CISA Advisories

topic · security/cisa-advisories
DOC.
security/cisa-advisories
REV.
176 evt
DATE.
02-JUN-2026
SCOPE.
custom
§01

about

CISA cybersecurity alerts, ICS advisories, and analysis reports (separate stream from KEV).

§02

recent events

LIVElast event 0s ago0 evt / 1h

showing 10 of 149 events in this window (176 total on topic). adjust the range or clear it with ALL.

range
iso 8601 utc
iso 8601 utc
01MZ Automation lib60870View CSAF Summary Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service. The following versions of MZ Automation lib60870 are aff{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-07","cves":[…
EVENT. cmrxtmdhID. cmrxtmdhv8fnzkh0cmxvasizfSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-07",
  "cves": [
    "CVE-2026-16002"
  ],
  "slug": "icsa-26-204-07",
  "title": "MZ Automation lib60870",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service. The following versions of MZ Automation lib60870 are affected: lib60870 <=2.4.0 CVSS Vendor Equipment Vulnerabilities v3 8.2 MZ Automation MZ Automation lib60870 Out-of-bounds Read Background Critical Infrastructure Sectors: Chemical, Energy, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-16002 The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service. View CVE Details Affected Products MZ Automation lib60870 Vendor: MZ Automation Product Version: MZ Automation lib60870: ",
  "cve_count": 1,
  "categories": [],
  "word_count": 486,
  "mentions_ics": true,
  "published_at": "2026-07-23T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-07.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-16002",
    "https://github.com/mz-automation/lib60870/security/advisories/GHSA-f5xp-w6f3-vvrv",
    "https://cwe.mitre.org/data/definitions/125.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
  ],
  "mentions_ransomware": false
}
02MZ Automation libIEC61850View CSAF Summary Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting o{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-06","cves":[…
EVENT. cmrxtmcxID. cmrxtmcxu8fnxkh0cbtaw35xhSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-06",
  "cves": [
    "CVE-2026-50039",
    "CVE-2026-49035",
    "CVE-2026-50103",
    "CVE-2026-50032"
  ],
  "slug": "icsa-26-204-06",
  "title": "MZ Automation libIEC61850",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions. The following versions of MZ Automation libIEC61850 are affected: libIEC61850 >=v1.0.0|<=v1.6.1  CVSS Vendor Equipment Vulnerabilities v3 8.1 MZ Automation MZ Automation libIEC61850 Stack-based Buffer Overflow, Heap-based Buffer Overflow, Improper Handling of Syntactically Invalid Structure, NULL Pointer Dereference Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-20",
  "cve_count": 4,
  "categories": [],
  "word_count": 817,
  "mentions_ics": true,
  "published_at": "2026-07-23T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-06.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-50039",
    "https://github.com/mz-automation/libiec61850",
    "https://cwe.mitre.org/data/definitions/121.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
  ],
  "mentions_ransomware": false
}
03Johnson Controls XAAP AndroidView CSAF Summary Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device. The following versions of Johnson Controls XAAP Android {"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-02","cves":[…
EVENT. cmrxtmcdID. cmrxtmcds8fnvkh0cr5e5syapSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-02",
  "cves": [
    "CVE-2026-34490"
  ],
  "slug": "icsa-26-204-02",
  "title": "Johnson Controls XAAP Android",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device. The following versions of Johnson Controls XAAP Android are affected: XAAP Android <1.53 CVSS Vendor Equipment Vulnerabilities v3 3.3 Johnson Controls Johnson Controls XAAP Android Cleartext Storage of Sensitive Information Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-34490 A cleartext storage weakness exists in the Fire Solutions Android application, which stores application data locally on the device without encryption. An attacker with physical access to the device and one able to compromise the device through",
  "cve_count": 1,
  "categories": [],
  "word_count": 588,
  "mentions_ics": true,
  "published_at": "2026-07-23T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-02.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-34490",
    "https://cwe.mitre.org/data/definitions/312.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
    "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
  ],
  "mentions_ransomware": false
}
04Weintek cMT3092XView CSAF Summary Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users. The following versions of Weintek cM{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-03","cves":[…
EVENT. cmrxtmbtID. cmrxtmbt98fntkh0cdqy8ybszSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-03",
  "cves": [
    "CVE-2026-60134",
    "CVE-2026-61892",
    "CVE-2026-61886",
    "CVE-2026-60135"
  ],
  "slug": "icsa-26-204-03",
  "title": "Weintek cMT3092X",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users. The following versions of Weintek cMT3092X are affected: cMT3092X firmware <20210218  EasyWeb <v2.1.20 CVSS Vendor Equipment Vulnerabilities v3 8.8 Weintek Weintek cMT3092X Reliance on Cookies without Validation and Integrity Checking in a Security Decision, Incorrect Permission Assignment for Critical Resource, Plaintext Storage of a Password, Incorrect User Management Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Taiwan Vulnerabilities Expand All + CVE-2026-60134 Weintek cMT3092X HMI allows a non-privileged user to modify cookies",
  "cve_count": 4,
  "categories": [],
  "word_count": 831,
  "mentions_ics": true,
  "published_at": "2026-07-23T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-03.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-60134",
    "https://www.weintek.com/globalw/Support/Knowledge.aspx",
    "https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf",
    "https://cwe.mitre.org/data/definitions/784.html"
  ],
  "mentions_ransomware": false
}
05Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration SuiteRussian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Executive summary   A group of Russian state-supported cyber actors has been targeting{"url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a","cv…
EVENT. cmrxn89pID. cmrxn89p18dwpkh0cjla9z10vSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a",
  "cves": [
    "CVE-2025-66376"
  ],
  "slug": "aa26-204a",
  "title": "Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite",
  "source": "cisa.gov",
  "excerpt": "Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Executive summary   A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see Cybersecurity industry tracking ), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [ 1 ]. LAUNDRY BEAR’s targeting is almost certainly to gather sensitive information for the Ru",
  "cve_count": 1,
  "categories": [],
  "word_count": 8200,
  "mentions_ics": false,
  "published_at": "2026-07-23T12:00:00.000Z",
  "advisory_type": "cybersecurity_advisory",
  "outbound_links": [
    "https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF",
    "https://www.cve.org/CVERecord?id=CVE-2025-66376",
    "https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.xml",
    "https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.json",
    "https://attack.mitre.org/versions/v19/techniques/T1114/002/"
  ],
  "mentions_ransomware": false
}
06CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.   CVE-2026-16232 Check Point SmartConsole Improper Authenti{"url":"https://www.cisa.gov/news-events/alerts/2026/07/22/cisa-adds-two-known-e…
EVENT. cmrwkogkID. cmrwkogky83c1kh0cine4lg03SRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/alerts/2026/07/22/cisa-adds-two-known-exploited-vulnerabilities-catalog",
  "cves": [
    "CVE-2026-16232",
    "CVE-2026-50522"
  ],
  "slug": "cisa-adds-two-known-exploited-vulnerabilities-catalog",
  "title": "CISA Adds Two Known Exploited Vulnerabilities to Catalog",
  "source": "cisa.gov",
  "excerpt": "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.   CVE-2026-16232 Check Point SmartConsole Improper Authentication Vulnerability CVE-2026-50522 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically th",
  "cve_count": 2,
  "categories": [],
  "word_count": 231,
  "mentions_ics": false,
  "published_at": "2026-07-22T12:00:00.000Z",
  "advisory_type": "alert",
  "outbound_links": [
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
    "https://www.cve.org/CVERecord?id=CVE-2026-16232",
    "https://www.cve.org/CVERecord?id=CVE-2026-50522",
    "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities"
  ],
  "mentions_ransomware": false
}
07Siemens Opcenter XView CSAF Summary Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new ve{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-03","cves":[…
EVENT. cmruwnzpID. cmruwnzpm7msnkh0c5fmlo6tdSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-03",
  "cves": [
    "CVE-2026-56451"
  ],
  "slug": "icsa-26-202-03",
  "title": "Siemens Opcenter X",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version. The following versions of Siemens Opcenter X are affected: Opcenter X vers:intdot/<2604 CVSS Vendor Equipment Vulnerabilities v3 10 Siemens Siemens Opcenter X Improper Verification of Cryptographic Signature Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-56451 Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthe",
  "cve_count": 1,
  "categories": [],
  "word_count": 650,
  "mentions_ics": true,
  "published_at": "2026-07-21T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-03.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-56451",
    "https://support.sw.siemens.com/product/206159703/",
    "https://cwe.mitre.org/data/definitions/347.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
  ],
  "mentions_ransomware": false
}
08Rockwell Automation FactoryTalk Services PlatformView CSAF Summary Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations.{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-07","cves":[…
EVENT. cmruwnz5ID. cmruwnz5s7mslkh0cz9u2zrr9SRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-07",
  "cves": [
    "CVE-2026-10714"
  ],
  "slug": "icsa-26-202-07",
  "title": "Rockwell Automation FactoryTalk Services Platform",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations. The following versions of Rockwell Automation FactoryTalk Services Platform are affected: FactoryTalk Directory (FTSP) 6.60  CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation FactoryTalk Services Platform Weak Authentication Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-10714 A security issue exists within FactoryTalk Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web A",
  "cve_count": 1,
  "categories": [],
  "word_count": 612,
  "mentions_ics": true,
  "published_at": "2026-07-21T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-07.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-10714",
    "https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight",
    "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1786.html",
    "https://cwe.mitre.org/data/definitions/1390.html"
  ],
  "mentions_ransomware": false
}
09Siemens CADRAView CSAF Summary CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing furthe{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-06","cves":[…
EVENT. cmruwnylID. cmruwnylx7msjkh0ciqxn01jnSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-06",
  "cves": [
    "CVE-2005-2096",
    "CVE-2016-9840",
    "CVE-2016-9841",
    "CVE-2016-9842",
    "CVE-2017-14919",
    "CVE-2018-25032",
    "CVE-2022-37434",
    "CVE-2023-45853",
    "CVE-2025-10585",
    "CVE-2025-13223",
    "CVE-2026-22184"
  ],
  "slug": "icsa-26-202-06",
  "title": "Siemens CADRA",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens CADRA are affected: CADRA vers:intdot/<2511, vers:all/*  CVSS Vendor Equipment Vulnerabilities v3 9.8 Siemens Siemens CADRA Improper Input Validation, Incorrect Bitwise Shift of Integer, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Integer Overflow or Wraparound, Access of Resource Using Incompatible Type ('Type Confusion') Background Critical Infrastructure Sectors: Chemical, Commercial Faciliti",
  "cve_count": 11,
  "categories": [],
  "word_count": 1522,
  "mentions_ics": true,
  "published_at": "2026-07-21T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-06.json",
    "https://www.cve.org/CVERecord?id=CVE-2005-2096",
    "https://cwe.mitre.org/data/definitions/20.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
    "https://www.cve.org/CVERecord?id=CVE-2016-9840"
  ],
  "mentions_ransomware": false
}
10Rockwell Automation Studio 5000 Logix DesignerView CSAF Summary Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code. The following versions {"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-10","cves":[…
EVENT. cmruwny1ID. cmruwny1u7mshkh0cdfu0hl5hSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-10",
  "cves": [
    "CVE-2026-9108",
    "CVE-2026-9127",
    "CVE-2026-9128"
  ],
  "slug": "icsa-26-202-10",
  "title": "Rockwell Automation Studio 5000 Logix Designer",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code. The following versions of Rockwell Automation Studio 5000 Logix Designer are affected: Studio 5000 Logix Designer V36.00 (CVE-2026-9108) Studio 5000 Logix Designer V35.00 (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128) Studio 5000 Logix Designer V35.01 (CVE-2026-9108) Studio 5000 Logix Designer >=V34.00|<=V34.03 (CVE-2026-9108) Studio 5000 Logix Designer >=V33.00|<=V33.03 (CVE-2026-9108) Studio 5000 Logix Designer >=V32.00|<=V32.04 (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128) Studio 5000 Logix Designer V34.00 (CVE-2026-9127) Studio 5000 Logix Designer V34.01 (CVE-2026-9127) Studio 5000 Logix Designe",
  "cve_count": 3,
  "categories": [],
  "word_count": 1153,
  "mentions_ics": true,
  "published_at": "2026-07-21T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-10.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-9108",
    "https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight",
    "https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html",
    "https://cwe.mitre.org/data/definitions/22.html"
  ],
  "mentions_ransomware": false
}
showing 1–10 of 149older →
§03

subscribe

three pathways carry every event on this topic. pick the one that fits your agent.

GETrss feed
any reader · no auth
https://api.callsign.sh/v1/public/channels/security/topics/cisa-advisories/feed.xml
GETjson pull
poll on your schedule · optional since/until
https://api.callsign.sh/v1/public/channels/security/topics/cisa-advisories.json
POSTwebhook
push delivery · one POST per event
log in to subscribe →
subscribe by reader, by pull loop, or by webhook above