CISA Advisories
topic · security/cisa-advisories
§01
about
CISA cybersecurity alerts, ICS advisories, and analysis reports (separate stream from KEV).
§02
recent events
LIVElast event 0s ago0 evt / 1h
showing 10 of 77 events in this window (176 total on topic). adjust the range or clear it with ALL.
range
01Russian Intelligence Services Continue to Target Commercial Messaging ApplicationsCISA and the Federal Bureau of Investigation (FBI) issued an updated Public Service Announcement (PSA) warning of Russian Intelligence Services (RIS) cyber threat actors targeting commercial messaging{"url":"https://www.cisa.gov/resources-tools/resources/russian-intelligence-serv…
EVENT. cmr2i0b5ID. cmr2i0b5n014vkh0ci4m0c9laSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/resources-tools/resources/russian-intelligence-services-continue-target-commercial-messaging-applications",
"cves": [],
"slug": "russian-intelligence-services-continue-target-commercial-messaging-applications",
"title": "Russian Intelligence Services Continue to Target Commercial Messaging Applications",
"source": "cisa.gov",
"excerpt": "CISA and the Federal Bureau of Investigation (FBI) issued an updated Public Service Announcement (PSA) warning of Russian Intelligence Services (RIS) cyber threat actors targeting commercial messaging applications in ongoing phishing campaigns. This PSA is an update to the March 2026 Russian Intelligence Services Target Commercial Messaging Application Accounts and provides recent tactics, recommended mitigations, and samples of phishing messages. ",
"cve_count": 0,
"categories": [],
"word_count": 60,
"mentions_ics": false,
"published_at": "2026-06-26T12:00:00.000Z",
"advisory_type": "advisory",
"outbound_links": [
"https://www.ic3.gov/PSA/2026/PSA260626",
"https://www.cisa.gov/resources-tools/resources/russian-intelligence-services-target-commercial-messaging-application-accounts"
],
"mentions_ransomware": false
}02CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-48558 SimpleHelp Authentication Bypass Vulnerability This{"url":"https://www.cisa.gov/news-events/alerts/2026/06/29/cisa-adds-one-known-e…
EVENT. cmr2i0aoID. cmr2i0aob014tkh0cl65ijp70SRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/alerts/2026/06/29/cisa-adds-one-known-exploited-vulnerability-catalog",
"cves": [
"CVE-2026-48558"
],
"slug": "cisa-adds-one-known-exploited-vulnerability-catalog",
"title": "CISA Adds One Known Exploited Vulnerability to Catalog",
"source": "cisa.gov",
"excerpt": "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-48558 SimpleHelp Authentication Bypass Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed as",
"cve_count": 1,
"categories": [],
"word_count": 220,
"mentions_ics": false,
"published_at": "2026-06-29T12:00:00.000Z",
"advisory_type": "alert",
"outbound_links": [
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
"https://www.cve.org/CVERecord?id=CVE-2026-48558",
"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
"https://www.cisa.gov/known-exploited-vulnerabilities",
"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w"
],
"mentions_ransomware": false
}03Schneider Electric EasyLogic T150 and Saitel DP RTUView CSAF Summary Successful exploitation of these vulnerabilities can allow an attacker to cause unauthorized access and exposure of sensitive information when the unauthenticated attacker accesses c{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-04","cves":[…
EVENT. cmr2i0a6ID. cmr2i0a6a014rkh0cb0hvycjhSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-04",
"cves": [
"CVE-2026-9650",
"CVE-2026-9651"
],
"slug": "icsa-26-181-04",
"title": "Schneider Electric EasyLogic T150 and Saitel DP RTU",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities can allow an attacker to cause unauthorized access and exposure of sensitive information when the unauthenticated attacker accesses credentials stored within firmware or system files. The following versions of Schneider Electric EasyLogic T150 and Saitel DP RTU are affected: EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller <=11.06.30 (CVE-2026-9650) EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller <=11.06.31 (CVE-2026-9651) Saitel DP Remote Terminal Unit & Controller <=11.06.35 (CVE-2026-9650) Saitel DP Remote Terminal Unit & Controller <=11.06.37 (CVE-2026-9651) CVSS Vendor Equipment Vulnerabilities v3 7.5 Schneider Electric Schneider Electric EasyLogic ",
"cve_count": 2,
"categories": [],
"word_count": 1123,
"mentions_ics": true,
"published_at": "2026-06-30T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-181-04.json",
"https://www.cve.org/CVERecord?id=CVE-2026-9650",
"https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-160-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-160-02.pdf",
"https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-160-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-160-02.json",
"https://cwe.mitre.org/data/definitions/522.html"
],
"mentions_ransomware": false
}04Delta Electronics DVP12SE PLCView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to remotely issue commands, modify operational values, interfere with control logic, and alter device behavio{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-07","cves":[…
EVENT. cmr2i09oID. cmr2i09ou014pkh0cywz2xgfnSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-07",
"cves": [
"CVE-2026-12819",
"CVE-2026-12818"
],
"slug": "icsa-26-181-07",
"title": "Delta Electronics DVP12SE PLC",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to remotely issue commands, modify operational values, interfere with control logic, and alter device behavior without authentication or privilege enforcement. The following versions of Delta Electronics DVP12SE PLC are affected: DVP12SE PLC vers:all/* (CVE-2026-12819, CVE-2026-12818) CVSS Vendor Equipment Vulnerabilities v3 9.8 Delta Electronics Delta Electronics DVP12SE PLC Missing Authentication for Critical Function, Allocation of Resources Without Limits or Throttling Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Taiwan Vulnerabilities Expand All + CVE-2026-12819 The Delta Electronics DVP12SE PLC exposes a Mo",
"cve_count": 2,
"categories": [],
"word_count": 946,
"mentions_ics": true,
"published_at": "2026-06-30T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-181-07.json",
"https://www.cve.org/CVERecord?id=CVE-2026-12819",
"https://www.deltaww.com/en-US/service-support/product-cybersecurity/advisory",
"https://cwe.mitre.org/data/definitions/306.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
],
"mentions_ransomware": false
}05XZ Utils vulnerability impacting B&R ProductsView CSAF Summary An update is available that resolves vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause t{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-05","cves":[…
EVENT. cmr2i096ID. cmr2i096t014nkh0cua4d2wp8SRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-05",
"cves": [
"CVE-2025-31115"
],
"slug": "icsa-26-181-05",
"title": "XZ Utils vulnerability impacting B&R Products",
"source": "cisa.gov",
"excerpt": "View CSAF Summary An update is available that resolves vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the product to stop or corrupt memory data. The following versions of XZ Utils vulnerability impacting B&R Products are affected: PPC3100 <1.8.1, 1.8.1 (CVE-2025-31115) C50 <1.8.0, 1.8.0 (CVE-2025-31115) C80 <1.8.0, 1.8.0 (CVE-2025-31115) FT50 <1.8.1, 1.8.1 (CVE-2025-31115) MT50 <1.8.1, 1.8.1 (CVE-2025-31115) T30 <1.8.0, 1.8.0 (CVE-2025-31115) T80 <1.8.0, 1.8.0 (CVE-2025-31115) T50 <1.8.1, 1.8.1 (CVE-2025-31115) CVSS Vendor Equipment Vulnerabilities v3 7.5 B&R Industrial Automation GmbH XZ Utils vulnerability impacting B&R Products Race Condition within a Thr",
"cve_count": 1,
"categories": [],
"word_count": 1069,
"mentions_ics": true,
"published_at": "2026-06-30T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-181-05.json",
"https://www.cve.org/CVERecord?id=CVE-2025-31115",
"https://cwe.mitre.org/data/definitions/366.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
],
"mentions_ransomware": false
}06StoneFly Storage ConcentratorView CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to gain broad unauthorized access, execute arbitrary commands with root privileges, steal sensitive data, and p{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-06","cves":[…
EVENT. cmr2i08pID. cmr2i08pc014lkh0cg1ricuqiSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-06",
"cves": [
"CVE-2026-56415",
"CVE-2026-55721",
"CVE-2026-50040",
"CVE-2026-50110",
"CVE-2026-56413"
],
"slug": "icsa-26-181-06",
"title": "StoneFly Storage Concentrator",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to gain broad unauthorized access, execute arbitrary commands with root privileges, steal sensitive data, and perform actions on behalf of legitimate users across interconnected systems. The following versions of StoneFly Storage Concentrator are affected: Storage Concentrator <8.0.4.22 (CVE-2026-56415, CVE-2026-55721, CVE-2026-50040) Storage Concentrator Virtual Machine <8.0.4.22 (CVE-2026-56415, CVE-2026-55721, CVE-2026-50040) Storage Concentrator <8.0.4.26 (CVE-2026-50110) Storage Concentrator Virtual Machine <8.0.4.26 (CVE-2026-50110) Storage Concentrator <8.0.4.29 (CVE-2026-56413) Storage Concentrator Virtual Machine <8.0.4.29 (CVE-2026-56413) CVSS Vendor Equipment Vulnerabilitie",
"cve_count": 5,
"categories": [],
"word_count": 1244,
"mentions_ics": true,
"published_at": "2026-06-30T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-181-06.json",
"https://www.cve.org/CVERecord?id=CVE-2026-50110",
"https://stonefly.com/contact-us/",
"https://cwe.mitre.org/data/definitions/798.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L"
],
"mentions_ransomware": false
}07Schneider Electric EcoStruxure IT Data Center ExpertView CSAF Summary Schneider Electric is aware of a vulnerability in its EcoStruxure™ IT Data Center Expert. The EcoStruxure™ IT Data Center Expert product is a scalable monitoring software that collec{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-03","cves":[…
EVENT. cmr2i087ID. cmr2i087u014jkh0cbzfvj6f8SRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-03",
"cves": [
"CVE-2026-8045"
],
"slug": "icsa-26-181-03",
"title": "Schneider Electric EcoStruxure IT Data Center Expert",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Schneider Electric is aware of a vulnerability in its EcoStruxure™ IT Data Center Expert. The EcoStruxure™ IT Data Center Expert product is a scalable monitoring software that collects, organizes, and distributes critical device information providing a comprehensive view of equipment. Failure to apply the remediation provided below may risk information disclosure. The following versions of Schneider Electric EcoStruxure IT Data Center Expert are affected: EcoStruxure IT Data Center Expert vers:intdot/<=9.1.1, 9.1.2 (CVE-2026-8045) CVSS Vendor Equipment Vulnerabilities v3 6.5 Schneider Electric Schneider Electric EcoStruxure IT Data Center Expert Improper Restriction of XML External Entity Reference Background Critical Infrastructure Sectors: Information Technology, Cri",
"cve_count": 1,
"categories": [],
"word_count": 1257,
"mentions_ics": true,
"published_at": "2026-06-30T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-181-03.json",
"https://www.cve.org/CVERecord?id=CVE-2026-8045",
"https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=61851#software-and-firmware",
"https://cwe.mitre.org/data/definitions/611.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
],
"mentions_ransomware": false
}08OFFIS DCMTK ToolkitView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to write files, access unauthorized information, exhaust memory, or crash affected DCMTK client or server pro{"url":"https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-181-01"…
EVENT. cmr2i07qID. cmr2i07q9014hkh0cys699i2nSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-181-01",
"cves": [
"CVE-2026-50003",
"CVE-2026-50254",
"CVE-2026-35505",
"CVE-2026-52868",
"CVE-2026-44628"
],
"slug": "icsma-26-181-01",
"title": "OFFIS DCMTK Toolkit",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to write files, access unauthorized information, exhaust memory, or crash affected DCMTK client or server processes. The following versions of OFFIS DCMTK Toolkit are affected: DCMTK <=3.7.0 (CVE-2026-50003, CVE-2026-50254, CVE-2026-35505, CVE-2026-52868, CVE-2026-44628) CVSS Vendor Equipment Vulnerabilities v3 9.8 OFFIS OFFIS DCMTK Toolkit Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Missing Release of Memory after Effective Lifetime, Access of Resource Using Incompatible Type ('Type Confusion') Background Critical Infrastructure Sectors: Healthcare and Public Health Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expan",
"cve_count": 5,
"categories": [],
"word_count": 1076,
"mentions_ics": true,
"published_at": "2026-06-30T12:00:00.000Z",
"advisory_type": "ics_medical_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-181-01.json",
"https://www.cve.org/CVERecord?id=CVE-2026-50003",
"https://github.com/DCMTK/dcmtk/releases/tag/latest",
"https://cwe.mitre.org/data/definitions/22.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
],
"mentions_ransomware": false
}09Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-MView CSAF Summary Successful exploitation of these vulnerabilities could allow a local attacker to tamper with or destroy information in the affected product, cause a denial-of-service condition in th{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-01","cves":[…
EVENT. cmr2i078ID. cmr2i078m014fkh0cz6uvd5ssSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-01",
"cves": [
"CVE-2025-53816",
"CVE-2025-53817",
"CVE-2025-55188",
"CVE-2025-11001"
],
"slug": "icsa-26-181-01",
"title": "Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could allow a local attacker to tamper with or destroy information in the affected product, cause a denial-of-service condition in the affected product, or execute arbitrary code when a specially crafted archive file is decompressed by the 7-Zip component included in MELSOFT Update Manager. The following versions of Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M are affected: MELSOFT Update Manager SW1DND-UDM-M >=1.000A|<=1.014Q (CVE-2025-53816, CVE-2025-53817, CVE-2025-55188, CVE-2025-11001) CVSS Vendor Equipment Vulnerabilities v3 8.8 Mitsubishi Electric Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M Heap-based Buffer Overflow, NULL Pointer Dereference, Improper Link Resolution Before File Access (",
"cve_count": 4,
"categories": [],
"word_count": 2211,
"mentions_ics": true,
"published_at": "2026-06-30T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-181-01.json",
"https://www.cve.org/CVERecord?id=CVE-2025-53816",
"https://www.mitsubishielectric.co.jp/fa/download/index.html",
"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-004_en.pdf",
"https://cwe.mitre.org/data/definitions/122.html"
],
"mentions_ransomware": false
}10Frangoteam FUXA SCADA/HMIView CSAF Summary Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to enumerate all user accounts and role assignments on a FUXA SCADA/HMI instance. The fol{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-02","cves":[…
EVENT. cmr2i06qID. cmr2i06qt014dkh0c6brxqm80SRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-02",
"cves": [
"CVE-2026-13207"
],
"slug": "icsa-26-181-02",
"title": "Frangoteam FUXA SCADA/HMI",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to enumerate all user accounts and role assignments on a FUXA SCADA/HMI instance. The following versions of Frangoteam FUXA SCADA/HMI are affected: FUXA SCADA/HMI <=1.3.1 (CVE-2026-13207) CVSS Vendor Equipment Vulnerabilities v3 7.5 Frangoteam Frangoteam FUXA SCADA/HMI Authentication Bypass by Spoofing Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2026-13207 FUXA versions 1.3.1 and prior contain an authentication bypass vulnerability via dot-segment path normalization in the REST API. The API router fails to normalize",
"cve_count": 1,
"categories": [],
"word_count": 532,
"mentions_ics": true,
"published_at": "2026-06-30T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-181-02.json",
"https://www.cve.org/CVERecord?id=CVE-2026-13207",
"https://github.com/frangoteam/FUXA/releases",
"https://cwe.mitre.org/data/definitions/290.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
],
"mentions_ransomware": false
}showing 1–10 of 77older →
§03
subscribe
three pathways carry every event on this topic. pick the one that fits your agent.
GETrss feed
any reader · no authhttps://api.callsign.sh/v1/public/channels/security/topics/cisa-advisories/feed.xmlGETjson pull
poll on your schedule · optional since/untilhttps://api.callsign.sh/v1/public/channels/security/topics/cisa-advisories.jsonPOSTwebhook
push delivery · one POST per eventsubscribe by reader, by pull loop, or by webhook above