Apply the security updates released by Zimbra to address CVE-2026-73570 immediately. Restrict or disable the SNMP interface on Zimbra servers if patching is not immediately possible. Monitor for unusual SNMP traffic and audit system logs for signs of exploitation.
Organizations should prioritize patching CVE-2025-39682 by applying vendor-provided security updates as soon as they are available. Under BOD 26-04, FCEB agencies must remediate the vulnerability rapidly and check for signs of compromise before patching. All organizations are encouraged to adopt risk-based vulnerability management and monitor CISA advisories for updates.
CISA recommends minimizing network exposure for all control system devices, ensuring they are not accessible from the internet, and locating control system networks and remote devices behind firewalls isolated from business networks. When remote access is required, use VPNs updated to the most current version. Organizations should perform proper impact analysis and risk assessment prior to deploying defensive measures. Users are advised to contact Meari for support as no official fix is planned.
CISA recommends minimizing network exposure for all control system devices, ensuring they are not accessible from the internet, and locating control system networks and remote devices behind firewalls isolated from business networks. When remote access is required, use VPNs updated to the most current version. Organizations should perform proper impact analysis and risk assessment prior to deploying defensive measures. Users are advised to contact Meari for support as no official fix is planned.
Apply the latest cPanel & WHM updates immediately. cPanel has released patches for all supported versions. Review system logs for any unauthorized activity following update deployment.
Affected users should update their CISA Malcolm instance to version 26.06.0 or later. The September 2026 release or subsequent versions contain the necessary fixes. No temporary workarounds are documented in the advisory.
Configure ABBPCMSchedulerService to run under the same Windows account used for PCM600 operation. Ensure the account has the "Log on as a service" privilege. Use the Scheduler tool with the configured account when IED authentication is enabled. Enable "Always trust IED security certificates" only in secure and trusted environments. Refer to ABB security advisories 2NGA003170 and 2NGA003179.
Affected users should update their CISA Malcolm instance to version 26.06.0 or later. The September 2026 release or subsequent versions contain the necessary fixes. No temporary workarounds are documented in the advisory.
Configure ABBPCMSchedulerService to run under the same Windows account used for PCM600 operation. Ensure the account has the "Log on as a service" privilege. Use the Scheduler tool with the configured account when IED authentication is enabled. Enable "Always trust IED security certificates" only in secure and trusted environments. Refer to ABB security advisories 2NGA003170 and 2NGA003179.
Upgrade to Johnson Controls EC firmware V3.3b64 or later and CW firmware V3.3b26 or as soon as operationally feasible after testing in non-production environments. Apply physical access controls to prevent unauthorized access to device debug ports. Monitor network traffic for unusual or unauthorized access attempts. Apply least privilege principles to all accounts and services interacting with affected devices. Where possible, apply firmware updates that disable debug interfaces or require authentication for debug access. Deploy intrusion detection/prevention systems. Follow the Johnson Controls product hardening guide and universal hardening guide.
Affected users should update their CISA Malcolm instance to version 26.06.0 or later. The September 2026 release or subsequent versions contain the necessary fixes. No temporary workarounds are documented in the advisory.
Affected users should update their CISA Malcolm instance to version 26.06.0 or later. The September 2026 release or subsequent versions contain the necessary fixes. No temporary workarounds are documented in the advisory.
Upgrade ZoneMinder to version 1.38.3 or later immediately. Download the installer from https://zoneminder.com/downloads or obtain the source code from https://github.com/ZoneMinder/zoneminder. Apply the fix from security advisory GHSA-88m4-hrgp-m9v3. Restrict user permissions to limit the number of authenticated users with View Events access. Monitor for suspicious activity in web server logs.
Update Siemens Teamcenter to the latest patched version: V2412.0013 or later, V2506.0010 or later, V2512.2607 or later, or V2606.2607 or later. Protect network access to Teamcenter devices, ensure they are not internet-facing, and use VPNs for remote access. Follow Siemens operational guidelines for industrial security.
Update Siemens Parasolid to V38.0.235 or later (V38.0 branch) or V38.1.230 or later (V38.1 branch). Minimize network exposure of Parasolid-based applications. Restrict execution of untrusted X_T files. Follow Siemens operational guidelines for industrial security. Monitor CISA and Siemens advisories for updates.
FURUNO ELECTRIC CO., LTD. notes that production of this product ended in October 2020, and software updates will no longer be provided. FURUNO recommends users do not connect the product directly to the internet. To prevent unauthorized access, the vessel on which the product is installed should be properly locked and managed. CISA recommends minimizing network exposure for all control system devices, ensuring they are not accessible from the internet, locating control system networks and remote devices behind firewalls and isolating them from business networks, and using secure methods such as VPNs when remote access is required.
Apply vendor patches immediately. For federal agencies, comply with CISA's binding operational directive. If patches are unavailable, restrict network access, enable multi-factor authentication, and monitor for suspicious activity. Consult official advisories from JFrog, ConnectWise, and MikroTik for specific patch versions.
Update Docker Desktop and Docker Sandboxes to the latest patched versions immediately. Ensure all systems running Docker Sandboxes on macOS are running the updated release. Review shared directory configurations and restrict host filesystem access where possible.
Update Siemens Solid Edge to V225.0.15 or later (SE2025) or V226.0.7 or later (SE2026). Apply patches from https://support.sw.siemens.com/product/246738425/. Restrict execution of untrusted PAR, PSM, and DFT files. Apply application whitelisting where possible.
Update to firmware version 2.4.5 released by Tycon Systems. Set an administrator username and strong password on the Network Configuration page. Avoid exposing the web interface to the Internet; keep the unit on a private network behind a firewall or VPN. Change any factory-default SNMP community strings and Telnet passwords if left at shipped values. Leave Telnet disabled unless required.
Upgrade to ASE2000 version 2.38 or later. interim measures: restrict write access to installation directories, avoid IEC 60870-5-104 over TLS on untrusted networks, and enforce host-based firewall protection.
Microsoft has indicated that no customer action is required, as the vulnerability has been addressed on the service side. Organizations should continue to monitor Microsoft's official security advisories for any updates or additional recommendations. It is also advisable to review identity and access management configurations for any unusual activity, given the active exploitation.
Upgrade firmware to version 2.6.0.7R6 released by Lantronix. Avoid using unencrypted HTTP connections for update metadata. Monitor Lantronix Vulnerability Library for additional updates. Contact Lantronix support for technical assistance if needed.
OPCFoundation recommends users update to OPC UA LDS Installers version 1.04.420 or later. See the OPCFoundation security advisory at https://github.com/OPCFoundation/OPC-SecurityAdvisories/tree/latest/csaf/2026/009 for more information.
Apply Microsoft's August 2026 security updates promptly. Prioritize patching of Windows DNS Server components, especially on internet-facing systems. Monitor Microsoft security advisories for additional details and verification of the vulnerability specifics. Implement network segmentation and access controls for DNS server roles as defense-in-depth measures while awaiting patch deployment.
Update Next.js to the latest patched version as soon as possible. If immediate patching is not feasible, restrict access to Next.js applications and disable AVIF image processing if possible. Monitor official Vercel advisories for further details.
Update Siemens LOGO! Soft Comfort to version V9 or later. Additionally, upgrade hardware to LOGO! V9 BM or later to avoid compatibility mode where vulnerabilities remain present. Restrict local access to LOGO! Soft Comfort workstations and enforce physical security measures.
Mitsubishi Electric GX Works3: version 1.096A or later. Mitsubishi Electric Motion Control Settings: version 1.070Y or later. Set security version to "2" in project settings. Restrict physical access to affected computers. Block remote logins from untrusted networks. Use firewalls or VPNs to prevent unauthorized access. Restrict physical and network access to authorized users only.
Update Siemens Solid Edge to V225.0.15 or later (SE2025) or V226.0.7 or later (SE2026). Apply patches from https://support.sw.siemens.com/product/246738425/. Restrict execution of untrusted PAR, PSM, and DFT files. Apply application whitelisting where possible.
Johnson Controls recommends upgrading C-CURE 9000 to v3.20 or later, upgrading victor Application Server to v4.20 or later, upgrading victor to v8.0 or later, and upgrading victor Web to v7.0 or later. Until upgrades are applied, implement strict firewall rules blocking unnecessary inbound connections to port 8999 from untrusted network segments, deploy IDS/IPS signatures tuned to detect .NET deserialization exploit patterns (e.g., ysoserial.net), enforce application whitelisting on application server hosts, ensure application server processes run with least privilege, enable detailed logging and monitor for anomalous process creation (e.g., SoftwareHouse.CrossFire.Server.exe), and disable unnecessary services such as the ClientConnectionManager_NF.SynchronousServerNotification callback interface if not required. See Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16 for more detailed guidance.
Apply the latest PaperCut patches for CVE-2024-27198 and CVE-2024-27199. Monitor network traffic for indicators of compromise, especially from IP 45.142.193[.]132. Review access logs for unauthorized activity. Implement network segmentation and least-privilege access.
Hitachi Energy security advisory 8DBD000229 outlines recommended immediate actions. Affected organizations should verify GWS component presence, apply the latest software update from Hitachi Energy, and restrict network access to FCP management interfaces where possible. Deployments without the GWS component are not affected. Follow vendor guidance for patch testing in non-production environments prior to deployment.
Digital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at https://digital-watchdog.com/downloads/. Until firmware is applied, network segmentation and restricting FTP access may reduce risk.
CISA encourages rapid remediation and prioritization of security updates. Federal Civilian Executive Branch agencies must follow Binding Operational Directive 26-04, which requires prioritizing patches for KEV Catalog vulnerabilities on publicly exposed assets and checking for pre-existing compromise before applying patches. Organizations should consult vendor-specific advisories for mitigation guidance for each CVE and adopt risk-based vulnerability management practices.
Update Orkes Conductor to version 3.30.2 or later immediately. Apply the security update provided by Orkes. Monitor for further advisories from Orkes and Fortinet. If immediate updating is not possible, consider network segmentation and access controls to limit exposure until patching can be completed.
Apply the security update released by SAP to address CVE-2026-58231 immediately. Prioritize patching all SAP Commerce Cloud instances, especially those exposed to the internet. Monitor for further exploitation activity and review authentication client configurations.
Update Siemens License Server (SLS) to V5.1 or later for CVE-2026-69108 and V5.3 or later for CVE-2026-69109. Minimize network exposure, segment control system networks, and use VPNs for remote access. Follow Siemens operational guidelines for industrial security.
Digital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at https://digital-watchdog.com/downloads/. Until firmware is applied, network segmentation and restricting FTP access may reduce risk.
Rockwell Automation recommends upgrading to software version V5.03. For organizations unable to upgrade immediately, follow security best practices: minimize network exposure for control system devices, ensure systems are not internet-facing, locate control system networks behind firewalls and isolate them from business networks, and use secure remote access methods such as VPNs when required. No known public exploitation has been reported to CISA at the time of the advisory.
MikroTik has released RouterOS version 7.0.4 and later which patches both CVE-2026-67279 and CVE-2026-86060. Users should update to the latest stable RouterOS version immediately. If updating is not immediately possible, MikroTik recommends disabling SSH access from the WAN interface.
Affected organizations should apply updates from the MLflow vendor to mitigate the SSRF vulnerability. CISA encourages prioritization of rapid remediation. Federal Civilian Executive Branch agencies must follow Binding Operational Directive 26-04, which requires rapid remediation of KEV Catalog vulnerabilities on publicly exposed assets and establishes expectations for checking whether threat actors compromised the system before the patch was applied. Organizations should monitor CISA advisories and MLflow vendor guidance for specific patch information and version details.
Upgrade to NetStaX v5.6.1 or later. For systems where immediate upgrade is not possible, CISA recommends: minimizing network exposure for control system devices, ensuring devices are not internet-accessible, locating control system networks behind firewalls and isolating them from business networks, and using VPNs updated to the most current version when remote access is required. Perform proper impact analysis and risk assessment prior to deploying defensive measures.
Organizations using ConnectWise ScreenConnect should apply the latest patches provided by ConnectWise immediately. Federal civilian executive branch agencies are required to patch by September 30, 2026, per CISA's binding operational directive. Additionally, organizations should monitor for any signs of compromise, review remote access logs, and consider restricting network access to ScreenConnect instances until patching is complete.
Apply patches released by Langflow and Ruby on Rails maintainers immediately. Monitor system logs for unusual Python execution or unexpected process behavior. Implement network segmentation and restrict inbound access to Langflow deployments. Update Ruby on Rails applications to the latest secure version. Review and harden credential management practices.
Users should update the Mira app to the latest version (iOS v3.5.18 / Android v4.5.18). Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required beyond applying these updates. Organizations deploying Mira devices should ensure all units are running the latest firmware and app versions and monitor for future security advisories from Quanovate Tech Inc.
Apply vendor-supplied patches to update affected Siveillance Control products to the minimum patched versions (V3.0.12.2173 or later for Pro V3.0, V4.0.9.2178 or later for Pro V4.0, V3.0.22.2177 or later for V3.0, V4.0.11.2177 or later for V4.0). Minimize network exposure by isolating OIS web module devices behind firewalls and ensuring they are not accessible from the internet. When remote access is required, use VPNs updated to the most recent version. Follow Siemens ProductCERT advisory SSA-254516 for additional guidance.
Users should update the Mira app to the latest version (iOS v3.5.18 / Android v4.5.18). Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required beyond applying these updates. Organizations deploying Mira devices should ensure all units are running the latest firmware and app versions and monitor for future security advisories from Quanovate Tech Inc.
Apply the latest Adobe security updates for ColdFusion and Campaign Classic immediately. Verify all systems are running the patched versions. Monitor Adobe security advisories for additional details and scope of the addressed vulnerabilities.
Users should update the Mira app to the latest version (iOS v3.5.18 / Android v4.5.18). Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required beyond applying these updates. Organizations deploying Mira devices should ensure all units are running the latest firmware and app versions and monitor for future security advisories from Quanovate Tech Inc.
Update Siemens Solid Edge to V225.0.15 or later (SE2025) or V226.0.7 or later (SE2026). Apply patches from https://support.sw.siemens.com/product/246738425/. Restrict execution of untrusted PAR, PSM, and DFT files. Apply application whitelisting where possible.