Bulletins

CISA (ALL)
07/30/2026

View CSAF

Summary

Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. The IGSS Definition module is a design-time component used by …

CISA (ALL)
07/30/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.

The following versions of Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module are affected:

  • ControlLogix 5580 >=V36|<=V37 (CVE-2026-9636)
  • CompactLogix 5380 >=V36|<=V37 (CVE-2026-9636)
  • GuardLogix 5580 …
CISA (ALL)
07/30/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device.

The following versions of MZ Automation GmbH libiec61850 are affected:

  • libiec61850 <1.6.2 (CVE-2026-66720, CVE-2026-66369, CVE-2026-63550, CVE-2026-65421, CVE-2026-66364, CVE-2026-66349, CVE-2026-56758, CVE-2026-66360)
CISA (ALL)
07/30/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code.

The following versions of o6 Automation open62541 are affected:

  • open62541 on Windows and Linux >=from_1.3.0|<=1.3.17 (CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559)
CISA (ALL)
07/30/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content.

The following versions of Johnson Controls OpenBlue Employee are affected:

  • OpenBlue Employee (FMS Employee) <=V2025.3.1 (CVE-2026-21662, CVE-2026-34495, CVE-2026-34497)
CISA (ALL)
07/30/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation and decryption of all associated traffic.

The following versions of MikroTik RouterOS are affected:

  • RouterOS …
CISA (ALL)
07/30/2026

Open source software (OSS) is embedded in nearly every modern system, from business applications to critical infrastructure. Our new Open Source Software: Security Principles and Practices guidance helps agencies securely use, evaluate, and publish open source software. It covers OSS risk management across the full lifecycle, introduces the C4 Framework …

CISA (ALL)
07/30/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition …