CISA notes that CareCam has not responded to coordination attempts. Users are encouraged to contact CareCam for mitigation information. No official patch has been confirmed available. Recommended actions include isolating affected devices from untrusted networks where possible, monitoring for unusual device behavior, and applying additional network-level access controls until a firmware update or official guidance is released.
Organizations should apply vendor-supplied patches immediately for all seven CVEs. Priority should be given to publicly exposed assets, particularly those within Federal Civilian Executive Branch agencies per BOD 26-04. Systems granting total control post-exploitation should be remediated first. Verify patch availability with respective vendors (Sangoma, Kludex, Kestra, BerriAI/LiteLLM, JFrog, SonicWall) and monitor for updates if patches are not yet released.
Botslab has not responded to requests to work with CISA to mitigate these vulnerabilities. No official patch has been publicly confirmed. Users of affected firmware versions are advised to reach out to Botslab via the official website (https://www.botslab.com/pages/about-botslab) for guidance. Organizations should monitor for firmware updates, segment affected devices on networks where possible, and review access controls for dashcam deployments.
ABB recommends applying the fix in Edgenius version 3.2.4.1 at the earliest convenience. Additional mitigations include limiting access to SSH or cockpit interfaces and noting that by default, no additional lower-privilege users are present on Edgenius installations. Refer to ABB PSIRT security advisory 7PAA024620 for further guidance.
Wärtsilä has developed a security patch for the affected version. Users are directed to contact Wärtsilä to obtain and install the latest patch via https://www.wartsila.com/services-catalogue/engine-services-4-stroke/wartsila-ics-patch-deployment#contact. CISA recommends minimizing network exposure for control system devices, ensuring they are not internet-accessible, locating control system networks behind firewalls and isolating them from business networks, and using secure remote access methods such as VPNs when remote access is required. Organizations should perform impact analysis and risk assessment prior to deploying defensive measures.
Broadcom has released security updates addressing CVE-2026-59346 and a second flaw. Users should update VMware Workstation and Fusion to the latest patched versions immediately. Apply the available patches to eliminate the vulnerability. Monitor VMware security advisories for any additional information regarding the second flaw or future updates.
CISA encourages organizations to apply vendor-provided mitigations and prioritize remediation of KEV Catalog vulnerabilities. Federal Civilian Executive Branch agencies must prioritize rapid remediation of CVE-2026-58704 on publicly exposed assets per BOD 26-04 and assess whether systems were compromised before patch application. All organizations should adopt risk-based vulnerability management practices.
Siemens recommends contacting customer support for detailed fix information. Follow Fortinet advisory for workarounds. CISA advises minimizing network exposure, placing control systems behind firewalls, and using updated VPNs for remote access.
Hitachi Energy security advisory 8DBD000229 outlines recommended immediate actions. Affected organizations should verify GWS component presence, apply the latest software update from Hitachi Energy, and restrict network access to FCP management interfaces where possible. Deployments without the GWS component are not affected. Follow vendor guidance for patch testing in non-production environments prior to deployment.
CISA encourages rapid remediation of KEV Catalog vulnerabilities. Affected vendors (Microsoft, Broadcom, Apple) should be consulted for patches. Federal agencies must check for prior compromise before patching per BOD 26-04 requirements. All organizations should adopt risk-based vulnerability management and prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets.
OwnCloud has released security updates to address CVE-2023-49105. CISA urges organizations to apply the patches immediately. Federal agencies must remediate or mitigate the vulnerability within the defined timeframe. Organizations should update to the latest patched version of ownCloud to prevent unauthorized access and data exfiltration.
Apply the update provided by Mitsubishi Electric (Update A) to all affected products. Additionally, implement network segmentation to isolate control system networks from untrusted networks, restrict physical and logical access to the network segment, and monitor for anomalous traffic patterns.
CISA notes that CareCam has not responded to coordination attempts. Users are encouraged to contact CareCam for mitigation information. No official patch has been confirmed available. Recommended actions include isolating affected devices from untrusted networks where possible, monitoring for unusual device behavior, and applying additional network-level access controls until a firmware update or official guidance is released.
Organizations using Ebyte NE2-D11 devices should: 1) Isolate affected devices from untrusted networks where possible, 2) Monitor for vendor communications regarding patch availability, 3) Contact Ebyte directly for updates on remediation, 4) Implement network segmentation and strict access controls to limit exposure, 5) Credentials should be rotated if exposure is suspected due to CVE-2026-73839.
Organizations should apply the AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate affected project files. For files that cannot be migrated, evaluate the risk of password leakage and implement stricter read access controls. Require PIMBoards users to change their passwords after migration. Migration is one-way due to changes in password hashing algorithms and encryption keys.
Upgrade GitLab to the patched version as specified in the official GitLab security advisory. Apply the latest security updates immediately. Monitor GitLab security bulletins for additional guidance.
Apply the latest security patches released by Arista and VMware for VeloCloud Orchestrator immediately. If patching is not immediately possible, consider disabling certificate-based Edge authentication, noting this will impact Edge connectivity. Monitor Arista and VMware security advisories for further guidance.
Update Bransys ELD Android to version 11.00.00 or newer and iOS to version 1.1.54 or newer via the app store. Apply network segmentation, firewall controls, and restrict internet exposure for Bransys ELD devices. Use VPNs for remote access and perform impact analysis prior to deploying defensive measures.
Implement Role-Based Access Control (RBAC) as recommended by Schneider Electric and follow the Security Guidelines for Administrators. Configure network segmentation to restrict access between trusted and untrusted networks. Enable and implement the RTU firewall service to restrict unauthorized access to device services. Consult the SCADAPack Cybersecurity Guide for hardening and secured communication best practices. Apply all standard practices referenced in the SCADAPack Cybersecurity Guide, including locating control system networks behind firewalls and isolating them from business networks.
Organizations should apply the AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate affected project files. For files that cannot be migrated, evaluate the risk of password leakage and implement stricter read access controls. Require PIMBoards users to change their passwords after migration. Migration is one-way due to changes in password hashing algorithms and encryption keys.
Update Siemens Reyrolle 7SR5 to version V2.70 or later. Apply the vendor fix via https://support.industry.siemens.com/cs/ww/en/view/109772413/. Monitor for future security advisories and restrict network access to the web management interface where possible.
Apply upstream kernel patch released August 6, 2026. Until Ubuntu releases a patched kernel for affected LTS versions, administrators should restrict container privileges, monitor official Ubuntu security advisories, and consider kernel recompilation from source if feasible. Limit AF_UNIX socket access within containers where possible.
Organizations should upgrade Orthanc DICOM Server to version 1.13.0 or later, as recommended by the vendor. Additionally, CISA advises minimizing network exposure of control systems and medical devices, ensuring they are not accessible from the internet, and placing them behind firewalls isolated from business networks. When remote access is necessary, use secure methods such as VPNs, and keep all systems updated. Perform impact analysis and risk assessment before deploying defensive measures.
Update Siemens Reyrolle 7SR5 to version V2.70 or later. Apply the vendor fix via https://support.industry.siemens.com/cs/ww/en/view/109772413/. Monitor for future security advisories and restrict network access to the web management interface where possible.
Upgrade to Unbound 1.26.1 immediately. Until patched, consider restricting recursive queries to trusted clients and monitoring DNS traffic for anomalies. Apply vendor patches as soon as possible.
Organizations should upgrade NetBotz 5 750 and 755 to firmware version 5.6.0, available from Schneider Electric's product page. Additionally, follow vendor recommendations: isolate control networks, use firewalls, restrict physical access, and avoid connecting programming software to untrusted networks.
Users should update the Mira app to the latest version (iOS v3.5.18 / Android v4.5.18). Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required beyond applying these updates. Organizations deploying Mira devices should ensure all units are running the latest firmware and app versions and monitor for future security advisories from Quanovate Tech Inc.
Users should update the Mira app to the latest version (iOS v3.5.18 / Android v4.5.18). Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required beyond applying these updates. Organizations deploying Mira devices should ensure all units are running the latest firmware and app versions and monitor for future security advisories from Quanovate Tech Inc.
Upgrade Malcolm to version 26.06.1 or later to address CVE-2026-55676. Upgrade to version 26.07.0 or later to address CVE-2026-63133, CVE-2026-63134, and CVE-2026-63177. For CVE-2026-19670 and CVE-2026-19671, monitor CISA advisory for updates. Restrict access to the upload functionality to trusted users only.
Update Bransys ELD Android to version 11.00.00 or newer and iOS to version 1.1.54 or newer via the app store. Apply network segmentation, firewall controls, and restrict internet exposure for Bransys ELD devices. Use VPNs for remote access and perform impact analysis prior to deploying defensive measures.
Update Langflow to the latest patched version available from the official repository. Restrict network exposure by placing Langflow instances behind firewalls or in private networks. Monitor for suspicious activity and review application logs for unauthorized code execution.
Organizations should apply vendor patches from Microsoft and MikroTik as soon as possible. CISA KEV catalog entries typically require applicable updates to mitigate the vulnerabilities. Prioritize patching internet-facing SharePoint servers and MikroTik routers.
Hitachi Energy security advisory 8DBD000229 outlines recommended immediate actions. Affected organizations should verify GWS component presence, apply the latest software update from Hitachi Energy, and restrict network access to FCP management interfaces where possible. Deployments without the GWS component are not affected. Follow vendor guidance for patch testing in non-production environments prior to deployment.
Update to the latest patched version of Elementor Pro immediately. Apply all available security updates from the Elementor development team. Monitor official Elementor security advisories for further details and confirmation of patches.
Organizations using Citrix NetScaler should apply the latest firmware updates as released by Citrix. Monitor official Citrix security advisories for CVE-2026-19490. If immediate patching is not possible, consider temporary network segmentation or access controls to limit exposure of NetScaler management interfaces. Ensure all NetScaler deployments are running the most recent supported software versions.
Apply VMware's security updates for CVE-2026-59310 immediately. Implement additional defensive measures as recommended by VMware to complement patching. Monitor for anomalous activity on vCenter Server systems. Review VMware's advisory for supplementary guidance on hardening affected deployments.
Wärtsilä has developed a security patch for the affected version. Users are directed to contact Wärtsilä to obtain and install the latest patch via https://www.wartsila.com/services-catalogue/engine-services-4-stroke/wartsila-ics-patch-deployment#contact. CISA recommends minimizing network exposure for control system devices, ensuring they are not internet-accessible, locating control system networks behind firewalls and isolating them from business networks, and using secure remote access methods such as VPNs when remote access is required. Organizations should perform impact analysis and risk assessment prior to deploying defensive measures.
Botslab has not responded to requests to work with CISA to mitigate these vulnerabilities. No official patch has been publicly confirmed. Users of affected firmware versions are advised to reach out to Botslab via the official website (https://www.botslab.com/pages/about-botslab) for guidance. Organizations should monitor for firmware updates, segment affected devices on networks where possible, and review access controls for dashcam deployments.
CISA notes that CareCam has not responded to coordination attempts. Users are encouraged to contact CareCam for mitigation information. No official patch has been confirmed available. Recommended actions include isolating affected devices from untrusted networks where possible, monitoring for unusual device behavior, and applying additional network-level access controls until a firmware update or official guidance is released.
Evaluate authorization policy for the Graphics application following the Least Privilege principle, ensuring only required users have access. Minimize network exposure for control system devices; ensure systems are not internet-facing. Locate control system networks behind firewalls and isolate from business networks. Use secure remote access methods such as VPNs, keeping them updated. Follow Siemens operational guidelines for industrial security. Monitor Siemens advisory SSA-330084 for updates on remediation.
Botslab has not responded to requests to work with CISA to mitigate these vulnerabilities. No official patch has been publicly confirmed. Users of affected firmware versions are advised to reach out to Botslab via the official website (https://www.botslab.com/pages/about-botslab) for guidance. Organizations should monitor for firmware updates, segment affected devices on networks where possible, and review access controls for dashcam deployments.
Install the latest firmware updates provided by Flow Neuroscience via the Flow app. Minimize network exposure for all control system devices and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. Use secure methods such as VPNs when remote access is required, and keep VPN software updated. Perform impact analysis and risk assessment prior to deploying defensive measures.
MikroTik has released RouterOS version 7.0.4 and later which patches both CVE-2026-67279 and CVE-2026-86060. Users should update to the latest stable RouterOS version immediately. If updating is not immediately possible, MikroTik recommends disabling SSH access from the WAN interface.
Apply the latest Check Point security updates and firmware versions as specified in the vendor advisory. Review network segmentation and access controls for VPN appliances.
Johnson Controls recommends upgrading C-CURE 9000 to v3.20 or later, upgrading victor Application Server to v4.20 or later, upgrading victor to v8.0 or later, and upgrading victor Web to v7.0 or later. Until upgrades are applied, implement strict firewall rules blocking unnecessary inbound connections to port 8999 from untrusted network segments, deploy IDS/IPS signatures tuned to detect .NET deserialization exploit patterns (e.g., ysoserial.net), enforce application whitelisting on application server hosts, ensure application server processes run with least privilege, enable detailed logging and monitor for anomalous process creation (e.g., SoftwareHouse.CrossFire.Server.exe), and disable unnecessary services such as the ClientConnectionManager_NF.SynchronousServerNotification callback interface if not required. See Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16 for more detailed guidance.
Apply vendor-fixed versions: BC or later for M800VW/M800VS/M80V/M80VW; FN or later for M800W/M800S/M80/M80W/E80; LK or later for M750VW/M730VW/M720VW/M750VS/M730VS/M720VS/M70V/E70. Use firewall or VPN to prevent unauthorized access. Operate products within LAN and block untrusted network access when internet connectivity is required.
Update affected products to the minimum patched versions: SIMOVE Fleetmanager V3.1.13 or later, V3.2.4 or later, V3.3.2 or later, or V4.0.1 or later. SIPLANT V3.1.4 or later. Restrict network access to affected devices behind firewalls. Implement user management to limit services' access rights to project files. Isolate control system networks from business networks per Siemens operational guidelines.
CISA encourages rapid remediation and prioritization of security updates. Federal Civilian Executive Branch agencies must follow Binding Operational Directive 26-04, which requires prioritizing patches for KEV Catalog vulnerabilities on publicly exposed assets and checking for pre-existing compromise before applying patches. Organizations should consult vendor-specific advisories for mitigation guidance for each CVE and adopt risk-based vulnerability management practices.
Apply the latest macOS security updates released by Apple to address CVE-2026-65400. Restrict Screen Sharing access to trusted networks and disable Screen Sharing if not required. Monitor system resources for unexpected cryptocurrency mining activity.