⌁ DAY 68UNDERCOVERED IN US

CISA advisories: vulnerabilities in industrial control systems

CISA released security advisories for vulnerabilities across multiple industrial automation products from ABB, Rockwell Automation, and AutomationDirect. Successful exploits could allow attackers to execute code, modify memory, delete files, and alter I/O states.

31 reportsprimary · other

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

ABB Advant Master Online Builder

rss:cisa-advisoriesprimary77d ago kagi ↗

View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory, where an incorrect version of Online Builder (ONB) was included in the media. An update is available that resolves the vulnerability, see details in Recommended immediate actions. The following versions of ABB Advant Master Online Builder are affected: Control Builder A <=1.4/4 (CVE-202

ABB T-MAC Plus

rss:cisa-advisoriesprimary77d ago kagi ↗

View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. An attacker who successfully exploited any of these vulnerabilities could potentially compromise the system in different ways. The following versions of ABB T-MAC Plus are affected: T-MAC Plus 4.0-24 (CVE-2025-14771, CVE

ABB Ability Edgenius

rss:cisa-advisoriesprimary77d ago kagi ↗

View CSAF Summary ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges o

Rockwell Automation 1715-AENTR EtherNet/IP Adapter

rss:cisa-advisoriesprimary77d ago kagi ↗

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device. The following versions of Rockwell Automation 1715-AENTR EtherNet/IP Adapter are affected: 1715-AENTR EtherNet/IP Adapter <=3.003 (CVE-2026-10577) CVSS

AutomationDirect Productivity Suite

rss:cisa-advisoriesprimary75d ago kagi ↗

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with local or physical access to cause memory corruption, unintended information disclosure, application instability, or a denial-of-service condition in the affected product. The following versions of AutomationDirect Productivity Suite are affected: Productivity Suite <=v4.6.2.2 (CVE-2026-60063, CVE-2026-6

Rockwell Automation Arena

rss:cisa-advisoriesprimary75d ago kagi ↗

View CSAF Summary Successful exploitation these vulnerabilities could allow an attacker to execute arbitrary code in the context of the current process. The following versions of Rockwell Automation Arena are affected: Arena <=V17.00.00 (CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, CVE-2026-8314) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation Arena Out-of-boun

NASA Core Flight System (cFS) Health & Safety (HS) Application

rss:cisa-advisoriesprimary75d ago kagi ↗

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of NASA Core Flight System (cFS) Health & Safety (HS) Application are affected: Core Flight System (cFS) Health & Safety (HS) Application CVSS Vendor Equipment Vulnerabilities v3 7.5 NASA NASA Core Flight System (cFS) Health & Safety (HS) Applicatio

Rockwell Automation Flex 5000 Adapter

rss:cisa-advisoriesprimary75d ago kagi ↗

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation Flex 5000 Adapter are affected: Flex 5000 Adapter 6.011 (CVE-2026-12659) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation Flex 5000 Adapter Double Free Background Cri

Siemens SICAM 8

rss:cisa-advisoriesprimary75d ago kagi ↗

View CSAF Summary Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: - SICAM A8000 Device firmware - CPCI85 for CP-8031/CP-8050 - SICORE for CP-8010/CP-8012 - SICAM EGS Device firmware - CPCI85 - SICAM S8000 - SICORE Siemens has released new versions for the affected products and recommends to update to the latest versions. The followin

Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT

rss:cisa-advisoriesprimary75d ago kagi ↗

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT are affected: 1756-EN3 <=V12.001 (CVE-2026-9653) 1756-EN2 <=V12.001 (CVE-2026-9653) 1756-ENBT V6.006 (CVE-2026-9653) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell A

Rockwell Automation FactoryTalk DataMosaix

rss:cisa-advisoriesprimary75d ago kagi ↗

View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious scripts on the server. The following versions of Rockwell Automation FactoryTalk DataMosaix are affected: DataMosaix Private Cloud <=8.02 (CVE-2026-9292) CVSS Vendor Equipment Vulnerabilities v3 6.1 Rockwell Automation Rockwell Automation FactoryTalk DataMosaix Improper Neutral

SALTO ProAccess Space

rss:cisa-advisoriesprimary75d ago kagi ↗

View CSAF Summary Successful exploitation of this vulnerability allows an authenticated attacker to escalate privileges and access spaces outside their assigned partition, within the same Salto ProAccess Space installation or system. Exploitation requires valid authenticated operator credentials and the partition feature to be enabled; installations without partitioning are not affected. The follo

Tycon Systems TPDIN-Monitor-WEB2

rss:cisa-advisoriesprimary70d ago kagi ↗

View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The following versions of Tycon Systems TPDIN-Monitor-WEB2 are affected: TPDIN-Monitor-WEB2 2.3.9 CVSS Vendor Equipment Vulnerabilities v3 9.8 Tycon System

Siemens SIDIS Secured SmartPlug

rss:cisa-advisoriesprimary70d ago kagi ↗

View CSAF Summary SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version. The following versions of Siemens SIDIS Secured SmartPlug are affected: SIDIS Secured SmartPlug vers:intdot

Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW

rss:cisa-advisoriesprimary70d ago kagi ↗

View CSAF Summary Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/ The following versions of Siemens RUG

Rockwell Automation 1734 POINT I/O

rss:cisa-advisoriesprimary70d ago kagi ↗

View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. The following versions of Rockwell Automation 1734 POINT I/O are affected: 1734 POINT I/O 3.023 CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1734 POINT I/O Allocation of Resources Without Limits or Throttling Back

Rockwell Automation 1718-AENTR/1719-AENTR

rss:cisa-advisoriesprimary70d ago kagi ↗

View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. The following versions of Rockwell Automation 1718-AENTR/1719-AENTR are affected: 1718/ 1719 Ex I/O 3.011 CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1718-AENTR/1719-AENTR Allocation of Resources Without Limits o

Rockwell Automation Studio 5000 Logix Designer

rss:cisa-advisoriesprimary70d ago kagi ↗

View CSAF Summary Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code. The following versions of Rockwell Automation Studio 5000 Logix Designer are affected: Studio 5000 Logix Designer V36.00 (CVE-2026-9108) Studio 5000 Logix Designer V35.00 (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128) Studio

Siemens CADRA

rss:cisa-advisoriesprimary70d ago kagi ↗

View CSAF Summary CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens CADRA are affected: CADRA vers:intdot/<2511, vers:all/*

Rockwell Automation FactoryTalk Services Platform

rss:cisa-advisoriesprimary70d ago kagi ↗

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations. The following versions of Rockwell Automation FactoryTalk Services Platform are affected: FactoryTalk Directory (FTSP) 6.60 CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell A

Siemens Opcenter X

rss:cisa-advisoriesprimary70d ago kagi ↗

View CSAF Summary Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version. The following versions of Siemens Opcenter X are affected: Opcenter X vers:intdot/<2604 CVSS Vendor Equipment Vulnerabilities v3 10

Rockwell Automation ThinManager

rss:cisa-advisoriesprimary70d ago kagi ↗

View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory. The following versions of Rockwell Automation ThinManager are affected: ThinManager >=13.0.0|<13.0.7, >=13.1.0|<13.1.5, >=13.2.0|<13.2.4, >=14.0.0|<14.0.2 CVSS Vendor Equipment Vulnerabilitie

Hackers target Windmill, GeoServer and NGINX flaws

kite:cybersecurityother69d ago kagi ↗

Attackers are exploiting CVE-2026-29059, a high-severity Windmill vulnerability with a CVSS score of 7.5, according to VulnCheck research cited by The Hacker News [thehackernews.com#1]. The flaw is an unauthenticated path traversal issue in Windmill's log-file retrieval function, allowing attackers to read files from affected servers without logging in [thehackernews.com#1]. Attackers also recentl

US agencies warn Iran-linked hackers target industrial controllers

kite:cybersecurityother68d ago kagi ↗

U.S. cybersecurity and law enforcement agencies updated an advisory on July 22 warning that Iran-affiliated hackers are targeting internet-exposed programmable logic controllers used in critical infrastructure, including water, energy and municipal facilities [securityweek.com#1][theregister.com#1][techcrunch.com#1][cybersecuritydive.com#1]. The alert expands earlier federal warnings focused on Ro

Weintek cMT3092X

rss:cisa-advisoriesprimary68d ago kagi ↗

View CSAF Summary Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users. The following versions of Weintek cMT3092X are affected: cMT3092X firmware <20210218 EasyWeb <v2.1.20 CVSS Vendor Equipment Vulnerabilities v3 8.8 Weintek Weintek cMT3092X Reliance on Cookies without Validation and Integrity Checking in

Johnson Controls XAAP Android

rss:cisa-advisoriesprimary68d ago kagi ↗

View CSAF Summary Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device. The following versions of Johnson Controls XAAP Android are affected: XAAP Android <1.53 CVSS Vendor Equipment Vulnerabilities v3 3.3 Johnson Controls Johnson Controls XAAP Android Cleartext Storage of Sensitive Information Background Critical Infrastructu

MZ Automation libIEC61850

rss:cisa-advisoriesprimary68d ago kagi ↗

View CSAF Summary Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions. The following versions of MZ Automation libIEC61850 are affected: libIEC61850 >=v1.0.0|<=v1.6.1 CVSS Vendor Equipment Vulnerabilities v3 8

MZ Automation lib60870

rss:cisa-advisoriesprimary68d ago kagi ↗

View CSAF Summary Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service. The following versions of MZ Automation lib60870 are affected: lib60870 <=2.4.0 CVSS Vendor Equipment Vulnerabilities v3 8.2 MZ Automation MZ Automation lib60870 Out-of-bounds Read Background Critical Infrastructure Sectors: Chemical, Energy, Water and Was

Johnson Controls C-CURE 9000 and Victor application server

rss:cisa-advisoriesprimary68d ago kagi ↗

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. The following versions of Johnson Controls C-CURE 9000 and Victor application server are affected: C-CURE 9000 and victor <=v2.90_v3.0 victor Web <=v7.1 CVSS Vendor Equipment Vulnerabilities v3 9.6 Johnson Controls Johnson Controls C-CURE 9000 and Victor

Panduit IntraVUE

rss:cisa-advisoriesprimary68d ago kagi ↗

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider knowledge, or advanced tooling. The following versions of Panduit IntraVUE are affected: IntraVUE <=3.2.1a14 CVSS Vendor Equipment Vulnerabilities v3 10 Pronetiqs Panduit IntraVUE Pla

Salon: Andrew Tate’s arrest causes trouble for Trump’s youngest son https://www. salon.com/2026/07/25/andrew-ta tes-arrest-causes-trouble-for-trumps-youngest-son/ @ Salon Yesterday. Time: How the Worl

mastodon:infosec-exchangeother66d ago kagi ↗

Salon: Andrew Tate’s arrest causes trouble for Trump’s youngest son https://www. salon.com/2026/07/25/andrew-ta tes-arrest-causes-trouble-for-trumps-youngest-son/ @ Salon Yesterday. Time: How the World Is Reacting to Trump's 'Forced Labor' Tariffs https:// time.com/article/2026/07/24/tr ump-forced-labor-tariffs-world-reaction/ @ time The New Republic: Trump Team Admits He’s Been Defunding States T