Bulletins

CISA (ALL)
07/30/2026

CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat …

CISA (ALL)
07/30/2026

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code.

The following versions of o6 Automation open62541 are affected:

  • open62541 on Windows and Linux >=from_1.3.0|<=1.3.17 (CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559)
CISA (ALL)
07/30/2026

Open source software (OSS) is embedded in nearly every modern system, from business applications to critical infrastructure. Our new Open Source Software: Security Principles and Practices guidance helps agencies securely use, evaluate, and publish open source software. It covers OSS risk management across the full lifecycle, introduces the C4 Framework …

CISA (ALL)
07/30/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition …

CISA (ALL)
07/30/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation and decryption of all associated traffic.

The following versions of MikroTik RouterOS are affected:

  • RouterOS …
CISA (ALL)
07/30/2026

View CSAF

Summary

Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. The IGSS Definition module is a design-time component used by …

CISA (ALL)
07/30/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller.

The following versions of Watchfire Controller Software are affected:

  • BC550 12.30 (CVE-2026-5846)
  • BC750 11.33|12.35 (CVE-2026-5846)
CISA (ALL)
07/30/2026

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources.

The following versions of Toptech Systems RCU II+ and Multiload II+ are affected:

  • RCU II+ <2025-11-24 (CVE-2026-12562)