Bulletins

CISA (ALL)
07/16/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious scripts on the server.

The following versions of Rockwell Automation FactoryTalk DataMosaix are affected:

  • DataMosaix Private Cloud <=8.02 (CVE-2026-9292)
CVSS Vendor
CISA (ALL)
07/16/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.

The following versions of NASA Core Flight System (cFS) Health & Safety (HS) Application are affected:

  • Core Flight System (cFS) Health & Safety (HS) Application
CISA (ALL)
07/16/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition.

The following versions of Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix are affected:

  • CompactLogix 5370 <=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)
  • Compact GuardLogix 5370 <=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)
CISA (ALL)
07/16/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.

The following versions of Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT are affected:

  • 1756-EN3 <=V12.001 (CVE-2026-9653)
  • 1756-EN2 <=V12.001 (CVE-2026-9653)
  • 1756-ENBT V6.006 (CVE-2026-9653)
CISA (ALL)
07/15/2026

Developed by CISA, the National Security Agency (NSA) and international partners, this joint guidance contains best practices for software manufacturers and online service providers to design and implement a coordinated vulnerability disclosure (CVD) program for working with external security researchers that includes a clear vulnerability disclosure policy (VDP) and process …

CISA (ALL)
07/14/2026

View CSAF

Summary

ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally …

CISA (ALL)
07/14/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device.

The following versions of Rockwell Automation 1715-AENTR EtherNet/IP Adapter are affected:

CISA (ALL)
07/14/2026

View CSAF

Summary

ABB became aware of vulnerability in the products versions listed as affected in the advisory, where an incorrect version of Online Builder (ONB) was included in the media. An update is available that resolves the vulnerability, see details in Recommended immediate actions.

The following …