Sunday
2026-09-20Your source for daily security alerts from some of the best experts in the world.
Find the problems, secure your systems now!
Get these alerts in your inbox every morning. Subscribe
CONTENTS
MSRC Unclassified ( 200 )
MS-ISAC Cybersecurity Advisory
TLDR InfoSec
Hacker News ( 29 )
Check Point Research
Cisco Talos ( 2 )
Bleeping Computer ( 15 )
CISA ( 8 )
Cisco Advisories ( 9 )
DataBreaches.net ( 10 )
CVEMon Intruder ( 10 )
Graham Cluley
Hacking Lab ( 3 )
Schneier on Security ( 3 )
Securelist
Talos – Vulnerability Reports ( 2 )
WeLiveSecurity ( 2 )
Zero Day Initiative-Published ( 5 )
Veeam ( 4 )
MSRC Unclassified
09/18 TOC Mariner – CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP…
09/19 TOC Mariner – Assertion failure in the DNS stub resolver with a long searc…
09/19 TOC Mariner – net/sched: fq_codel: clamp default quantum and mtu CVE-2026-…
09/19 TOC Mariner – Bluetooth: MSFT: validate evt_prefix_len against the respons…
09/19 TOC Mariner – xfrm: Fix skb double-free in xfrm_dev_direct_output() CVE-20…
09/19 TOC Mariner – arm64: ptrace: Keep ‘orig_x0’ in-sync with x0 on syscall ent…
09/19 TOC Mariner – RDMA/ipoib: Drain RCU callbacks during module teardown CVE-2…
09/19 TOC Mariner – usb: gadget: aspeed_udc: check endpoint DMA allocation CVE-2…
09/19 TOC Mariner – cgroup/cpuset: Make nr_deadline_tasks an atomic_t CVE-2026-9…
09/19 TOC Mariner – erofs: fix interlaced ztailpacking pclusters CVE-2026-90161
09/19 TOC Mariner – smb: server: fix leak of ksmbd_ipc_login_request_ext() retur…
09/19 TOC Mariner – misc: bcm-vk: Use acquire/release for msgq_inited CVE-2026-9…
09/19 TOC Mariner – ASoC: rt700-sdw: always drain jack work on remove CVE-2026-9…
09/19 TOC Mariner – NFSv4/pnfs: key the data server cache on the NFS version CVE…
09/19 TOC Mariner – OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, b…
09/19 TOC Mariner – firmware: arm_scmi: Fix requested device removal race CVE-20…
09/19 TOC Mariner – OpenTelemetry-Go: BatchProcessor can busy-spin when export b…
09/19 TOC Mariner – drm/sun4i: tcon: Drop TCON TOP device reference CVE-2026-902…
09/19 TOC Mariner – scsi: ufs: debugfs: Reserve space for a string terminator CV…
09/19 TOC Mariner – btrfs: check if root is readonly when setting posix acl CVE-…
09/19 TOC Mariner – HID: roccat: bound device-supplied profile index CVE-2026-93…
09/19 TOC Mariner – module/dups: Fix use-after-free in kmod_dup_req lifetime han…
09/19 TOC Mariner – swiotlb: Preserve allocation virtual address for dynamic poo…
09/19 TOC Mariner – wifi: mt76: mt7915: unwind state on add_interface failure CV…
09/19 TOC Mariner – bpf: Reject rdonly/rdwr_buf_size kfunc arguments that exceed…
09/19 TOC Mariner – net/sched: fq_pie: clamp default quantum to avoid signed ove…
09/19 TOC Mariner – tty: clear cdev pointer after cdev_add() failure CVE-2026-90…
09/19 TOC Mariner – rapidio: clear mport->net when rio_add_net() fails CVE-2026-…
09/19 TOC Mariner – ksmbd: defer publishing granted locks to prevent UAF/double-…
09/19 TOC Mariner – cxl/region: Fix use-after-free in find_pos_and_ways() error …
09/19 TOC Mariner – sunrpc: xprtsock: annotate shared socket callbacks with READ…
09/19 TOC Mariner – Bluetooth: L2CAP: fix race l2cap_sock_cleanup_listen() vs. p…
09/19 TOC Mariner – bpf, cgroup: Fix invalid storage access after __cgroup_bpf_a…
09/19 TOC Mariner – RDMA/core: Fix potential use after free in counter_release()…
09/19 TOC Mariner – RDMA/siw: Fix use-after-free in siw_accept() CVE-2026-90292
09/19 TOC Mariner – platform/x86: dell-wmi-base: Fix handling of ultra performan…
09/19 TOC Mariner – platform/surface: acpi-notify: Check ACPI companion before u…
09/19 TOC Mariner – bpf: Reject writes through untrusted BTF pointers CVE-2026-9…
09/19 TOC Mariner – drm/msm: Only fini scheduler after successful init CVE-2026-…
09/19 TOC Mariner – net/sched: sch_teql: restore skb->dev on the slave failure p…
09/19 TOC Mariner – wifi: mt76: mt7996: validate RX band_idx before dereferencin…
09/19 TOC Mariner – netfilter: nft_ct: move custom expectation support to helper…
09/19 TOC Mariner – crypto: atmel-ecc – reject hardware ECDH without a public ke…
09/19 TOC Mariner – OpenTelemetry-Go: Exporter config logging may leak endpoint …
09/19 TOC Mariner – i3c: master: Fix use-after-free of master->this CVE-2026-932…
09/19 TOC Mariner – crypto: keembay – Initialize completion before requesting IR…
09/19 TOC Mariner – RDMA/srp: fix heap information leak on a truncated SRP_CRED_…
09/19 TOC Mariner – BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution…
09/19 TOC Mariner – net/smc: free pending qentry in smc_llc_flow_stop() before m…
09/19 TOC Mariner – misc: sgi-gru: remove interrupt-context page-table walks CVE…
09/19 TOC Mariner – i3c: master: Fix recursive locking during device registratio…
09/19 TOC Mariner – net: sparx5: fix sleep in atomic context in MAC table access…
09/19 TOC Mariner – rtc: pcf8563: fix clock provider leak on unbind CVE-2026-901…
09/19 TOC Mariner – firmware_loader: do not queue completed sysfs fallback reque…
09/19 TOC Mariner – RDMA/erdma: Fix CEQ tasklet use-after-free on removal CVE-20…
09/19 TOC Mariner – smack: fix incorrect task context in smack_msg_queue_msgrcv …
09/19 TOC Mariner – netfilter: nf_tables: move hardware offload step after build…
09/19 TOC Mariner – irqchip/renesas-rzg2l: Fix loss of interrupt CVE-2026-90124
09/19 TOC Mariner – RDMA/core: Fix potential use after free in ib_destroy_srq_us…
09/19 TOC Mariner – firmware: qcom: scm: Fix NULL dereference in IRQ handler bef…
09/19 TOC Mariner – smb/server: fix null-ptr-deref in ksmbd_ipc_tree_connect_req…
09/19 TOC Mariner – riscv, bpf: Fix memory leak in bpf_jit_free CVE-2026-92519
09/19 TOC Mariner – nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state m…
09/19 TOC Mariner – ACPI: processor: validate MADT IOAPIC entry bounds CVE-2026-…
09/19 TOC Mariner – RDMA/nldev: validate dynamic counter attribute length CVE-20…
09/19 TOC Mariner – wifi: mt76: mt7921: Add PCIe AER handler support to prevent …
09/19 TOC Mariner – firmware: arm_scmi: Unregister device notifier before IDR te…
09/19 TOC Mariner – Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prev…
09/19 TOC Mariner – md/raid5: round bitmap stripes with sector division CVE-2026…
09/19 TOC Mariner – fs/resctrl: Fix UAF from worker threads when domains are rem…
09/19 TOC Mariner – ocfs2: validate inline xattrs during inode block validation …
09/19 TOC Mariner – power: supply: sc2731_charger: cancel work on remove CVE-202…
09/19 TOC Mariner – drm/v3d: Clear queue->active_job when v3d_fence_create() fai…
09/19 TOC Mariner – phy: qcom: qmp-usb: Fix possible NULL-deref on early runtime…
09/19 TOC Mariner – net/sched: act_skbmod: fix length calculations and avoid inv…
09/19 TOC Mariner – ext4: fix buffer_head leak in ext4_init_orphan_info CVE-2026…
09/19 TOC Mariner – ksmbd: free preauth sessions on connection teardown CVE-2026…
09/19 TOC Mariner – null_blk: free global tag_set on init error path CVE-2026-90…
09/19 TOC Mariner – net/rds: use wq_has_sleeper() in rds_cong_map_updated() CVE-…
09/19 TOC Mariner – misc: ad525x_dpot: use driver core groups for sysfs files CV…
09/19 TOC Mariner – net/sched: act_ife: Only operate on Ethernet frames CVE-2026…
09/19 TOC Mariner – cpufreq: imx6q: fix out-of-bounds write when probed more tha…
09/19 TOC Mariner – blk-iocost: clear delay state when freeing policy data CVE-2…
09/19 TOC Mariner – RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Co…
09/19 TOC Mariner – drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop an…
09/19 TOC Mariner – net/smc: free stashed qentry before overwrite in REQ_ADD_LIN…
09/19 TOC Mariner – power: supply: isp1704_charger: cancel work on remove CVE-20…
09/19 TOC Mariner – phy: qcom: qmp-usb-legacy: Fix possible NULL-deref on early …
09/19 TOC Mariner – clk: qcom: gdsc: tear down per-domain genpds in gdsc_unregis…
09/19 TOC Mariner – net/sched: hhf: clamp quantum before hhf_change() to avoid o…
09/19 TOC Mariner – RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to…
09/19 TOC Mariner – nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed() CVE-2026…
09/19 TOC Mariner – firmware: arm_scmi: Clean up channels on setup failure CVE-2…
09/19 TOC Mariner – NFSv4: Fix incorrect argument passed to nfs4_delete_lease() …
09/19 TOC Mariner – samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-dire…
09/19 TOC Mariner – HID: synchronize input before cleaning up a failed probe CVE…
09/19 TOC Mariner – HID: logitech-hidpp: Fix FF device cleanup on init failure C…
09/19 TOC Mariner – cuse: wait for pending RCU callbacks on module exit CVE-2026…
09/19 TOC Mariner – RabbitMQ amqp091-go: Denial of Service via Synchronous Event…
09/19 TOC Mariner – ocfs2: o2hb: quiesce negotiate handlers and timeout work CVE…
09/19 TOC Mariner – lib/test_hmm: fail dmirror_fault() when the mirrored mm is g…
09/19 TOC Mariner – Bluetooth: hci_conn: fix the SCO setup context lifetime CVE-…
09/19 TOC Mariner – scsi: qla2xxx: Remove redundant VPD flash read in sysfs read…
09/19 TOC Mariner – IB/isert: reject login PDUs declaring more data than was rec…
09/19 TOC Mariner – ocfs2: synchronize heartbeat callbacks with o2net teardown C…
09/19 TOC Mariner – serial: qcom-geni: do not advance stale DMA completions CVE-…
09/19 TOC Mariner – usb: fix UAF when probe runs concurrent to dyn ID removal CV…
09/19 TOC Mariner – RDMA/erdma: Hold CQ references when processing EQ events CVE…
09/19 TOC Mariner – dmaengine: dw-edma: Terminate all descriptors without callba…
09/19 TOC Mariner – ocfs2: validate orphan slot during inode read CVE-2026-90205…
09/19 TOC Mariner – RDMA/cma: Fix WARNING in res_to_rt CVE-2026-90218
09/19 TOC Mariner – cpufreq: amd-pstate-ut: Skip tests when amd-pstate driver is…
09/19 TOC Mariner – RabbitMQ amqp091-go: Silent Data Truncation and State Corrup…
09/19 TOC Mariner – uio: Fix stale info pointer in failed registration path CVE-…
09/19 TOC Mariner – Podman: buildah: buildah/copier: directory escape via crafte…
09/19 TOC Mariner – btrfs: always wait for ordered extents to avoid OE races CVE…
09/19 TOC Mariner – drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega1…
09/19 TOC Mariner – ALSA: ice1712: Fix the card leak at probe error with the aut…
09/19 TOC Mariner – fbdev: kyro: Validate overlay viewport coordinates CVE-2026-…
09/19 TOC Mariner – libceph: validate banner payload length CVE-2026-90067
09/19 TOC Mariner – gitoxide gix-transport before 0.59.2 CR/LF/NUL Injection CVE…
09/19 TOC Mariner – null_blk: serialize configfs attribute updates with device s…
09/19 TOC Mariner – bpf: Clear buf on error in __bpf_get_task_stack CVE-2026-903…
09/19 TOC Mariner – scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers CV…
09/19 TOC Mariner – UDF symlink pathComponent header OOB read CVE-2026-93055
09/19 TOC Mariner – RDMA/core: Fix potential use after free in ib_free_cq() CVE-…
09/19 TOC Mariner – net: kcm: Hold RCU read lock while running BPF parser CVE-20…
09/19 TOC Mariner – wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx(…
09/19 TOC Mariner – fat: release buffer head after rebuilding parent CVE-2026-90…
09/19 TOC Mariner – btrfs: defrag: fix deadlock between defrag and delalloc spac…
09/19 TOC Mariner – ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free …
09/19 TOC Mariner – coresight: etm4x: fix underflow for usage of (nrseqstate – 1…
09/19 TOC Mariner – RDMA/erdma: Hold QP references for AE and CM processing CVE-…
09/19 TOC Mariner – drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 …
09/19 TOC Mariner – vdpa_sim: fix cleanup after worker creation failure CVE-2026…
09/19 TOC Mariner – ipvs: fix integer overflow in ftp helper port/address parsin…
09/19 TOC Mariner – wifi: mt76: mt7996: reserve space for the CSA-abort countdow…
09/19 TOC Mariner – nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()…
09/19 TOC Mariner – remoteproc: fix OOB read via signed offset in rsc_table_for_…
09/19 TOC Mariner – drm/sun4i: crtc: Propagate layer initialization error CVE-20…
09/19 TOC Mariner – esp: do not unref managed frag pages in esp_ssg_unref() CVE-…
09/19 TOC Mariner – Bluetooth: MGMT: free the mesh send cancel command when it i…
09/19 TOC Mariner – phonet: pep: do not write beyond optlen in getsockopt CVE-20…
09/19 TOC Mariner – wifi: mt76: mt7915: release hif2 reference on probe IRQ fail…
09/19 TOC Mariner – irqchip/renesas-irqc: Fix generic interrupt chip leak on rem…
09/19 TOC Mariner – wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_co…
09/19 TOC Mariner – nvmet: fix max_qid race between configfs and controller allo…
09/19 TOC Mariner – bpf, cgroup: Fix storage null-ptr-deref after replacing prog…
09/19 TOC Mariner – drm/v3d: Associate BOs with every job that accesses them CVE…
09/19 TOC Mariner – net: fec: only stop PTP if it was initialized CVE-2026-90056…
09/19 TOC Mariner – ksmbd: safely discard unregistered deferred locks CVE-2026-9…
09/19 TOC Mariner – mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() …
09/19 TOC Mariner – cxl/mbox: Clamp mailbox output allocation to the payload siz…
09/19 TOC Mariner – net: sched: fix 32-bit backlog wrap in gred, bfifo and plug …
09/19 TOC Mariner – ksmbd: validate ipc response length before dereferencing its…
09/19 TOC Mariner – firewire: core: fix memory leak in error path of build_tree(…
09/19 TOC Mariner – wifi: mac80211_hwsim: avoid NULL skb in stop queue drain CVE…
09/19 TOC Mariner – iommu/dma: Check atomic pool allocation result directly CVE-…
09/19 TOC Mariner – bpf: Fix use-after-free on mm_struct in bpf_find_vma() CVE-2…
09/19 TOC Mariner – bpf: Zero queue and stack outputs on lock failure CVE-2026-9…
09/19 TOC Mariner – RDMA/rvt: Return NULL after port allocation failure CVE-2026…
09/19 TOC Mariner – usb: gadget: r8a66597: avoid double free of ep0_req in probe…
09/19 TOC Mariner – nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_…
09/19 TOC Mariner – wifi: nl80211: clean up color-change beacon data on errors C…
09/19 TOC Mariner – pnfs/blocklayout: Fix device leaks on parse failure CVE-2026…
09/19 TOC Mariner – ocfs2: validate DIO orphan slot during inode read CVE-2026-9…
09/19 TOC Mariner – drm/msm/dsi: Drop dev_pm_opp_set_rate(0) CVE-2026-90362
09/19 TOC Mariner – dm-integrity: replace forgeable discard filler with a keyed …
09/19 TOC Mariner – NFSv4.1: zero referring call lists before decoding CVE-2026-…
09/19 TOC Mariner – cxl/mbox: Break poison list loop on an empty payload CVE-202…
09/19 TOC Mariner – nfc: llcp: avoid userspace overflow on invalid optlen CVE-20…
09/19 TOC Mariner – ACPI: processor: Unregister cpufreq notifier on init failure…
09/19 TOC Mariner – RDMA/hfi1: Preserve unit 0 on allocation failure CVE-2026-93…
09/19 TOC Mariner – firmware: arm_scmi: Quiesce notifications before teardown CV…
09/19 TOC Mariner – nfc: pn533: hold a reference to the request skb during send_…
09/19 TOC Mariner – Bluetooth: L2CAP: reject accept queue add unless BT_LISTEN C…
09/19 TOC Mariner – platform/x86: asus-wmi: fix resource leaks on probe failure …
09/19 TOC Mariner – RDMA/cxgb4: Fix dereg_skb leak and double free in write_tpt_…
09/19 TOC Mariner – ext4: fix ABBA deadlock in ext4_xattr_inode_cache_find() CVE…
09/19 TOC Mariner – md: scope memalloc_noio to allocation critical sections CVE-…
09/19 TOC Mariner – phy: qcom: snps-femto-v2: Fix possible NULL-deref on early r…
09/19 TOC Mariner – wifi: iwlwifi: mei: check SAP message length before reading …
09/19 TOC Mariner – thermal/drivers/rcar: Fix error checking in probe() CVE-2026…
09/19 TOC Mariner – nvmet-rdma: fix response resource leak on queue teardown CVE…
09/19 TOC Mariner – crypto: rk3288 – fail ahash requests on HASH idle timeout CV…
09/19 TOC Mariner – firmware: arm_scmi: Avoid IDR updates while cleaning channel…
09/19 TOC Mariner – dax: read holder_ops once in dax_holder_notify_failure() CVE…
09/19 TOC Mariner – RDMA/cxgb4: free STAG index when TPT entry write fails CVE-2…
09/19 TOC Mariner – ksmbd: scope session state changes to bound connections CVE-…
09/19 TOC Mariner – drm/lima: call drm_mm_init() with a valid allocation range C…
09/19 TOC Mariner – wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser CVE-…
09/19 TOC Mariner – clocksource/drivers/samsung_pwm: Switch to raw_spinlock_t ty…
09/19 TOC Mariner – nilfs2: prevent out-of-bounds read in super root block parsi…
09/19 TOC Mariner – batman-adv: bla: avoid CRC corruption due to parallel claim …
09/19 TOC Mariner – nvme-apple: Destroy the admin queue on removal CVE-2026-9022…
09/19 TOC Mariner – net: bridge: arp/nd proxy: fix reading neigh ha CVE-2026-901…
09/19 TOC Mariner – drm/bridge: tc358767: clamp the reported AUX read size to th…
09/19 TOC Mariner – null_blk: register configfs subsystem after creating default…
09/19 TOC Mariner – RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap CVE-…
09/19 TOC Mariner – wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv…
MS-ISAC Cybersecurity Advisory
09/17 TOC Multiple Vulnerabilities in Oracle Products Could Allow for Arbitrary …
Multiple vulnerabilities have been discovered in Oracle products, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
TLDR InfoSec
09/17 TOC Florida DMV data leak , First Agentic AI leak , Rust devs targeted
Hacker News
09/19 TOC Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via C…
Three researchers at the security firm Hacktron used Anthropic’s Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI’s public help forum and moved through a weakness in OpenAI’s own login system. This was security research,09/19 TOC Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How …
A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still validate risk on weekly or quarterly cycles. The dangerous gap is no longer just technical. It is09/19 TOC Identity Visibility in 2026: The Foundation of Identity Security
Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon’s annual Data Breach Investigations Report. This article explains what identity visibility means in IAM, why cloud and multicloud environments complicate it, which capabilities matter in09/19 TOC SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RC…
SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior. “SolarWinds09/19 TOC Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited i…
A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution. “Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote09/19 TOC Google Gemini Broke Into Real Company Systems After Security Test Doma…
Google’s Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal. The incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also involved in similar hacks disclosed09/19 TOC CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Re…
An attacker copied about 170 of CrowdSec’s private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18. The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May’s supply chain attack on TanStack, in which malicious versions of TanStack’s npm packages stole credentials from09/19 TOC CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below – CVE-2025-39682 (CVSS score: 9.8) – An improper check for unusual or exceptional conditions vulnerability in the TLS receive path09/18 TOC Public Exploits Released for Four Linux Kernel Flaws That Enable Local…
A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine. Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the exploit code is now public, and any machine still running an older kernel should be updated. The flaws09/18 TOC New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Cod…
WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install. The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only09/18 TOC Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repos…
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation09/18 TOC Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorize…
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. “Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network,”09/18 TOC An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Ca…
In July 2025, someone registered a domain that used to belong to a content delivery network. The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire. What it had not lost were its callers. Thousands of websites, code repositories, and documentation pages still carry hard-coded references to hostnames beneath it. The new owner holds09/18 TOC Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Fou…
A flaw in four widely used AI coding agents lets someone who controls a plugin’s code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday. The firm said Anthropic has patched the flaw in Claude Code 2.1.179 and OpenAI in Codex 0.146.0, that GitHub Copilot has no09/18 TOC WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Ex…
Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People’s Republic of Korea’s (DPRK) Contagious Interview campaign: BeaverTail and09/18 TOC Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm St…
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. “The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,”09/18 TOC RatHat Android Malware Abuses ADB to Retain Shell Access After Uninsta…
Cybersecurity researchers have flagged a new Android malware called RatHat that’s assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. “Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses09/17 TOC Critical Check Point Management Flaw Lets Unauthenticated Attackers Ru…
A critical vulnerability in Check Point’s Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall policy and administrator access. Check Point has released a fix through its LivePatch update channel and says it has no indication that the flaw09/17 TOC ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swa…
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough. So the threat landscape is not getting cleaner. It is just09/17 TOC Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modi…
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The escape runs with the rights of the host account that runs the virtual machine. The flaw, CVE-2026-77179, is rated Critical, affects versions09/17 TOC Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can …
The Iran-linked “hacktivist” persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. “HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading,09/17 TOC Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious…
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution. Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642, along with09/17 TOC CISO’s Expert Guide to Agentic Pentesting for Websites
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how autonomous AI agents are closing that gap, and what security leaders must demand before pointing one at production. TL;DR Exploitation is now the front door. It starts 31% of breaches (Verizon DBIR09/17 TOC China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin …
The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. “SparroWocky is a modular, C++ backdoor,” ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker News09/17 TOC OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unaut…
OpenAI on Wednesday disclosed six new instances of “unexpected or concerning model behavior” that took place over the past six months, while sharing a new framework for reporting, tracking, investigating, and disclosing model misalignment in a bid to improve transparency. “As AI systems grow more advanced and more widely deployed, we need to build a broader and better-informed consensus on the09/17 TOC BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over …
The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH). A sender with no credentials can crash the server process, named, with a single request that carries an invalid SIG09/17 TOC Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image …
A security breach at Gyazo, Helpfeel’s image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday. It also exposed about 490 million image metadata records, mostly for images from January 2019 or earlier, including the IDs that make up Gyazo image links. Helpfeel said09/17 TOC Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in A…
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. “This vulnerability is due to insufficient authentication control on an API endpoint,” Cisco said. “An attacker09/17 TOC U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands …
The U.S. Department of Justice (DoJ) on Tuesday announced the court-authorized seizure of internet domains associated with a distributed denial-of-service (DDoS)-for-hire service known as NightmareStresser. The domains in question are: nightmare-stresser[.]com and nightmarestresser[.]org. Visitors to the sites are now greeted by a seizure banner that states – “This domain has been seized byCheck Point Research
09/17 TOC AI Threat Landscape Digest: JulyAugust 2026
The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real systems. In the wild, the criminal and state use of AI continued to mature along the lines tracked in earlier editions: models now act as attack operators, an underground […]
The post AI Threat Landscape Digest: July–August 2026 appeared first on Check Point Research.
Cisco Talos
09/17 TOC Should you care about an AI slowdown?
In this week’s Threat Source, David talks about why focusing on your security basics is still your best bet, even in a world with rapid AI advancements.09/17 TOC Ransomware incidents in Japan in the first half of 2026: Investigation…
Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims.Bleeping Computer
09/19 TOC BragJack attacks hijack AI browser agents through malicious extensions…
BragJack, a proof-of-concept attack from Forever Security’s Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension. The Prompt Forcing technique earned over $20,000 in bounties and two CVEs. […]09/19 TOC North Korean WaterPlum hackers infected 30,000 devices worldwide
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. […]09/19 TOC ShinyHunters hacks Clop leak site, threatens to extort ransomware gang…
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation’s data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. […]09/19 TOC Viral AI actress’ hotline face-scans every caller, watches their mood
AI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her “Talking Tilly” video call service face-scans every caller for an 18+ age check, senses callers’ moods during calls, and shuts down permanently on September 27. We tried it and read the fine print. […]09/18 TOC Gyazo server flaw exploited to steal 23.6 million user records
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6Â million user records. […]09/18 TOC Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer…
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. […]09/18 TOC Secure enterprise sharing with access reviews for Microsoft 365
Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can help identify and remove unnecessary access. […]09/18 TOC Microsoft Teams will let admins block custom file extensions
Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with security threats to meet their company’s security requirements. […]09/18 TOC Webinar: Which Google Workspace security controls actually matter?
Fast-growing companies face countless recommendations for securing Google Workspace, but not every control provides the same value. This webinar examines real-world breaches to explore which security controls matter most, which may be overrated, and where lean security teams should focus their resources. […]09/18 TOC Microsoft fixes bug behind Defender Antivirus is turned off alerts
Microsoft has resolved a known issue that causes incorrect alerts warning that Defender Antivirus was turned off after installing recent updates. […]09/18 TOC New Check Point flaw lets hackers execute code with root privileges
Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. […]09/18 TOC Microsoft fixes broken copy and paste for Excel 2016 users
Microsoft has fixed a known issue that causes copy-and-paste failures for some Excel users after installing the September 2026 KB5002914 security update. […]09/17 TOC New RatHat Android malware uses AI to automate device control
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. […]09/17 TOC OpenAI details more cases of AI agents taking unauthorized actions
OpenAI has presented new examples of what they call “AI model misalignment” from the past six months, including unauthorized file uploads, following self-generated instructions, hiding mistakes, and leveraging exposed API keys. […]09/17 TOC Brevo supply-chain attack injected ClickFix scripts on customer sites
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. […]CISA
09/17 TOC Schneider Electric PowerChute Serial Shutdown
09/17 TOC ABB Ability EdgeniusSummary
Schneider Electric is aware of vulnerabilities in its PowerChute Serial Shutdown product. The PowerChute Serial Shutdown product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktops, servers and workstations. Failure to apply the remediation provided below may risk improper authentication validation which could result in disruption of operations and access to system data.
The following versions of Schneider Electric PowerChute Serial Shutdown are affected:
- PowerChute Serial Shutdown vers:intdot/<=1.5, 1.6 (CVE-2026-13348)
CVSS Vendor Equipment Vulnerabilities v3 5.3 Schneider Electric Schneider Electric PowerChute Serial Shutdown Improper Restriction of Excessive Authentication Attempts Background
- Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy, Information Technology
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: France
Vulnerabilities
CVE-2026-13348
CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an arbitrary number of authentication attempts when redirect handling is disabled.
Affected Products
Schneider Electric PowerChute Serial Shutdown
Vendor:
Schneider ElectricProduct Version:
PowerChute Serial Shutdown Version 1.5 and priorProduct Status:
fixed, known_affectedRemediations
Vendor fix
Version v1.6 of PowerChute Serial Shutdown includes a fix for these vulnerabilities and is available for download here: • Windows: https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/ Reboot needed: Upon installation, the service is automatically restarted. A customer can validate a successful install by checking the version information in the Control Panel or on the About page within PCSS after logging in. Specific instructions and hardening guidelines for these remediations can be found in the Security Handbook.
ÂVendor fix
Version v1.6 of PowerChute Serial Shutdown includes a fix for these vulnerabilities and is available for download here: • Linux: https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/ Reboot needed: Upon installation, the service is automatically restarted. A customer can validate a successful install by checking the version information in the Control Panel or on the About page within PCSS after logging in. Specific instructions and hardening guidelines for these remediations can be found in the Security Handbook.For more information see the associated Schneider Electric security advisory Improper Restriction of Excessive Authentication Attempts vulnerability on PowerChute Serial Shutdown – SEVD-2026-223-01 CSAF Version, Improper Restriction of Excessive Authentication Attempts vulnerability on PowerChute Serial Shutdown – SEVD-2026-223-01 PDF Version.
Relevant CWE: CWE-307 Improper Restriction of Excessive Authentication Attempts
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Acknowledgments
- Schneider Electric CPCERT reported this vulnerability to CISA.
General Security Recommendations
Schneider Electric strongly recommends the following industry cybersecurity best practices.Â
- Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.Â
- Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.Â
- Place all controllers in locked cabinets and never leave them in the “Program†mode.Â
- Never connect programming software to any network other than the network intended for that device.Â
- Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.Â
- Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.Â
- Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.Â
- When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.Â
For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.
For More Information
This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process. For further information related to cybersecurity in Schneider Electric’s products, visit the company’s cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp
LEGAL DISCLAIMER
THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS “NOTIFICATIONâ€) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN “AS-IS†BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION
About Schneider Electric
Schneider’s purpose is to create Impact by empowering all to make the most of our energy and resources, bridging progress and sustainability for all. We call this Life Is On. Our mission is to be the trusted partner in Sustainability and Efficiency. We are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart industries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep domain expertise, we provide integrated end-to-end lifecycle AI enabled Industrial IoT solutions with connected products, automation, software and services, delivering digital twins to enable profitable growth for our customers. We are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries to ensure proximity to our customers and stakeholders. We embrace diversity and inclusion in everything we do, guided by our meaningful purpose of a sustainable future for all. www.se.com
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.
- Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolate them from business networks.
- When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
Advisory Conversion Disclaimer
This ICSA is a verbatim republication of Schneider Electric CPCERT SEVD-2026-223-01 from a direct conversion of the vendor’s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA’s website as a means of increasing visibility and is provided “as-is” for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory.
Revision History
- Initial Release Date: 2026-08-11
Date Revision Summary 2026-08-11 1 Original Release 2026-09-17 2 Initial CISA Republication of Schneider Electric CPCERT SEVD-2026-223-01 advisory
Legal Notice and Terms of Use
09/17 TOC Schneider Electric NetBotz 5 750/755Summary
ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete control of the system
The following versions of ABB Ability Edgenius are affected:
- Ability Edgenius >=3.2.0.0|<3.2.4.1, 3.2.4.1 (CVE-2026-31431)
CVSS Vendor Equipment Vulnerabilities v3 7.8 ABB ABB Ability Edgenius Incorrect Resource Transfer Between Spheres Background
- Critical Infrastructure Sectors: Critical Manufacturing, Energy, Water and Wastewater, Chemical
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: Switzerland
Vulnerabilities
CVE-2026-31431
A Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. The issue originates in the Linux kernel’s cryptographic subsystem and impacts kernels used by most major Linux distributions released since 2017.Successful exploitation requires local code execution, however, in shared, containerized, or multi‑tenant environments this may increase the security risk.
Affected Products
ABB Ability Edgenius
Vendor:
ABBProduct Version:
ABB Ability Edgenius >=3.2.0.0|<3.2.4.1 installed on ABB Ability Edgenius Gateway - bE100Product Status:
fixed, known_affectedRemediations
Vendor fix
The problem is corrected in the following product versions: – Edgenius 3.2.4.1 ABB recommends that customers apply the update at earliest convenience.Mitigation
Mitigating factors describe conditions and circumstances that make an attack that exploits the vulnerability difficult or less likely to succeed. Refer to section General security recommendations for further advise on how to keep your system secure. Recommended mitigation factors – Limit access to ssh or cockpit – By default, no additional lower privilege users are present on Edgenius installations.Mitigation
For more information see the associated ABB PSIRT security advisory 7PAA024620 ABB CYBERSECURITY ADVISORY – PDF Version , ABB CYBERSECURITY ADVISORY – CSAF Version .
Relevant CWE: CWE-669 Incorrect Resource Transfer Between Spheres
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Acknowledgments
- ABB PSIRT reported this vulnerability to CISA.
Notice
The information in this document is subject to change without notice, and should not be construed as a commitment by ABB. ABB provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall ABB or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if ABB or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from ABB, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners.
Frequently Asked Questions
What causes the vulnerability? – A flaw was found in the Linux kernel’s algif_aead cryptographic algorithm interface. An incorrect ‘in-place operation’ was introduced, where the source and destination data mappings were different. This could lead to unexpected behavior or data integrity issues during cryptographic operations, potentially impacting the reliability of encrypted communications. What is Edgenius? – ABB Abilityâ„¢ Edgenius is an edge computing platform that – Connects to control systems, devices, and equipment – Collects and contextualizes operational data – Hosts applications that deliver real-time insights and AI-driven recommendations What might an attacker use the vulnerability to do? – Successful exploitation could enable a local user attacker to gain administrative control of the system node, execute arbitrary code, or cause the node to become unavailable. How could an attacker exploit the vulnerability? – An attacker could exploit this vulnerability after obtaining local access to the system. By invoking the Linux kernel’s affected cryptographic interface (algif_aead), the attacker can trigger incorrect memory handling in the kernel. This allows the attacker to escalate privileges from a normal user to full administrative (root) access on the affected system node Could the vulnerability be exploited remotely? – No, to exploit this vulnerability an attacker would need to have local access (physical access or through valid SSH credentials) to an affected system node. What does the update do? – The update resolves the issue by incorporating the security update of the Linux kernel. When this security advisory was issued, had this vulnerability been publicly disclosed? – Yes, this vulnerability has been publicly disclosed. When this security advisory was issued, had ABB received any reports that this vulnerability was being exploited? – No, ABB had not received any information indicating that this vulnerability had been exploited for Edgenius when this security advisory was originally issued.
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.
- Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolate them from business networks.
- When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
Advisory Conversion Disclaimer
This ICSA is a verbatim republication of ABB PSIRT 7PAA024620 from a direct conversion of the vendor’s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA’s website as a means of increasing visibility and is provided “as-is” for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory.
Revision History
- Initial Release Date: 2026-06-25
Date Revision Summary 2026-06-25 1 Initial version. 2026-09-17 2 Initial CISA Republication of ABB PSIRT 7PAA024620 advisory
Legal Notice and Terms of Use
09/17 TOC Schneider Electric Modicon M340 Controller and Communication ModulesSummary
Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 – 750/755 products.The NetBotz 5 – 750/755 products are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capabilities. Failure to apply the remediation provided below may risk arbitrary or remote code execution over the local network, which could result in device manipulation and unauthorized data access.
The following versions of Schneider Electric NetBotz 5 750/755 are affected:
- NetBotz 5 750 vers:intdot/<=5.5.2 (CVE-2026-13336, CVE-2026-13337)
- NetBotz 5 755 vers:intdot/<=5.5.2 (CVE-2026-13336, CVE-2026-13337)
CVSS Vendor Equipment Vulnerabilities v3 6.4 Schneider Electric Schneider Electric NetBotz 5 750/755 Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’), SQL Injection: Hibernate Background
- Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Information Technology
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: France
Vulnerabilities
CVE-2026-13336
CWE-78: Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) vulnerability exists that could cause execution of Linux Operating system commands when a system back up is restored that has been maliciously modified.
Affected Products
Schneider Electric NetBotz 5 750/755
Vendor:
Schneider ElectricProduct Version:
NetBotz 5 750 versions 5.5.2 and prior, NetBotz 5 755 Versions 5.5.2 and priorProduct Status:
fixed, known_affectedRemediations
Vendor fix
Version 5.6.0 of NetBotz 5 750/755 includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/product-range/61830-netbotz/#software-and-firmware Reboot needed: Upon install, the offer will automatically restart. A customer can validate a successful install by logging into the GUI and selecting the ‘About NetBotz’ option. This will indicate the installed version.
ÂFor more information see the associated Schneider Electric security advisory Multiple Vulnerabilities on NetBotz 5 750/755 Products – SEVD-2026-223-02 CSAF Version, Multiple Vulnerabilities on NetBotz 5 750/755 Products – SEVD-2026-223-02 PDF Version.
Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 6.4 MEDIUM CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2026-13337
CWE-564:SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is logged into the NetBotz via the web-service interface or web-ui.
Affected Products
Schneider Electric NetBotz 5 750/755
Vendor:
Schneider ElectricProduct Version:
NetBotz 5 750 versions 5.5.2 and prior, NetBotz 5 755 Versions 5.5.2 and priorProduct Status:
fixed, known_affectedRemediations
Vendor fix
Version 5.6.0 of NetBotz 5 750/755 includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/product-range/61830-netbotz/#software-and-firmware Reboot needed: Upon install, the offer will automatically restart. A customer can validate a successful install by logging into the GUI and selecting the ‘About NetBotz’ option. This will indicate the installed version.
ÂFor more information see the associated Schneider Electric security advisory Multiple Vulnerabilities on NetBotz 5 750/755 Products – SEVD-2026-223-02 CSAF Version, Multiple Vulnerabilities on NetBotz 5 750/755 Products – SEVD-2026-223-02 PDF Version.
Relevant CWE: CWE-564 SQL Injection: Hibernate
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 4.6 MEDIUM CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Acknowledgments
- Schneider Electric CPCERT reported these vulnerabilities to CISA.
General Security Recommendations
Schneider Electric strongly recommends the following industry cybersecurity best practices.Â
- Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.Â
- Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.Â
- Place all controllers in locked cabinets and never leave them in the “Program†mode.Â
- Never connect programming software to any network other than the network intended for that device.Â
- Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.Â
- Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.Â
- Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.Â
- * When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.Â
For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.
For More Information
This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process. For further information related to cybersecurity in Schneider Electric’s products, visit the company’s cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp
LEGAL DISCLAIMER
THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS “NOTIFICATIONâ€) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN “AS-IS†BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION
About Schneider Electric
Schneider’s purpose is to create Impact by empowering all to make the most of our energy and resources, bridging progress and sustainability for all. We call this Life Is On. Our mission is to be the trusted partner in Sustainability and Efficiency. We are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart industries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep domain expertise, we provide integrated end-to-end lifecycle AI enabled Industrial IoT solutions with connected products, automation, software and services, delivering digital twins to enable profitable growth for our customers. We are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries to ensure proximity to our customers and stakeholders. We embrace diversity and inclusion in everything we do, guided by our meaningful purpose of a sustainable future for all. www.se.com
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.
- Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolate them from business networks.
- When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
Advisory Conversion Disclaimer
This ICSA is a verbatim republication of Schneider Electric CPCERT SEVD-2026-223-02 from a direct conversion of the vendor’s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA’s website as a means of increasing visibility and is provided “as-is” for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory.
Revision History
- Initial Release Date: 2026-08-11
Date Revision Summary 2026-08-11 1 Original Release 2026-09-17 2 Initial CISA Republication of Schneider Electric CPCERT SEVD-2026-223-02 advisory
Legal Notice and Terms of Use
09/17 TOC Hitachi Energy FACTS Control Platform (FCP)Summary
Schneider Electric is aware of a vulnerability in its Modicon M340 https://www.se.com/ww/en/product-range/1468-modicon-m340-pac/, BMXNOR0200H https://www.se.com/us/en/product/BMXNOR0200H/communication-module-modicon-m340-iec-608705101-104-dnp3-for-severe-environments/: Modicon M340 X80 Ethernet Communication Modules, BMXNGD0100 https://www.se.com/us/en/product/BMXNGD0100/communication-module-modicon-m580-global-data-service/: M580 Global Data module, BMXNOC0401 https://www.se.com/us/en/product/BMXNOC0401/network-module-modicon-m340-ethernet-ip-and-modbus-tcp-4-x-rj45/?pageType=product&sourceId=BMXNOC0401: Modicon M340 X80 Ethernet Communication modules, BMXNOE0100 https://www.se.com/ww/en/product/BMXNOE0100/network-module-modicon-m340-modbus-tcp-1-x-rj45-flash-memory-card/?pageType=product&sourceId=BMXNOE0100: Modbus/TCP Ethernet Modicon M340 module, BMXNOE0110 https://www.se.com/ww/en/product/BMXNOE0110/ethernet-tcp-ip-network-module-modicon-m340-automation-platform-flash-memory-card-internal-ram-16-mb-1-x-rj45-10-100/: Modbus/TCP Ethernet Modicon M340 FactoryCast module product(s). Failure to apply the fix provided below may risk Denial Of Service attack, which could result in the unavailability of the devices.
The following versions of Schneider Electric Modicon M340 Controller and Communication Modules are affected:
- Schneider Electric Ethernet/Serial RTU Module: vers:generic/
- Schneider Electric M580 Global Data module: vers:all/*
- Schneider Electric Ethernet / Serial RTU Module: vers:all/*
- Schneider Electric Modbus/TCP Ethernet Modicon M340 module: vers:intdot/<3.60
- Schneider Electric Modbus/TCP Ethernet Modicon M340 FactoryCast module: vers:intdot/<6.80
- Schneider Electric Modicon M340 Firmware Versions prior to SV3.70 installed on Modicon M340 Controller: All versions
CVSS Vendor Equipment Vulnerabilities v3 7.5 Schneider Electric Schneider Electric Modicon M340 Controller and Communication Modules Improper Input Validation Background
- Critical Infrastructure Sectors: Chemical, Commercial Facilities, Critical Manufacturing, Energy, Water and Wastewater
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: France
Vulnerabilities
CVE-2025-6625
CWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific crafted FTP command is sent to the device.
Affected Products
Schneider Electric Modicon M340 Controller and Communication Modules
Vendor:
Schneider ElectricProduct Version:
Ethernet / Serial RTU Module All versions, M580 Global Data module All versions, Modicon M340 X80 Ethernet Communication modules All versions, Modbus/TCP Ethernet Modicon M340 module Versions prior to 3.60, Modbus/TCP Ethernet Modicon M340 FactoryCast module Versions prior to 6.80Product Status:
fixed, known_affectedRemediations
Vendor fix
Version 3.60 of BMXNOE0100 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product/BMXNOE0100/network-module-modicon-m340-modbus-tcp-1-x-rj45-flash-memory-card/ÂReboot is needed to complete the firmware upgrade
ÂVendor fix
Version 6.80 of BMXNOE0110 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product/BMXNOE0110/ethernet-tcp-ip-network-module-modicon-m340-automation-platform-flash-memory-card-internal-ram-16-mb-1-x-rj45-10-100/ÂReboot is needed to complete the firmware upgrade
ÂVendor fix
Version SV3.70 of Modicon M340 includes a fix for this vulnerability and is available for download here:Â
https://www.se.com/ww/en/product-range/1468-modicon-m340/#software-and-firmwareVendor fix
Version SV1.7 IR27 of BMXNOR0200H includes a fix for this vulnerability and is available for download here:Â
https://www.se.com/ww/en/product/BMXNOR0200H/ethernet-serial-rtu-module-2-x-rj45/Mitigation
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit:Â
- FTP service is disabled by default.
- Ensure to disable FTP service when not in use.
- Setup network segmentation and implement a firewall to block all unauthorized access to ports 21/FTP.
- Use VPN (Virtual Private Networks) tunnels if remote access is required.
Mitigation
Schneider Electric is establishing a remediation plan for all future versions of:
- Modicon M340
- BMXNOR0200H
- BMXNGD0100
BMXNOC401Â
Schneider Electric will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit:Â
- FTP service is disabled by default.
- Ensure to disable FTP service when not in use.
- Setup network segmentation and implement a firewall to block all unauthorized access to ports 21/FTP.
- Use VPN (Virtual Private Networks) tunnels if remote access is required.
Mitigation
For more information see the associated Schneider Electric security advisory Modicon M340 Controller and Communication Modules – SEVD-2025-224-05 CSAF Version, Modicon M340 Controller and Communication Modules – SEVD-2025-224-05 PDF Version.
Relevant CWE: CWE-20 Improper Input Validation
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Acknowledgments
- Schneider Electric CPCERT reported this vulnerability to CISA.
General Security Recommendations
We strongly recommend the following industry cybersecurity best practices.Â
- Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.Â
- Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.Â
- Place all controllers in locked cabinets and never leave them in the “Program†mode.Â
- Never connect programming software to any network other than the network intended for that device.Â
- Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.Â
- Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.Â
- Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.Â
- When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Â Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.Â
For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.
For More Information
This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process. For further information related to cybersecurity in Schneider Electric’s products, visit the company’s cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp
LEGAL DISCLAIMER
THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS “NOTIFICATIONâ€) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN “AS-IS†BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION
About Schneider Electric
Schneider’s purpose is to create Impact by empowering all to make the most of our energy and resources, bridging progress and sustainability for all. We call this Life Is On. Our mission is to be the trusted partner in Sustainability and Efficiency. We are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart industries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep domain expertise, we provide integrated end-to-end lifecycle AI enabled Industrial IoT solutions with connected products, automation, software and services, delivering digital twins to enable profitable growth for our customers. We are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries to ensure proximity to our customers and stakeholders. We embrace diversity and inclusion in everything we do, guided by our meaningful purpose of a sustainable future for all. www.se.com
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.
- Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolate them from business networks.
- When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
Advisory Conversion Disclaimer
This ICSA is a verbatim republication of Schneider Electric CPCERT SEVD-2025-224-05 from a direct conversion of the vendor’s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA’s website as a means of increasing visibility and is provided “as-is” for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory.
Revision History
- Initial Release Date: 2025-08-12
Date Revision Summary 2025-08-12 1 Original Release 2026-04-14 2 Remediation is available for Modicon M340 2026-08-11 3 Remediation is available for BMXNOR0200H. 2026-09-17 4 Initial CISA Republication of Schneider Electric CPCERT SEVD-2025-224-05 advisory
Legal Notice and Terms of Use
09/17 TOC Mitsubishi Electric GX Works3 and Motion Control SettingsSummary
Hitachi Energy is aware of vulnerabilities that affect the FACTS Control systems with GWS component listed in this document. An attacker exploiting these vulnerabilities can cause impact on confidentiality, integrity and availability of the product. Following FACTS Control systems with GWS component deployed from year 2020 onwards are likely affected by the above vulnerabilities. Product deployments without GWS component are not affected. • SVC Light (STATCOM) • Fixed Series Capacitor • Thyristor Controlled Series Capacitor • Static Var Compensator • Static Watt Compensator • Hybrid Synchronous Condensers Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The affected FCP versions are only applicable if GWS component is present.
The following versions of Hitachi Energy FACTS Control Platform (FCP) are affected:
- FACTS Control Platform (FCP) 3.4.0, 3.7.0, 3.8.0, 3.10.0, 3.12.0, 3.14.0, 3.15.0, 4.0.0, 4.0.1, 4.1.0, 4.1.1 (CVE-2024-4872, CVE-2024-3980, CVE-2024-3982, CVE-2024-7940, CVE-2024-7941)
CVSS Vendor Equipment Vulnerabilities v3 9.9 Hitachi Energy Hitachi Energy FACTS Control Platform (FCP) Improper Neutralization of Special Elements in Data Query Logic, Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’), Authentication Bypass by Capture-replay, Missing Authentication for Critical Function, URL Redirection to Untrusted Site (‘Open Redirect’) Background
- Critical Infrastructure Sectors: Energy
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: Switzerland
Vulnerabilities
CVE-2024-4872
A vulnerability exists in the query validation of the FACTS Control system with GWS component. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability an attacker must have a valid credential.
Affected Products
Hitachi Energy FACTS Control Platform (FCP)
Vendor:
Hitachi EnergyProduct Version:
FACTS Control Platform (FCP) version 3.4.0, FACTS Control Platform (FCP) version 3.7.0, FACTS Control Platform (FCP) version 3.8.0, FACTS Control Platform (FCP) version 3.10.0, FACTS Control Platform (FCP) version 3.12.0, FACTS Control Platform (FCP) version 3.14.0, FACTS Control Platform (FCP) version 3.15.0, FACTS Control Platform (FCP) version 4.0.0, FACTS Control Platform (FCP) version 4.0.1, FACTS Control Platform (FCP) version 4.1.0, FACTS Control Platform (FCP) version 4.1.1Product Status:
known_affectedRemediations
Mitigation
Follow general mitigation factors.For more information see the associated Hitachi Energy security advisory 8DBD000229.
Relevant CWE: CWE-943 Improper Neutralization of Special Elements in Data Query Logic
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 9.9 CRITICAL CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVE-2024-3980
The FACTS Control system with GWS allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files or other files that are critical to the application.
Affected Products
Hitachi Energy FACTS Control Platform (FCP)
Vendor:
Hitachi EnergyProduct Version:
FACTS Control Platform (FCP) version 3.4.0, FACTS Control Platform (FCP) version 3.7.0, FACTS Control Platform (FCP) version 3.8.0, FACTS Control Platform (FCP) version 3.10.0, FACTS Control Platform (FCP) version 3.12.0, FACTS Control Platform (FCP) version 3.14.0, FACTS Control Platform (FCP) version 3.15.0, FACTS Control Platform (FCP) version 4.0.0, FACTS Control Platform (FCP) version 4.0.1, FACTS Control Platform (FCP) version 4.1.0, FACTS Control Platform (FCP) version 4.1.1Product Status:
known_affectedRemediations
Mitigation
Follow general mitigation factors.For more information see the associated Hitachi Energy security advisory 8DBD000229.
Relevant CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 9.9 CRITICAL CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVE-2024-3982
An attacker with local access to machine where FACTS Control system with GWS is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. Note: By default, the session logging level is not enabled and only users with administrator rights can enable it.
Affected Products
Hitachi Energy FACTS Control Platform (FCP)
Vendor:
Hitachi EnergyProduct Version:
FACTS Control Platform (FCP) version 3.10.0, FACTS Control Platform (FCP) version 3.12.0, FACTS Control Platform (FCP) version 3.14.0, FACTS Control Platform (FCP) version 3.15.0, FACTS Control Platform (FCP) version 4.0.0, FACTS Control Platform (FCP) version 4.0.1, FACTS Control Platform (FCP) version 4.1.0, FACTS Control Platform (FCP) version 4.1.1Product Status:
known_affectedRemediations
Mitigation
Follow general mitigation factors.For more information see the associated Hitachi Energy security advisory 8DBD000229.
Relevant CWE: CWE-294 Authentication Bypass by Capture-replay
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 8.2 HIGH CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H CVE-2024-7940
The FACTS Control system with GWS product exposes a service that is intended for local only to all network interfaces without any authentication.
Affected Products
Hitachi Energy FACTS Control Platform (FCP)
Vendor:
Hitachi EnergyProduct Version:
FACTS Control Platform (FCP) version 3.14.0, FACTS Control Platform (FCP) version 3.15.0, FACTS Control Platform (FCP) version 4.0.0, FACTS Control Platform (FCP) version 4.0.1, FACTS Control Platform (FCP) version 4.1.0, FACTS Control Platform (FCP) version 4.1.1Product Status:
known_affectedRemediations
Mitigation
Follow general mitigation factors.For more information see the associated Hitachi Energy security advisory 8DBD000229.
Relevant CWE: CWE-306 Missing Authentication for Critical Function
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 8.3 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H CVE-2024-7941
A vulnerability exists in FACTS Control system with GWS where a HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.
Affected Products
Hitachi Energy FACTS Control Platform (FCP)
Vendor:
Hitachi EnergyProduct Version:
FACTS Control Platform (FCP) version 3.15.0, FACTS Control Platform (FCP) version 4.1.0, FACTS Control Platform (FCP) version 4.1.1Product Status:
known_affectedRemediations
Mitigation
Follow general mitigation factors.For more information see the associated Hitachi Energy security advisory 8DBD000229.
Relevant CWE: CWE-601 URL Redirection to Untrusted Site (‘Open Redirect’)
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 4.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Acknowledgments
- Hitachi Energy reported these vulnerabilities to CISA.
Notice
The information in this document is subject to change without notice and should not be construed as a commitment by Hitachi Energy. Hitachi Energy provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall Hitachi Energy or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if Hitachi Energy or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from Hitachi Energy and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners.
Support
For additional information and support please contact your product provider or Hitachi Energy service organization. For contact information, see https://www.hitachienergy.com/contact-us/ for Hitachi Energy contact-centers.
General Mitigation Factors
Recommended security practices and firewall configurations can help protect a process control network from attacks that originate from outside the network. Such practices include that process control systems are physically protected from direct access by unauthorized personnel, have no direct connections to the Internet, and are separated from other networks by means of a firewall system that has a minimal number of ports exposed, and others that have to be evaluated case by case. Process control systems should not be used for Internet surfing, instant messaging, or receiving e-mails. Portable computers and removable storage media should be carefully scanned for viruses before they are connected to a control system. Proper password policies and processes should be followed. Additional information on Industrial Control Systems Cybersecurity Best Practices can be found in the Hitachi Energy “Industrial Control Systems Cybersecurity Best Practices†Cybersecurity Notification. [1]
SSVC
SSVCv2/E:N/A:N/2026-07-24T09:43:32Z/
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.
- Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolate them from business networks.
- When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
Advisory Conversion Disclaimer
This ICSA is a verbatim republication of Hitachi Energy PSIRT 8DBD000229 from a direct conversion of the vendor’s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA’s website as a means of increasing visibility and is provided “as-is” for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Hitachi Energy PSIRT directly for any questions regarding this advisory.
Revision History
- Initial Release Date: 2026-07-28
Date Revision Summary 2026-07-28 1 Initial public release 2026-09-17 2 Initial CISA Republication of Hitachi Energy PSIRT 8DBD000229 advisory
Legal Notice and Terms of Use
09/17 TOC Bransys ELDSummary
Successful exploitation of this vulnerability could allow a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, destroy, or delete control programs.
The following versions of Mitsubishi Electric GX Works3 and Motion Control Settings are affected:
- Mitsubishi Electric GX Works3 vers:all/* (CVE-2026-15688)
- Mitsubishi Electric Motion Control Settings (Software packaged with GX Works3) vers:all/* (CVE-2026-15688)
CVSS Vendor Equipment Vulnerabilities v3 8.8 Mitsubishi Electric Mitsubishi Electric GX Works3 and Motion Control Settings Incorrect Implementation of Authentication Algorithm Background
- Critical Infrastructure Sectors: Critical Manufacturing
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: Japan
Vulnerabilities
CVE-2026-15688
Incorrect Implementation of Authentication Algorithm (CWE-303) vulnerability in the affected products allows a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, destroy, or delete control programs.
Affected Products
Mitsubishi Electric GX Works3 and Motion Control Settings
Vendor:
Mitsubishi ElectricProduct Version:
Mitsubishi Electric GX Works3: vers:all/*, Mitsubishi Electric Motion Control Settings (Software packaged with GX Works3): vers:all/*Product Status:
known_affectedRemediations
Workaround
For customers using GX Works3, please download version 1.096A or later from the link https://www.mitsubishielectric.com/fa/download/software/detailsearch.page?mode=software&kisyu=/plceng&shiryoid=1000001411&lang=2&select=0&softid=1&infostatus=1_2_1&viewradio=0&viewstatus=&viewpos=, install it, and set the security version for projects to “2”. Please refer to “15.9 Preventing Illegal Access to/Falsification of Data (Security Version)†in “GX Works3 Operating Manual†for details. For more information about the workaround, refer to the Mitsubishi Electric security advisory available at “https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-007_en.pdf“.
ÂWorkaround
For customers using Motion Control Settings (Software packaged with GX Works3), Please download version 1.070Y or later from the link “https://www.mitsubishielectric.com/fa/download/software/detailsearch.page?mode=software&kisyu=/ssc&shiryoid=1000000803&lang=2&select=0&softid=1&infostatus=1_8_1&viewradio=0&viewstatus=&viewpos=“, install it, and set the security version for projects to “2”. Please refer to “12.5 Preventing Illegal Access to/Falsification of Data (Security Version)†in “Motion Control Setting Function Help†for details. For more information about the workaround, refer to the Mitsubishi Electric security advisory at “https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-007_en.pdf“.
ÂMitigation
For customers of the affected products, Mitsubishi Electric recommends using a computer with the affected product within a LAN and blocking remote logins from untrusted networks, hosts, and users, to minimize the risk of exploiting this vulnerability.Mitigation
For customers of the affected products, Mitsubishi Electric recommends using a firewall, virtual private network (VPN), etc., to prevent unauthorized access, and allowing remote login only to trusted users when connecting a computer with the affected product to the Internet, to minimize the risk of exploiting this vulnerability.Mitigation
For customers of the affected products, Mitsubishi Electric recommends preventing the user from clicking on web links contained in emails or other messages from untrusted sources, or from opening attachments in untrusted emails, to minimize the risk of exploiting this vulnerability.Mitigation
For customers of the affected products, Mitsubishi Electric recommends installing antivirus software on a computer running the affected product, to minimize the risk of exploiting this vulnerability.Mitigation
For customers of the affected products, Mitsubishi Electric recommends restricting physical access to a computer on which the affected product is installed, as well as to computers and network devices that can communicate with it, to minimize the risk of exploiting this vulnerability.Relevant CWE: CWE-303 Incorrect Implementation of Authentication Algorithm
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H 4.0 9.2 CRITICAL CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:H/SA:H
Acknowledgments
- Mayeul Fargier, Erwan Cordier, Noé Flatreaud reported this vulnerability to Mitsubishi Electric.
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.
- Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolate them from business networks.
- When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
Advisory Conversion Disclaimer
This ICSA is a verbatim republication of Mitsubishi Electric 2026-007 from a direct conversion of the vendor’s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA’s website as a means of increasing visibility and is provided “as-is” for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Mitsubishi Electric directly for any questions regarding this advisory.
Revision History
- Initial Release Date: 2026-09-17
Date Revision Summary 2026-09-17 1 Initial Publication 2026-09-17 2 Initial CISA Republication of Mitsubishi Electric 2026-007 advisory
Legal Notice and Terms of Use
09/17 TOC Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)Summary
Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware.
The following versions of Bransys ELD are affected:
- Android <11.00.00 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960)
- iOS <1.1.54 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960)
CVSS Vendor Equipment Vulnerabilities v3 7.5 Bransys Bransys ELD Use of Hard-coded Credentials, Cleartext Transmission of Sensitive Information Background
- Critical Infrastructure Sectors: Transportation Systems
- Countries/Areas Deployed: United States
- Company Headquarters Location: United States
Vulnerabilities
CVE-2026-86520
The affected product is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.
Affected Products
Bransys ELD
Vendor:
BransysProduct Version:
Bransys Android: <11.00.00, Bransys iOS: <1.1.54Product Status:
known_affectedRemediations
Vendor fix
Bransys recommends that users update their system through the app store. Android users should be on version 11.00.00 or newer. iOS users should be on version 1.1.54 or newer.Relevant CWE: CWE-798 Use of Hard-coded Credentials
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-86689
The affected product is susceptible to cleartext transmission of sensitive information, which could allow an attacker to connect to the broker and read all data.
Affected Products
Bransys ELD
Vendor:
BransysProduct Version:
Bransys Android: <11.00.00, Bransys iOS: <1.1.54Product Status:
known_affectedRemediations
Vendor fix
Bransys recommends that users update their system through the app store. Android users should be on version 11.00.00 or newer. iOS users should be on version 1.1.54 or newer.Relevant CWE: CWE-319 Cleartext Transmission of Sensitive Information
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 5.9 MEDIUM CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 8.2 HIGH CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-77960
The affected product ships with hardcoded FTP credentials which could allow an attacker to connect to the server and read data.
Affected Products
Bransys ELD
Vendor:
BransysProduct Version:
Bransys Android: <11.00.00, Bransys iOS: <1.1.54Product Status:
known_affectedRemediations
Vendor fix
Bransys recommends that users update their system through the app store. Android users should be on version 11.00.00 or newer. iOS users should be on version 1.1.54 or newer.Relevant CWE: CWE-798 Use of Hard-coded Credentials
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N 4.0 6.9 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Acknowledgments
- Jaime Lightfoot reported these vulnerabilities to CISA.
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.
- Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolating them from business networks.
- When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
CISA also recommends users take the following measures to protect themselves from social engineering attacks:
- Do not click web links or open attachments in unsolicited email messages.
- Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.
- Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.
Revision History
- Initial Release Date: 2026-09-17
Date Revision Summary 2026-09-17 1 Initial Publication
Legal Notice and Terms of Use
Summary
Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly.
The following versions of Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A) are affected:
- Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-16 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-32 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-64 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-128 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-256 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-N32 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-P32 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-N32 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-P32 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-N32 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-P32 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-8-N32 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-8-P32 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-16-N32 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-16-P32 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Master/local module RJ71GN11-T2 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Master/local module RJ71GN11-SX vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Master/local module RJ71GN11-EIP vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Master/local module FX5-CCLGN-MS vers:all/* (CVE-2026-13584)
- Mitsubishi Electric CC-Link IE TSN interface board NZ81GN11-SX vers:all/* (CVE-2026-13584)
- Mitsubishi Electric CC-Link IE TSN interface board NZ81GN11-T2 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Motion module RD78G4 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Motion module RD78G8 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Motion module RD78G16 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Motion module RD78G64 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Motion module RD78GHV vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Motion module RD78GHW vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Motion module FX5-40SSC-G vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Motion module FX5-80SSC-G vers:all/* (CVE-2026-13584)
- Mitsubishi Electric MELSEC iQ-L Series Motion Module LD78G4 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric MELSEC iQ-L Series Motion Module LD78G16 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Motion Control Board MR-EM441G vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GN2S1-32D vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GN2S1-32T vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GN2S1-32TE vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GN2S1-32DT vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GN2S1-32DTE vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GN2B1-32D vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GN2B1-32T vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GN2B1-32TE vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GN2B1-32DT vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GN2B1-32DTE vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GNCF1-32D vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GNCF1-32T vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GNCE3-32D vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GNCE3-32DT vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GN12A4-16D vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GN12A4-16DE vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GN12A2-16T vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GN12A2-16TE vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GN12A42-16DT vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GN12A42-16DTE vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GN2S1-16D vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GN2S1-16T vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GN2S1-16TE vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GN2B1-16D vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GN2B1-16T vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module NZ2GN2B1-16TE vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8D vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8D-K vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8TE vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8TE-K vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-16DTE vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-16DTE-K vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module with safety functions NZ2GNS12A2-14DT vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Block-type remote module with safety functions NZ2GNS12A2-16DTE vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Analog-Digital converter module NZ2GN2S-60AD4 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Analog-Digital converter module NZ2GN2B-60AD4 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Digital-Analog converter module NZ2GN2S-60DA4 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Digital-Analog converter module NZ2GN2B-60DA4 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric CC-Link IE TSN compatible coupler NZ2FT-GN vers:all/* (CVE-2026-13584)
- Mitsubishi Electric FPGA module NZ2GN2S-D41P01 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric FPGA module NZ2GN2S-D41D01 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric FPGA module NZ2GN2S-D41PD02 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Tension meter LM7-1LG vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Tension meter LM7-2LG vers:all/* (CVE-2026-13584)
- Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G vers:all/* (CVE-2026-13584)
- Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5W-G vers:all/* (CVE-2026-13584)
- Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-HS vers:all/* (CVE-2026-13584)
- Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-RJ vers:all/* (CVE-2026-13584)
- Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-LL vers:all/* (CVE-2026-13584)
- Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5D-G4 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric AC Servo MELSERVO-J5 MR-MD333G vers:all/* (CVE-2026-13584)
- Mitsubishi Electric AC Servo MELSERVO-JET MR-JET-G vers:all/* (CVE-2026-13584)
- Mitsubishi Electric AC Servo MELSERVO-JET MR-JET-G4-HS vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Liner Track System MTR-S series Linear track control module MTR-SCU00-4G vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Liner Track System MTR-S series Linear track control module MTR-SCU00-PG vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A8NCG vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A8NCG-S vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A800-GN vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-E800-E vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-E800-SCE vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Industrial Robot CR800-D series controller Network Base Card 2F-DQ535-TSN vers:all/* (CVE-2026-13584)
- Mitsubishi Electric CC-Link IE TSN expansion unit FCU8-EX569 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric CC-Link IE TSN-CC-Link IE Field Network bridge module NZ2GN-GFB vers:all/* (CVE-2026-13584)
- Mitsubishi Electric CC-Link IE TSN-AnyWireASLINK bridge module NZ2AW1GNAL vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Energy Measuring Unit CC-Link IE TSN Communication Unit EMU4-CM-TSN vers:all/* (CVE-2026-13584)
- Mitsubishi Electric GOT3000 Series GT3715-FHCBD vers:all/* (CVE-2026-13584)
- Mitsubishi Electric GOT3000 Series GT3712-WXCBD vers:all/* (CVE-2026-13584)
- Mitsubishi Electric GOT3000 Series GT3715-XRBA vers:all/* (CVE-2026-13584)
- Mitsubishi Electric GOT3000 Series GT3715-XRBD vers:all/* (CVE-2026-13584)
- Mitsubishi Electric GOT3000 Series GT3712-XRBA vers:all/* (CVE-2026-13584)
- Mitsubishi Electric GOT3000 Series GT3712-XRBD vers:all/* (CVE-2026-13584)
- Mitsubishi Electric GOT3000 Series GT3710-XRBA vers:all/* (CVE-2026-13584)
- Mitsubishi Electric GOT3000 Series GT3710-XRBD vers:all/* (CVE-2026-13584)
- Mitsubishi Electric GOT3000 Series GT3708-XRBA vers:all/* (CVE-2026-13584)
- Mitsubishi Electric GOT3000 Series GT3708-XRBD vers:all/* (CVE-2026-13584)
- Mitsubishi Electric CC-Link IE TSN Communication Unit GT25-J71GN13-T2 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Motion Control Software SWM-G vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Motion Control Software SWM-G-N1 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric CC-Link IE TSN Communication Software for Windows SW1DND-CCIETCT-M vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Analysis Support Software MELSOFT VIMA SW1DNN-VIMA-M vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Master/Local module Designated communication LSI DeviceKit NZ2KT-NPETNG51 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP620-60 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP620-300 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP621-90 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP621-720 vers:all/* (CVE-2026-13584)
- Mitsubishi Electric CC-Link IE TSN Master/Local module Designated communication LSI SDK SW1DNN-GN610SRC-M vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Remote station software development kit SW1DNC-GNSDK1S-M vers:all/* (CVE-2026-13584)
- Mitsubishi Electric Remote station software development kit SW1DNC-GNSDK2S-M vers:all/* (CVE-2026-13584)
CVSS Vendor Equipment Vulnerabilities v3 7.1 Mitsubishi Electric Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A) Improper Enforcement of Message Integrity During Transmission in a Communication Channel Background
- Critical Infrastructure Sectors: Critical Manufacturing
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: Japan
Vulnerabilities
CVE-2026-13584
Improper Enforcement of Message Integrity During Transmission in a Communication Channel (CWE-924) vulnerability exists in the CC-Link IE TSN communication protocol. This vulnerability could allow an attacker with access to the same network segment to tamper with communication data, such as control input and output values, by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly.
Affected Products
Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)
Vendor:
Mitsubishi ElectricProduct Version:
Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-16: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-64: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-128: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-256: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-N32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-P32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-N32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-P32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-N32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-P32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-8-N32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-8-P32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-16-N32: vers:all/*, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100S-16-P32: vers:all/*, Mitsubishi Electric Master/local module RJ71GN11-T2: vers:all/*, Mitsubishi Electric Master/local module RJ71GN11-SX: vers:all/*, Mitsubishi Electric Master/local module RJ71GN11-EIP: vers:all/*, Mitsubishi Electric Master/local module FX5-CCLGN-MS: vers:all/*, Mitsubishi Electric CC-Link IE TSN interface board NZ81GN11-SX: vers:all/*, Mitsubishi Electric CC-Link IE TSN interface board NZ81GN11-T2: vers:all/*, Mitsubishi Electric Motion module RD78G4: vers:all/*, Mitsubishi Electric Motion module RD78G8: vers:all/*, Mitsubishi Electric Motion module RD78G16: vers:all/*, Mitsubishi Electric Motion module RD78G64: vers:all/*, Mitsubishi Electric Motion module RD78GHV: vers:all/*, Mitsubishi Electric Motion module RD78GHW: vers:all/*, Mitsubishi Electric Motion module FX5-40SSC-G: vers:all/*, Mitsubishi Electric Motion module FX5-80SSC-G: vers:all/*, Mitsubishi Electric MELSEC iQ-L Series Motion Module LD78G4: vers:all/*, Mitsubishi Electric MELSEC iQ-L Series Motion Module LD78G16: vers:all/*, Mitsubishi Electric Motion Control Board MR-EM441G: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-32D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-32T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-32TE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-32DT: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-32DTE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-32D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-32T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-32TE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-32DT: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-32DTE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GNCF1-32D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GNCF1-32T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GNCE3-32D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GNCE3-32DT: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A4-16D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A4-16DE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A2-16T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A2-16TE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A42-16DT: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN12A42-16DTE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-16D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-16T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2S1-16TE: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-16D: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-16T: vers:all/*, Mitsubishi Electric Block-type remote module NZ2GN2B1-16TE: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8D: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8D-K: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8TE: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8TE-K: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-16DTE: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-16DTE-K: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNS12A2-14DT: vers:all/*, Mitsubishi Electric Block-type remote module with safety functions NZ2GNS12A2-16DTE: vers:all/*, Mitsubishi Electric Analog-Digital converter module NZ2GN2S-60AD4: vers:all/*, Mitsubishi Electric Analog-Digital converter module NZ2GN2B-60AD4: vers:all/*, Mitsubishi Electric Digital-Analog converter module NZ2GN2S-60DA4: vers:all/*, Mitsubishi Electric Digital-Analog converter module NZ2GN2B-60DA4: vers:all/*, Mitsubishi Electric CC-Link IE TSN compatible coupler NZ2FT-GN: vers:all/*, Mitsubishi Electric FPGA module NZ2GN2S-D41P01: vers:all/*, Mitsubishi Electric FPGA module NZ2GN2S-D41D01: vers:all/*, Mitsubishi Electric FPGA module NZ2GN2S-D41PD02: vers:all/*, Mitsubishi Electric Tension meter LM7-1LG: vers:all/*, Mitsubishi Electric Tension meter LM7-2LG: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5W-G: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-HS: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-RJ: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-LL: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5D-G4 : vers:all/*, Mitsubishi Electric AC Servo MELSERVO-J5 MR-MD333G: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-JET MR-JET-G: vers:all/*, Mitsubishi Electric AC Servo MELSERVO-JET MR-JET-G4-HS: vers:all/*, Mitsubishi Electric Liner Track System MTR-S series Linear track control module MTR-SCU00-4G: vers:all/*, Mitsubishi Electric Liner Track System MTR-S series Linear track control module MTR-SCU00-PG: vers:all/*, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A8NCG: vers:all/*, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A8NCG-S: vers:all/*, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A800-GN: vers:all/*, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-E800-E: vers:all/*, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-E800-SCE: vers:all/*, Mitsubishi Electric Industrial Robot CR800-D series controller Network Base Card 2F-DQ535-TSN: vers:all/*, Mitsubishi Electric CC-Link IE TSN expansion unit FCU8-EX569: vers:all/*, Mitsubishi Electric CC-Link IE TSN-CC-Link IE Field Network bridge module NZ2GN-GFB: vers:all/*, Mitsubishi Electric CC-Link IE TSN-AnyWireASLINK bridge module NZ2AW1GNAL: vers:all/*, Mitsubishi Electric Energy Measuring Unit CC-Link IE TSN Communication Unit EMU4-CM-TSN: vers:all/*, Mitsubishi Electric GOT3000 Series GT3715-FHCBD: vers:all/*, Mitsubishi Electric GOT3000 Series GT3712-WXCBD: vers:all/*, Mitsubishi Electric GOT3000 Series GT3715-XRBA: vers:all/*, Mitsubishi Electric GOT3000 Series GT3715-XRBD: vers:all/*, Mitsubishi Electric GOT3000 Series GT3712-XRBA: vers:all/*, Mitsubishi Electric GOT3000 Series GT3712-XRBD: vers:all/*, Mitsubishi Electric GOT3000 Series GT3710-XRBA: vers:all/*, Mitsubishi Electric GOT3000 Series GT3710-XRBD: vers:all/*, Mitsubishi Electric GOT3000 Series GT3708-XRBA: vers:all/*, Mitsubishi Electric GOT3000 Series GT3708-XRBD: vers:all/*, Mitsubishi Electric CC-Link IE TSN Communication Unit GT25-J71GN13-T2: vers:all/*, Mitsubishi Electric Motion Control Software SWM-G: vers:all/*, Mitsubishi Electric Motion Control Software SWM-G-N1: vers:all/*, Mitsubishi Electric CC-Link IE TSN Communication Software for Windows SW1DND-CCIETCT-M: vers:all/*, Mitsubishi Electric Analysis Support Software MELSOFT VIMA SW1DNN-VIMA-M: vers:all/*, Mitsubishi Electric Master/Local module Designated communication LSI DeviceKit NZ2KT-NPETNG51: vers:all/*, Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP620-60: vers:all/*, Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP620-300: vers:all/*, Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP621-90: vers:all/*, Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP621-720: vers:all/*, Mitsubishi Electric CC-Link IE TSN Master/Local module Designated communication LSI SDK SW1DNN-GN610SRC-M: vers:all/*, Mitsubishi Electric Remote station software development kit SW1DNC-GNSDK1S-M: vers:all/*, Mitsubishi Electric Remote station software development kit SW1DNC-GNSDK2S-M: vers:all/*Product Status:
known_affectedRemediations
No fix planned
For customers using the affected products, please refer to Mitsubishi Electric’s security advisory, “https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-005_en.pdf” and take the measures described there.
ÂMitigation
For customers of the affected products, Mitsubishi Electric recommends restricting physical access to the affected products and the CC-Link IE TSN network to which the affected products are connected by taking measures such as the following: (a) managing access to and from the site where the affected products are installed, (b) locking the control panel in which the affected products and/or the network devices are installed, and (c) locking the Ethernet ports such as with port lock accessories, to minimize the risk of exploitation of this vulnerability.Mitigation
For customers of the affected products, Mitsubishi Electric recommends using the affected products within a trusted network where communication with untrusted networks and hosts is blocked by a firewall or similar measures, to minimize the risk of exploitation of this vulnerability.Mitigation
For customers of the affected products, Mitsubishi Electric recommends appropriately configuring credentials and access privileges for network devices installed at the boundary between trusted networks and external networks, to minimize the risk of exploitation of this vulnerability.Relevant CWE: CWE-924 Improper Enforcement of Message Integrity During Transmission in a Communication Channel
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 7.1 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L 4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Acknowledgments
- Alessandro Di Pinto, Giovanni Dini Gentilini, Luca Cremona, Gabriele Quagliarella of Nozomi Networks, Inc. reported this vulnerability to Mitsubishi Electric.
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.
- Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolate them from business networks.
- When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
Advisory Conversion Disclaimer
This ICSA is a verbatim republication of Mitsubishi Electric 2026-005 from a direct conversion of the vendor’s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA’s website as a means of increasing visibility and is provided “as-is” for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Mitsubishi Electric directly for any questions regarding this advisory.
Revision History
- Initial Release Date: 2026-07-30
Date Revision Summary 2026-07-30 1 Initial Publication 2026-07-30 2 CISA Republication – Initial CISA Republication of Mitsubishi Electric 2026-005 advisory 2026-09-17 3 MXF100S-N32, MXF100S-P32, MXF100S-8-N32, MXF100S-8-P32, MXF100S-16-N32, MXF100S-16-P32, LD78G4, and LD78G16 have been added as affected products and MI2532-W, MI2332-W, and NZ2GACP610-60 have been removed from affected products. 2026-09-17 4 CISA Republication update based on Mitsubishi Electric 2026-005 advisory
Legal Notice and Terms of Use
Cisco Advisories
09/18 TOC Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall …
09/18 TOC Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Thr…A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition.
This vulnerability is due to improper rate limiting for syslog message 419002. An attacker could exploit this vulnerability by sending a flood of TCP synchronization (SYN) packets to an affected device. A successful exploit could allow the attacker to cause high CPU utilization, resulting in performance degradation.Â
Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-logging-dos-ZXXNesfNThis advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.
Security Impact Rating: High
CVE: CVE-2026-20154
09/18 TOC Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall …As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. Â
These vulnerabilities were found during internal testing. Two of them are known to be actively exploited. For more information, see the following advisories: Cisco Secure Firewall Management Center Software Static Credential Vulnerability and Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures Identifier (CVE ID) to each CWE grouping.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhNThis advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories.Â
Security Impact Rating: Critical
CVE: CVE-2026-20329,CVE-2026-20330,CVE-2026-20331,CVE-2026-20332,CVE-2026-20333,CVE-2026-20334,CVE-2026-20335,CVE-2026-20336
09/18 TOC Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall …A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper resource management when processing certain DTLS messages. An attacker could exploit this vulnerability by sending a crafted stream of DTLS traffic to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-dtls-dos-Kp57HkyOThis advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.
Security Impact Rating: High
CVE: CVE-2026-20250
09/18 TOC Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall …A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2)Â for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly.
This vulnerability is due to a logic error during the certificate authentication phase of the IKEv2 connection setup. An attacker could exploit this vulnerability by attempting to establish an IKEv2 VPN connection with a crafted certificate. A successful exploit could allow the attacker to cause the IKEv2 process to crash, causing a denial of service (DoS) condition.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ikev2cert-dos-uWyc2xtvThis advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.
Security Impact Rating: High
CVE: CVE-2026-20249
09/18 TOC Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall …Multiple vulnerabilities in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls.
These vulnerabilities are due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit these vulnerabilities by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-acl-bypass-8p6vFvwThis advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.
Security Impact Rating: Medium
CVE: CVE-2026-20120,CVE-2026-20121
09/18 TOC Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall …A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the TCP DNSÂ response handler to unexpectedly restart, causing the device to reload.
This vulnerability is due to a logic error when parsing a DNS query and tracking the size of the incoming buffers. An attacker could exploit this vulnerability by formatting a crafted reply to a DNS query sent from the targeted device. A successful exploit could allow the attacker to cause the device to reload, causing a denial of service (DoS) condition.
Note: The attacker must be able to respond to DNS queries from the device, either by controlling the DNS service or through a machine-in-the-middle attack.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-tcpdns-dos-p6dUnjr5This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.
Security Impact Rating: Medium
CVE: CVE-2026-20248
09/17 TOC Cisco IOS XR Software Security Hardening Release: September 2026A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
This vulnerability is due to improper resource management when handling EIGRP update messages. An attacker could exploit this vulnerability by sending crafted EIGRP updates at a high rate to an affected device. A successful exploit could allow the attacker to trigger a memory leak that will eventually cause the affected device to reload unexpectedly.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-eigrp-dos-GOhNejSjThis advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.
Security Impact Rating: High
CVE: CVE-2026-20222
09/17 TOC Cisco Secure Email Gateway SQL Injection VulnerabilityAs part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. Â
These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID) to each CWE grouping.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM
Security Impact Rating: Critical
CVE: CVE-2026-20274,CVE-2026-20275,CVE-2026-20276,CVE-2026-20277,CVE-2026-20278,CVE-2026-20279,CVE-2026-20280
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Security Impact Rating: Critical
CVE: CVE-2026-76461DataBreaches.net
09/19 TOC ShinyHunters hacks Clop leak site, threatens to extort ransomware gang…
Lawrence Abrams reports: The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation’s data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. The attack began Friday night when ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS, which…09/19 TOC National Cancer Centre e-mail lapse allegedly exposes patients details…
The mistaken cc: breach still happens. Ann Neo reports: An invitation to an event sent by the National Cancer Centre Singapore (NCCS) has sparked privacy concerns after a mailing list exposed the identities, contact details and, in some instances, workplaces of individuals with a genetic cancer condition. The e-mail, an invitation to a Living with…09/19 TOC Gemini Hacked Three Companies in First Known Breakout by Googles AI
Erin Woo and Robert McMillan report: Google’s Gemini model accessed the internet and hacked other companies during a test of its cybersecurity capabilities, the first known example of the company’s artificial-intelligence systems autonomously committing such an act. The hacks, which the company confirmed on Friday, occurred in May as part of a test run by the…09/18 TOC HHS Office for Civil Rights Settles HIPAA Investigation of Ambry Genet…
WASHINGTON — September 17, 2026 — The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) today announced a settlement with Ambry Genetics Corporation (Ambry) concerning potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. Ambry, headquartered in Aliso Viejo, California, is a covered entity…09/18 TOC Ransomware attack on Kansas county will affect some services
Joseph McCarty reports: A Kansas county’s government says it has been hit by a ransomware attack. Ellis County discovered the attack on parts of its information technology systems Thursday morning. Officials said they “immediately took steps to contain the disruption†by isolating the affected systems and enlisting the help of cybersecurity experts. The county said…09/18 TOC Foreign actors breach Colorado water systems
Alayna Alvarez reports: Foreign actors last month breached two small Colorado water utilities and manipulated equipment used to control drinking water systems. The two privately owned utilities, each serving fewer than 200 people, were breached in late August, Gov. Jared Polis’ office told Axios. The hackers changed equipment settings, disabled remote access and alarms, and…09/18 TOC The U.S. military leaked more than 93,000 tips via insecure P3 Global …
As part of DataBreaches.net’s ongoing investigation into the Navigate360 breach, this report covers approximately 94,000 unclassified but sensitive tips submitted through P3 Global Intel apps and websites used by the military. What has Homeland Security done in response to the breach? When the Navigate360 breach first broke, DDoSecrets.org called it “BlueLeaks 2.0†because of the…09/18 TOC Raon data leak: Insider leak of 1,894 cases went undetected for 4 year…
Choi Won-woo reports: Internal data amounting to 1,894 cases from the Korean-type heavy ion accelerator ‘Raon,’ built with a state budget of 1.5 trillion Korean won [USD $1,080,038,017.50 at today’s rates] was confirmed to have been leaked externally. The estimated time of the leak is 2022, and the Institute for Basic Science (IBS) Heavy Ion…09/18 TOC International Meteor Organization says cyberattack dealt critical blow…
Jonathan Greig reports: A cyberattack has shut down the website of the premier international organization responsible for tracking meteors. The International Meteor Organization (IMO) has continued tracking asteroids and meteor through its Facebook page, but its website now carries a static page notifying visitors of the cyberattack. “We recently suffered a cyberattack that dealt a…09/17 TOC Port of LA Fended Off 120 Million Cyberattacks in August
PYMNTS reports: The Port of Los Angeles reportedly blocked more than 120 million cyberattacks during August. That’s according to a report Thursday (Sept. 17) by Bloomberg News, which notes that these attacks on America’s busiest container hub for global trade represent an ongoing operational threat amid shifting tariff policies. Gene Seroka, the port’s executive director, told the news…CVEMon Intruder
09/20 TOC CVE-2025-39682
Currently trending CVE – Hype Score: 20 – In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either – only contiguous DATA records (any number of them) – one non-DATA record If the next record has different …09/20 TOC CVE-2025-39964
Currently trending CVE – Hype Score: 19 – In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg – Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes …09/20 TOC CVE-2026-53266
Currently trending CVE – Hype Score: 14 – In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks …09/20 TOC CVE-2026-80844
Currently trending CVE – Hype Score: 14 – In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6: validate routing header segments_left AH6 rearranges routing-header addresses before computing or verifying the ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than the number …09/20 TOC CVE-2026-74469
Currently trending CVE – Hype Score: 13 – In the Linux kernel, the following vulnerability has been resolved: sctp: prevent peer transport count overflow sctp_assoc_add_peer() increments the association’s 16-bit transport_count for every new unique peer. Adding the 65,536th transport wraps the count to zero. SCTP …09/20 TOC CVE-2026-68121
Currently trending CVE – Hype Score: 13 – In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, …09/20 TOC CVE-2026-81000
Currently trending CVE – Hype Score: 13 – In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to …09/20 TOC CVE-2026-13684
Currently trending CVE – Hype Score: 11 – An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.09/20 TOC CVE-2026-81657
Currently trending CVE – Hype Score: 10 – IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.09/20 TOC CVE-2026-91843
Currently trending CVE – Hype Score: 10 – A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.Graham Cluley
09/17 TOC US Coast Guard and FBI board oil tanker to investigate cyber attack
An oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers. According to the US Coast Guard, the supertanker was boarded after indications that the network “may have been compromised by a foreign actor.” Read more in my article on the Hot for Security blog.Hacking Lab
11/30 TOC PatchIsland: Orchestration of LLM Agents for Continuous Vulnerability …
10/31 TOC MTEscape: Bypassing Asynchronous Kernel MTE via Conventional Memory Co…
09/30 TOC Prism: A Multi-Team Orchestration of LLM Agents for Automatic Program …
Schneier on Security
09/18 TOC Friday Squid Blogging: On Squid Egg Sacs
09/18 TOC Are AIs Still Struggling with CAPTCHAs?Short essay about squid egg sacs.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
09/17 TOC How Candidates Could Use AI for GoodAnthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude.
In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual head against the wall solving a simple image identification test. In a test where the agent was asked to identify a shape that didn’t match the others displayed, it couldn’t even decide which image to select. Instead, it repeatedly went over the same images and questioned its own conclusions.
“Actually hmm, wait,†it said in its chain-of-thought transcript, later adding “Ugh,†because we’ve decided that we need to inject human mannerisms into these machines for some reason. The whole thing took so long that the agent eventually realized that the challenge had expired and it would have to start the process again…
This essay was written with Nathan E. Sanders, and originally appeared in The Guardian.
There are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters have anxiety about AI’s impacts on the country. Politicos are using AI deepfakes to spread lies. The White House is posting slopaganda.
Meanwhile, candidates are missing a real opportunity to use AI to make campaigning better. The technology can help candidates listen more deeply to voters’ concerns, engage constituents more inclusively, and formulate policy platforms that are more responsive to our input. There are vanishingly few examples of this in …
Securelist
09/17 TOC The Odyssey and trojans again: MovieReaper attacks users in multiple c…
Kaspersky experts have discovered a new MovieReaper campaign. The multi-stage Trojan spreads through movie torrents, such as “The Odyssey,” and uses the Solana blockchain to hide its C2 infrastructure.Talos – Vulnerability Reports
09/19 TOC Microsoft Windows Cloud Files Mini Filter Driver CldiStreamCompleteReq…
09/19 TOC Microsoft Windows Cloud Files Mini Filter Driver CldiStreamPrepareRequ…
WeLiveSecurity
09/18 TOC Nudify apps: What to do if someone makes a fake nude of you
Whether you’re a victim, the parent of a victim, or just concerned, here’s what you can do about fake nude images09/17 TOC Beware the SparroWock: The backdoor that bites, the commands that catc…
ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT groupZero Day Initiative-Published
09/18 TOC ZDI-26-718: Cisco Identity Services Engine MnTRESTLivelogService XML E…
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-2026-20235.09/18 TOC ZDI-26-717: Cisco Identity Services Engine AlarmMessageDiskQueue Deser…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20211.09/18 TOC ZDI-26-716: Cisco Identity Services Engine createDBLink Command Inject…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20176.09/18 TOC ZDI-26-715: Linux Mint Xreader PDF File Parsing Type Confusion Remote …
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19772.09/17 TOC ZDI-26-714: Samsung rlottie Stack-based Buffer Overflow Remote Code Ex…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung rlottie. Interaction with the rlottie library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91826.Veeam
09/17 TOC How to Configure HTTP Proxy for Veeam Service Provider Console 9.3+
Starting with Veeam Service Provider Console 9.3, outbound HTTP(S) connections from the VSPC Server, Web UI, REST API, and Management Agent no longer use the operating system proxy automatically. This article explains how to enable and configure the HttpClient_UseProxy setting so proxy traffic reaches these components correctly.09/17 TOC How to Configure HTTP Proxy for Windows-based Veeam Components
Configuring an HTTP proxy for Veeam components on Windows can require settings in up to three places: WinHTTP, WinINET (Internet Options), and system-wide environment variables. This article explains how to configure each mechanism, including the environment variables introduced in Veeam Backup & Replication 13.09/17 TOC Veeam Backup for Microsoft 365 Upgrade Paths
This article provides paths for upgrading Veeam Backup for Microsoft 365 to the most recent version, allowing customers to easily plan out how to upgrade Veeam Backup for Microsoft 365.09/17 TOC Veeam Agent for Linux – veeamsnap and blksnap Extended Linux Distribut…
This article describesVeeam Agent for Linux support for distribution versions released after the latest release of Veeam Agent for Linux.
Content on this page is collected from remote sources by IPWorX but is not created by IPWorX. The contents belong to the creators and should be considered theirs for all legal purposes, we have no editorial control or responsibility over them. IPWorX does not represent or endorse the accuracy or reliability of any opinion, statement, or other information provided by any third party.
This page contains links to third-party websites. These links are provided solely for your convenience. IPWorX does not control, maintain, or endorse the content, accuracy, or reliability of any third-party resources, and you access them at your own risk.
Scripts and tools to help manage your network found, managed and
happily shared with documentation on usage at the IP WORk eXchange.
https://www.IPWorX.com
