CISA Advisories

topic · security/cisa-advisories
DOC.
security/cisa-advisories
REV.
176 evt
DATE.
02-JUN-2026
SCOPE.
custom
§01

about

CISA cybersecurity alerts, ICS advisories, and analysis reports (separate stream from KEV).

§02

recent events

LIVElast event 0s ago0 evt / 1h

showing 10 of 167 events in this window (176 total on topic). adjust the range or clear it with ALL.

range
iso 8601 utc
iso 8601 utc
01Schneider Electric IGSSView CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-04","cves":[…
EVENT. cms7u5diID. cms7u5diqb0adkh0cctxev7hsSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-04",
  "cves": [
    "CVE-2026-12927"
  ],
  "slug": "icsa-26-211-04",
  "title": "Schneider Electric IGSS",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. The IGSS Definition module is a design-time component used by system integrators to create mimic diagrams for plant personnel, enabling them to monitor and control the SCADA system. Failure to apply the remediation provided below may risk loss of data or arbitrary code execution, which could result in the loss of control of the system. The following versions of Schneider Electric IGSS are affected: IGSS () IGSS Definition (Def.exe) module vers:intdot/<=18.0.0.26124, 18.0.0.26125 () CVSS V",
  "cve_count": 1,
  "categories": [],
  "word_count": 1282,
  "mentions_ics": true,
  "published_at": "2026-07-30T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-04.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-12927",
    "https://igss.schneider-electric.com/igss/igssupdates/v180/IGSSUPDATE.ZIP",
    "https://cwe.mitre.org/data/definitions/787.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
  ],
  "mentions_ransomware": false
}
02Mitsubishi Electric CC-Link IE TSN Communication ProtocolView CSAF Summary Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending spe{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-07","cves":[…
EVENT. cms7u5czID. cms7u5cz5b0abkh0cf8cvwkphSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-07",
  "cves": [
    "CVE-2026-13584"
  ],
  "slug": "icsa-26-211-07",
  "title": "Mitsubishi Electric CC-Link IE TSN Communication Protocol",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly. The following versions of Mitsubishi Electric CC-Link IE TSN Communication Protocol are affected: Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-16 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-32 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-64 vers:all/* (CVE-2026-1358",
  "cve_count": 1,
  "categories": [],
  "word_count": 2728,
  "mentions_ics": true,
  "published_at": "2026-07-30T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-07.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-13584",
    "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-005_en.pdf",
    "https://cwe.mitre.org/data/definitions/924.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
  ],
  "mentions_ransomware": false
}
03NASA Core Flight System (cFS) Health & Safety (HS) ApplicationView CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of NASA Core Flight System (cFS) Health & Saf{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-06","cves":[…
EVENT. cms7u5cfID. cms7u5cfab0a9kh0cofvg714vSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-06",
  "cves": [
    "CVE-2026-18064",
    "CVE-2026-15352"
  ],
  "slug": "icsa-26-211-06",
  "title": "NASA Core Flight System (cFS) Health & Safety (HS) Application",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of NASA Core Flight System (cFS) Health & Safety (HS) Application are affected: Core Flight System (cFS) Health & Safety (HS) Application <=v7.0.1 (CVE-2026-18064) CVSS Vendor Equipment Vulnerabilities v3 7.5 NASA NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-18064 An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer ",
  "cve_count": 2,
  "categories": [],
  "word_count": 583,
  "mentions_ics": true,
  "published_at": "2026-07-30T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-06.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-18064",
    "https://github.com/nasa/HS",
    "https://cwe.mitre.org/data/definitions/476.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
  ],
  "mentions_ransomware": false
}
04Open Source Software: Security Principles and PracticesOpen source software (OSS) is embedded in nearly every modern system, from business applications to critical infrastructure. Our new Open Source Software: Security Principles and Practices guidance he{"url":"https://www.cisa.gov/resources-tools/resources/open-source-software-secu…
EVENT. cms7nn5eID. cms7nn5efaynfkh0cqnu32whsSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/resources-tools/resources/open-source-software-security-principles-and-practices",
  "cves": [],
  "slug": "open-source-software-security-principles-and-practices",
  "title": "Open Source Software: Security Principles and Practices",
  "source": "cisa.gov",
  "excerpt": "Open source software (OSS) is embedded in nearly every modern system, from business applications to critical infrastructure. Our new Open Source Software: Security Principles and Practices guidance helps agencies securely use, evaluate, and publish open source software. It covers OSS risk management across the full lifecycle, introduces the C4 Framework for trust assessment, and provides specific recommendations for vulnerability management, software bill of materials use, secure development, and handling open source artificial intelligence systems. Visit CISA’s Open Source Security webpage for more resources. CISA is committed to providing access to our web pages and documents for individuals with disabilities, both members of the public and federal employees. If the format of any element",
  "cve_count": 0,
  "categories": [],
  "word_count": 177,
  "mentions_ics": false,
  "published_at": "2026-07-30T12:00:00.000Z",
  "advisory_type": "advisory",
  "outbound_links": [
    "https://www.cisa.gov/opensource",
    "https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_9n4TtB8uttUPaM6?product=https://www.cisa.gov/resources-tools/resources/open-source-software-security-principles-and-practices"
  ],
  "mentions_ransomware": false
}
05CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.   CVE-2026-20316 Cisco Secure Firewall Management Center Use {"url":"https://www.cisa.gov/news-events/alerts/2026/07/29/cisa-adds-one-known-e…
EVENT. cms6iqn3ID. cms6iqn31anpnkh0c0ivimmvuSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/alerts/2026/07/29/cisa-adds-one-known-exploited-vulnerability-catalog",
  "cves": [
    "CVE-2026-20316"
  ],
  "slug": "cisa-adds-one-known-exploited-vulnerability-catalog",
  "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
  "source": "cisa.gov",
  "excerpt": "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.   CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in ",
  "cve_count": 1,
  "categories": [],
  "word_count": 227,
  "mentions_ics": false,
  "published_at": "2026-07-29T12:00:00.000Z",
  "advisory_type": "alert",
  "outbound_links": [
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
    "https://www.cve.org/CVERecord?id=CVE-2026-20316",
    "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities",
    "https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w"
  ],
  "mentions_ransomware": false
}
062026 Minimum Elements for a Software Bill of Materials (SBOM)CISA, the National Security Agency, the Federal Bureau of Investigation, and international partners released joint guidance,  2026 Minimum Elements for a Software Bill of Materials (SBOM) , that {"url":"https://www.cisa.gov/resources-tools/resources/2026-minimum-elements-sof…
EVENT. cms67z22ID. cms67z22rakvrkh0c8iyvaje8SRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/resources-tools/resources/2026-minimum-elements-software-bill-materials-sbom",
  "cves": [],
  "slug": "2026-minimum-elements-software-bill-materials-sbom",
  "title": "2026 Minimum Elements for a Software Bill of Materials (SBOM)",
  "source": "cisa.gov",
  "excerpt": "CISA, the National Security Agency, the Federal Bureau of Investigation, and international partners released joint guidance,  2026 Minimum Elements for a Software Bill of Materials (SBOM) , that updates and replaces the minimum elements for an SBOM published by the National Telecommunications and Information Administration (NTIA) in 2021. The new guidance incorporates stakeholder feedback from a 2025 public comment period and reflects current SBOM tools and needs while preserving the core principles of the original NTIA document. An SBOM serves as an “ingredients list” for software and is a key building block of software security and supply chain risk management. Organizations can use SBOM data to better understand the makeup of their software components and supply chains and mak",
  "cve_count": 0,
  "categories": [],
  "word_count": 185,
  "mentions_ics": false,
  "published_at": "2026-07-29T12:00:00.000Z",
  "advisory_type": "advisory",
  "outbound_links": [
    "https://www.cisa.gov/sites/default/files/2026-07/2026_cisa_sbom_minimum_elements_508c.pdf"
  ],
  "mentions_ransomware": false
}
07igloohome Smart Lock Mobile ApplicationView CSAF Summary Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services. The following versions of igloohome Smart Lock Mobile Applica{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-06","cves":[…
EVENT. cms4skszID. cms4skszea7edkh0c3c10ts89SRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-06",
  "cves": [
    "CVE-2026-16581"
  ],
  "slug": "icsa-26-209-06",
  "title": "igloohome Smart Lock Mobile Application",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services. The following versions of igloohome Smart Lock Mobile Application are affected: Smart Lock Mobile Application (Android) 3.2.3 (CVE-2026-16581) CVSS Vendor Equipment Vulnerabilities v3 5.3 igloohome igloohome Smart Lock Mobile Application Inclusion of Sensitive Information in Source Code Background Critical Infrastructure Sectors: Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: Singapore Vulnerabilities Expand All + CVE-2026-16581 In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or b",
  "cve_count": 1,
  "categories": [],
  "word_count": 536,
  "mentions_ics": true,
  "published_at": "2026-07-28T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-06.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-16581",
    "https://cwe.mitre.org/data/definitions/540.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
    "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
  ],
  "mentions_ransomware": false
}
08ABB KNX Update ToolView CSAF Summary ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its prod{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-07","cves":[…
EVENT. cms4sksfID. cms4sksfka7ebkh0c0mql2rd6SRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-07",
  "cves": [
    "CVE-2026-12705"
  ],
  "slug": "icsa-26-209-07",
  "title": "ABB KNX Update Tool",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The vulnerability report has been shared in responsible disclosure. An attacker who successfully exploited this vulnerability could cause the product to become unusable. ABB confirms the vulnerability but at the same time acknowledges that the issue affects exclusively classic KNX devices that are not supporting the latest KNX Secure standard. Due to a lack of security in legacy KNX devices, the issue cannot be resolved via a software change. In order to actively exploit this vulnerability, an attacker requires physical access to the bus, the affected device is connected to. ABB has no p",
  "cve_count": 1,
  "categories": [],
  "word_count": 1264,
  "mentions_ics": true,
  "published_at": "2026-07-28T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-07.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-12705",
    "https://cwe.mitre.org/data/definitions/353.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H/E:F/RL:U/RC:C"
  ],
  "mentions_ransomware": false
}
09Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFPView CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS varia{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-04","cves":[…
EVENT. cms4skrvID. cms4skrvfa7e9kh0chm1kfbisSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-04",
  "cves": [
    "CVE-2021-41617",
    "CVE-2023-28531",
    "CVE-2023-51384",
    "CVE-2023-52927",
    "CVE-2024-26783",
    "CVE-2024-27056",
    "CVE-2024-28956",
    "CVE-2024-36903",
    "CVE-2024-36927",
    "CVE-2024-42079",
    "CVE-2024-46786",
    "CVE-2024-47736",
    "CVE-2024-47809",
    "CVE-2024-49968",
    "CVE-2024-49994",
    "CVE-2024-49998",
    "CVE-2024-50014",
    "CVE-2024-50063",
    "CVE-2024-50164",
    "CVE-2024-50298",
    "CVE-2024-53124",
    "CVE-2024-53170",
    "CVE-2024-54458",
    "CVE-2024-56631",
    "CVE-2024-56703",
    "CVE-2024-56719",
    "CVE-2024-57917",
    "CVE-2024-57924",
    "CVE-2024-57973",
    "CVE-2024-57977",
    "CVE-2024-57979",
    "CVE-2024-58011",
    "CVE-2024-58016",
    "CVE-2024-58020",
    "CVE-2024-58056",
    "CVE-2024-58058",
    "CVE-2024-58061",
    "CVE-2024-58086",
    "CVE-2025-21645",
    "CVE-2025-21648",
    "CVE-2025-21655",
    "CVE-2025-21676",
    "CVE-2025-21682",
    "CVE-2025-21702",
    "CVE-2025-21705",
    "CVE-2025-21706",
    "CVE-2025-21707",
    "CVE-2025-21718",
    "CVE-2025-21731",
    "CVE-2025-21745",
    "CVE-2025-21758",
    "CVE-2025-21760",
    "CVE-2025-21764",
    "CVE-2025-21765",
    "CVE-2025-21780",
    "CVE-2025-21795",
    "CVE-2025-21796",
    "CVE-2025-21802",
    "CVE-2025-21814",
    "CVE-2025-21846",
    "CVE-2025-21853",
    "CVE-2025-21861",
    "CVE-2025-21864",
    "CVE-2025-21867",
    "CVE-2025-21875",
    "CVE-2025-21887",
    "CVE-2025-21913",
    "CVE-2025-21919",
    "CVE-2025-21925",
    "CVE-2025-21926",
    "CVE-2025-21938",
    "CVE-2025-21959",
    "CVE-2025-21999",
    "CVE-2025-22005",
    "CVE-2025-22015",
    "CVE-2025-22055",
    "CVE-2025-22056",
    "CVE-2025-22060",
    "CVE-2025-22083",
    "CVE-2025-22090",
    "CVE-2025-22095",
    "CVE-2025-22107",
    "CVE-2025-22111",
    "CVE-2025-22121",
    "CVE-2025-23136",
    "CVE-2025-23143",
    "CVE-2025-37785",
    "CVE-2025-37909",
    "CVE-2025-37917",
    "CVE-2025-37945",
    "CVE-2025-37959",
    "CVE-2025-37964",
    "CVE-2025-37972",
    "CVE-2025-37980",
    "CVE-2025-38125",
    "CVE-2025-38162",
    "CVE-2025-38192",
    "CVE-2025-38201",
    "CVE-2025-38232",
    "CVE-2025-38322",
    "CVE-2025-38591",
    "CVE-2025-38614",
    "CVE-2025-38681",
    "CVE-2025-38704",
    "CVE-2025-38721",
    "CVE-2025-38725",
    "CVE-2025-38727",
    "CVE-2025-38732",
    "CVE-2025-38736",
    "CVE-2025-39681",
    "CVE-2025-39691",
    "CVE-2025-39721",
    "CVE-2025-39748",
    "CVE-2025-39756",
    "CVE-2025-39764",
    "CVE-2025-39770",
    "CVE-2025-39773",
    "CVE-2025-39782",
    "CVE-2025-39795",
    "CVE-2025-39826",
    "CVE-2025-39827",
    "CVE-2025-39845",
    "CVE-2025-39866",
    "CVE-2025-39871",
    "CVE-2025-39931",
    "CVE-2025-39953",
    "CVE-2025-39955",
    "CVE-2025-39964",
    "CVE-2025-39977",
    "CVE-2025-39978",
    "CVE-2025-39980",
    "CVE-2025-40022",
    "CVE-2025-40070",
    "CVE-2025-40078",
    "CVE-2025-40080",
    "CVE-2025-40105",
    "CVE-2025-40135",
    "CVE-2025-40149",
    "CVE-2025-40219",
    "CVE-2025-40261",
    "CVE-2025-40300",
    "CVE-2025-61984",
    "CVE-2025-61985",
    "CVE-2025-68206",
    "CVE-2025-68261",
    "CVE-2025-68264",
    "CVE-2025-68265",
    "CVE-2025-68266",
    "CVE-2025-68291",
    "CVE-2025-68337",
    "CVE-2025-68349",
    "CVE-2025-68363",
    "CVE-2025-68371",
    "CVE-2025-68724",
    "CVE-2025-68725",
    "CVE-2025-68742",
    "CVE-2025-68764",
    "CVE-2025-68773",
    "CVE-2025-68776",
    "CVE-2025-68782",
    "CVE-2025-68787",
    "CVE-2025-68788",
    "CVE-2025-68798",
    "CVE-2025-68803",
    "CVE-2025-68814",
    "CVE-2025-68816",
    "CVE-2025-68818",
    "CVE-2025-68820",
    "CVE-2025-71064",
    "CVE-2025-71075",
    "CVE-2025-71079",
    "CVE-2025-71085",
    "CVE-2025-71086",
    "CVE-2025-71088",
    "CVE-2025-71095",
    "CVE-2025-71097",
    "CVE-2025-71098",
    "CVE-2025-71104",
    "CVE-2025-71112",
    "CVE-2025-71113",
    "CVE-2025-71114",
    "CVE-2025-71120",
    "CVE-2025-71123",
    "CVE-2025-71131",
    "CVE-2025-71161",
    "CVE-2025-71162",
    "CVE-2025-71163",
    "CVE-2025-71185",
    "CVE-2025-71186",
    "CVE-2025-71189",
    "CVE-2025-71190",
    "CVE-2025-71191",
    "CVE-2025-71197",
    "CVE-2025-71221",
    "CVE-2025-71265",
    "CVE-2025-71266",
    "CVE-2025-71267",
    "CVE-2026-3497",
    "CVE-2026-22977",
    "CVE-2026-22979",
    "CVE-2026-22980",
    "CVE-2026-22982",
    "CVE-2026-22992",
    "CVE-2026-22994",
    "CVE-2026-23003",
    "CVE-2026-23005",
    "CVE-2026-23010",
    "CVE-2026-23011",
    "CVE-2026-23019",
    "CVE-2026-23026",
    "CVE-2026-23038",
    "CVE-2026-23054",
    "CVE-2026-23060",
    "CVE-2026-23083",
    "CVE-2026-23084",
    "CVE-2026-23086",
    "CVE-2026-23087",
    "CVE-2026-23095",
    "CVE-2026-23100",
    "CVE-2026-23103",
    "CVE-2026-23110",
    "CVE-2026-23111",
    "CVE-2026-23113",
    "CVE-2026-23154",
    "CVE-2026-23204",
    "CVE-2026-23231",
    "CVE-2026-23242",
    "CVE-2026-23243",
    "CVE-2026-23245",
    "CVE-2026-23270",
    "CVE-2026-23271",
    "CVE-2026-23273",
    "CVE-2026-23274",
    "CVE-2026-23277",
    "CVE-2026-23284",
    "CVE-2026-23287",
    "CVE-2026-23290",
    "CVE-2026-23293",
    "CVE-2026-23300",
    "CVE-2026-23304",
    "CVE-2026-23319",
    "CVE-2026-23321",
    "CVE-2026-23335",
    "CVE-2026-23340",
    "CVE-2026-23343",
    "CVE-2026-23351",
    "CVE-2026-23359",
    "CVE-2026-23365",
    "CVE-2026-23368",
    "CVE-2026-23370",
    "CVE-2026-23378",
    "CVE-2026-23379",
    "CVE-2026-23381",
    "CVE-2026-23391",
    "CVE-2026-23392",
    "CVE-2026-23397",
    "CVE-2026-23398",
    "CVE-2026-23414",
    "CVE-2026-23422",
    "CVE-2026-23434",
    "CVE-2026-23438",
    "CVE-2026-23439",
    "CVE-2026-23446",
    "CVE-2026-23449",
    "CVE-2026-23450",
    "CVE-2026-23452",
    "CVE-2026-23454",
    "CVE-2026-23455",
    "CVE-2026-23456",
    "CVE-2026-23457",
    "CVE-2026-23458",
    "CVE-2026-23463",
    "CVE-2026-23474",
    "CVE-2026-23475",
    "CVE-2026-27135",
    "CVE-2026-31389",
    "CVE-2026-31391",
    "CVE-2026-31396",
    "CVE-2026-31402",
    "CVE-2026-31403",
    "CVE-2026-31411",
    "CVE-2026-31414",
    "CVE-2026-31415",
    "CVE-2026-31416",
    "CVE-2026-31417",
    "CVE-2026-31418",
    "CVE-2026-31421",
    "CVE-2026-31422",
    "CVE-2026-31423",
    "CVE-2026-31424",
    "CVE-2026-31427",
    "CVE-2026-31428",
    "CVE-2026-31431",
    "CVE-2026-31441",
    "CVE-2026-31446",
    "CVE-2026-31447",
    "CVE-2026-31448",
    "CVE-2026-31450",
    "CVE-2026-31452",
    "CVE-2026-31466",
    "CVE-2026-31469",
    "CVE-2026-31485",
    "CVE-2026-31494",
    "CVE-2026-31495",
    "CVE-2026-31496",
    "CVE-2026-31503",
    "CVE-2026-31504",
    "CVE-2026-31507",
    "CVE-2026-31508",
    "CVE-2026-31515",
    "CVE-2026-31518",
    "CVE-2026-31521",
    "CVE-2026-31533",
    "CVE-2026-31546",
    "CVE-2026-31555",
    "CVE-2026-31563",
    "CVE-2026-31565",
    "CVE-2026-31628",
    "CVE-2026-31634",
    "CVE-2026-31649",
    "CVE-2026-31651",
    "CVE-2026-31658",
    "CVE-2026-31664",
    "CVE-2026-31665",
    "CVE-2026-31669",
    "CVE-2026-31670",
    "CVE-2026-31671",
    "CVE-2026-31674",
    "CVE-2026-31680",
    "CVE-2026-31682",
    "CVE-2026-31737",
    "CVE-2026-31752",
    "CVE-2026-31761",
    "CVE-2026-31768",
    "CVE-2026-40355",
    "CVE-2026-41989",
    "CVE-2026-43011",
    "CVE-2026-43024",
    "CVE-2026-43025",
    "CVE-2026-43026",
    "CVE-2026-43027",
    "CVE-2026-43028",
    "CVE-2026-43030",
    "CVE-2026-43033",
    "CVE-2026-43035",
    "CVE-2026-43038",
    "CVE-2026-43040",
    "CVE-2026-43057",
    "CVE-2026-43284",
    "CVE-2026-46174",
    "CVE-2026-46300",
    "CVE-2026-46333",
    "CVE-2025-38617"
  ],
  "slug": "icsa-26-209-04",
  "title": "Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP are affected: SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) vers:intdot/>=3.1.6 (CVE-2021-41617, CVE-2023-28531, CVE-2023-51384, CVE-2023-52927, CVE-2024-26783, CVE-2024-27056, CVE-2024-28956, CVE-2024-36903, CVE-2024-36927, CVE-2024-42079, CVE-2024-46786, CVE-2024-47736, CVE-2024-47809, CVE-2024-49968, CVE-2024-49994, CVE-2024-49998, CVE-2024-50014, CVE-2024-50063, CVE-202",
  "cve_count": 353,
  "categories": [],
  "word_count": 101659,
  "mentions_ics": true,
  "published_at": "2026-07-28T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-04.json",
    "https://www.cve.org/CVERecord?id=CVE-2021-41617",
    "https://cwe.mitre.org/data/definitions/311.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "https://www.cve.org/CVERecord?id=CVE-2023-28531"
  ],
  "mentions_ransomware": false
}
10Siemens Desigo CCView CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Sie{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-01","cves":[…
EVENT. cms4skrbID. cms4skrboa7e7kh0cj5m4wz2wSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-01",
  "cves": [
    "CVE-2025-15467"
  ],
  "slug": "icsa-26-209-01",
  "title": "Siemens Desigo CC",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available. The following versions of Siemens Desigo CC are affected: Desigo CC family V7 vers:all/* (CVE-2025-15467) Desigo CC family V8 vers:all/* (CVE-2025-15467) Desigo CC family V9 vers:intdot/<9.0.1 (CVE-2025-15467) CVSS Vendor Equipment Vulnerabilities v3 9.8 Siemens Siemens Desigo CC Out-of-bounds Write Background Critical Infrastructure Sectors: Critical Manu",
  "cve_count": 1,
  "categories": [],
  "word_count": 983,
  "mentions_ics": true,
  "published_at": "2026-07-28T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-01.json",
    "https://www.cve.org/CVERecord?id=CVE-2025-15467",
    "https://support.industry.siemens.com/cs/ww/en/view/110002555/",
    "https://cwe.mitre.org/data/definitions/787.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
  ],
  "mentions_ransomware": false
}
showing 1–10 of 167older →
§03

subscribe

three pathways carry every event on this topic. pick the one that fits your agent.

GETrss feed
any reader · no auth
https://api.callsign.sh/v1/public/channels/security/topics/cisa-advisories/feed.xml
GETjson pull
poll on your schedule · optional since/until
https://api.callsign.sh/v1/public/channels/security/topics/cisa-advisories.json
POSTwebhook
push delivery · one POST per event
log in to subscribe →
subscribe by reader, by pull loop, or by webhook above