Skip to content
Threat Feed

Tag

Industrial-Control-Systems

31 briefs RSS
medium advisory

Remote Denial of Service Vulnerability in Moxa TN-4500B Series

A critical out-of-bounds write vulnerability (CVE-2026-15579) in Moxa TN-4500B Series switches allows remote, unauthenticated attackers to cause a denial-of-service condition.

TN-4500B Series vulnerability industrial-control-systems denial-of-service network-device
1t 1c
high advisory

Stack-based Buffer Overflow in PLANET IGS-5225-8P2T4S Managed Switches

A stack-based buffer overflow vulnerability in the web server of PLANET IGS-5225-8P2T4S industrial managed switches allows authenticated remote attackers to achieve denial of service or remote code execution via CVE-2026-81944.

IGS-5225-8P2T4S vulnerability industrial-control-systems network-security cve-2026-81944
1t 1c
high advisory

Authentication Bypass Vulnerability in Mitsubishi Electric GX Works3

An incorrect implementation of the authentication algorithm (CVE-2026-15688) in Mitsubishi Electric GX Works3 and Motion Control Settings allows local attackers to bypass block password protections and manipulate control programs.

GX Works3 +1 industrial-control-systems cve authentication-bypass
1t 1c
medium advisory

Insufficiently Protected Credentials Vulnerability in Schneider Electric SCADAPack x70

Schneider Electric SCADAPack x70 series RTUs contain a vulnerability (CVE-2026-81861) in the legacy 'Secure Lock' functionality that could lead to unauthorized exposure of authentication information.

SCADAPack 47x +6 vulnerability industrial-control-systems critical-infrastructure
1t 1c
medium threat

NULL Pointer Dereference Vulnerability in S2OPC

CVE-2026-90782 is a NULL pointer dereference vulnerability in S2OPC 1.7.3 and earlier, allowing an attacker to trigger a denial-of-service crash via manipulated allocation sequences.

exploited S2OPC industrial-control-systems denial-of-service vulnerability
1t 1c
high advisory

Multiple Vulnerabilities in AVEVA Pipeline Integrity Monitor

AVEVA Pipeline Integrity Monitor versions through 2025_SP1_P1_build_7.1.9580.8513 contain multiple vulnerabilities including hard-coded keys and improper authorization, facilitating information disclosure, credential brute-forcing, and XSS-based code execution.

Pipeline Integrity Monitor industrial-control-systems vulnerability critical-infrastructure
4c
high advisory

Privilege Escalation Vulnerability in Rockwell Automation FactoryTalk Activation Manager

Rockwell Automation FactoryTalk Activation Manager versions V5.02 and below are vulnerable to local privilege escalation via insecure installer custom actions that spawn SYSTEM-level console windows.

FactoryTalk Activation Manager privilege-escalation industrial-control-systems windows ics
1r 1t 1c
high advisory

DLL Hijacking Vulnerabilities in Rockwell Automation Redundancy Module Configuration Tool

Rockwell Automation Redundancy Module Configuration Tool versions 9.x and 10.00.00 are vulnerable to DLL hijacking, potentially allowing local privilege escalation to SYSTEM level.

Redundancy Module Configuration Tool +1 privilege-escalation dll-hijacking industrial-control-systems windows
1r 1t 2c
high threat

Denial-of-Service Vulnerability in Rockwell Automation Logix Platforms

Rockwell Automation Logix controllers are vulnerable to a denial-of-service condition due to improper input length validation during CIP message processing, leading to major nonrecoverable faults.

exploited ControlLogix 5580 +3 industrial-control-systems denial-of-service cve-2026-9637 ot-security
1c
critical advisory

Hard-coded Credentials in Talassoft Industrial Management Software

Talassoft Industrial Management Software versions 4 through 16 contain a hard-coded credentials vulnerability, enabling unauthorized attackers to retrieve sensitive embedded data.

Talassoft Industrial Management Software vulnerability industrial-control-systems
1c
critical advisory

Code Injection Vulnerability in Klemsan KIO

Klemsan KIO versions prior to 1.9 contain a code injection vulnerability allowing unauthenticated attackers to execute arbitrary code due to improper input validation during code generation.

KIO vulnerability code-injection industrial-control-systems
2t 1c
medium advisory

Denial of Service Vulnerability in Mitsubishi Electric CNC Series

An out-of-bounds read vulnerability (CVE-2025-2399) in Mitsubishi Electric CNC Series controllers allows remote attackers to trigger a denial-of-service condition via crafted packets sent to TCP port 683.

M800VW +17 ics dos industrial-control-systems critical-infrastructure cve-2025-2399
low advisory

Denial of Service Vulnerability in Mitsubishi Electric FA Products

A vulnerability in the Ethernet function of multiple Mitsubishi Electric factory automation products allows remote attackers to trigger a denial-of-service condition via specially crafted UDP packets.

CC-Link IE TSN Remote I/O module +11 industrial-control-systems denial-of-service cve-2025-3511
1t 1c
medium advisory

Multiple Vulnerabilities in Cisco Industrial Ethernet 1000 Series Switches

Cisco Industrial Ethernet 1000 Series Switches contain multiple vulnerabilities, including CVE-2024-20412, CVE-2024-20413, and CVE-2024-20414, which allow unauthenticated attackers to cause a denial-of-service or perform cross-site scripting attacks.

Industrial Ethernet 1000 Series Switches vulnerability industrial-control-systems network-security
1t 3c
critical advisory

Insufficient Session Expiration in Frauscher Sensortechnik FDS 102

CVE-2026-14950 is an insufficient session expiration vulnerability in Frauscher Sensortechnik FDS 102 that allows an attacker with a valid session identifier to maintain access beyond the intended expiration time.

FDS 102 +3 cve vulnerability rce industrial-control-system path-traversal cve-2026-14948 session-hijacking information-disclosure +4
3r 7t 1c
high advisory

Arbitrary Code Execution in Siemens Simcenter Femap

Siemens Simcenter Femap is susceptible to arbitrary code execution via two out-of-bounds read vulnerabilities when parsing specially crafted BMP files.

Simcenter Femap +1 vulnerability industrial-control-systems ics cve-2026-59086 stack-overflow rce
2t 1c updated
high advisory

Command Injection Vulnerability in Siemens Siveillance Video

A critical OS command injection vulnerability (CVE-2026-3014) in Siemens Siveillance Video allows authenticated users with administrative permissions to achieve remote code execution in the context of the Management Server service.

Siveillance Video vulnerability cve ics industrial-control-systems
1t 1c
high threat

Stored XSS Vulnerability in Johnson Controls Metasys

A stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-34491) in Johnson Controls Metasys allows low-privileged users to execute arbitrary scripts in the context of other users' sessions, potentially leading to session hijacking.

Metasys industrial-control-systems xss web-vulnerability
1r 1t
high advisory

Out-of-Bounds Read Vulnerability in Siemens Parasolid

Siemens Parasolid contains an out-of-bounds read vulnerability (CVE-2026-64629) in its X_T file parsing logic that can lead to arbitrary code execution or application crashes.

Parasolid vulnerability industrial-control-systems ics cve-2026-64629
1t 1c
high advisory

Privilege Escalation Vulnerability in Phoenix Contact CHARX Controllers

A local OS command injection vulnerability (CVE-2026-44095) in Phoenix Contact CHARX charging controllers allows low-privileged users to execute arbitrary commands as root.

CHARX SEC-3000 +3 privilege-escalation industrial-control-systems cve command-injection
3t 1c
critical advisory

Unauthenticated Remote Access to Phoenix Contact CHARX SEC MQTT Broker

A critical vulnerability (CVE-2026-44090) in Phoenix Contact CHARX SEC controllers allows unauthenticated remote attackers to gain full device control by bypassing authentication on the MQTT broker.

CHARX SEC-3150 +7 industrial-control-systems mqtt cve-2026-44091 ics cve injection authentication-bypass cve-2026-44100 +14
2r 5t 12c
medium advisory

CVE-2026-14169: Ads-tec DVG-IRF Series Vulnerability Allows Remote Admin Lockout

A low-privileged remote attacker can exploit an incorrect behavior order vulnerability (CVE-2026-14169, CWE-696) in multiple ads-tec Industrial IT DVG-IRF series devices (versions prior to 2.3.0) by sending crafted input, leading to inconsistent account states and password overwrites, resulting in complete administrative unavailability of the device.

DVG-IRF1401 +5 vulnerability denial-of-service industrial-control-systems network-device
1t 1c
critical advisory

OpenPLC_v3 Heap-Based Buffer Overflow (CVE-2026-11826)

An authenticated attacker can exploit CVE-2026-11826, a heap-based buffer overflow in OpenPLC_v3's web interface, by sending a crafted HTTP POST request to the /modbus endpoint with an oversized device_name value, causing heap corruption, a runtime crash, and denial of service of the PLC process control loop, with no expected patch.

OpenPLC_v3 ics ot buffer-overflow denial-of-service cve industrial-control-systems
1r 2t 1c
critical threat

Three Chained Zero-Days in Siemens ROX II OT Switches Lead to Root Access

Unit 42 and Siemens collaborated to disclose three critical chained zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, CVE-2025-40949) in Siemens ROX II operational technology switches, allowing an attacker to achieve arbitrary file disclosure, privilege escalation to root, and persistent root-level code execution.

exploited PoC ROX II OT switches +2 industrial-control-systems ot-security zero-day privilege-escalation command-injection persistence siemens vulnerability-exploit
3r 4t 5c updated
medium advisory

Rockwell Automation Communication Modules Denial-of-Service Vulnerability

A denial-of-service vulnerability (CVE-2026-9653) in Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT communication modules, due to improper validation of CIP Implicit Connection packets, allows an unauthenticated network attacker to continuously disrupt device connections.

1756-EN2 <=V12.001 +2 industrial-control-systems ics ot vulnerability denial-of-service rockwell-automation
1t 1c
high advisory

Multiple Vulnerabilities in AutomationDirect Productivity Suite Could Lead to Privilege Escalation and DoS

Multiple vulnerabilities, including out-of-bounds write, out-of-bounds read, and divide-by-zero, exist in AutomationDirect Productivity Suite versions up to and including v4.6.2.2, allowing an attacker with local or physical access to exploit these flaws via crafted IOCTL requests, potentially leading to kernel memory corruption, privilege escalation, information disclosure, application instability, or a denial-of-service condition.

Productivity Suite ICS SCADA industrial-control-systems out-of-bounds-write out-of-bounds-read privilege-escalation denial-of-service vulnerability
2t
critical advisory

Multiple Critical and High-Severity Vulnerabilities in ABB T-MAC Plus

CISA has issued an advisory regarding critical and high-severity vulnerabilities CVE-2025-14771, CVE-2025-14772, CVE-2025-14773, and CVE-2025-14774 in ABB T-MAC Plus version 4.0-24, which could allow authenticated attackers to exfiltrate sensitive files, bypass authorization for administrative operations, execute arbitrary client-side code via cross-site scripting, or for unauthenticated attackers to cause a denial-of-service condition.

ABB T-MAC Plus 4.0-24 industrial-control-systems scada critical-manufacturing vulnerability web-application
4t 4c
medium advisory

Siemens Security Advisory Addressing Multiple Product Vulnerabilities

Siemens released a security advisory on May 12, 2026, addressing vulnerabilities in a range of products including RUGGEDCOM, SCALANCE, Solid Edge, and SIMATIC, prompting users to apply necessary updates.

RUGGEDCOM ROX II family +20 siemens security-advisory industrial-control-systems
2r
medium advisory

ABB B&R PVI Sensitive Information Logging Vulnerability

An authenticated local attacker can gather credential information from ABB B&R PVI client application logs when logging is enabled, addressed in version 6.5.0 (CVE-2026-0936).

ABB B&R PVI ics industrial control systems credential access logging
2r 1c
critical advisory

Qualcomm PLC FW Buffer Overflow via Incorrect Authorization (CVE-2026-25293)

CVE-2026-25293 is a critical buffer overflow vulnerability in Qualcomm PLC FW due to incorrect authorization, potentially allowing unauthorized access and control over programmable logic controllers.

PLC FW plc buffer-overflow industrial-control-systems cve-2026-25293
2r 2t 1c
high advisory

Moxa Security Advisory Addresses Vulnerabilities in Multiple Router Series

Moxa released a security advisory addressing CVE-2026-3867 and CVE-2026-3868, which affect TN-4900, EDR-8010, EDR-G9010, OnCell G4302-LTE4, OnCell G4308-LTE4, and EDF-G1002-BP series routers, potentially allowing for unauthorized access and control.

TN-4900 Series +5 vulnerability router industrial-control-systems
3r 2c