) CVSS Vendor Equipment Vulnerabilities v3 9.8 Avation Avation Light Engine Pro Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: Australia Vulnerabilities Expand All + CVE-2026-1341 Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control. View CVE Details Affected Products Avation Light Engine Pro Vendor: Avation Product Version: Avation Light Engine Pro: vers:all/* Product Status: known_affected Remediations Vendor fix Avation has not responded to CISA's request to coordinate. Users of Avation Light Engine Pro are encouraged to contact Avation for more information. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Acknowledgments Souvik Kandar reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-02-03 Date Revision Summary 2026-02-03 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Rockwell Automation ArmorStart LT

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation ArmorStart LT are affected: ArmorStart LT 290D <=V2.002 (CVE-2025-9464, CVE-2025-9465, CVE-2025-9466, CVE-2025-9278, CVE-2025-9279, CVE-2025-9280, CVE-2025-9281, CVE-2025-9282, CVE-2025-9283) ArmorStart LT 291D <=V2.002 (CVE-2025-9464,…
Read full source summary
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation ArmorStart LT are affected: ArmorStart LT 290D <=V2.002 (CVE-2025-9464, CVE-2025-9465, CVE-2025-9466, CVE-2025-9278, CVE-2025-9279, CVE-2025-9280, CVE-2025-9281, CVE-2025-9282, CVE-2025-9283) ArmorStart LT 291D <=V2.002 (CVE-2025-9464, CVE-2025-9465, CVE-2025-9466, CVE-2025-9278, CVE-2025-9279, CVE-2025-9280, CVE-2025-9281, CVE-2025-9282, CVE-2025-9283) ArmorStart LT 294D <=V2.002 (CVE-2025-9464, CVE-2025-9465, CVE-2025-9466, CVE-2025-9278, CVE-2025-9279, CVE-2025-9280, CVE-2025-9281, CVE-2025-9282, CVE-2025-9283) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation ArmorStart LT Uncontrolled Resource Consumption Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2025-9464 A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. This vulnerability is triggered during fuzzing of multiple CIP classes, which causes the CIP port to become unresponsive. View CVE Details Affected Products Rockwell Automation ArmorStart LT Vendor: Rockwell Automation Product Version: Rockwell Automation ArmorStart LT 290D: <=V2.002, Rockwell Automation ArmorStart LT 291D: <=V2.002, Rockwell Automation ArmorStart LT 294D: <=V2.002 Product Status: known_affected Remediations Mitigation There is no patch or upgrade at this time. Rockwell Automation recommends users apply security best practices to mitigate the risk of these vulnerabilities. Mitigation See Rockwell Automation's SD1768 advisory for more information. Relevant CWE: CWE-400 Uncontrolled Resource Consumption Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2025-9465 A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. View CVE Details Affected Products Rockwell Automation ArmorStart LT Vendor: Rockwell Automation Product Version: Rockwell Automation ArmorStart LT 290D: <=V2.002, Rockwell Automation ArmorStart LT 291D: <=V2.002, Rockwell Automation ArmorStart LT 294D: <=V2.002 Product Status: known_affected Remediations Mitigation There is no patch or upgrade at this time. Rockwell Automation recommends users apply security best practices to mitigate the risk of these vulnerabilities. Mitigation See Rockwell Automation's SD1768 advisory for more information. Relevant CWE: CWE-400 Uncontrolled Resource Consumption Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2025-9466 A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP and CIP grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. View CVE Details Affected Products Rockwell Automation ArmorStart LT Vendor: Rockwell Automation Product Version: Rockwell Automation ArmorStart LT 290D: <=V2.002, Rockwell Automation ArmorStart LT 291D: <=V2.002, Rockwell Automation ArmorStart LT 294D: <=V2.002 Product Status: known_affected Remediations Mitigation There is no patch or upgrade at this time. Rockwell Automation recommends users apply security best practices to mitigate the risk of these vulnerabilities. Mitigation See Rockwell Automation's SD1768 advisory for more information. Relevant CWE: CWE-400 Uncontrolled Resource Consumption Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2025-9278 A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. After running a Burp Suite active scan, the device loses ICMP connectivity, causing the web application to become inaccessible. View CVE Details Affected Products Rockwell Automation ArmorStart LT Vendor: Rockwell Automation Product Version: Rockwell Automation ArmorStart LT 290D: <=V2.002, Rockwell Automation ArmorStart LT 291D: <=V2.002, Rockwell Automation ArmorStart LT 294D: <=V2.002 Product Status: known_affected Remediations Mitigation There is no patch or upgrade at this time. Rockwell Automation recommends users apply security best practices to mitigate the risk of these vulnerabilities. Mitigation See Rockwell Automation's SD1768 advisory for more information. Relevant CWE: CWE-400 Uncontrolled Resource Consumption Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2025-9279 A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limit Storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. View CVE Details Affected Products Rockwell Automation ArmorStart LT Vendor: Rockwell Automation Product Version: Rockwell Automation ArmorStart LT 290D: <=V2.002, Rockwell Automation ArmorStart LT 291D: <=V2.002, Rockwell Automation ArmorStart LT 294D: <=V2.002 Product Status: known_affected Remediations Mitigation There is no patch or upgrade at this time. Rockwell Automation recommends users apply security best practices to mitigate the risk of these vulnerabilities. Mitigation See Rockwell Automation's SD1768 advisory for more information. Relevant CWE: CWE-400 Uncontrolled Resource Consumption Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2025-9280 A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. Fuzzing performed using Defensics causes the device to become unresponsive, requiring a reboot. View CVE Details Affected Products Rockwell Automation ArmorStart LT Vendor: Rockwell Automation Product Version: Rockwell Automation ArmorStart LT 290D: <=V2.002, Rockwell Automation ArmorStart LT 291D: <=V2.002, Rockwell Automation ArmorStart LT 294D: <=V2.002 Product Status: known_affected Remediations Mitigation There is no patch or upgrade at this time. Rockwell Automation recommends users apply security best practices to mitigate the risk of these vulnerabilities. Mitigation See Rockwell Automation's SD1768 advisory for more information. Relevant CWE: CWE-400 Uncontrolled Resource Consumption Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2025-9281 A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive step limit storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. View CVE Details Affected Products Rockwell Automation ArmorStart LT Vendor: Rockwell Automation Product Version: Rockwell Automation ArmorStart LT 290D: <=V2.002, Rockwell Automation ArmorStart LT 291D: <=V2.002, Rockwell Automation ArmorStart LT 294D: <=V2.002 Product Status: known_affected Remediations Mitigation There is no patch or upgrade at this time. Rockwell Automation recommends users apply security best practices to mitigate the risk of these vulnerabilities. Mitigation See Rockwell Automation's SD1768 advisory for more information. Relevant CWE: CWE-400 Uncontrolled Resource Consumption Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2025-9282 A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive limited storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. View CVE Details Affected Products Rockwell Automation ArmorStart LT Vendor: Rockwell Automation Product Version: Rockwell Automation ArmorStart LT 290D: <=V2.002, Rockwell Automation ArmorStart LT 291D: <=V2.002, Rockwell Automation ArmorStart LT 294D: <=V2.002 Product Status: known_affected Remediations Mitigation There is no patch or upgrade at this time. Rockwell Automation recommends users apply security best practices to mitigate the risk of these vulnerabilities. Mitigation See Rockwell Automation's SD1768 advisory for more information. Relevant CWE: CWE-400 Uncontrolled Resource Consumption Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2025-9283 A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limits Storms tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. View CVE Details Affected Products Rockwell Automation ArmorStart LT Vendor: Rockwell Automation Product Version: Rockwell Automation ArmorStart LT 290D: <=V2.002, Rockwell Automation ArmorStart LT 291D: <=V2.002, Rockwell Automation ArmorStart LT 294D: <=V2.002 Product Status: known_affected Remediations Mitigation There is no patch or upgrade at this time. Rockwell Automation recommends users apply security best practices to mitigate the risk of these vulnerabilities. Mitigation See Rockwell Automation's SD1768 advisory for more information. Relevant CWE: CWE-400 Uncontrolled Resource Consumption Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Acknowledgments Rockwell Automation reported these vulnerabilties to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-01-29 Date Revision Summary 2026-01-29 1 Initial Republication of Rockwell Automation advisory SD1768 Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

KiloView Encoder Series (Update A)

View CSAF Summary Successful exploitation of this vulnerability could allow an unauthenticated attacker to create or delete administrator accounts, granting full administrative control. The following versions of KiloView Encoder Series are affected: Encoder Series E1 hardware Version 1.4 4.7.2516 (CVE-2026-1453) Encoder Series E1 hardware Version 1.6.20…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an unauthenticated attacker to create or delete administrator accounts, granting full administrative control. The following versions of KiloView Encoder Series are affected: Encoder Series E1 hardware Version 1.4 4.7.2516 (CVE-2026-1453) Encoder Series E1 hardware Version 1.6.20 4.7.2511|4.8.2523|4.8.2611|4.6.2400|4.7.2512|4.8.2561|4.8.2554|4.3.2029|4.8.2555|4.6.2408 (CVE-2026-1453) Encoder Series E1-s hardware Version 1.4 4.7.2516|4.8.2519|4.8.2525|4.8.2611|4.8.2561|4.8.2554|4.8.2523 (CVE-2026-1453) Encoder Series E2 hardware Version 1.7.20 4.8.2611|4.8.2561 (CVE-2026-1453) Encoder Series E2 hardware Version 1.8.20 4.8.2523|4.8.2611|4.8.2554 (CVE-2026-1453) Encoder Series G1 hardware Version 1.6.20 4.8.2561 (CVE-2026-1453) Encoder Series P1 hardware Version 1.3.20 4.8.2633|4.8.2608 (CVE-2026-1453) Encoder Series P2 hardware Version 1.8.20 4.8.2633 (CVE-2026-1453) Encoder Series RE1 hardware Version 2.0.00 4.7.2513 (CVE-2026-1453) Encoder Series RE1 hardware Version 3.0.00 4.8.2519|4.8.2561|4.8.2611|4.8.2525 (CVE-2026-1453) CVSS Vendor Equipment Vulnerabilities v3 9.8 KiloView KiloView Encoder Series Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Communications, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-1453 A missing authentication for critical function vulnerability in KiloView Encoder Series could allow an unauthenticated attacker to create or delete administrator accounts. This vulnerability can grant the attacker full administrative control over the product. View CVE Details Affected Products KiloView Encoder Series Vendor: KiloView Product Version: KiloView Encoder Series E1 hardware Version 1.4: 4.7.2516, KiloView Encoder Series E1 hardware Version 1.6.20: 4.7.2511|4.8.2523|4.8.2611|4.6.2400|4.7.2512|4.8.2561|4.8.2554|4.3.2029|4.8.2555|4.6.2408, KiloView Encoder Series E1-s hardware Version 1.4: 4.7.2516|4.8.2519|4.8.2525|4.8.2611|4.8.2561|4.8.2554|4.8.2523, KiloView Encoder Series E2 hardware Version 1.7.20: 4.8.2611|4.8.2561, KiloView Encoder Series E2 hardware Version 1.8.20: 4.8.2523|4.8.2611|4.8.2554, KiloView Encoder Series G1 hardware Version 1.6.20: 4.8.2561, KiloView Encoder Series P1 hardware Version 1.3.20: 4.8.2633|4.8.2608, KiloView Encoder Series P2 hardware Version 1.8.20: 4.8.2633, KiloView Encoder Series RE1 hardware Version 2.0.00: 4.7.2513, KiloView Encoder Series RE1 hardware Version 3.0.00: 4.8.2519|4.8.2561|4.8.2611|4.8.2525 Product Status: known_affected Remediations Mitigation KiloView states that these specific hardware versions are end-of-life; therefore, no patches will be released due to hardware limitations. KiloView recommends that users implement mitigation measures such as network isolation or upgrade to newer hardware generations. Mitigation Users of affected versions of KiloView Encoder Series are invited to contact KiloView customer support at https://www.kiloview.com/contact/ for additional information. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Acknowledgments Muhammad Ammar (0xam225) reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-01-29 Date Revision Summary 2026-01-29 1 Initial Publication 2026-02-05 2 Update A - Affected products are end-of-life Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-1281 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant…
Read full source summary
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-1281 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
· CISA Cybersecurity Advisory

Rockwell Automation ControlLogix

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation ControlLogix are affected: ControlLogix Redundancy Enhanced Module Catalog 1756-RM2 Firmware vers:all/* (CVE-2025-14027) ControlLogix Redundancy Enhanced Module Catalog 1756-RM2XT Firmware vers:all/* (CVE-2025-14027) CVSS Vendor Equipment…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation ControlLogix are affected: ControlLogix Redundancy Enhanced Module Catalog 1756-RM2 Firmware vers:all/* (CVE-2025-14027) ControlLogix Redundancy Enhanced Module Catalog 1756-RM2XT Firmware vers:all/* (CVE-2025-14027) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation ControlLogix Missing Release of Memory after Effective Lifetime Background Critical Infrastructure Sectors: Chemical, Energy, Critical Manufacturing, Food and Agriculture, Transportation Systems, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2025-14027 Multiple denial-of-service issues exist in 1756-RM2 and 1756-RM2XT firmware (ControlLogix Redundancy Enhanced Modules). These issues can be triggered through various crafted inputs, including malformed Class 3 messages, memory leak conditions, and other resource exhaustion scenarios. Exploitation may cause the device to become unresponsive and, in some cases, result in a major nonrecoverable fault. Recovery may require a restart. View CVE Details Affected Products Rockwell Automation ControlLogix Vendor: Rockwell Automation Product Version: Rockwell Automation ControlLogix Redundancy Enhanced Module Catalog 1756-RM2 Firmware: vers:all/*, Rockwell Automation ControlLogix Redundancy Enhanced Module Catalog 1756-RM2XT Firmware: vers:all/* Product Status: known_affected Remediations Mitigation Rockwell Automation recommends that users upgrade from the 1756-RM2 to 1756-RM3. Mitigation If users are unable to upgrade to the 1756-RM3, security best practices should be applied. Mitigation See Rockwell Automation's SD1769 advisory for more information. Relevant CWE: CWE-401 Missing Release of Memory after Effective Lifetime Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Acknowledgments Rockwell Automation reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-01-29 Date Revision Summary 2026-01-29 1 Initial Republication of Rockwell Automation advisory SD1769 Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Fortinet Releases Guidance to Address Ongoing Exploitation of Authentication Bypass Vulnerability CVE-2026-24858

Newly disclosed vulnerability Common Vulnerabilities and Exposures (CVE)-2026-24858 [Common Weakness Enumeration (CWE)-288: Authentication Bypass Using an Alternate Path or Channel] allows malicious actors with a FortiCloud account and a registered device to log in to separate devices registered to other users in FortiOS, FortiManager, FortiWeb, FortiProxy, and FortiAnalyzer, if FortiCloud single sign on (SSO) is…
Read full source summary
Newly disclosed vulnerability Common Vulnerabilities and Exposures (CVE)-2026-24858 [Common Weakness Enumeration (CWE)-288: Authentication Bypass Using an Alternate Path or Channel] allows malicious actors with a FortiCloud account and a registered device to log in to separate devices registered to other users in FortiOS, FortiManager, FortiWeb, FortiProxy, and FortiAnalyzer, if FortiCloud single sign on (SSO) is enabled on devices.1 Users are vulnerable to CVE-2026-24858 even if they updated Fortinet devices to address previously disclosed FortiCloud SSO bypass vulnerabilities CVE-2025-59718 and CVE-2025-59719 [CWE-347: Improper Verification of Cryptographic Signature].2 CVE-2025-59718 and CVE-2025-59719 affect FortiOS, FortiWeb, FortiProxy, and FortiSwitch Manager, and allow malicious actors to bypass the SSO login authentication via a crafted Security Assertion Markup Language (SAML) message.3 On Fortinet devices that had been fully upgraded to the latest release addressing CVE-2025-59718 and CVE-2025-59719 at the time of CVE-2026-24858 exploitation, Fortinet observed the following malicious activity: Unauthorized firewall configuration changes on FortiGate devices. Unauthorized creation of accounts. Unauthorized configuration changes of virtual private networks (VPNs) to grant access to new accounts.4 According to Fortinet, on Jan. 26, 2026, Fortinet disabled all FortiCloud SSO authentication to mitigate CVE-2026-24858, then reinstated the service on Jan. 27, 2026, with changes to prevent exploitation of vulnerable devices. CISA added CVE-2026-24858 to its Known Exploited Vulnerabilities (KEV) Catalog on Jan. 27, 2026. CISA urges users to check for indicators of compromise on all internet-accessible Fortinet products affected by this vulnerability and immediately apply updates as soon as they are available using Fortinet’s instructions: Administrative FortiCloud SSO authentication bypass Analysis of Single Sign-On Abuse on FortiOS Disclaimer The information in this report is being provided “as is” for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA. Notes Fortinet, “Administrative FortiCloud SSO Authentication Bypass,” FortiGuard Labs, last modified January 27, 2026, https://fortiguard.fortinet.com/psirt/FG-IR-26-060. Fortinet, “Multiple Fortinet Products’ FortiCloud SSO Login Authentication Bypass,” FortiGuard Labs, last modified December 9, 2025, https://fortiguard.fortinet.com/psirt/FG-IR-25-647. Carl Windsor, “Analysis of Single Sign-On Abuse on FortiOS,” PSIRT Blogs (blog), Fortinet, last modified January 22, 2026, https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios. Arctic Wolf Labs, “Arctic Wolf Observes Malicious Configuration Changes on Fortinet FortiGate Devices via SSO Accounts,” Arctic Wolf Blog (blog), Arctic Wolf, last modified January 21, 2026, https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-configuration-changes-fortinet-fortigate-devices-via-sso-accounts/.
· CISA Cybersecurity Advisory

Schneider Electric Zigbee Products

View CSAF Summary Schneider Electric is aware of multiple vulnerabilities with EmberZNet disclosed by Silicon Labs. Many vendors, including Schneider Electric, use Silicon Labs’ Zigbee processors in their offers. The following have denial of service vulnerabilities: Wiser iTRV, Wiser RTR, Wiser UFH, Wiser Heat Switch, Wiser Boiler Relay, cFMT (Exaact, Elko, Odace, Merten), Wiser Micromodule, Iconic Wiser Connected…
Read full source summary
View CSAF Summary Schneider Electric is aware of multiple vulnerabilities with EmberZNet disclosed by Silicon Labs. Many vendors, including Schneider Electric, use Silicon Labs’ Zigbee processors in their offers. The following have denial of service vulnerabilities: Wiser iTRV, Wiser RTR, Wiser UFH, Wiser Heat Switch, Wiser Boiler Relay, cFMT (Exaact, Elko, Odace, Merten), Wiser Micromodule, Iconic Wiser Connected Smart Dimmer, Iconic Zigbee devices, Wiser Application Modules, Wiser Connected Pushbutton Switch/Dimmer/Shutter controller, Rotary Dimmer, Motion Sensor Dimmer/Switch, Smart socket outlets, and EV socket outlet. See the following table. Failure to apply the mitigations provided below may risk denial of service, which could result in products being unavailable. The following versions of Schneider Electric Zigbee Products are affected: Wiser iTRV2 (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser iTRV3 (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser RTR2 (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser UFH (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser 16A Electrical Heat Switch (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser Boiler Relay (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Exxact cFMT 16a (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Elko cFMT 16a (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Odace cFMT 2a (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Merten cFMT 16a (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Merten cFMT 2a (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser Power Micromodule (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser FIP Micromodule (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Iconic, Wiser Connected Smart Dimmer (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Iconic, Wiser Connected Smart Switch, 2AX (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Iconic, Wiser Connected Smart Switch, 10AX (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Iconic, Connected AC Fan Controller (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Iconic, Connected Smart Socket (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser Connected Application Module 1-Gang (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser Connected Application Module 2-Gang (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser Connected Push Button Dimmer (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser Connected Push Button Switch (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser Connected Push Button Shutter (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser Connected Motion Dimmer (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser Connected Motion Switch (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser Connected Rotary Dimmer (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Connected Wireless Switch (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Micromodule Switch (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Micromodule Dimmer (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Micromodule Shutter (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Connected Single Socket Outlet (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Connected Double Socket Outlet (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Fuga Connected Socket Outlet (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Mureva EV Link (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) CVSS Vendor Equipment Vulnerabilities v3 6.5 Schneider Electric Schneider Electric Zigbee Products Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Uncontrolled Resource Consumption Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy, Information Technology, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: France Vulnerabilities Expand All + CVE-2024-6350 A CWE-120: A buffer overflow vulnerability exists that could cause a denial of service when a malicious device joins the network. View CVE Details Affected Products Schneider Electric Zigbee Products Vendor: Schneider Electric Product Version: Wiser iTRV2 All Versions, Wiser iTRV3 All Versions, Wiser RTR2 All Versions, Wiser UFH All Versions, Wiser 16A Electrical Heat Switch All Versions, Wiser Boiler Relay All Versions, Exxact cFMT 16a All Versions, Elko cFMT 16a All Versions, Odace cFMT 2a All Versions, Merten cFMT 16a All Versions, Merten cFMT 2a All Versions, Wiser Power Micromodule All Versions, Wiser FIP Micromodule All Versions, Iconic, Wiser Connected Smart Dimmer All Versions, Iconic, Wiser Connected Smart Switch, 2AX All Versions, Iconic, Wiser Connected Smart Switch, 10AX All Versions, Iconic, Connected AC Fan Controller All Versions, Iconic, Connected Smart Socket All Versions, Wiser Connected Application Module 1-Gang All Versions, Wiser Connected Application Module 2-Gang All Versions, Wiser Connected Push Button Dimmer All Versions, Wiser Connected Push Button Switch All Versions, Wiser Connected Push Button Shutter All Versions, Wiser Connected Motion Dimmer All Versions, Wiser Connected Motion Switch All Versions, Wiser Connected Rotary Dimmer All Versions, Connected Wireless Switch All Versions, Micromodule Switch All Versions, Micromodule Dimmer All Versions, Micromodule Shutter All Versions, Connected Single Socket Outlet All Versions, Connected Double Socket Outlet All Versions, Fuga Connected Socket Outlet All Versions, Mureva EV Link All Versions Product Status: known_affected Remediations Mitigation Customers should immediately apply the following mitigations to reduce the risk of exploit: To keep your Zigbee network safe and prevent unauthorized access: • Restrict device access: Do not allow unknown devices to join your network. • Review hub settings: Check how your Zigbee hub manages device pairing. • Control network availability: Only open the network when adding new devices and close it immediately after. • Use install codes and avoid the well-known key: Whenever possible, use unique install codes for added security. Replace default keys with secure, unique keys. Relevant CWE: CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2024-6351 A CWE-120: A buffer overflow vulnerability exists that could cause a denial of service when a malicious device joins the network. View CVE Details Affected Products Schneider Electric Zigbee Products Vendor: Schneider Electric Product Version: Wiser iTRV2 All Versions, Wiser iTRV3 All Versions, Wiser RTR2 All Versions, Wiser UFH All Versions, Wiser 16A Electrical Heat Switch All Versions, Wiser Boiler Relay All Versions, Exxact cFMT 16a All Versions, Elko cFMT 16a All Versions, Odace cFMT 2a All Versions, Merten cFMT 16a All Versions, Merten cFMT 2a All Versions, Wiser Power Micromodule All Versions, Wiser FIP Micromodule All Versions, Iconic, Wiser Connected Smart Dimmer All Versions, Iconic, Wiser Connected Smart Switch, 2AX All Versions, Iconic, Wiser Connected Smart Switch, 10AX All Versions, Iconic, Connected AC Fan Controller All Versions, Iconic, Connected Smart Socket All Versions, Wiser Connected Application Module 1-Gang All Versions, Wiser Connected Application Module 2-Gang All Versions, Wiser Connected Push Button Dimmer All Versions, Wiser Connected Push Button Switch All Versions, Wiser Connected Push Button Shutter All Versions, Wiser Connected Motion Dimmer All Versions, Wiser Connected Motion Switch All Versions, Wiser Connected Rotary Dimmer All Versions, Connected Wireless Switch All Versions, Micromodule Switch All Versions, Micromodule Dimmer All Versions, Micromodule Shutter All Versions, Connected Single Socket Outlet All Versions, Connected Double Socket Outlet All Versions, Fuga Connected Socket Outlet All Versions, Mureva EV Link All Versions Product Status: known_affected Remediations Mitigation Customers should immediately apply the following mitigations to reduce the risk of exploit: To keep your Zigbee network safe and prevent unauthorized access: • Restrict device access: Do not allow unknown devices to join your network. • Review hub settings: Check how your Zigbee hub manages device pairing. • Control network availability: Only open the network when adding new devices and close it immediately after. • Use install codes and avoid the well-known key: Whenever possible, use unique install codes for added security. Replace default keys with secure, unique keys. Relevant CWE: CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') Metrics CVSS Version Base Score Base Severity Vector String 3.1 4.3 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2024-6352 A CWE-120: A buffer overflow vulnerability exists that could cause a denial of service when a malicious device joins the network. View CVE Details Affected Products Schneider Electric Zigbee Products Vendor: Schneider Electric Product Version: Wiser iTRV2 All Versions, Wiser iTRV3 All Versions, Wiser RTR2 All Versions, Wiser UFH All Versions, Wiser 16A Electrical Heat Switch All Versions, Wiser Boiler Relay All Versions, Exxact cFMT 16a All Versions, Elko cFMT 16a All Versions, Odace cFMT 2a All Versions, Merten cFMT 16a All Versions, Merten cFMT 2a All Versions, Wiser Power Micromodule All Versions, Wiser FIP Micromodule All Versions, Iconic, Wiser Connected Smart Dimmer All Versions, Iconic, Wiser Connected Smart Switch, 2AX All Versions, Iconic, Wiser Connected Smart Switch, 10AX All Versions, Iconic, Connected AC Fan Controller All Versions, Iconic, Connected Smart Socket All Versions, Wiser Connected Application Module 1-Gang All Versions, Wiser Connected Application Module 2-Gang All Versions, Wiser Connected Push Button Dimmer All Versions, Wiser Connected Push Button Switch All Versions, Wiser Connected Push Button Shutter All Versions, Wiser Connected Motion Dimmer All Versions, Wiser Connected Motion Switch All Versions, Wiser Connected Rotary Dimmer All Versions, Connected Wireless Switch All Versions, Micromodule Switch All Versions, Micromodule Dimmer All Versions, Micromodule Shutter All Versions, Connected Single Socket Outlet All Versions, Connected Double Socket Outlet All Versions, Fuga Connected Socket Outlet All Versions, Mureva EV Link All Versions Product Status: known_affected Remediations Mitigation Customers should immediately apply the following mitigations to reduce the risk of exploit: To keep your Zigbee network safe and prevent unauthorized access: • Restrict device access: Do not allow unknown devices to join your network. • Review hub settings: Check how your Zigbee hub manages device pairing. • Control network availability: Only open the network when adding new devices and close it immediately after. • Use install codes and avoid the well-known key: Whenever possible, use unique install codes for added security. Replace default keys with secure, unique keys. Relevant CWE: CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') Metrics CVSS Version Base Score Base Severity Vector String 3.1 4.3 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2024-10106 A CWE-120: A buffer overflow vulnerability exists that could cause a denial of service when a malicious device joins the network. View CVE Details Affected Products Schneider Electric Zigbee Products Vendor: Schneider Electric Product Version: Wiser iTRV2 All Versions, Wiser iTRV3 All Versions, Wiser RTR2 All Versions, Wiser UFH All Versions, Wiser 16A Electrical Heat Switch All Versions, Wiser Boiler Relay All Versions, Exxact cFMT 16a All Versions, Elko cFMT 16a All Versions, Odace cFMT 2a All Versions, Merten cFMT 16a All Versions, Merten cFMT 2a All Versions, Wiser Power Micromodule All Versions, Wiser FIP Micromodule All Versions, Iconic, Wiser Connected Smart Dimmer All Versions, Iconic, Wiser Connected Smart Switch, 2AX All Versions, Iconic, Wiser Connected Smart Switch, 10AX All Versions, Iconic, Connected AC Fan Controller All Versions, Iconic, Connected Smart Socket All Versions, Wiser Connected Application Module 1-Gang All Versions, Wiser Connected Application Module 2-Gang All Versions, Wiser Connected Push Button Dimmer All Versions, Wiser Connected Push Button Switch All Versions, Wiser Connected Push Button Shutter All Versions, Wiser Connected Motion Dimmer All Versions, Wiser Connected Motion Switch All Versions, Wiser Connected Rotary Dimmer All Versions, Connected Wireless Switch All Versions, Micromodule Switch All Versions, Micromodule Dimmer All Versions, Micromodule Shutter All Versions, Connected Single Socket Outlet All Versions, Connected Double Socket Outlet All Versions, Fuga Connected Socket Outlet All Versions, Mureva EV Link All Versions Product Status: known_affected Remediations Mitigation Customers should immediately apply the following mitigations to reduce the risk of exploit: To keep your Zigbee network safe and prevent unauthorized access: • Restrict device access: Do not allow unknown devices to join your network. • Review hub settings: Check how your Zigbee hub manages device pairing. • Control network availability: Only open the network when adding new devices and close it immediately after. • Use install codes and avoid the well-known key: Whenever possible, use unique install codes for added security. Replace default keys with secure, unique keys. Relevant CWE: CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') Metrics CVSS Version Base Score Base Severity Vector String 3.1 3.7 LOW CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2024-7322 A CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service when a malicious device joins the network. View CVE Details Affected Products Schneider Electric Zigbee Products Vendor: Schneider Electric Product Version: Wiser iTRV2 All Versions, Wiser iTRV3 All Versions, Wiser RTR2 All Versions, Wiser UFH All Versions, Wiser 16A Electrical Heat Switch All Versions, Wiser Boiler Relay All Versions, Exxact cFMT 16a All Versions, Elko cFMT 16a All Versions, Odace cFMT 2a All Versions, Merten cFMT 16a All Versions, Merten cFMT 2a All Versions, Wiser Power Micromodule All Versions, Wiser FIP Micromodule All Versions, Iconic, Wiser Connected Smart Dimmer All Versions, Iconic, Wiser Connected Smart Switch, 2AX All Versions, Iconic, Wiser Connected Smart Switch, 10AX All Versions, Iconic, Connected AC Fan Controller All Versions, Iconic, Connected Smart Socket All Versions, Wiser Connected Application Module 1-Gang All Versions, Wiser Connected Application Module 2-Gang All Versions, Wiser Connected Push Button Dimmer All Versions, Wiser Connected Push Button Switch All Versions, Wiser Connected Push Button Shutter All Versions, Wiser Connected Motion Dimmer All Versions, Wiser Connected Motion Switch All Versions, Wiser Connected Rotary Dimmer All Versions, Connected Wireless Switch All Versions, Micromodule Switch All Versions, Micromodule Dimmer All Versions, Micromodule Shutter All Versions, Connected Single Socket Outlet All Versions, Connected Double Socket Outlet All Versions, Fuga Connected Socket Outlet All Versions, Mureva EV Link All Versions Product Status: known_affected Remediations Mitigation Customers should immediately apply the following mitigations to reduce the risk of exploit: To keep your Zigbee network safe and prevent unauthorized access: • Restrict device access: Do not allow unknown devices to join your network. • Review hub settings: Check how your Zigbee hub manages device pairing. • Control network availability: Only open the network when adding new devices and close it immediately after. • Use install codes and avoid the well-known key: Whenever possible, use unique install codes for added security. Replace default keys with secure, unique keys. Relevant CWE: CWE-400 Uncontrolled Resource Consumption Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.8 MEDIUM CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H Acknowledgments Schneider Electric CPCERT reported these vulnerabilities to CISA. Silicon Labs reported these vulnerabilities to Schneider Electric General Security Recommendations We strongly recommend the following industry cybersecurity best practices. https://www.se.com/us/en/download/document/7EN52-0390/ * Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network. * Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks. * Place all controllers in locked cabinets and never leave them in the “Program” mode. * Never connect programming software to any network other than the network intended for that device. * Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks. * Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation. * Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet. * When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices. For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document. For More Information This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process. For further information related to cybersecurity in Schneider Electric’s products, visit the company’s cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp LEGAL DISCLAIMER THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS “NOTIFICATION”) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN “AS-IS” BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION About Schneider Electric At Schneider, we believe access to energy and digital is a basic human right. We empower all to do more with less, ensuring Life Is On everywhere, for everyone, at every moment. We provide energy and automation digital solutions for efficiency and sustainability. We combine world-leading energy technologies, real-time automation, software and services into integrated solutions for Homes, Buildings, Data Centers, Infrastructure and Industries. We are committed to unleash the infinite possibilities of an open, global, innovative community that is passionate with our Meaningful Purpose, Inclusive and Empowered values. www.se.com Vulnerability Details These vulnerabilities disclosed by Silicon Labs affect their Zigbee processors, which are used in multiple Schneider Electric's products. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Schneider Electric CPCERT SEVD-2026-013-03 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory. Revision History Initial Release Date: 2026-01-13 Date Revision Summary 2026-01-13 1 Original Release 2026-01-27 2 Initial Republication of Schneider Electric CPCERT SEVD-2026-013-03 advisory Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-24858 Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD)…
Read full source summary
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-24858 Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
· CISA Cybersecurity Advisory

Johnson Controls Metasys Products

View CSAF Summary Successful exploitation of this vulnerability could result in remote SQL execution, leading to alteration or loss of data. The following versions of Johnson Controls Metasys Products are affected: Metasys Application and Data Server (ADS) (CVE-2025-26385) Metasys Extended Application and Data Server (ADX) (CVE-2025-26385) Metasys LCS8500 (CVE-2025-26385) Metasys NAE8500 (CVE-2025-26385) Metasys…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could result in remote SQL execution, leading to alteration or loss of data. The following versions of Johnson Controls Metasys Products are affected: Metasys Application and Data Server (ADS) (CVE-2025-26385) Metasys Extended Application and Data Server (ADX) (CVE-2025-26385) Metasys LCS8500 (CVE-2025-26385) Metasys NAE8500 (CVE-2025-26385) Metasys System Configuration Tool (SCT) (CVE-2025-26385) Metasys Controller Configuration Tool (CCT) (CVE-2025-26385) CVSS Vendor Equipment Vulnerabilities v3 10 Johnson Controls Johnson Controls Metasys Products Improper Neutralization of Special Elements used in a Command ('Command Injection') Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy, Government Services and Facilities, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2025-26385 Under certain circumstances a successful exploitation of this vulnerability could allow remote SQL execution. View CVE Details Affected Products Johnson Controls Metasys Products Vendor: Johnson Controls Product Version: Johnson Controls Metasys Application and Data Server (ADS): <=14.1, Johnson Controls Metasys Extended Application and Data Server (ADX):14.1, Johnson Controls Metasys LCS8500: >=12.0|<=14.1, Johnson Controls Metasys NAE8500: >=12.0|<=14.1, Johnson Controls Metasys System Configuration Tool (SCT): <=17.1, Johnson Controls Metasys Controller Configuration Tool (CCT): <=17.0 Product Status: known_affected Remediations Mitigation Johnson Controls recommends downloading and executing the Metasys patch for GIV-165989 from the License Portal. Login credentials are required. Mitigation Johnson Controls advises following the Metasys Release 14 Hardening Guide to ensure each Metasys installation is on a segmented network and not exposed to untrusted networks such as the internet. Mitigation Additionally, closing incoming TCP port 1433 can protect against exploitation of this vulnerability. Mitigation For more detailed mitigation instructions, visit Johnson Controls Product Security Advisory JCI-PSA-2026-02. Relevant CWE: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 10 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Acknowledgments Johnson Controls reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-01-27 Date Revision Summary 2026-01-27 1 Initial Republication of Johnson Controls advisory JCI-PSA-2026-02 Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

iba Systems ibaPDA

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized actions on the file system. The following versions of iba Systems ibaPDA are affected: ibaPDA (CVE-2025-14988) CVSS Vendor Equipment Vulnerabilities v3 9.8 iba Systems iba Systems ibaPDA Incorrect Permission Assignment for Critical Resource Background Critical Infrastructure Sectors: Critical Manufacturing…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized actions on the file system. The following versions of iba Systems ibaPDA are affected: ibaPDA (CVE-2025-14988) CVSS Vendor Equipment Vulnerabilities v3 9.8 iba Systems iba Systems ibaPDA Incorrect Permission Assignment for Critical Resource Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2025-14988 A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain conditions. This may impact the confidentiality, integrity, or availability of the system. View CVE Details Affected Products iba Systems ibaPDA Vendor: iba Systems Product Version: iba Systems ibaPDA: 8.12.0 Product Status: known_affected Remediations Vendor fix iba Systems recommends users update to ibaPDA v8.12.1 or a later version. Mitigation If Installing the update is not possible, iba Systems recommends users: Mitigation Enable User Management:To activate user management, navigate to User Management settings under the Configure option. Set a password for the admin user to enable user management. Vendor fix Configure Server Access:To configure, open Server Access Manager (found under Configure in the ibaPDA Client). Set the configuration to restrict access. For example, only 127.0.0.1 (localhost) or specific system IP addresses to communicate with ibaPDA can connect to the ibaPDA Server. (In this example, only connections from localhost are permitted to access ibaPDA.) Vendor fix Restrict Connections to Localhost (if ibaPDA is only accessed from the system where it runs): Vendor fix Go to I/O Manager, then General, and deactivate the option "Automatically open necessary ports in Windows Firewall." (If this option remains active, after a restart of ibaPDA or a restart for data acquisition, the firewall will be reconfigured automatically.) Vendor fix Then, go to Advanced Windows Firewall settings and delete or deactivate all incoming rules for the ibaPDA Client and Server. Vendor fix Manually create firewall rules for the connection used for ibaPDA and verify that the correct ports are configured. For assistance with identifying the ports used by the ibaPDA service can be found in the iba Help Center. Vendor fix Note: After making the changes, verify that all ibaPDA services are operating as expected and that the data acquisition is functioning correctly. Relevant CWE: CWE-732 Incorrect Permission Assignment for Critical Resource Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Acknowledgments Siemens reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-01-27 Date Revision Summary 2026-01-27 1 Initial Publication Legal Notice and Terms of Use
Browse saved snapshots