Bulletins

CISA (ALL)
10/08/2026

View CSAF

Summary

The following versions of Grid Protection Alliance openPDC and openHistorian are affected:

  • openPDC <2.9.477, <2.9.482 (CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022)
  • openPDC (Docker image) <2.9.477, <2.9.482 (CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022, CVE-2026-105278)
  • openHistorian <2.8.580, <2.8.585 (CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022)
…
CISA (ALL)
10/08/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow a malicious user to access the device and gain administrative access. This access would allow the user to view, edit, and upload configuration files. Further, a malicious user can cause the switch to reboot by navigating to a …

CISA (ALL)
10/08/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary scripts in a user's browser, consume excessive system resources, enumerate files, create or modify files, and potentially execute arbitrary code.

The following versions of Satel Netco Design are affected:

  • Satel …
CISA (ALL)
10/06/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device.

The following versions of Johnson Controls EasyIO FG are affected:

  • EasyIO FG firmware <=2.0b52 (CVE-2026-27872, CVE-2026-27873)
…
CVSS Vendor
CISA (ALL)
10/06/2026

View CSAF

Summary

Hitachi Energy is aware of RCE (Remote Code Execution) vulnerability in Apache ActiveMQ component of SOI product versions listed in this document. These vulnerabilities can be exploited to carry out various attacks affecting confidentiality, integrity, and availability of the product. Please refer to the Recommended …

CISA (ALL)
10/06/2026

View CSAF

Summary

Hitachi Energy is aware of open-source software vulnerabilities that affect REB500 product versions listed in this document. These vulnerabilities can be exploited to carry out Denial of Service (DoS) attack on the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.

…
CISA (ALL)
10/06/2026

View CSAF

Summary

Successful exploitation of this vulnerability could crash the device being accessed; a buffer overflow condition may allow remote code execution.

The following versions of Savannah lwIP SMTP client are affected:

  • lwIP SMTP client 2.2.1 (CVE-2026-15340)
…
CVSS
CISA (ALL)
10/01/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system.

The following versions of Armatura LLC Armatura One …