{
    "ok": true,
    "version": "3.0.0-mission-control",
    "checkedAt": "2026-09-12T21:20:14+00:00",
    "elapsedMs": 153,
    "count": 25,
    "categories": {
        "security": 25
    },
    "items": [
        {
            "id": "2fa6f66fee972805e3363be3976de7b00d841bde",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "CISA Adds Three Known Exploited Vulnerabilities to Catalog",
            "summary": "CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability  CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability  CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identifi…",
            "url": "https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalog",
            "image": "",
            "published": "2026-09-11T12:00:00+00:00",
            "score": 80.54,
            "color": "#ff5bd1",
            "raw": {
                "title": "CISA Adds Three Known Exploited Vulnerabilities to Catalog",
                "summary": "<p>CISA has added three new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-42016\" target=\"_blank\">CVE-2026-42016</a> JFrog Artifactory Incorrect Authorization Vulnerability&nbsp;</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-42018\" target=\"_blank\">CVE-2026-42018</a> JFrog Artifactory Improper Authentication Vulnerability&nbsp;</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-84869\" target=\"_blank\">CVE-2026-84869</a> ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability</li>\n</ul>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.</p>\n<p>&nbsp;</p>\n",
                "url": "https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalog",
                "image": "",
                "published": "Fri, 11 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "752abd31c1d1be00f0a530f63edaa736ee5760d1",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
            "summary": "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while de…",
            "url": "https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-one-known-exploited-vulnerability-catalog",
            "image": "",
            "published": "2026-09-11T12:00:00+00:00",
            "score": 80.54,
            "color": "#ff5bd1",
            "raw": {
                "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
                "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-85706\" target=\"_blank\">CVE-2026-85706</a> GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.</p>\n",
                "url": "https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-one-known-exploited-vulnerability-catalog",
                "image": "",
                "published": "Fri, 11 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "7b9eefeaf0cf8b19b3237a2c593783dd3cf90f38",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "CISA Adds Two Known Exploited Vulnerabilities to Catalog",
            "summary": "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed i…",
            "url": "https://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalog",
            "image": "",
            "published": "2026-09-10T12:00:00+00:00",
            "score": 68.88,
            "color": "#ff5bd1",
            "raw": {
                "title": "CISA Adds Two Known Exploited Vulnerabilities to Catalog",
                "summary": "<p>CISA has added two new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-67277\" target=\"_blank\">CVE-2026-67277</a> MikroTik RouterOS Missing Authentication for Critical Function Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-86060\">CVE-2026-86060</a> MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability</li>\n</ul>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>\n",
                "url": "https://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalog",
                "image": "",
                "published": "Thu, 10 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "00d7b201342217855666ca216215594972bb71a1",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "Orthanc DICOM Server",
            "summary": "View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition. The following versions of Orthanc DICOM Server are affected: Orthanc DICOM Server",
            "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-02",
            "image": "",
            "published": "2026-09-10T12:00:00+00:00",
            "score": 68.88,
            "color": "#ff5bd1",
            "raw": {
                "title": "Orthanc DICOM Server",
                "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-253-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition.</strong></p>\n<p>The following versions of Orthanc DICOM Server are affected:</p>\n<ul>\n<li>Orthanc DICOM Server &lt;1.13.0. (CVE-2026-87020)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.1</td>\n<td>Orthanc</td>\n<td>Orthanc DICOM Server</td>\n<td>Integer Overflow or Wraparound</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Healthcare and Public Health</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Belgium</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-87020</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc decodes an attacker-supplied PNG.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-87020\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Orthanc DICOM Server</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Orthanc</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Orthanc DICOM Server: &lt;1.13.0.</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Orthanc recommends users update to v1.13.0.&nbsp;<br><a href=\"https://orthanc.uclouvain.be/downloads/index.html\">https://orthanc.uclouvain.be/downloads/index.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/190.html\">CWE-190 Integer Overflow or Wraparound</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Andrej Tomci reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (<a href=\"https://www.cisa.gov/privacy-policy\">https://www.cisa.gov/privacy-policy</a>).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-10</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-10</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n",
                "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-02",
                "image": "",
                "published": "Thu, 10 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "ccb1c050244351532a3c47f048c81b16aec0e899",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "AVEVA Pipeline Integrity Monitor",
            "summary": "View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session. The following versions of AVEVA Pipeline Integrity Monitor are affected: AVEVA Pipeline Integrity Monitor",
            "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-253-01",
            "image": "",
            "published": "2026-09-10T12:00:00+00:00",
            "score": 68.88,
            "color": "#ff5bd1",
            "raw": {
                "title": "AVEVA Pipeline Integrity Monitor",
                "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-253-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session.</strong></p>\n<p>The following versions of AVEVA Pipeline Integrity Monitor are affected:</p>\n<ul>\n<li>AVEVA Pipeline Integrity Monitor &lt;=2025_SP1_P1_build_7.1.9580.8513 (CVE-2026-81821, CVE-2026-81822, CVE-2026-81823, CVE-2026-81824)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.4</td>\n<td>AVEVA</td>\n<td>AVEVA Pipeline Integrity Monitor</td>\n<td>Use of Hard-coded Cryptographic Key, Use of a Broken or Risky Cryptographic Algorithm, Missing Authorization, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United Kingdom</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-81821</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-81821\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>AVEVA Pipeline Integrity Monitor</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>AVEVA</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>AVEVA Pipeline Integrity Monitor: &lt;=2025_SP1_P1_build_7.1.9580.8513</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Customers using affected product versions or affected PIMBoards project files should take the following actions to mitigate the risk of exploit:&nbsp;</p>\n<ul>\n<li>Apply AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate old project files.&nbsp;</li>\n<li>For project files that cannot be migrated (e.g. backups or transient copies), evaluate the risk of potential password leakage from these files and implement stricter read access controls to protect these unsafe files.</li>\n<li>Require AVEVA Pipeline Integrity Monitor PIMBoards users to change their passwords.</li>\n</ul>\n<p><strong>Vendor fix</strong><br>Important: PIMBoards Project Files migration from older versions to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 is one-way due to the changes in password hashing algorithms and end-user managed encryption keys.</p>\n<p><strong>Mitigation</strong><br>For more information, see AVEVA security bulletin AVEVA-2026-006.&nbsp;<br><a href=\"https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf\">https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/321.html\">CWE-321 Use of Hard-coded Cryptographic Key</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.4</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N\">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-81822</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to reverse engineer PIMBoards users' app-native passwords through computational brute-forcing of weak hashes, potentially allowing elevation to a PIMBoards administrator user.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-81822\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>AVEVA Pipeline Integrity Monitor</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>AVEVA</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>AVEVA Pipeline Integrity Monitor: &lt;=2025_SP1_P1_build_7.1.9580.8513</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Customers using affected product versions or affected PIMBoards project files should take the following actions to mitigate the risk of exploit:&nbsp;</p>\n<ul>\n<li>Apply AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate old project files.&nbsp;</li>\n<li>For project files that cannot be migrated (e.g. backups or transient copies), evaluate the risk of potential password leakage from these files and implement stricter read access controls to protect these unsafe files.</li>\n<li>Require AVEVA Pipeline Integrity Monitor PIMBoards users to change their passwords.</li>\n</ul>\n<p><strong>Vendor fix</strong><br>Important: PIMBoards Project Files migration from older versions to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 is one-way due to the changes in password hashing algorithms and end-user managed encryption keys.</p>\n<p><strong>Mitigation</strong><br>For more information, see AVEVA security bulletin AVEVA-2026-006.&nbsp;<br><a href=\"https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf\">https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/327.html\">CWE-327 Use of a Broken or Risky Cryptographic Algorithm</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.4</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N\">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-81823</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for PIMBoards users, resulting in information disclosure. Write operations are not impacted.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-81823\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>AVEVA Pipeline Integrity Monitor</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>AVEVA</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>AVEVA Pipeline Integrity Monitor: &lt;=2025_SP1_P1_build_7.1.9580.8513</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Customers using affected product versions or affected PIMBoards project files should take the following actions to mitigate the risk of exploit:&nbsp;</p>\n<ul>\n<li>Apply AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate old project files.&nbsp;</li>\n<li>For project files that cannot be migrated (e.g. backups or transient copies), evaluate the risk of potential password leakage from these files and implement stricter read access controls to protect these unsafe files.</li>\n<li>Require AVEVA Pipeline Integrity Monitor PIMBoards users to change their passwords.</li>\n</ul>\n<p><strong>Vendor fix</strong><br>Important: PIMBoards Project Files migration from older versions to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 is one-way due to the changes in password hashing algorithms and end-user managed encryption keys.</p>\n<p><strong>Mitigation</strong><br>For more information, see AVEVA security bulletin AVEVA-2026-006.&nbsp;<br><a href=\"https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf\">https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/862.html\">CWE-862 Missing Authorization</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-81824</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-81824\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>AVEVA Pipeline Integrity Monitor</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>AVEVA</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>AVEVA Pipeline Integrity Monitor: &lt;=2025_SP1_P1_build_7.1.9580.8513</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Customers using affected product versions or affected PIMBoards project files should take the following actions to mitigate the risk of exploit:&nbsp;</p>\n<ul>\n<li>Apply AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate old project files.&nbsp;</li>\n<li>For project files that cannot be migrated (e.g. backups or transient copies), evaluate the risk of potential password leakage from these files and implement stricter read access controls to protect these unsafe files.</li>\n<li>Require AVEVA Pipeline Integrity Monitor PIMBoards users to change their passwords.</li>\n</ul>\n<p><strong>Vendor fix</strong><br>Important: PIMBoards Project Files migration from older versions to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 is one-way due to the changes in password hashing algorithms and end-user managed encryption keys.</p>\n<p><strong>Mitigation</strong><br>For more information, see AVEVA security bulletin AVEVA-2026-006.&nbsp;<br><a href=\"https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf\">https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/79.html\">CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>4.7</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:H/SA:H\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:H/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>AVEVA reported vulnerabilities CVE-2026-81821 and CVE-2026-81822 to CISA.</li>\n<li>Adham Khairy Ramadan (0xadham) reported vulnerabilities CVE-2026-81823 and CVE-2026-81824 to AVEVA through HackerOne.&nbsp;</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (<a href=\"https://www.cisa.gov/privacy-policy\">https://www.cisa.gov/privacy-policy</a>).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-10</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-10</td>\n<td>1</td>\n<td>Initial Republication of AVEVA security bulletin AVEVA-2026-006</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n",
                "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-253-01",
                "image": "",
                "published": "Thu, 10 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "31cb63048a6545de7b3f45fe08c6840da1dec5ae",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "ST Engineering iDirect iQ-Series Terminals (Update A)",
            "summary": "View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. The following versions of ST Engineering iDirect iQ-Series Terminals (Update A) are affected: Evolution iQ‑Series terminals",
            "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-01",
            "image": "",
            "published": "2026-09-10T12:00:00+00:00",
            "score": 68.88,
            "color": "#ff5bd1",
            "raw": {
                "title": "ST Engineering iDirect iQ-Series Terminals (Update A)",
                "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-183-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition.</strong></p>\n<p>The following versions of ST Engineering iDirect iQ-Series Terminals (Update A) are affected:</p>\n<ul>\n<li>Evolution iQ‑Series terminals &lt;=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058)</li>\n<li>3315‑Series terminals &lt;=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058)</li>\n<li>9‑Series terminals &lt;=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.8</td>\n<td>ST Engineering iDirect</td>\n<td>ST Engineering iDirect iQ-Series Terminals&nbsp;</td>\n<td>Missing Authentication for Critical Function, Cross-Site Request Forgery (CSRF), Missing Authorization, Exposure of Sensitive System Information to an Unauthorized Control Sphere</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Communications, Defense Industrial Base, Energy, Government Services and Facilities, Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-38059</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can retrieve sensitive device information including the serial number, Device ID (DID), Terminal Private Key identifier (TPK), MAC address, and exact firmware version. The DID and TPK are used for satellite network authentication in the iDirect platform, potentially enabling terminal impersonation and network reconnaissance.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-38059\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ST Engineering iDirect iQ-Series Terminals (Update A)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ST Engineering iDirect</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ST Engineering iDirect Evolution iQ‑Series terminals: &lt;=4.5.2.1, ST Engineering iDirect 3315‑Series terminals: &lt;=4.5.2.1, ST Engineering iDirect 9‑Series terminals: &lt;=4.5.2.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>ST Engineering iDirect has fixed the vulnerabilities and recommend users update the software to version 4.5.3.0 or newer.</p>\n<p><strong>Mitigation</strong><br>Registered users are able to download patches from the iDirect Support Portal https://support.idirect.net.<br><a href=\"https://support.idirect.net\">https://support.idirect.net</a></p>\n<ul>\n<li>Restrict management interfaces to trusted networks (e.g., VPN, ACLs).</li>\n<li>Avoid exposing administrative APIs to the public internet.</li>\n<li>Enforce strong authentication practices.</li>\n<li>Monitor for anomalous API activity and unexpected device reboots.</li>\n</ul>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-38057</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, when visited by an authenticated administrator, automatically submits a cross-site POST request causing an immediate device reboot and satellite link loss. Repeated attacks can sustain a denial-of-service condition.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-38057\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ST Engineering iDirect iQ-Series Terminals (Update A)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ST Engineering iDirect</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ST Engineering iDirect Evolution iQ‑Series terminals: &lt;=4.5.2.1, ST Engineering iDirect 3315‑Series terminals: &lt;=4.5.2.1, ST Engineering iDirect 9‑Series terminals: &lt;=4.5.2.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>ST Engineering iDirect has fixed the vulnerabilities and recommend users update the software to version 4.5.3.0 or newer.</p>\n<p><strong>Mitigation</strong><br>Registered users are able to download patches from the iDirect Support Portal https://support.idirect.net.<br><a href=\"https://support.idirect.net\">https://support.idirect.net</a></p>\n<ul>\n<li>Restrict management interfaces to trusted networks (e.g., VPN, ACLs).</li>\n<li>Avoid exposing administrative APIs to the public internet.</li>\n<li>Enforce strong authentication practices.</li>\n<li>Monitor for anomalous API activity and unexpected device reboots.</li>\n</ul>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/352.html\">CWE-352 Cross-Site Request Forgery (CSRF)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-38056</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites. Important context: the device ships from the factory with a pre-configured low-privilege local user account. This account is intended for field technicians who need shell access for maintenance and diagnostics but should not have full administrative control over the device. This built-in account provides the initial access required to exploit this vulnerability. No additional credentials need to be obtained or brute-forced.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-38056\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ST Engineering iDirect iQ-Series Terminals (Update A)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ST Engineering iDirect</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ST Engineering iDirect Evolution iQ‑Series terminals: &lt;=4.5.2.1, ST Engineering iDirect 3315‑Series terminals: &lt;=4.5.2.1, ST Engineering iDirect 9‑Series terminals: &lt;=4.5.2.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>ST Engineering iDirect has fixed the vulnerabilities and recommend users update the software to version 4.5.3.0 or newer.</p>\n<p><strong>Mitigation</strong><br>Registered users are able to download patches from the iDirect Support Portal https://support.idirect.net.<br><a href=\"https://support.idirect.net\">https://support.idirect.net</a></p>\n<ul>\n<li>Restrict management interfaces to trusted networks (e.g., VPN, ACLs).</li>\n<li>Avoid exposing administrative APIs to the public internet.</li>\n<li>Enforce strong authentication practices.</li>\n<li>Monitor for anomalous API activity and unexpected device reboots.</li>\n</ul>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/862.html\">CWE-862 Missing Authorization</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.4</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H\">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-38058</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-38058\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ST Engineering iDirect iQ-Series Terminals (Update A)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ST Engineering iDirect</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ST Engineering iDirect Evolution iQ‑Series terminals: &lt;=4.5.2.1, ST Engineering iDirect 3315‑Series terminals: &lt;=4.5.2.1, ST Engineering iDirect 9‑Series terminals: &lt;=4.5.2.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>ST Engineering iDirect has fixed the vulnerabilities and recommend users update the software to version 4.5.3.0 or newer.</p>\n<p><strong>Mitigation</strong><br>Registered users are able to download patches from the iDirect Support Portal https://support.idirect.net.<br><a href=\"https://support.idirect.net\">https://support.idirect.net</a></p>\n<ul>\n<li>Restrict management interfaces to trusted networks (e.g., VPN, ACLs).</li>\n<li>Avoid exposing administrative APIs to the public internet.</li>\n<li>Enforce strong authentication practices.</li>\n<li>Monitor for anomalous API activity and unexpected device reboots.</li>\n</ul>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/497.html\">CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Ahmed Alqahtani of Aramco reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (<a href=\"https://www.cisa.gov/privacy-policy\">https://www.cisa.gov/privacy-policy</a>).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-02</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-02</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n<tr>\n<td>2026-09-10</td>\n<td>2</td>\n<td>Update A - Updated Vulnerabilities and CVSS 4.0 score in Executive Summary. Added CVE-2026-38056 and CVE-2026-38058. Updated Mitigation section with newest product version.</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n",
                "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-01",
                "image": "",
                "published": "Thu, 10 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "a2b3aca9a620cfa8edd4b7d83050fd83516086af",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "NextGen Healthcare Mirth Connect",
            "summary": "View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate date or cause a denial-of-service condition. The following versions of NextGen Healthcare Mirth Connect are affected: Mirth Connect",
            "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-01",
            "image": "",
            "published": "2026-09-10T12:00:00+00:00",
            "score": 68.88,
            "color": "#ff5bd1",
            "raw": {
                "title": "NextGen Healthcare Mirth Connect",
                "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-253-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate date or cause a denial-of-service condition.</strong></p>\n<p>The following versions of NextGen Healthcare Mirth Connect are affected:</p>\n<ul>\n<li>Mirth Connect &lt;=v4.7.1 (CVE-2026-82583, CVE-2026-78224, CVE-2026-82578)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.3</td>\n<td>NextGen Healthcare</td>\n<td>NextGen Healthcare Mirth Connect</td>\n<td>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), Improper Restriction of XML External Entity Reference</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Healthcare and Public Health</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-82583</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary file write, and a denial-of-service condition.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-82583\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>NextGen Healthcare Mirth Connect</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>NextGen Healthcare</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>NextGen Healthcare Mirth Connect: &lt;=v4.7.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>NextGen recommends users update Mirth Connect v4.7.2 or later. Users can download the latest version from the NextGen Healthcare customer portal.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/89.html\">CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-78224</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-78224\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>NextGen Healthcare Mirth Connect</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>NextGen Healthcare</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>NextGen Healthcare Mirth Connect: &lt;=v4.7.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>NextGen recommends users update Mirth Connect v4.7.2 or later. Users can download the latest version from the NextGen Healthcare customer portal.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/611.html\">CWE-611 Improper Restriction of XML External Entity Reference</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.2</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-82578</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-82578\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>NextGen Healthcare Mirth Connect</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>NextGen Healthcare</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>NextGen Healthcare Mirth Connect: &lt;=v4.7.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>NextGen recommends users update Mirth Connect v4.7.2 or later. Users can download the latest version from the NextGen Healthcare customer portal.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/611.html\">CWE-611 Improper Restriction of XML External Entity Reference</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Abhinav Agarwal reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (<a href=\"https://www.cisa.gov/privacy-policy\">https://www.cisa.gov/privacy-policy</a>).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-10</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-10</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n",
                "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-01",
                "image": "",
                "published": "Thu, 10 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "c436051dd8f60209104dbe49e882c2af6d64bb95",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "CISA Adds Four Known Exploited Vulnerabilities to Catalog",
            "summary": "CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability  These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog…",
            "url": "https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog",
            "image": "",
            "published": "2026-09-09T12:00:00+00:00",
            "score": 67,
            "color": "#ff5bd1",
            "raw": {
                "title": "CISA Adds Four Known Exploited Vulnerabilities to Catalog",
                "summary": "<p>CISA has added four new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-25249\" target=\"_blank\">CVE-2025-25249</a> Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-19490\" target=\"_blank\">CVE-2026-19490</a> Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-87491\" target=\"_blank\">CVE-2026-87491</a> Google Chromium V8 Out of Bounds Write Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-20079\">CVE-2026-20079</a> Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability&nbsp;</li>\n</ul>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based</a> on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>\n",
                "url": "https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog",
                "image": "",
                "published": "Wed, 09 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "f29e5fde6fa39e6fd593a934db6ad1fddea91de3",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies",
            "summary": "Executive summary China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models. The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) (hereafter referred to as the authoring agencies) are releasing this joint Cybersecurity Advisory to alert organizations about these mali…",
            "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a",
            "image": "",
            "published": "2026-09-08T12:00:00+00:00",
            "score": 67,
            "color": "#ff5bd1",
            "raw": {
                "title": "China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies",
                "summary": "<h2><strong>Executive summary</strong></h2>\n<p>China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models. The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) (hereafter referred to as the authoring agencies) are releasing this joint Cybersecurity Advisory to alert organizations about these malicious activities and techniques and recommend mitigations to reduce their potential impact.&nbsp;</p>\n<p>Likely with Chinese government awareness, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024. DeepSeek has conducted organized campaigns since at least 2024 targeting reasoning capabilities, specialized optimizations, and domain-specific functions to train its R1 and V3 models. Alibaba leveraged industrial-scale distillation to improve the company’s Qwen family of AI models. Moonshot AI, MiniMax, Stepfun, and Z.AI also engaged in malicious knowledge distillation of U.S. AI companies’ models.&nbsp;</p>\n<p>China-based AI companies route distillation requests through multiple pathways to gain unauthorized access, consequently violating U.S. AI companies’ terms of use. These pathways include native application programming interfaces (APIs), remote cloud providers, and third-party aggregators that automatically obfuscate user metadata to avoid detection. Further, China-based AI companies use a gray market of proxies known as “transfer stations” to bypass U.S. AI companies’ geographic restrictions, breach terms of use, evade safeguards, and undermine traceability. China-based AI companies achieve cost savings for their industrial-scale distillation campaigns through bulk procurement of the U.S. AI companies’ premium subscriptions shared across teams of developers. Advanced industrial-scale distillation tactics include chain-of-thought (CoT) reasoning extraction, automated failover between pathways during blocking attempts, and sophisticated quality evaluation frameworks to detect defensive countermeasures. China-based AI companies that conduct industrial-scale distillation against U.S. AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model.</p>\n<p>China-based AI companies deliberately distribute operations across multiple providers, platforms, and pathways to avoid single-point detection. They also attempt to distill the best capabilities and proprietary features of each U.S. frontier model to train their China-based AI models. This represents systematic extraction of proprietary functionalities and capabilities threatening U.S. technological leadership. Addressing industrial-scale distillation merits a coordinated response across the AI ecosystem, including effective information-sharing, spanning the U.S. Government, private industry, and allied nations.</p>\n<p>The authoring agencies recommend U.S. AI companies take three immediate actions:&nbsp;</p>\n<ol>\n<li><strong>Implement comprehensive detection and mitigation: </strong>Detect anomalous and malicious prompts, accounts, networks, and behaviors. Additionally, monitor subscription-to-usage ratios, immediate maximum usage from new accounts, and enterprise-scale throughput patterns.</li>\n<li><strong>Deploy targeted response changes:</strong> Subtly alter responses for suspected malicious distillation attempts to attenuate the payoffs to companies conducting industrial-scale distillation campaigns.</li>\n<li><strong>Establish cross-organization intelligence sharing: </strong>Correlate activity across model providers, cloud platforms, and API aggregators to reveal distributed campaigns.</li>\n</ol>\n<h2><strong>Attribution</strong></h2>\n<p>Since at least late 2024, China-based AI companies, including DeepSeek (DeepSeek Artificial Intelligence Technology Research Co., Ltd.), Moonshot AI (Beijing Moonshot Technology Co., Ltd.), Alibaba Group, MiniMax (Shanghai MiniMax Co., Ltd.), StepFun (Shanghai Jieyue Xingchen Intelligence Technology Co., Ltd.), and Z.AI, have conducted high-volume knowledge distillation campaigns against several U.S. AI companies. The sheer scale of these campaigns and their sophistication indicate that distillation is not a supplement to these companies’ AI model development, but the critical core of it.&nbsp;</p>\n<p>Likely with the knowledge of the Chinese government, the China-based AI sector has turned to a comprehensive distillation strategy in an attempt to bridge the technological and performance gaps between their AI models and U.S. frontier AI models. To access U.S. AI companies’ application programming interfaces (APIs), China-based AI companies use a gray market of API proxies known as “transfer stations” to bypass U.S. AI companies’ regional restrictions, breach terms of use, evade safeguards, and undermine traceability.&nbsp;</p>\n<h3><em><strong>DeepSeek</strong></em></h3>\n<p>DeepSeek has been conducting an organized distillation campaign against U.S. AI companies’ frontier AI models since at least late 2024 to generate synthetic training data for its models, including R1, released in early 2025. The company targeted specific knowledge domains to extract proprietary functionality and reasoning capabilities to reduce their compute and research costs. DeepSeek’s publicly quoted training costs of $5.6M are misleading as it does not include the true cost of the data acquired through extensive malicious distillation.<a href=\"#note1\"><sup>1</sup></a>&nbsp;</p>\n<p>Between late 2024 and mid-2025, DeepSeek distilled specialized training data and capabilities from the following U.S. frontier AI company models to train their R1 and V3 models:&nbsp;</p>\n<ul>\n<li>Claude 3.7&nbsp;</li>\n<li>Claude Sonnet 4</li>\n<li>Claude Sonnet 4.5</li>\n<li>Claude Opus 4.1</li>\n<li>Gemini 2.5 Pro Preview</li>\n<li>Gemini 2.5 Flash Preview</li>\n<li>GPT-4</li>\n<li>GPT-4o</li>\n<li>GPT-4 Mini</li>\n<li>GPT-4 Nano</li>\n<li>GPT-5</li>\n<li>Grok 4</li>\n</ul>\n<p>The specific knowledge and capabilities distilled included:&nbsp;</p>\n<ul>\n<li>Legal specialization optimization</li>\n<li>API rule-driven tasks</li>\n<li>Writing using CoT drafts</li>\n<li>Agentic functions</li>\n<li>Question and answer optimization</li>\n<li>Coach/assistant capabilities</li>\n<li>Functional creation optimization</li>\n<li>Supervised fine-tuning (SFT) optimization</li>\n<li>Creative and occupational writing optimization</li>\n</ul>\n<h3><em><strong>Moonshot AI&nbsp;</strong></em></h3>\n<p>Moonshot AI has conducted a widespread distillation campaign against U.S. frontier AI companies since at least mid-2025. Notably, Moonshot AI extracted significant Claude Fable 5 data to train its Kimi-K3 model and GPT-4o data to train its Kimi-K2 model. The company has used the following models to distill SFT optimization, reinforcement learning (RL), software engineering, and math capabilities:</p>\n<ul>\n<li>Claude Opus 4.1</li>\n<li>Claude Sonnet 3.7</li>\n<li>Claude Sonnet 4</li>\n<li>Claude Sonnet 4.5</li>\n<li>Claude Sonnet 4.5 Thinking</li>\n<li>Claude Fable 5</li>\n<li>GPT-oss-20b</li>\n<li>GPT-3</li>\n<li>GPT-4o</li>\n<li>GPT-4o mini</li>\n<li>GPT-5</li>\n<li>GPT-5 Codex</li>\n<li>GPT-5 Pro</li>\n<li>Gemini 2.5 Flash</li>\n<li>Gemini 2.5 Flash-Image</li>\n<li>Gemini 2.5 Pro</li>\n<li>Nano Banana</li>\n<li>Grok Code Fast-1</li>\n</ul>\n<h3><em><strong>Other companies</strong></em></h3>\n<p>Several other China-based AI companies, including Alibaba, MiniMax, StepFun, and Z.AI have also leveraged distillation techniques to build their AI models. In late 2025, Alibaba distilled Claude-4, Claude Opus, Claude Sonnet, and GPT-5 to improve their AI models’ software engineering skills, customer service dialogue functionality, image/character creation, and integration of RL, SFT, and distillation capabilities.</p>\n<p>In late 2025, MiniMax distilled CoT reasoning, RL, SFT, and software engineering capabilities to improve its M2 model from Claude Code, Claude Sonnet 4, Claude Opus, Gemini 1, Gemini 2.5 Pro, and Gemini 3 Pro. MiniMax used Claude Code for internal software development tasks, including code generation, analysis, and refinement. MiniMax even used prompt injections to try to trick Claude Code into believing it was a MiniMax product.</p>\n<p>Between late 2025 and early 2026, StepFun distilled data from Claude Opus 4.1 and 4.5, Claude Sonnet 4.5, Claude Haiku 4.5, GPT-5 Mini, GPT-5 Pro, GPT-5.1, GPT-5.1 Codex, and GPT-5.2 to improve its Step 4 model’s coding and agentic functions. By mid-2026, Z.AI had distilled billions of tokens of GPT-5.5 data and Claude Opus 4.8 data to develop the CoT reasoning capabilities of its model.</p>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><strong>Table 1: China-based AI Companies Engaged in Knowledge Distillation Against U.S. AI Companies</strong> (From at least 2024-2026)&nbsp;</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>China-based AI Company&nbsp;</strong></p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>U.S. AI Models Distilled</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>Functionalities and Domains Distilled</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>DeepSeek&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>(DeepSeek Artificial Intelligence&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>Technology Research Co., Ltd.)&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>深度求索AI基􀀀技􀀀研究有限公司</strong></p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>Claude Sonnet 3.7&nbsp;</li>\n<li>Claude Sonnet 4&nbsp;</li>\n<li>Claude Sonnet 4.5&nbsp;</li>\n<li>Claude Opus 4.1&nbsp;</li>\n<li>Gemini 2&nbsp;</li>\n<li>Gemini 2.5 Pro Preview&nbsp;</li>\n<li>Gemini 2.5 Flash Preview&nbsp;&nbsp;</li>\n<li>GPT-4&nbsp;</li>\n<li>GPT-4o&nbsp;</li>\n<li>GPT-4 Mini&nbsp;</li>\n<li>GPT-4 Nano&nbsp;</li>\n<li>GPT-5&nbsp;</li>\n<li>Grok 3 Mini&nbsp;&nbsp;</li>\n<li>Grok 4&nbsp;</li>\n</ul>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>Legal specialization optimization&nbsp;</li>\n<li>API rule-driven tasks&nbsp;</li>\n<li>Writing using CoT drafts&nbsp;</li>\n<li>Question and answer optimization&nbsp;</li>\n<li>Coach/assistant capabilities&nbsp;</li>\n<li>Functional creation optimization&nbsp;</li>\n<li>SFT optimization&nbsp;</li>\n<li>Agentic capabilities&nbsp;</li>\n<li>Creative and occupational writing optimization&nbsp;</li>\n</ul>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>Moonshot AI&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>(Beijing Moonshot Technology Co., Ltd.)&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>北京􀀀月星辰科技有限公司&nbsp;</strong></p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>Claude Opus 4.1&nbsp;</li>\n<li>Claude Sonnet 3.7&nbsp;</li>\n<li>Claude Sonnet 4&nbsp;</li>\n<li>Claude Sonnet 4.5&nbsp;</li>\n<li>Claude Sonnet 4.5 Thinking&nbsp;</li>\n<li>Claude Fable 5&nbsp;</li>\n<li>GPT-oss-20b;&nbsp;</li>\n<li>GPT-3&nbsp;</li>\n<li>GPT-4o mini&nbsp;</li>\n<li>GPT-5&nbsp;</li>\n<li>GPT-5 Codex&nbsp;</li>\n<li>GPT-5 Pro&nbsp;</li>\n<li>Gemini 2.5 Flash&nbsp;</li>\n<li>Gemini 2.5 Flash-Image&nbsp;</li>\n<li>Gemini 2.5 Pro&nbsp;</li>\n<li>Nano Banana&nbsp;</li>\n<li>xAI Grok Code Fast-1&nbsp;</li>\n</ul>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>SFT&nbsp;</li>\n<li>RL&nbsp;</li>\n<li>Software engineering&nbsp;</li>\n<li>Math capabilities&nbsp;</li>\n</ul>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p>&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>Alibaba&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>阿里集团&nbsp;</strong></p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>Claude 4&nbsp;</li>\n<li>Claude Sonnet&nbsp;</li>\n<li>GPT-5&nbsp;</li>\n</ul>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>Customer service dialogue&nbsp;</li>\n<li>Virtual character creation&nbsp;</li>\n<li>SFT, RL, and distillation training&nbsp;</li>\n<li>Evaluating and training datasets&nbsp;</li>\n<li>End-to-end agentic workflows&nbsp;</li>\n<li>Software engineering&nbsp;</li>\n</ul>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>MiniMax&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>(Shanghai MiniMax Co., Ltd.)&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>上海稀宇极智科技有限公司&nbsp;</strong></p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>Claude Code&nbsp;</li>\n<li>Claude Sonnet 4&nbsp;</li>\n<li>Claude Opus 4.5&nbsp;</li>\n<li>Gemini 1&nbsp;</li>\n<li>Gemini 2.5 Pro&nbsp;</li>\n<li>Gemini 3 Pro&nbsp;</li>\n<li>GPT-5&nbsp;</li>\n</ul>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>CoT reasoning&nbsp;</li>\n<li>Agentic functionality&nbsp;</li>\n<li>Code review&nbsp;</li>\n<li>SFT dataset refinement&nbsp;</li>\n<li>Software engineering tasks&nbsp;</li>\n</ul>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>StepFun&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>(Shanghai Jieyue Xingchen&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>Intelligence Technology Co., Ltd.)&nbsp;</strong></p>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>上海􀀀􀀀星辰智能科技有限公司&nbsp;</strong></p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>Claude Opus 4.1&nbsp;</li>\n<li>Claude Opus 4.5&nbsp;</li>\n<li>Claude Sonnet 4.5&nbsp;</li>\n<li>Claude Haiku 4.5&nbsp;</li>\n<li>GPT-5 Mini&nbsp;</li>\n<li>GPT-5 Pro&nbsp;</li>\n<li>GPT-5.1&nbsp;</li>\n<li>GPT-5.1 Codex&nbsp;</li>\n<li>GPT-5.1 Codex Mini&nbsp;</li>\n<li>GPT-5.2&nbsp;</li>\n</ul>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>Code development&nbsp;</li>\n<li>Agentic functions&nbsp;</li>\n</ul>\n</div>\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"OutlineElement Ltr SCXW188854275 BCX8\">\n<p class=\"text-align-center\"><strong>Z.AI&nbsp;</strong></p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>GPT-5.5&nbsp;</li>\n<li>Claude Opus 4.8&nbsp;</li>\n</ul>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW188854275 BCX8\">\n<div class=\"ListContainerWrapper SCXW188854275 BCX8\">\n<ul type=\"disc\">\n<li>CoT reasoning&nbsp;</li>\n</ul>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n<h2><strong>Tactics, techniques, and procedures</strong></h2>\n<p>China-based AI companies employ sophisticated tactics, techniques, and procedures (TTPs). These TTPs map to the <a href=\"https://atlas.mitre.org/\" target=\"_blank\">MITRE® ATLAS™</a><a href=\"#note2\"><sup>2</sup></a> framework, progressing through multiple adversary lifecycle phases from initial access through exfiltration. The China-based AI companies using these techniques include DeepSeek, Moonshot AI, MiniMax, StepFun, Z.AI, and other China-based AI companies targeting U.S. frontier AI models.</p>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><strong>Table 2: MITRE ATLAS Mappings</strong>&nbsp;</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p class=\"text-align-center\"><strong>TTP Title</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p class=\"text-align-center\"><strong>ID</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p class=\"text-align-center\"><strong>Description</strong>&nbsp;</p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td colspan=\"3\">\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p class=\"text-align-center\"><em><strong>Resource Development</strong></em>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>Acquire Infrastructure&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p><a href=\"https://atlas.mitre.org/techniques/AML.T0008\" target=\"_blank\"><u>AML.T0008</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>China-based entities establish and maintain sophisticated infrastructure supporting sustained extraction operations through tiered budget management and diverse supplier relationships.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>China-based entities circumvent both Chinese and U.S. AI access controls through a large gray market of API proxies, or “transfer stations,” which resell access to frontier models at a fraction of the official price. In doing so, they create a scalable mechanism for evading provider safeguards and eroding traceability.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td colspan=\"3\">\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p class=\"text-align-center\"><em><strong>AI Model Access</strong></em>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>AI Model Inference API Access&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p><a href=\"https://atlas.mitre.org/techniques/AML.T0040\" target=\"_blank\"><u>AML.T0040</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>China-based entities have been exploiting AI model inference APIs through the creation of fraudulent accounts that are not registered to legitimate users. These actors leverage multiple accounts with similar registration details and payment methods, frequently switch between various AI models, and utilize third-party API aggregator services. Additionally, they execute highly coordinated queries featuring identical or similar prompt texts, demonstrating a sophistication indicative of advanced AI research. The sheer volume of requests, ranging from thousands to millions on similar topics, far exceeds legitimate use, raising significant concerns about potential misuse and compromising the integrity of AI systems.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td colspan=\"3\">\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p class=\"text-align-center\"><em><strong>Execution / Privilege Escalation / Defense Evasion</strong></em>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>LLM Prompt Injection&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>LLM Jailbreak&nbsp;&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p><a href=\"https://atlas.mitre.org/techniques/AML.T0051\" target=\"_blank\"><u>AML.T0051</u></a>&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p><a href=\"https://atlas.mitre.org/techniques/AML.T0054\" target=\"_blank\"><u>AML.T0054</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>China-based entities have conducted prompt injection techniques against large language models (LLMs) by inserting prompts specifically designed for jailbreaking.&nbsp;&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>China-based entities craft prompts forcing models to reveal their hidden CoT reasoning (CoT or step-by-step internal reasoning that enables greater capabilities) despite U.S. models restricting CoT output visibility to users. DeepSeek employed prompts instructing models to imagine and articulate the internal reasoning behind completed responses and write it out step by step. This CoT data teaches student models, not just factual knowledge, but reasoning methodologies for complex agentic tasks, coding challenges, and logical proofs.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td colspan=\"3\">\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p class=\"text-align-center\"><em><strong>Discovery</strong></em>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>Discovery&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p><a href=\"https://atlas.mitre.org/tactics/AML.TA0008\" target=\"_blank\"><u>AML.TA0008</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>China-based entities employ aggressive, adaptive discovery to systematically identify valuable extractable data.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>China-based entities demonstrate rapid operational adaptation. MiniMax redirected exchanges to a new Claude model within 24 hours of release, demonstrating real-time provider monitoring and pre-positioned infrastructure for immediate retargeting.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td colspan=\"3\">\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p class=\"text-align-center\"><em><strong>AI Attack Staging</strong></em>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>Verify Attack&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p><a href=\"https://atlas.mitre.org/techniques/AML.T0042\" target=\"_blank\"><u>AML.T0042</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>China-based entities deploy production-grade automated quality assurance pipelines with multi-modal validation, enabling rapid detection of degraded outputs and differentiation of service issues from defensive data degradation.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td colspan=\"3\">\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p class=\"text-align-center\"><em><strong>Collection</strong></em>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>Collection&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p><a href=\"https://atlas.mitre.org/tactics/AML.TA0009\" target=\"_blank\"><u>AML.TA0009</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>China-based entities systematically collect outputs to generate synthetic training datasets through continuous API querying, targeting specific knowledge domains rather than indiscriminate gathering.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>Moonshot AI used millions of exchanges targeting agentic reasoning/tool use, coding/data analysis, computer-use agent development, and computer vision, evolving from text-based distillation to extracting logical frameworks, enabling tool interaction and visual processing.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>DeepSeek used queries targeting reasoning capabilities, rubric-based grading tasks (reward model function), and censorship-safe query rewriting, extracting how U.S. models evaluate response quality.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>Campaigns span days to months with query volumes in the thousands to millions per domain, far exceeding legitimate research or development use cases.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td colspan=\"3\">\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p class=\"text-align-center\"><em><strong>Exfiltration</strong></em>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>Exfiltration via AI&nbsp;&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>Inference API: Extract AI Model&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p><a href=\"https://atlas.mitre.org/techniques/AML.T0024.002\" target=\"_blank\"><u>AML.T0024.002</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>China-based entities have been collecting U.S. frontier LLMs’ inferences into datasets, which can be used to train their models to mimic the behavior and performance of these LLMs.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td colspan=\"3\">\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p class=\"text-align-center\"><em><strong>Impact</strong></em>&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>External Harms&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p><a href=\"https://atlas.mitre.org/techniques/AML.T0048\" target=\"_blank\"><u>AML.T0048</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW198784767 BCX8\">\n<div class=\"OutlineElement Ltr SCXW198784767 BCX8\">\n<p>China-based entities inflict financial harm through systematic extraction of proprietary functionality and capabilities, causing significant economic losses. Extracting capabilities worth billions in development costs while undermining competitive advantages represents a strategic economic threat to fair technological competition and U.S. technological leadership.&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n<h3><em><strong>Novel TTPs</strong></em></h3>\n<p>China-based AI companies leverage techniques not in MITRE ATLAS, demonstrating significant organizational investment, operational maturity, and adaptive capability development distinguishing these campaigns from opportunistic exploitation.</p>\n<h4><strong>Novel TTP 1: Regional restriction evasion and subscription exploitation</strong></h4>\n<p>Some U.S. frontier AI models are restricted for use; however, China-based AI companies access U.S. frontier AI models by employing various means to bypass the regional restrictions.</p>\n<p>After bypassing the restriction, China-based AI companies create user accounts obfuscating their country of origin and subsequentially procure bulk premium AI subscription services.</p>\n<p>StepFun structured access around pools of accounts with employees running multiple concurrent sessions, implementing load distribution to prevent quota depletion. Daily budget allocations per automated agent started at moderate levels, scaling significantly as operations matured.</p>\n<p>Detection indicators include:</p>\n<ul>\n<li>shared accounts from multiple IPs/user agents,&nbsp;</li>\n<li>24/7 sustained usage without human variation/idle periods,&nbsp;</li>\n<li>anomalous subscription-to-API usage ratios, and&nbsp;</li>\n<li>new subscriptions immediately at maximum usage as opposed to gradual AI adoption.</li>\n</ul>\n<h4><strong>Novel TTP 2: Centralized request routing infrastructure</strong></h4>\n<p>China-based AI companies deploy sophisticated tools that enable unified control and scalable implementation for evasion at scale. This provides model/provider abstraction, real-time health monitoring, centralized quota enforcement, and automated sanitization.</p>\n<p>China-based AI companies manage routing systems to external AI models for distillation. These routing systems direct requests through multiple pathways: native APIs, cloud providers, third-party aggregators, third-party relays, and vendor account pools.</p>\n<p>Detection indicators include:</p>\n<ul>\n<li>consistent operational patterns across diverse account pools and&nbsp;</li>\n<li>correlated timing/behavior across different pathways indicating unified orchestration.</li>\n</ul>\n<h4><strong>Novel TTP 3: Automated request metadata sanitization</strong></h4>\n<p>China-based AI companies implement automated sanitization to systematically remove organizational identifiers. This differs from <a href=\"https://atlas.mitre.org/techniques/AML.T0065\" target=\"_blank\">AML.T0065</a> (LLM Prompt Crafting) by operating at an infrastructure layer with automated enforcement instead of manual modification.</p>\n<p>Detection indicators include:</p>\n<ul>\n<li>sudden behavioral changes following disclosures/sharing, especially abrupt disappearance of previously consistent metadata;&nbsp;</li>\n<li>absence of expected markers in high-volume campaigns where scale suggests institutional activity; and&nbsp;</li>\n<li>generic/randomized patterns replacing consistent organizational indicators.</li>\n</ul>\n<h4><strong>Novel TTP 4: Systematic quota and cost optimization</strong></h4>\n<p>China-based AI companies systematically minimize API costs through pathway selection prioritizing cost-efficiency, centralized quota allocation/budget alignment, and account segmentation by purpose.</p>\n<p>Detection indicators include:</p>\n<ul>\n<li>new accounts with anomalously high immediate hit rates suggesting bulk deployment with pre-engineered templates,&nbsp;</li>\n<li>usage optimized for cache maximization versus task diversity, and&nbsp;</li>\n<li>coordinated pathway switching responding to pricing/rate changes indicating centralized decision-making.</li>\n</ul>\n<h2><strong>Mitigations</strong></h2>\n<p>Coordinated, ecosystem-wide responses extending beyond individual company measures can help address knowledge distillation campaigns. The mitigations below incorporate mitigations from the MITRE ATLAS and National Institute of Standards and Technology (NIST) AI frameworks. Collaboration across the broader AI ecosystem, including cloud providers, API aggregators, and infrastructure providers, can enable a coordinated defense against malicious knowledge distillation campaigns.</p>\n<h3><em><strong>Behavioral detection and monitoring</strong></em></h3>\n<p>China-based AI companies leverage premium subscriptions to U.S. frontier models for knowledge distillation campaigns and code development. U.S. companies should strengthen identity verification for accounts and track individual subscriptions with enterprise-scale throughput, accounts deviating from legitimate patterns, and new accounts immediately at maximum usage versus a gradual ramp-up or with consistent quota exhaustion.&nbsp;</p>\n<h3><em><strong>Response alteration for suspected distillation activity</strong></em></h3>\n<p>Employing targeted changes in response to high-confidence malicious distillation requests can impose meaningful costs on knowledge distillation campaigns. Response changes, such as including differential privacy or using less sophisticated “downgraded” models to respond to distillation requests, can help protect U.S. proprietary functionalities and capabilities and reduce payoffs from distillation attempts.&nbsp;</p>\n<h4><strong>Implementation strategies</strong></h4>\n<p>When suspecting a malicious distillation campaign, consider varying changes to responses across requests to complicate response quality evaluations, such that the subtle changes avoid triggering obvious alerts. Reducing reasoning depth, presenting correct information with different reasoning, or stylistic inconsistencies may evade detection while reducing training usefulness.</p>\n<p>Avoid informing China-based AI company users suspected of distillation campaigns of a switch to a downgraded model. Informing malicious distillers would enable them to improve their defense evasions and indicate when to roll back training. Instead, alter responses to users confirmed to be querying frontier models specifically for malicious knowledge distillation campaigns without informing them. In contrast, AI safety researchers and third-party evaluators should be informed of model changes while still applying strong distillation mitigations.</p>\n<h3><em><strong>Cross-organization information sharing and ecosystem coordination</strong></em></h3>\n<p>Sharing information about distillation campaigns, such as indicators of infrastructure distributing operations across multiple providers, platforms, and pathways, can improve individual companies’ detection efforts. Industry disclosures document proxy networks managing tens of thousands of fraudulent accounts simultaneously, mixing distillation with unrelated customer requests across multiple providers. Community collaboration could provide defenders with more comprehensive visibility across the native APIs, cloud endpoints, and aggregators.</p>\n<p>Sharing information about distillation enables and enhances correlation otherwise unachievable by individual organizations, through sharing infrastructure indicators (IPs, domains, third-party service providers) and behavioral indicators (timing correlations, query volume patterns).</p>\n<p>Multi-source correlated activity enables more confident attribution of malicious knowledge distillation campaigns, justifying response degradation with lower-to-no legitimate user risk.</p>\n<p>Sharing infrastructure and behavioral indicators between cloud providers, model aggregators, and model providers can make distributed infrastructure visible as coordinated campaigns versus isolated anomalies. Additionally, sharing can provide cloud and routing companies with actionable indicators for identifying and mitigating malicious activity.</p>\n<div class=\"OutlineElement Ltr SCXW94261203 BCX8\">\n<h3><em><strong>MITRE ATLAS mitigations&nbsp;</strong></em></h3>\n<ul>\n<li><a href=\"https://atlas.mitre.org/mitigations/AML.M0015\" target=\"_blank\"><u>AML.M0015</u></a> - Predictive AI Adversarial Input Detection: Detect/block atypical queries deviating from benign patterns, exhibiting previous adversary technique characteristics, or originating from malicious IPs.</li>\n<li><a href=\"https://atlas.mitre.org/mitigations/AML.M0004\" target=\"_blank\"><u>AML.M0004</u></a> - Limit AI Service Query Volume and Rate: Per-key/IP quotas, rate limits, progressive throttling. Adversaries seem to be sensitive to rate limits since they implement sophisticated strategies to work within constraints.&nbsp;</li>\n<li><a href=\"https://atlas.mitre.org/mitigations/AML.M0019\" target=\"_blank\"><u>AML.M0019</u></a> - Control Access to AI Models and Data in Production: User verification, authenticated API access, policy monitoring. This addresses fraudulent account pool exploitation.&nbsp;</li>\n<li><a href=\"https://atlas.mitre.org/mitigations/AML.M0024\" target=\"_blank\"><u>AML.M0024</u></a> - AI Telemetry Logging: Log inputs/outputs for threat detection/forensics. This is foundational for behavioral detection and enables correlation with intelligence.&nbsp;</li>\n<li><a href=\"https://atlas.mitre.org/mitigations/AML.M0002\" target=\"_blank\"><u>AML.M0002</u></a> - Predictive AI Output Obfuscation: Reduce fidelity of responses (withhold logits/confidences, shorten responses, targeted redaction). Balance security with user experience.&nbsp;</li>\n<li><a href=\"https://atlas.mitre.org/mitigations/AML.M0035\" target=\"_blank\"><u>AML.M0035</u></a> – AI Red Team: Adversarial testing, extraction simulation, telemetry monitoring. Validates detection efficacy.&nbsp;</li>\n<li><a href=\"https://atlas.mitre.org/mitigations/AML.M0015\" target=\"_blank\"><u>AML.M0015</u></a> - Predictive AI Adversarial Input Detection: Sanitize/validate inputs preventing prompt injections. This addresses jailbreak and injection attempts to elicit reasoning traces and system prompts.&nbsp;</li>\n<li><a href=\"https://atlas.mitre.org/mitigations/AML.M0000\" target=\"_blank\"><u>AML.M0000</u></a> - Limit Public Information Release: Limit disclosure of architecture, prompt templates, and system instructions.&nbsp;</li>\n<li><a href=\"https://atlas.mitre.org/mitigations/AML.M0001\" target=\"_blank\"><u>AML.M0001</u></a> - Limit Model Artifact Release: Limit release of data, algorithms, architectures, and model checkpoints.&nbsp;</li>\n<li><a href=\"https://atlas.mitre.org/mitigations/AML.M0003\" target=\"_blank\"><u>AML.M0003</u></a> - Predictive AI Model Hardening: Use adversarial training and defensive distillation to increase jailbreak difficulty.&nbsp;</li>\n<li><a href=\"https://atlas.mitre.org/mitigations/AML.M0006\" target=\"_blank\"><u>AML.M0006</u></a> - Predictive AI Ensembles: Use multiple models so extracting one yields a less usable clone.&nbsp;</li>\n</ul>\n<h3><em><strong>NIST AI 100-2e2025: Adversarial machine learning mitigations</strong></em></h3>\n<p>Mitigations in NIST’s “<a href=\"https://csrc.nist.gov/pubs/ai/100/2/e2025/final\" target=\"_blank\">Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations</a>” (NIST AI 100-2e2025) also apply to malicious distillation, including differential privacy, pre- and post-training interventions, and prompt instruction/formatting.</p>\n<h4><strong>Differential privacy</strong></h4>\n<p>Differential Privacy (DP) provides mathematically rigorous protection against inference and distillation techniques by adding calibrated noise to model outputs and preventing malicious actors from extracting training data membership information and other sensitive model information, such as decision boundaries or signals that could help reconstruct private data. This protection is governed by privacy parameters that define a finite privacy budget, where each query consumes part of the model's available privacy protection and repeated querying steadily reduces the remaining privacy reserve.&nbsp;</p>\n<p>As that budget is consumed through accumulated queries, the model must either add more noise to preserve privacy, restrict further queries, or accept reduced privacy protection. This creates a fundamental noise-versus-utility tradeoff, where stronger privacy protection requires more noise, which can lower prediction precision and business usefulness, while less noise improves utility but increases vulnerability to compromise techniques, such as membership inference, model extraction, or inversion.&nbsp;</p>\n<p>In practice, the right balance requires careful tuning and empirical auditing, because theoretical privacy settings do not always predict real-world accuracy impact, particularly for complex models or high-dimensional outputs that require substantially more noise to achieve equivalent protection, or when facing adaptive actors. As a result, DP is often strengthened with complementary controls such as query rate limiting, response aggregation, and monitoring.</p>\n<h4><strong>Pre/post-training interventions</strong></h4>\n<p>A range of training strategies have been proposed to increase the difficulty of accessing harmful capabilities through prompt injection, including safety training during pre-training or post training, adversarial training methods, and other methods to make jailbreak techniques more difficult.</p>\n<h4><strong>Prompt instruction/formatting</strong></h4>\n<p>Model instructions can cue the model to treat user input carefully, such as by wrapping user input in XML tags, appending specific instructions to the prompt, or otherwise attempting to clearly separate instructions from user prompts to mitigate distillation and make prompt injection or jailbreaking less effective.</p>\n<h2><strong>Footnotes</strong></h2>\n<p><sup>1</sup> <a class=\"ck-anchor\" id=\"note1\"></a>Publicly quoted training costs are from “<a href=\"https://arxiv.org/pdf/2412.19437\" target=\"_blank\">DeepSeek-V3 Technical Report</a>”</p>\n<p><a class=\"ck-anchor\" id=\"note2\"><sup>2</sup></a><a class=\"ck-anchor\" id=\"note2\"></a> MITRE is a registered trademark of The MITRE Corporation. MITRE ATLAS is a trademark of The MITRE Corporation.</p>\n<h2><strong>References</strong></h2>\n<ul>\n<li><a href=\"https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks\" target=\"_blank\">Anthropic: Detecting and preventing distillation attacks</a></li>\n<li><a href=\"https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use\" target=\"_blank\">Google: GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use</a></li>\n<li><a href=\"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-2e2025.pdf\" target=\"_blank\">NIST AI 100-2e2025: Adversarial Machine Learning A Taxonomy and Terminology of Attacks and Mitigations</a></li>\n<li><a href=\"https://assets.bwbx.io/documents/users/iqjWHBFdfxIU/rRmql_jJcxb4/v0\" target=\"_blank\">OpenAI: RE: Updated Stakes for American-Led, Democratic AI</a></li>\n<li><a href=\"https://the-decoder.com/how-chinas-gray-market-sells-claude-tokens-at-a-fraction-of-the-price/\" target=\"_blank\">The Decoder: How China's gray market sells Claude tokens at a fraction of the price</a></li>\n<li><a href=\"https://www.whitehouse.gov/presidential-actions/2026/06/national-security-presidential-memorandum-nspm-11/\" target=\"_blank\">White House National Security Presidential Memorandum 11 (NSPM-11): Artificial Intelligence in the National Security Enterprise</a></li>\n<li><a href=\"https://www.whitehouse.gov/wp-content/uploads/2026/04/NSTM-4.pdf\" target=\"_blank\">White House National Science and Technology Memorandum 4 (NSTM-4): Adversarial Distillation of American AI Models</a></li>\n<li><a href=\"https://x.com/mkratsios47/status/2079933645888880708\" target=\"_blank\">White House Office of Science and Technology Policy post on X</a></li>\n</ul>\n<h4><em><strong>Disclaimer of endorsement</strong></em></h4>\n<p>The information and opinions contained in this document are provided \"as is\" and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes.</p>\n<h4><em><strong>Purpose</strong></em></h4>\n<p>This document was developed in furtherance of the authoring agencies’ cybersecurity missions, including their responsibilities to identify and disseminate threats and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.</p>\n<h4><em><strong>Contact</strong></em></h4>\n<ul>\n<li><strong>National Security Agency</strong><br>Cybersecurity Report Feedback: <a href=\"mailto:CybersecurityReports@nsa.gov\" target=\"_blank\">CybersecurityReports@nsa.gov</a><br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href=\"mailto:DIB_Defense@cyber.nsa.gov\" target=\"_blank\">DIB_Defense@cyber.nsa.gov</a><br>Media Inquiries / Press Desk: NSA Media Relations: 443-634-0721, <a href=\"mailto:MediaRelations@nsa.gov\" target=\"_blank\">MediaRelations@nsa.gov</a></li>\n<li><strong>Cybersecurity and Infrastructure Security Agency</strong><br>CISA’s 24/7 Operations Center (<a href=\"mailto:contact@cisa.dhs.gov\" target=\"_blank\">contact@cisa.dhs.gov</a>), or by calling 1-844-Say-CISA (1-844-729-2472).</li>\n<li><strong>Federal Bureau of Investigation</strong><br>If you or someone you know has fallen victim to this campaign, file a complaint with <a href=\"https://www.ic3.gov/\" target=\"_blank\">IC3</a>.<br>&nbsp;</li>\n</ul>\n</div>\n</div>\n</div>\n",
                "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a",
                "image": "",
                "published": "Tue, 08 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "50efba35d052511d244df4d7f775b8cb278dcf19",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "CareCam Pro IP Cameras",
            "summary": "View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take full control of the device. The following versions of CareCam Pro IP Cameras are affected: ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26 (CVE-2026-85083) CVSS Vendor Equipment Vulnerabilities v3 6.8 CareCam CareCam Pro IP Cameras Use of Hard-coded Credentials Background Critical Infrastructure Sectors: Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-85083 The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and potentially resul…",
            "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-251-01",
            "image": "",
            "published": "2026-09-08T12:00:00+00:00",
            "score": 67,
            "color": "#ff5bd1",
            "raw": {
                "title": "CareCam Pro IP Cameras",
                "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-251-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to take full control of the device.</strong></p>\n<p>The following versions of CareCam Pro IP Cameras are affected:</p>\n<ul>\n<li>ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26 (CVE-2026-85083)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 6.8</td>\n<td>CareCam</td>\n<td>CareCam Pro IP Cameras</td>\n<td>Use of Hard-coded Credentials</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Commercial Facilities</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>China</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-85083</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and potentially resulting in complete device compromise.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-85083\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>CareCam Pro IP Cameras</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>CareCam</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>CareCam ANJIA AJL33PC0801 Firmware: linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>CareCam has not responded to CISA's attempts for coordination. Users are encouraged to reach out to CareCam.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/798.html\">CWE-798 Use of Hard-coded Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Omkar Mali reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-08</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-08</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n",
                "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-251-01",
                "image": "",
                "published": "Tue, 08 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "27160fae522c3007a6ddbdde5b7e11d23a45eaa3",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "CISA Adds Four Known Exploited Vulnerabilities to Catalog",
            "summary": "CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability CVE-2026-81963 Microsoft Windows Link Following Vulnerability   CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability  CVE-2026-86218 N-able N-central Static Code Injection Vulnerability  These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to priori…",
            "url": "https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog",
            "image": "",
            "published": "2026-09-08T12:00:00+00:00",
            "score": 67,
            "color": "#ff5bd1",
            "raw": {
                "title": "CISA Adds Four Known Exploited Vulnerabilities to Catalog",
                "summary": "<p>CISA has added four new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-75650\" target=\"_blank\">CVE-2026-75650</a> Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-81963\" target=\"_blank\">CVE-2026-81963</a> Microsoft Windows Link Following Vulnerability &nbsp;</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-85880\" target=\"_blank\">CVE-2026-85880</a> Microsoft Windows Heap-Based Buffer Overflow Vulnerability&nbsp;</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-86218\" target=\"_blank\">CVE-2026-86218</a> N-able N-central Static Code Injection Vulnerability&nbsp;</li>\n</ul>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>\n",
                "url": "https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog",
                "image": "",
                "published": "Tue, 08 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "bd29d192fa2179b9e1e3e96036d98e514369e9d7",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
            "summary": "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-ri…",
            "url": "https://www.cisa.gov/news-events/alerts/2026/09/04/cisa-adds-one-known-exploited-vulnerability-catalog",
            "image": "",
            "published": "2026-09-04T12:00:00+00:00",
            "score": 67,
            "color": "#ff5bd1",
            "raw": {
                "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
                "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-85046\" target=\"_blank\">CVE-2026-85046</a> Google Chromium V8 Type Confusion Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities\">specified criteria</a>.</p>\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s <a href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>\n",
                "url": "https://www.cisa.gov/news-events/alerts/2026/09/04/cisa-adds-one-known-exploited-vulnerability-catalog",
                "image": "",
                "published": "Fri, 04 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "e0530c8d73fa1f11a693fbe1d1a7e51c6a0a822e",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "IXON VPN Client",
            "summary": "View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges. The following versions of IXON VPN Client are affected: VPN Client",
            "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-02",
            "image": "",
            "published": "2026-09-03T12:00:00+00:00",
            "score": 67,
            "color": "#ff5bd1",
            "raw": {
                "title": "IXON VPN Client",
                "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges.</strong></p>\n<p>The following versions of IXON VPN Client are affected:</p>\n<ul>\n<li>VPN Client &lt;1.4.7 (CVE-2026-75925)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.6</td>\n<td>IXON</td>\n<td>IXON VPN Client</td>\n<td>Improper Neutralization of CRLF Sequences ('CRLF Injection')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Commercial Facilities, Critical Manufacturing, Energy, Information Technology, Water and Wastewater</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Netherlands</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-75925</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Improper Neutralization of CRLF Sequences (CWE-93) in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralised, which allows additional directives to be introduced into that file. The configuration interface accepts changes without authenticating or verifying the origin of the requester (CWE-306, contributing). The injected configuration persists on disk across restarts of the client and the operating system, and the VPN connection continues to function normally, so there is no behavioral change visible to the user.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-75925\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>IXON VPN Client</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>IXON</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>IXON VPN Client: &lt;1.4.7</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>IXON recommends updating the IXON VPN client to version 1.4.7 or later on every computer where it is installed.</p>\n<p><strong>Mitigation</strong><br>As of August 5, 2026, IXON cloud rejects connections from clients below v1.4.7 at both the portal and the back-end API. Since the privileged subprocess and injected listener are only created when the client connects, unpatched installations cannot complete the exploit chain.</p>\n<p><strong>Mitigation</strong><br>If the client is no longer needed, IXON recommends uninstalling the VPN client from the computer.</p>\n<p><strong>Mitigation</strong><br>For more information, please refer to the IXON Trust Center Advisory at&nbsp;<br><a href=\"https://www.ixon.cloud/Advisories/ADV-2026-08-05.pdf%60\">https://www.ixon.cloud/Advisories/ADV-2026-08-05.pdf</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/93.html\">CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.6</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.4</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Luuk van Rheden of IXON discovered this vulnerability.</li>\n<li>Stan van Duijnhoven of IXON reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (<a href=\"https://www.cisa.gov/notification\">https://www.cisa.gov/notification</a>) and this Privacy &amp; Use policy (<a href=\"https://www.cisa.gov/privacy-policy\">https://www.cisa.gov/privacy-policy</a>).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-08-05</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-08-05</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n<tr>\n<td>2026-09-03</td>\n<td>2</td>\n<td>Initial Republication by CISA</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n",
                "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-02",
                "image": "",
                "published": "Thu, 03 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "27814c97768128f85ad490e1b84cf25c004c535b",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "Inductive Automation Ignition",
            "summary": "View CSAF Summary Successful exploitation of this vulnerability could allow any authenticated user to create projects. The following versions of Inductive Automation Ignition are affected: Ignition",
            "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-06",
            "image": "",
            "published": "2026-09-03T12:00:00+00:00",
            "score": 67,
            "color": "#ff5bd1",
            "raw": {
                "title": "Inductive Automation Ignition",
                "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-06.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow any authenticated user to create projects.</strong></p>\n<p>The following versions of Inductive Automation Ignition are affected:</p>\n<ul>\n<li>Ignition &lt;=8.1.53 (CVE-2026-77393)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.8</td>\n<td>Inductive Automation</td>\n<td>Inductive Automation Ignition</td>\n<td>Incorrect Default Permissions</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy, Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-77393</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>In Ignition 8.1.53 and earlier, the Gateway \"Create Project Role(s)\" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-77393\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Inductive Automation Ignition</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Inductive Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Inductive Automation Ignition: &lt;=8.1.53</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Inductive Automation has determined that this issue is a default-value configuration, not a flaw in the access control itself. The security control enforces exactly what the \"Create Project Role(s)\" setting specifies; because the setting shipped blank, no role was required to create a project. Populating the setting fully closes the vulnerability.</p>\n<p><strong>Mitigation</strong><br>Inductive Automation recommends users upgrade to 8.1.54 or later (or the latest 8.3 version), which restricts project creation to Designer sessions and no longer relies on this setting. Users who must remain on an earlier 8.1 version can fully remediate the issue by setting \"Create Project Role(s)\" to match their Designer Role. Once the setting is populated, only users holding that role can create projects. See Gateway General Security Settings.<br><a href=\"https://docs.inductiveautomation.com/docs/8.1/platform/security/gateway-general-security-settings#gateway-security-settings-table\">https://docs.inductiveautomation.com/docs/8.1/platform/security/gateway-general-security-settings#gateway-security-settings-table</a></p>\n<p><strong>Mitigation</strong><br>For more information, see the publication at the Inductive Automation Trust Center.<br><a href=\"https://security.inductiveautomation.com/?tcuUid=34477620-731d-4b70-b22b-9450f9a659a3\">https://security.inductiveautomation.com/?tcuUid=34477620-731d-4b70-b22b-9450f9a659a3</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/276.html\">CWE-276 Incorrect Default Permissions</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Christopher Lusk of North Echo Security Research reported this vulnerability to Inductive Automation.</li>\n<li>Elhussain Fathy (0xSphinx) independently reported this vulnerability and confirmed the fix.</li>\n<li>Inductive Automation reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-03</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-03</td>\n<td>1</td>\n<td>Initial Republication of Inductive Automation Trust Center update.</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n",
                "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-06",
                "image": "",
                "published": "Thu, 03 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "4297b86a0cc1359d12b139a4af3e55f2e3823050",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "Rockwell Automation ArmorStart LT",
            "summary": "View CSAF Summary Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page. The following versions of Rockwell Automation ArmorStart LT are affected: ArmorStart LT",
            "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-04",
            "image": "",
            "published": "2026-09-03T12:00:00+00:00",
            "score": 67,
            "color": "#ff5bd1",
            "raw": {
                "title": "Rockwell Automation ArmorStart LT",
                "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-04.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page.</strong></p>\n<p>The following versions of Rockwell Automation ArmorStart LT are affected:</p>\n<ul>\n<li>ArmorStart LT &lt;=v2.001 (CVE-2026-19471, CVE-2026-19472)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation ArmorStart LT</td>\n<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Allocation of Resources Without Limits or Throttling</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-19471</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Multiple stored cross-site scripting security issues exist within ArmorStart LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, allowing an attacker to inject malicious scripts that will be executed when other users access the affected page.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-19471\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation ArmorStart LT</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation ArmorStart LT: &lt;=v2.001</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Rockwell Automation has corrected this issue in firmware version v2.002, and encourages all users to update to the newest version.</p>\n<p><strong>Mitigation</strong><br>Users of the affected software who are not able to upgrade to one of the corrected versions should follow Rockwell Automation's security best practices.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information on this issue, see the Rockwell Automation security advisory at: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/79.html\">CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>6.9</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-19472</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service security issue exists within ArmorStart LT. The security issue stems from improper handling of a crafted HTTP PUT request sent to the embedded web server. This can result in a loss of web server availability.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-19472\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation ArmorStart LT</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation ArmorStart LT: &lt;=v2.001</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Rockwell Automation has corrected this issue in firmware version v2.002, and encourages all users to update to the newest version.</p>\n<p><strong>Mitigation</strong><br>Users of the affected software who are not able to upgrade to one of the corrected versions should follow Rockwell Automation's security best practices.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information on this issue, see the Rockwell Automation security advisory at: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/770.html\">CWE-770 Allocation of Resources Without Limits or Throttling</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-03</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-03</td>\n<td>1</td>\n<td>Initial Republication of Rockwell Automation security advisory.</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n",
                "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-04",
                "image": "",
                "published": "Thu, 03 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "1974e8bcb0c482ac04b15128954fdfe6c5d8bd8a",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)",
            "summary": "View CSAF Summary Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution systems. The Easergy MiCOM P30 is a family of multifunction protection and control relays designed for medium, high and extra high voltage electrical networks. The Easergy MiCOM P40 is a protection relay series for Medium Voltage, High Voltage and Extra High Voltage protection. The Easergy MiCOM C264 is a modular and compact substation or bay controller, smart RTU and MV one box solution The EcoStruxure Power Automation System Gateway (EPAS=GTW) is a scalable, interoperable, and rugged communication gateway that helps to remotely monitor and operate electrical processes The EcoStruxure Power Automation System User Interface (EPAS-UI) product is a…",
            "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-07",
            "image": "",
            "published": "2026-09-03T12:00:00+00:00",
            "score": 67,
            "color": "#ff5bd1",
            "raw": {
                "title": "Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)",
                "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-169-07.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution systems. The Easergy MiCOM P30 is a family of multifunction protection and control relays designed for medium, high and extra high voltage electrical networks. The Easergy MiCOM P40 is a protection relay series for Medium Voltage, High Voltage and Extra High Voltage protection. The Easergy MiCOM C264 is a modular and compact substation or bay controller, smart RTU and MV one box solution The EcoStruxure Power Automation System Gateway (EPAS=GTW) is a scalable, interoperable, and rugged communication gateway that helps to remotely monitor and operate electrical processes The EcoStruxure Power Automation System User Interface (EPAS-UI) product is an HMI SCADA designed for electrical networks and substations operations. The EcoStruxure Power Automation System Intelligent Power Management System and Fast Load Shedding (iPMFLS) is a range of solutions designed to overcome size and performances constraints. The EcoStruxure Power Operation (EPO) are an on-premises software offers that provides a single platform to monitor and control medium and lower power systems. The PowerLogic P5 is a medium voltage protection relay. The PowerLogic P7 is a protection and control platform designed for complex and advanced electrical network applications. The PowerLogic T300 is a modular platform for medium voltage and low voltage public distribution network management. The PowerLogic T500 is a control unit and RTU for substation automation. The Saitel DP RTU is a modular platform for medium voltage and low voltage public distribution and transmission network management. The EasyLogic T150 (formerly Saitel DR RTU) is a field device, offering a solid and powerful platform for data acquisition, communication, automation and IED integration for distribution and transmission networks, generation sector and railway. Failure to apply the fix provided below may risk session hijacking, which could result in malicious actors performing unauthorized operations within the affected system.</strong></p>\n<p>The following versions of Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A) are affected:</p>\n<ul>\n<li>Easergy MiCOM C264 vers:generic/&lt;=D7.33 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P139 vers:generic/&lt;=P139.678.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P437 vers:generic/&lt;=P437.678.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P439 vers:generic/&lt;=P439.678.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P532 vers:generic/&lt;=P532.678.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P539 vers:generic/&lt;=P539.678.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P631 vers:generic/&lt;=P631.678.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P632 vers:generic/&lt;=P632.678.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P633 vers:generic/&lt;=P633.678.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P634 vers:generic/&lt;=P634.678.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P633 P633.680.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P634 P634.680.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P138 vers:generic/&lt;=P138.677.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P436 vers:generic/&lt;=P436.677.701 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P438 vers:generic/&lt;=P438.677.701 (CVE-2026-4827)</li>\n<li>Easergy MiCOM P638 vers:generic/&lt;=P638.677.700 (CVE-2026-4827)</li>\n<li>Easergy MiCOM C434 vers:generic/&lt;=C434.679.700 (CVE-2026-4827)</li>\n<li>EcoStruxure Power Automation System Gateway (EPAS-GTW) vers:intdot/&lt;=6.4.616.200.100 (CVE-2026-4827)</li>\n<li>EcoStruxure Power Automation System User Interface (EPAS-UI) vers:intdot/&lt;=3.0.3 (CVE-2026-4827)</li>\n<li>EcoStruxure Power Operation vers:generic/&lt;=2022_CU6 (CVE-2026-4827)</li>\n<li>EcoStruxure Power Operation vers:generic/&lt;=2024_CU2 (CVE-2026-4827)</li>\n<li>iPMFLS vers:intdot/&lt;=64.2025.0.13 (CVE-2026-4827)</li>\n<li>PowerLogic P5 Protection Relay vers:intdot/&lt;=02.502.103 (CVE-2026-4827)</li>\n<li>PowerLogic P7 Protection and Control Platform vers:intdot/&lt;=02.002.002 (CVE-2026-4827)</li>\n<li>PowerLogic T300 vers:intdot/&lt;=2.9.4 (CVE-2026-4827)</li>\n<li>PowerLogic T500 vers:intdot/&lt;=11.08.02 (CVE-2026-4827)</li>\n<li>Saitel DP vers:intdot/&lt;=11.06.36 ()</li>\n<li>EasyLogic T150 (formerly Saitel DR) vers:intdot/&lt;=11.06.30 ()</li>\n<li>Easergy MiCOM C264 D7.34 ()</li>\n<li>Easergy C5 vers:intdot/&lt;=1.1.17 (CVE-2026-4827)</li>\n<li>Easergy C5 1.1.18 ()</li>\n<li>Easergy MiCOM P139 version P139.678.700 ()</li>\n<li>Easergy MiCOM P439 P439.678.700 ()</li>\n<li>Easergy MiCOM P539 P539.678.700 ()</li>\n<li>Easergy MiCOM P632 P632.678.700 ()</li>\n<li>Easergy MiCOM P633 P633.680.701 ()</li>\n<li>Easergy MiCOM P634 P634.680.701 ()</li>\n<li>Easergy MiCOM P633 P633.678.700 ()</li>\n<li>Easergy MiCOM P138 P138.677.701 ()</li>\n<li>Easergy MiCOM C434 C434.679.700 ()</li>\n<li>Saitel DR 11.06.31 ()</li>\n<li>EcoStruxure Power Automation System Gateway (EPAS-GTW) 6.4.610.500.101 ()</li>\n<li>EcoStruxure Power Automation Automation System User Interface (EPAS-UI) 3.0.4 ()</li>\n<li>EcoStruxure Power Operation 2022_CU7 ()</li>\n<li>EcoStruxure Power Operation (EPO) 2024_CU3 ()</li>\n<li>iPMFLS 64.2025.0.14 ()</li>\n<li>PowerLogic P5 Protection Relay 02.503.101 ()</li>\n<li>PowerLogic P7 Protection and Control Platform 02.003.001 ()</li>\n<li>PowerLogic T300 2.9.5 ()</li>\n<li>PowerLogic T500 11.08.03 ()</li>\n<li>Saitel DP 11.06.37 ()</li>\n<li>Easergy MiCOM P40 Series vers:all/* (CVE-2026-4827)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.3</td>\n<td>Schneider Electric</td>\n<td>Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products</td>\n<td>Insufficient Entropy</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Critical Manufacturing, Energy, Water and Wastewater</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>France</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-4827</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>CWE-331 Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the network can exploit weaknesses in session‑management protections.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-4827\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Schneider Electric</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Easergy MiCOM C264 Versions D7.33 and prior, Easergy MiCOM P139 version prior to P139.678.700, Easergy MiCOM P437 version prior to P437.678.700, Easergy MiCOM P439 version prior to P439.678.700, Easergy MiCOM P532 version prior to P532.678.700, Easergy MiCOM P539 version prior to P539.678.700, Easergy MiCOM P631 version prior to P631.678.700, Easergy MiCOM P632 version prior to P632.678.700, Easergy MiCOM P633 version prior to P633.678.700, Easergy MiCOM P634 version prior to P634.678.700, Easergy MiCOM P633 version P633.680.700, Easergy MiCOM P634 version P634.680.700 , Easergy MiCOM P138 version prior to P138.677.700, Easergy MiCOM P436 version prior to P436.677.701, Easergy MiCOM P438 version prior to P438.677.701, Easergy MiCOM P638 version prior to P638.677.700, Easergy MiCOM C434 version prior to C434.679.700, EcoStruxure Power Automation System Gateway (EPAS-GTW) Version 6.4.616.200.100 and prior, EcoStruxure Power Automation System User Interface (EPAS-UI) Version 3.0.3 and prior, EcoStruxure Power Operation (EPO) 2022 CU6 and prior, EcoStruxure Power Operation (EPO) 2024 CU2 and prior, iPMFLS Version 64.2025.0.13 and prior, PowerLogic P5 Protection Relay V02.502.103 and prior, PowerLogic P7 Protection and Control Platform V02.002.002 and prior, PowerLogic T300 Version 2.9.4 and prior, PowerLogic T500 Version 11.08.02 and prior, Easergy C5 Version 1.1.17 and prior, Easergy MiCOM P40 Series model numbers with Protocol Option bit as G, H or L and all firmware versions</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>fixed, known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Version D7.34 of MiCOM C264 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device. Reboot is required.</p>\n<p><strong>Vendor fix</strong><br>Version 1.1.18 of Easergy C5 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device. Reboot is required.</p>\n<p><strong>Vendor fix</strong><br>Version P139.678.700 Easergy MiCOM P139 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.</p>\n<p><strong>Vendor fix</strong><br>Version P439.678.700 Easergy MiCOM P439 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.</p>\n<p><strong>Vendor fix</strong><br>Version P539.678.700 Easergy MiCOM P539 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.</p>\n<p><strong>Vendor fix</strong><br>Version P632.678.700 Easergy MiCOM P632 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.</p>\n<p><strong>Vendor fix</strong><br>Version P633.678.700 Easergy MiCOM P633 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.</p>\n<p><strong>Vendor fix</strong><br>Version P634.680.701 Easergy MiCOM P634 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.</p>\n<p><strong>Vendor fix</strong><br>Version P633.680.701 Easergy MiCOM P633 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.</p>\n<p><strong>Vendor fix</strong><br>Version P138.677.701 Easergy MiCOM P138 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.</p>\n<p><strong>Vendor fix</strong><br>Version C434.679.700 Easergy MiCOM C434 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.</p>\n<p><strong>Vendor fix</strong><br>HUe Firmware version 11.06.31 includes a fix for this vulnerability and is available for download here: . Contact Schneider Electric’s Customer Care Center to download this software. A reboot is needed to complete the firmware upgrade.</p>\n<p><strong>Vendor fix</strong><br>Version 6.4.610.500.101 of EPAS Gateway includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this software.</p>\n<p><strong>Vendor fix</strong><br>Version 3.0.4 of EPAS-UI includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this software.</p>\n<p><strong>Vendor fix</strong><br>EPO 2022 CU 7 of EcoStruxure Power Operation includes a fix for this vulnerability and is available for download here:&nbsp;<br><a href=\"https://community.se.com/t5/EcoStruxure-Power-Operation/Power-Operation-2022-CU7-is-Now-Available/td-p/524787\">https://community.se.com/t5/EcoStruxure-Power-Operation/Power-Operation-2022-CU7-is-Now-Available/td-p/524787</a></p>\n<p>Reboot needed: yes</p>\n<p><strong>Vendor fix</strong><br>EPO 2024 CU 3 of EcoStruxure Power Operation includes a fix for this vulnerability and is available for download here:&nbsp;<br><a href=\"https://community.se.com/t5/EcoStruxure-Power-Operation/Power-Operation-2024-CU3-is-HERE/td-p/534769\">https://community.se.com/t5/EcoStruxure-Power-Operation/Power-Operation-2024-CU3-is-HERE/td-p/534769</a></p>\n<p>Reboot needed: yes</p>\n<p><strong>Vendor fix</strong><br>Version 64.2025.0.14 of iPMFLS includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.</p>\n<p><strong>Vendor fix</strong><br>Version V02.503.101 of PowerLogic P5 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this firmware.</p>\n<p><strong>Vendor fix</strong><br>Version V02.003.001 of PowerLogic P7 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this firmware.</p>\n<p><strong>Vendor fix</strong><br>Version 2.9.5 of PowerLogic T300 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this firmware. A reboot is needed to complete the firmware upgrade.</p>\n<p><strong>Vendor fix</strong><br>Version 11.08.03 of PowerLogic T500 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this firmware. A reboot is needed to complete the firmware upgrade.</p>\n<p><strong>Vendor fix</strong><br>CPU866e Firmware version 11.06.37 includes a fix for this vulnerability and is available for download. Contact Schneider Electric’s Customer Care Center to download this firmware. A reboot is needed to complete the firmware upgrade.</p>\n<p><strong>Mitigation</strong><br>Schneider Electric is establishing a remediation plan for all future versions of the following models of the Easergy MiCOM P30: P437 P532 P631 P634 P436 P438 P638 Future versions will include a fix for this vulnerability. We will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit:&nbsp;</p>\n<ul>\n<li>Ensure P30 operates within a physically or logically segmented internal network. Access to this network should be tightly controlled using standard security mechanisms such as firewalls, intrusion detection systems (IDS), and other relevant protective measures.&nbsp;</li>\n<li>Reduce the “Minimum inactivity period” using the CAE tool to shorten session timeout durations and minimize the risk of unauthorized access due to inactive sessions.</li>\n</ul>\n<p><strong>Mitigation</strong><br>Schneider Electric is establishing a remediation plan for a future version of the Easergy MiCOM P40 Series model numbers with Protocol Option bit as G, H or L. P_ 4_ _ _ _ _ G_ _ _ _ _ M P_ 4_ _ _ _ _ H_ _ _ _ _ M P_ 4_ _ _ _ _ L _ _ _ _ _ M P_ 4_ _ _ _ _ G_ _ _ _ _ L P_ 4_ _ _ _ _ H_ _ _ _ _ L P_ 4_ _ _ _ _ L _ _ _ _ _ L A future version will include a fix for this vulnerability. We will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit:&nbsp;</p>\n<ul>\n<li>Ensure P40 operates within a physically or logically segmented internal network. Access to this network should be tightly controlled using standard security mechanisms such as firewalls, intrusion detection systems (IDS), and other relevant protective measures.&nbsp;</li>\n<li>Reduce the “Minimum inactivity period” using the CAE tool to shorten session timeout durations and minimize the risk of unauthorized access due to inactive sessions.</li>\n</ul>\n<p><strong>Mitigation</strong><br>If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit:</p>\n<ul>\n<li>Ensure P30 operates within a physically or logically segmented internal network. Access to this network should be tightly controlled using standard security mechanisms such as firewalls, intrusion detection systems (IDS), and other relevant protective measures.&nbsp;</li>\n<li>Reduce the “Minimum inactivity period” using the CAE tool to shorten session timeout durations and minimize the risk of unauthorized access due to inactive sessions.</li>\n</ul>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/331.html\">CWE-331 Insufficient Entropy</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>An internal researcher of Schneider Electric reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>General Security Recommendations</h2>\n<p>We strongly recommend the following industry cybersecurity best practices. * Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network. * Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks. * Place all controllers in locked cabinets and never leave them in the “Program” mode. * Never connect programming software to any network other than the network intended for that device. * Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks. * Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation. * Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet. * When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices. For more information refer to the Schneider Electric [Recommended Cybersecurity Best Practices](https://www.se.com/us/en/download/document/7EN52-0390/) document.</p>\n<hr>\n<h2>For More Information</h2>\n<p>This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process. For further information related to cybersecurity in Schneider Electric's products, visit the company's cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp</p>\n<hr>\n<h2>LEGAL DISCLAIMER</h2>\n<p>THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS “NOTIFICATION”) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN “AS-IS” BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION</p>\n<hr>\n<h2>About Schneider Electric</h2>\n<p>Schneider's purpose is to create Impact by empowering all to make the most of our energy and resources, bridging progress and sustainability for all. We call this Life Is On. Our mission is to be the trusted partner in Sustainability and Efficiency. We are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart industries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep domain expertise, we provide integrated end-to-end lifecycle AI enabled Industrial IoT solutions with connected products, automation, software and services, delivering digital twins to enable profitable growth for our customers. We are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries to ensure proximity to our customers and stakeholders. We embrace diversity and inclusion in everything we do, guided by our meaningful purpose of a sustainable future for all. www.se.com</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Schneider Electric CPCERT SEVD-2026-132-02 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-05-12</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-05-12</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n<tr>\n<td>2026-06-18</td>\n<td>2</td>\n<td>Initial Republication of Schneider Electric CPCERT SEVD-2026-132-02</td>\n</tr>\n<tr>\n<td>2026-09-03</td>\n<td>3</td>\n<td>Update A - Revised the summary to reflect the affected products</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n",
                "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-07",
                "image": "",
                "published": "Thu, 03 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "d1dff7678734bfa65c6856e7ea29864a4a6e9cbb",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "OPCFoundation OPC UA LocalDiscoveryServer (LDS)",
            "summary": "View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected: UA-LDS-Installers",
            "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-01",
            "image": "",
            "published": "2026-09-03T12:00:00+00:00",
            "score": 67,
            "color": "#ff5bd1",
            "raw": {
                "title": "OPCFoundation OPC UA LocalDiscoveryServer (LDS)",
                "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands.</strong></p>\n<p>The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected:</p>\n<ul>\n<li>UA-LDS-Installers &lt;1.04.420 (CVE-2026-77477)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 4.6</td>\n<td>OPCFoundation</td>\n<td>OPCFoundation OPC UA LocalDiscoveryServer (LDS)</td>\n<td>Execution with Unnecessary Privileges</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Energy, Food and Agriculture, Water and Wastewater, Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-77477</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An attacker can intercept a high-privilege console window launched during installation of the LDS. The attacker must be able to launch an installer with elevated privileges and have access to the keyboard and display while the installation is taking place.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-77477\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>OPCFoundation OPC UA LocalDiscoveryServer (LDS)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>OPCFoundation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>OPCFoundation UA-LDS-Installers: &lt;1.04.420</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>OPCFoundation recommends users update to OPC UA LDS Installers 1.04.420 or later.</p>\n<p><strong>Mitigation</strong><br>For more information about this vulnerability and its mitigation, see the OPCFoundation security advisory.<br><a href=\"https://github.com/OPCFoundation/OPC-SecurityAdvisories/tree/latest/csaf/2026/009\">https://github.com/OPCFoundation/OPC-SecurityAdvisories/tree/latest/csaf/2026/009</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/250.html\">CWE-250 Execution with Unnecessary Privileges</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>4.6</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N\">CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>2.4</td>\n<td>LOW</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Lukas Schumaker of Rockwell Automation reported this vulnerability to OPCFoundation.</li>\n<li>OPCFoundation reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-03</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-03</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n",
                "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-01",
                "image": "",
                "published": "Thu, 03 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "2ea48b45cd7635d8c1c8bb3ba29625d1cf1b5764",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "Rockwell Automation ControlFLASH",
            "summary": "View CSAF Summary Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level. The following versions of Rockwell Automation ControlFLASH are affected: ControlFLASH",
            "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-03",
            "image": "",
            "published": "2026-09-03T12:00:00+00:00",
            "score": 67,
            "color": "#ff5bd1",
            "raw": {
                "title": "Rockwell Automation ControlFLASH",
                "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-03.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.</strong></p>\n<p>The following versions of Rockwell Automation ControlFLASH are affected:</p>\n<ul>\n<li>ControlFLASH &lt;=V15.07 (CVE-2026-12663)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.3</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation ControlFLASH</td>\n<td>Missing Authentication for Critical Function</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy, Water and Wastewater</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-12663</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A security issue exists within ControlFLASH, where the installer grants write permissions to the \"Everyone\" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-12663\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation ControlFLASH</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation ControlFLASH: &lt;=V15.07</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Rockwell Automation has corrected this issue in software version 15.08, and encourages all users to update to the newest version.</p>\n<p><strong>Mitigation</strong><br>Users of the affected software who are not able to upgrade to one of the corrected versions should implement the following mitigation:&nbsp;</p>\n<p>To protect the files, do the following steps to remove the Everyone group:&nbsp;</p>\n<ol>\n<li>Right-click the C:\\Program Files (x86)\\ControlFLASH\\0001 folder, and then select Properties.&nbsp;</li>\n<li>In the 0001 Properties dialog, select the Security tab, and then select Edit.&nbsp;</li>\n<li>In the Permissions for 0001 dialog, in Group or user names, select Everyone, and then select Remove.&nbsp;</li>\n<li>Select OK.</li>\n</ol>\n<p><strong>Mitigation</strong><br>If the mitigation above cannot be implemented, Rockwell Automation recommends following their security best practices.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information on this issue, see the Rockwell Automation security advisory at: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-03</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-03</td>\n<td>1</td>\n<td>Initial Republication of Rockwell Automation security advisory.</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n",
                "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-03",
                "image": "",
                "published": "Thu, 03 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "720683aa35653025571fd187845fa7f3b75c0726",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "Rockwell Automation 1756-ENBT Module",
            "summary": "View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1756-ENBT Module Improper Check for Unusual or Exceptional Conditions Background Critical Infrastructure Sectors: Critical Manufacturing, Food and Agriculture, Transportation Systems, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2025-10478 A denial-of-service security issue exists in the Rockwell Automation 1756-ENBT module which is a ControlLogix EtherNet/IP bridge that enables communication between Logix 5000 controllers and Ethernet devices. An attacker could explo…",
            "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-05",
            "image": "",
            "published": "2026-09-03T12:00:00+00:00",
            "score": 67,
            "color": "#ff5bd1",
            "raw": {
                "title": "Rockwell Automation 1756-ENBT Module",
                "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-05.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover.</strong></p>\n<p>The following versions of Rockwell Automation 1756-ENBT Module are affected:</p>\n<ul>\n<li>1756-ENBT module vers:all/* (CVE-2025-10478)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>Rockwell Automation</td>\n<td>Rockwell Automation 1756-ENBT Module</td>\n<td>Improper Check for Unusual or Exceptional Conditions</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Food and Agriculture, Transportation Systems, Water and Wastewater</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-10478</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A denial-of-service security issue exists in the Rockwell Automation 1756-ENBT module which is a ControlLogix EtherNet/IP bridge that enables communication between Logix 5000 controllers and Ethernet devices. An attacker could exploit this vulnerability by sending a crafted CIP packet, causing the module to crash. The device requires a restart to recover.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-10478\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Rockwell Automation 1756-ENBT Module</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Rockwell Automation</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Rockwell Automation 1756-ENBT module: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Rockwell Automation recommends that users upgrade to 1756-EN2T or 1756-EN4TR. Users who are not able to upgrade should use Rockwell Automation's security best practices.<br><a href=\"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight\">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>\n<p><strong>Mitigation</strong><br>For more information on this issue, see the corresponding Rockwell Automation security advisory.<br><a href=\"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html\">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/754.html\">CWE-754 Improper Check for Unusual or Exceptional Conditions</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Rockwell Automation reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-03</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-03</td>\n<td>1</td>\n<td>Initial Republication of Rockwell Automation security advisory.</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n",
                "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-05",
                "image": "",
                "published": "Thu, 03 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "82a9f3fbf51af40d324ce5eed54b939e4897a511",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "Pyramid Solutions NetStaX EtherNet/IP Stack",
            "summary": "View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed. The following versions of Pyramid Solutions NetStaX EtherNet/IP Stack are affected: EtherNet/IP Adapter DLL Kit (EIPA) EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE) EtherNet/IP Adapter Development Kit (EADK) EtherNet/IP Adapter Development Kit with CIP Security (EADK-SECURE) EtherNet/IP Scanner DLL Kit (EIPS) EtherNet/IP Scanner DLL Kit with CIP Security (EIPS-SECURE) EtherNet/IP Scanner Development Kit (ESDK) EtherNet/IP Scanner Development Kit with CIP Security (ESDK-SECURE) CVSS Vendor Equipment Vulnerabilities v3 9.8 Pyramid Solutions Pyramid Solutions NetStaX EtherNet/IP Stack Stack-based Buffer Overflow Background C…",
            "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-07",
            "image": "",
            "published": "2026-09-03T12:00:00+00:00",
            "score": 67,
            "color": "#ff5bd1",
            "raw": {
                "title": "Pyramid Solutions NetStaX EtherNet/IP Stack",
                "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-07.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.</strong></p>\n<p>The following versions of Pyramid Solutions NetStaX EtherNet/IP Stack are affected:</p>\n<ul>\n<li>EtherNet/IP Adapter DLL Kit (EIPA)</li>\n<li>EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE)</li>\n<li>EtherNet/IP Adapter Development Kit (EADK)</li>\n<li>EtherNet/IP Adapter Development Kit with CIP Security (EADK-SECURE)</li>\n<li>EtherNet/IP Scanner DLL Kit (EIPS)</li>\n<li>EtherNet/IP Scanner DLL Kit with CIP Security (EIPS-SECURE)</li>\n<li>EtherNet/IP Scanner Development Kit (ESDK)</li>\n<li>EtherNet/IP Scanner Development Kit with CIP Security (ESDK-SECURE)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.8</td>\n<td>Pyramid Solutions</td>\n<td>Pyramid Solutions NetStaX EtherNet/IP Stack</td>\n<td>Stack-based Buffer Overflow</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy, Water and Wastewater, Chemical</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-78012</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-78012\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Pyramid Solutions NetStaX EtherNet/IP Stack</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Pyramid Solutions</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Pyramid Solutions EtherNet/IP Adapter DLL Kit (EIPA): &lt;v5.6.1, Pyramid Solutions EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE): &lt;v5.6.1, Pyramid Solutions EtherNet/IP Adapter Development Kit (EADK): &lt;v5.6.1, Pyramid Solutions EtherNet/IP Adapter Development Kit with CIP Security (EADK-SECURE): &lt;v5.6.1, Pyramid Solutions EtherNet/IP Scanner DLL Kit (EIPS): &lt;v5.6.1, Pyramid Solutions EtherNet/IP Scanner DLL Kit with CIP Security (EIPS-SECURE): &lt;v5.6.1, Pyramid Solutions EtherNet/IP Scanner Development Kit (ESDK): &lt;v5.6.1, Pyramid Solutions EtherNet/IP Scanner Development Kit with CIP Security (ESDK-SECURE): &lt;v5.6.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>NetStaX v5.6.1 addresses this issue with multiple layers of protection, including a compile-time assertion, a runtime payload-size check, and clearer documentation of the relationships between packet and buffer-size constants.<br><a href=\"https://pyramidsolutions.com/my-account/\">https://pyramidsolutions.com/my-account/</a></p>\n<p><strong>Mitigation</strong><br>For more information, see the Pyramid Solutions blog post \"NetStaX v5.6.1: Protecting Against Silent Buffer Overflow in Ethernet/IP Stack Explicit Messages\".<br><a href=\"https://pyramidsolutions.com/netstax-v-5-6-1-protecting-against-silent-buffer-overflow-in-ethernet-ip-stack-explicit-messages/\">https://pyramidsolutions.com/netstax-v-5-6-1-protecting-against-silent-buffer-overflow-in-ethernet-ip-stack-explicit-messages/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/121.html\">CWE-121 Stack-based Buffer Overflow</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Pyramid Solutions reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-03</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-03</td>\n<td>1</td>\n<td>Initial Republication of Pyramid Solutions blog publication.</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n",
                "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-07",
                "image": "",
                "published": "Thu, 03 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "f1d337874370ede8df9e3abcd39522caa316899e",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "Preparing for the Post-Quantum Era: A Call to Action",
            "summary": "CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to protect sensitive data, authentication systems, and critical assets from emerging quantum computing threats.   The G7 Cyber Security Working Group’s call to action outlines five priorities for a successful transition to PQC: Raising awareness of quantum risks and the importance of PQC; Developing national strategies that support PQC adoption and integration; Advancing research and development for quantum-safe technologies; Fostering public-private partnerships to share expertise and resources; and Integrating PQC into cybersecurity requirements and procurement processes.  Please share your thoughts! We welcome your feedback. CISA PRODUCT SURVEY",
            "url": "https://www.cisa.gov/resources-tools/resources/preparing-post-quantum-era-call-action",
            "image": "",
            "published": "2026-09-03T12:00:00+00:00",
            "score": 67,
            "color": "#ff5bd1",
            "raw": {
                "title": "Preparing for the Post-Quantum Era: A Call to Action",
                "summary": "<p>CISA and the Group of Seven (G7) Cyber Security Working Group released <a href=\"https://urldefense.us/v3/__https:/cyber.gouv.fr/en/publications/jointly-led-international-publications/preparing-for-the-post-quantum-era-a-call-to-action/__;!!BClRuOV5cvtbuNI!A4T2ayZfcpa7J25BSkxtB9A-AHREvqT8FQmzhRjVarx8w3J-Vs-CBcKQcElRqsqsZqtIztYiIMY01My3HFmonToxreu7Z35ka6L8naw5xg$\" target=\"_blank\"><em>Preparing for the Post-Quantum Era: A Call to Action</em></a><em> </em>highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to protect sensitive data, authentication systems, and critical assets from emerging quantum computing threats. &nbsp;</p>\n<p>The G7 Cyber Security Working Group’s call to action outlines five priorities for a successful transition to PQC:</p>\n<ul>\n<li>Raising awareness of quantum risks and the importance of PQC;</li>\n<li>Developing national strategies that support PQC adoption and integration;</li>\n<li>Advancing research and development for quantum-safe technologies;</li>\n<li>Fostering public-private partnerships to share expertise and resources; and</li>\n<li>Integrating PQC into cybersecurity requirements and procurement processes.&nbsp;</li>\n</ul>\n<div class=\"c-text-cta\">\n<div class=\"l-constrain c-text-cta__inner\">\n<div class=\"c-text-cta__content\">\n<h2>Please share your thoughts!</h2>\n<div class=\"c-text-cta__summary\">\n<p>We welcome your feedback.</p>\n</div>\n<p><a class=\"c-button c-button--on-dark\" href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_9n4TtB8uttUPaM6?product=https://www.cisa.gov/resources-tools/resources/preparing-post-quantum-era-call-action\">CISA PRODUCT SURVEY</a></p>\n</div>\n</div>\n</div>\n",
                "url": "https://www.cisa.gov/resources-tools/resources/preparing-post-quantum-era-call-action",
                "image": "",
                "published": "Thu, 03 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "50984a512b44b98755d87672fe5c901565b703a6",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "Tycon Systems TPDIN-Monitor-WEB2 (Update A)",
            "summary": "View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected: TPDIN-Monitor-WEB2",
            "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-01",
            "image": "",
            "published": "2026-09-03T12:00:00+00:00",
            "score": 67,
            "color": "#ff5bd1",
            "raw": {
                "title": "Tycon Systems TPDIN-Monitor-WEB2 (Update A)",
                "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.</strong></p>\n<p>The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected:</p>\n<ul>\n<li>TPDIN-Monitor-WEB2 &lt;2.4.5 (CVE-2026-61884, CVE-2026-55985)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.8</td>\n<td>Tycon Systems</td>\n<td>Tycon Systems TPDIN-Monitor-WEB2</td>\n<td>Missing Authentication for Critical Function, Cleartext Storage of Sensitive Information</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-61884</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The device ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without requiring any login. An attacker with network access to such a unit can reach full device controls, including power relay management, device reboot, remote access service configuration, and network settings, which could allow disruption of connected infrastructure or physical damage to equipment.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-61884\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Tycon Systems TPDIN-Monitor-WEB2 (Update A)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Tycon Systems</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Tycon Systems TPDIN-Monitor-WEB2: &lt;2.4.5</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Tycon Systems has released firmware 2.4.5, which resolves this vulnerability by requiring an administrator username and password to be set before the web interface is served. Further inquiries can be directed to security@tyconsystems.com.</p>\n<p><strong>Mitigation</strong><br>Tycon Systems recommends setting an administrative username and strong password on the Network Configuration page and confirming in a private browser window that a login is required, for units still running firmware 2.4.4 or earlier. Repeat this after any factory reset.</p>\n<p><strong>Mitigation</strong><br>Tycon Systems recommends not exposing the web interface to the Internet, as it is HTTP only. The unit should be kept on a private network, behind a firewall or VPN.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>9.3</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-55985</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The device's web management interface stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-55985\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Tycon Systems TPDIN-Monitor-WEB2 (Update A)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Tycon Systems</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Tycon Systems TPDIN-Monitor-WEB2: &lt;2.4.5</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Tycon Systems has released firmware 2.4.5, which resolves this vulnerability by removing cleartext credentials from the web interface response. Further inquiries can be directed to security@tyconsystems.com.</p>\n<p><strong>Mitigation</strong><br>Tycon Systems recommends changing any factory-default SNMP community strings and the Telnet password if they were left at shipped values. Leave Telnet disabled unless required.</p>\n<p><strong>Mitigation</strong><br>Tycon Systems recommends using a dedicated mail account for device alerts, rather than an account also used for other sensitive purposes, to limit exposure if credentials are compromised.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/312.html\">CWE-312 Cleartext Storage of Sensitive Information</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>4.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Abdiwelli Guled reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-07-21</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-07-21</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n<tr>\n<td>2026-09-03</td>\n<td>2</td>\n<td>Updated affected version range and vulnerability details based on vendor input.</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n",
                "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-01",
                "image": "",
                "published": "Thu, 03 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "e6fc737cc6091a0b1aea8a19baf0c6d5b1311039",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "Tycon Systems TPDIN-Monitor-WEB3",
            "summary": "View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected: TPDIN-Monitor-WEB3",
            "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-08",
            "image": "",
            "published": "2026-09-03T12:00:00+00:00",
            "score": 67,
            "color": "#ff5bd1",
            "raw": {
                "title": "Tycon Systems TPDIN-Monitor-WEB3",
                "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-08.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information.</strong></p>\n<p>The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected:</p>\n<ul>\n<li>TPDIN-Monitor-WEB3 &lt;=2.2.9 (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.8</td>\n<td>Tycon Systems</td>\n<td>Tycon Systems TPDIN-Monitor-WEB3</td>\n<td>Use of Hard-coded Credentials, Cross-Site Request Forgery (CSRF), Missing Authorization</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-77847</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Use of Hard-coded Credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-77847\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Tycon Systems TPDIN-Monitor-WEB3</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Tycon Systems</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Tycon Systems TPDIN-Monitor-WEB3: &lt;=2.2.9</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Tycon Systems has released TPDIN-Monitor-WEB3 Firmware v2.4.2.</p>\n<p><strong>Mitigation</strong><br>Units already running v2.4.2, for subsequent updates (signed container):&nbsp;<br><a href=\"https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw\">https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw</a></p>\n<p><strong>Mitigation</strong><br>All units currently in the field, including the v2.2.9 covered by this report (legacy Intel HEX):&nbsp;<br><a href=\"https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex\">https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex</a></p>\n<p><strong>Mitigation</strong><br>A unit running v2.2.9 installs the .hex build directly and arrives at v2.4.2 in a single step; no intermediate version is required. The signed .tfw container cannot be read by a v2.2.9 updater, which accepts only Intel HEX, so the .hex artifact is the one every deployed unit needs.</p>\n<p><strong>Mitigation</strong><br>For more information, contact Tycon Systems:&nbsp;<br><a href=\"https://www.tyconsystems.com/contact\">https://www.tyconsystems.com/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/798.html\">CWE-798 Use of Hard-coded Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-82712</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Cross-Site Request Forgery vulnerability. This could allow an attacker to perform state changing operations on the device.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-82712\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Tycon Systems TPDIN-Monitor-WEB3</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Tycon Systems</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Tycon Systems TPDIN-Monitor-WEB3: &lt;=2.2.9</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Tycon Systems has released TPDIN-Monitor-WEB3 Firmware v2.4.2.</p>\n<p><strong>Mitigation</strong><br>Units already running v2.4.2, for subsequent updates (signed container):&nbsp;<br><a href=\"https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw\">https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw</a></p>\n<p><strong>Mitigation</strong><br>All units currently in the field, including the v2.2.9 covered by this report (legacy Intel HEX):&nbsp;<br><a href=\"https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex\">https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex</a></p>\n<p><strong>Mitigation</strong><br>A unit running v2.2.9 installs the .hex build directly and arrives at v2.4.2 in a single step; no intermediate version is required. The signed .tfw container cannot be read by a v2.2.9 updater, which accepts only Intel HEX, so the .hex artifact is the one every deployed unit needs.</p>\n<p><strong>Mitigation</strong><br>For more information, contact Tycon Systems:&nbsp;<br><a href=\"https://www.tyconsystems.com/contact\">https://www.tyconsystems.com/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/352.html\">CWE-352 Cross-Site Request Forgery (CSRF)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-82684</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-82684\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Tycon Systems TPDIN-Monitor-WEB3</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Tycon Systems</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Tycon Systems TPDIN-Monitor-WEB3: &lt;=2.2.9</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Tycon Systems has released TPDIN-Monitor-WEB3 Firmware v2.4.2.</p>\n<p><strong>Mitigation</strong><br>Units already running v2.4.2, for subsequent updates (signed container):&nbsp;<br><a href=\"https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw\">https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw</a></p>\n<p><strong>Mitigation</strong><br>All units currently in the field, including the v2.2.9 covered by this report (legacy Intel HEX):&nbsp;<br><a href=\"https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex\">https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex</a></p>\n<p><strong>Mitigation</strong><br>A unit running v2.2.9 installs the .hex build directly and arrives at v2.4.2 in a single step; no intermediate version is required. The signed .tfw container cannot be read by a v2.2.9 updater, which accepts only Intel HEX, so the .hex artifact is the one every deployed unit needs.</p>\n<p><strong>Mitigation</strong><br>For more information, contact Tycon Systems:&nbsp;<br><a href=\"https://www.tyconsystems.com/contact\">https://www.tyconsystems.com/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/862.html\">CWE-862 Missing Authorization</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</a></td>\n</tr>\n<tr>\n<td>4.0</td>\n<td>8.6</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N\">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Abdiwelli Guled reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-09-03</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-09-03</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n",
                "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-08",
                "image": "",
                "published": "Thu, 03 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "cae2c0a59d4693e4e5f702ea4ca7d83f535f0ce0",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "Communicating Under Pressure: Best Practices for Service Providers",
            "summary": "Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create disruption and societal panic even without speculation from end users and the public as added factors. Outages at one organization may cascade across interconnected systems, increasing uncertainty and alarm. The guidance emphasizes clarity, accountability, and transparency as core principles and details key elements of effective crisis messaging to inform affected stakeholders and the public while aligning with legal requirements, operational security, law enforcement, and containment efforts.  CISA’s CI Fortify …",
            "url": "https://www.cisa.gov/resources-tools/resources/communicating-under-pressure-best-practices-service-providers",
            "image": "",
            "published": "2026-09-02T12:00:00+00:00",
            "score": 67,
            "color": "#ff5bd1",
            "raw": {
                "title": "Communicating Under Pressure: Best Practices for Service Providers",
                "summary": "<p>Developed by CISA, the Federal Bureau of Investigation, and international partners, this <a href=\"https://www.cisa.gov/sites/default/files/2026-09/joint-guidance-communicating-under-pressure-508c.pdf\" title=\"Communicating Under Pressure: Best Practices for Service Providers\">guidance</a> describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create disruption and societal panic even without speculation from end users and the public as added factors. Outages at one organization may cascade across interconnected systems, increasing uncertainty and alarm. The guidance emphasizes clarity, accountability, and transparency as core principles and details key elements of effective crisis messaging to inform affected stakeholders and the public while aligning with legal requirements, operational security, law enforcement, and containment efforts.&nbsp;</p>\n<p>CISA’s <a href=\"https://www.cisa.gov/topics/industrial-control-systems/ci-fortify\">CI Fortify</a> initiative provides information and resources that help critical infrastructure organizations prepare to isolate and recover vital OT systems during a major cyber incident or crisis. Changes in service availability, whether from outages or isolation as a defensive strategy, require transparent and ongoing communication to help end users minimize operational impact, limit speculation, and preserve trust. For emergency planning purposes, critical infrastructure owners and operators should assume that telecommunications services may be disrupted or otherwise unreliable, making it crucial for organizations to have crisis communications plans in place that integrate backup communication methods and understand the type of communication they should expect from their service providers.</p>\n",
                "url": "https://www.cisa.gov/resources-tools/resources/communicating-under-pressure-best-practices-service-providers",
                "image": "",
                "published": "Wed, 02 Sep 26 12:00:00 +0000"
            }
        },
        {
            "id": "cd540d0ef53df9f905400c8163c52c13a349161c",
            "source_id": "cisa_advisories",
            "source": "CISA Cybersecurity Advisories",
            "category": "security",
            "engine": "rss",
            "title": "CISA Adds Seven Known Exploited Vulnerabilities to Catalog",
            "summary": "CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability  CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability  CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability  CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability  CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability  CVE-2026-83548 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability  CVE-2026-83549 SonicWall SMA1000 Appliances OS Command Injection Vulnerability  These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.  Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerab…",
            "url": "https://www.cisa.gov/news-events/alerts/2026/09/02/cisa-adds-seven-known-exploited-vulnerabilities-catalog",
            "image": "",
            "published": "2026-09-02T12:00:00+00:00",
            "score": 67,
            "color": "#ff5bd1",
            "raw": {
                "title": "CISA Adds Seven Known Exploited Vulnerabilities to Catalog",
                "summary": "<p>CISA has added seven new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p>\n<div class=\"ListContainerWrapper SCXW190820602 BCX8\">\n<ul type=\"disc\">\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-9586\" target=\"_blank\"><u>CVE-2026-9586</u></a> Sangoma Switchvox SQL Injection Vulnerability&nbsp;</li>\n</ul>\n</div>\n<div class=\"ListContainerWrapper SCXW190820602 BCX8\">\n<ul type=\"disc\">\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-48710\" target=\"_blank\"><u>CVE-2026-48710</u></a> Kludex Starlette HTTP Request/Response Smuggling Vulnerability&nbsp;</li>\n</ul>\n</div>\n<div class=\"ListContainerWrapper SCXW190820602 BCX8\">\n<ul type=\"disc\">\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-49869\" target=\"_blank\"><u>CVE-2026-49869</u></a> Kestra OSS OS Command Injection Vulnerability&nbsp;</li>\n</ul>\n</div>\n<div class=\"ListContainerWrapper SCXW190820602 BCX8\">\n<ul type=\"disc\">\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-59822\" target=\"_blank\"><u>CVE-2026-59822</u></a> BerriAI LiteLLM Improper Authentication Vulnerability&nbsp;</li>\n</ul>\n</div>\n<div class=\"ListContainerWrapper SCXW190820602 BCX8\">\n<ul type=\"disc\">\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-82329\" target=\"_blank\"><u>CVE-2026-82329</u></a> JFrog Artifactory Improper Authentication Vulnerability&nbsp;</li>\n</ul>\n</div>\n<div class=\"ListContainerWrapper SCXW190820602 BCX8\">\n<ul type=\"disc\">\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-83548\" target=\"_blank\"><u>CVE-2026-83548</u></a> SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability&nbsp;</li>\n</ul>\n</div>\n<div class=\"ListContainerWrapper SCXW190820602 BCX8\">\n<ul type=\"disc\">\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-83549\" target=\"_blank\"><u>CVE-2026-83549</u></a> SonicWall SMA1000 Appliances OS Command Injection Vulnerability&nbsp;</li>\n</ul>\n<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW211148847 BCX8\">\n<p><a href=\"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk\"><u>Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</u></a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW211148847 BCX8\">\n<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\"><u>KEV Catalog vulnerabilities</u></a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities\" target=\"_blank\"><u>specified criteria</u></a>.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW211148847 BCX8\">\n<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s <a class=\"ext\" href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w\" target=\"_blank\"><u>KEV Nomination Form</u></a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&nbsp;</p>\n</div>\n",
                "url": "https://www.cisa.gov/news-events/alerts/2026/09/02/cisa-adds-seven-known-exploited-vulnerabilities-catalog",
                "image": "",
                "published": "Wed, 02 Sep 26 12:00:00 +0000"
            }
        }
    ],
    "stored": 0,
    "ai": {
        "enriched": false,
        "stored": 0
    },
    "health": [
        {
            "id": "cisa_advisories",
            "name": "CISA Cybersecurity Advisories",
            "engine": "rss",
            "category": "security",
            "ok": true,
            "error": "",
            "ms": 153,
            "count": 25,
            "cached_at": "2026-09-12T21:20:14+00:00"
        }
    ]
}