CISA Advisories
topic · security/cisa-advisories
§01
about
CISA cybersecurity alerts, ICS advisories, and analysis reports (separate stream from KEV).
§02
recent events
LIVElast event 0s ago0 evt / 1h
showing 10 of 95 events in this window (176 total on topic). adjust the range or clear it with ALL.
range
01Siemens WinCC Certificate ManagerView CSAF Summary WinCC Certificate Manager insufficiently protects key material that could allow an attacker to extract sensitive information. Siemens has released a new version for SIMATIC WinCC Uni{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-01","cves":[…
EVENT. cmr2i0jyID. cmr2i0jy2015vkh0cqkks9b1dSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-01",
"cves": [
"CVE-2026-24349"
],
"slug": "icsa-26-174-01",
"title": "Siemens WinCC Certificate Manager",
"source": "cisa.gov",
"excerpt": "View CSAF Summary WinCC Certificate Manager insufficiently protects key material that could allow an attacker to extract sensitive information. Siemens has released a new version for SIMATIC WinCC Unified PC Runtime V21 and recommends to update to the latest version. Siemens recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens WinCC Certificate Manager are affected: SIMATIC WinCC Unified PC Runtime V16 vers:all/* SIMATIC WinCC Unified PC Runtime V17 vers:all/* SIMATIC WinCC Unified PC Runtime V18 vers:all/* SIMATIC WinCC Unified PC Runtime V19 vers:all/* SIMATIC WinCC Unified PC Runtime V20 vers:all/* SIMATIC WinCC Unified PC Runtime V21 vers:intdot/<21.0.2 CVSS Vendor Equipment Vulner",
"cve_count": 1,
"categories": [],
"word_count": 793,
"mentions_ics": true,
"published_at": "2026-06-23T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-174-01.json",
"https://www.cve.org/CVERecord?id=CVE-2026-24349",
"https://support.industry.siemens.com/cs/ww/en/view/109991140/",
"https://cwe.mitre.org/data/definitions/313.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
],
"mentions_ransomware": false
}02ABB Freelance Security LockView CSAF Summary Successful exploitation of this vulnerability could allow access to underlying OS functions even when Freelance Operations is active, depending on system configuration and user permi{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-05","cves":[…
EVENT. cmr2i0jgID. cmr2i0jga015tkh0cg2kt77b6SRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-05",
"cves": [
"CVE-2025-7064"
],
"slug": "icsa-26-174-05",
"title": "ABB Freelance Security Lock",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of this vulnerability could allow access to underlying OS functions even when Freelance Operations is active, depending on system configuration and user permissions. The following versions of ABB Freelance Security Lock are affected: ABB System Version (<=Freelance 2013) installed with ABB Freelance Security Lock(All versions) vers:all/* ABB System Version (Freelance 2013 SP1) installed with ABB Freelance Security Lock(All versions) vers:all/* ABB System Version (Freelance 2016) installed with ABB Freelance Security Lock(All versions) vers:all/* ABB System Version (Freelance 2016 SP1) installed with ABB Freelance Security Lock(All versions) vers:all/* ABB System Version (Freelance 2019) installed with ABB Freelance Securi",
"cve_count": 1,
"categories": [],
"word_count": 785,
"mentions_ics": true,
"published_at": "2026-06-23T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-174-05.json",
"https://www.cve.org/CVERecord?id=CVE-2025-7064",
"https://search.abb.com/library/Download.aspx?DocumentID=7PAA020361&LanguageCode=en&DocumentPartId=&Action=Launch",
"https://psirt.abb.com/csaf/2026/7paa020361.json",
"https://cwe.mitre.org/data/definitions/305.html"
],
"mentions_ransomware": false
}03Siemens Products using OpenSSLView CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Sie{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-03","cves":[…
EVENT. cmr2i0iyID. cmr2i0iyq015rkh0c8tbl8tv7SRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-03",
"cves": [
"CVE-2025-15467"
],
"slug": "icsa-26-174-03",
"title": "Siemens Products using OpenSSL",
"source": "cisa.gov",
"excerpt": "View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens Products using OpenSSL are affected: AI Lightweight Inference Server vers:all/* (CVE-2025-15467) Connector for Azure vers:intdot/<1.8.0 (CVE-2025-15467) Databus vers:intdot/<3.3.2 (CVE-2025-15467) HiMed Cockpit vers:all/* (CVE-2025-15467) RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) vers:all/* (CVE-2025-154",
"cve_count": 1,
"categories": [],
"word_count": 2402,
"mentions_ics": true,
"published_at": "2026-06-23T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-174-03.json",
"https://www.cve.org/CVERecord?id=CVE-2025-15467",
"https://support.industry.siemens.com/cs/ww/en/view/109999722/",
"https://docs.eu1.edge.siemens.cloud/release_notes/scope_of_delivery/scope_of_delivery.html",
"https://support.industry.siemens.com/cs/ww/en/view/109800912/"
],
"mentions_ransomware": false
}04Siemens SIPROTEC 5 Using DIGSI5 ProtocolView CSAF Summary SIPROTEC 5 is vulnerable to arbitrary file uploads by authenticated users using the DIGSI 5 protocol. This could allow an attacker to upload malicious configuration files, potentiall{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-02","cves":[…
EVENT. cmr2i0ihID. cmr2i0ih6015pkh0cb0s2rniaSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-02",
"cves": [
"CVE-2025-40808"
],
"slug": "icsa-26-174-02",
"title": "Siemens SIPROTEC 5 Using DIGSI5 Protocol",
"source": "cisa.gov",
"excerpt": "View CSAF Summary SIPROTEC 5 is vulnerable to arbitrary file uploads by authenticated users using the DIGSI 5 protocol. This could allow an attacker to upload malicious configuration files, potentially causing a permanent denial of service condition. As a mitigation measure, users of the CP050 and CP150 device models are advised to upgrade to version 9.90 or later. For CP300 device models, devices 7ST85 and 7ST86 are advised to upgrade to version 10.00 or later, while the remaining models should upgrade to version 9.90 or later. These versions introduce an allow-list feature that restricts arbitrary file uploads and reduces the risk associated with this vulnerability. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet avai",
"cve_count": 1,
"categories": [],
"word_count": 1510,
"mentions_ics": true,
"published_at": "2026-06-23T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-174-02.json",
"https://www.cve.org/CVERecord?id=CVE-2025-40808",
"https://cwe.mitre.org/data/definitions/434.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H"
],
"mentions_ransomware": false
}05Impact of Linux Kernel vulnerabilities on B&R productsView CSAF Summary B&R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory. Successful local exploitation {"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-06","cves":[…
EVENT. cmr2i0hzID. cmr2i0hzg015nkh0c84dpr6mySRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-06",
"cves": [
"CVE-2026-31431",
"CVE-2026-43284",
"CVE-2026-46333",
"CVE-2026-46300",
"CVE-2026-43494"
],
"slug": "icsa-26-174-06",
"title": "Impact of Linux Kernel vulnerabilities on B&R products",
"source": "cisa.gov",
"excerpt": "View CSAF Summary B&R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory. Successful local exploitation of these vulnerabilities could allow an attacker to escalate privileges on the affected system. Public proof-of-concept exploits are available for the vulnerabilities described herein. At the time of publication of this advisory, B&R had no evidence of active exploitation targeting B&R products. The following versions of Impact of Linux Kernel vulnerabilities on B&R products are affected: Linux for B&R <=12 APROL <APROL-AutoYaST-DVD- V4.4-010.10.260602 X20EDS410 /all CVSS Vendor Equipment Vulnerabilities v3 7.8 B&R Industrial Automation GmbH Impact of Linu",
"cve_count": 5,
"categories": [],
"word_count": 3774,
"mentions_ics": true,
"published_at": "2026-06-23T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-174-06.json",
"https://www.cve.org/CVERecord?id=CVE-2026-31431",
"https://cwe.mitre.org/data/definitions/669.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H/RC:C",
"https://www.cve.org/CVERecord?id=CVE-2026-43284"
],
"mentions_ransomware": false
}06Siemens SINEC INSView CSAF Summary SINEC INS before V1.0 SP2 Update 6 is affected by multiple vulnerabilities. Siemens has released a new version for SINEC INS and recommends to update to the latest version. The follo{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-04","cves":[…
EVENT. cmr2i0hhID. cmr2i0hhx015lkh0cgjg3ip06SRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-04",
"cves": [
"CVE-2026-46746",
"CVE-2026-46747",
"CVE-2026-46748",
"CVE-2026-46749"
],
"slug": "icsa-26-174-04",
"title": "Siemens SINEC INS",
"source": "cisa.gov",
"excerpt": "View CSAF Summary SINEC INS before V1.0 SP2 Update 6 is affected by multiple vulnerabilities. Siemens has released a new version for SINEC INS and recommends to update to the latest version. The following versions of Siemens SINEC INS are affected: SINEC INS vers:intdot/<1.0.2.6 CVSS Vendor Equipment Vulnerabilities v3 8.8 Siemens Siemens SINEC INS Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Path Traversal: '/dir/../filename', Execution with Unnecessary Privileges, Use of a One-Way Hash with a Predictable Salt Background Critical Infrastructure Sectors: Critical Manufacturing, Transportation Systems, Energy, Healthcare and Public Health, Financial Services, Government Services and Facilities Countries/Areas Deployed: Worldwide Compan",
"cve_count": 4,
"categories": [],
"word_count": 988,
"mentions_ics": true,
"published_at": "2026-06-23T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-174-04.json",
"https://www.cve.org/CVERecord?id=CVE-2026-46746",
"https://support.industry.siemens.com/cs/ww/en/view/110002283/",
"https://cwe.mitre.org/data/definitions/78.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
],
"mentions_ransomware": false
}07CISA Adds Four Known Exploited Vulnerabilities to CatalogCISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-67038 Lantronix EDS5000 Code Injection Vulnerab{"url":"https://www.cisa.gov/news-events/alerts/2026/06/23/cisa-adds-four-known-…
EVENT. cmr2i0h0ID. cmr2i0h09015jkh0c3i4w0vp3SRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/alerts/2026/06/23/cisa-adds-four-known-exploited-vulnerabilities-catalog",
"cves": [
"CVE-2025-67038",
"CVE-2026-34908",
"CVE-2026-34909",
"CVE-2026-34910"
],
"slug": "cisa-adds-four-known-exploited-vulnerabilities-catalog",
"title": "CISA Adds Four Known Exploited Vulnerabilities to Catalog",
"source": "cisa.gov",
"excerpt": "CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-67038 Lantronix EDS5000 Code Injection Vulnerability CVE-2026-34908 Ubiquiti UniFi OS Improper Access Control Vulnerability CVE-2026-34909 Ubiquiti UniFi OS Path Traversal Vulnerability CVE-2026-34910 Ubiquiti UniFi OS Improper Input Validation Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog a",
"cve_count": 4,
"categories": [],
"word_count": 244,
"mentions_ics": false,
"published_at": "2026-06-23T12:00:00.000Z",
"advisory_type": "alert",
"outbound_links": [
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
"https://www.cve.org/CVERecord?id=CVE-2025-67038",
"https://www.cve.org/CVERecord?id=CVE-2026-34908",
"https://www.cve.org/CVERecord?id=CVE-2026-34909",
"https://www.cve.org/CVERecord?id=CVE-2026-34910"
],
"mentions_ransomware": false
}08Using SASE in a Modern TIC 3.0 SolutionUsing SASE in a Modern TIC 3.0 Solution CISA’s guidance, The Journey to Zero Trust – Using Secure Access Service Edge in a Modern TIC 3.0 Solution , details how the Trusted Internet Connections (TIC) {"url":"https://www.cisa.gov/resources-tools/resources/using-sase-modern-tic-30-…
EVENT. cmr2i0giID. cmr2i0gim015hkh0c9o2dd4fuSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/resources-tools/resources/using-sase-modern-tic-30-solution",
"cves": [],
"slug": "using-sase-modern-tic-30-solution",
"title": "Using SASE in a Modern TIC 3.0 Solution",
"source": "cisa.gov",
"excerpt": "Using SASE in a Modern TIC 3.0 Solution CISA’s guidance, The Journey to Zero Trust – Using Secure Access Service Edge in a Modern TIC 3.0 Solution , details how the Trusted Internet Connections (TIC) 3.0 initiative is helping agencies modernize the way their users connect to applications, data and services. While federal agencies are the target audience, any organization looking to modernize its perimeter-based architectures, advance zero trust adoption, and improve visibility and control across distributed environments will benefit from this guidance. To learn more about ZT principles, visit Zero Trust . CISA Product Survey We welcome your feedback. CISA Product Survey ",
"cve_count": 0,
"categories": [],
"word_count": 105,
"mentions_ics": false,
"published_at": "2026-06-24T12:00:00.000Z",
"advisory_type": "advisory",
"outbound_links": [
"https://www.cisa.gov/sites/default/files/2026-07/The_Journey_to_Zero_Trust-Using_SAS_in_a_Modern_TIC3.0_Solution.pdf",
"https://www.cisa.gov/topics/cybersecurity-best-practices/zero-trust",
"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_9n4TtB8uttUPaM6?product=https://www.cisa.gov/resources-tools/resources/using-sase-modern-tic-30-solution"
],
"mentions_ransomware": false
}09H.VIEW HV-500S6 IP CameraView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code and upload malicious files to the affected device. The following versions of H.VIEW{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-05","cves":[…
EVENT. cmr2i0g0ID. cmr2i0g0g015fkh0cggf78i1lSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-05",
"cves": [
"CVE-2026-55975",
"CVE-2026-56414"
],
"slug": "icsa-26-176-05",
"title": "H.VIEW HV-500S6 IP Camera",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code and upload malicious files to the affected device. The following versions of H.VIEW HV-500S6 IP Camera are affected: H.VIEW HV-500S6 IP Camera IPCAM_V4.06.88.251229 CVSS Vendor Equipment Vulnerabilities v3 7.2 H.VIEW H.VIEW HV-500S6 IP Camera Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Unrestricted Upload of File with Dangerous Type Background Critical Infrastructure Sectors: Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-55975 A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fi",
"cve_count": 2,
"categories": [],
"word_count": 684,
"mentions_ics": true,
"published_at": "2026-06-25T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-176-05.json",
"https://www.cve.org/CVERecord?id=CVE-2026-55975",
"https://hviewsmart.com/pages/contact-us",
"https://cwe.mitre.org/data/definitions/78.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
],
"mentions_ransomware": false
}10EVoke Systems Charging Station Management SystemView CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services thr{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-02","cves":[…
EVENT. cmr2i0fiID. cmr2i0fiz015dkh0c1urqjlijSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-02",
"cves": [
"CVE-2026-40702",
"CVE-2026-50176",
"CVE-2026-54479",
"CVE-2026-44622"
],
"slug": "icsa-26-176-02",
"title": "EVoke Systems Charging Station Management System",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks. The following versions of EVoke Systems Charging Station Management System are affected: EVoke CSMS vers:all/* CVSS Vendor Equipment Vulnerabilities v3 9.4 EVoke Systems EVoke Systems Charging Station Management System Missing Authentication for Critical Function, Improper Restriction of Excessive Authentication Attempts, Insufficient Session Expiration, Insufficiently Protected Credentials Background Critical Infrastructure Sectors: Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilit",
"cve_count": 4,
"categories": [],
"word_count": 2378,
"mentions_ics": true,
"published_at": "2026-06-25T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-176-02.json",
"https://www.cve.org/CVERecord?id=CVE-2026-40702",
"https://evokesystems.com/contact-us/",
"https://cwe.mitre.org/data/definitions/306.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
],
"mentions_ransomware": false
}showing 1–10 of 95older →
§03
subscribe
three pathways carry every event on this topic. pick the one that fits your agent.
GETrss feed
any reader · no authhttps://api.callsign.sh/v1/public/channels/security/topics/cisa-advisories/feed.xmlGETjson pull
poll on your schedule · optional since/untilhttps://api.callsign.sh/v1/public/channels/security/topics/cisa-advisories.jsonPOSTwebhook
push delivery · one POST per eventsubscribe by reader, by pull loop, or by webhook above