CISA Advisories
topic · security/cisa-advisories
§01
about
CISA cybersecurity alerts, ICS advisories, and analysis reports (separate stream from KEV).
§02
recent events
LIVElast event 0s ago0 evt / 1h
showing 10 of 158 events in this window (176 total on topic). adjust the range or clear it with ALL.
range
01Siemens Desigo CCView CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Sie{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-01","cves":[…
EVENT. cms4skrbID. cms4skrboa7e7kh0cj5m4wz2wSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-01",
"cves": [
"CVE-2025-15467"
],
"slug": "icsa-26-209-01",
"title": "Siemens Desigo CC",
"source": "cisa.gov",
"excerpt": "View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available. The following versions of Siemens Desigo CC are affected: Desigo CC family V7 vers:all/* (CVE-2025-15467) Desigo CC family V8 vers:all/* (CVE-2025-15467) Desigo CC family V9 vers:intdot/<9.0.1 (CVE-2025-15467) CVSS Vendor Equipment Vulnerabilities v3 9.8 Siemens Siemens Desigo CC Out-of-bounds Write Background Critical Infrastructure Sectors: Critical Manu",
"cve_count": 1,
"categories": [],
"word_count": 983,
"mentions_ics": true,
"published_at": "2026-07-28T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-01.json",
"https://www.cve.org/CVERecord?id=CVE-2025-15467",
"https://support.industry.siemens.com/cs/ww/en/view/110002555/",
"https://cwe.mitre.org/data/definitions/787.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
],
"mentions_ransomware": false
}02Siemens SIMATIC S7-PLCSIM AdvancedView CSAF Summary SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific cou{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-03","cves":[…
EVENT. cms4skqrID. cms4skqrra7e5kh0c3qg710thSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-03",
"cves": [
"CVE-2026-54429"
],
"slug": "icsa-26-209-03",
"title": "Siemens SIMATIC S7-PLCSIM Advanced",
"source": "cisa.gov",
"excerpt": "View CSAF Summary SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIMATIC S7-PLCSIM Advanced are affected: SIMATIC S7-PLCSIM Advanced vers:all/* (CVE-2026-54429) CVSS Vendor Equipment Vulnerabilities v3 7.4 Siemens Siemens SIMATIC S7-PLCSIM Advanced Allocation of Resources Without Limits or Throttling Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-54429 Affected devices do not properly handle high-volume multicast network traf",
"cve_count": 1,
"categories": [],
"word_count": 797,
"mentions_ics": true,
"published_at": "2026-07-28T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-03.json",
"https://www.cve.org/CVERecord?id=CVE-2026-54429",
"https://cwe.mitre.org/data/definitions/770.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"
],
"mentions_ransomware": false
}03CI Fortify – Advice for isolating vital systemsCI Fortify – Advice for isolating vital systems CISA and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), in collaboration with the Federal Bureau of Investigation a{"url":"https://www.cisa.gov/resources-tools/resources/ci-fortify-advice-isolati…
EVENT. cms4skq7ID. cms4skq7aa7e3kh0cbnjxmhstSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/resources-tools/resources/ci-fortify-advice-isolating-vital-systems",
"cves": [],
"slug": "ci-fortify-advice-isolating-vital-systems",
"title": "CI Fortify – Advice for isolating vital systems",
"source": "cisa.gov",
"excerpt": "CI Fortify – Advice for isolating vital systems CISA and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), in collaboration with the Federal Bureau of Investigation and international partners, released joint guidance CI Fortify – Advice for isolating vital systems . This guidance contains practical steps for critical infrastructure (CI) organizations to isolate vital operational technology and enabling systems from all other networks in the event of disruption or crisis and operate in isolation for an extended period. Developed to address escalating cyber threats, the guidance outlines key steps for identifying critical systems, mapping connections, and implementing effective separation points. By following these recommendations, organizations can enhance ",
"cve_count": 0,
"categories": [],
"word_count": 123,
"mentions_ics": false,
"published_at": "2026-07-28T12:00:00.000Z",
"advisory_type": "advisory",
"outbound_links": [
"https://www.cyber.gov.au/business-government/secure-design/operational-technology-environments/ci-fortify/ci-fortify-advice-for-isolating-vital-systems"
],
"mentions_ransomware": false
}04MikroTik RouterOS and Cloud Hosted RouterView CSAF Summary Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system access. The following versions of MikroTik RouterOS and Cl{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-05","cves":[…
EVENT. cms4skpmID. cms4skpmia7e1kh0clzkeyg8bSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-05",
"cves": [
"CVE-2026-16347"
],
"slug": "icsa-26-209-05",
"title": "MikroTik RouterOS and Cloud Hosted Router",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system access. The following versions of MikroTik RouterOS and Cloud Hosted Router are affected: RouterOS vers:all/* (CVE-2026-16347) Cloud Hosted Router vers:all/* (CVE-2026-16347) CVSS Vendor Equipment Vulnerabilities v3 8.8 MikroTik MikroTik RouterOS and Cloud Hosted Router Improper Restriction of Excessive Authentication Attempts Background Critical Infrastructure Sectors: Information Technology, Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: Latvia Vulnerabilities Expand All + CVE-2026-16347 MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessiv",
"cve_count": 1,
"categories": [],
"word_count": 598,
"mentions_ics": true,
"published_at": "2026-07-28T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-05.json",
"https://www.cve.org/CVERecord?id=CVE-2026-16347",
"https://mikrotik.com/support",
"https://cwe.mitre.org/data/definitions/307.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
],
"mentions_ransomware": false
}05Siemens Mendix RuntimeView CSAF Summary Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access {"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-02","cves":[…
EVENT. cms4skp1ID. cms4skp1ta7dzkh0c06jxv1foSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-02",
"cves": [
"CVE-2026-7891"
],
"slug": "icsa-26-209-02",
"title": "Siemens Mendix Runtime",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely. This documentation gap may lead application developers to unknowingly apply overly permissive access rules to System.User, resulting in unintended exposure of sensitive user data or privilege escalation within deployed Mendix applications. A common misconfiguration identified is with the anonymous user role with a System.User entity to gain access to all stored records, even though no access rights are explicitly configured on that role. Siemens recommends Mendix developers to review their access rules based on updated documentation. The following versions of Siemens Mendix Run",
"cve_count": 1,
"categories": [],
"word_count": 774,
"mentions_ics": true,
"published_at": "2026-07-28T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-02.json",
"https://www.cve.org/CVERecord?id=CVE-2026-7891",
"https://cwe.mitre.org/data/definitions/277.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
],
"mentions_ransomware": false
}06CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Informatio{"url":"https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-e…
EVENT. cms3ntrtID. cms3ntrt49wohkh0cvkavntrsSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog",
"cves": [
"CVE-2025-68686",
"CVE-2026-16812"
],
"slug": "cisa-adds-two-known-exploited-vulnerabilities-catalog",
"title": "CISA Adds Two Known Exploited Vulnerabilities to Catalog",
"source": "cisa.gov",
"excerpt": "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerab",
"cve_count": 2,
"categories": [],
"word_count": 236,
"mentions_ics": false,
"published_at": "2026-07-27T12:00:00.000Z",
"advisory_type": "alert",
"outbound_links": [
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
"https://www.cve.org/CVERecord?id=CVE-2025-68686",
"https://www.cve.org/CVERecord?id=CVE-2026-16812",
"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities"
],
"mentions_ransomware": false
}07Rockwell Automation ThinManagerView CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended di{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-05","cves":[…
EVENT. cmry00uwID. cmry00uwf8horkh0cvhinsddbSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-05",
"cves": [
"CVE-2026-11917"
],
"slug": "icsa-26-204-05",
"title": "Rockwell Automation ThinManager",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory. The following versions of Rockwell Automation ThinManager are affected: ThinManager >=13.0.0|<13.0.7, >=13.1.0|<13.1.5, >=13.2.0|<13.2.4, >=14.0.0|<14.0.2 CVSS Vendor Equipment Vulnerabilities v3 8.1 Rockwell Automation Rockwell Automation ThinManager Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Background Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy, Food and Agriculture, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All",
"cve_count": 1,
"categories": [],
"word_count": 629,
"mentions_ics": true,
"published_at": "2026-07-23T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-05.json",
"https://www.cve.org/CVERecord?id=CVE-2026-11917",
"https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight",
"https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html",
"https://cwe.mitre.org/data/definitions/22.html"
],
"mentions_ransomware": false
}08Panduit IntraVUEView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, spe{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-04","cves":[…
EVENT. cmrxtmejID. cmrxtmej58fo3kh0c2ohi8ksvSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-04",
"cves": [
"CVE-2026-40430",
"CVE-2026-42933",
"CVE-2026-44955",
"CVE-2026-50044",
"CVE-2026-28698"
],
"slug": "icsa-26-204-04",
"title": "Panduit IntraVUE",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider knowledge, or advanced tooling. The following versions of Panduit IntraVUE are affected: IntraVUE <=3.2.1a14 CVSS Vendor Equipment Vulnerabilities v3 10 Pronetiqs Panduit IntraVUE Plaintext Storage of a Password, Unintended Proxy or Intermediary ('Confused Deputy'), Exposure of Sensitive System Information to an Unauthorized Control Sphere, Inadequate Encryption Strength Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Information Technology, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Netherlands ",
"cve_count": 5,
"categories": [],
"word_count": 937,
"mentions_ics": true,
"published_at": "2026-07-23T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-04.json",
"https://www.cve.org/CVERecord?id=CVE-2026-40430",
"https://cwe.mitre.org/data/definitions/256.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
],
"mentions_ransomware": false
}09Johnson Controls C-CURE 9000 and Victor application serverView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. The following versions of Johnson Controls C-CURE 9000 {"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01","cves":[…
EVENT. cmrxtme0ID. cmrxtme0i8fo1kh0c15eou3slSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01",
"cves": [
"CVE-2026-21655",
"CVE-2026-21653",
"CVE-2026-34496"
],
"slug": "icsa-26-204-01",
"title": "Johnson Controls C-CURE 9000 and Victor application server",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. The following versions of Johnson Controls C-CURE 9000 and Victor application server are affected: C-CURE 9000 and victor <=v2.90_v3.0 victor Web <=v7.1 CVSS Vendor Equipment Vulnerabilities v3 9.6 Johnson Controls Johnson Controls C-CURE 9000 and Victor application server Server-Side Request Forgery (SSRF), Execution with Unnecessary Privileges Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-21655 Under certain circumstances, successful exploitation of this vulnerability could allow an unauthenticat",
"cve_count": 3,
"categories": [],
"word_count": 1246,
"mentions_ics": true,
"published_at": "2026-07-23T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-01.json",
"https://www.cve.org/CVERecord?id=CVE-2026-21655",
"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories",
"https://cwe.mitre.org/data/definitions/918.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
],
"mentions_ransomware": false
}10MZ Automation lib60870View CSAF Summary Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service. The following versions of MZ Automation lib60870 are aff{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-07","cves":[…
EVENT. cmrxtmdhID. cmrxtmdhv8fnzkh0cmxvasizfSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-07",
"cves": [
"CVE-2026-16002"
],
"slug": "icsa-26-204-07",
"title": "MZ Automation lib60870",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service. The following versions of MZ Automation lib60870 are affected: lib60870 <=2.4.0 CVSS Vendor Equipment Vulnerabilities v3 8.2 MZ Automation MZ Automation lib60870 Out-of-bounds Read Background Critical Infrastructure Sectors: Chemical, Energy, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-16002 The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service. View CVE Details Affected Products MZ Automation lib60870 Vendor: MZ Automation Product Version: MZ Automation lib60870: ",
"cve_count": 1,
"categories": [],
"word_count": 486,
"mentions_ics": true,
"published_at": "2026-07-23T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-07.json",
"https://www.cve.org/CVERecord?id=CVE-2026-16002",
"https://github.com/mz-automation/lib60870/security/advisories/GHSA-f5xp-w6f3-vvrv",
"https://cwe.mitre.org/data/definitions/125.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
],
"mentions_ransomware": false
}showing 1–10 of 158older →
§03
subscribe
three pathways carry every event on this topic. pick the one that fits your agent.
GETrss feed
any reader · no authhttps://api.callsign.sh/v1/public/channels/security/topics/cisa-advisories/feed.xmlGETjson pull
poll on your schedule · optional since/untilhttps://api.callsign.sh/v1/public/channels/security/topics/cisa-advisories.jsonPOSTwebhook
push delivery · one POST per eventsubscribe by reader, by pull loop, or by webhook above