CISA Advisories
topic · security/cisa-advisories
§01
about
CISA cybersecurity alerts, ICS advisories, and analysis reports (separate stream from KEV).
§02
recent events
LIVElast event 0s ago0 evt / 1h
showing 10 of 140 events in this window (176 total on topic). adjust the range or clear it with ALL.
range
01Rockwell Automation Studio 5000 Logix DesignerView CSAF Summary Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code. The following versions {"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-10","cves":[…
EVENT. cmruwny1ID. cmruwny1u7mshkh0cdfu0hl5hSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-10",
"cves": [
"CVE-2026-9108",
"CVE-2026-9127",
"CVE-2026-9128"
],
"slug": "icsa-26-202-10",
"title": "Rockwell Automation Studio 5000 Logix Designer",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code. The following versions of Rockwell Automation Studio 5000 Logix Designer are affected: Studio 5000 Logix Designer V36.00 (CVE-2026-9108) Studio 5000 Logix Designer V35.00 (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128) Studio 5000 Logix Designer V35.01 (CVE-2026-9108) Studio 5000 Logix Designer >=V34.00|<=V34.03 (CVE-2026-9108) Studio 5000 Logix Designer >=V33.00|<=V33.03 (CVE-2026-9108) Studio 5000 Logix Designer >=V32.00|<=V32.04 (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128) Studio 5000 Logix Designer V34.00 (CVE-2026-9127) Studio 5000 Logix Designer V34.01 (CVE-2026-9127) Studio 5000 Logix Designe",
"cve_count": 3,
"categories": [],
"word_count": 1153,
"mentions_ics": true,
"published_at": "2026-07-21T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-10.json",
"https://www.cve.org/CVERecord?id=CVE-2026-9108",
"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight",
"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html",
"https://cwe.mitre.org/data/definitions/22.html"
],
"mentions_ransomware": false
}02Rockwell Automation 1718-AENTR/1719-AENTRView CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. The following versions of Rockwell Automation 1718-AE{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-08","cves":[…
EVENT. cmruwnxhID. cmruwnxhp7msdkh0c4rjrthokSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-08",
"cves": [
"CVE-2026-9140"
],
"slug": "icsa-26-202-08",
"title": "Rockwell Automation 1718-AENTR/1719-AENTR",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. The following versions of Rockwell Automation 1718-AENTR/1719-AENTR are affected: 1718/ 1719 Ex I/O 3.011 CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1718-AENTR/1719-AENTR Allocation of Resources Without Limits or Throttling Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-9140 A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to become overloaded and ",
"cve_count": 1,
"categories": [],
"word_count": 552,
"mentions_ics": true,
"published_at": "2026-07-21T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-08.json",
"https://www.cve.org/CVERecord?id=CVE-2026-9140",
"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight",
"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html",
"https://cwe.mitre.org/data/definitions/770.html"
],
"mentions_ransomware": false
}03Rockwell Automation 1734 POINT I/OView CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. The following versions of Rockwell Automation 1734 PO{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-09","cves":[…
EVENT. cmruwnwxID. cmruwnwxp7msbkh0crqks0wh2SRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-09",
"cves": [
"CVE-2026-10573"
],
"slug": "icsa-26-202-09",
"title": "Rockwell Automation 1734 POINT I/O",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. The following versions of Rockwell Automation 1734 POINT I/O are affected: 1734 POINT I/O 3.023 CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1734 POINT I/O Allocation of Resources Without Limits or Throttling Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-10573 A denial-of-service security issue exists in 1734 POINT I/O module. The security issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A restart is",
"cve_count": 1,
"categories": [],
"word_count": 548,
"mentions_ics": true,
"published_at": "2026-07-21T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-09.json",
"https://www.cve.org/CVERecord?id=CVE-2026-10573",
"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight",
"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html",
"https://cwe.mitre.org/data/definitions/770.html"
],
"mentions_ransomware": false
}04Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFWView CSAF Summary Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customer{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-02","cves":[…
EVENT. cmruwnwdID. cmruwnwds7ms9kh0cvo69lhgoSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-02",
"cves": [
"CVE-2026-0266",
"CVE-2026-0272",
"CVE-2026-0273"
],
"slug": "icsa-26-202-02",
"title": "Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/ The following versions of Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW are affected: RUGGEDCOM APE1808 vers:all/* CVSS Vendor Equipment Vulnerabilities v3 7.2 Siemens Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Missing Authorization, Improper Neutralization of Special Elements used in an OS Command ('OS Com",
"cve_count": 3,
"categories": [],
"word_count": 1067,
"mentions_ics": true,
"published_at": "2026-07-21T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-02.json",
"https://www.cve.org/CVERecord?id=CVE-2026-0266",
"https://cwe.mitre.org/data/definitions/79.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N",
"https://www.cve.org/CVERecord?id=CVE-2026-0272"
],
"mentions_ransomware": false
}05Siemens IAM ClientView CSAF Summary Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens {"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-05","cves":[…
EVENT. cmruwnvuID. cmruwnvu87ms7kh0cp9hxuzmcSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-05",
"cves": [
"CVE-2025-40945"
],
"slug": "icsa-26-202-05",
"title": "Siemens IAM Client",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available. The following versions of Siemens IAM Client are affected: COMOS V10.4.5 vers:intdot/<10.4.5.0.2 COMOS V10.6 vers:intdot/<10.6.1 Designcenter NX vers:intdot/<2512.7000 Simcenter 3D vers:intdot/<2512.7000 Simcenter Femap V2506 vers:intdot/<2506.0003 Simcenter Femap V2512 vers:intdot/<2512.0002 Simcenter Nastran ",
"cve_count": 1,
"categories": [],
"word_count": 903,
"mentions_ics": true,
"published_at": "2026-07-21T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-05.json",
"https://www.cve.org/CVERecord?id=CVE-2025-40945",
"https://support.sw.siemens.com/product/222981661/",
"https://support.sw.siemens.com/product/246738425/",
"https://support.sw.siemens.com/product/297028302/"
],
"mentions_ransomware": false
}06Siemens SIDIS Secured SmartPlugView CSAF Summary SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has relea{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-04","cves":[…
EVENT. cmruwnv9ID. cmruwnv9e7ms5kh0c5z1dx3b4SRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-04",
"cves": [
"CVE-2022-23303",
"CVE-2019-9494",
"CVE-2022-23304",
"CVE-2019-9495",
"CVE-2022-37660",
"CVE-2022-48174",
"CVE-2025-5222",
"CVE-2025-5914",
"CVE-2025-9230",
"CVE-2025-9231",
"CVE-2025-9232",
"CVE-2025-26465",
"CVE-2025-32462",
"CVE-2026-5121"
],
"slug": "icsa-26-202-04",
"title": "Siemens SIDIS Secured SmartPlug",
"source": "cisa.gov",
"excerpt": "View CSAF Summary SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version. The following versions of Siemens SIDIS Secured SmartPlug are affected: SIDIS Secured SmartPlug vers:intdot/<7.26.0310 CVSS Vendor Equipment Vulnerabilities v3 9.8 Siemens Siemens SIDIS Secured SmartPlug Improper Enforcement of Message Integrity During Transmission in a Communication Channel, Reusing a Nonce, Key Pair in Encryption, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Integer Overflow or Wraparound, Out-of-bounds Read, Covert Timing Chan",
"cve_count": 14,
"categories": [],
"word_count": 2160,
"mentions_ics": true,
"published_at": "2026-07-21T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-04.json",
"https://www.cve.org/CVERecord?id=CVE-2022-23303",
"https://cwe.mitre.org/data/definitions/924.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"https://www.cve.org/CVERecord?id=CVE-2022-23304"
],
"mentions_ransomware": false
}07Tycon Systems TPDIN-Monitor-WEB2View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment,{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-01","cves":[…
EVENT. cmruwnuoID. cmruwnuoe7ms3kh0ccs1n2ycmSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-01",
"cves": [
"CVE-2026-61884",
"CVE-2026-55985"
],
"slug": "icsa-26-202-01",
"title": "Tycon Systems TPDIN-Monitor-WEB2",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The following versions of Tycon Systems TPDIN-Monitor-WEB2 are affected: TPDIN-Monitor-WEB2 2.3.9 CVSS Vendor Equipment Vulnerabilities v3 9.8 Tycon Systems Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel, Cleartext Storage of Sensitive Information Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-61884 The web management interface of the affected device does not perfo",
"cve_count": 2,
"categories": [],
"word_count": 640,
"mentions_ics": true,
"published_at": "2026-07-21T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-01.json",
"https://www.cve.org/CVERecord?id=CVE-2026-61884",
"https://www.tyconsystems.com/contact",
"https://cwe.mitre.org/data/definitions/288.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
],
"mentions_ransomware": false
}08CISA Adds Four Known Exploited Vulnerabilities to CatalogCISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability{"url":"https://www.cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-…
EVENT. cmruujnjID. cmruujnjp7m7bkh0c6ec628t5SRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog",
"cves": [
"CVE-2021-27137",
"CVE-2026-0770",
"CVE-2026-63030",
"CVE-2026-60137"
],
"slug": "cisa-adds-four-known-exploited-vulnerabilities-catalog",
"title": "CISA Adds Four Known Exploited Vulnerabilities to Catalog",
"source": "cisa.gov",
"excerpt": "CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability CVE-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability CVE-2026-63030 WordPress Core Interpretation Conflict Vulnerability CVE-2026-60137 WordPress Core SQL Injection Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importan",
"cve_count": 4,
"categories": [],
"word_count": 244,
"mentions_ics": false,
"published_at": "2026-07-21T12:00:00.000Z",
"advisory_type": "alert",
"outbound_links": [
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
"https://www.cve.org/CVERecord?id=CVE-2021-27137",
"https://www.cve.org/CVERecord?id=CVE-2026-0770",
"https://www.cve.org/CVERecord?id=CVE-2026-63030",
"https://www.cve.org/CVERecord?id=CVE-2026-60137"
],
"mentions_ransomware": false
}09CISA Adds Three Known Exploited Vulnerabilities to CatalogCISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-25089 Fortinet FortiSandbox OS Command Injection Vuln{"url":"https://www.cisa.gov/news-events/alerts/2026/07/16/cisa-adds-three-known…
EVENT. cmrnvo22ID. cmrnvo2225ssxkh0cxzdhc8tvSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/alerts/2026/07/16/cisa-adds-three-known-exploited-vulnerabilities-catalog",
"cves": [
"CVE-2026-25089",
"CVE-2026-39808",
"CVE-2026-58644"
],
"slug": "cisa-adds-three-known-exploited-vulnerabilities-catalog",
"title": "CISA Adds Three Known Exploited Vulnerabilities to Catalog",
"source": "cisa.gov",
"excerpt": "CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-25089 Fortinet FortiSandbox OS Command Injection Vulnerability CVE-2026-39808 Fortinet FortiSandbox OS Command Injection Vulnerability CVE-2026-58644 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to ",
"cve_count": 3,
"categories": [],
"word_count": 238,
"mentions_ics": false,
"published_at": "2026-07-16T12:00:00.000Z",
"advisory_type": "alert",
"outbound_links": [
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
"https://www.cve.org/CVERecord?id=CVE-2026-25089",
"https://www.cve.org/CVERecord?id=CVE-2026-39808",
"https://www.cve.org/CVERecord?id=CVE-2026-58644",
"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk"
],
"mentions_ransomware": false
}10Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBTView CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation 1756-EN2, 1756-EN3, and 17{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-02","cves":[…
EVENT. cmrnp92wID. cmrnp92w05r0nkh0ccqln8bz7SRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-02",
"cves": [
"CVE-2026-9653"
],
"slug": "icsa-26-197-02",
"title": "Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT are affected: 1756-EN3 <=V12.001 (CVE-2026-9653) 1756-EN2 <=V12.001 (CVE-2026-9653) 1756-ENBT V6.006 (CVE-2026-9653) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT Improper Validation of Integrity Check Value Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-9653 A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to impro",
"cve_count": 1,
"categories": [],
"word_count": 546,
"mentions_ics": true,
"published_at": "2026-07-16T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-02.json",
"https://www.cve.org/CVERecord?id=CVE-2026-9653",
"https://cwe.mitre.org/data/definitions/354.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
],
"mentions_ransomware": false
}showing 1–10 of 140older →
§03
subscribe
three pathways carry every event on this topic. pick the one that fits your agent.
GETrss feed
any reader · no authhttps://api.callsign.sh/v1/public/channels/security/topics/cisa-advisories/feed.xmlGETjson pull
poll on your schedule · optional since/untilhttps://api.callsign.sh/v1/public/channels/security/topics/cisa-advisories.jsonPOSTwebhook
push delivery · one POST per eventsubscribe by reader, by pull loop, or by webhook above