πŸ›‘οΈ Threat Intelligence Report

Generated: 2026-09-23 06:00:09

πŸ“Š Statistics

Total Items: 75

Sources Scraped: 6

Items with CVEs: 41

Errors: 0

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

The Hacker News General CVE-2026-93616

πŸ“… Tue, 22 Sep 2026 23:59:39 +0530

Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

The Hacker News General

πŸ“… Tue, 22 Sep 2026 23:33:10 +0530

WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch the project still supports, back to 4.7, and WordPress is telling site owners

Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

The Hacker News General

πŸ“… Tue, 22 Sep 2026 23:28:15 +0530

Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data. The package, named "tw-pkgprobe-7731," was first uploaded to the npm registry in mid-August 2026 by an npm account named "twdepprobe7731."

Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

The Hacker News General

πŸ“… Tue, 22 Sep 2026 22:33:31 +0530

Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

The Hacker News General CVE-2026-90898

πŸ“… Tue, 22 Sep 2026 22:11:12 +0530

A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is

Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates

The Hacker News General

πŸ“… Tue, 22 Sep 2026 21:44:04 +0530

A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used in

AI Agents Are Rewriting the Rules of Lateral Movement

The Hacker News General

πŸ“… Tue, 22 Sep 2026 18:00:00 +0530

Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has? A person may try several ways to complete a task. A deterministic application follows the flow its developer wrote. But an AI agent is relentless in its pursuit of done. In May

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

The Hacker News General CVE-2026-93952

πŸ“… Tue, 22 Sep 2026 17:59:00 +0530

Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are

DORA Year Two: Can Your SOC Actually See the Attack?

The Hacker News General

πŸ“… Tue, 22 Sep 2026 17:15:00 +0530

When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing third-party service providers, updating contract clauses, and documenting incident escalation workflows. Now in its second year, the harder part of DORA is

New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

The Hacker News General CVE-2026-89775

πŸ“… Tue, 22 Sep 2026 17:08:40 +0530

A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it can be used to escape the guest and run code on the host machine.

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

The Hacker News General CVE-2026-65660

πŸ“… Tue, 22 Sep 2026 16:47:41 +0530

A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

The Hacker News General

πŸ“… Tue, 22 Sep 2026 15:08:18 +0530

A malicious npm package named "indexed-btree" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls. "Indexed-btree is a malicious npm package mimicking the legit sorted-btree package, an ordinary B-tree/indexing utility," Checkmarx said. "

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

The Hacker News General

πŸ“… Tue, 22 Sep 2026 13:22:03 +0530

The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. "SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols," Trellix researchers

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

The Hacker News General

πŸ“… Tue, 22 Sep 2026 12:03:57 +0530

Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21. It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta. The flaw is in

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

The Hacker News General CVE-2026-93485

πŸ“… Tue, 22 Sep 2026 11:33:14 +0530

A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE-2026-93485 and called "Comment2Shell," on September 17 in version 7.1.1 and told site owners to update right away. There is

Siemens Industrial Edge Management

CISA General CVE-2026-18963

πŸ“… Tue, 22 Sep 26 12:00:00 +0000

View CSAF

Summary

Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification. Siemens has released new versions for the affected products and recommends to update to the latest versions.

The following versions of Siemens Industrial Edge Management are affected:

CVSS Vendor Equipment Vulnerabilities
v3 9.1 Siemens Siemens Industrial Edge Management Weak Password Recovery Mechanism for Forgotten Password

Background


Vulnerabilities

Expand All +

CVE-2026-18963

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.

View CVE Details


Affected Products

Siemens Industrial Edge Management
Vendor:
Siemens
Product Version:
Industrial Edge Management Cloud, Industrial Edge Management Pro V1 >= V1.14.9 < V1.15.20, Industrial Edge Management Pro V2 >= V2.2.0 < V2.2.2, Industrial Edge Management Virtual >= V2.6.0 < V2.9.1
Product Status:
known_affected
Remediations

Mitigation
Block direct internet access to IEM Pro / IEM Virtual The most effective immediate measure is to block direct internet access to your IEM Pro or IEM V instance. This ensures that no external attacks can occur via this vulnerability.

Mitigation
Configure a Web Application Firewall (WAF) or Reverse Proxy If complete blocking of internet access is not immediately feasible, you can use a Web Application Firewall (WAF) or a Reverse Proxy to block the affected path. Please configure your WAF or Reverse Proxy to block the following path: /auth/realms/customer/login-actions/reset-credentials Please note that by blocking this path, the password reset functionality will be unavailable.

Mitigation
Deactivate Password Reset in Keycloak Realm Settings Deactivate the password reset functionality directly within the Keycloak realm settings. To do this, navigate to: Identity & access management > realm settings > Login > Forgot password > Off Please note that by deactivating this setting, the password reset functionality will be unavailable.

Vendor fix
Update to V1.15.20 or later version
https://iehub.eu1.edge.siemens.cloud/

Vendor fix
Update to V2.2.2 or later version
https://iehub.eu1.edge.siemens.cloud/

Vendor fix
Update to V2.9.1 or later version
https://iehub.eu1.edge.siemens.cloud/

Vendor fix
Vulnerability mitigated with firewall rules on 2026-08-26 and fixed with update on 2026-09-02; no user actions necessary.

Mitigation
For more information see the associated Siemens security advisory SSA-503852: Authentication Bypass Vulnerability in Industrial Edge Management - CSAF Version, SSA-503852: Authentication Bypass Vulnerability in Industrial Edge Management - HTML Version

Relevant CWE: CWE-640 Weak Password Recovery Mechanism for Forgotten Password


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 9.1 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Acknowledgments


General Recommendations

As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity 


Additional Resources

For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories 


Terms of Use

The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.


Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.


Advisory Conversion Disclaimer

This ICSA is a verbatim republication of Siemens ProductCERT SSA-503852 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.

Revision History

Date Revision Summary
2026-09-08 1 Publication Date
2026-09-22 2 Initial CISA Republication of Siemens ProductCERT SSA-503852 advisory

Legal Notice and Terms of Use

OpenPLC Runtime v3

CISA General CVE-2026-88020

πŸ“… Tue, 22 Sep 26 12:00:00 +0000

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives.

The following versions of OpenPLC Runtime v3 are affected:

CVSS Vendor Equipment Vulnerabilities
v3 6.1 Autonomy Logic OpenPLC Runtime v3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Background


Vulnerabilities

Expand All +

CVE-2026-88020

The affected product is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding.

View CVE Details


Affected Products

OpenPLC Runtime v3
Vendor:
Autonomy Logic
Product Version:
Autonomy Logic OpenPLC: 3
Product Status:
known_affected
Remediations

Vendor fix
Autonomy Logic recommends users upgrade to OpenPLC v4 as OpenPLC v3 is end-of-life and is no longer receiving patches, bug fixes, or security updates.

Relevant CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
4.0 5.3 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

Acknowledgments


Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

CISA also recommends users take the following measures to protect themselves from social engineering attacks:

No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.


Revision History

Date Revision Summary
2026-09-22 1 Initial Publication

Legal Notice and Terms of Use

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA General CVE-2026-93616 CVE-2026-85102 CVE-2026-93952 CVE-2026-94127

πŸ“… Tue, 22 Sep 26 12:00:00 +0000

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. 

Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. 

While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria

Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.

lwIP (Lightweight IP)

CISA General CVE-2026-91018

πŸ“… Tue, 22 Sep 26 12:00:00 +0000

View CSAF

Summary

Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system.

The following versions of lwIP (Lightweight IP) are affected:

CVSS Vendor Equipment Vulnerabilities
v3 8.8 lwIP lwIP (Lightweight IP) Double Free

Background


Vulnerabilities

Expand All +

CVE-2026-91018

The affected product has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system.

View CVE Details


Affected Products

lwIP (Lightweight IP)
Vendor:
lwIP
Product Version:
lwIP API: >=2.0.1|<=2.2.1
Product Status:
known_affected
Remediations

Mitigation
Users of lwIP are encouraged to update their version of lwIP using the repository found at https://cgit.git.savannah.gnu.org/cgit/lwip.git. The commit identifier that contains the fix is f873b6295933e4149a2132adf3e9a2d2a676a5ec.
 

Relevant CWE: CWE-415 Double Free


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
4.0 8.7 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Acknowledgments


Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

CISA also recommends users take the following measures to protect themselves from social engineering attacks:

No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.


Revision History

Date Revision Summary
2026-09-22 1 Initial Publication

Legal Notice and Terms of Use

Siemens WTV676 and WTV776

CISA General CVE-2026-89207

πŸ“… Tue, 22 Sep 26 12:00:00 +0000

View CSAF

Summary

The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices. Siemens has released new versions for the affected products and recommends to update to the latest versions.

The following versions of Siemens WTV676 and WTV776 are affected:

CVSS Vendor Equipment Vulnerabilities
v3 6.5 Siemens Siemens WTV676 and WTV776 Improper Validation of Specified Type of Input

Background


Vulnerabilities

Expand All +

CVE-2026-89207

Affected devices do not properly validate input received from backend services. This could allow an unauthenticated remote attacker to force the device into protection mode, which results in losing remote connectivity functions (Web Access).

View CVE Details


Affected Products

Siemens WTV676 and WTV776
Vendor:
Siemens
Product Version:
WTV676-HB6035 Web Interface < V3.94, WTV776-HB6035 Web Interface < V4.17
Product Status:
known_affected
Remediations

Vendor fix
Update to V3.94 or later version
https://support.industry.siemens.com/cs/ww/en/view/109480838/

Vendor fix
Update to V4.17 or later version
https://support.industry.siemens.com/cs/ww/en/view/109480838/

Mitigation
For more information see the associated Siemens security advisory SSA-823812 in HTML and CSAF.

Relevant CWE: CWE-1287 Improper Validation of Specified Type of Input


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Acknowledgments


General Recommendations

As a general security measure Siemens strongly recommends protecting network access to affected products with appropriate mechanisms. It is advised to follow recommended security practices in order to run the devices in a protected IT environment.


Additional Resources

For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories 


Terms of Use

The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.


Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.


Advisory Conversion Disclaimer

This ICSA is a verbatim republication of Siemens ProductCERT SSA-823812 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.

Revision History

Date Revision Summary
2026-09-16 1 Publication Date
2026-09-22 2 Initial CISA Republication of Siemens ProductCERT SSA-823812 advisory

Legal Notice and Terms of Use

Siemens SIPLUS and SIMATIC Products

CISA General CVE-2026-31431

πŸ“… Tue, 22 Sep 26 12:00:00 +0000

View CSAF

Summary

Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

The following versions of Siemens SIPLUS and SIMATIC Products are affected:

CVSS Vendor Equipment Vulnerabilities
v3 7.8 Siemens Siemens SIPLUS and SIMATIC Products Incorrect Resource Transfer Between Spheres

Background


Vulnerabilities

Expand All +

CVE-2026-31431

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

View CVE Details


Affected Products

Siemens SIPLUS and SIMATIC Products
Vendor:
Siemens
Product Version:
SIMATIC AX Runtime Core Linux Common Debian, SIMATIC HMI MTP1000, Unified Comfort Panel neutral (6AV2128-3KB36-0AX1) < V21.2.1, SIMATIC HMI MTP1200 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3MB27-1BX0) < V21.2.1, SIMATIC HMI MTP1200 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3MB27-0BX0) < V21.2.1, SIMATIC HMI MTP1200 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3MB27-0AX0) < V21.2.1, SIMATIC HMI MTP1200 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3MB57-1BX0) < V21.2.1, SIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3MB57-0BX0) < V21.2.1, SIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3MB57-0AX0) < V21.2.1, SIMATIC HMI MTP1200 Unified Basic (6AV2123-3MB32-0AW0) < V21.2.1, SIMATIC HMI MTP1200 Unified Comfort Panel (6AV2128-3MB06-0AX1) < V21.2.1, SIMATIC HMI MTP1200 Unified Comfort Panel hygienic (6AV2128-3MB40-0AX0) < V21.2.1, SIMATIC AX Runtime Core Linux Common Debian arm64, SIMATIC HMI MTP1200 Unified Comfort Panel hygienic neutral design (6AV2128-3MB70-0AX0) < V21.2.1, SIMATIC HMI MTP1200 Unified Comfort Panel neutral design (6AV2128-3MB36-0AX1) < V21.2.1, SIMATIC HMI MTP1500 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3QB27-1BX0) < V21.2.1, SIMATIC HMI MTP1500 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3QB27-0BX0) < V21.2.1, SIMATIC HMI MTP1500 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3QB27-0AX0) < V21.2.1, SIMATIC HMI MTP1500 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3QB57-1BX0) < V21.2.1, SIMATIC HMI MTP1500 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3QB57-0BX0) < V21.2.1, SIMATIC HMI MTP1500 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3QB57-0AX0) < V21.2.1, SIMATIC HMI MTP1500 Unified Comfort Panel (6AV2128-3QB06-0AX1) < V21.2.1, SIMATIC HMI MTP1500 Unified Comfort Panel hygienic (6AV2128-3QB40-0AX0) < V21.2.1, SIMATIC AX Runtime Core Linux Platform Container Common Debian Development, SIMATIC HMI MTP1500 Unified Comfort Panel hygienic neutral design (6AV2128-3QB70-0AX0) < V21.2.1, SIMATIC HMI MTP1500 Unified Comfort Panel neutral design (6AV2128-3QB36-0AX1) < V21.2.1, SIMATIC HMI MTP1900 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3UB27-1BX0) < V21.2.1, SIMATIC HMI MTP1900 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3UB27-0BX0) < V21.2.1, SIMATIC HMI MTP1900 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3UB27-0AX0) < V21.2.1, SIMATIC HMI MTP1900 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3UB57-1BX0) < V21.2.1, SIMATIC HMI MTP1900 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3UB57-0BX0) < V21.2.1, SIMATIC HMI MTP1900 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3UB57-0AX0) < V21.2.1, SIMATIC HMI MTP1900 Unified Comfort Panel (6AV2128-3UB06-0AX1) < V21.2.1, SIMATIC HMI MTP1900 Unified Comfort Panel hygienic (6AV2128-3UB40-0AX0) < V21.2.1, SIMATIC AX Runtime Core Linux VMWare Development, SIMATIC HMI MTP1900 Unified Comfort Panel hygienic neutral design (6AV2128-3UB70-0AX0) < V21.2.1, SIMATIC HMI MTP1900 Unified Comfort Panel neutral design (6AV2128-3UB36-0AX1) < V21.2.1, SIMATIC HMI MTP2200 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3XB27-1BX0) < V21.2.1, SIMATIC HMI MTP2200 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3XB27-0BX0) < V21.2.1, SIMATIC HMI MTP2200 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3XB27-0AX0) < V21.2.1, SIMATIC HMI MTP2200 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3XB57-1BX0) < V21.2.1, SIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3XB57-0BX0) < V21.2.1, SIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3XB57-0AX0) < V21.2.1, SIMATIC HMI MTP2200 Unified Comfort Hygienic (6AV2128-3XB40-0AX0) < V21.2.1, SIMATIC HMI MTP2200 Unified Comfort Hygienic neutral design (6AV2128-3XB70-0AX0) < V21.2.1, SIMATIC CN 4100 < V6.0, SIMATIC HMI MTP2200 Unified Comfort Panel (6AV2128-3XB06-0AX1) < V21.2.1, SIMATIC HMI MTP2200 Unified Comfort Panel neutral design (6AV2128-3XB36-0AX1) < V21.2.1, SIMATIC HMI MTP400 Unified Basic (6AV2123-3DB32-0AW0) < V21.2.1, SIMATIC HMI MTP700 Unified Basic (6AV2123-3GB32-0AW0) < V21.2.1, SIMATIC HMI MTP700 Unified Comfort Panel (6AV2128-3GB06-0AX1) < V21.2.1, SIMATIC HMI MTP700 Unified Comfort Panel hygienic neutral design (6AV2128-3GB40-0AX0) < V21.2.1, SIMATIC HMI MTP700 Unified Comfort Panel hygienic neutral design (6AV2128-3GB70-0AX0) < V21.2.1, SIMATIC HMI MTP700, Unified Comfort Panel neutral design (6AV2128-3GB36-0AX1) < V21.2.1, SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2), SIMATIC IPC Industrial Edge Device OS (IED-OS), SIMATIC HMI MTP1000 Unified Basic (6AV2123-3KB32-0AW0) < V21.2.1, SIMATIC S7-1500 TM MFP (6ES7558-1AA00-0AB0), SIPLUS HMI MTP1000 Unified Basic (6AG1123-3KB32-2AW0) < V21.2.1, SIPLUS HMI MTP1000 Unified Comfort (6AG1128-3KB06-4AX1) < V21.2.1, SIPLUS HMI MTP1200 Unified Basic (6AG1123-3MB32-2AW0) < V21.2.1, SIPLUS HMI MTP1200 Unified Comfort (6AG1128-3MB06-4AX1) < V21.2.1, SIPLUS HMI MTP400 Unified Basic (6AG1123-3DB32-2AW0) < V21.2.1, SIPLUS HMI MTP700 Unified Basic (6AG1123-3GB32-2AW0) < V21.2.1, SIPLUS HMI MTP700 Unified Comfort (6AG1128-3GB06-4AX1) < V21.2.1, SIMATIC HMI MTP1000 Unified Comfort Panel (6AV2128-3KB06-0AX1) < V21.2.1, SIMATIC HMI MTP1000 Unified Comfort Panel hygienic (6AV2128-3KB40-0AX0) < V21.2.1, SIMATIC HMI MTP1000 Unified Comfort Panel hygienic neutral design (6AV2128-3KB70-0AX0) < V21.2.1
Product Status:
known_affected
Remediations

Mitigation
Limit access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only.

Mitigation
Only build and run applications from trusted sources.

None available
Currently no fix is available

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825897/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825897/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825897/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825897/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 SP2 Update 1 or later version TODO: download link missing

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V6.0 or later version
https://support.industry.siemens.com/cs/ww/en/view/109814144/

Vendor fix
For more information see the associated Siemens security advisory SSA-328642: "Copy Fail" Vulnerability in Multiple Industrial Products - CSAF Version, SSA-328642: "Copy Fail" Vulnerability in Multiple Industrial Products - HTML Version

Relevant CWE: CWE-669 Incorrect Resource Transfer Between Spheres


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Acknowledgments


General Recommendations

As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity 


Additional Resources

For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories 


Terms of Use

The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.


Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.


Advisory Conversion Disclaimer

This ICSA is a verbatim republication of Siemens ProductCERT SSA-328642 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.

Revision History

Date Revision Summary
2026-09-08 1 Publication Date
2026-09-22 2 Initial CISA Republication of Siemens ProductCERT SSA-328642 advisory

Legal Notice and Terms of Use

Siemens Desigo CC family

CISA General CVE-2026-34223

πŸ“… Tue, 22 Sep 26 12:00:00 +0000

View CSAF

Summary

A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization.

The following versions of Siemens Desigo CC family are affected:

CVSS Vendor Equipment Vulnerabilities
v3 8.2 Siemens Siemens Desigo CC family Improper Control of Generation of Code ('Code Injection')

Background


Vulnerabilities

Expand All +

CVE-2026-34223

The affected application is vulnerable to Client Code Execution (CCE) due to insufficient input validation when handling scripts embedded within user-defined graphics documents. Specifically, when the script within a graphics document is designed or modified by an attacker to include malicious commands. When a user opens a compromised graphics document, the embedded script is executed on the client application instance, allowing an attacker to write arbitrary files to the client's operating system. Successful exploitation requires an attacker to craft a malicious graphics document and entice a user with sufficient privileges to display it. This could lead to compromise of the client operating system and potential lateral movement within the organization.

View CVE Details


Affected Products

Siemens Desigo CC family
Vendor:
Siemens
Product Version:
Desigo CC family V6, Desigo CC family V7
Product Status:
known_affected
Remediations

Mitigation
Evaluate authorization policy for Graphics application following Least Privilege principle, so only required users have access to the configuration.

None available
Currently no fix is available.

Mitigation
For more information see the associated Siemens security advisory SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family - CSAF Version, SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family - HTML Version.

Relevant CWE: CWE-94 Improper Control of Generation of Code ('Code Injection')


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.2 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Acknowledgments


General Recommendations

As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity 


Additional Resources

For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories 


Terms of Use

The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.


Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.


Advisory Conversion Disclaimer

This ICSA is a verbatim republication of Siemens ProductCERT SSA-330084 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.

Revision History

Date Revision Summary
2026-09-08 1 Publication Date
2026-09-22 2 Initial CISA Republication of Siemens ProductCERT SSA-330084 advisory

Legal Notice and Terms of Use

Siemens SIMOVE Fleetmanager and SIPLANT

CISA General CVE-2026-67367

πŸ“… Tue, 22 Sep 26 12:00:00 +0000

View CSAF

Summary

SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope. Siemens has released new versions for the affected products and recommends to update to the latest versions.

The following versions of Siemens SIMOVE Fleetmanager and SIPLANT are affected:

CVSS Vendor Equipment Vulnerabilities
v3 8.6 Siemens Siemens SIMOVE Fleetmanager and SIPLANT Relative Path Traversal

Background


Vulnerabilities

Expand All +

CVE-2026-67367

Affected devices do not properly validate and neutralize directory traversal sequences in the file-serving endpoint of the embedded HTTP server. This could allow an unauthenticated remote attacker to read arbitrary files from the underlying operating system without any credentials, potentially exposing sensitive data such as credential stores, private keys, and configuration secrets.

View CVE Details


Affected Products

Siemens SIMOVE Fleetmanager and SIPLANT
Vendor:
Siemens
Product Version:
SIMOVE Fleetmanager V3.1 < V3.1.13, SIMOVE Fleetmanager V3.2 < V3.2.4, SIMOVE Fleetmanager V3.3 < V3.3.2, SIMOVE Fleetmanager V4.0 < V4.0.1, SIPLANT V1.7, SIPLANT V2.2, SIPLANT V3.0, SIPLANT V3.1 < V3.1.4
Product Status:
known_affected
Remediations

Mitigation
Configure appropriate user management by restricting services' access rights to project files.

Mitigation
Restrict network access to affected devices.

Vendor fix
Update to V3.1.13 or later version
https://support.industry.siemens.com/cs/ww/en/view/109813191/

Vendor fix
Update to V3.1.4 or later version Contact customer support siplant-support.de@siemens.com

Vendor fix
Update to V3.2.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109813191/

Vendor fix
Update to V3.3.2 or later version
https://support.industry.siemens.com/cs/ww/en/view/109813191/

Vendor fix
Update to V4.0.1 or later version
https://support.industry.siemens.com/cs/ww/en/view/110004946/

Vendor fix
Contact customer support siplant-support.de@siemens.com

Mitigation
For more information see the associated Siemens security advisory SSA-517424: Path Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT - CSAF Version, SSA-517424: Path Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT - HTML Version.

Relevant CWE: CWE-23 Relative Path Traversal


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.6 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Acknowledgments


General Recommendations

As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity 


Additional Resources

For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories 


Terms of Use

The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.


Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.


Advisory Conversion Disclaimer

This ICSA is a verbatim republication of Siemens ProductCERT SSA-517424 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.

Revision History

Date Revision Summary
2026-09-08 1 Publication Date
2026-09-22 2 Initial CISA Republication of Siemens ProductCERT SSA-517424 advisory

Legal Notice and Terms of Use

Siemens Siveillance Control

CISA General CVE-2026-50093

πŸ“… Tue, 22 Sep 26 12:00:00 +0000

View CSAF

Summary

A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server. Siemens has released patches and updates for Siveillance OIS to apply to the products that incorporate the OIS service, and recommends to update to the latest versions.

The following versions of Siemens Siveillance Control are affected:

CVSS Vendor Equipment Vulnerabilities
v3 9 Siemens Siemens Siveillance Control Unrestricted Upload of File with Dangerous Type

Background


Vulnerabilities

Expand All +

CVE-2026-50093

A vulnerability in the OIS web module allows an attacker to upload arbitrary files to the server. Successful exploitation of this vulnerability could allow an attacker to gain root access on the host system, potentially leading to a full compromise of the affected OIS environment.

View CVE Details


Affected Products

Siemens Siveillance Control
Vendor:
Siemens
Product Version:
Siveillance Control Pro V3.0 < V3.0.12.2173, Siveillance Control Pro V4.0 < V4.0.9.2178, Siveillance Control V3.0 < V3.0.22.2177, Siveillance Control V4.0 < V4.0.11.2177
Product Status:
known_affected
Remediations

Vendor fix
Update to V3.0.12.2173 or later version
https://support.industry.siemens.com/cs/ww/en/view/110004860/

Vendor fix
Update to V3.0.22.2177 or later version
https://support.industry.siemens.com/cs/ww/en/view/110004859/

Vendor fix
Update to V4.0.11.2177 or later version
https://support.industry.siemens.com/cs/ww/en/view/110004859/

Vendor fix
Update to V4.0.9.2178 or later version
https://support.industry.siemens.com/cs/ww/en/view/110004860/

Vendor fix
For more information see the associated Siemens security advisory SSA-254516: Arbitrary File Upload in OIS Web Module - CSAF Version, SSA-254516: Arbitrary File Upload in OIS Web Module - HTML Version.

Relevant CWE: CWE-434 Unrestricted Upload of File with Dangerous Type


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 9 CRITICAL CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Acknowledgments


General Recommendations

As a general security measure Siemens strongly recommends to protect network access to affected products with appropriate mechanisms. It is advised to follow recommended security practices in order to run the devices in a protected IT environment.


Additional Resources

For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories 


Terms of Use

The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.


Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.


Advisory Conversion Disclaimer

This ICSA is a verbatim republication of Siemens ProductCERT SSA-254516 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.

Revision History

Date Revision Summary
2026-09-08 1 Publication Date
2026-09-22 2 Initial CISA Republication of Siemens ProductCERT SSA-254516 advisory

Legal Notice and Terms of Use

lwIP TCP/IP Stack MQTT Client Application

CISA General CVE-2026-87121

πŸ“… Tue, 22 Sep 26 12:00:00 +0000

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to gain full code execution on the device.

The following versions of lwIP TCP/IP Stack MQTT Client Application are affected:

CVSS Vendor Equipment Vulnerabilities
v3 9.8 lwIP lwIP TCP/IP Stack MQTT Client Application Out-of-bounds Write

Background


Vulnerabilities

Expand All +

CVE-2026-87121

The affected product is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.

View CVE Details


Affected Products

lwIP TCP/IP Stack MQTT Client Application
Vendor:
lwIP
Product Version:
lwIP MQTT Client Application: >=2.0.1|<=2.2.1
Product Status:
known_affected
Remediations

Mitigation
Users of lwIP are encouraged to update their version of lwIP using the repository found at https://savannah.nongnu.org/projects/lwip. The commit identifier that contains the fix is f89407ea711879c04d91c92b35d67be78bbaf0f1.
 

Relevant CWE: CWE-787 Out-of-bounds Write


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Acknowledgments


Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

CISA also recommends users take the following measures to protect themselves from social engineering attacks:

No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.


Revision History

Date Revision Summary
2026-09-22 1 Initial Publication

Legal Notice and Terms of Use

CISA Adds One Known Exploited Vulnerability to Catalog

CISA General CVE-2026-7273

πŸ“… Mon, 21 Sep 26 12:00:00 +0000

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. 

Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. 

While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria

Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. 

CISA Adds One Known Exploited Vulnerability to Catalog

CISA General CVE-2025-39682

πŸ“… Fri, 18 Sep 26 12:00:00 +0000

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.

Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.

While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.

Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA General CVE-2025-39964 CVE-2026-53266

πŸ“… Fri, 18 Sep 26 12:00:00 +0000

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. 

Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. 

While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria

Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. 

Schneider Electric Modicon M340 Controller and Communication Modules

CISA General CVE-2025-6625

πŸ“… Thu, 17 Sep 26 12:00:00 +0000

View CSAF

Summary

Schneider Electric is aware of a vulnerability in its Modicon M340 https://www.se.com/ww/en/product-range/1468-modicon-m340-pac/, BMXNOR0200H https://www.se.com/us/en/product/BMXNOR0200H/communication-module-modicon-m340-iec-608705101-104-dnp3-for-severe-environments/: Modicon M340 X80 Ethernet Communication Modules, BMXNGD0100 https://www.se.com/us/en/product/BMXNGD0100/communication-module-modicon-m580-global-data-service/: M580 Global Data module, BMXNOC0401 https://www.se.com/us/en/product/BMXNOC0401/network-module-modicon-m340-ethernet-ip-and-modbus-tcp-4-x-rj45/?pageType=product&sourceId=BMXNOC0401: Modicon M340 X80 Ethernet Communication modules, BMXNOE0100 https://www.se.com/ww/en/product/BMXNOE0100/network-module-modicon-m340-modbus-tcp-1-x-rj45-flash-memory-card/?pageType=product&sourceId=BMXNOE0100: Modbus/TCP Ethernet Modicon M340 module, BMXNOE0110 https://www.se.com/ww/en/product/BMXNOE0110/ethernet-tcp-ip-network-module-modicon-m340-automation-platform-flash-memory-card-internal-ram-16-mb-1-x-rj45-10-100/: Modbus/TCP Ethernet Modicon M340 FactoryCast module product(s). Failure to apply the fix provided below may risk Denial Of Service attack, which could result in the unavailability of the devices.

The following versions of Schneider Electric Modicon M340 Controller and Communication Modules are affected:

CVSS Vendor Equipment Vulnerabilities
v3 7.5 Schneider Electric Schneider Electric Modicon M340 Controller and Communication Modules Improper Input Validation

Background


Vulnerabilities

Expand All +

CVE-2025-6625

CWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific crafted FTP command is sent to the device.

View CVE Details


Affected Products

Schneider Electric Modicon M340 Controller and Communication Modules
Vendor:
Schneider Electric
Product Version:
Ethernet / Serial RTU Module All versions, M580 Global Data module All versions, Modicon M340 X80 Ethernet Communication modules All versions, Modbus/TCP Ethernet Modicon M340 module Versions prior to 3.60, Modbus/TCP Ethernet Modicon M340 FactoryCast module Versions prior to 6.80
Product Status:
fixed, known_affected
Remediations

Vendor fix
Version 3.60 of BMXNOE0100 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product/BMXNOE0100/network-module-modicon-m340-modbus-tcp-1-x-rj45-flash-memory-card/ 

Reboot is needed to complete the firmware upgrade
 

Vendor fix
Version 6.80 of BMXNOE0110 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product/BMXNOE0110/ethernet-tcp-ip-network-module-modicon-m340-automation-platform-flash-memory-card-internal-ram-16-mb-1-x-rj45-10-100/ 

Reboot is needed to complete the firmware upgrade
 

Vendor fix
Version SV3.70 of Modicon M340 includes a fix for this vulnerability and is available for download here: 
https://www.se.com/ww/en/product-range/1468-modicon-m340/#software-and-firmware

Vendor fix
Version SV1.7 IR27 of BMXNOR0200H includes a fix for this vulnerability and is available for download here: 
https://www.se.com/ww/en/product/BMXNOR0200H/ethernet-serial-rtu-module-2-x-rj45/

Mitigation
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: 

  • FTP service is disabled by default.
  • Ensure to disable FTP service when not in use.
  • Setup network segmentation and implement a firewall to block all unauthorized access to ports 21/FTP.
  • Use VPN (Virtual Private Networks) tunnels if remote access is required.

Mitigation
Schneider Electric is establishing a remediation plan for all future versions of:

  • Modicon M340
  • BMXNOR0200H
  • BMXNGD0100
  • BMXNOC401 

    Schneider Electric will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit: 

  • FTP service is disabled by default.
  • Ensure to disable FTP service when not in use.
  • Setup network segmentation and implement a firewall to block all unauthorized access to ports 21/FTP.
  • Use VPN (Virtual Private Networks) tunnels if remote access is required.

Mitigation

For more information see the associated Schneider Electric security advisory Modicon M340 Controller and Communication Modules - SEVD-2025-224-05 CSAF Version, Modicon M340 Controller and Communication Modules - SEVD-2025-224-05 PDF Version.

Relevant CWE: CWE-20 Improper Input Validation


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Acknowledgments


General Security Recommendations

We strongly recommend the following industry cybersecurity best practices. 

For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.


For More Information

This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process. For further information related to cybersecurity in Schneider Electric's products, visit the company's cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp


LEGAL DISCLAIMER

THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS β€œNOTIFICATION”) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN β€œAS-IS” BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION


About Schneider Electric

Schneider's purpose is to create Impact by empowering all to make the most of our energy and resources, bridging progress and sustainability for all. We call this Life Is On. Our mission is to be the trusted partner in Sustainability and Efficiency. We are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart industries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep domain expertise, we provide integrated end-to-end lifecycle AI enabled Industrial IoT solutions with connected products, automation, software and services, delivering digital twins to enable profitable growth for our customers. We are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries to ensure proximity to our customers and stakeholders. We embrace diversity and inclusion in everything we do, guided by our meaningful purpose of a sustainable future for all. www.se.com


Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.


Advisory Conversion Disclaimer

This ICSA is a verbatim republication of Schneider Electric CPCERT SEVD-2025-224-05 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory.

Revision History

Date Revision Summary
2025-08-12 1 Original Release
2026-04-14 2 Remediation is available for Modicon M340
2026-08-11 3 Remediation is available for BMXNOR0200H.
2026-09-17 4 Initial CISA Republication of Schneider Electric CPCERT SEVD-2025-224-05 advisory

Legal Notice and Terms of Use

Schneider Electric NetBotz 5 750/755

CISA General CVE-2026-13336 CVE-2026-13337

πŸ“… Thu, 17 Sep 26 12:00:00 +0000

View CSAF

Summary

Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 – 750/755 products.The NetBotz 5 – 750/755 products are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capabilities. Failure to apply the remediation provided below may risk arbitrary or remote code execution over the local network, which could result in device manipulation and unauthorized data access.

The following versions of Schneider Electric NetBotz 5 750/755 are affected:

CVSS Vendor Equipment Vulnerabilities
v3 6.4 Schneider Electric Schneider Electric NetBotz 5 750/755 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), SQL Injection: Hibernate

Background


Vulnerabilities

Expand All +

CVE-2026-13336

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause execution of Linux Operating system commands when a system back up is restored that has been maliciously modified.

View CVE Details


Affected Products

Schneider Electric NetBotz 5 750/755
Vendor:
Schneider Electric
Product Version:
NetBotz 5 750 versions 5.5.2 and prior, NetBotz 5 755 Versions 5.5.2 and prior
Product Status:
fixed, known_affected
Remediations

Vendor fix
Version 5.6.0 of NetBotz 5 750/755 includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/product-range/61830-netbotz/#software-and-firmware Reboot needed: Upon install, the offer will automatically restart. A customer can validate a successful install by logging into the GUI and selecting the β€˜About NetBotz’ option. This will indicate the installed version.
 

For more information see the associated Schneider Electric security advisory Multiple Vulnerabilities on NetBotz 5 750/755 Products - SEVD-2026-223-02 CSAF Version, Multiple Vulnerabilities on NetBotz 5 750/755 Products - SEVD-2026-223-02 PDF Version.

Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 6.4 MEDIUM CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

CVE-2026-13337

CWE-564:SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is logged into the NetBotz via the web-service interface or web-ui.

View CVE Details


Affected Products

Schneider Electric NetBotz 5 750/755
Vendor:
Schneider Electric
Product Version:
NetBotz 5 750 versions 5.5.2 and prior, NetBotz 5 755 Versions 5.5.2 and prior
Product Status:
fixed, known_affected
Remediations

Vendor fix
Version 5.6.0 of NetBotz 5 750/755 includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/product-range/61830-netbotz/#software-and-firmware Reboot needed: Upon install, the offer will automatically restart. A customer can validate a successful install by logging into the GUI and selecting the β€˜About NetBotz’ option. This will indicate the installed version.
 

For more information see the associated Schneider Electric security advisory Multiple Vulnerabilities on NetBotz 5 750/755 Products - SEVD-2026-223-02 CSAF Version, Multiple Vulnerabilities on NetBotz 5 750/755 Products - SEVD-2026-223-02 PDF Version.

Relevant CWE: CWE-564 SQL Injection: Hibernate


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 4.6 MEDIUM CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Acknowledgments


General Security Recommendations

Schneider Electric strongly recommends the following industry cybersecurity best practices. 

For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.


For More Information

This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process. For further information related to cybersecurity in Schneider Electric’s products, visit the company’s cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp


LEGAL DISCLAIMER

THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS β€œNOTIFICATION”) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN β€œAS-IS” BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION


About Schneider Electric

Schneider's purpose is to create Impact by empowering all to make the most of our energy and resources, bridging progress and sustainability for all. We call this Life Is On. Our mission is to be the trusted partner in Sustainability and Efficiency. We are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart industries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep domain expertise, we provide integrated end-to-end lifecycle AI enabled Industrial IoT solutions with connected products, automation, software and services, delivering digital twins to enable profitable growth for our customers. We are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries to ensure proximity to our customers and stakeholders. We embrace diversity and inclusion in everything we do, guided by our meaningful purpose of a sustainable future for all. www.se.com


Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.


Advisory Conversion Disclaimer

This ICSA is a verbatim republication of Schneider Electric CPCERT SEVD-2026-223-02 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory.

Revision History

Date Revision Summary
2026-08-11 1 Original Release
2026-09-17 2 Initial CISA Republication of Schneider Electric CPCERT SEVD-2026-223-02 advisory

Legal Notice and Terms of Use

ISC Stormcast For Wednesday, September 23rd, 2026 https://isc.sans.edu/podcastdetail/10106, (Wed, Sep 23rd)

SANS ISC General

πŸ“… Wed, 23 Sep 2026 02:40:13 GMT

Macfinger ClickFix campaign, (Tue, Sep 22nd)

SANS ISC General

πŸ“… Wed, 23 Sep 2026 00:55:11 GMT

Introduction

The Truth about GET and HTTP Standards, (Tue, Sep 22nd)

SANS ISC General

πŸ“… Tue, 22 Sep 2026 19:06:15 GMT

On Friday, Xavier talked about the newly introduced HTTP Query method. This new method was introduced to allow "GET" requests that include a body. The main reason for this was that GET requests typically do not contain a body. But what if they do?

LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)

SANS ISC General

πŸ“… Tue, 22 Sep 2026 13:10:20 GMT

At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached requirements and provide a price quotation for a fiber optic system and appeared to impersonate an employee of a legitimate company.

ISC Stormcast For Tuesday, September 22nd, 2026 https://isc.sans.edu/podcastdetail/10104, (Tue, Sep 22nd)

SANS ISC General

πŸ“… Tue, 22 Sep 2026 03:50:10 GMT

TerminalFix: PNG Steganography, (Mon, Sep 21st)

SANS ISC General

πŸ“… Mon, 21 Sep 2026 10:33:53 GMT

Microsoft Security Research published an interesting blog post "TerminalFix campaign deploys a reverse tunnel through multistage intrusion" about a malware campaign. The aspect that I want to take a closer look at, is the fact that the threat actors used PNG files with steganography. I reached out to the researchers and they kindly shared the IOCs for the PNG files with me.

ISC Stormcast For Monday, September 21st, 2026 https://isc.sans.edu/podcastdetail/10102, (Mon, Sep 21st)

SANS ISC General

πŸ“… Mon, 21 Sep 2026 05:15:12 GMT

HTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th)

SANS ISC General

πŸ“… Sat, 19 Sep 2026 04:51:46 GMT

In June 2026 the IETF published RFC 10008[1], defining a new HTTP method: "QUERY". The HTTP protocol faced already by changes (HTTP/2, HTTP/3) but it's the first new standard HTTP verb since "PATCH" in 2010!

ISC Stormcast For Friday, September 18th, 2026 https://isc.sans.edu/podcastdetail/10100, (Fri, Sep 18th)

SANS ISC General

πŸ“… Fri, 18 Sep 2026 02:00:02 GMT

ISC Stormcast For Thursday, September 17th, 2026 https://isc.sans.edu/podcastdetail/10098, (Thu, Sep 17th)

SANS ISC General

πŸ“… Thu, 17 Sep 2026 02:00:03 GMT

Mitsubishi Electric GX Works3 and Motion Control Settings

US-CERT ICS General CVE-2026-15688

πŸ“… Thu, 17 Sep 26 12:00:00 +0000

View CSAF

Summary

Successful exploitation of this vulnerability could allow a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, destroy, or delete control programs.

The following versions of Mitsubishi Electric GX Works3 and Motion Control Settings are affected:

CVSS Vendor Equipment Vulnerabilities
v3 8.8 Mitsubishi Electric Mitsubishi Electric GX Works3 and Motion Control Settings Incorrect Implementation of Authentication Algorithm

Background


Vulnerabilities

Expand All +

CVE-2026-15688

Incorrect Implementation of Authentication Algorithm (CWE-303) vulnerability in the affected products allows a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, destroy, or delete control programs.

View CVE Details


Affected Products

Mitsubishi Electric GX Works3 and Motion Control Settings
Vendor:
Mitsubishi Electric
Product Version:
Mitsubishi Electric GX Works3: vers:all/*, Mitsubishi Electric Motion Control Settings (Software packaged with GX Works3): vers:all/*
Product Status:
known_affected
Remediations

Workaround
For customers using GX Works3, please download version 1.096A or later from the link https://www.mitsubishielectric.com/fa/download/software/detailsearch.page?mode=software&kisyu=/plceng&shiryoid=1000001411&lang=2&select=0&softid=1&infostatus=1_2_1&viewradio=0&viewstatus=&viewpos=, install it, and set the security version for projects to "2". Please refer to β€œ15.9 Preventing Illegal Access to/Falsification of Data (Security Version)” in β€œGX Works3 Operating Manual” for details. For more information about the workaround, refer to the Mitsubishi Electric security advisory available at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-007_en.pdf".
 

Workaround
For customers using Motion Control Settings (Software packaged with GX Works3), Please download version 1.070Y or later from the link "https://www.mitsubishielectric.com/fa/download/software/detailsearch.page?mode=software&kisyu=/ssc&shiryoid=1000000803&lang=2&select=0&softid=1&infostatus=1_8_1&viewradio=0&viewstatus=&viewpos=", install it, and set the security version for projects to "2". Please refer to β€œ12.5 Preventing Illegal Access to/Falsification of Data (Security Version)” in β€œMotion Control Setting Function Help” for details. For more information about the workaround, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-007_en.pdf".
 

Mitigation
For customers of the affected products, Mitsubishi Electric recommends using a computer with the affected product within a LAN and blocking remote logins from untrusted networks, hosts, and users, to minimize the risk of exploiting this vulnerability.

Mitigation
For customers of the affected products, Mitsubishi Electric recommends using a firewall, virtual private network (VPN), etc., to prevent unauthorized access, and allowing remote login only to trusted users when connecting a computer with the affected product to the Internet, to minimize the risk of exploiting this vulnerability.

Mitigation
For customers of the affected products, Mitsubishi Electric recommends preventing the user from clicking on web links contained in emails or other messages from untrusted sources, or from opening attachments in untrusted emails, to minimize the risk of exploiting this vulnerability.

Mitigation
For customers of the affected products, Mitsubishi Electric recommends installing antivirus software on a computer running the affected product, to minimize the risk of exploiting this vulnerability.

Mitigation
For customers of the affected products, Mitsubishi Electric recommends restricting physical access to a computer on which the affected product is installed, as well as to computers and network devices that can communicate with it, to minimize the risk of exploiting this vulnerability.

Relevant CWE: CWE-303 Incorrect Implementation of Authentication Algorithm


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
4.0 9.2 CRITICAL CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:H/SA:H

Acknowledgments


Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.


Advisory Conversion Disclaimer

This ICSA is a verbatim republication of Mitsubishi Electric 2026-007 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Mitsubishi Electric directly for any questions regarding this advisory.

Revision History

Date Revision Summary
2026-09-17 1 Initial Publication
2026-09-17 2 Initial CISA Republication of Mitsubishi Electric 2026-007 advisory

Legal Notice and Terms of Use

Bransys ELD

US-CERT ICS General CVE-2026-86520 CVE-2026-77960 CVE-2026-86689

πŸ“… Thu, 17 Sep 26 12:00:00 +0000

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware.

The following versions of Bransys ELD are affected:

CVSS Vendor Equipment Vulnerabilities
v3 7.5 Bransys Bransys ELD Use of Hard-coded Credentials, Cleartext Transmission of Sensitive Information

Background


Vulnerabilities

Expand All +

CVE-2026-86520

The affected product is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.

View CVE Details


Affected Products

Bransys ELD
Vendor:
Bransys
Product Version:
Bransys Android: <11.00.00, Bransys iOS: <1.1.54
Product Status:
known_affected
Remediations

Vendor fix
Bransys recommends that users update their system through the app store. Android users should be on version 11.00.00 or newer. iOS users should be on version 1.1.54 or newer.

Relevant CWE: CWE-798 Use of Hard-coded Credentials


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVE-2026-86689

The affected product is susceptible to cleartext transmission of sensitive information, which could allow an attacker to connect to the broker and read all data.

View CVE Details


Affected Products

Bransys ELD
Vendor:
Bransys
Product Version:
Bransys Android: <11.00.00, Bransys iOS: <1.1.54
Product Status:
known_affected
Remediations

Vendor fix
Bransys recommends that users update their system through the app store. Android users should be on version 11.00.00 or newer. iOS users should be on version 1.1.54 or newer.

Relevant CWE: CWE-319 Cleartext Transmission of Sensitive Information


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 5.9 MEDIUM CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
4.0 8.2 HIGH CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVE-2026-77960

The affected product ships with hardcoded FTP credentials which could allow an attacker to connect to the server and read data.

View CVE Details


Affected Products

Bransys ELD
Vendor:
Bransys
Product Version:
Bransys Android: <11.00.00, Bransys iOS: <1.1.54
Product Status:
known_affected
Remediations

Vendor fix
Bransys recommends that users update their system through the app store. Android users should be on version 11.00.00 or newer. iOS users should be on version 1.1.54 or newer.

Relevant CWE: CWE-798 Use of Hard-coded Credentials


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
4.0 6.9 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Acknowledgments


Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

CISA also recommends users take the following measures to protect themselves from social engineering attacks:

No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.


Revision History

Date Revision Summary
2026-09-17 1 Initial Publication

Legal Notice and Terms of Use

Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)

US-CERT ICS General CVE-2026-13584

πŸ“… Thu, 17 Sep 26 12:00:00 +0000

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly.

The following versions of Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A) are affected:

CVSS Vendor Equipment Vulnerabilities
v3 7.1 Mitsubishi Electric Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A) Improper Enforcement of Message Integrity During Transmission in a Communication Channel

Background


Vulnerabilities

Expand All +

CVE-2026-13584

Improper Enforcement of Message Integrity During Transmission in a Communication Channel (CWE-924) vulnerability exists in the CC-Link IE TSN communication protocol. This vulnerability could allow an attacker with access to the same network segment to tamper with communication data, such as control input and output values, by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly.

View CVE Details


Affected Products

Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)
Vendor:
Mitsubishi Electric
Product Version:
Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-16: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-64: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-128: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-256: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-N32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-P32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-N32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-P32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-N32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-P32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-8-N32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-8-P32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-16-N32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-16-P32: vers:all/*, Mitsubishi Electric Master/local module RJ71GN11-T2: vers:all/*, Mitsubishi Electric Master/local module RJ71GN11-SX: vers:all/*, Mitsubishi Electric Master/local module RJ71GN11-EIP: vers:all/*, Mitsubishi Electric Master/local module FX5-CCLGN-MS: vers:all/*, Mitsubishi Electric CC-Link IE TSN interface board NZ81GN11-SX: vers:all/*, Mitsubishi Electric CC-Link IE TSN interface board NZ81GN11-T2: vers:all/*, Mitsubishi Electric Motion module RD78G4: vers:all/*, Mitsubishi Electric Motion module RD78G8: vers:all/*, Mitsubishi Electric Motion module RD78G16: vers:all/*, Mitsubishi Electric Motion module RD78G64: vers:all/*, Mitsubishi Electric Motion module RD78GHV: vers:all/*, Mitsubishi Electric Motion module RD78GHW: vers:all/*, Mitsubishi Electric Motion module FX5-40SSC-G: vers:all/*, Mitsubishi Electric Motion module FX5-80SSC-G: vers:all/*, Mitsubishi Electric MELSEC iQ-L Series Motion Module LD78G4: vers:all/*, Mitsubishi Electric MELSEC iQ-L Series Motion Module LD78G16: vers:all/*, Mitsubishi Electric Motion Control Board MR-EM441G: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-32D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-32T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-32TE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-32DT: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-32DTE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-32D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-32T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-32TE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-32DT: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-32DTE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GNCF1-32D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GNCF1-32T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GNCE3-32D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GNCE3-32DT: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A4-16D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A4-16DE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A2-16T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A2-16TE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A42-16DT: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A42-16DTE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-16D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-16T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-16TE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-16D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-16T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-16TE: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8D: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8D-K: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8TE: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8TE-K: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-16DTE: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-16DTE-K: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNS12A2-14DT: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNS12A2-16DTE: vers:all/*, Mitsubishi Electric Analog-Digital converter module NZ2GN2S-60AD4: vers:all/*, Mitsubishi Electric Analog-Digital converter module NZ2GN2B-60AD4: vers:all/*, Mitsubishi Electric Digital-Analog converter module NZ2GN2S-60DA4: vers:all/*, Mitsubishi Electric Digital-Analog converter module NZ2GN2B-60DA4: vers:all/*, Mitsubishi Electric CC-Link IE TSN compatible coupler NZ2FT-GN: vers:all/*, Mitsubishi Electric FPGA module NZ2GN2S-D41P01: vers:all/*, Mitsubishi Electric FPGA module NZ2GN2S-D41D01: vers:all/*, Mitsubishi Electric FPGA module NZ2GN2S-D41PD02: vers:all/*, Mitsubishi Electric Tension meter LM7-1LG: vers:all/*, Mitsubishi Electric Tension meter LM7-2LG: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5W-G: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-HS: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-RJ: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-LL: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5D-G4 : vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-MD333G: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-JET MR-JET-G: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-JET MR-JET-G4-HS: vers:all/*, Mitsubishi Electric Liner Track System MTR-S series Linear track control module MTR-SCU00-4G: vers:all/*, Mitsubishi Electric Liner Track System MTR-S series Linear track control module MTR-SCU00-PG: vers:all/*, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A8NCG: vers:all/*, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A8NCG-S: vers:all/*, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A800-GN: vers:all/*, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-E800-E: vers:all/*, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-E800-SCE: vers:all/*, Mitsubishi Electric Industrial Robot CR800-D series controller Network Base Card 2F-DQ535-TSN: vers:all/*, Mitsubishi Electric CC-Link IE TSN expansion unit FCU8-EX569: vers:all/*, Mitsubishi Electric CC-Link IE TSN-CC-Link IE Field Network bridge module NZ2GN-GFB: vers:all/*, Mitsubishi Electric CC-Link IE TSN-AnyWireASLINK bridge module NZ2AW1GNAL: vers:all/*, Mitsubishi Electric Energy Measuring Unit CC-Link IE TSN Communication Unit EMU4-CM-TSN: vers:all/*, Mitsubishi Electric GOT3000 Series GT3715-FHCBD: vers:all/*, Mitsubishi Electric GOT3000 Series GT3712-WXCBD: vers:all/*, Mitsubishi Electric GOT3000 Series GT3715-XRBA: vers:all/*, Mitsubishi Electric GOT3000 Series GT3715-XRBD: vers:all/*, Mitsubishi Electric GOT3000 Series GT3712-XRBA: vers:all/*, Mitsubishi Electric GOT3000 Series GT3712-XRBD: vers:all/*, Mitsubishi Electric GOT3000 Series GT3710-XRBA: vers:all/*, Mitsubishi Electric GOT3000 Series GT3710-XRBD: vers:all/*, Mitsubishi Electric GOT3000 Series GT3708-XRBA: vers:all/*, Mitsubishi Electric GOT3000 Series GT3708-XRBD: vers:all/*, Mitsubishi Electric CC-Link IE TSN Communication Unit GT25-J71GN13-T2: vers:all/*, Mitsubishi Electric Motion Control Software SWM-G: vers:all/*, Mitsubishi Electric Motion Control Software SWM-G-N1: vers:all/*, Mitsubishi Electric CC-Link IE TSN Communication Software for Windows SW1DND-CCIETCT-M: vers:all/*, Mitsubishi Electric Analysis Support Software MELSOFT VIMA SW1DNN-VIMA-M: vers:all/*, Mitsubishi Electric Master/Local module Designated communication LSI DeviceKit NZ2KT-NPETNG51: vers:all/*, Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP620-60: vers:all/*, Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP620-300: vers:all/*, Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP621-90: vers:all/*, Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP621-720: vers:all/*, Mitsubishi Electric CC-Link IE TSN Master/Local module Designated communication LSI SDK SW1DNN-GN610SRC-M: vers:all/*, Mitsubishi Electric Remote station software development kit SW1DNC-GNSDK1S-M: vers:all/*, Mitsubishi Electric Remote station software development kit SW1DNC-GNSDK2S-M: vers:all/*
Product Status:
known_affected
Remediations

No fix planned
For customers using the affected products, please refer to Mitsubishi Electric's security advisory, "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-005_en.pdf" and take the measures described there.
 

Mitigation
For customers of the affected products, Mitsubishi Electric recommends restricting physical access to the affected products and the CC-Link IE TSN network to which the affected products are connected by taking measures such as the following: (a) managing access to and from the site where the affected products are installed, (b) locking the control panel in which the affected products and/or the network devices are installed, and (c) locking the Ethernet ports such as with port lock accessories, to minimize the risk of exploitation of this vulnerability.

Mitigation
For customers of the affected products, Mitsubishi Electric recommends using the affected products within a trusted network where communication with untrusted networks and hosts is blocked by a firewall or similar measures, to minimize the risk of exploitation of this vulnerability.

Mitigation
For customers of the affected products, Mitsubishi Electric recommends appropriately configuring credentials and access privileges for network devices installed at the boundary between trusted networks and external networks, to minimize the risk of exploitation of this vulnerability.

Relevant CWE: CWE-924 Improper Enforcement of Message Integrity During Transmission in a Communication Channel


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 7.1 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N

Acknowledgments


Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.


Advisory Conversion Disclaimer

This ICSA is a verbatim republication of Mitsubishi Electric 2026-005 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Mitsubishi Electric directly for any questions regarding this advisory.

Revision History

Date Revision Summary
2026-07-30 1 Initial Publication
2026-07-30 2 CISA Republication - Initial CISA Republication of Mitsubishi Electric 2026-005 advisory
2026-09-17 3 MXF100S-N32, MXF100S-P32, MXF100S-8-N32, MXF100S-8-P32, MXF100S-16-N32, MXF100S-16-P32, LD78G4, and LD78G16 have been added as affected products and MI2532-W, MI2332-W, and NZ2GACP610-60 have been removed from affected products.
2026-09-17 4 CISA Republication update based on Mitsubishi Electric 2026-005 advisory

Legal Notice and Terms of Use

Hitachi Energy FACTS Control Platform (FCP)

US-CERT ICS General CVE-2024-7941 CVE-2024-7940 CVE-2024-3982 CVE-2024-4872 CVE-2024-3980

πŸ“… Thu, 17 Sep 26 12:00:00 +0000

View CSAF

Summary

Hitachi Energy is aware of vulnerabilities that affect the FACTS Control systems with GWS component listed in this document. An attacker exploiting these vulnerabilities can cause impact on confidentiality, integrity and availability of the product. Following FACTS Control systems with GWS component deployed from year 2020 onwards are likely affected by the above vulnerabilities. Product deployments without GWS component are not affected. β€’ SVC Light (STATCOM) β€’ Fixed Series Capacitor β€’ Thyristor Controlled Series Capacitor β€’ Static Var Compensator β€’ Static Watt Compensator β€’ Hybrid Synchronous Condensers Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The affected FCP versions are only applicable if GWS component is present.

The following versions of Hitachi Energy FACTS Control Platform (FCP) are affected:

CVSS Vendor Equipment Vulnerabilities
v3 9.9 Hitachi Energy Hitachi Energy FACTS Control Platform (FCP) Improper Neutralization of Special Elements in Data Query Logic, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Authentication Bypass by Capture-replay, Missing Authentication for Critical Function, URL Redirection to Untrusted Site ('Open Redirect')

Background


Vulnerabilities

Expand All +

CVE-2024-4872

A vulnerability exists in the query validation of the FACTS Control system with GWS component. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability an attacker must have a valid credential.

View CVE Details


Affected Products

Hitachi Energy FACTS Control Platform (FCP)
Vendor:
Hitachi Energy
Product Version:
FACTS Control Platform (FCP) version 3.4.0, FACTS Control Platform (FCP) version 3.7.0, FACTS Control Platform (FCP) version 3.8.0, FACTS Control Platform (FCP) version 3.10.0, FACTS Control Platform (FCP) version 3.12.0, FACTS Control Platform (FCP) version 3.14.0, FACTS Control Platform (FCP) version 3.15.0, FACTS Control Platform (FCP) version 4.0.0, FACTS Control Platform (FCP) version 4.0.1, FACTS Control Platform (FCP) version 4.1.0, FACTS Control Platform (FCP) version 4.1.1
Product Status:
known_affected
Remediations

Mitigation
Follow general mitigation factors.

For more information see the associated Hitachi Energy security advisory 8DBD000229.

Relevant CWE: CWE-943 Improper Neutralization of Special Elements in Data Query Logic


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 9.9 CRITICAL CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVE-2024-3980

The FACTS Control system with GWS allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files or other files that are critical to the application.

View CVE Details


Affected Products

Hitachi Energy FACTS Control Platform (FCP)
Vendor:
Hitachi Energy
Product Version:
FACTS Control Platform (FCP) version 3.4.0, FACTS Control Platform (FCP) version 3.7.0, FACTS Control Platform (FCP) version 3.8.0, FACTS Control Platform (FCP) version 3.10.0, FACTS Control Platform (FCP) version 3.12.0, FACTS Control Platform (FCP) version 3.14.0, FACTS Control Platform (FCP) version 3.15.0, FACTS Control Platform (FCP) version 4.0.0, FACTS Control Platform (FCP) version 4.0.1, FACTS Control Platform (FCP) version 4.1.0, FACTS Control Platform (FCP) version 4.1.1
Product Status:
known_affected
Remediations

Mitigation
Follow general mitigation factors.

For more information see the associated Hitachi Energy security advisory 8DBD000229.

Relevant CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 9.9 CRITICAL CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVE-2024-3982

An attacker with local access to machine where FACTS Control system with GWS is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. Note: By default, the session logging level is not enabled and only users with administrator rights can enable it.

View CVE Details


Affected Products

Hitachi Energy FACTS Control Platform (FCP)
Vendor:
Hitachi Energy
Product Version:
FACTS Control Platform (FCP) version 3.10.0, FACTS Control Platform (FCP) version 3.12.0, FACTS Control Platform (FCP) version 3.14.0, FACTS Control Platform (FCP) version 3.15.0, FACTS Control Platform (FCP) version 4.0.0, FACTS Control Platform (FCP) version 4.0.1, FACTS Control Platform (FCP) version 4.1.0, FACTS Control Platform (FCP) version 4.1.1
Product Status:
known_affected
Remediations

Mitigation
Follow general mitigation factors.

For more information see the associated Hitachi Energy security advisory 8DBD000229.

Relevant CWE: CWE-294 Authentication Bypass by Capture-replay


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.2 HIGH CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CVE-2024-7940

The FACTS Control system with GWS product exposes a service that is intended for local only to all network interfaces without any authentication.

View CVE Details


Affected Products

Hitachi Energy FACTS Control Platform (FCP)
Vendor:
Hitachi Energy
Product Version:
FACTS Control Platform (FCP) version 3.14.0, FACTS Control Platform (FCP) version 3.15.0, FACTS Control Platform (FCP) version 4.0.0, FACTS Control Platform (FCP) version 4.0.1, FACTS Control Platform (FCP) version 4.1.0, FACTS Control Platform (FCP) version 4.1.1
Product Status:
known_affected
Remediations

Mitigation
Follow general mitigation factors.

For more information see the associated Hitachi Energy security advisory 8DBD000229.

Relevant CWE: CWE-306 Missing Authentication for Critical Function


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.3 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

CVE-2024-7941

A vulnerability exists in FACTS Control system with GWS where a HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.

View CVE Details


Affected Products

Hitachi Energy FACTS Control Platform (FCP)
Vendor:
Hitachi Energy
Product Version:
FACTS Control Platform (FCP) version 3.15.0, FACTS Control Platform (FCP) version 4.1.0, FACTS Control Platform (FCP) version 4.1.1
Product Status:
known_affected
Remediations

Mitigation
Follow general mitigation factors.

For more information see the associated Hitachi Energy security advisory 8DBD000229.

Relevant CWE: CWE-601 URL Redirection to Untrusted Site ('Open Redirect')


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 4.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Acknowledgments


Notice

The information in this document is subject to change without notice and should not be construed as a commitment by Hitachi Energy. Hitachi Energy provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall Hitachi Energy or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if Hitachi Energy or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from Hitachi Energy and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners.


Support

For additional information and support please contact your product provider or Hitachi Energy service organization. For contact information, see https://www.hitachienergy.com/contact-us/ for Hitachi Energy contact-centers.


General Mitigation Factors

Recommended security practices and firewall configurations can help protect a process control network from attacks that originate from outside the network. Such practices include that process control systems are physically protected from direct access by unauthorized personnel, have no direct connections to the Internet, and are separated from other networks by means of a firewall system that has a minimal number of ports exposed, and others that have to be evaluated case by case. Process control systems should not be used for Internet surfing, instant messaging, or receiving e-mails. Portable computers and removable storage media should be carefully scanned for viruses before they are connected to a control system. Proper password policies and processes should be followed. Additional information on Industrial Control Systems Cybersecurity Best Practices can be found in the Hitachi Energy β€œIndustrial Control Systems Cybersecurity Best Practices” Cybersecurity Notification. [1]


SSVC

SSVCv2/E:N/A:N/2026-07-24T09:43:32Z/


Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.


Advisory Conversion Disclaimer

This ICSA is a verbatim republication of Hitachi Energy PSIRT 8DBD000229 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Hitachi Energy PSIRT directly for any questions regarding this advisory.

Revision History

Date Revision Summary
2026-07-28 1 Initial public release
2026-09-17 2 Initial CISA Republication of Hitachi Energy PSIRT 8DBD000229 advisory

Legal Notice and Terms of Use

ABB Ability Edgenius

US-CERT ICS General CVE-2026-31431

πŸ“… Thu, 17 Sep 26 12:00:00 +0000

View CSAF

Summary

ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete control of the system

The following versions of ABB Ability Edgenius are affected:

CVSS Vendor Equipment Vulnerabilities
v3 7.8 ABB ABB Ability Edgenius Incorrect Resource Transfer Between Spheres

Background


Vulnerabilities

Expand All +

CVE-2026-31431

A Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. The issue originates in the Linux kernel’s cryptographic subsystem and impacts kernels used by most major Linux distributions released since 2017.Successful exploitation requires local code execution, however, in shared, containerized, or multi‑tenant environments this may increase the security risk.

View CVE Details


Affected Products

ABB Ability Edgenius
Vendor:
ABB
Product Version:
ABB Ability Edgenius >=3.2.0.0|<3.2.4.1 installed on ABB Ability Edgenius Gateway - bE100
Product Status:
fixed, known_affected
Remediations

Vendor fix
The problem is corrected in the following product versions: - Edgenius 3.2.4.1 ABB recommends that customers apply the update at earliest convenience.

Mitigation
Mitigating factors describe conditions and circumstances that make an attack that exploits the vulnerability difficult or less likely to succeed. Refer to section General security recommendations for further advise on how to keep your system secure. Recommended mitigation factors - Limit access to ssh or cockpit - By default, no additional lower privilege users are present on Edgenius installations.

Mitigation

For more information see the associated ABB PSIRT security advisory 7PAA024620 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .

Relevant CWE: CWE-669 Incorrect Resource Transfer Between Spheres


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Acknowledgments


Notice

The information in this document is subject to change without notice, and should not be construed as a commitment by ABB. ABB provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall ABB or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if ABB or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from ABB, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners.


Frequently Asked Questions

What causes the vulnerability? - A flaw was found in the Linux kernel's algif_aead cryptographic algorithm interface. An incorrect 'in-place operation' was introduced, where the source and destination data mappings were different. This could lead to unexpected behavior or data integrity issues during cryptographic operations, potentially impacting the reliability of encrypted communications. What is Edgenius? - ABB Abilityβ„’ Edgenius is an edge computing platform that - Connects to control systems, devices, and equipment - Collects and contextualizes operational data - Hosts applications that deliver real-time insights and AI-driven recommendations What might an attacker use the vulnerability to do? - Successful exploitation could enable a local user attacker to gain administrative control of the system node, execute arbitrary code, or cause the node to become unavailable. How could an attacker exploit the vulnerability? - An attacker could exploit this vulnerability after obtaining local access to the system. By invoking the Linux kernel’s affected cryptographic interface (algif_aead), the attacker can trigger incorrect memory handling in the kernel. This allows the attacker to escalate privileges from a normal user to full administrative (root) access on the affected system node Could the vulnerability be exploited remotely? - No, to exploit this vulnerability an attacker would need to have local access (physical access or through valid SSH credentials) to an affected system node. What does the update do? - The update resolves the issue by incorporating the security update of the Linux kernel. When this security advisory was issued, had this vulnerability been publicly disclosed? - Yes, this vulnerability has been publicly disclosed. When this security advisory was issued, had ABB received any reports that this vulnerability was being exploited? - No, ABB had not received any information indicating that this vulnerability had been exploited for Edgenius when this security advisory was originally issued.


Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.


Advisory Conversion Disclaimer

This ICSA is a verbatim republication of ABB PSIRT 7PAA024620 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory.

Revision History

Date Revision Summary
2026-06-25 1 Initial version.
2026-09-17 2 Initial CISA Republication of ABB PSIRT 7PAA024620 advisory

Legal Notice and Terms of Use

Phishing URL detected

OpenPhish Phishing

πŸ“… 2026-09-23T06:00:07.062317

Reported phishing site: https://135461223.site/pl/1997/4d0edf93-77fc-410f-9146-48767b992a51/758479/x

Phishing URL detected

OpenPhish Phishing

πŸ“… 2026-09-23T06:00:07.062336

Reported phishing site: https://135461223.site/1997/4d0edf93-77fc-410f-9146-48767b992a51/758479

Phishing URL detected

OpenPhish Phishing

πŸ“… 2026-09-23T06:00:07.062339

Reported phishing site: https://135461223.site/pl/1997/4d0edf93-77fc-410f-9146-48767b992a51/758479

Phishing URL detected

OpenPhish Phishing

πŸ“… 2026-09-23T06:00:07.062341

Reported phishing site: https://www.wbeuvvfx.com/

Phishing URL detected

OpenPhish Phishing

πŸ“… 2026-09-23T06:00:07.062343

Reported phishing site: https://www.wbeuvipfx.com/

Phishing URL detected

OpenPhish Phishing

πŸ“… 2026-09-23T06:00:07.062344

Reported phishing site: https://www.roblox.com.mu/users/9879227979/profile

Phishing URL detected

OpenPhish Phishing

πŸ“… 2026-09-23T06:00:07.062346

Reported phishing site: https://pelicanelectric.s3.us-east-2.amazonaws.com/pelicanelectric-cc.html

Phishing URL detected

OpenPhish Phishing

πŸ“… 2026-09-23T06:00:07.062348

Reported phishing site: http://artbrandesign.co.za/~botsaloprimary/tax/index.html

Phishing URL detected

OpenPhish Phishing

πŸ“… 2026-09-23T06:00:07.062349

Reported phishing site: http://victorinternationalschool.com.ng/~primeli3/admin

Phishing URL detected

OpenPhish Phishing

πŸ“… 2026-09-23T06:00:07.062351

Reported phishing site: http://mail.dementorsbusinesslinkgeneralmerchandise.com.ng/~primeli3/admin

Phishing URL detected

OpenPhish Phishing

πŸ“… 2026-09-23T06:00:07.062353

Reported phishing site: http://ywavworkhub.com/~primeli3/admin

Phishing URL detected

OpenPhish Phishing

πŸ“… 2026-09-23T06:00:07.062354

Reported phishing site: http://kingsandqueenswears.com/~primeli3/admin

Phishing URL detected

OpenPhish Phishing

πŸ“… 2026-09-23T06:00:07.062355

Reported phishing site: http://alliancepowergeneration.com/~primeli3/admin

Phishing URL detected

OpenPhish Phishing

πŸ“… 2026-09-23T06:00:07.062357

Reported phishing site: http://victoradedokun.com/~primeli3/admin

Phishing URL detected

OpenPhish Phishing

πŸ“… 2026-09-23T06:00:07.062358

Reported phishing site: http://theshepherd.com.ng/~primeli3/admin

CVE-2026-93952: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

CISA KEV Known Exploited Vulnerability CVE-2026-93952

πŸ“… 2026-09-22

Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

CVE-2026-94127: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

CISA KEV Known Exploited Vulnerability CVE-2026-94127

πŸ“… 2026-09-22

F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.

CVE-2026-93616: Check Point Multiple Products Path Traversal Vulnerability

CISA KEV Known Exploited Vulnerability CVE-2026-93616

πŸ“… 2026-09-22

Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.

CVE-2026-85102: Check Point Multiple Products Improper Certificate Validation Vulnerability

CISA KEV Known Exploited Vulnerability CVE-2026-85102

πŸ“… 2026-09-22

Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

CVE-2026-7273: Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

CISA KEV Known Exploited Vulnerability CVE-2026-7273

πŸ“… 2026-09-21

Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

CVE-2025-39964: Linux Kernel Race Condition Vulnerability

CISA KEV Known Exploited Vulnerability CVE-2025-39964

πŸ“… 2026-09-18

Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.

CVE-2026-53266: Linux Kernel Out-of-Bounds Write Vulnerability

CISA KEV Known Exploited Vulnerability CVE-2026-53266

πŸ“… 2026-09-18

Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

CVE-2025-39682: Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

CISA KEV Known Exploited Vulnerability CVE-2025-39682

πŸ“… 2026-09-18

Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

CVE-2026-58704: Google Pixel Improper Authorization Vulnerability

CISA KEV Known Exploited Vulnerability CVE-2026-58704

πŸ“… 2026-09-16

Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.

CVE-2026-76460: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

CISA KEV Known Exploited Vulnerability CVE-2026-76460

πŸ“… 2026-09-16

Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

CVE-2026-87886: Acronis Backup Incorrect Default Permissions Vulnerability

CISA KEV Known Exploited Vulnerability CVE-2026-87886

πŸ“… 2026-09-16

Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.

CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability

CISA KEV Known Exploited Vulnerability CVE-2026-76461

πŸ“… 2026-09-14

Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

CVE-2026-84869: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

CISA KEV Known Exploited Vulnerability CVE-2026-84869

πŸ“… 2026-09-11

ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation.

CVE-2026-42016: JFrog Artifactory Incorrect Authorization Vulnerability

CISA KEV Known Exploited Vulnerability CVE-2026-42016

πŸ“… 2026-09-11

JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

CVE-2026-42018: JFrog Artifactory Improper Authentication Vulnerability

CISA KEV Known Exploited Vulnerability CVE-2026-42018

πŸ“… 2026-09-11

JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.