❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 28 September 2026Security/Privacy

Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway

By: CISA
27 September 2026 at 08:00

CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778.Β 

CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.

Because updating Citrix NetScaler appliances can be complex and may require downtime, CISA is issuing this Alert to help organizations assess exposure, prioritize mitigation, and account for these vulnerabilities into their risk-management activities.Β 

Given the potential consequences of successful exploitation and the fact that malicious actors are exploiting at least some of these vulnerabilities, CISA urges users and administrators to review Citrix’s advisories. If possible, users are encouraged to check for indication of compromise prior to patching. Citrix has made indicators of compromise available through NetScaler Console and published additional guidance in their recent publication, Security Bulletin for CVE-2026-88771 through CVE-2026-88778, to support organizations in assessing potential compromise. Should your organization suspect compromise, it is important to preserve forensic evidence prior to applying updates, as updates may result in loss of forensic visibility.Β 

Disclaimer

The information in this report is being provided β€œas is” for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA.

CISA Adds Two Known Exploited Vulnerabilities to Catalog

By: CISA
27 September 2026 at 08:00

CISA has added two new vulnerabilities to itsΒ Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

  • CVE-2026-88771 Citrix NetScaler Improper Input Validation Vulnerability
  • CVE-2026-88772 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.

Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.

While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation ofΒ KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet theΒ specified criteria.

Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’sΒ KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.

Before yesterdaySecurity/Privacy

CISA Adds Two Known Exploited Vulnerabilities to Catalog

By: CISA
25 September 2026 at 08:00

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

  • CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability
  • CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.Β 

Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.Β 

While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.Β 

Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.

CISA Adds One Known Exploited Vulnerability to Catalog

By: CISA
25 September 2026 at 08:00

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.Β 

Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.Β 

While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.Β 

Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.Β 

Eufy Omni C20, Omni X10 Pro

By: CISA
24 September 2026 at 08:00

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to run system level commands or execute arbitrary code.

The following versions of Eufy Omni C20, Omni X10 Pro are affected:

  • Omni C20 <1.6.4 (CVE-2026-93289, CVE-2026-93290, CVE-2026-93291)
  • Omni X10 Pro <1.6.4 (CVE-2026-93289)
CVSS Vendor Equipment Vulnerabilities
v3 9.4 Eufy Eufy Omni C20, Omni X10 Pro Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Use of Hard-coded Credentials, Improper Certificate Validation

Background

  • Critical Infrastructure Sectors: Information Technology
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: China

Vulnerabilities

Expand All +

CVE-2026-93289

The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.

View CVE Details


Affected Products

Eufy Omni C20, Omni X10 Pro
Vendor:
Eufy
Product Version:
Eufy Omni C20: <1.6.4, Eufy Omni X10 Pro: <1.6.4
Product Status:
known_affected
Remediations

Mitigation
Eufy recommends users to upgrade to version 1.6.4 or later.

Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 7.5 HIGH CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
4.0 9 CRITICAL CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CVE-2026-93290

Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access information like mapping data.

View CVE Details


Affected Products

Eufy Omni C20, Omni X10 Pro
Vendor:
Eufy
Product Version:
Eufy Omni C20: <1.6.4
Product Status:
known_affected
Remediations

Mitigation
Eufy recommends users to upgrade to version 1.6.4 or later.

Relevant CWE: CWE-798 Use of Hard-coded Credentials


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 5.5 MEDIUM CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
4.0 6.8 MEDIUM CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVE-2026-93291

Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.

View CVE Details


Affected Products

Eufy Omni C20, Omni X10 Pro
Vendor:
Eufy
Product Version:
Eufy Omni C20: <1.6.4
Product Status:
known_affected
Remediations

Mitigation
Eufy recommends users to upgrade to version 1.6.4 or later.

Relevant CWE: CWE-295 Improper Certificate Validation


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 9.4 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Acknowledgments

  • Jared of Somerset Recon reported these vulnerabilities to CISA.

Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.

  • Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
  • Locate control system networks and remote devices behind firewalls and isolating them from business networks.
  • When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.


Revision History

  • Initial Release Date: 2026-09-24
Date Revision Summary
2026-09-24 1 Initial Publication

Legal Notice and Terms of Use

Botslab G980H Dashcams

By: CISA
24 September 2026 at 08:00

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication controls, gain unauthorized access to sensitive data and privileged device functionality, modify device configuration, disrupt device operation.

The following versions of Botslab G980H Dashcams are affected:

  • G980H dash cam series 30010_QHG980HN5294SysFW+ (CVE-2026-84399, CVE-2026-82566, CVE-2026-85496, CVE-2026-77967, CVE-2026-88761, CVE-2026-82716, CVE-2026-84403, CVE-2026-75558, CVE-2026-81630, CVE-2026-87118, CVE-2026-82708, CVE-2026-79959, CVE-2026-82585)
  • G980H dash cam series 58_QHG980HMCN5291SysFW+ (CVE-2026-84399, CVE-2026-82566, CVE-2026-85496, CVE-2026-77967, CVE-2026-88761, CVE-2026-88956, CVE-2026-82716, CVE-2026-84403, CVE-2026-75558, CVE-2026-81630, CVE-2026-87118, CVE-2026-82708, CVE-2026-82585)
CVSS Vendor Equipment Vulnerabilities
v3 8.8 Botslab Botslab G980H Dashcams Incorrect Authorization, Insufficient Session Expiration, Generation of Predictable Numbers or Identifiers, Authentication Bypass by Capture-replay, Use of Weak Credentials, Missing Authentication for Critical Function, Insertion of Sensitive Information into Log File, Use of Hard-coded Cryptographic Key, Insufficient Verification of Data Authenticity, Out-of-bounds Write, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Use of Hard-coded Credentials, Cleartext Transmission of Sensitive Information

Background

  • Critical Infrastructure Sectors: Transportation Systems
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: China

Vulnerabilities

Expand All +

CVE-2026-84399

The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established it, and subsequent privileged operations rely on possession of a valid session identifier without adequately validating the requesting client's authenticated context. An unauthenticated attacker with adjacent network access could potentially use valid session state associated with another client to access privileged functionality.

View CVE Details


Affected Products

Botslab G980H Dashcams
Vendor:
Botslab
Product Version:
Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+
Product Status:
known_affected
Remediations

Mitigation
Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:Β 
https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-863 Incorrect Authorization


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
4.0 8.7 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVE-2026-82566

The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions, a newly established connection can displace an existing client while previously established session state remains active until a separate expiration mechanism invalidates it. An unauthenticated attacker with adjacent network access could potentially take advantage of this residual authentication state to access functionality associated with another client's session.

View CVE Details


Affected Products

Botslab G980H Dashcams
Vendor:
Botslab
Product Version:
Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+
Product Status:
known_affected
Remediations

Mitigation
Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:Β 
https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-613 Insufficient Session Expiration


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
4.0 8.7 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVE-2026-85496

The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active session exists could potentially determine a valid session identifier and use it to bypass intended authorization controls.

View CVE Details


Affected Products

Botslab G980H Dashcams
Vendor:
Botslab
Product Version:
Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+
Product Status:
known_affected
Remediations

Mitigation
Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:Β 
https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-340 Generation of Predictable Numbers or Identifiers


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
4.0 7.7 HIGH CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVE-2026-77967

The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unauthenticated attacker with adjacent network access who captures a valid authentication value could replay it from another client to establish an authenticated session and access privileged device functionality.

View CVE Details


Affected Products

Botslab G980H Dashcams
Vendor:
Botslab
Product Version:
Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+
Product Status:
known_affected
Remediations

Mitigation
Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:Β 
https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-294 Authentication Bypass by Capture-replay


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.1 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
4.0 8.6 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

CVE-2026-88761

The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product. An unauthenticated attacker within WiFi range could potentially determine the remaining password characters through limited guessing and gain unauthorized access to the device network.

View CVE Details


Affected Products

Botslab G980H Dashcams
Vendor:
Botslab
Product Version:
Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+
Product Status:
known_affected
Remediations

Mitigation
Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:Β 
https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-1391 Use of Weak Credentials


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 5.3 MEDIUM CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
4.0 6 MEDIUM CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVE-2026-88956

The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface. The affected account does not require a password before granting access to a privileged system interface, and the interface also displays the device's WiFi password during startup. An unauthenticated attacker with physical access to the device could connect to the UART interface, obtain root privileges, and recover the WiFi password.

View CVE Details


Affected Products

Botslab G980H Dashcams
Vendor:
Botslab
Product Version:
Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+
Product Status:
known_affected
Remediations

Mitigation
Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:Β 
https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-306 Missing Authentication for Critical Function


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 6.8 MEDIUM CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
4.0 7 HIGH CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVE-2026-82716

The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process. These logs remain accessible on removable storage after the support operation has completed. An unauthenticated attacker with physical access to the storage media could retrieve the logs and obtain sensitive device information.

View CVE Details


Affected Products

Botslab G980H Dashcams
Vendor:
Botslab
Product Version:
Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+
Product Status:
known_affected
Remediations

Mitigation
Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:Β 
https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-532 Insertion of Sensitive Information into Log File


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 4.6 MEDIUM CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
4.0 5.1 MEDIUM CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVE-2026-84403

The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. An unauthenticated attacker within Bluetooth range could intercept or directly retrieve sensitive device information, including device identifiers, firmware information, and protected WiFi credentials.

View CVE Details


Affected Products

Botslab G980H Dashcams
Vendor:
Botslab
Product Version:
Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+
Product Status:
known_affected
Remediations

Mitigation
Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:Β 
https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-306 Missing Authentication for Critical Function


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 6.2 MEDIUM CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
4.0 6.9 MEDIUM CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVE-2026-75558

The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who obtains the protected credential and extracts the cryptographic material from the firmware could recover the WiFi password and gain unauthorized access to the device network.

View CVE Details


Affected Products

Botslab G980H Dashcams
Vendor:
Botslab
Product Version:
Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+
Product Status:
known_affected
Remediations

Mitigation
Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:Β 
https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-321 Use of Hard-coded Cryptographic Key


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 5.3 MEDIUM CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
4.0 6 MEDIUM CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVE-2026-81630

The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of a trusted cryptographic signature. A suitably positioned attacker who intercepts a firmware download, or an authenticated attacker who submits a crafted update, could install modified firmware and execute unauthorized code on the device.

View CVE Details


Affected Products

Botslab G980H Dashcams
Vendor:
Botslab
Product Version:
Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+
Product Status:
known_affected
Remediations

Mitigation
Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:Β 
https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-345 Insufficient Verification of Data Authenticity


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.1 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
4.0 9.2 CRITICAL CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVE-2026-87118

The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality. An authenticated attacker with adjacent network access could submit crafted command data that corrupts memory, potentially disrupting authentication state or causing the affected process to terminate and the device to restart, resulting in a temporary denial of service.

View CVE Details


Affected Products

Botslab G980H Dashcams
Vendor:
Botslab
Product Version:
Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+
Product Status:
known_affected
Remediations

Mitigation
Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:Β 
https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-787 Out-of-bounds Write


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 5.7 MEDIUM CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
4.0 6.9 MEDIUM CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVE-2026-82708

The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a crafted request to access files within the device's removable storage that were not intended to be directly accessible through the web server. Exposed files could include recordings, images, diagnostic logs, or firmware files.

View CVE Details


Affected Products

Botslab G980H Dashcams
Vendor:
Botslab
Product Version:
Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+
Product Status:
known_affected
Remediations

Mitigation
Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:Β 
https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVE-2026-79959

The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical access to the device could recover the credential and use it to obtain root access through the UART interface.

View CVE Details


Affected Products

Botslab G980H Dashcams
Vendor:
Botslab
Product Version:
Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+
Product Status:
known_affected
Remediations

Mitigation
Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:Β 
https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-798 Use of Hard-coded Credentials


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 6.8 MEDIUM CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
4.0 7 HIGH CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVE-2026-82585

The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network could obtain stored recordings, live video, location information, images, diagnostic logs, or other sensitive information exchanged between the device and its mobile application.

View CVE Details


Affected Products

Botslab G980H Dashcams
Vendor:
Botslab
Product Version:
Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+
Product Status:
known_affected
Remediations

Mitigation
Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:Β 
https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-319 Cleartext Transmission of Sensitive Information


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Acknowledgments

  • Julian of Software Secured reported these vulnerabilities to CISA.

Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.

  • Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
  • Locate control system networks and remote devices behind firewalls and isolating them from business networks.
  • When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

CISA also recommends users take the following measures to protect themselves from social engineering attacks:

  • Do not click web links or open attachments in unsolicited email messages.
  • Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.
  • Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.

No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.


Revision History

  • Initial Release Date: 2026-09-24
Date Revision Summary
2026-09-24 1 Initial Publication

Legal Notice and Terms of Use

CISA Adds Two Known Exploited Vulnerabilities to Catalog

By: CISA
24 September 2026 at 08:00

Β CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

  • CVE-2026-5430 WSO2 Multiple Products Path Traversal Vulnerability
  • CVE-2026-71362 Adobe Commerce and Magento Incorrect Authorization Vulnerability

These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.Β 

Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.Β 

While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.Β 

Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.Β 

Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators

By: CISA
23 September 2026 at 08:00

Introduction

The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA)β€”hereafter referred to as the β€œauthoring agencies”—have published this fact sheet to highlight considerations for critical infrastructure entities to reduce risk and minimize vulnerabilities when working with third-party industrial control system (ICS) integrators.

ICS is an umbrella term referring to integrated networks of hardware and software designed to monitor and automate physical processes, encompassing specialized control systems and devices, such as supervisory control and data acquisition (SCADA) systems and programmable logic controllers. Third-party integrators provide varying types of services for ICS, such as control system design, installation, operational data analysis, device support and service, and daily operational control.

Critical infrastructure owners and operators should maintain caution when granting third-party ICS integrators high levels of access or control over industrial processes, ensuring theΒ principle of least privilege (PoLP), is applied. PoLPΒ within OT environments lends itself to granting users, processes, and systemsΒ only the minimum access necessaryΒ to perform their assigned tasks, and no more. PoLP is designed to protect owners and operators. Not adopting principles such as PoLP could expose owners and operators to malicious cyber actors seeking to compromise critical infrastructure, possibly providing sensitive access to pathways that actors can exploit to cause disruptive and destructive effects to equipment and critical functions.Β 

Critical infrastructure owners and operators should action the recommendations in this fact sheet to work with integrators to ensure secure practices and frameworks are put in place to reduce the risk of malicious actors exploiting third-party accesses to compromise critical infrastructure operational environments.

Examples of Risk and Exploitation

Much like IT systems, using third-party ICS integrators in critical infrastructure may inadvertently introduce security issues to a customer environment by exposing systems and services not pre-configured to the customer’s security requirements. Critical infrastructure owners and operators that rely on third-party integrators for system design face supply chain risks if integrators and owners and operators do not collectively enforce clear requirements for the secure procurement and handling of system components. Furthermore, third-party integrators that operate and host data outside of the United States may pose additional risks, as they may be subject to different data storage and management laws that do not meet the security needs of U.S. critical infrastructure entities.

According to FBI technical analysis, between March and April 2025, malicious foreign cyber actors gained access to the network of a U.S. industrial automation solutions company that offered servicesβ€”such as system integration, engineering consulting, and SCADA programmingβ€”for industrial customers, including power utilities and transportation entities. While on the network, threat actors searched terms, including β€œcustomers” and β€œSCADA,” and created nine .zip files consisting of approximately 800 files for presumed exfiltration, including customer SCADA information, ICS device details, and other schematics. Malicious cyber actors could leverage the exfiltrated information to later conduct disruptive attacks against operational environments and disrupt critical services.

Recommendations to Assess Risk

Critical infrastructure owners and operators should make risk-informed decisions when considering introducing third-party integrators into their networks and operations, guided by a robust understanding of the organizational risks posed by providing sensitive access to their systems.

Organizations should routinely conduct risk assessments to evaluate contracts that involve access to industrial systems, to determine impacts to the organization’s data autonomy and process controls. Risk assessments should address hardware and software supply chain vulnerabilities introduced by integrator equipment, as well as the IT and OT security of these devices and their associated networks. When considering implementing foreign-owned integrators, critical infrastructure owners and operators should also include geopolitical considerations in their risk assessments, such as how the critical infrastructure entity may be directly or indirectly targeted based on the geopolitical climate.

Critical infrastructure owners and operators should consider the following questions in their risk assessments to safeguard the security of their operational systems when working with third-party ICS integrators:

What organizational data does the integrator store or have access to?

Critical infrastructure network designs, device specifications, logs, and other data can all be useful information for malicious cyber actors. When evaluating the risk of enabling integrators to store or access this data, consider the potential for a malicious cyber actor to access this data through the integrator’s network.

Where is the data stored?

If the integrator is foreign-owned, consider whether the utility data is stored within the United States or internationally. If data is stored internationally, the laws of that respective country may govern it and may apply even if the integrator is a U.S. subsidiary.

Does the integrator have remote access for operational support?

If the integrator has remote access to the organization’s ICS network, then there is a potential risk that a malicious cyber actor could gain access to the integrator’s network and pivot into the utility’s network to gain control of their systems. Consider the security of the organization’s remote connections when evaluating the risk these potential access points pose to the organization’s network.Β 

Can the organization operate independently if the integrator is compromised?

Having redundancies in place and the ability to recover the system and operate without the integrator, especially for operationally critical processes, can reduce risk in the event of integrator compromise. Operators should maintain secure, offline backups of all software required to operate equipment to facilitate system recovery.Β 

Recommendations to Reduce Risk

The authoring agencies recommend critical infrastructure owners and operators implement the following steps to reduce the risks associated with using third-party ICS integrators:

  • Include cybersecurity and supply chain cybersecurity in contracts and service agreements.Β When preparing service agreements, include requirements on areas such as:
    • Data storage locations, information protection agreements, and protection of ICS data and design documentation,
    • Remote access capabilities,
    • Basics of the integrator’s cybersecurity program,
    • Change management and patch management policies,
    • Actions taken to secure deployed components (e.g., changing default passwords, disabling unused ports),
    • Listing authorized personnel with access to systems, and
    • Processes that enable local engineering support when necessary, limiting required integrator intervention.
  • Evaluate devices with external internet exposure. Organizations should work with integrators to understand where devices are hosted and minimize exposure by disconnecting devices from the public-facing internet.
  • Monitor and log remote access. Ensure integrators access equipment using routes you are able to monitor. Use on-demand remote access if possible, so operators have to proactively allow remote access.
  • Request an inventory of all software and hardware supplied by the integrator, as well as documentation for how it connects to your infrastructure and how it will be updated.
  • Practice procedures and maintain capabilities for manual operations, keeping in mind, and accounting for, where third parties fit into the environment and recovery procedures.

Resources

Contact Information

The authoring agencies strongly urge critical infrastructure operators to report suspicious cyber activity to the following entities:

  • Report cyber activity to your local FBI field office or IC3, or contact CISA via CISA’s 24/7 Operations Center at contact@cisa.dhs.gov or 1-844-Say-CISA (1-844-729-2472).
  • Report any leads, threats, and suspected criminal activity by submitting an electronic tip, calling 1-800-CALL-FBI (1-800-225-5324), or contacting your local FBI field office.
    Note: This website cannot be used to report emergencies or immediate threat to life. For emergencies or immediate threat to life, please call 911.
  • If you are a law enforcement entity, use the unclassified information-sharing system eGuardian (accessible via the Law Enforcement Enterprise Portal) for reporting suspicious activity reports to the FBI. Note: If the information is urgent, then contact your local FBIΒ field office directly and follow up with an eGuardian report.

Disclaimer

CISA and the authoring agencies do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA and the authoring agencies.

Version History

September 23, 2026: Initial version.

Siemens Industrial Edge Management

By: CISA
22 September 2026 at 08:00

View CSAF

Summary

Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification. Siemens has released new versions for the affected products and recommends to update to the latest versions.

The following versions of Siemens Industrial Edge Management are affected:

  • Industrial Edge Management Cloud vers:all/* (CVE-2026-18963)
  • Industrial Edge Management Pro V1 vers:intdot/>=1.14.9|<1.15.20 (CVE-2026-18963)
  • Industrial Edge Management Pro V2 vers:intdot/>=2.2.0|<2.2.2 (CVE-2026-18963)
  • Industrial Edge Management Virtual vers:intdot/>=2.6.0|<2.9.1 (CVE-2026-18963)
CVSS Vendor Equipment Vulnerabilities
v3 9.1 Siemens Siemens Industrial Edge Management Weak Password Recovery Mechanism for Forgotten Password

Background

  • Critical Infrastructure Sectors: Critical Manufacturing
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: Germany

Vulnerabilities

Expand All +

CVE-2026-18963

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.

View CVE Details


Affected Products

Siemens Industrial Edge Management
Vendor:
Siemens
Product Version:
Industrial Edge Management Cloud, Industrial Edge Management Pro V1 >= V1.14.9 < V1.15.20, Industrial Edge Management Pro V2 >= V2.2.0 < V2.2.2, Industrial Edge Management Virtual >= V2.6.0 < V2.9.1
Product Status:
known_affected
Remediations

Mitigation
Block direct internet access to IEM Pro / IEM Virtual The most effective immediate measure is to block direct internet access to your IEM Pro or IEM V instance. This ensures that no external attacks can occur via this vulnerability.

Mitigation
Configure a Web Application Firewall (WAF) or Reverse Proxy If complete blocking of internet access is not immediately feasible, you can use a Web Application Firewall (WAF) or a Reverse Proxy to block the affected path. Please configure your WAF or Reverse Proxy to block the following path: /auth/realms/customer/login-actions/reset-credentials Please note that by blocking this path, the password reset functionality will be unavailable.

Mitigation
Deactivate Password Reset in Keycloak Realm Settings Deactivate the password reset functionality directly within the Keycloak realm settings. To do this, navigate to: Identity & access management > realm settings > Login > Forgot password > Off Please note that by deactivating this setting, the password reset functionality will be unavailable.

Vendor fix
Update to V1.15.20 or later version
https://iehub.eu1.edge.siemens.cloud/

Vendor fix
Update to V2.2.2 or later version
https://iehub.eu1.edge.siemens.cloud/

Vendor fix
Update to V2.9.1 or later version
https://iehub.eu1.edge.siemens.cloud/

Vendor fix
Vulnerability mitigated with firewall rules on 2026-08-26 and fixed with update on 2026-09-02; no user actions necessary.

Mitigation
For more information see the associated Siemens security advisory SSA-503852: Authentication Bypass Vulnerability in Industrial Edge Management - CSAF Version, SSA-503852: Authentication Bypass Vulnerability in Industrial Edge Management - HTML Version

Relevant CWE: CWE-640 Weak Password Recovery Mechanism for Forgotten Password


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 9.1 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Acknowledgments

  • Siemens ProductCERT reported this vulnerability to CISA.

General Recommendations

As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurityΒ 


Additional Resources

For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisoriesΒ 


Terms of Use

The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.


Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.

  • Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.
  • Locate control system networks and remote devices behind firewalls and isolate them from business networks.
  • When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.


Advisory Conversion Disclaimer

This ICSA is a verbatim republication of Siemens ProductCERT SSA-503852 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.

Revision History

  • Initial Release Date: 2026-09-08
Date Revision Summary
2026-09-08 1 Publication Date
2026-09-22 2 Initial CISA Republication of Siemens ProductCERT SSA-503852 advisory

Legal Notice and Terms of Use

OpenPLC Runtime v3

By: CISA
22 September 2026 at 08:00

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives.

The following versions of OpenPLC Runtime v3 are affected:

  • OpenPLC 3 (CVE-2026-88020)
CVSS Vendor Equipment Vulnerabilities
v3 6.1 Autonomy Logic OpenPLC Runtime v3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Background

  • Critical Infrastructure Sectors: Critical Manufacturing, Energy, Transportation Systems, Water and Wastewater Systems
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: United States

Vulnerabilities

Expand All +

CVE-2026-88020

The affected product is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding.

View CVE Details


Affected Products

OpenPLC Runtime v3
Vendor:
Autonomy Logic
Product Version:
Autonomy Logic OpenPLC: 3
Product Status:
known_affected
Remediations

Vendor fix
Autonomy Logic recommends users upgrade to OpenPLC v4 as OpenPLC v3 is end-of-life and is no longer receiving patches, bug fixes, or security updates.

Relevant CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
4.0 5.3 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

Acknowledgments

  • Rajivarnan R. and Shirshak of Secnora reported this vulnerability to CISA.

Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.

  • Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
  • Locate control system networks and remote devices behind firewalls and isolating them from business networks.
  • When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

CISA also recommends users take the following measures to protect themselves from social engineering attacks:

  • Do not click web links or open attachments in unsolicited email messages.
  • Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.
  • Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.

No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.


Revision History

  • Initial Release Date: 2026-09-22
Date Revision Summary
2026-09-22 1 Initial Publication

Legal Notice and Terms of Use

CISA Adds Four Known Exploited Vulnerabilities to Catalog

By: CISA
22 September 2026 at 08:00

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

  • CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability
  • CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability
  • CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
  • CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.Β 

Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.Β 

While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.Β 

Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.

lwIP (Lightweight IP)

By: CISA
22 September 2026 at 08:00

View CSAF

Summary

Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system.

The following versions of lwIP (Lightweight IP) are affected:

  • API >=2.0.1|<=2.2.1 (CVE-2026-91018)
CVSS Vendor Equipment Vulnerabilities
v3 8.8 lwIP lwIP (Lightweight IP) Double Free

Background

  • Critical Infrastructure Sectors: Chemical, Communications, Critical Manufacturing, Energy, Financial Services, Healthcare and Public Health, Transportation Systems, Water and Wastewater Systems
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: Sweden

Vulnerabilities

Expand All +

CVE-2026-91018

The affected product has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system.

View CVE Details


Affected Products

lwIP (Lightweight IP)
Vendor:
lwIP
Product Version:
lwIP API: >=2.0.1|<=2.2.1
Product Status:
known_affected
Remediations

Mitigation
Users of lwIP are encouraged to update their version of lwIP using the repository found at https://cgit.git.savannah.gnu.org/cgit/lwip.git. The commit identifier that contains the fix is f873b6295933e4149a2132adf3e9a2d2a676a5ec.
Β 

Relevant CWE: CWE-415 Double Free


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
4.0 8.7 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Acknowledgments

  • Eric Evenchick of Tetrel Security reported this vulnerability to CISA.

Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.

  • Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
  • Locate control system networks and remote devices behind firewalls and isolating them from business networks.
  • When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

CISA also recommends users take the following measures to protect themselves from social engineering attacks:

  • Do not click web links or open attachments in unsolicited email messages.
  • Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.
  • Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.

No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.


Revision History

  • Initial Release Date: 2026-09-22
Date Revision Summary
2026-09-22 1 Initial Publication

Legal Notice and Terms of Use

Siemens WTV676 and WTV776

By: CISA
22 September 2026 at 08:00

View CSAF

Summary

The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices. Siemens has released new versions for the affected products and recommends to update to the latest versions.

The following versions of Siemens WTV676 and WTV776 are affected:

  • WTV676-HB6035 Web Interface vers:intdot/<3.94 (CVE-2026-89207)
  • WTV776-HB6035 Web Interface vers:intdot/<4.17 (CVE-2026-89207)
CVSS Vendor Equipment Vulnerabilities
v3 6.5 Siemens Siemens WTV676 and WTV776 Improper Validation of Specified Type of Input

Background

  • Critical Infrastructure Sectors: Energy
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: Germany

Vulnerabilities

Expand All +

CVE-2026-89207

Affected devices do not properly validate input received from backend services. This could allow an unauthenticated remote attacker to force the device into protection mode, which results in losing remote connectivity functions (Web Access).

View CVE Details


Affected Products

Siemens WTV676 and WTV776
Vendor:
Siemens
Product Version:
WTV676-HB6035 Web Interface < V3.94, WTV776-HB6035 Web Interface < V4.17
Product Status:
known_affected
Remediations

Vendor fix
Update to V3.94 or later version
https://support.industry.siemens.com/cs/ww/en/view/109480838/

Vendor fix
Update to V4.17 or later version
https://support.industry.siemens.com/cs/ww/en/view/109480838/

Mitigation
For more information see the associated Siemens security advisory SSA-823812 in HTML and CSAF.

Relevant CWE: CWE-1287 Improper Validation of Specified Type of Input


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Acknowledgments

  • Siemens ProductCERT reported this vulnerability to CISA.

General Recommendations

As a general security measure Siemens strongly recommends protecting network access to affected products with appropriate mechanisms. It is advised to follow recommended security practices in order to run the devices in a protected IT environment.


Additional Resources

For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisoriesΒ 


Terms of Use

The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.


Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.

  • Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.
  • Locate control system networks and remote devices behind firewalls and isolate them from business networks.
  • When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.


Advisory Conversion Disclaimer

This ICSA is a verbatim republication of Siemens ProductCERT SSA-823812 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.

Revision History

  • Initial Release Date: 2026-09-16
Date Revision Summary
2026-09-16 1 Publication Date
2026-09-22 2 Initial CISA Republication of Siemens ProductCERT SSA-823812 advisory

Legal Notice and Terms of Use

Siemens SIPLUS and SIMATIC Products

By: CISA
22 September 2026 at 08:00

View CSAF

Summary

Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

The following versions of Siemens SIPLUS and SIMATIC Products are affected:

  • SIMATIC AX Runtime Core Linux Common Debian vers:all/* (CVE-2026-31431)
  • SIMATIC AX Runtime Core Linux Common Debian arm64 vers:all/* (CVE-2026-31431)
  • SIMATIC AX Runtime Core Linux Platform Container Common Debian Development vers:all/* (CVE-2026-31431)
  • SIMATIC AX Runtime Core Linux VMWare Development vers:all/* (CVE-2026-31431)
  • SIMATIC CN 4100 vers:intdot/<6.0 (CVE-2026-31431)
  • SIMATIC HMI MTP1000 Unified Basic (6AV2123-3KB32-0AW0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1000 Unified Comfort Panel (6AV2128-3KB06-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1000 Unified Comfort Panel hygienic (6AV2128-3KB40-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1000 Unified Comfort Panel hygienic neutral design (6AV2128-3KB70-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1000, Unified Comfort Panel neutral (6AV2128-3KB36-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1200 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3MB27-1BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1200 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3MB27-0BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1200 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3MB27-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1200 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3MB57-1BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3MB57-0BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3MB57-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1200 Unified Basic (6AV2123-3MB32-0AW0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1200 Unified Comfort Panel (6AV2128-3MB06-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1200 Unified Comfort Panel hygienic (6AV2128-3MB40-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1200 Unified Comfort Panel hygienic neutral design (6AV2128-3MB70-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1200 Unified Comfort Panel neutral design (6AV2128-3MB36-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1500 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3QB27-1BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1500 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3QB27-0BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1500 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3QB27-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1500 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3QB57-1BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1500 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3QB57-0BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1500 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3QB57-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1500 Unified Comfort Panel (6AV2128-3QB06-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1500 Unified Comfort Panel hygienic (6AV2128-3QB40-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1500 Unified Comfort Panel hygienic neutral design (6AV2128-3QB70-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1500 Unified Comfort Panel neutral design (6AV2128-3QB36-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1900 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3UB27-1BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1900 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3UB27-0BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1900 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3UB27-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1900 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3UB57-1BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1900 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3UB57-0BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1900 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3UB57-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1900 Unified Comfort Panel (6AV2128-3UB06-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1900 Unified Comfort Panel hygienic (6AV2128-3UB40-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1900 Unified Comfort Panel hygienic neutral design (6AV2128-3UB70-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP1900 Unified Comfort Panel neutral design (6AV2128-3UB36-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP2200 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3XB27-1BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP2200 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3XB27-0BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP2200 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3XB27-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP2200 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3XB57-1BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3XB57-0BX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3XB57-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP2200 Unified Comfort Hygienic (6AV2128-3XB40-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP2200 Unified Comfort Hygienic neutral design (6AV2128-3XB70-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP2200 Unified Comfort Panel (6AV2128-3XB06-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP2200 Unified Comfort Panel neutral design (6AV2128-3XB36-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP400 Unified Basic (6AV2123-3DB32-0AW0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP700 Unified Basic (6AV2123-3GB32-0AW0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP700Β Unified Comfort Panel (6AV2128-3GB06-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP700 Unified Comfort Panel hygienic neutral design (6AV2128-3GB40-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP700 Unified Comfort Panel hygienic neutral design (6AV2128-3GB70-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC HMI MTP700, Unified Comfort Panel neutral design (6AV2128-3GB36-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) vers:all/* (CVE-2026-31431)
  • SIMATIC IPC Industrial Edge Device OS (IED-OS) vers:all/* (CVE-2026-31431)
  • SIMATIC S7-1500 TM MFP (6ES7558-1AA00-0AB0) vers:all/* (CVE-2026-31431)
  • SIPLUS HMI MTP1000 Unified Basic (6AG1123-3KB32-2AW0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIPLUS HMI MTP1000 Unified Comfort (6AG1128-3KB06-4AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIPLUS HMI MTP1200 Unified Basic (6AG1123-3MB32-2AW0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIPLUS HMI MTP1200 Unified Comfort (6AG1128-3MB06-4AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIPLUS HMI MTP400 Unified Basic (6AG1123-3DB32-2AW0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIPLUS HMI MTP700 Unified Basic (6AG1123-3GB32-2AW0) vers:intdot/<21.0.2.1 (CVE-2026-31431)
  • SIPLUS HMI MTP700 Unified Comfort (6AG1128-3GB06-4AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431)
CVSS Vendor Equipment Vulnerabilities
v3 7.8 Siemens Siemens SIPLUS and SIMATIC Products Incorrect Resource Transfer Between Spheres

Background

  • Critical Infrastructure Sectors: Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, Commercial Facilities
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: Germany

Vulnerabilities

Expand All +

CVE-2026-31431

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

View CVE Details


Affected Products

Siemens SIPLUS and SIMATIC Products
Vendor:
Siemens
Product Version:
SIMATIC AX Runtime Core Linux Common Debian, SIMATIC HMI MTP1000, Unified Comfort Panel neutral (6AV2128-3KB36-0AX1) < V21.2.1, SIMATIC HMI MTP1200 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3MB27-1BX0) < V21.2.1, SIMATIC HMI MTP1200 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3MB27-0BX0) < V21.2.1, SIMATIC HMI MTP1200 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3MB27-0AX0) < V21.2.1, SIMATIC HMI MTP1200 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3MB57-1BX0) < V21.2.1, SIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3MB57-0BX0) < V21.2.1, SIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3MB57-0AX0) < V21.2.1, SIMATIC HMI MTP1200 Unified Basic (6AV2123-3MB32-0AW0) < V21.2.1, SIMATIC HMI MTP1200 Unified Comfort Panel (6AV2128-3MB06-0AX1) < V21.2.1, SIMATIC HMI MTP1200 Unified Comfort Panel hygienic (6AV2128-3MB40-0AX0) < V21.2.1, SIMATIC AX Runtime Core Linux Common Debian arm64, SIMATIC HMI MTP1200 Unified Comfort Panel hygienic neutral design (6AV2128-3MB70-0AX0) < V21.2.1, SIMATIC HMI MTP1200 Unified Comfort Panel neutral design (6AV2128-3MB36-0AX1) < V21.2.1, SIMATIC HMI MTP1500 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3QB27-1BX0) < V21.2.1, SIMATIC HMI MTP1500 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3QB27-0BX0) < V21.2.1, SIMATIC HMI MTP1500 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3QB27-0AX0) < V21.2.1, SIMATIC HMI MTP1500 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3QB57-1BX0) < V21.2.1, SIMATIC HMI MTP1500 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3QB57-0BX0) < V21.2.1, SIMATIC HMI MTP1500 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3QB57-0AX0) < V21.2.1, SIMATIC HMI MTP1500 Unified Comfort Panel (6AV2128-3QB06-0AX1) < V21.2.1, SIMATIC HMI MTP1500 Unified Comfort Panel hygienic (6AV2128-3QB40-0AX0) < V21.2.1, SIMATIC AX Runtime Core Linux Platform Container Common Debian Development, SIMATIC HMI MTP1500 Unified Comfort Panel hygienic neutral design (6AV2128-3QB70-0AX0) < V21.2.1, SIMATIC HMI MTP1500 Unified Comfort Panel neutral design (6AV2128-3QB36-0AX1) < V21.2.1, SIMATIC HMI MTP1900 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3UB27-1BX0) < V21.2.1, SIMATIC HMI MTP1900 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3UB27-0BX0) < V21.2.1, SIMATIC HMI MTP1900 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3UB27-0AX0) < V21.2.1, SIMATIC HMI MTP1900 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3UB57-1BX0) < V21.2.1, SIMATIC HMI MTP1900 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3UB57-0BX0) < V21.2.1, SIMATIC HMI MTP1900 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3UB57-0AX0) < V21.2.1, SIMATIC HMI MTP1900 Unified Comfort Panel (6AV2128-3UB06-0AX1) < V21.2.1, SIMATIC HMI MTP1900 Unified Comfort Panel hygienic (6AV2128-3UB40-0AX0) < V21.2.1, SIMATIC AX Runtime Core Linux VMWare Development, SIMATIC HMI MTP1900 Unified Comfort Panel hygienic neutral design (6AV2128-3UB70-0AX0) < V21.2.1, SIMATIC HMI MTP1900 Unified Comfort Panel neutral design (6AV2128-3UB36-0AX1) < V21.2.1, SIMATIC HMI MTP2200 Comfort Pro for stand (expandable, flange at the bottom) (6AV2128-3XB27-1BX0) < V21.2.1, SIMATIC HMI MTP2200 Comfort Pro for support arm (expandable, round tube) and extension unit (6AV2128-3XB27-0BX0) < V21.2.1, SIMATIC HMI MTP2200 Comfort Pro for support arm (not extendable, flange on top) (6AV2128-3XB27-0AX0) < V21.2.1, SIMATIC HMI MTP2200 Comfort Pro neutral design for stand (expandable, flange at the bottom) (6AV2128-3XB57-1BX0) < V21.2.1, SIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (expandable, round tube) and extension (6AV2128-3XB57-0BX0) < V21.2.1, SIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (not extendable, flange on top) (6AV2128-3XB57-0AX0) < V21.2.1, SIMATIC HMI MTP2200 Unified Comfort Hygienic (6AV2128-3XB40-0AX0) < V21.2.1, SIMATIC HMI MTP2200 Unified Comfort Hygienic neutral design (6AV2128-3XB70-0AX0) < V21.2.1, SIMATIC CN 4100 < V6.0, SIMATIC HMI MTP2200 Unified Comfort Panel (6AV2128-3XB06-0AX1) < V21.2.1, SIMATIC HMI MTP2200 Unified Comfort Panel neutral design (6AV2128-3XB36-0AX1) < V21.2.1, SIMATIC HMI MTP400 Unified Basic (6AV2123-3DB32-0AW0) < V21.2.1, SIMATIC HMI MTP700 Unified Basic (6AV2123-3GB32-0AW0) < V21.2.1, SIMATIC HMI MTP700Β Unified Comfort Panel (6AV2128-3GB06-0AX1) < V21.2.1, SIMATIC HMI MTP700 Unified Comfort Panel hygienic neutral design (6AV2128-3GB40-0AX0) < V21.2.1, SIMATIC HMI MTP700 Unified Comfort Panel hygienic neutral design (6AV2128-3GB70-0AX0) < V21.2.1, SIMATIC HMI MTP700, Unified Comfort Panel neutral design (6AV2128-3GB36-0AX1) < V21.2.1, SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2), SIMATIC IPC Industrial Edge Device OS (IED-OS), SIMATIC HMI MTP1000 Unified Basic (6AV2123-3KB32-0AW0) < V21.2.1, SIMATIC S7-1500 TM MFP (6ES7558-1AA00-0AB0), SIPLUS HMI MTP1000 Unified Basic (6AG1123-3KB32-2AW0) < V21.2.1, SIPLUS HMI MTP1000 Unified Comfort (6AG1128-3KB06-4AX1) < V21.2.1, SIPLUS HMI MTP1200 Unified Basic (6AG1123-3MB32-2AW0) < V21.2.1, SIPLUS HMI MTP1200 Unified Comfort (6AG1128-3MB06-4AX1) < V21.2.1, SIPLUS HMI MTP400 Unified Basic (6AG1123-3DB32-2AW0) < V21.2.1, SIPLUS HMI MTP700 Unified Basic (6AG1123-3GB32-2AW0) < V21.2.1, SIPLUS HMI MTP700 Unified Comfort (6AG1128-3GB06-4AX1) < V21.2.1, SIMATIC HMI MTP1000 Unified Comfort Panel (6AV2128-3KB06-0AX1) < V21.2.1, SIMATIC HMI MTP1000 Unified Comfort Panel hygienic (6AV2128-3KB40-0AX0) < V21.2.1, SIMATIC HMI MTP1000 Unified Comfort Panel hygienic neutral design (6AV2128-3KB70-0AX0) < V21.2.1
Product Status:
known_affected
Remediations

Mitigation
Limit access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only.

Mitigation
Only build and run applications from trusted sources.

None available
Currently no fix is available

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825897/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825897/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825897/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825897/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 SP2 Update 1 or later version TODO: download link missing

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V21 Update 2 SR1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109825605/

Vendor fix
Update to V6.0 or later version
https://support.industry.siemens.com/cs/ww/en/view/109814144/

Vendor fix
For more information see the associated Siemens security advisory SSA-328642: "Copy Fail" Vulnerability in Multiple Industrial Products - CSAF Version, SSA-328642: "Copy Fail" Vulnerability in Multiple Industrial Products - HTML Version

Relevant CWE: CWE-669 Incorrect Resource Transfer Between Spheres


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Acknowledgments

  • Siemens ProductCERT reported this vulnerability to CISA.

General Recommendations

As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurityΒ 


Additional Resources

For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisoriesΒ 


Terms of Use

The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.


Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.

  • Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.
  • Locate control system networks and remote devices behind firewalls and isolate them from business networks.
  • When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.


Advisory Conversion Disclaimer

This ICSA is a verbatim republication of Siemens ProductCERT SSA-328642 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.

Revision History

  • Initial Release Date: 2026-09-08
Date Revision Summary
2026-09-08 1 Publication Date
2026-09-22 2 Initial CISA Republication of Siemens ProductCERT SSA-328642 advisory

Legal Notice and Terms of Use

Siemens Desigo CC family

By: CISA
22 September 2026 at 08:00

View CSAF

Summary

A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization.

The following versions of Siemens Desigo CC family are affected:

  • Desigo CC family V6 vers:all/* (CVE-2026-34223)
  • Desigo CC family V7 vers:all/* (CVE-2026-34223)
CVSS Vendor Equipment Vulnerabilities
v3 8.2 Siemens Siemens Desigo CC family Improper Control of Generation of Code ('Code Injection')

Background

  • Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: Germany

Vulnerabilities

Expand All +

CVE-2026-34223

The affected application is vulnerable to Client Code Execution (CCE) due to insufficient input validation when handling scripts embedded within user-defined graphics documents. Specifically, when the script within a graphics document is designed or modified by an attacker to include malicious commands. When a user opens a compromised graphics document, the embedded script is executed on the client application instance, allowing an attacker to write arbitrary files to the client's operating system. Successful exploitation requires an attacker to craft a malicious graphics document and entice a user with sufficient privileges to display it. This could lead to compromise of the client operating system and potential lateral movement within the organization.

View CVE Details


Affected Products

Siemens Desigo CC family
Vendor:
Siemens
Product Version:
Desigo CC family V6, Desigo CC family V7
Product Status:
known_affected
Remediations

Mitigation
Evaluate authorization policy for Graphics application following Least Privilege principle, so only required users have access to the configuration.

None available
Currently no fix is available.

Mitigation
For more information see the associated Siemens security advisory SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family - CSAF Version, SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family - HTML Version.

Relevant CWE: CWE-94 Improper Control of Generation of Code ('Code Injection')


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.2 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Acknowledgments

  • Michelin CERT reported this vulnerability to Siemens.

General Recommendations

As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurityΒ 


Additional Resources

For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisoriesΒ 


Terms of Use

The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.


Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.

  • Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.
  • Locate control system networks and remote devices behind firewalls and isolate them from business networks.
  • When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.


Advisory Conversion Disclaimer

This ICSA is a verbatim republication of Siemens ProductCERT SSA-330084 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.

Revision History

  • Initial Release Date: 2026-09-08
Date Revision Summary
2026-09-08 1 Publication Date
2026-09-22 2 Initial CISA Republication of Siemens ProductCERT SSA-330084 advisory

Legal Notice and Terms of Use

Siemens SIMOVE Fleetmanager and SIPLANT

By: CISA
22 September 2026 at 08:00

View CSAF

Summary

SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope. Siemens has released new versions for the affected products and recommends to update to the latest versions.

The following versions of Siemens SIMOVE Fleetmanager and SIPLANT are affected:

  • SIMOVE Fleetmanager V3.1 vers:intdot/<3.1.13 (CVE-2026-67367)
  • SIMOVE Fleetmanager V3.2 vers:intdot/<3.2.4 (CVE-2026-67367)
  • SIMOVE Fleetmanager V3.3 vers:intdot/<3.3.2 (CVE-2026-67367)
  • SIMOVE Fleetmanager V4.0 vers:intdot/<4.0.1 (CVE-2026-67367)
  • SIPLANT V1.7 vers:all/* (CVE-2026-67367)
  • SIPLANT V2.2 vers:all/* (CVE-2026-67367)
  • SIPLANT V3.0 vers:all/* (CVE-2026-67367)
  • SIPLANT V3.1 vers:intdot/<3.1.4 (CVE-2026-67367)
CVSS Vendor Equipment Vulnerabilities
v3 8.6 Siemens Siemens SIMOVE Fleetmanager and SIPLANT Relative Path Traversal

Background

  • Critical Infrastructure Sectors: Critical Manufacturing
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: Germany

Vulnerabilities

Expand All +

CVE-2026-67367

Affected devices do not properly validate and neutralize directory traversal sequences in the file-serving endpoint of the embedded HTTP server. This could allow an unauthenticated remote attacker to read arbitrary files from the underlying operating system without any credentials, potentially exposing sensitive data such as credential stores, private keys, and configuration secrets.

View CVE Details


Affected Products

Siemens SIMOVE Fleetmanager and SIPLANT
Vendor:
Siemens
Product Version:
SIMOVE Fleetmanager V3.1 < V3.1.13, SIMOVE Fleetmanager V3.2 < V3.2.4, SIMOVE Fleetmanager V3.3 < V3.3.2, SIMOVE Fleetmanager V4.0 < V4.0.1, SIPLANT V1.7, SIPLANT V2.2, SIPLANT V3.0, SIPLANT V3.1 < V3.1.4
Product Status:
known_affected
Remediations

Mitigation
Configure appropriate user management by restricting services' access rights to project files.

Mitigation
Restrict network access to affected devices.

Vendor fix
Update to V3.1.13 or later version
https://support.industry.siemens.com/cs/ww/en/view/109813191/

Vendor fix
Update to V3.1.4 or later version Contact customer support siplant-support.de@siemens.com

Vendor fix
Update to V3.2.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109813191/

Vendor fix
Update to V3.3.2 or later version
https://support.industry.siemens.com/cs/ww/en/view/109813191/

Vendor fix
Update to V4.0.1 or later version
https://support.industry.siemens.com/cs/ww/en/view/110004946/

Vendor fix
Contact customer support siplant-support.de@siemens.com

Mitigation
For more information see the associated Siemens security advisory SSA-517424: Path Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT - CSAF Version, SSA-517424: Path Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT - HTML Version.

Relevant CWE: CWE-23 Relative Path Traversal


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.6 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Acknowledgments

  • Siemens ProductCERT reported this vulnerability to CISA.

General Recommendations

As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurityΒ 


Additional Resources

For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisoriesΒ 


Terms of Use

The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.


Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.

  • Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.
  • Locate control system networks and remote devices behind firewalls and isolate them from business networks.
  • When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.


Advisory Conversion Disclaimer

This ICSA is a verbatim republication of Siemens ProductCERT SSA-517424 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.

Revision History

  • Initial Release Date: 2026-09-08
Date Revision Summary
2026-09-08 1 Publication Date
2026-09-22 2 Initial CISA Republication of Siemens ProductCERT SSA-517424 advisory

Legal Notice and Terms of Use

Siemens Siveillance Control

By: CISA
22 September 2026 at 08:00

View CSAF

Summary

A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server. Siemens has released patches and updates for Siveillance OIS to apply to the products that incorporate the OIS service, and recommends to update to the latest versions.

The following versions of Siemens Siveillance Control are affected:

  • Siveillance Control Pro V3.0 vers:intdot/<3.0.12.2173 (CVE-2026-50093)
  • Siveillance Control Pro V4.0 vers:intdot/<4.0.9.2178 (CVE-2026-50093)
  • Siveillance Control V3.0 vers:intdot/<3.0.22.2177 (CVE-2026-50093)
  • Siveillance Control V4.0 vers:intdot/<4.0.11.2177 (CVE-2026-50093)
CVSS Vendor Equipment Vulnerabilities
v3 9 Siemens Siemens Siveillance Control Unrestricted Upload of File with Dangerous Type

Background

  • Critical Infrastructure Sectors: Critical Manufacturing, Communications, Commercial Facilities
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: Germany

Vulnerabilities

Expand All +

CVE-2026-50093

A vulnerability in the OIS web module allows an attacker to upload arbitrary files to the server. Successful exploitation of this vulnerability could allow an attacker to gain root access on the host system, potentially leading to a full compromise of the affected OIS environment.

View CVE Details


Affected Products

Siemens Siveillance Control
Vendor:
Siemens
Product Version:
Siveillance Control Pro V3.0 < V3.0.12.2173, Siveillance Control Pro V4.0 < V4.0.9.2178, Siveillance Control V3.0 < V3.0.22.2177, Siveillance Control V4.0 < V4.0.11.2177
Product Status:
known_affected
Remediations

Vendor fix
Update to V3.0.12.2173 or later version
https://support.industry.siemens.com/cs/ww/en/view/110004860/

Vendor fix
Update to V3.0.22.2177 or later version
https://support.industry.siemens.com/cs/ww/en/view/110004859/

Vendor fix
Update to V4.0.11.2177 or later version
https://support.industry.siemens.com/cs/ww/en/view/110004859/

Vendor fix
Update to V4.0.9.2178 or later version
https://support.industry.siemens.com/cs/ww/en/view/110004860/

Vendor fix
For more information see the associated Siemens security advisory SSA-254516: Arbitrary File Upload in OIS Web Module - CSAF Version, SSA-254516: Arbitrary File Upload in OIS Web Module - HTML Version.

Relevant CWE: CWE-434 Unrestricted Upload of File with Dangerous Type


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 9 CRITICAL CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Acknowledgments

  • Siemens ProductCERT reported this vulnerability to CISA.

General Recommendations

As a general security measure Siemens strongly recommends to protect network access to affected products with appropriate mechanisms. It is advised to follow recommended security practices in order to run the devices in a protected IT environment.


Additional Resources

For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisoriesΒ 


Terms of Use

The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.


Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.

  • Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.
  • Locate control system networks and remote devices behind firewalls and isolate them from business networks.
  • When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.


Advisory Conversion Disclaimer

This ICSA is a verbatim republication of Siemens ProductCERT SSA-254516 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.

Revision History

  • Initial Release Date: 2026-09-08
Date Revision Summary
2026-09-08 1 Publication Date
2026-09-22 2 Initial CISA Republication of Siemens ProductCERT SSA-254516 advisory

Legal Notice and Terms of Use

lwIP TCP/IP Stack MQTT Client Application

By: CISA
22 September 2026 at 08:00

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to gain full code execution on the device.

The following versions of lwIP TCP/IP Stack MQTT Client Application are affected:

  • MQTT Client Application >=2.0.1|<=2.2.1 (CVE-2026-87121)
CVSS Vendor Equipment Vulnerabilities
v3 9.8 lwIP lwIP TCP/IP Stack MQTT Client Application Out-of-bounds Write

Background

  • Critical Infrastructure Sectors: Chemical, Communications, Critical Manufacturing, Energy, Financial Services, Healthcare and Public Health, Transportation Systems, Water and Wastewater Systems
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: Sweden

Vulnerabilities

Expand All +

CVE-2026-87121

The affected product is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.

View CVE Details


Affected Products

lwIP TCP/IP Stack MQTT Client Application
Vendor:
lwIP
Product Version:
lwIP MQTT Client Application: >=2.0.1|<=2.2.1
Product Status:
known_affected
Remediations

Mitigation
Users of lwIP are encouraged to update their version of lwIP using the repository found at https://savannah.nongnu.org/projects/lwip. The commit identifier that contains the fix is f89407ea711879c04d91c92b35d67be78bbaf0f1.
Β 

Relevant CWE: CWE-787 Out-of-bounds Write


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Acknowledgments

  • Shahriyar Jalayeri of ByteRay Ltd. reported this vulnerability to CISA.

Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.

  • Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
  • Locate control system networks and remote devices behind firewalls and isolating them from business networks.
  • When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

CISA also recommends users take the following measures to protect themselves from social engineering attacks:

  • Do not click web links or open attachments in unsolicited email messages.
  • Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.
  • Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.

No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.


Revision History

  • Initial Release Date: 2026-09-22
Date Revision Summary
2026-09-22 1 Initial Publication

Legal Notice and Terms of Use

CISA Adds One Known Exploited Vulnerability to Catalog

By: CISA
21 September 2026 at 08:00

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

  • CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.Β 

Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.Β 

While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.Β 

Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.Β 

CISA Adds Two Known Exploited Vulnerabilities to Catalog

By: CISA
18 September 2026 at 08:00

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.Β 

Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.Β 

While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.Β 

Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.Β 

❌
❌