Update Xiiaozet LK100W firmware to version 2.1.240 or later. As interim mitigations, minimize network exposure by ensuring the device is not accessible from the internet, locate it behind firewalls and isolate it from business networks, and use updated VPNs for any required remote access. Perform impact analysis and risk assessment before deploying defensive measures.
CISA notes that CareCam has not responded to coordination attempts. Users are encouraged to contact CareCam for mitigation information. No official patch has been confirmed available. Recommended actions include isolating affected devices from untrusted networks where possible, monitoring for unusual device behavior, and applying additional network-level access controls until a firmware update or official guidance is released.
Linux Foundation / Kernel maintainers·highCVSS 7.5
Apply the latest Linux kernel patches that address the KVM ARM64 memory handling code. Disable nested virtualization if not required. Monitor vendor advisories and kernel security mailing lists for follow-up updates. Ensure systems are running kernel versions containing the fix for CVE-2026-89775.
As of the advisory date, no patch is available. Ebyte has not confirmed a timeline. Organizations should: 1) Restrict network access to the device's web management interface to trusted users only. 2) Use network segmentation to isolate the device from untrusted networks. 3) Monitor device logs for unauthorized access or configuration changes. 4) Contact Ebyte for patch availability updates. 5) If possible, disable remote management features until a patch is applied.
Update ANDRITZ HIPASE-250/250 SCALA to version V8.15.00 or later. If immediate updating is not possible, network segmentation and monitoring of unauthorized access to device endpoints are recommended. Contact ANDRITZ at https://www.andritz.com/group-en/contact for patch guidance.
ABB recommends replacing the bundled MongoDB instance with a supported and patched version, or uninstalling IIoT Services where not required. Users should update MongoDB to versions at or above the patch thresholds (e.g., MongoDB Server v7.0.28+, v8.0.17+, v8.2.3+, v6.0.27+, v5.0.32+, v4.4.30+, v4.2.9+, v4.0.20+, v3.6.20+). Refer to ABB PSIRT advisory 9AKK108472A9037 and zenon online help for configuration guidance.
CISA notes that CareCam has not responded to coordination attempts. Users are encouraged to contact CareCam for mitigation information. No official patch has been confirmed available. Recommended actions include isolating affected devices from untrusted networks where possible, monitoring for unusual device behavior, and applying additional network-level access controls until a firmware update or official guidance is released.
Cisco has released security updates addressing CVE-2026-20079. Users of affected Secure Firewall Management Center versions should upgrade to the latest patched releases immediately. Specific patch versions and download links are available in Cisco's security advisory PSA-2026-0282. As a defensive measure, restrict access to the FMC management interface to trusted networks and implement strong network segmentation.
Organizations should upgrade to PowerChute Serial Shutdown version 1.6, available for Windows and Linux. After installation, the service restarts automatically; verify the version via the Control Panel or About page. Additionally, follow Schneider Electric's recommended cybersecurity best practices, including network segmentation, physical security controls, and minimizing exposure of control systems to the internet.
Update Siemens Reyrolle 7SR5 to version V2.70 or later. Apply the vendor fix via https://support.industry.siemens.com/cs/ww/en/view/109772413/. Monitor for future security advisories and restrict network access to the web management interface where possible.
Update to firmware version 2.4.5 released by Tycon Systems. Set an administrator username and strong password on the Network Configuration page. Avoid exposing the web interface to the Internet; keep the unit on a private network behind a firewall or VPN. Change any factory-default SNMP community strings and Telnet passwords if left at shipped values. Leave Telnet disabled unless required.
Users should update the Mira app to the latest version (iOS v3.5.18 / Android v4.5.18). Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required beyond applying these updates. Organizations deploying Mira devices should ensure all units are running the latest firmware and app versions and monitor for future security advisories from Quanovate Tech Inc.
Organizations using Gitea should apply security updates promptly to mitigate CVE-2026-60004. Per BOD 26-04, Federal Civilian Executive Branch agencies must prioritize rapid remediation of KEV Catalog vulnerabilities on publicly exposed assets and check for threat actor compromise before patching. All organizations are encouraged to adopt risk-based vulnerability management practices and monitor CISA and Gitea advisories for patch availability and exploitation updates.
Organizations should apply vendor-supplied patches immediately for all seven CVEs. Priority should be given to publicly exposed assets, particularly those within Federal Civilian Executive Branch agencies per BOD 26-04. Systems granting total control post-exploitation should be remediated first. Verify patch availability with respective vendors (Sangoma, Kludex, Kestra, BerriAI/LiteLLM, JFrog, SonicWall) and monitor for updates if patches are not yet released.
No patch or specific mitigation is required for this retracted vulnerability. Siemens recommends protecting network access to devices with appropriate mechanisms and following the company's operational guidelines for industrial security, available at https://www.siemens.com/cert/operational-guidelines-industrial-security and https://www.siemens.com/industrialsecurity.
Update Siemens Simcenter Femap to version V2606.0001 or later. Apply the vendor fix available at https://support.sw.siemens.com/product/275652363/. Minimize network exposure for Simcenter Femap instances and avoid opening untrusted BMP files with the application. Follow Siemens operational guidelines for industrial security.
Affected users should contact Zhibotong Electronics for firmware updates, implement network segmentation, and monitor for anomalous router behavior. Verify CVE assignments through official CNA processes. No official patch has been released as of disclosure.
Update Siemens Solid Edge to V225.0.15 or later (SE2025) or V226.0.7 or later (SE2026). Apply patches from https://support.sw.siemens.com/product/246738425/. Restrict execution of untrusted PAR, PSM, and DFT files. Apply application whitelisting where possible.
Organizations should apply vendor-provided patches immediately. For Cisco ASA/FTD, consult Cisco security advisories. For Microsoft Windows, apply the latest security updates. For Metabase, follow the vendor's guidance. Additionally, review systems for indicators of compromise before patching, as recommended by BOD 26-04.
Users should update the Mira app to the latest version (iOS v3.5.18 / Android v4.5.18). Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required beyond applying these updates. Organizations deploying Mira devices should ensure all units are running the latest firmware and app versions and monitor for future security advisories from Quanovate Tech Inc.
CISA encourages organizations to prioritize remediation of KEV Catalog vulnerabilities. Specific patch instructions are not provided in the advisory; organizations should consult Ray-Project official guidance for patching and mitigation steps. Federal agencies must follow Binding Operational Directive 26-04 requirements for rapid remediation on publicly exposed assets.
Organizations should apply updates to TrueConf Server to address CVE-2026-72529 and CVE-2026-72530. CISA BOD 26-04 establishes expectations for checking whether threat actors compromised systems before the patch was applied. Prioritize remediation on publicly exposed assets.
Update affected firmware to WTV676-HB6035 Web Interface V3.94 or later, or WTV776-HB6035 Web Interface V4.17 or later. Minimize network exposure by ensuring affected devices are not accessible from the internet. Locate control system networks behind firewalls and isolate from business networks. Use VPNs for remote access and keep VPNs and connected devices updated.
Hitachi Energy security advisory 8DBD000229 outlines recommended immediate actions. Affected organizations should verify GWS component presence, apply the latest software update from Hitachi Energy, and restrict network access to FCP management interfaces where possible. Deployments without the GWS component are not affected. Follow vendor guidance for patch testing in non-production environments prior to deployment.
As of the advisory date, no patch is available. Ebyte has not confirmed a timeline. Organizations should: 1) Restrict network access to the device's web management interface to trusted users only. 2) Use network segmentation to isolate the device from untrusted networks. 3) Monitor device logs for unauthorized access or configuration changes. 4) Contact Ebyte for patch availability updates. 5) If possible, disable remote management features until a patch is applied.
Users are strongly encouraged to update lwIP to a version beyond 2.2.1. The fix is available in the upstream repository at https://cgit.git.savannah.gnu.org/cgit/lwip.git with commit identifier f873b6295933e4149a2132adf3e9a2d2a676a5ec. Minimize network exposure for control system devices and ensure systems are not accessible from the internet. Use VPNs for remote access where required, keeping devices and VPN software updated.
Organizations should apply vendor-supplied patches immediately for all seven CVEs. Priority should be given to publicly exposed assets, particularly those within Federal Civilian Executive Branch agencies per BOD 26-04. Systems granting total control post-exploitation should be remediated first. Verify patch availability with respective vendors (Sangoma, Kludex, Kestra, BerriAI/LiteLLM, JFrog, SonicWall) and monitor for updates if patches are not yet released.
Organizations using Progress LoadMaster should apply vendor-provided patches immediately. Federal Civilian Executive Branch agencies must follow the remediation requirements and pre-patch compromise verification procedures outlined in BOD 26-04. All other organizations are encouraged to adopt risk-based vulnerability management practices and prioritize remediation of KEV Catalog vulnerabilities on publicly exposed assets.
Johnson Controls recommends upgrading C-CURE 9000 to v3.20 or later, upgrading victor Application Server to v4.20 or later, upgrading victor to v8.0 or later, and upgrading victor Web to v7.0 or later. Until upgrades are applied, implement strict firewall rules blocking unnecessary inbound connections to port 8999 from untrusted network segments, deploy IDS/IPS signatures tuned to detect .NET deserialization exploit patterns (e.g., ysoserial.net), enforce application whitelisting on application server hosts, ensure application server processes run with least privilege, enable detailed logging and monitor for anomalous process creation (e.g., SoftwareHouse.CrossFire.Server.exe), and disable unnecessary services such as the ClientConnectionManager_NF.SynchronousServerNotification callback interface if not required. See Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16 for more detailed guidance.
As of the advisory date, no patch is available. Ebyte has not confirmed a timeline. Organizations should: 1) Restrict network access to the device's web management interface to trusted users only. 2) Use network segmentation to isolate the device from untrusted networks. 3) Monitor device logs for unauthorized access or configuration changes. 4) Contact Ebyte for patch availability updates. 5) If possible, disable remote management features until a patch is applied.
Rently has patched this vulnerability in late June 2026. Users should update to the latest version of Rently Smart Home. CISA recommends minimizing network exposure for control system devices, ensuring they are not accessible from the internet, locating control system networks behind firewalls isolated from business networks, and using updated VPNs for remote access.
Apply Sangoma's released security updates and firmware patches immediately. Restrict network access to the Switchvox management interface to trusted networks only. Monitor logs for suspicious SQL injection attempts or unexpected reverse shell connections.
Organizations should immediately apply vendor-provided patches for the listed vulnerabilities. For CVE-2019-1068, Citrix has released updates; consult official advisories. Additionally, monitor CISA's KEV catalog for updates and implement compensating controls if patches cannot be applied immediately. Federal agencies must comply with BOD 22-01 deadlines.
FURUNO ELECTRIC CO., LTD. notes that production of this product ended in October 2020, and software updates will no longer be provided. FURUNO recommends users do not connect the product directly to the internet. To prevent unauthorized access, the vessel on which the product is installed should be properly locked and managed. CISA recommends minimizing network exposure for all control system devices, ensuring they are not accessible from the internet, locating control system networks and remote devices behind firewalls and isolating them from business networks, and using secure methods such as VPNs when remote access is required.
Upgrade Johnson Controls Simplex Incident Manager to version v2.01.01 or later. Restrict local access to authorized personnel only. Implement endpoint protection and monitoring to detect memory-dumping tools or suspicious processes. Enforce strong access control policies and the principle of least privilege on host systems. Utilize full-disk encryption and secure boot to reduce the risk of offline memory analysis. Monitor for unauthorized local access attempts and implement audit logging.
Organizations should apply updates to TrueConf Server to address CVE-2026-72529 and CVE-2026-72530. CISA BOD 26-04 establishes expectations for checking whether threat actors compromised systems before the patch was applied. Prioritize remediation on publicly exposed assets.
Organizations should apply vendor-supplied patches immediately for all seven CVEs. Priority should be given to publicly exposed assets, particularly those within Federal Civilian Executive Branch agencies per BOD 26-04. Systems granting total control post-exploitation should be remediated first. Verify patch availability with respective vendors (Sangoma, Kludex, Kestra, BerriAI/LiteLLM, JFrog, SonicWall) and monitor for updates if patches are not yet released.
Update Siemens Simcenter Femap to version V2606.0001 or later. Apply the vendor fix available at https://support.sw.siemens.com/product/275652363/. Minimize network exposure for Simcenter Femap instances and avoid opening untrusted BMP files with the application. Follow Siemens operational guidelines for industrial security.
Upgrade to ASE2000 version 2.38 or later. interim measures: restrict write access to installation directories, avoid IEC 60870-5-104 over TLS on untrusted networks, and enforce host-based firewall protection.
Upgrade firmware to version 2.6.0.7R6 released by Lantronix. Avoid using unencrypted HTTP connections for update metadata. Monitor Lantronix Vulnerability Library for additional updates. Contact Lantronix support for technical assistance if needed.
As of the advisory date, no patch is available. Ebyte has not confirmed a timeline. Organizations should: 1) Restrict network access to the device's web management interface to trusted users only. 2) Use network segmentation to isolate the device from untrusted networks. 3) Monitor device logs for unauthorized access or configuration changes. 4) Contact Ebyte for patch availability updates. 5) If possible, disable remote management features until a patch is applied.
Upgrade Malcolm to version 26.06.1 or later to address CVE-2026-55676. Upgrade to version 26.07.0 or later to address CVE-2026-63133, CVE-2026-63134, and CVE-2026-63177. For CVE-2026-19670 and CVE-2026-19671, monitor CISA advisory for updates. Restrict access to the upload functionality to trusted users only.
Upgrade to EasyIO Neo Series EC Controllers V3.3b64 or later and CW Controllers V3.3b26 or later. If immediate update is not possible, enforce HTTPS/TLS for all web-based management access, disable HTTP access entirely, place devices on isolated and segmented networks behind a firewall, use a VPN for remote access, and monitor network traffic for unencrypted sensitive data. Apply the recommendations in the Johnson Controls Hardening Guide and refer to advisory JCI-PSA-2026-30 for further guidance.
Rockwell Automation recommends updating affected controllers to the following minimum firmware versions: ControlLogix 5580 and GuardLogix 5580 to version 34.015 and later; CompactLogix 5380, Compact GuardLogix 5380, and CompactLogix 5480 to version 37.011 and later. As a defensive mitigation, CISA recommends minimizing network exposure for control system devices, ensuring they are not internet-accessible, locating control system networks behind firewalls, and isolating them from business networks. When remote access is required, use VPNs updated to the most current version. Perform proper impact analysis and risk assessment before deploying defensive measures.
Autonomy Logic recommends upgrading to OpenPLC v4 as v3 is end-of-life. CISA recommends minimizing network exposure, placing control system devices behind firewalls, isolating from business networks, and using VPNs for remote access with current versions. No known public exploitation reported.
Apple has released security updates addressing CVE-2026-86950. Users should update their devices to the latest available software versions. For iOS and iPadOS, go to Settings > General > Software Update. For macOS, use System Settings > General > Software Update. Organizations should ensure all managed devices are updated promptly. If immediate updating is not possible, exercise caution when opening files from untrusted sources, including email attachments, links, and downloads from the web.
Users should immediately update all affected WordPress plugins and themes to their latest available versions. Enable web application firewall rules to block known exploitation patterns. Monitor Wordfence and Patchstack advisories for vendor-specific patches and detailed mitigation guidance. Apply the principle of least privilege to user accounts and regularly audit plugin and theme permissions.
Users and operators of WAGO PLCs with Nucleus FTP server should apply vendor-supplied patches or mitigations for CVE-2021-31886. Network segmentation should be used to limit exposure of FTP services in industrial environments. Monitoring for unusual FTP activity is recommended.
Users should update to Medixant RadiAnt DICOM version 2026.1, available at https://www.radiantviewer.com/files/RadiAnt-2026.1-Setup.exe. Additionally, only open DICOM files from trusted and reliable sources. CISA recommends minimizing network exposure for medical devices, using firewalls and VPNs for remote access, and following general security practices to avoid social engineering attacks.
Apply vendor-released firmware updates: BMXNOE0100 version 3.60, BMXNOE0110 version 6.80, Modicon M340 Controller SV3.70, BMXNOR0200H SV1.7_IR27. As interim mitigations, disable FTP service when not in use, implement network segmentation, block unauthorized access to port 21/FTP via firewall, and use VPN tunnels for remote access.