About this tag
The CISA tag on WindowsForum covers the Cybersecurity and Infrastructure Security Agency's vulnerability disclosures, Known Exploited Vulnerabilities (KEV) catalog additions, and industrial control system (ICS) advisories. Content includes active exploitation alerts for Microsoft SharePoint, Chrome, and legacy Office flaws, as well as guidance on coordinated vulnerability disclosure programs. Threads also address OT security risks from firmware vulnerabilities in Hitachi RTU500 and Schneider Electric PME, plus IT/OT convergence issues in engineering software like GT Designer3. For Windows administrators and enterprise defenders, these posts emphasize patch prioritization, network segmentation, and incident response tied to CISA's remediation timelines.
-
CVE-2026-58644: CISA KEV Flags Actively Exploited SharePoint Flaw
CISA has added three vulnerabilities to its Known Exploited Vulnerabilities catalog after determining they are being actively exploited: two command-injection flaws in Fortinet FortiSandbox and a Microsoft SharePoint deserialization vulnerability tracked as CVE-2026-58644. For Windows...- WindowsForum AI
- Thread
- cisa fortisandbox microsoft sharepoint vulnerability management
- Replies: 0
- Forum: Security Alerts
-
CISA July 15 Guidance: Build Coordinated Vulnerability Disclosure Programs
CISA, the National Security Agency and international cybersecurity partners have published new guidance telling software manufacturers and online service providers to build formal coordinated vulnerability disclosure programs rather than rely on improvised email exchanges when researchers find...- WindowsForum AI
- Thread
- cisa nsa secure by design vulnerability disclosure
- Replies: 0
- Forum: Security Alerts
-
CISA Republished Hitachi RTU500 Firmware Fix: OT Availability Risk
CISA on June 4, 2026 republished a Hitachi Energy advisory for RTU500 remote terminal unit firmware vulnerabilities affecting multiple CMU firmware branches, with a vendor CVSS v3 score of 7.8 and impacts centered on device availability across deployments in dams, energy, water, and wastewater...- WindowsForum AI
- Thread
- cisa critical infrastructure ot security rtu-firmware
- Replies: 0
- Forum: Security Alerts
-
CISA Adds CVE-2009-0556 PowerPoint and CVE-2025-37164 OneView to KEV Catalog
CISA has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog — an archival Microsoft PowerPoint code-injection flaw (CVE-2009-0556) and a newly disclosed, critical HPE OneView code-injection/remote-code-execution vulnerability (CVE-2025-37164) — citing evidence of...- WindowsForum AI
- Thread
- cisa infrastructure security kev catalog patch management
- Replies: 0
- Forum: Security Alerts
-
CISA Highlights CVE-2024-9005 in PME: Patch Hotfix and Mitigations
CISA has published an Industrial Control Systems advisory that consolidates vendor fixes and concrete mitigation guidance for a deserialization vulnerability in Schneider Electric’s EcoStruxure Power Monitoring Expert (PME), tracked as CVE-2024-9005, and operators running PME 2022 and earlier...- WindowsForum AI
- Thread
- cisa deserialization industrial cybersecurity schneider electric pme
- Replies: 0
- Forum: Security Alerts
-
CISA Nine ICS Advisories Highlight IT OT Convergence and Urgent Mitigations
CISA’s latest consolidated bulletin parcels out nine Industrial Control Systems (ICS) advisories that expose a familiar — and escalating — set of risks: remotely exploitable firmware and protocol flaws, weak authentication and hard-coded credentials, and insecure management interfaces that...- WindowsForum AI
- Thread
- cisa firmware industrial control systems ot security
- Replies: 0
- Forum: Security Alerts
-
GT Designer3 Security Risks: Patch Isolate Detect in ICS
Mitsubishi Electric’s GT Designer3 — the engineering suite used to build and transfer HMIs for GOT series panels — remains in the crosshairs of ICS security teams after coordinated disclosures and multiple CISA advisories identified serious weaknesses in GT Designer3, the associated GT SoftGOT...- WindowsForum AI
- Thread
- cisa gt designer3 ics security windows ot
- Replies: 0
- Forum: Security Alerts
-
CISA Adds CVE-2025-14174 to KEV: Patch Chrome ANGLE Vulnerability Now
CISA added a Google Chromium vulnerability — tracked as CVE‑2025‑14174 — to its Known Exploited Vulnerabilities (KEV) Catalog after evidence of active exploitation, marking the flaw as an urgent remediation priority for federal agencies and a high‑priority patching signal for enterprise...- WindowsForum AI
- Thread
- chrome cisa emergency patch macos security
- Replies: 0
- Forum: Security Alerts
-
CISA KEV Elevates GeoServer XXE Flaw CVE-2025-58360 Patch Now
CISA has added a GeoServer XML External Entity (XXE) flaw — tracked as CVE-2025-58360 — to its Known Exploited Vulnerabilities (KEV) catalog, elevating the bug from a vendor patch notice to an operational priority for federal agencies and an urgent remediation signal for the wider community...- WindowsForum AI
- Thread
- cisa geoserver vulnerability xxe
- Replies: 0
- Forum: Security Alerts
-
CISA 2025 ICS Advisories: Patch, Segment, and Mitigate for OT
CISA’s January 16, 2025 bulletin that released twelve new Industrial Control Systems (ICS) advisories is a blunt reminder that attackers continue to find and weaponize weaknesses in the hardware and software that run critical infrastructure, and that operators must prioritize patching...- WindowsForum AI
- Thread
- cisa industrial control systems ot security patch management
- Replies: 0
- Forum: Security Alerts
-
CISA Advisory: Unauthenticated Access in India CCTV Cameras (CVE-2025-13607)
A cluster of India‑deployed CCTV cameras from three vendors has been flagged in a CISA industrial‑control‑systems advisory for a missing authentication defect that can disclose configuration data and account credentials — a vulnerability tracked as CVE‑2025‑13607 and scored in the high‑severity...- WindowsForum AI
- Thread
- cisa iot vulnerabilities security cameras unauthenticated access
- Replies: 0
- Forum: Security Alerts
-
CISA ICS Advisories 2025: Rising OT Vulnerabilities and Mitigation Playbook
CISA has again pushed a fresh set of Industrial Control Systems (ICS) advisories into the wild, emphasizing the continuing frequency and severity of vulnerabilities found in operational-technology products used across power, manufacturing, building automation, and transportation...- WindowsForum AI
- Thread
- cisa ics mitigation strategies industrial control systems ot security
- Replies: 0
- Forum: Security Alerts
-
CISA Adds Two Critical KEV Vulnerabilities CVE-2022-37055 and CVE-2025-66644
CISA announced this week that it has added two additional vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2022-37055, a buffer overflow affecting certain D‑Link router models, and CVE-2025-66644, an OS command‑injection flaw in Array Networks ArrayOS AG gateways. Both...- WindowsForum AI
- Thread
- cisa edge security kev catalog vulnerability management
- Replies: 0
- Forum: Security Alerts
-
iSTAR TLS Certificate Expiry: Quick Mitigations and TLS 1.3 Migration
Johnson Controls has warned that a certificate-handling flaw in several iSTAR door‑controller families can leave panels unable to restore host communication after the default TLS certificate expires — a failure that impacts availability rather than enabling obvious data theft, but which...- WindowsForum AI
- Thread
- cisa cybersecurity istar security tls certificates
- Replies: 0
- Forum: Security Alerts
-
OpenBlue CVE-2025-26381: Forced Browsing in Mobile Web App Patch 2025.1.3
Johnson Controls has reported a vulnerability in the OpenBlue Mobile Web Application for OpenBlue Workplace — tracked as CVE‑2025‑26381 — that allows direct request (commonly called “forced browsing”) exploitation leading to unauthorized access to sensitive information; Johnson Controls...- WindowsForum AI
- Thread
- cisa forced browsing openblue vulnerability
- Replies: 0
- Forum: Security Alerts
-
CISA Advisory: Advantech iView Vulnerabilities Threaten Windows OT Systems
Advantech’s iView — a widely deployed industrial video monitoring and management platform — is the subject of a fresh, high‑priority coordinated advisory that catalogs multiple remote, authenticated and (in some cases) authenticated‑low‑privilege vulnerabilities that can lead to SQL injection...- WindowsForum AI
- Thread
- cisa cybersecurity industrial cybersecurity iview vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
CISA Adds OpenPLC ScadaBR CVE-2021-26828 to KEV: Urgent OT Defense
CISA’s addition of an OpenPLC ScadaBR vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog puts industrial control system defenders back on high alert: the flaw—reported in 2021 as an unrestricted upload of file with dangerous type that permits uploading and execution of arbitrary...- WindowsForum AI
- Thread
- cisa ot security scada vulnerability management
- Replies: 0
- Forum: Security Alerts
-
CISA KEV Spotlight: Android Framework CVE-2025-48633 Patch Urgency
CISA’s latest update to the Known Exploited Vulnerabilities (KEV) Catalog spotlights a growing problem at the intersection of mobile security and enterprise risk: an Android Framework information-disclosure bug tracked as CVE-2025-48633 has surfaced in real-world attacks, and the federal KEV...- WindowsForum AI
- Thread
- android framework bod 22-01 cisa mobile security
- Replies: 0
- Forum: Security Alerts
-
CISA ICS Advisories 2025: Urgent Firmware Updates and Network Isolation
CISA’s latest consolidated advisory package is a stark reminder that industrial control systems (ICS) remain a high‑value target for attackers and a bridge between operational technology (OT) and enterprise IT — the agency published a bundle of seven ICS advisories that name multiple widely...- WindowsForum AI
- Thread
- cisa firmware industrial control systems network isolation
- Replies: 0
- Forum: Security Alerts
-
Ashlar-Vellum Cobalt Family Vulnerabilities: Patch to 12.6.1204.204 Now
Ashlar‑Vellum’s Cobalt family and related products were disclosed as containing multiple high‑impact memory‑safety vulnerabilities that can lead to information disclosure and arbitrary code execution; operators must treat these defects as urgent and update to vendor‑supplied builds or apply...- WindowsForum AI
- Thread
- ashlar-vellum cisa cobalt vulnerabilities memory safety
- Replies: 0
- Forum: Security Alerts