Bulletins

CISA (ALL)
07/23/2026

View CSAF

Summary

Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device.

The following versions of Johnson Controls XAAP Android are affected:

  • XAAP Android <1.53
CVSS Vendor Equipment Vulnerabilities
CISA (ALL)
07/23/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions.

The following versions of MZ Automation libIEC61850 are affected:

  • libIEC61850 >=v1.0.0|<=v1.6.1 
CISA (ALL)
07/23/2026

View CSAF

Summary

Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service.

The following versions of MZ Automation lib60870 are affected:

  • lib60870 <=2.4.0
CVSS Vendor Equipment
CISA (ALL)
07/23/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution.

The following versions of Johnson Controls C-CURE 9000 and Victor application server are affected:

  • C-CURE 9000 and victor <=v2.90_v3.0 
  • victor Web <=v7.1 
CISA (ALL)
07/21/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product.

The following versions of Rockwell Automation 1734 POINT I/O are affected:

  • 1734 POINT I/O 3.023 
CVSS Vendor
CISA (ALL)
07/21/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product.

The following versions of Rockwell Automation 1718-AENTR/1719-AENTR are affected:

  • 1718/ 1719 Ex I/O 3.011 
CVSS Vendor
CISA (ALL)
07/21/2026

View CSAF

Summary

Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/

The following …