Skip to content
Threat Feed

Tag

Critical-Infrastructure

18 briefs RSS
medium advisory

Insufficiently Protected Credentials Vulnerability in Schneider Electric SCADAPack x70

Schneider Electric SCADAPack x70 series RTUs contain a vulnerability (CVE-2026-81861) in the legacy 'Secure Lock' functionality that could lead to unauthorized exposure of authentication information.

SCADAPack 47x +6 vulnerability industrial-control-systems critical-infrastructure
1t 1c
critical advisory

Critical Vulnerabilities in Digital Watchdog VMAX DVR and NVR Products

Multiple high-severity vulnerabilities in Digital Watchdog VMAX series devices allow unauthenticated remote attackers to bypass authentication, gain root access via hard-coded credentials, and execute arbitrary system commands.

VMAX A1 G4 DVRs +4 critical-infrastructure ics authentication-bypass remote-code-execution
2t
high advisory

Multiple Vulnerabilities in AVEVA Pipeline Integrity Monitor

AVEVA Pipeline Integrity Monitor versions through 2025_SP1_P1_build_7.1.9580.8513 contain multiple vulnerabilities including hard-coded keys and improper authorization, facilitating information disclosure, credential brute-forcing, and XSS-based code execution.

Pipeline Integrity Monitor industrial-control-systems vulnerability critical-infrastructure
4c
critical advisory

Critical Authentication Bypass in Tenda AC18 Telnet Handler

A critical authentication bypass vulnerability in the Tenda AC18 router allows remote, unauthenticated attackers to gain unauthorized access via the Telnet service.

AC18 critical-infrastructure network-security authentication-bypass
1t 1c
medium advisory

Denial of Service Vulnerability in Mitsubishi Electric CNC Series

An out-of-bounds read vulnerability (CVE-2025-2399) in Mitsubishi Electric CNC Series controllers allows remote attackers to trigger a denial-of-service condition via crafted packets sent to TCP port 683.

M800VW +17 ics dos industrial-control-systems critical-infrastructure cve-2025-2399
critical threat

Active Exploitation of Siemens S7 Series PLCs in US Critical Infrastructure

The IC3 has issued an advisory regarding the active exploitation of Siemens S7 Series PLCs within US critical infrastructure sectors using CVE-2026-4357 to disrupt operational technology.

exploited S7 Series PLC critical-infrastructure ot-security vulnerability-management
1t
high threat

Medusa Ransomware Operations and Tactics

Medusa ransomware affiliates target critical infrastructure and healthcare entities using rapid exploitation of newly disclosed vulnerabilities and abuse of legitimate RMM software for persistence and exfiltration.

Medusa ransomware initial-access exfiltration rmm critical-infrastructure healthcare
3t
critical advisory

Critical OS Command Injection in Haiwell IoT Cloud HMI Gateway

An unauthenticated OS command injection vulnerability in the Haiwell IoT Cloud HMI Gateway allows attackers to achieve arbitrary command execution with root privileges via the Net Check feature.

Haiwell IoT Cloud HMI Gateway ics rce cve-2026-19188 critical-infrastructure
1r 2t
high threat

Gunra Ransomware Gang Exploitation of Fortinet Appliances

The Gunra ransomware-as-a-service group is leveraging critical Fortinet vulnerabilities (CVE-2024-55591 and CVE-2025-24472) to gain initial access, hijack VDI sessions, and bypass multi-factor authentication in attacks against critical infrastructure.

FortiOS +1 Gunra ransomware fortinet vpn critical-infrastructure authentication-bypass
4t 2c
critical advisory

Authentication Bypass in AMMOS Instrument Toolkit GUI

The AMMOS Instrument Toolkit (AIT) GUI before version 2.5.1 allows unauthenticated attackers to bypass credential checks to establish sessions and issue arbitrary spacecraft commands.

AMMOS Instrument Toolkit authentication-bypass cve-2026-60112 critical-infrastructure
1t 1c
medium advisory

Critical Unauthenticated Remote Access Vulnerability in Rockwell Automation 1715-AENTR EtherNet/IP Adapter (CVE-2026-10577)

A critical unauthenticated remote access vulnerability, CVE-2026-10577, in Rockwell Automation 1715-AENTR EtherNet/IP Adapter versions <=3.003 allows an attacker to exploit a network-accessible debug port with missing privilege controls, enabling remote command-line interface access to read/delete files, modify memory, and change I/O states, impacting the confidentiality, integrity, and availability of industrial control systems.

1715-AENTR EtherNet/IP Adapter <=3.003 ics ot vulnerability critical-infrastructure remote-code-execution
1t 1c
high threat

NCSC Warns of State-Sponsored Espionage via IP Cameras Targeting Critical Infrastructure

Russian state-sponsored actors, along with hacktivist groups and cybercriminals, are exploiting IP cameras to spy on critical infrastructure in NATO countries, including the Netherlands, prompting NCSC to advise organizations and home users to secure their devices through updates, network segmentation, and attack surface reduction.

Russian state-sponsored actors ip-camera espionage critical-infrastructure state-sponsored advisory network-segmentation security-best-practices
2t
high threat

Multiple Vulnerabilities in Schneider Electric PowerChute Serial Shutdown

Multiple vulnerabilities, including CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400, and CVE-2026-2401, in Schneider Electric PowerChute Serial Shutdown versions 1.4 and prior could allow attackers with adjacent network access and high privileges to overwrite critical system files via path traversal, forge or inject malicious log data, gain unauthorized account access through excessive authentication attempts, trigger denial-of-service conditions, or expose sensitive information.

exploited PowerChute Serial Shutdown ics ot vulnerability path-traversal crlf-injection dos log-tampering critical-infrastructure
5t 5c
high advisory

CVE-2026-8377: Missing Authorization in Armiya GKS Allows Data Collection

A critical Missing Authorization vulnerability (CVE-2026-8377) in Armiya Information Technologies Ltd. Co.'s Access Control System (GKS) before Version 2 allows an unauthenticated or unauthorized attacker to collect sensitive data from common resource locations, leading to unauthorized information disclosure.

Access Control System vulnerability access-control-system missing-authorization data-collection critical-infrastructure
2t 1c
critical threat

FortiBleed Campaign: 73,932 FortiGate Systems Credentials Exposed

A Russian-speaking threat group utilized a large dataset of administrative and VPN credentials, likely sourced from exposed FortiGate configuration files and active credential harvesting, to access government, critical infrastructure, and multinational corporate networks, resulting in widespread data exfiltration.

FortiGate +1 Russian-speaking threat group credential-theft fortios state-sponsored espionage data-exfiltration russian-speaking critical-infrastructure government
3r 9t 1i
medium advisory

Hitachi Energy GMS600 Vulnerable to Bleichenbacher Attack via CVE-2022-4304

Hitachi Energy GMS600 versions 1.3.0 and 1.3.1 are affected by CVE-2022-4304, a vulnerability in the OpenSSL RSA Decryption implementation; an attacker could exploit this timing-based side channel to recover plaintext across a network in a Bleichenbacher-style attack by sending trial messages to the server and recording processing times, eventually decrypting application data.

GMS600 versions 1.3.0 and 1.3.1 bleichenbacher timing attack openssl critical infrastructure
2r 1t 1c
medium advisory

Siemens SIPROTEC 5 Insufficient Session ID Randomness Leads to Session Hijacking (CVE-2024-54017)

Siemens SIPROTEC 5 devices are vulnerable to session hijacking (CVE-2024-54017) due to the use of insufficiently random numbers in session identifier generation, potentially allowing an unauthenticated remote attacker to brute-force a valid session and gain unauthorized read access.

SIPROTEC 5 6MD84 +62 ics session hijacking cve-2024-54017 siemens critical infrastructure
2r 1t 1c
critical advisory

ABB Edgenius Management Portal Authentication Bypass Vulnerability

An authentication bypass vulnerability in ABB Edgenius Management Portal versions 3.2.0.0 and 3.2.1.1 allows attackers to execute arbitrary code and modify application configurations by sending a specially crafted message to the system node.

Edgenius Management Portal 3.2.0.0 +2 abb edgenius authentication bypass CVE-2025-10571 critical infrastructure
2r 1t 1c