Tag
critical
threat
Active Exploitation of Siemens S7 Series PLCs in US Critical Infrastructure
1 TTPThe IC3 has issued an advisory regarding the active exploitation of Siemens S7 Series PLCs within US critical infrastructure sectors using CVE-2026-4357 to disrupt operational technology.
exploited
S7 Series PLC
critical-infrastructure
ot-security
vulnerability-management
1t
critical
advisory
Unauthenticated Remote Access to Phoenix Contact CHARX SEC MQTT Broker
2 rules 5 TTPs 12 CVEsA critical vulnerability (CVE-2026-44090) in Phoenix Contact CHARX SEC controllers allows unauthenticated remote attackers to gain full device control by bypassing authentication on the MQTT broker.
CHARX SEC-3150 +7
industrial-control-systems
mqtt
cve-2026-44091
ics
cve
injection
authentication-bypass
cve-2026-44100
+14
2r
5t
12c
critical
threat
Three Chained Zero-Days in Siemens ROX II OT Switches Lead to Root Access
3 rules 4 TTPs 5 CVEsUnit 42 and Siemens collaborated to disclose three critical chained zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, CVE-2025-40949) in Siemens ROX II operational technology switches, allowing an attacker to achieve arbitrary file disclosure, privilege escalation to root, and persistent root-level code execution.
exploited
PoC
ROX II OT switches +2
industrial-control-systems
ot-security
zero-day
privilege-escalation
command-injection
persistence
siemens
vulnerability-exploit
3r
4t
5c
updated