Bulletins

SIEMENS CERT
09/16/2026
The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices. Siemens has released new versions for the affected products and recommends to update to the …
CISA (ALL)
09/15/2026

View CSAF

Summary

Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version.

The following versions of Siemens Reyrolle 7SR5 are affected:

  • Reyrolle 7SR5 vers:intdot/<2.70 (CVE-2024-42384, CVE-2024-42385, CVE-2024-42386, …
CISA (ALL)
09/15/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem.

The following versions of mySCADA myPRO Manager are affected:

  • mySCADA myPRO Manager <=2.1 (CVE-2026-73807, CVE-2026-82567)
CISA (ALL)
09/15/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a network pivot point.

The following versions of Digital Watchdog VMAX DVR and NVR …

CISA (ALL)
09/15/2026

Developed by the National Institute of Standards and Technology (NIST) and CISA, this interagency report provides federal agencies and cloud service providers with guidelines to protect the identity assertions, access tokens, and cryptographic mechanisms that support modern authentication and authorization. As agencies adopt hybrid and multi-cloud environments, single sign-on, federation, …

CISA (ALL)
09/15/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to deliver an unauthorized update, execute code, or extract credentials to allow the attacker to impersonate a privileged client.

The following versions of Wärtsilä FOS-Onboard are affected:

  • FOS-Onboard 5.07.0923.01 (CVE-2026-78225, CVE-2026-81855)
CISA (ALL)
09/15/2026

View CSAF

Summary

Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and SCADAPack 57x products are Remote Terminal Units that provide communication capabilities for remote monitoring and control. Failure to apply the mitigations provided below …

CISA (ALL)
09/15/2026

View CSAF

Summary

Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version.

The following versions of Siemens Mendix …