The Canadian Centre for Cyber Security released a daily advisory digest containing 6 security advisories for 2026-07-07. The advisories cover critical vulnerabilities in a range of products including Android and Samsung mobile devices, VMware Tanzu, ABB industrial control systems, Django web framework, and Zimbra collaboration software. Administrators are urged to review the referenced bulletins and apply the necessary patches and mitigations.
ICS
33 posts
Cyber Centre Daily Advisory Digest — 2026-07-07 (6 advisories) Threat landscape for industrial automation systems. Q1 2026 Kaspersky's Q1 2026 ICS threat landscape report indicates a continued overall decline in malware blocked on industrial automation systems, reaching 19.6%. However, specific regions like Southern Europe and industries like biometric systems saw notable increases in threats, particularly from malicious scripts, phishing, and spyware. The report highlights the persistent risk to OT environments from common threat vectors like internet browsing and email.
Cyber Centre Daily Advisory Digest — 2026-07-06 (8 advisories) The Canadian Centre for Cyber Security published a daily advisory digest on 2026-07-06 compiling eight security advisories from Red Hat, Ubuntu, Dell, CISA ICS, IBM, Roundcube, OpenSSH, and Microsoft Edge. The advisories address vulnerabilities across a broad range of products including Linux kernels, industrial control systems, enterprise software suites, webmail, SSH, and browser software. No specific CVEs, IOCs, or threat actor details are provided in the digest; administrators are directed to vendor advisories for patching guidance.
Cyber Centre Daily Advisory Digest — 2026-06-22 (5 advisories) The Canadian Centre for Cyber Security published a daily digest summarizing security advisories from IBM, Ubuntu, Dell, CISA (ICS), and Red Hat. The advisories cover a wide range of enterprise software, Linux kernels, and industrial control systems requiring immediate patching to address newly disclosed vulnerabilities.
Schneider Electric EasyLogic T150 and Saitel DP (CVE-2026-6865) Schneider Electric EasyLogic T150 and Saitel DP Remote Terminal Units are affected by a high-severity Path Traversal vulnerability (CVE-2026-6865, CVSS 7.1). This flaw allows authenticated attackers to access sensitive files on the device due to improper limitation of a pathname to a restricted directory. Firmware updates are available to patch the vulnerability.
Rockwell Automation FLEX I/O EtherNet/IP Adapters (CVE-2026-0646, CVE-2026-0647) Rockwell Automation FLEX I/O EtherNet/IP Adapters version 2.012 are affected by two vulnerabilities. CVE-2026-0647 allows unauthenticated account takeover via the embedded web server, while CVE-2026-0646 enables a denial-of-service condition through malformed CIP protocol requests.
Rockwell Automation RSLinx (CVE-2020-13573) Rockwell Automation RSLinx Classic versions 4.50.00 and prior contain an out-of-bounds read and stack-based buffer overflow vulnerability (CVE-2020-13573). Successful exploitation by a remote attacker can lead to a denial of service condition where the application becomes unresponsive, or potentially allow for remote code execution.
Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP (CVE-2026-11317) Rockwell Automation Logix 5370 and 5570 controllers are affected by a high-severity denial-of-service vulnerability (CVE-2026-11317, CVSS 8.7) triggered by crafted Common Industrial Protocol (CIP) messages. Successful exploitation results in a major nonrecoverable fault (MNRF) due to improper resource shutdown or release, requiring a manual program download to restore operations.
Cyber Centre Daily Advisory Digest — 2026-06-15 (5 advisories) The Canadian Centre for Cyber Security released a daily digest summarizing five security advisories for vulnerabilities patched between June 8 and 14, 2026. The advisories cover a wide range of enterprise software, infrastructure, Linux kernels, and industrial control systems from vendors including IBM, Dell, Ubuntu, Red Hat, and various ICS manufacturers. Organizations are strongly encouraged to review the specific vendor advisories and apply necessary updates.
Schneider Electric EcoStruxure Panel Server (CVE-2026-6866) Schneider Electric EcoStruxure Panel Servers contain an insecure default initialization vulnerability (CVE-2026-6866, CVSS 7.5) that can lead to unauthorized authentication. Under rare circumstances, credentials may revert to initial settings, allowing attackers to access sensitive information using known default credentials.
Siemens KACO Blueplanet Inverters (CVE-2025-40946, CVE-2026-41125) Siemens KACO Blueplanet Inverters contain two vulnerabilities, including a hard-coded cryptographic key issue (CVE-2025-40946) that allows attackers to derive device credentials from serial numbers, and an SQL injection (CVE-2026-41125) in the KACO Meteor server enabling privilege escalation. Siemens has released firmware updates for select models and recommends network isolation for affected devices.
NAVTOR NavBox (CVE-2026-21404) NAVTOR NavBox versions 4.16.1.20 and prior contain a hard-coded credentials vulnerability (CVE-2026-21404) within the Windows Communication Foundation (SOAP) implementation. A local attacker can extract these credentials to authenticate against the SOAP interface, gaining access to privileged WCF methods to write or overwrite files within application-defined paths, potentially causing operational disruption.
Hitachi Energy MACH HiDraw (CVE-2026-7310) Hitachi Energy MACH HiDraw versions 9.22 and prior contain a heap-based buffer overflow vulnerability (CVE-2026-7310, CVSS 5.5) in their XML parser functionality. An authenticated local attacker can exploit this by tricking a user into opening a crafted XML file, potentially leading to denial of service or arbitrary code execution.
Hitachi Energy ITT600 Explorer (CVE-2024-8176, CVE-2025-59375) Hitachi Energy ITT600 Explorer contains two high-severity vulnerabilities (CVE-2024-8176, CVE-2025-59375) within its libexpat library implementation. These flaws, triggered via crafted IEC61850 messages or documents during server simulation, can lead to uncontrolled recursion and resource exhaustion, resulting in Denial of Service (DoS) or memory corruption.
MacGregor Voyage Data Recorder (VDR) G4e (CVE-2026-42941, CVE-2026-42951, CVE-2026-44611 +2 more) CISA released an advisory detailing multiple vulnerabilities in Danelec's MacGregor Voyage Data Recorder (VDR) G4e devices, including default and hard-coded credentials, weak password hashing, and insecure file access. Exploitation of these flaws could allow an attacker on an adjacent network to gain full administrator access to the affected transportation sector devices. Danelec has released firmware version V5.250 to address these vulnerabilities.
Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter A critical vulnerability (CVE-2026-7786, CVSS 9.8) affects the Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter. The device firmware version 7.03T.07 contains hard-coded plaintext administrative credentials, allowing unauthenticated remote attackers to extract the credentials and gain full administrator access to the device. The vendor has not responded to coordination attempts, necessitating immediate network isolation of affected devices.
Schnieider Electric EcoStruxure Machine Expert HVAC Schneider Electric EcoStruxure Machine Expert HVAC versions prior to 1.10.0 are affected by a cleartext storage vulnerability (CVE-2026-6332, CVSS 5.5). This flaw allows an authorized local attacker accessing the software to view sensitive information, leading to the potential disclosure of protected source code and a loss of confidentiality. Updating to version 1.10.0 resolves the issue.
ABB EIBPORT ABB EIBPORT building management systems running firmware prior to version 3.9.2 contain a high-severity Cross-Site Scripting (XSS) vulnerability (CVE-2021-22291). Successful exploitation allows attackers to steal session IDs, leading to unauthenticated device access, sensitive information disclosure, and unauthorized configuration changes.
ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) ABB B&R Automation Runtime contains a critical Improper Resource Locking vulnerability (CVE-2025-3450) within its System Diagnostics Manager (SDM) component. An unauthenticated, remote attacker can exploit this flaw by sending a specially crafted message over the network to delete data, resulting in a denial-of-service condition that halts the affected system node.
Eppendorf BioFlo 320 Eppendorf BioFlo 320 bioreactors are affected by a critical vulnerability (CVE-2026-7251, CVSS 9.8) involving a hard-coded password in the VNC server. If VNC is enabled, remote attackers can exploit this flaw to gain full control over the bioreactor's user interface and data. Eppendorf has released a software update (Version 5.0) that permanently removes VNC functionality to mitigate the risk.
ABB Ability Camera Connect ABB Ability Camera Connect versions 1.5.0.14 and earlier contain multiple critical and high-severity vulnerabilities due to an outdated bundled VLC media player component. These flaws, including buffer overflows and integer underflows, could allow an attacker to execute arbitrary code or cause a denial of service via crafted media files. The risk is significantly reduced as the application is typically deployed in isolated, air-gapped ICS environments.
ABB LVS MConfig ABB LVS MConfig versions 1.4.9.21 and prior contain a high-severity vulnerability (CVE-2025-9970) where user credentials are stored in cleartext in application memory. An attacker with local or physical access to the host machine can export a memory dump during runtime to extract these passwords, potentially allowing unauthorized modification of low voltage switchgear components.
ABB Terra AC ABB Terra AC wallbox EV chargers are affected by a heap-based buffer overflow vulnerability (CVE-2025-5517, CVSS 6.8) due to improper length validation of OCPP fields. An attacker who hijacks the OCPP backend or intercepts unencrypted HTTP traffic can send crafted messages to execute arbitrary code, alter firmware, or cause a denial of service.
Cyber Centre Daily Advisory Digest — 2026-05-25 (7 advisories) The Canadian Centre for Cyber Security released a daily advisory digest summarizing security updates from IBM, Roundcube, Dell, Ubuntu, CISA (ICS), Red Hat, and cPanel. Organizations are strongly encouraged to review the respective vendor advisories and apply available patches to mitigate potential vulnerabilities across enterprise, cloud, and industrial control systems.
ABB Terra AC Wallbox ABB Terra AC Wallbox (JP) versions 1.8.33 and prior are affected by multiple buffer overflow vulnerabilities (CVE-2025-10504, CVE-2025-12142, CVE-2025-12143) with a CVSS score of 6.1. Successful exploitation requires a threat actor to hijack the Bluetooth connection, potentially allowing them to pollute memory, alter firmware behavior, and take remote control of the device.
ABB B&R Automation Studio ABB has disclosed multiple vulnerabilities in B&R Automation Studio versions prior to 6.5, stemming from an outdated third-party SQLite component. These flaws, which include heap-based buffer overflows and integer overflows, could potentially be exploited to achieve remote code execution, data exposure, or denial of service, though no active exploitation has been observed.
Cyber Centre Daily Advisory Digest — 2026-05-19 (2 advisories) The Canadian Centre for Cyber Security (CCCS) released a daily digest highlighting recent security advisories for various Industrial Control Systems (ICS) and Microsoft Edge. Organizations are advised to review the specific CISA ICS advisories for products from ABB, Siemens, and others, and to update Microsoft Edge to version 148.0.3967.70 or later.
Cyber Centre Daily Advisory Digest — 2026-05-11 (5 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting critical vulnerabilities across Cisco, IBM, Dell, Ubuntu, and various ICS platforms. Notably, Cisco ASA and FTD devices are affected by a newly identified persistence mechanism known as the FIRESTARTER backdoor, which survives previous patches for CVE-2025-20333, CVE-2025-20362, and CVE-2025-20363.
Cyber Centre Daily Advisory Digest — 2026-05-04 (5 advisories) The Canadian Centre for Cyber Security released a daily digest of five security advisories covering critical vulnerabilities across IBM, Dell, FreeBSD, Ubuntu, and various ICS products. Notable flaws include a Remote Code Execution vulnerability in FreeBSD via malicious DHCP options (CVE-2026-42511) and a Local Privilege Escalation via execve() (CVE-2026-7270).
Cyber Centre Daily Advisory Digest — 2026-04-27 (9 advisories) The Canadian Centre for Cyber Security released a daily digest of nine security advisories covering critical vulnerabilities across enterprise software, Linux kernels, and industrial control systems (ICS). Organizations are urged to apply patches for affected products from vendors including IBM, Dell, Ubuntu, Red Hat, Moxa, VMware, Notepad++, and Microsoft to prevent potential exploitation.
Cyber Centre Daily Advisory Digest — 2026-04-20 (6 advisories) The Canadian Centre for Cyber Security published a daily digest of six security advisories on April 20, 2026. The advisories cover critical vulnerabilities and updates for various IBM, Dell, Ubuntu, Red Hat, and ICS/SCADA products, including a specific NTP vulnerability (CVE-2020-11868) in Moxa Ethernet switches.
Why East-West Visibility Matters for Grid Security The convergence of IT and OT in electric grid infrastructure has increased the risk of lateral movement by adversaries. To protect critical operations and comply with regulations like NERC-CIP-15, organizations must implement deep east-west network visibility capable of understanding specialized industrial protocols.
Alert: NCSC advises UK organisations to take action following conflict in the Middle East The NCSC has issued an alert advising UK organizations, particularly those with ties to the Middle East, to bolster their cybersecurity posture amid ongoing regional conflicts. While direct threats to the UK remain low, there is a heightened risk of collateral damage from Iran-linked hacktivists utilizing DDoS, phishing, and ICS targeting.