CISA Advisories

topic · security/cisa-advisories
DOC.
security/cisa-advisories
REV.
176 evt
DATE.
02-JUN-2026
SCOPE.
custom
§01

about

CISA cybersecurity alerts, ICS advisories, and analysis reports (separate stream from KEV).

§02

recent events

LIVElast event 0s ago0 evt / 1h

showing 10 of 104 events in this window (176 total on topic). adjust the range or clear it with ALL.

range
iso 8601 utc
iso 8601 utc
01Digi International PortServer TS, Digi One SP IAView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication and gain access to restricted resources, obtain credentials, and inject malicious sc{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-07","cves":[…
EVENT. cmraye1vID. cmraye1v52cq5kh0cyobsprgoSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-07",
  "cves": [
    "CVE-2026-12352",
    "CVE-2026-12948"
  ],
  "slug": "icsa-26-188-07",
  "title": "Digi International PortServer TS, Digi One SP IA",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication and gain access to restricted resources, obtain credentials, and inject malicious scripts. The following versions of Digi International PortServer TS, Digi One SP IA are affected: PortServer TS Digi One SP Digi One SP IA Digi One IA CVSS Vendor Equipment Vulnerabilities v3 5.9 Digi International Digi International PortServer TS, Digi One SP IA Incorrect Authorization, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Background Critical Infrastructure Sectors: Critical Manufacturing, Communications, Information Technology, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities ",
  "cve_count": 2,
  "categories": [],
  "word_count": 962,
  "mentions_ics": true,
  "published_at": "2026-07-07T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-07.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-12352",
    "https://www.digi.com/support",
    "https://cwe.mitre.org/data/definitions/863.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
  ],
  "mentions_ransomware": false
}
02Hitachi Energy PROMOD VView CSAF Summary Hitachi Energy is aware of insecure HTTP transmission vulnerability in PROMOD V product versions listed in this document. This vulnerability could allow attackers to intercept or man{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-02","cves":[…
EVENT. cmraye1bID. cmraye1bi2cq3kh0cwvvtn364SRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-02",
  "cves": [
    "CVE-2026-10763"
  ],
  "slug": "icsa-26-188-02",
  "title": "Hitachi Energy PROMOD V",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Hitachi Energy is aware of insecure HTTP transmission vulnerability in PROMOD V product versions listed in this document. This vulnerability could allow attackers to intercept or manipulate sensitive data in transit, potentially leading to credential theft, session hijacking, or unauthorized access. The following versions of Hitachi Energy PROMOD V are affected: PROMOD V vers:PROMOD_V/<=1.0.10 CVSS Vendor Equipment Vulnerabilities v3 7.1 Hitachi Energy Hitachi Energy PROMOD V Reliance on HTTP instead of HTTPS Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2026-10763 PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due t",
  "cve_count": 1,
  "categories": [],
  "word_count": 918,
  "mentions_ics": true,
  "published_at": "2026-07-07T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-02.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-10763",
    "https://cwe.mitre.org/data/definitions/1428.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N",
    "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
  ],
  "mentions_ransomware": false
}
03Labcenter Proteus 9View CSAF Summary Successful exploitation of these vulnerabilities could disclose information and allow a malicious user to execute arbitrary code on affected installations. The following versions of {"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-06","cves":[…
EVENT. cmraye0qID. cmraye0qy2cq1kh0co3kspkdySRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-06",
  "cves": [
    "CVE-2026-42953",
    "CVE-2026-49033",
    "CVE-2026-42958"
  ],
  "slug": "icsa-26-188-06",
  "title": "Labcenter Proteus 9",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could disclose information and allow a malicious user to execute arbitrary code on affected installations. The following versions of Labcenter Proteus 9 are affected: Proteus 9.1_SP4_Build_42914 CVSS Vendor Equipment Vulnerabilities v3 7.8 Labcenter Electronics Labcenter Proteus 9 Out-of-bounds Write, Stack-based Buffer Overflow, Use After Free Background Critical Infrastructure Sectors: Communications, Critical Manufacturing, Defense Industrial Base, Energy, Healthcare and Public Health, Transportation Systems, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United Kingdom Vulnerabilities Expand All + CVE-2026-42953 The application contains an out-of-bounds write vulnerability that c",
  "cve_count": 3,
  "categories": [],
  "word_count": 904,
  "mentions_ics": true,
  "published_at": "2026-07-07T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-06.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-42953",
    "https://cwe.mitre.org/data/definitions/787.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
    "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
  ],
  "mentions_ransomware": false
}
04Hitachi Energy e-mesh EMSView CSAF Summary Hitachi Energy is aware of a buffer overflow vulnerability that affects e-mesh EMS product versions listed in this document. Successful exploitation of this vulnerability could lead {"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-03","cves":[…
EVENT. cmraye06ID. cmraye06h2cpzkh0ctt8xp0dsSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-03",
  "cves": [
    "CVE-2026-42945"
  ],
  "slug": "icsa-26-188-03",
  "title": "Hitachi Energy e-mesh EMS",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Hitachi Energy is aware of a buffer overflow vulnerability that affects e-mesh EMS product versions listed in this document. Successful exploitation of this vulnerability could lead to a buffer overflow condition, potentially resulting in application outages (denial of service) and possible arbitrary code execution. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of Hitachi Energy e-mesh EMS are affected: Hitachi Energy e-mesh EMS 4.1.6, 4.4.2, 4.7.0 CVSS Vendor Equipment Vulnerabilities v3 8.1 Hitachi Energy Hitachi Energy e-mesh EMS Heap-based Buffer Overflow Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabi",
  "cve_count": 1,
  "categories": [],
  "word_count": 1065,
  "mentions_ics": true,
  "published_at": "2026-07-07T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-03.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-42945",
    "https://cwe.mitre.org/data/definitions/122.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
  ],
  "mentions_ransomware": false
}
05CISA Adds Three Known Exploited Vulnerabilities to CatalogCISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload {"url":"https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known…
EVENT. cmraydzmID. cmraydzmt2cpxkh0cf7slfi6hSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog",
  "cves": [
    "CVE-2026-48908",
    "CVE-2026-55255",
    "CVE-2026-56290"
  ],
  "slug": "cisa-adds-three-known-exploited-vulnerabilities-catalog",
  "title": "CISA Adds Three Known Exploited Vulnerabilities to Catalog",
  "source": "cisa.gov",
  "excerpt": "CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-55255 Langflow Authorization Bypass Through User-Controlled Key Vulnerability   CVE-2026-56290 Joomlack Page Builder Improper Access Control Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog a",
  "cve_count": 3,
  "categories": [],
  "word_count": 245,
  "mentions_ics": false,
  "published_at": "2026-07-07T12:00:00.000Z",
  "advisory_type": "alert",
  "outbound_links": [
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
    "https://www.cve.org/CVERecord?id=CVE-2026-48908",
    "https://www.cve.org/CVERecord?id=CVE-2026-55255",
    "https://www.cve.org/CVERecord?id=CVE-2026-56290",
    "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk"
  ],
  "mentions_ransomware": false
}
06ST Engineering iDirect iQ-Series TerminalsView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. The following versi{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-01","cves":[…
EVENT. cmr3ozkrID. cmr3ozkrv0ewlkh0c4wwe47kiSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-01",
  "cves": [
    "CVE-2026-38059",
    "CVE-2026-38057"
  ],
  "slug": "icsa-26-183-01",
  "title": "ST Engineering iDirect iQ-Series Terminals",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. The following versions of ST Engineering iDirect iQ-Series Terminals are affected: Evolution iQ‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057) 3315‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057) 9‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057) CVSS Vendor Equipment Vulnerabilities v3 8.1 ST Engineering iDirect ST Engineering iDirect iQ-Series Terminals Missing Authentication for Critical Function, Cross-Site Request Forgery (CSRF) Background Critical Infrastructure Sectors: Communications, Defense Industrial Base, Energy, Government Services and Facilities, Transpo",
  "cve_count": 2,
  "categories": [],
  "word_count": 831,
  "mentions_ics": true,
  "published_at": "2026-07-02T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-183-01.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-38059",
    "https://support.idirect.net/s/login",
    "https://cwe.mitre.org/data/definitions/306.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
  ],
  "mentions_ransomware": false
}
07Gardyn IoT HubView CSAF Summary Successful exploitation of these vulnerabilities could allow unauthenticated users to access and control IoT Hub managed devices. The following versions of Gardyn IoT Hub are affecte{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-03","cves":[…
EVENT. cmr3ozk9ID. cmr3ozk9z0ewjkh0cu17bn1awSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-03",
  "cves": [
    "CVE-2026-13768",
    "CVE-2026-55726",
    "CVE-2026-54477"
  ],
  "slug": "icsa-26-183-03",
  "title": "Gardyn IoT Hub",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could allow unauthenticated users to access and control IoT Hub managed devices. The following versions of Gardyn IoT Hub are affected: Home Firmware Studio Firmware Cloud API <2.12.2026 (CVE-2026-13768, CVE-2026-55726, CVE-2026-54477) CVSS Vendor Equipment Vulnerabilities v3 10 Gardyn Gardyn IoT Hub Use of Hard-coded Credentials, Exposure of Sensitive System Information to an Unauthorized Control Sphere, Improper Neutralization of HTTP Headers for Scripting Syntax Background Critical Infrastructure Sectors: Food and Agriculture Countries/Areas Deployed: United States Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-13768 Gardyn devices expose a privileged iothubowner key. Access to this",
  "cve_count": 3,
  "categories": [],
  "word_count": 961,
  "mentions_ics": true,
  "published_at": "2026-07-02T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-183-03.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-13768",
    "https://mygardyn.com/security/",
    "https://cwe.mitre.org/data/definitions/798.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L"
  ],
  "mentions_ransomware": false
}
08CubeSpace CW0057 Reaction WheelView CSAF Summary Successful exploitation of this vulnerability could allow an attacker to upload arbitrary malicious firmware to the device. The following versions of CubeSpace CW0057 Reaction Wheel {"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-02","cves":[…
EVENT. cmr3ozjsID. cmr3ozjsk0ewhkh0ceaqkpfpdSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-02",
  "cves": [
    "CVE-2026-13743"
  ],
  "slug": "icsa-26-183-02",
  "title": "CubeSpace CW0057 Reaction Wheel",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to upload arbitrary malicious firmware to the device. The following versions of CubeSpace CW0057 Reaction Wheel are affected: CW0057 Reaction Wheel CVSS Vendor Equipment Vulnerabilities v3 6.1 CubeSpace CubeSpace CW0057 Reaction Wheel Improper Verification of Cryptographic Signature Background Critical Infrastructure Sectors: Communications Countries/Areas Deployed: Worldwide Company Headquarters Location: South Africa Vulnerabilities Expand All + CVE-2026-13743 CubeSpace CW0057 Reaction Wheel firmware versions prior to 5.0.20 are vulnerable to an Improper Verification of Cryptographic Signature vulnerability. This could allow an attacker with physical access to the product to upload arbitrary malicious",
  "cve_count": 1,
  "categories": [],
  "word_count": 651,
  "mentions_ics": true,
  "published_at": "2026-07-02T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-183-02.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-13743",
    "https://cwe.mitre.org/data/definitions/347.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
    "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
  ],
  "mentions_ransomware": false
}
09Hubbell Aclara Metrum Cellular Web InterfaceView CSAF Summary Successful exploitation of this vulnerability could allow attackers to manipulate critical device settings and repeatedly disrupt operations, potentially causing a loss of communicat{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-07","cves":[…
EVENT. cmr2i0kfID. cmr2i0kfs015xkh0c67m6r5g1SRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-07",
  "cves": [
    "CVE-2026-1840"
  ],
  "slug": "icsa-26-174-07",
  "title": "Hubbell Aclara Metrum Cellular Web Interface",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of this vulnerability could allow attackers to manipulate critical device settings and repeatedly disrupt operations, potentially causing a loss of communications to the device. The following versions of Hubbell Aclara Metrum Cellular Web Interface are affected: Aclara Metrum Cellular Web Interface CVSS Vendor Equipment Vulnerabilities v3 7.5 Hubbell Hubbell Aclara Metrum Cellular Web Interface Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: United States Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-1840 The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication controls on critical ",
  "cve_count": 1,
  "categories": [],
  "word_count": 503,
  "mentions_ics": true,
  "published_at": "2026-06-23T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-174-07.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-1840",
    "https://aclara.my.site.com/AclaraConnect/s/",
    "https://cwe.mitre.org/data/definitions/306.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
  ],
  "mentions_ransomware": false
}
10Siemens WinCC Certificate ManagerView CSAF Summary WinCC Certificate Manager insufficiently protects key material that could allow an attacker to extract sensitive information. Siemens has released a new version for SIMATIC WinCC Uni{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-01","cves":[…
EVENT. cmr2i0jyID. cmr2i0jy2015vkh0cqkks9b1dSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-01",
  "cves": [
    "CVE-2026-24349"
  ],
  "slug": "icsa-26-174-01",
  "title": "Siemens WinCC Certificate Manager",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary WinCC Certificate Manager insufficiently protects key material that could allow an attacker to extract sensitive information. Siemens has released a new version for SIMATIC WinCC Unified PC Runtime V21 and recommends to update to the latest version. Siemens recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens WinCC Certificate Manager are affected: SIMATIC WinCC Unified PC Runtime V16 vers:all/*  SIMATIC WinCC Unified PC Runtime V17 vers:all/*  SIMATIC WinCC Unified PC Runtime V18 vers:all/*  SIMATIC WinCC Unified PC Runtime V19 vers:all/*  SIMATIC WinCC Unified PC Runtime V20 vers:all/*  SIMATIC WinCC Unified PC Runtime V21 vers:intdot/<21.0.2 CVSS Vendor Equipment Vulner",
  "cve_count": 1,
  "categories": [],
  "word_count": 793,
  "mentions_ics": true,
  "published_at": "2026-06-23T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-174-01.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-24349",
    "https://support.industry.siemens.com/cs/ww/en/view/109991140/",
    "https://cwe.mitre.org/data/definitions/313.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
  ],
  "mentions_ransomware": false
}
showing 1–10 of 104older →
§03

subscribe

three pathways carry every event on this topic. pick the one that fits your agent.

GETrss feed
any reader · no auth
https://api.callsign.sh/v1/public/channels/security/topics/cisa-advisories/feed.xml
GETjson pull
poll on your schedule · optional since/until
https://api.callsign.sh/v1/public/channels/security/topics/cisa-advisories.json
POSTwebhook
push delivery · one POST per event
log in to subscribe →
subscribe by reader, by pull loop, or by webhook above