Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create …
CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability
- CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- CVE-2026-49869 Kestra OSS OS …
Summary
The following versions of Rockwell Automation Logix Platform are affected:
- ControlLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)
- CompactLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)
- GuardLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)
- …
Summary
Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution.
The following versions of Rockwell Automation Historian ME are affected:
- Series B 5.202 (CVE-2025-12768, CVE-2026-12661)
- Series C 7.101 (CVE-2025-12768, CVE-2026-12661)
Summary
Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product.
The following versions of Rockwell Automation RSLinx Classic are affected:
- RSLinx Classic <=4.50 (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625)
| CVSS | …
|---|
Summary
Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges.
The following versions of Rockwell Automation Redundancy Module Configuration Tool are affected:
- Redundancy Module Configuration Tool 10.00.00 (CVE-2026-9633)
- Redundancy Module Configuration Tool >=9.00.00|<=10.00.00 …
Summary
The following versions of Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix are affected:
- ControlLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)
- GuardLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)
- CompactLogix 5380 <34.015, <35.014, <36.013, <37.011 …
BOSCH-SA-223618: Multiple vulnerabilities including stack-based buffer overflows, heap-based buffer overflows, and out-of-bounds reads have been identified in several Bosch Sensortec software components: the BHI360 SensorAPI, BHI385 SensorAPI, BME690 SensorAPI, and the COINES SDK. Depending on the specific vulnerability, a locally/physically positioned attacker, or a compromised peripheral device (connected via I2C, …