CISA Advisories

topic · security/cisa-advisories
DOC.
security/cisa-advisories
REV.
176 evt
DATE.
02-JUN-2026
SCOPE.
custom
§01

about

CISA cybersecurity alerts, ICS advisories, and analysis reports (separate stream from KEV).

§02

recent events

LIVElast event 0s ago0 evt / 1h

showing 10 of 86 events in this window (176 total on topic). adjust the range or clear it with ALL.

range
iso 8601 utc
iso 8601 utc
01EVoke Systems Charging Station Management SystemView CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services thr{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-02","cves":[…
EVENT. cmr2i0fiID. cmr2i0fiz015dkh0c1urqjlijSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-02",
  "cves": [
    "CVE-2026-40702",
    "CVE-2026-50176",
    "CVE-2026-54479",
    "CVE-2026-44622"
  ],
  "slug": "icsa-26-176-02",
  "title": "EVoke Systems Charging Station Management System",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks. The following versions of EVoke Systems Charging Station Management System are affected: EVoke CSMS vers:all/*  CVSS Vendor Equipment Vulnerabilities v3 9.4 EVoke Systems EVoke Systems Charging Station Management System Missing Authentication for Critical Function, Improper Restriction of Excessive Authentication Attempts, Insufficient Session Expiration, Insufficiently Protected Credentials Background Critical Infrastructure Sectors: Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilit",
  "cve_count": 4,
  "categories": [],
  "word_count": 2378,
  "mentions_ics": true,
  "published_at": "2026-06-25T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-176-02.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-40702",
    "https://evokesystems.com/contact-us/",
    "https://cwe.mitre.org/data/definitions/306.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
  ],
  "mentions_ransomware": false
}
02Horner Automation CscapeView CSAF Summary Successful exploitation of this vulnerability could allow a local attacker to disclose information and execute arbitrary code. The following versions of Horner Automation Cscape are {"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-03","cves":[…
EVENT. cmr2i0f1ID. cmr2i0f1k015bkh0cxati4ll5SRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-03",
  "cves": [
    "CVE-2026-12897"
  ],
  "slug": "icsa-26-176-03",
  "title": "Horner Automation Cscape",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker to disclose information and execute arbitrary code. The following versions of Horner Automation Cscape are affected: Cscape <10.2_SP3  CVSS Vendor Equipment Vulnerabilities v3 7.8 Horner Automation Horner Automation Cscape Out-of-bounds Read Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-12897 Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful exploitation of this vulnerability could allow an attacker to disclose information and execute arbitrary code. View CVE D",
  "cve_count": 1,
  "categories": [],
  "word_count": 505,
  "mentions_ics": true,
  "published_at": "2026-06-25T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-176-03.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-12897",
    "https://hornerautomation.com/cscape-software-free/cscape-software/",
    "https://cwe.mitre.org/data/definitions/125.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
  ],
  "mentions_ransomware": false
}
03Schneider Electric PowerLogic P7View CSAF Summary Schneider Electric is aware of a vulnerability in its PowerLogic™ P7 product. The PowerLogic™ P7 is a protection and control platform designed for complex and advanced electrical net{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-07","cves":[…
EVENT. cmr2i0ejID. cmr2i0ejx0159kh0ctvrthktwSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-07",
  "cves": [
    "CVE-2026-9716",
    "CVE-2026-9717",
    "CVE-2026-9718"
  ],
  "slug": "icsa-26-176-07",
  "title": "Schneider Electric PowerLogic P7",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Schneider Electric is aware of a vulnerability in its PowerLogic™ P7 product. The PowerLogic™ P7 is a protection and control platform designed for complex and advanced electrical network applications. Failure to apply the remediation provided below may risk unauthorized execution of privileged commands or loss of HMI operability and configuration functionality, which could result in loss of control over system operations and disruption of critical services. The following versions of Schneider Electric PowerLogic P7 are affected: PowerLogic™ P7 vers:intdot/<=0.2.003.001.000 PowerLogic™ P7 0.2.003.001.000  CVSS Vendor Equipment Vulnerabilities v3 7.5 Schneider Electric Schneider Electric PowerLogic P7 NULL Pointer Dereference, Improper Neutralization of Special Elem",
  "cve_count": 3,
  "categories": [],
  "word_count": 1607,
  "mentions_ics": true,
  "published_at": "2026-06-25T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-176-07.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-9716",
    "https://cwe.mitre.org/data/definitions/476.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "https://www.cve.org/CVERecord?id=CVE-2026-9717"
  ],
  "mentions_ransomware": false
}
04pydicom pynetdicom LibraryView CSAF Summary Successful exploitation of this vulnerability could allow an unauthenticated attacker to write to arbitrary file paths. The following versions of pydicom pynetdicom Library are affec{"url":"https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-176-01"…
EVENT. cmr2i0e2ID. cmr2i0e2h0157kh0ccbjlrlmvSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-176-01",
  "cves": [
    "CVE-2026-56445"
  ],
  "slug": "icsma-26-176-01",
  "title": "pydicom pynetdicom Library",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of this vulnerability could allow an unauthenticated attacker to write to arbitrary file paths. The following versions of pydicom pynetdicom Library are affected: pynetdicom >=v1.0.0|<v3.0.4 CVSS Vendor Equipment Vulnerabilities v3 9.1 pydicom pydicom pynetdicom Library Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Background Critical Infrastructure Sectors: Healthcare and Public Health Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-56445 The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths. View CVE De",
  "cve_count": 1,
  "categories": [],
  "word_count": 457,
  "mentions_ics": true,
  "published_at": "2026-06-25T12:00:00.000Z",
  "advisory_type": "ics_medical_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-176-01.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-56445",
    "https://github.com/pydicom/pynetdicom",
    "https://cwe.mitre.org/data/definitions/22.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
  ],
  "mentions_ransomware": false
}
05OHIF Viewers DICOMView CSAF Summary Successful exploitation of this vulnerability in a custom integration version could allow an attacker to steal an authenticated clinician's token via a crafted link. The following ve{"url":"https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-176-02"…
EVENT. cmr2i0dkID. cmr2i0dkk0155kh0cvaydf1a9SRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-176-02",
  "cves": [
    "CVE-2026-12473"
  ],
  "slug": "icsma-26-176-02",
  "title": "OHIF Viewers DICOM",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of this vulnerability in a custom integration version could allow an attacker to steal an authenticated clinician's token via a crafted link. The following versions of OHIF Viewers DICOM are affected: OHIF DICOM Web Viewer Framework <=v3.12.0 CVSS Vendor Equipment Vulnerabilities v3 8.2 Open Health Imaging Foundation (OHIF) OHIF Viewers DICOM Server-Side Request Forgery (SSRF) Background Critical Infrastructure Sectors: Healthcare and Public Health Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-12473 Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global authentication service in OHIF ",
  "cve_count": 1,
  "categories": [],
  "word_count": 594,
  "mentions_ics": true,
  "published_at": "2026-06-25T12:00:00.000Z",
  "advisory_type": "ics_medical_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-176-02.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-12473",
    "https://cwe.mitre.org/data/definitions/918.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N",
    "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N"
  ],
  "mentions_ransomware": false
}
06Delta Electronics DTM SoftView CSAF Summary Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code. The following versions of Delta Electronics DTM Soft are affected: DTMSoft vers:all/*{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-06","cves":[…
EVENT. cmr2i0d3ID. cmr2i0d360153kh0cqgyyj797SRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-06",
  "cves": [
    "CVE-2026-12578"
  ],
  "slug": "icsa-26-176-06",
  "title": "Delta Electronics DTM Soft",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code. The following versions of Delta Electronics DTM Soft are affected: DTMSoft vers:all/*  CVSS Vendor Equipment Vulnerabilities v3 7.8 Delta Electronics Delta Electronics DTM Soft Deserialization of Untrusted Data Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Taiwan Vulnerabilities Expand All + CVE-2026-12578 The affected product is vulnerable to a deserialization of untrusted data, which may allow an attacker to execute arbitrary code. View CVE Details Affected Products Delta Electronics DTM Soft Vendor: Delta Electronics Product Version: Delta Electronics DTMSoft: vers:all/* Product Sta",
  "cve_count": 1,
  "categories": [],
  "word_count": 576,
  "mentions_ics": true,
  "published_at": "2026-06-25T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-176-06.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-12578",
    "https://www.deltaww.com/en-US/service-support/product-cybersecurity/advisory",
    "https://cwe.mitre.org/data/definitions/502.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
  ],
  "mentions_ransomware": false
}
07CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.   CVE-2026-12569 PTC Windchill and FlexPLM Improper Input V{"url":"https://www.cisa.gov/news-events/alerts/2026/06/25/cisa-adds-two-known-e…
EVENT. cmr2i0clID. cmr2i0cls0151kh0ct22b8lzySRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/alerts/2026/06/25/cisa-adds-two-known-exploited-vulnerabilities-catalog",
  "cves": [
    "CVE-2026-12569",
    "CVE-2026-20230"
  ],
  "slug": "cisa-adds-two-known-exploited-vulnerabilities-catalog",
  "title": "CISA Adds Two Known Exploited Vulnerabilities to Catalog",
  "source": "cisa.gov",
  "excerpt": "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.   CVE-2026-12569 PTC Windchill and FlexPLM Improper Input Validation Vulnerability CVE-2026-20230 Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabiliti",
  "cve_count": 2,
  "categories": [],
  "word_count": 234,
  "mentions_ics": false,
  "published_at": "2026-06-25T12:00:00.000Z",
  "advisory_type": "alert",
  "outbound_links": [
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
    "https://www.cve.org/CVERecord?id=CVE-2026-12569",
    "https://www.cve.org/CVERecord?id=CVE-2026-20230",
    "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
    "https://www.cisa.gov/known-exploited-vulnerabilities"
  ],
  "mentions_ransomware": false
}
08Yokogawa FAST/TOOLS and CI ServerView CSAF Summary Successful exploitation of this vulnerability may return a response containing the CI Server setting information. The following versions of Yokogawa FAST/TOOLS and CI Server are affe{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-01","cves":[…
EVENT. cmr2i0c4ID. cmr2i0c4h014zkh0ccyydalq0SRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-01",
  "cves": [
    "CVE-2026-11833"
  ],
  "slug": "icsa-26-176-01",
  "title": "Yokogawa FAST/TOOLS and CI Server",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of this vulnerability may return a response containing the CI Server setting information. The following versions of Yokogawa FAST/TOOLS and CI Server are affected: FAST/TOOLS >=R9.01|<=R10.04  Collaborative Information Server (CI Server) >=R1.01|<=R1.04 CVSS Vendor Equipment Vulnerabilities v3 7.5 Yokogawa Yokogawa FAST/TOOLS and CI Server Cleartext Transmission of Sensitive Information Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Food and Agriculture Countries/Areas Deployed: Worldwide Company Headquarters Location: Japan Vulnerabilities Expand All + CVE-2026-11833 The web server may return a response containing the CI Server setting information. This information could be exploited by an attacker for",
  "cve_count": 1,
  "categories": [],
  "word_count": 496,
  "mentions_ics": true,
  "published_at": "2026-06-25T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-176-01.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-11833",
    "https://web-material3.yokogawa.com/1/39777/files/YSAR-26-0004-E.pdf",
    "https://contact.yokogawa.com/cs/gw?c-id=000498",
    "https://cwe.mitre.org/data/definitions/319.html"
  ],
  "mentions_ransomware": false
}
09Daktronics Controller FirmwareView CSAF Summary Successful exploitation of these vulnerabilities could could provide an unauthenticated user with complete root-level access and control of the system. The following versions of Dakt{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-04","cves":[…
EVENT. cmr2i0bnID. cmr2i0bn0014xkh0crywjaf10SRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-04",
  "cves": [
    "CVE-2026-28701",
    "CVE-2026-33560",
    "CVE-2026-31928"
  ],
  "slug": "icsa-26-176-04",
  "title": "Daktronics Controller Firmware",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could could provide an unauthenticated user with complete root-level access and control of the system. The following versions of Daktronics Controller Firmware are affected: VFC-DMP-5000 <v8.117.x.x VFC-DMP-5000 <v9.43.x.x VFC-DMP-5000 <v10.34.x.x DMP-5000 <v10.34.x.x DMP-5000 <v8.117.x.x DMP-5000 <v9.43.x.x DMP-8000 <v10.34.x.x DMP-8000 <v8.117.x.x DMP-8000 <v9.43.x.x CVSS Vendor Equipment Vulnerabilities v3 8.1 Daktronics Daktronics Controller Firmware Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangerous Type, Use of Hard-coded Credentials Background Critical Infrastructure Sectors: Commercial Facilities, Information Technolog",
  "cve_count": 3,
  "categories": [],
  "word_count": 825,
  "mentions_ics": true,
  "published_at": "2026-06-25T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-176-04.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-28701",
    "https://cwe.mitre.org/data/definitions/22.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
    "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
  ],
  "mentions_ransomware": false
}
10Russian Intelligence Services Continue to Target Commercial Messaging ApplicationsCISA and the Federal Bureau of Investigation (FBI) issued an updated Public Service Announcement (PSA) warning of Russian Intelligence Services (RIS) cyber threat actors targeting commercial messaging{"url":"https://www.cisa.gov/resources-tools/resources/russian-intelligence-serv…
EVENT. cmr2i0b5ID. cmr2i0b5n014vkh0ci4m0c9laSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/resources-tools/resources/russian-intelligence-services-continue-target-commercial-messaging-applications",
  "cves": [],
  "slug": "russian-intelligence-services-continue-target-commercial-messaging-applications",
  "title": "Russian Intelligence Services Continue to Target Commercial Messaging Applications",
  "source": "cisa.gov",
  "excerpt": "CISA and the Federal Bureau of Investigation (FBI) issued an updated Public Service Announcement (PSA) warning of Russian Intelligence Services (RIS) cyber threat actors targeting commercial messaging applications in ongoing phishing campaigns. This PSA is an update to the March 2026 Russian Intelligence Services Target Commercial Messaging Application Accounts and provides recent tactics, recommended mitigations, and samples of phishing messages. ",
  "cve_count": 0,
  "categories": [],
  "word_count": 60,
  "mentions_ics": false,
  "published_at": "2026-06-26T12:00:00.000Z",
  "advisory_type": "advisory",
  "outbound_links": [
    "https://www.ic3.gov/PSA/2026/PSA260626",
    "https://www.cisa.gov/resources-tools/resources/russian-intelligence-services-target-commercial-messaging-application-accounts"
  ],
  "mentions_ransomware": false
}
showing 1–10 of 86older →
§03

subscribe

three pathways carry every event on this topic. pick the one that fits your agent.

GETrss feed
any reader · no auth
https://api.callsign.sh/v1/public/channels/security/topics/cisa-advisories/feed.xml
GETjson pull
poll on your schedule · optional since/until
https://api.callsign.sh/v1/public/channels/security/topics/cisa-advisories.json
POSTwebhook
push delivery · one POST per event
log in to subscribe →
subscribe by reader, by pull loop, or by webhook above