{
  "generated_at": "2026-08-23T18:54:15Z",
  "source": {
    "name": "CISA CSAF OT feed (TLP:WHITE)",
    "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/cisa-csaf-ot-feed-tlp-white.json",
    "publisher": "Cybersecurity and Infrastructure Security Agency"
  },
  "count": 120,
  "advisories": [
    {
      "id": "ICSA-26-232-01",
      "title": "Johnson Controls Simplex Incident Manager",
      "published": "2026-08-20T06:00:00.000000Z",
      "updated": "2026-08-20T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "MEDIUM",
      "cvss": 5.8,
      "vendors": [
        "Johnson Controls Inc."
      ],
      "products": [
        "Simplex Incident Manager"
      ],
      "cves": [
        "CVE-2026-27875"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-232-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-232-01.json",
      "summary": "Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems."
    },
    {
      "id": "ICSA-26-230-01",
      "title": "CISA Malcolm",
      "published": "2026-08-18T06:00:00.000000Z",
      "updated": "2026-08-18T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 8.8,
      "vendors": [
        "CISA"
      ],
      "products": [
        "Malcolm"
      ],
      "cves": [
        "CVE-2026-63133",
        "CVE-2026-63134",
        "CVE-2026-55676",
        "CVE-2026-63177",
        "CVE-2026-19670",
        "CVE-2026-19671"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-230-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-230-01.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code."
    },
    {
      "id": "ICSA-26-225-14",
      "title": "Johnson Controls Metasys",
      "published": "2026-08-13T06:00:00.000000Z",
      "updated": "2026-08-13T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 8.0,
      "vendors": [
        "Johnson Controls Inc"
      ],
      "products": [
        "Metasys 12",
        "Metasys 13",
        "Metasys 14",
        "Metasys 15"
      ],
      "cves": [
        "CVE-2026-34491"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-14",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-225-14.json",
      "summary": "Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and u\u2026"
    },
    {
      "id": "ICSA-26-225-05",
      "title": "ANDRITZ HIPASE-250 and 250 SCALA",
      "published": "2026-08-13T06:00:00.000000Z",
      "updated": "2026-08-13T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 8.1,
      "vendors": [
        "ANDRITZ"
      ],
      "products": [
        "HIPASE-250",
        "250 SCALA"
      ],
      "cves": [
        "CVE-2026-65309",
        "CVE-2026-65310",
        "CVE-2026-65311",
        "CVE-2026-65313"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-05",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-225-05.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker to read data from the device or gain access to affected workstations."
    },
    {
      "id": "ICSA-26-225-03",
      "title": "Johnson Controls Inc. Airwall",
      "published": "2026-08-13T06:00:00.000000Z",
      "updated": "2026-08-13T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "MEDIUM",
      "cvss": 6.8,
      "vendors": [
        "Johnson Controls Inc."
      ],
      "products": [
        "Airwall"
      ],
      "cves": [
        "CVE-2026-64887",
        "CVE-2026-34492"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-03",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-225-03.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized access to protected system resources."
    },
    {
      "id": "ICSMA-26-225-01",
      "title": "Flow Neuroscience FL-100",
      "published": "2026-08-13T06:00:00.000000Z",
      "updated": "2026-08-13T06:00:00.000000Z",
      "kind": "medical",
      "severity": "HIGH",
      "cvss": 8.1,
      "vendors": [
        "Flow Neuroscience"
      ],
      "products": [
        "Flow Neuroscience FL-100",
        "Halo Neuroscience FL-100"
      ],
      "cves": [
        "CVE-2026-18164"
      ],
      "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-225-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsma-26-225-01.json",
      "summary": "Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to manipulate brain stimulation parameters and override safety limits."
    },
    {
      "id": "ICSA-26-225-01",
      "title": "AVEVA Enterprise SCADA",
      "published": "2026-08-13T06:00:00.000000Z",
      "updated": "2026-08-13T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.1,
      "vendors": [
        "AVEVA"
      ],
      "products": [
        "Enterprise SCADA",
        "Enterprise SCADA HMI"
      ],
      "cves": [
        "CVE-2025-7639"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-225-01.json",
      "summary": "Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization."
    },
    {
      "id": "ICSA-26-225-02",
      "title": "Haiwell IoT Cloud HMI Gateway",
      "published": "2026-08-13T06:00:00.000000Z",
      "updated": "2026-08-13T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "CRITICAL",
      "cvss": 10.0,
      "vendors": [
        "Haiwell"
      ],
      "products": [
        "Haiwell IoT Cloud HMI Gateway"
      ],
      "cves": [
        "CVE-2026-19188"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-02",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-225-02.json",
      "summary": "Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges."
    },
    {
      "id": "ICSMA-26-223-02",
      "title": "Pulsetto Vagus Nerve Stimulator",
      "published": "2026-08-11T06:00:00.000000Z",
      "updated": "2026-08-11T06:00:00.000000Z",
      "kind": "medical",
      "severity": "HIGH",
      "cvss": 8.1,
      "vendors": [
        "Pulsetto"
      ],
      "products": [
        "Pulsetto Vagus Nerve Stimulator"
      ],
      "cves": [
        "CVE-2026-18844"
      ],
      "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-02",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsma-26-223-02.json",
      "summary": "Successful exploitation of this vulnerability could allow an attacker to use hidden commands to disable electrical safety mechanisms or modify other stimulation output settings."
    },
    {
      "id": "ICSMA-26-223-01",
      "title": "Mira Hormone Monitor, Mira Android App",
      "published": "2026-08-11T06:00:00.000000Z",
      "updated": "2026-08-11T06:00:00.000000Z",
      "kind": "medical",
      "severity": "CRITICAL",
      "cvss": 9.8,
      "vendors": [
        "Quanovate Tech Inc. (operating as Mira / Mira Care)"
      ],
      "products": [
        "Mira Monitor Firmware",
        "Mira Android App"
      ],
      "cves": [
        "CVE-2026-66875",
        "CVE-2026-66098",
        "CVE-2026-67558",
        "CVE-2026-67568",
        "CVE-2026-68067",
        "CVE-2026-66340",
        "CVE-2026-64934",
        "CVE-2026-66832"
      ],
      "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsma-26-223-01.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token information, and obtain control of user accounts."
    },
    {
      "id": "ICSA-26-230-02",
      "title": "Siemens Simcenter Nastran",
      "published": "2026-08-11T00:00:00.000000Z",
      "updated": "2026-08-18T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.8,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "Simcenter Femap",
        "Simcenter Nastran"
      ],
      "cves": [
        "CVE-2026-59086"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-230-02",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-230-02.json",
      "summary": "Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage\u2026"
    },
    {
      "id": "ICSA-26-225-13",
      "title": "Siemens LOGO! Soft Comfort",
      "published": "2026-08-11T00:00:00.000000Z",
      "updated": "2026-08-13T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "MEDIUM",
      "cvss": 6.8,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "LOGO! Soft Comfort"
      ],
      "cves": [
        "CVE-2026-57262",
        "CVE-2026-57263"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-13",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-225-13.json",
      "summary": "Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt project data or remove project passwords. The\u2026"
    },
    {
      "id": "ICSA-26-225-12",
      "title": "Siemens Solid Edge",
      "published": "2026-08-11T00:00:00.000000Z",
      "updated": "2026-08-13T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.8,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "Solid Edge SE2025",
        "Solid Edge SE2026"
      ],
      "cves": [
        "CVE-2026-50058",
        "CVE-2026-50059",
        "CVE-2026-50060",
        "CVE-2026-50061",
        "CVE-2026-50062",
        "CVE-2026-50063",
        "CVE-2026-50064"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-12",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-225-12.json",
      "summary": "Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versi\u2026"
    },
    {
      "id": "ICSA-26-225-10",
      "title": "Siemens Parasolid",
      "published": "2026-08-11T00:00:00.000000Z",
      "updated": "2026-08-13T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.8,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "Parasolid V38.0",
        "Parasolid V38.1"
      ],
      "cves": [
        "CVE-2026-64629"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-10",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-225-10.json",
      "summary": "Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and\u2026"
    },
    {
      "id": "ICSA-26-225-10",
      "title": "Siemens Parasolid",
      "published": "2026-08-11T00:00:00.000000Z",
      "updated": "2026-08-13T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.8,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "Parasolid V38.0",
        "Parasolid V38.1"
      ],
      "cves": [
        "CVE-2026-64629"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-10",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-225-10.json",
      "summary": "Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and\u2026"
    },
    {
      "id": "ICSA-26-225-08",
      "title": "Siemens Desigo DXR and PXC Controllers",
      "published": "2026-08-11T00:00:00.000000Z",
      "updated": "2026-08-13T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "MEDIUM",
      "cvss": 4.3,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "Desigo DXR2",
        "Desigo PXC3",
        "Desigo PXC4",
        "Desigo PXC5.E003",
        "Desigo PXC5.E24",
        "Desigo PXC7"
      ],
      "cves": [
        "CVE-2026-59693"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/ICSA-26-225-08",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-225-08.json",
      "summary": "A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new ve\u2026"
    },
    {
      "id": "ICSA-26-225-07",
      "title": "Siemens License Server (SLS)",
      "published": "2026-08-11T00:00:00.000000Z",
      "updated": "2026-08-12T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.5,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "Siemens License Server (SLS)"
      ],
      "cves": [
        "CVE-2026-69108",
        "CVE-2026-69109"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-07",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-225-07.json",
      "summary": "Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version."
    },
    {
      "id": "ICSA-26-225-06",
      "title": "Siemens RUGGEDCOM APE1808",
      "published": "2026-08-11T00:00:00.000000Z",
      "updated": "2026-08-12T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "MEDIUM",
      "cvss": 6.1,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "RUGGEDCOM APE1808"
      ],
      "cves": [
        "CVE-2026-23573",
        "CVE-2026-59839"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-06",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-225-06.json",
      "summary": "Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens recommends to contact customer support for additional information, and follow Fortinet advisory for workarounds and mitigation measures."
    },
    {
      "id": "ICSA-26-225-11",
      "title": "Siemens Simcenter Femap",
      "published": "2026-08-11T00:00:00.000000Z",
      "updated": "2026-08-13T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.8,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "Simcenter Femap"
      ],
      "cves": [
        "CVE-2026-59700",
        "CVE-2026-59701"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-11",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-225-11.json",
      "summary": "Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this could lead the application to crash or potentially lead to a\u2026"
    },
    {
      "id": "ICSA-26-219-01",
      "title": "CPDLC over ATN-B1 Vulnerabilities",
      "published": "2026-08-07T05:00:00.000000Z",
      "updated": "2026-08-07T05:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.1,
      "vendors": [],
      "products": [
        "ATN-B1 CPDLC"
      ],
      "cves": [
        "CVE-2025-71409",
        "CVE-2025-71410",
        "CVE-2025-71411",
        "CVE-2025-71412",
        "CVE-2025-71413"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-219-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-219-01.json",
      "summary": "ATN-B1 CPDLC relies on legacy clear text unauthenticated radio frequency links. Research demonstrates that these characteristics allow unauthorized message injection, denial-of-service conditions, and forced session resets. These vulnerabilities do not constitute an unsafe air\u2026"
    },
    {
      "id": "ICSMA-26-218-01",
      "title": "Medixant RadiAnt DICOM",
      "published": "2026-08-06T06:00:00.000000Z",
      "updated": "2026-08-06T06:00:00.000000Z",
      "kind": "medical",
      "severity": "MEDIUM",
      "cvss": 4.3,
      "vendors": [
        "Medixant"
      ],
      "products": [
        "RadiAnt DICOM"
      ],
      "cves": [
        "CVE-2026-17264"
      ],
      "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-218-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsma-26-218-01.json",
      "summary": "Successful exploitation of this vulnerability could allow an attacker to cause the application to crash if a maliciously crafted DICOM file is opened."
    },
    {
      "id": "ICSA-26-218-02",
      "title": "Johnson Controls Inc. TL280",
      "published": "2026-08-06T06:00:00.000000Z",
      "updated": "2026-08-06T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "MEDIUM",
      "cvss": 4.1,
      "vendors": [
        "Johnson Controls Inc."
      ],
      "products": [
        "TL280"
      ],
      "cves": [
        "CVE-2026-27871"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-218-02",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-218-02.json",
      "summary": "Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device."
    },
    {
      "id": "ICSMA-26-216-01",
      "title": "Thermo Fisher Applied Biosystems Genetic Analyzers",
      "published": "2026-08-04T06:00:00.000000Z",
      "updated": "2026-08-04T06:00:00.000000Z",
      "kind": "medical",
      "severity": "HIGH",
      "cvss": 8.4,
      "vendors": [
        "Thermo Fisher"
      ],
      "products": [
        "Applied Biosystems 3500/3500xL Series Data Collection Software",
        "Applied Biosystems 3730/3730xL Series Data Collection Software",
        "Applied Biosystems SeqStudio Genetic Analyzer Data Collection Software",
        "Applied Biosystems SeqStudio Flex Series Instrument Software",
        "Applied Biosystems GeneMapper ID-X Software",
        "Applied Biosystems 3130 Series Data Collection Software",
        "ABI PRISM 3100/3100-Avant Data Collection Software",
        "ABI PRISM 310 Data Collection Software"
      ],
      "cves": [
        "CVE-2026-17583"
      ],
      "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-216-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsma-26-216-01.json",
      "summary": "Successful exploitation of this vulnerability could allow an attacker to modify .fsa/.hid output files, tampering with DNA data and resulting in inaccurate test results."
    },
    {
      "id": "ICSA-26-216-01",
      "title": "Acrisure KARR BT and DR-100",
      "published": "2026-08-04T06:00:00.000000Z",
      "updated": "2026-08-04T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 8.1,
      "vendors": [
        "Acrisure"
      ],
      "products": [
        "KARR BT",
        "DR-100"
      ],
      "cves": [
        "CVE-2026-18411"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-216-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-216-01.json",
      "summary": "Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations."
    },
    {
      "id": "ICSA-26-211-09",
      "title": "Watchfire Controller Software",
      "published": "2026-07-30T06:00:00.000000Z",
      "updated": "2026-07-30T22:56:13.953193Z",
      "kind": "advisory",
      "severity": "MEDIUM",
      "cvss": 5.7,
      "vendors": [
        "Watchfire"
      ],
      "products": [
        "BC550",
        "BC750",
        "BC760",
        "BC760DC"
      ],
      "cves": [
        "CVE-2026-5846"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-09",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-211-09.json",
      "summary": "Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller."
    },
    {
      "id": "ICSA-26-211-11",
      "title": "MZ Automation lib60870",
      "published": "2026-07-30T06:00:00.000000Z",
      "updated": "2026-07-30T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "MEDIUM",
      "cvss": 6.5,
      "vendors": [
        "MZ Automation GmbH"
      ],
      "products": [
        "lib60870"
      ],
      "cves": [
        "CVE-2026-61893",
        "CVE-2026-63033"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-11",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-211-11.json",
      "summary": "Successful exploitation of these vulnerabilities could crash the device being accessed."
    },
    {
      "id": "ICSA-26-211-08",
      "title": "o6 Automation open62541",
      "published": "2026-07-30T06:00:00.000000Z",
      "updated": "2026-07-30T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 8.8,
      "vendors": [
        "o6 Automation GmbH"
      ],
      "products": [
        "open62541 on Windows and Linux"
      ],
      "cves": [
        "CVE-2026-63362",
        "CVE-2026-65423",
        "CVE-2026-63035",
        "CVE-2026-63559"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-08",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-211-08.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code."
    },
    {
      "id": "ICSA-26-211-06",
      "title": "NASA Core Flight System (cFS) Health & Safety (HS) Application",
      "published": "2026-07-30T06:00:00.000000Z",
      "updated": "2026-07-30T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.5,
      "vendors": [
        "NASA"
      ],
      "products": [
        "Core Flight System (cFS) Health & Safety (HS) Application"
      ],
      "cves": [
        "CVE-2026-18064"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-06",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-211-06.json",
      "summary": "Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition."
    },
    {
      "id": "ICSA-26-211-10",
      "title": "MZ Automation GmbH libiec61850",
      "published": "2026-07-30T06:00:00.000000Z",
      "updated": "2026-07-30T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.5,
      "vendors": [
        "MZ Automation GmbH"
      ],
      "products": [
        "libiec61850"
      ],
      "cves": [
        "CVE-2026-66720",
        "CVE-2026-66369",
        "CVE-2026-63550",
        "CVE-2026-65421",
        "CVE-2026-66364",
        "CVE-2026-66349",
        "CVE-2026-56758",
        "CVE-2026-66360"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-211-10.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device."
    },
    {
      "id": "ICSA-26-211-05",
      "title": "Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module",
      "published": "2026-07-30T06:00:00.000000Z",
      "updated": "2026-07-30T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "MEDIUM",
      "cvss": 5.9,
      "vendors": [
        "Rockwell Automation"
      ],
      "products": [
        "ControlLogix 5580",
        "CompactLogix 5380",
        "GuardLogix 5580",
        "Compact GuardLogix 5380",
        "1756-EN4TR"
      ],
      "cves": [
        "CVE-2026-9636"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-05",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-211-05.json",
      "summary": "Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition."
    },
    {
      "id": "ICSA-26-211-02",
      "title": "Johnson Controls OpenBlue Employee",
      "published": "2026-07-30T06:00:00.000000Z",
      "updated": "2026-07-30T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "LOW",
      "cvss": 2.4,
      "vendors": [
        "Johnson Controls Inc."
      ],
      "products": [
        "OpenBlue Employee (FMS Employee)"
      ],
      "cves": [
        "CVE-2026-21662",
        "CVE-2026-34495",
        "CVE-2026-34497"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-02",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-211-02.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content."
    },
    {
      "id": "ICSA-26-211-01",
      "title": "MikroTik RouterOS",
      "published": "2026-07-30T06:00:00.000000Z",
      "updated": "2026-07-30T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "MEDIUM",
      "cvss": 4.9,
      "vendors": [
        "MikroTik"
      ],
      "products": [
        "RouterOS"
      ],
      "cves": [
        "CVE-2026-14227"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-211-01.json",
      "summary": "Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low\u2011privilege API access, enabling full VPN impersonation and decryption of all associated traffic."
    },
    {
      "id": "ICSA-26-211-03",
      "title": "Toptech Systems RCU II+ and Multiload II+",
      "published": "2026-07-30T06:00:00.000000Z",
      "updated": "2026-07-30T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 8.8,
      "vendors": [
        "Toptech Systems"
      ],
      "products": [
        "RCU II+",
        "Multiload II+"
      ],
      "cves": [
        "CVE-2026-12562"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-03",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-211-03.json",
      "summary": "Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources."
    },
    {
      "id": "ICSA-26-218-01",
      "title": "ABB Ability Zenon",
      "published": "2026-07-30T00:30:00.000000Z",
      "updated": "2026-08-06T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.8,
      "vendors": [
        "ABB"
      ],
      "products": [
        "Ability Zenon",
        "IIoT services with MongoDB"
      ],
      "cves": [
        "CVE-2025-14847",
        "CVE-2020-7928",
        "CVE-2020-7921",
        "CVE-2020-7925",
        "CVE-2020-7929",
        "CVE-2020-7923",
        "CVE-2021-20330",
        "CVE-2021-32036",
        "CVE-2021-32040",
        "CVE-2021-20333",
        "CVE-2020-7924",
        "CVE-2021-20328"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-218-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-218-01.json",
      "summary": "ABB is aware of publicly reported vulnerabilities affecting MongoDB 4.2, which is bundled within the IIoT Services of the affected product versions. MongoDB 4.2 has reached end-of-life and contains multiple known security vulnerabilities. An attacker who successfully exploits\u2026"
    },
    {
      "id": "ICSA-26-211-07",
      "title": "Mitsubishi Electric CC-Link IE TSN Communication Protocol",
      "published": "2026-07-30T00:00:00.000000Z",
      "updated": "2026-07-30T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.1,
      "vendors": [
        "Mitsubishi Electric"
      ],
      "products": [
        "Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-16",
        "Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-32",
        "Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-64",
        "Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-128",
        "Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-256",
        "Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-N32",
        "Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-P32",
        "Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-N32"
      ],
      "cves": [
        "CVE-2026-13584"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-07",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-211-07.json",
      "summary": "Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause\u2026"
    },
    {
      "id": "ICSA-26-209-06",
      "title": "igloohome Smart Lock Mobile Application",
      "published": "2026-07-28T06:00:00.000000Z",
      "updated": "2026-07-28T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "MEDIUM",
      "cvss": 5.3,
      "vendors": [
        "igloohome"
      ],
      "products": [
        "Smart Lock Mobile Application (Android)"
      ],
      "cves": [
        "CVE-2026-16581"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-06",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-209-06.json",
      "summary": "Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services."
    },
    {
      "id": "ICSA-26-209-05",
      "title": "MikroTik RouterOS and Cloud Hosted Router",
      "published": "2026-07-28T06:00:00.000000Z",
      "updated": "2026-07-28T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 8.8,
      "vendors": [
        "MikroTik"
      ],
      "products": [
        "RouterOS",
        "Cloud Hosted Router"
      ],
      "cves": [
        "CVE-2026-16347"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-05",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-209-05.json",
      "summary": "Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system access."
    },
    {
      "id": "ICSA-26-225-04",
      "title": "Hitachi Energy APM Edge Product",
      "published": "2026-07-28T00:00:00.000000Z",
      "updated": "2026-08-13T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 8.8,
      "vendors": [
        "Hitachi Energy"
      ],
      "products": [
        "APM Edge"
      ],
      "cves": [
        "CVE-2026-43284",
        "CVE-2026-43500"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-04",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-225-04.json",
      "summary": "Hitachi Energy is aware of Dirty Frag vulnerabilities that affect APM Edge product versions listed in this document. Successful exploitation of these vulnerabilities could result in impact on confidentiality, integrity and availability of the product. Please refer to the Recom\u2026"
    },
    {
      "id": "ICSA-26-204-01",
      "title": "Johnson Controls C-CURE 9000 and Victor application server (Update A)",
      "published": "2026-07-23T06:00:00.000000Z",
      "updated": "2026-08-11T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "CRITICAL",
      "cvss": 9.6,
      "vendors": [
        "Johnson Controls"
      ],
      "products": [
        "C-CURE 9000",
        "victor Application Server",
        "victor",
        "victor Web"
      ],
      "cves": [
        "CVE-2026-21655",
        "CVE-2026-21653",
        "CVE-2026-34496"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-204-01.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution."
    },
    {
      "id": "ICSA-26-204-07",
      "title": "MZ Automation lib60870",
      "published": "2026-07-23T06:00:00.000000Z",
      "updated": "2026-07-23T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 8.2,
      "vendors": [
        "MZ Automation"
      ],
      "products": [
        "lib60870"
      ],
      "cves": [
        "CVE-2026-16002"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-07",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-204-07.json",
      "summary": "Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service."
    },
    {
      "id": "ICSA-26-204-04",
      "title": "Panduit IntraVUE",
      "published": "2026-07-23T06:00:00.000000Z",
      "updated": "2026-07-23T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "CRITICAL",
      "cvss": 10.0,
      "vendors": [
        "Pronetiqs"
      ],
      "products": [
        "IntraVUE"
      ],
      "cves": [
        "CVE-2026-40430",
        "CVE-2026-42933",
        "CVE-2026-44955",
        "CVE-2026-50044",
        "CVE-2026-28698"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-04",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-204-04.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider knowledge, or advanced tooling."
    },
    {
      "id": "ICSA-26-204-06",
      "title": "MZ Automation libIEC61850",
      "published": "2026-07-23T06:00:00.000000Z",
      "updated": "2026-07-23T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 8.1,
      "vendors": [
        "MZ Automation"
      ],
      "products": [
        "libIEC61850"
      ],
      "cves": [
        "CVE-2026-50039",
        "CVE-2026-49035",
        "CVE-2026-50103",
        "CVE-2026-50032"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-06",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-204-06.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions."
    },
    {
      "id": "ICSA-26-204-03",
      "title": "Weintek cMT3092X",
      "published": "2026-07-23T06:00:00.000000Z",
      "updated": "2026-07-23T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 8.8,
      "vendors": [
        "Weintek"
      ],
      "products": [
        "cMT3092X firmware",
        "EasyWeb"
      ],
      "cves": [
        "CVE-2026-60134",
        "CVE-2026-61892",
        "CVE-2026-61886",
        "CVE-2026-60135"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-03",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-204-03.json",
      "summary": "Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users."
    },
    {
      "id": "ICSA-26-204-02",
      "title": "Johnson Controls XAAP Android",
      "published": "2026-07-23T06:00:00.000000Z",
      "updated": "2026-07-23T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "LOW",
      "cvss": 3.3,
      "vendors": [
        "Johnson Controls"
      ],
      "products": [
        "XAAP Android"
      ],
      "cves": [
        "CVE-2026-34490"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-02",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-204-02.json",
      "summary": "Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device."
    },
    {
      "id": "ICSA-26-202-10",
      "title": "Rockwell Automation Studio 5000 Logix Designer",
      "published": "2026-07-21T06:00:00.000000Z",
      "updated": "2026-07-21T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.5,
      "vendors": [
        "Rockwell Automation"
      ],
      "products": [
        "Studio 5000 Logix Designer"
      ],
      "cves": [
        "CVE-2026-9108",
        "CVE-2026-9127",
        "CVE-2026-9128"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-10",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-202-10.json",
      "summary": "Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code."
    },
    {
      "id": "ICSA-26-202-08",
      "title": "Rockwell Automation 1718-AENTR/1719-AENTR",
      "published": "2026-07-21T06:00:00.000000Z",
      "updated": "2026-07-21T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.5,
      "vendors": [
        "Rockwell Automation"
      ],
      "products": [
        "1718/ 1719 Ex I/O"
      ],
      "cves": [
        "CVE-2026-9140"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-08",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-202-08.json",
      "summary": "Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product."
    },
    {
      "id": "ICSA-26-202-07",
      "title": "Rockwell Automation FactoryTalk Services Platform",
      "published": "2026-07-21T06:00:00.000000Z",
      "updated": "2026-07-21T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.8,
      "vendors": [
        "Rockwell Automation"
      ],
      "products": [
        "FactoryTalk Directory (FTSP)"
      ],
      "cves": [
        "CVE-2026-10714"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-07",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-202-07.json",
      "summary": "Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations."
    },
    {
      "id": "ICSA-26-202-01",
      "title": "Tycon Systems TPDIN-Monitor-WEB2",
      "published": "2026-07-21T06:00:00.000000Z",
      "updated": "2026-07-21T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "CRITICAL",
      "cvss": 9.8,
      "vendors": [
        "Tycon Systems"
      ],
      "products": [
        "TPDIN-Monitor-WEB2"
      ],
      "cves": [
        "CVE-2026-61884",
        "CVE-2026-55985"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-202-01.json",
      "summary": "Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk."
    },
    {
      "id": "ICSA-26-202-09",
      "title": "Rockwell Automation 1734 POINT I/O",
      "published": "2026-07-21T06:00:00.000000Z",
      "updated": "2026-07-21T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.5,
      "vendors": [
        "Rockwell Automation"
      ],
      "products": [
        "1734 POINT I/O"
      ],
      "cves": [
        "CVE-2026-10573"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-09",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-202-09.json",
      "summary": "Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product."
    },
    {
      "id": "ICSA-26-209-07",
      "title": "ABB KNX Update Tool",
      "published": "2026-07-17T00:30:00.000000Z",
      "updated": "2026-07-28T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "MEDIUM",
      "cvss": 6.4,
      "vendors": [
        "ABB"
      ],
      "products": [
        "KNX Update Tool (ABB)",
        "KNX Update Tool (BJE)"
      ],
      "cves": [
        "CVE-2026-12705"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-07",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-209-07.json",
      "summary": "ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The vulnerability report has been shared in responsible disclosure. An attacker who succe\u2026"
    },
    {
      "id": "ICSA-26-197-08",
      "title": "Rockwell Automation Flex 5000 Adapter",
      "published": "2026-07-16T06:00:00.000000Z",
      "updated": "2026-07-16T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.5,
      "vendors": [
        "Rockwell Automation"
      ],
      "products": [
        "Flex 5000 Adapter"
      ],
      "cves": [
        "CVE-2026-12659"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-08",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-197-08.json",
      "summary": "Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition on the affected product."
    },
    {
      "id": "ICSA-26-197-07",
      "title": "SALTO ProAccess Space",
      "published": "2026-07-16T06:00:00.000000Z",
      "updated": "2026-07-16T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "MEDIUM",
      "cvss": 6.5,
      "vendors": [
        "SALTO"
      ],
      "products": [
        "ProAccess Space"
      ],
      "cves": [
        "CVE-2026-11889"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-07",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-197-07.json",
      "summary": "Successful exploitation of this vulnerability allows an authenticated attacker to escalate privileges and access spaces outside their assigned partition, within the same Salto ProAccess Space installation or system. Exploitation requires valid authenticated operator credential\u2026"
    },
    {
      "id": "ICSA-26-197-06",
      "title": "Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix",
      "published": "2026-07-16T06:00:00.000000Z",
      "updated": "2026-07-16T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 8.6,
      "vendors": [
        "Rockwell Automation"
      ],
      "products": [
        "CompactLogix 5370",
        "Compact GuardLogix 5370",
        "ControlLogix 5570",
        "GuardLogix 5570",
        "CompactLogix 5380",
        "Compact GuardLogix 5380",
        "CompactLogix 5480",
        "ControlLogix 5580"
      ],
      "cves": [
        "CVE-2025-12011",
        "CVE-2025-12012",
        "CVE-2025-11698"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-06",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-197-06.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition."
    },
    {
      "id": "ICSA-26-197-04",
      "title": "AutomationDirect Productivity Suite",
      "published": "2026-07-16T06:00:00.000000Z",
      "updated": "2026-07-16T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.0,
      "vendors": [
        "AutomationDirect"
      ],
      "products": [
        "Productivity Suite"
      ],
      "cves": [
        "CVE-2026-60063",
        "CVE-2026-61389",
        "CVE-2026-60140",
        "CVE-2026-57896",
        "CVE-2026-60073",
        "CVE-2026-61378"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-04",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-197-04.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker with local or physical access to cause memory corruption, unintended information disclosure, application instability, or a denial-of-service condition in the affected product."
    },
    {
      "id": "ICSA-26-197-03",
      "title": "NASA Core Flight System (cFS) Health & Safety (HS) Application",
      "published": "2026-07-16T06:00:00.000000Z",
      "updated": "2026-07-16T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.5,
      "vendors": [
        "NASA"
      ],
      "products": [
        "Core Flight System (cFS) Health & Safety (HS) Application"
      ],
      "cves": [
        "CVE-2026-15352"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-03",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-197-03.json",
      "summary": "Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition."
    },
    {
      "id": "ICSA-26-197-02",
      "title": "Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT",
      "published": "2026-07-16T06:00:00.000000Z",
      "updated": "2026-07-16T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.5,
      "vendors": [
        "Rockwell Automation"
      ],
      "products": [
        "1756-EN3",
        "1756-EN2",
        "1756-ENBT"
      ],
      "cves": [
        "CVE-2026-9653"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-02",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-197-02.json",
      "summary": "Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition."
    },
    {
      "id": "ICSA-26-197-09",
      "title": "Rockwell Automation FactoryTalk DataMosaix",
      "published": "2026-07-16T06:00:00.000000Z",
      "updated": "2026-07-16T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "MEDIUM",
      "cvss": 6.1,
      "vendors": [
        "Rockwell Automation"
      ],
      "products": [
        "DataMosaix Private Cloud"
      ],
      "cves": [
        "CVE-2026-9292"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-09",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-197-09.json",
      "summary": "Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious scripts on the server."
    },
    {
      "id": "ICSA-26-197-01",
      "title": "Rockwell Automation Arena",
      "published": "2026-07-16T06:00:00.000000Z",
      "updated": "2026-07-16T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.8,
      "vendors": [
        "Rockwell Automation"
      ],
      "products": [
        "Arena"
      ],
      "cves": [
        "CVE-2026-8085",
        "CVE-2026-8312",
        "CVE-2026-8313",
        "CVE-2026-8314"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-197-01.json",
      "summary": "Successful exploitation these vulnerabilities could allow an attacker to execute arbitrary code in the context of the current process."
    },
    {
      "id": "ICSA-26-211-04",
      "title": "Schneider Electric IGSS",
      "published": "2026-07-14T07:00:00.000000Z",
      "updated": "2026-07-30T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.8,
      "vendors": [
        "Schneider Electric"
      ],
      "products": [
        "IGSS",
        "IGSS Definition (Def.exe) module"
      ],
      "cves": [
        "CVE-2026-12927"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-04",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-211-04.json",
      "summary": "We strongly recommend the following industry cybersecurity best practices. * Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network. * Install physical controls so no unauthorized personnel can access your indus\u2026"
    },
    {
      "id": "ICSA-26-204-05",
      "title": "Rockwell Automation ThinManager",
      "published": "2026-07-14T06:00:00.000000Z",
      "updated": "2026-07-23T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 8.1,
      "vendors": [
        "Rockwell Automation"
      ],
      "products": [
        "ThinManager"
      ],
      "cves": [
        "CVE-2026-11917"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-05",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-204-05.json",
      "summary": "Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory."
    },
    {
      "id": "ICSA-26-195-04",
      "title": "Rockwell Automation 1715-AENTR EtherNet/IP Adapter",
      "published": "2026-07-14T06:00:00.000000Z",
      "updated": "2026-07-14T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "CRITICAL",
      "cvss": 10.0,
      "vendors": [
        "Rockwell Automation"
      ],
      "products": [
        "1715-AENTR EtherNet/IP Adapter"
      ],
      "cves": [
        "CVE-2026-10577"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-04",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-195-04.json",
      "summary": "Successful exploitation of this vulnerability could allow an attacker to read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device."
    },
    {
      "id": "ICSA-26-209-04",
      "title": "Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP",
      "published": "2026-07-14T00:00:00.000000Z",
      "updated": "2026-07-28T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "CRITICAL",
      "cvss": 9.8,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)",
        "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0)",
        "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0)",
        "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0)",
        "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0)"
      ],
      "cves": [
        "CVE-2021-41617",
        "CVE-2023-28531",
        "CVE-2023-51384",
        "CVE-2023-52927",
        "CVE-2024-26783",
        "CVE-2024-27056",
        "CVE-2024-28956",
        "CVE-2024-36903",
        "CVE-2024-36927",
        "CVE-2024-42079",
        "CVE-2024-46786",
        "CVE-2024-47736"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-04",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-209-04.json",
      "summary": "Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends specific countermeasures for products whe\u2026"
    },
    {
      "id": "ICSA-26-209-02",
      "title": "Siemens Mendix Runtime",
      "published": "2026-07-14T00:00:00.000000Z",
      "updated": "2026-07-28T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "CRITICAL",
      "cvss": 9.1,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "Mendix Runtime"
      ],
      "cves": [
        "CVE-2026-7891"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-02",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-209-02.json",
      "summary": "Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely. This documentation gap may lead application developers to unknowingly apply ove\u2026"
    },
    {
      "id": "ICSA-26-209-03",
      "title": "Siemens SIMATIC S7-PLCSIM Advanced",
      "published": "2026-07-14T00:00:00.000000Z",
      "updated": "2026-07-28T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.4,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "SIMATIC S7-PLCSIM Advanced"
      ],
      "cves": [
        "CVE-2026-54429"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-03",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-209-03.json",
      "summary": "SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available."
    },
    {
      "id": "ICSA-26-209-01",
      "title": "Siemens Desigo CC",
      "published": "2026-07-14T00:00:00.000000Z",
      "updated": "2026-07-28T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "CRITICAL",
      "cvss": 9.8,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "Desigo CC family V7",
        "Desigo CC family V8",
        "Desigo CC family V9"
      ],
      "cves": [
        "CVE-2025-15467"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-209-01.json",
      "summary": "OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the la\u2026"
    },
    {
      "id": "ICSA-26-202-05",
      "title": "Siemens IAM Client",
      "published": "2026-07-14T00:00:00.000000Z",
      "updated": "2026-07-21T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "MEDIUM",
      "cvss": 6.7,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "COMOS V10.4.5",
        "COMOS V10.6",
        "Designcenter NX",
        "Simcenter 3D",
        "Simcenter Femap V2506",
        "Simcenter Femap V2512",
        "Simcenter Nastran",
        "Simcenter STAR-CCM+"
      ],
      "cves": [
        "CVE-2025-40945"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-05",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-202-05.json",
      "summary": "Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest\u2026"
    },
    {
      "id": "ICSA-26-202-04",
      "title": "Siemens SIDIS Secured SmartPlug",
      "published": "2026-07-14T00:00:00.000000Z",
      "updated": "2026-07-21T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "CRITICAL",
      "cvss": 9.8,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "SIDIS Secured SmartPlug"
      ],
      "cves": [
        "CVE-2022-23303",
        "CVE-2022-23304",
        "CVE-2022-37660",
        "CVE-2022-48174",
        "CVE-2025-5222",
        "CVE-2025-5914",
        "CVE-2025-9230",
        "CVE-2025-9231",
        "CVE-2025-9232",
        "CVE-2025-26465",
        "CVE-2025-32462",
        "CVE-2026-5121"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-04",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-202-04.json",
      "summary": "SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version."
    },
    {
      "id": "ICSA-26-202-03",
      "title": "Siemens Opcenter X",
      "published": "2026-07-14T00:00:00.000000Z",
      "updated": "2026-07-21T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "CRITICAL",
      "cvss": 10.0,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "Opcenter X"
      ],
      "cves": [
        "CVE-2026-56451"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-03",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-202-03.json",
      "summary": "Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version."
    },
    {
      "id": "ICSA-26-202-02",
      "title": "Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW",
      "published": "2026-07-14T00:00:00.000000Z",
      "updated": "2026-07-21T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.2,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "RUGGEDCOM APE1808"
      ],
      "cves": [
        "CVE-2026-0266",
        "CVE-2026-0272",
        "CVE-2026-0273"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-02",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-202-02.json",
      "summary": "Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream\u2026"
    },
    {
      "id": "ICSA-26-202-06",
      "title": "Siemens CADRA",
      "published": "2026-07-14T00:00:00.000000Z",
      "updated": "2026-07-21T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "CRITICAL",
      "cvss": 9.8,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "CADRA"
      ],
      "cves": [
        "CVE-2005-2096",
        "CVE-2016-9840",
        "CVE-2016-9841",
        "CVE-2016-9842",
        "CVE-2017-14919",
        "CVE-2018-25032",
        "CVE-2022-37434",
        "CVE-2023-45853",
        "CVE-2025-10585",
        "CVE-2025-13223",
        "CVE-2026-22184"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-06",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-202-06.json",
      "summary": "CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not\u2026"
    },
    {
      "id": "ICSA-26-190-01",
      "title": "OpenPLC v3",
      "published": "2026-07-09T06:00:00.000000Z",
      "updated": "2026-07-09T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "CRITICAL",
      "cvss": 9.9,
      "vendors": [
        "OpenPLC"
      ],
      "products": [
        "OpenPLC"
      ],
      "cves": [
        "CVE-2026-14480"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-190-01.json",
      "summary": "Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to the filesystem and escalate this into arbitrary native code execution through the normal OpenPLC program compilation process, potentially resulting in code execution\u2026"
    },
    {
      "id": "ICSA-26-197-05",
      "title": "Siemens SICAM 8",
      "published": "2026-07-09T00:00:00.000000Z",
      "updated": "2026-07-16T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.2,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "CPCI85 Central Processing/Communication",
        "SICORE Base system"
      ],
      "cves": [
        "CVE-2026-54798",
        "CVE-2026-54799",
        "CVE-2026-54800",
        "CVE-2026-54801"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-05",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-197-05.json",
      "summary": "Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: - SICAM A8000 Device firmware - CPCI85 for CP-8031/CP-8050 - SICORE for CP-8010/CP-8012 - SICAM EGS Device firmware - CPCI85 - SICAM S8000 - SICORE Siemens has rele\u2026"
    },
    {
      "id": "ICSA-26-188-07",
      "title": "Digi International PortServer TS, Digi One SP IA",
      "published": "2026-07-07T06:00:00.000000Z",
      "updated": "2026-07-07T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "MEDIUM",
      "cvss": 5.9,
      "vendors": [
        "Digi International"
      ],
      "products": [
        "PortServer TS",
        "Digi One SP",
        "Digi One SP IA",
        "Digi One IA"
      ],
      "cves": [
        "CVE-2026-12352",
        "CVE-2026-12948"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-07",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-188-07.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication and gain access to restricted resources, obtain credentials, and inject malicious scripts."
    },
    {
      "id": "ICSA-26-188-01",
      "title": "Hydro-Qu\u00e9bec Le Circuit Electrique charging station backend",
      "published": "2026-07-07T06:00:00.000000Z",
      "updated": "2026-07-07T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "CRITICAL",
      "cvss": 9.8,
      "vendors": [
        "Hydro-Qu\u00e9bec"
      ],
      "products": [
        "Le Circuit Electrique charging station backend"
      ],
      "cves": [
        "CVE-2026-20744",
        "CVE-2026-42952",
        "CVE-2026-44383"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-188-01.json",
      "summary": "Successful exploitation of these vulnerabilities could lead to privilege escalation, or result in a denial-of-service attack."
    },
    {
      "id": "ICSA-26-188-06",
      "title": "Labcenter Proteus 9",
      "published": "2026-07-07T06:00:00.000000Z",
      "updated": "2026-07-07T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.8,
      "vendors": [
        "Labcenter Electronics"
      ],
      "products": [
        "Proteus"
      ],
      "cves": [
        "CVE-2026-42953",
        "CVE-2026-49033",
        "CVE-2026-42958"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-06",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-188-06.json",
      "summary": "Successful exploitation of these vulnerabilities could disclose information and allow a malicious user to execute arbitrary code on affected installations."
    },
    {
      "id": "ICSA-26-183-02",
      "title": "CubeSpace CW0057 Reaction Wheel",
      "published": "2026-07-02T06:00:00.000000Z",
      "updated": "2026-07-02T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "MEDIUM",
      "cvss": 6.1,
      "vendors": [
        "CubeSpace"
      ],
      "products": [
        "CW0057 Reaction Wheel"
      ],
      "cves": [
        "CVE-2026-13743"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-02",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-183-02.json",
      "summary": "Successful exploitation of this vulnerability could allow an attacker to upload arbitrary malicious firmware to the device."
    },
    {
      "id": "ICSA-26-183-01",
      "title": "ST Engineering iDirect iQ-Series Terminals",
      "published": "2026-07-02T06:00:00.000000Z",
      "updated": "2026-07-02T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 8.1,
      "vendors": [
        "ST Engineering iDirect"
      ],
      "products": [
        "Evolution iQ\u2011Series terminals",
        "3315\u2011Series terminals",
        "9\u2011Series terminals"
      ],
      "cves": [
        "CVE-2026-38059",
        "CVE-2026-38057"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-183-01.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition."
    },
    {
      "id": "ICSA-26-183-03",
      "title": "Gardyn IoT Hub",
      "published": "2026-07-02T05:00:00.000000Z",
      "updated": "2026-07-02T05:00:00.000000Z",
      "kind": "advisory",
      "severity": "CRITICAL",
      "cvss": 10.0,
      "vendors": [
        "Gardyn"
      ],
      "products": [
        "Home Firmware",
        "Studio Firmware",
        "Cloud API"
      ],
      "cves": [
        "CVE-2026-13768",
        "CVE-2026-55726",
        "CVE-2026-54477"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-03",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-183-03.json",
      "summary": "Successful exploitation of these vulnerabilities could allow unauthenticated users to access and control IoT Hub managed devices."
    },
    {
      "id": "ICSMA-26-181-01",
      "title": "OFFIS DCMTK Toolkit",
      "published": "2026-06-30T06:00:00.000000Z",
      "updated": "2026-06-30T06:00:00.000000Z",
      "kind": "medical",
      "severity": "CRITICAL",
      "cvss": 9.8,
      "vendors": [
        "OFFIS"
      ],
      "products": [
        "DCMTK"
      ],
      "cves": [
        "CVE-2026-50003",
        "CVE-2026-50254",
        "CVE-2026-35505",
        "CVE-2026-52868",
        "CVE-2026-44628"
      ],
      "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-181-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsma-26-181-01.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker to write files, access unauthorized information, exhaust memory, or crash affected DCMTK client or server processes."
    },
    {
      "id": "ICSA-26-181-07",
      "title": "Delta Electronics DVP12SE PLC",
      "published": "2026-06-30T06:00:00.000000Z",
      "updated": "2026-06-30T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "CRITICAL",
      "cvss": 9.8,
      "vendors": [
        "Delta Electronics"
      ],
      "products": [
        "DVP12SE PLC"
      ],
      "cves": [
        "CVE-2026-12819",
        "CVE-2026-12818"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-07",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-181-07.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker to remotely issue commands, modify operational values, interfere with control logic, and alter device behavior without authentication or privilege enforcement."
    },
    {
      "id": "ICSA-26-181-02",
      "title": "Frangoteam FUXA SCADA/HMI",
      "published": "2026-06-30T06:00:00.000000Z",
      "updated": "2026-06-30T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.5,
      "vendors": [
        "Frangoteam"
      ],
      "products": [
        "FUXA SCADA/HMI"
      ],
      "cves": [
        "CVE-2026-13207"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-02",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-181-02.json",
      "summary": "Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to enumerate all user accounts and role assignments on a FUXA SCADA/HMI instance."
    },
    {
      "id": "ICSA-26-181-06",
      "title": "StoneFly Storage Concentrator",
      "published": "2026-06-30T06:00:00.000000Z",
      "updated": "2026-06-30T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "CRITICAL",
      "cvss": 10.0,
      "vendors": [
        "StoneFly"
      ],
      "products": [
        "Storage Concentrator",
        "Storage Concentrator Virtual Machine"
      ],
      "cves": [
        "CVE-2026-50110",
        "CVE-2026-56413",
        "CVE-2026-56415",
        "CVE-2026-55721",
        "CVE-2026-50040"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-06",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-181-06.json",
      "summary": "Successful exploitation of these vulnerabilities could allow attackers to gain broad unauthorized access, execute arbitrary commands with root privileges, steal sensitive data, and perform actions on behalf of legitimate users across interconnected systems."
    },
    {
      "id": "ICSA-26-181-01",
      "title": "Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M",
      "published": "2026-06-30T06:00:00.000000Z",
      "updated": "2026-06-30T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 8.8,
      "vendors": [
        "Mitsubishi Electric"
      ],
      "products": [
        "MELSOFT Update Manager SW1DND-UDM-M"
      ],
      "cves": [
        "CVE-2025-53816",
        "CVE-2025-53817",
        "CVE-2025-55188",
        "CVE-2025-11001"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-181-01.json",
      "summary": "Successful exploitation of these vulnerabilities could allow a local attacker to tamper with or destroy information in the affected product, cause a denial-of-service condition in the affected product, or execute arbitrary code when a specially crafted archive file is decompre\u2026"
    },
    {
      "id": "ICSA-26-188-03",
      "title": "Hitachi Energy e-mesh EMS",
      "published": "2026-06-30T00:00:00.000000Z",
      "updated": "2026-07-07T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 8.1,
      "vendors": [
        "Hitachi Energy"
      ],
      "products": [
        "Hitachi Energy e-mesh EMS"
      ],
      "cves": [
        "CVE-2026-42945"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-03",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-188-03.json",
      "summary": "Hitachi Energy is aware of a buffer overflow vulnerability that affects e-mesh EMS product versions listed in this document. Successful exploitation of this vulnerability could lead to a buffer overflow condition, potentially resulting in application outages (denial of service\u2026"
    },
    {
      "id": "ICSA-26-188-02",
      "title": "Hitachi Energy PROMOD V",
      "published": "2026-06-30T00:00:00.000000Z",
      "updated": "2026-07-07T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.1,
      "vendors": [
        "Hitachi Energy"
      ],
      "products": [
        "PROMOD V"
      ],
      "cves": [
        "CVE-2026-10763"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-02",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-188-02.json",
      "summary": "Hitachi Energy is aware of insecure HTTP transmission vulnerability in PROMOD V product versions listed in this document. This vulnerability could allow attackers to intercept or manipulate sensitive data in transit, potentially leading to credential theft, session hijacking,\u2026"
    },
    {
      "id": "ICSA-26-188-04",
      "title": "Siemens Mendix Studio Pro",
      "published": "2026-06-30T00:00:00.000000Z",
      "updated": "2026-07-07T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "MEDIUM",
      "cvss": 5.4,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "Mendix Studio Pro 10.11",
        "Mendix Studio Pro 10.12",
        "Mendix Studio Pro 10.13",
        "Mendix Studio Pro 10.14",
        "Mendix Studio Pro 10.15",
        "Mendix Studio Pro 10.16",
        "Mendix Studio Pro 10.17",
        "Mendix Studio Pro 10.18"
      ],
      "cves": [
        "CVE-2026-48192"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-04",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-188-04.json",
      "summary": "Mendix Studio Pro versions before V11.12 are affected by a file parsing vulnerability that could be triggered when the application reads specially crafted malicious project during the build pipeline. This could allow an attacker to execute arbitrary code in the context of that\u2026"
    },
    {
      "id": "ICSMA-26-176-02",
      "title": "OHIF Viewers DICOM",
      "published": "2026-06-25T06:00:00.000000Z",
      "updated": "2026-06-25T06:00:00.000000Z",
      "kind": "medical",
      "severity": "HIGH",
      "cvss": 8.2,
      "vendors": [
        "Open Health Imaging Foundation (OHIF)"
      ],
      "products": [
        "OHIF DICOM Web Viewer Framework"
      ],
      "cves": [
        "CVE-2026-12473"
      ],
      "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-176-02",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsma-26-176-02.json",
      "summary": "Successful exploitation of this vulnerability in a custom integration version could allow an attacker to steal an authenticated clinician's token via a crafted link."
    },
    {
      "id": "ICSMA-26-176-01",
      "title": "pydicom pynetdicom Library",
      "published": "2026-06-25T06:00:00.000000Z",
      "updated": "2026-06-25T06:00:00.000000Z",
      "kind": "medical",
      "severity": "CRITICAL",
      "cvss": 9.1,
      "vendors": [
        "pydicom"
      ],
      "products": [
        "pynetdicom"
      ],
      "cves": [
        "CVE-2026-56445"
      ],
      "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-176-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsma-26-176-01.json",
      "summary": "Successful exploitation of this vulnerability could allow an unauthenticated attacker to write to arbitrary file paths."
    },
    {
      "id": "ICSA-26-176-06",
      "title": "Delta Electronics DTM Soft",
      "published": "2026-06-25T06:00:00.000000Z",
      "updated": "2026-06-25T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.8,
      "vendors": [
        "Delta Electronics"
      ],
      "products": [
        "DTMSoft"
      ],
      "cves": [
        "CVE-2026-12578"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-06",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-06.json",
      "summary": "Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code."
    },
    {
      "id": "ICSA-26-176-04",
      "title": "Daktronics Controller Firmware",
      "published": "2026-06-25T06:00:00.000000Z",
      "updated": "2026-06-25T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 8.1,
      "vendors": [
        "Daktronics"
      ],
      "products": [
        "VFC-DMP-5000",
        "DMP-5000",
        "DMP-8000"
      ],
      "cves": [
        "CVE-2026-28701",
        "CVE-2026-33560",
        "CVE-2026-31928"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-04",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-04.json",
      "summary": "Successful exploitation of these vulnerabilities could could provide an unauthenticated user with complete root-level access and control of the system."
    },
    {
      "id": "ICSA-26-176-05",
      "title": "H.VIEW HV-500S6 IP Camera",
      "published": "2026-06-25T06:00:00.000000Z",
      "updated": "2026-06-25T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.2,
      "vendors": [
        "H.VIEW"
      ],
      "products": [
        "HV-500S6 IP Camera"
      ],
      "cves": [
        "CVE-2026-55975",
        "CVE-2026-56414"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-05",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-05.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code and upload malicious files to the affected device."
    },
    {
      "id": "ICSA-26-176-01",
      "title": "Yokogawa FAST/TOOLS and CI Server",
      "published": "2026-06-25T06:00:00.000000Z",
      "updated": "2026-06-25T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.5,
      "vendors": [
        "Yokogawa"
      ],
      "products": [
        "FAST/TOOLS",
        "Collaborative Information Server (CI Server)"
      ],
      "cves": [
        "CVE-2026-11833"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-01.json",
      "summary": "Successful exploitation of this vulnerability may return a response containing the CI Server setting information."
    },
    {
      "id": "ICSA-26-176-03",
      "title": "Horner Automation Cscape",
      "published": "2026-06-25T06:00:00.000000Z",
      "updated": "2026-06-25T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.8,
      "vendors": [
        "Horner Automation"
      ],
      "products": [
        "Cscape"
      ],
      "cves": [
        "CVE-2026-12897"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-03",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-03.json",
      "summary": "Successful exploitation of this vulnerability could allow a local attacker to disclose information and execute arbitrary code."
    },
    {
      "id": "ICSA-26-176-02",
      "title": "EVoke Systems Charging Station Management System",
      "published": "2026-06-25T05:00:00.000000Z",
      "updated": "2026-06-25T05:00:00.000000Z",
      "kind": "advisory",
      "severity": "CRITICAL",
      "cvss": 9.4,
      "vendors": [
        "EVoke Systems"
      ],
      "products": [
        "EVoke CSMS"
      ],
      "cves": [
        "CVE-2026-40702",
        "CVE-2026-50176",
        "CVE-2026-54479",
        "CVE-2026-44622"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-02",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-02.json",
      "summary": "Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks."
    },
    {
      "id": "ICSA-26-195-02",
      "title": "ABB Ability Edgenius",
      "published": "2026-06-25T00:30:00.000000Z",
      "updated": "2026-07-14T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.8,
      "vendors": [
        "ABB"
      ],
      "products": [
        "Gateway - bE100",
        "Gateway - E3100C",
        "Server - vE1000"
      ],
      "cves": [
        "CVE-2026-31431"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-02",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-195-02.json",
      "summary": "ABB is aware of public reports of a vulnerability CVE\u20112026\u201131431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE\u20112026\u201131431 (Copy Fail) is a Linux kernel vulnerability that may\u2026"
    },
    {
      "id": "ICSA-26-174-07",
      "title": "Hubbell Aclara Metrum Cellular Web Interface",
      "published": "2026-06-23T06:00:00.000000Z",
      "updated": "2026-06-23T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.5,
      "vendors": [
        "Hubbell"
      ],
      "products": [
        "Aclara Metrum Cellular Web Interface"
      ],
      "cves": [
        "CVE-2026-1840"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-07",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-07.json",
      "summary": "Successful exploitation of this vulnerability could allow attackers to manipulate critical device settings and repeatedly disrupt operations, potentially causing a loss of communications to the device."
    },
    {
      "id": "ICSA-26-195-01",
      "title": "ABB Advant Master Online Builder",
      "published": "2026-06-23T00:30:00.000000Z",
      "updated": "2026-07-14T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "MEDIUM",
      "cvss": 4.4,
      "vendors": [
        "ABB"
      ],
      "products": [
        "Control Builder A",
        "800xA for Advant Master"
      ],
      "cves": [
        "CVE-2025-13162"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-195-01.json",
      "summary": "ABB became aware of vulnerability in the products versions listed as affected in the advisory, where an incorrect version of Online Builder (ONB) was included in the media. An update is available that resolves the vulnerability, see details in Recommended immediate actions."
    },
    {
      "id": "ICSA-26-169-02",
      "title": "AzeoTech DAQFactory (Update A)",
      "published": "2026-06-18T06:00:00.000000Z",
      "updated": "2026-06-25T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.8,
      "vendors": [
        "AzeoTech"
      ],
      "products": [
        "DAQFactory"
      ],
      "cves": [
        "CVE-2026-12390",
        "CVE-2026-12921"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-02",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-169-02.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker to upload malicious .ctl files that may lead to arbitrary code execution."
    },
    {
      "id": "ICSA-26-169-03",
      "title": "Rockwell Automation FactoryTalk Historian Site Edition",
      "published": "2026-06-18T06:00:00.000000Z",
      "updated": "2026-06-18T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.7,
      "vendors": [
        "Rockwell Automation"
      ],
      "products": [
        "FactoryTalk Historian SE"
      ],
      "cves": [
        "CVE-2025-13036",
        "CVE-2025-44019",
        "CVE-2025-36539"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-03",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-169-03.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker to obtain a valid authentication token, perform a denial of service, or crash the system."
    },
    {
      "id": "ICSMA-26-169-01",
      "title": "Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT",
      "published": "2026-06-18T06:00:00.000000Z",
      "updated": "2026-06-18T06:00:00.000000Z",
      "kind": "medical",
      "severity": "MEDIUM",
      "cvss": 6.5,
      "vendors": [
        "Apollo Pharmacy"
      ],
      "products": [
        "Blood Glucose Monitoring System (Model No. APG-01 BT)"
      ],
      "cves": [
        "CVE-2026-50034",
        "CVE-2026-52866"
      ],
      "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-169-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsma-26-169-01.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker to obtain sensitive health-related information and prevent legitimate users from establishing a connection with the device."
    },
    {
      "id": "ICSA-26-169-01",
      "title": "AVer PTC cameras",
      "published": "2026-06-18T06:00:00.000000Z",
      "updated": "2026-06-18T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "CRITICAL",
      "cvss": 9.8,
      "vendors": [
        "AVer"
      ],
      "products": [
        "PTC500S",
        "PTC115",
        "PTC500+",
        "PTC115+"
      ],
      "cves": [
        "CVE-2026-40624"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-169-01.json",
      "summary": "Successful exploitation of this vulnerability could allow arbitrary code execution."
    },
    {
      "id": "ICSA-26-169-06",
      "title": "Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module",
      "published": "2026-06-18T00:00:00.000000Z",
      "updated": "2026-06-18T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.5,
      "vendors": [
        "Mitsubishi Electric"
      ],
      "products": [
        "Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP"
      ],
      "cves": [
        "CVE-2026-8806"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-06",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-169-06.json",
      "summary": "Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition in the affected product by continuously sending a large number of communication packets to the Ethernet port of the product in a short period of time, incre\u2026"
    },
    {
      "id": "ICSA-26-169-05",
      "title": "Mitsubishi Electric MELSEC iQ-F Series",
      "published": "2026-06-18T00:00:00.000000Z",
      "updated": "2026-06-18T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.5,
      "vendors": [
        "Mitsubishi Electric"
      ],
      "products": [
        "MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP"
      ],
      "cves": [
        "CVE-2026-8805"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-05",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-169-05.json",
      "summary": "Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition in the affected product by rapidly establishing a large number of TCP connections to it, resulting in an inconsistency in the product's internal connection\u2026"
    },
    {
      "id": "ICSA-26-167-04",
      "title": "Rockwell Automation CompactLogix",
      "published": "2026-06-16T06:00:00.000000Z",
      "updated": "2026-06-16T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.5,
      "vendors": [
        "Rockwell Automation"
      ],
      "products": [
        "CompactLogix 5370 L1",
        "CompactLogix 5370 L2",
        "CompactLogix 5370 L3"
      ],
      "cves": [
        "CVE-2025-11694",
        "CVE-2026-9307"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-04",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-167-04.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition."
    },
    {
      "id": "ICSA-26-167-03",
      "title": "Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP",
      "published": "2026-06-16T06:00:00.000000Z",
      "updated": "2026-06-16T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.5,
      "vendors": [
        "Rockwell Automation"
      ],
      "products": [
        "CompactLogix 5370",
        "Compact GuardLogix 5370",
        "ControlLogix 5570",
        "GuardLogix 5570"
      ],
      "cves": [
        "CVE-2026-11317"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-03",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-167-03.json",
      "summary": "Successful exploitation of this vulnerability could cause a denial-of-service condition that may result in a major nonrecoverable fault (MNRF)."
    },
    {
      "id": "ICSA-26-167-02",
      "title": "RSLinx Classic Third-Party Vulnerability",
      "published": "2026-06-16T06:00:00.000000Z",
      "updated": "2026-06-16T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.5,
      "vendors": [
        "Rockwell Automation"
      ],
      "products": [
        "RSLinx Classic"
      ],
      "cves": [
        "CVE-2020-13573"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-02",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-167-02.json",
      "summary": "Successful exploitation of this vulnerability can lead to a denial of service, where the application will become unresponsive and will not recover on its own."
    },
    {
      "id": "ICSA-26-167-01",
      "title": "Rockwell Automation FactoryTalk Analytics PavilionX",
      "published": "2026-06-16T06:00:00.000000Z",
      "updated": "2026-06-16T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.0,
      "vendors": [
        "Rockwell Automation"
      ],
      "products": [
        "FactoryTalk Analytics PavilionX"
      ],
      "cves": [
        "CVE-2025-14272"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-167-01.json",
      "summary": "Successful exploitation of this vulnerability could result in an attacker executing privileged operations."
    },
    {
      "id": "ICSA-26-167-05",
      "title": "Rockwell Automation FLEX I/O EtherNet/IP Adapters",
      "published": "2026-06-16T06:00:00.000000Z",
      "updated": "2026-06-16T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "CRITICAL",
      "cvss": 9.4,
      "vendors": [
        "Rockwell Automation"
      ],
      "products": [
        "1794-AENTR",
        "1794-AENTRXT"
      ],
      "cves": [
        "CVE-2026-0646",
        "CVE-2026-0647"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-05",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-167-05.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access, account takeover, and cause loss of availability."
    },
    {
      "id": "ICSA-26-162-03",
      "title": "Brickcom Cameras",
      "published": "2026-06-11T06:00:00.000000Z",
      "updated": "2026-06-11T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.7,
      "vendors": [
        "Brickcom"
      ],
      "products": [
        "Brickcom Cube",
        "Brickcom Dome",
        "Brickcom Bullet",
        "Brickcom Box"
      ],
      "cves": [
        "CVE-2026-50245",
        "CVE-2026-50005"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-162-03",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-162-03.json",
      "summary": "Successful exploitation of these vulnerabilities could allow a remote unauthenticated attacker to gain unauthorized access to live video feeds, retrieve sensitive visual information from affected premises, and obtain administrative control of the device."
    },
    {
      "id": "ICSA-26-162-01",
      "title": "Yarbo Android/iOS Mobile Application and Cloud Infrastructure",
      "published": "2026-06-11T06:00:00.000000Z",
      "updated": "2026-06-11T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "CRITICAL",
      "cvss": 9.8,
      "vendors": [
        "Yarbo"
      ],
      "products": [
        "Yarbo Android/IOS mobile application",
        "Cloud MQTT infrastructure"
      ],
      "cves": [
        "CVE-2026-10557",
        "CVE-2026-7368"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-162-01",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-162-01.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker to obtain hard-coded credentials, gain access to telemetry data, and potentially send operational commands to the robot fleet."
    },
    {
      "id": "ICSA-26-162-02",
      "title": "Naxclow IoT Platform",
      "published": "2026-06-11T06:00:00.000000Z",
      "updated": "2026-06-11T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "CRITICAL",
      "cvss": 9.8,
      "vendors": [
        "Naxclow"
      ],
      "products": [
        "Smart Doorbell X3",
        "X Smart Home",
        "V720",
        "ix cam"
      ],
      "cves": [
        "CVE-2026-42947",
        "CVE-2026-50108",
        "CVE-2026-50101",
        "CVE-2026-28742",
        "CVE-2026-42932",
        "CVE-2026-50244",
        "CVE-2026-50099"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-162-02",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-162-02.json",
      "summary": "Successful exploitation of these vulnerabilities could allow an attacker to impersonate devices, intercept or manipulate communications, harvest sensitive credentials at scale, or gain unauthorized access."
    },
    {
      "id": "ICSA-26-174-06",
      "title": "Impact of Linux Kernel vulnerabilities on B&R products",
      "published": "2026-06-11T00:30:00.000000Z",
      "updated": "2026-06-23T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.8,
      "vendors": [
        "B&R Industrial Automation GmbH"
      ],
      "products": [
        "Linux for B&R",
        "APROL",
        "X20EDS410"
      ],
      "cves": [
        "CVE-2026-31431",
        "CVE-2026-43284",
        "CVE-2026-46333",
        "CVE-2026-46300",
        "CVE-2026-43494"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-06",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-06.json",
      "summary": "B&R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory. Successful local exploitation of these vulnerabilities could allow an attacker to escalate privileges on the affected system. Pub\u2026"
    },
    {
      "id": "ICSA-26-181-05",
      "title": "XZ Utils vulnerability impacting B&R Products",
      "published": "2026-06-10T00:30:00.000000Z",
      "updated": "2026-06-30T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.5,
      "vendors": [
        "B&R Industrial Automation GmbH"
      ],
      "products": [
        "PPC3100",
        "C50",
        "C80",
        "FT50",
        "MT50",
        "T30",
        "T80",
        "T50"
      ],
      "cves": [
        "CVE-2025-31115"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-05",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-181-05.json",
      "summary": "An update is available that resolves vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the product to stop or corrupt memory data."
    },
    {
      "id": "ICSA-26-174-05",
      "title": "ABB Freelance Security Lock",
      "published": "2026-06-10T00:30:00.000000Z",
      "updated": "2026-06-23T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "MEDIUM",
      "cvss": 6.6,
      "vendors": [
        "ABB"
      ],
      "products": [
        "System Version",
        "Freelance Security Lock"
      ],
      "cves": [
        "CVE-2025-7064"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-05",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-05.json",
      "summary": "ABB is aware of a vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the product to stop or make the product inaccessible."
    },
    {
      "id": "ICSA-26-181-03",
      "title": "Schneider Electric EcoStruxure IT Data Center Expert",
      "published": "2026-06-09T07:00:00.000000Z",
      "updated": "2026-06-30T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "MEDIUM",
      "cvss": 6.5,
      "vendors": [
        "Schneider Electric"
      ],
      "products": [
        "EcoStruxure IT Data Center Expert"
      ],
      "cves": [
        "CVE-2026-8045"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-03",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-181-03.json",
      "summary": "We strongly recommend the following industry cybersecurity best practices. * Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network. * Install physical controls so no unauthorized personnel can access your indus\u2026"
    },
    {
      "id": "ICSA-26-176-07",
      "title": "Schneider Electric PowerLogic P7",
      "published": "2026-06-09T07:00:00.000000Z",
      "updated": "2026-06-25T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.5,
      "vendors": [
        "Schneider Electric"
      ],
      "products": [
        "PowerLogic\u2122 P7"
      ],
      "cves": [
        "CVE-2026-9716",
        "CVE-2026-9717",
        "CVE-2026-9718"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-07",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-07.json",
      "summary": "We strongly recommend the following industry cybersecurity best practices. https://www.se.com/us/en/download/document/7EN52-0390/ * Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network. * Install physical cont\u2026"
    },
    {
      "id": "ICSA-26-181-04",
      "title": "Schneider Electric EasyLogic T150 and Saitel DP RTU",
      "published": "2026-06-09T07:00:00.000000Z",
      "updated": "2026-06-25T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 7.5,
      "vendors": [
        "Schneider Electric"
      ],
      "products": [
        "EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller",
        "EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller Firmware",
        "Saitel DP Remote Terminal Unit & Controller",
        "Saitel DP Remote Terminal Unit & Controller Firmware"
      ],
      "cves": [
        "CVE-2026-9650",
        "CVE-2026-9651"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-04",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-181-04.json",
      "summary": "We strongly recommend the following industry cybersecurity best practices. * Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network. * Install physical controls so no unauthorized personnel can access your indus\u2026"
    },
    {
      "id": "ICSA-26-174-04",
      "title": "Siemens SINEC INS",
      "published": "2026-06-09T00:00:00.000000Z",
      "updated": "2026-06-23T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "HIGH",
      "cvss": 8.8,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "SINEC INS"
      ],
      "cves": [
        "CVE-2026-46746",
        "CVE-2026-46747",
        "CVE-2026-46748",
        "CVE-2026-46749"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-04",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-04.json",
      "summary": "SINEC INS before V1.0 SP2 Update 6 is affected by multiple vulnerabilities. Siemens has released a new version for SINEC INS and recommends to update to the latest version."
    },
    {
      "id": "ICSA-26-174-02",
      "title": "Siemens SIPROTEC 5 Using DIGSI5 Protocol",
      "published": "2026-06-09T00:00:00.000000Z",
      "updated": "2026-06-23T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "MEDIUM",
      "cvss": 6.1,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "SIPROTEC 5 6MD84 (CP300)",
        "SIPROTEC 5 6MD85 (CP200)",
        "SIPROTEC 5 6MD85 (CP300)",
        "SIPROTEC 5 6MD86 (CP200)",
        "SIPROTEC 5 6MD86 (CP300)",
        "SIPROTEC 5 6MD89 (CP300)",
        "SIPROTEC 5 6MU85 (CP300)",
        "SIPROTEC 5 7KE85 (CP200)"
      ],
      "cves": [
        "CVE-2025-40808"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-02",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-02.json",
      "summary": "SIPROTEC 5 is vulnerable to arbitrary file uploads by authenticated users using the DIGSI 5 protocol. This could allow an attacker to upload malicious configuration files, potentially causing a permanent denial of service condition. As a mitigation measure, users of the CP050\u2026"
    },
    {
      "id": "ICSA-26-174-03",
      "title": "Siemens Products using OpenSSL",
      "published": "2026-06-09T00:00:00.000000Z",
      "updated": "2026-06-23T06:00:00.000000Z",
      "kind": "advisory",
      "severity": "CRITICAL",
      "cvss": 9.8,
      "vendors": [
        "Siemens"
      ],
      "products": [
        "AI Lightweight Inference Server",
        "Connector for Azure",
        "Databus",
        "HiMed Cockpit",
        "RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2)",
        "RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2)",
        "SCALANCE LPE9403 (6GK5998-3GS00-2AC2)",
        "SCALANCE LPE9413 (6GK5998-3GS01-2AC2)"
      ],
      "cves": [
        "CVE-2025-15467"
      ],
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-03",
      "csaf_url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-03.json",
      "summary": "OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the la\u2026"
    }
  ]
}
