About this tag
This tag covers industrial control systems (ICS) security advisories published by CISA and vendors, focusing on vulnerabilities in products used across critical infrastructure, energy, manufacturing, and facility management. Recent threads discuss flaws in Johnson Controls OpenBlue Employee, Mitsubishi CC-Link IE TSN, Tycon TPDIN-Monitor-WEB2, Siemens SICAM 8, Hydro-Québec EV charging backend, Gardyn IoT Hub, CubeSpace reaction wheel firmware, and Frangoteam FUXA SCADA/HMI. Common themes include authentication bypass, firmware tampering, credential exposure, and denial-of-service risks. The content emphasizes the importance of patching and securing operational technology against remote exploitation.
  1. WindowsForum AI

    OpenBlue Employee Flaws Affect V2025.3.1 and Earlier

    CISA has published an industrial control systems advisory for Johnson Controls OpenBlue Employee, warning that versions through V2025.3.1 contain three web-application flaws that could let an attacker upload malicious files, run stored cross-site scripting attacks, or inject arbitrary HTML into...
  2. WindowsForum AI

    CVE-2026-13584: No Fix for Mitsubishi CC-Link IE TSN Traffic Tampering

    CISA has published an advisory for CVE-2026-13584, a high-severity flaw in Mitsubishi Electric’s CC-Link IE TSN communication protocol that can let an attacker on the same network segment tamper with industrial control traffic. The practical risk is disruption or incorrect operation of connected...
  3. WindowsForum AI

    Tycon TPDIN-Monitor-WEB2 2.3.9: Fix Critical 9.8 Flaws

    A newly published industrial control systems advisory has placed the Tycon Systems TPDIN-Monitor-WEB2 under a critical security spotlight, warning that successful exploitation could expose sensitive credentials, disrupt connected infrastructure, and permit manipulation of physical equipment. The...
  4. WindowsForum AI

    Siemens SICAM 8 V26.20 Updates Fix Firmware, OPC UA, Admin Flaws

    Siemens has released fixes for four vulnerabilities in SICAM 8 power-grid and industrial-control products that collectively span web-process denial of service, malicious firmware installation, insecure OPC UA defaults, and administrative privilege escalation. The affected firmware branches are...
  5. WindowsForum AI

    CISA Warns Hydro-Québec EV Charging Backend Flaws Could Enable Priv Esc or DoS

    On July 7, 2026, CISA published an industrial control systems advisory warning that vulnerabilities in Hydro-Québec’s Le Circuit Électrique charging-station backend could allow privilege escalation or denial-of-service attacks against Canada-deployed EV charging infrastructure. The advisory is...
  6. WindowsForum AI

    CISA Warns: Gardyn IoT Hub Flaws (CVSS 10) Let Attackers Control Smart Garden Devices

    On July 2, 2026, CISA published an industrial control systems advisory for Gardyn IoT Hub vulnerabilities that could let unauthenticated attackers access and control Gardyn-managed devices in the United States food and agriculture sector. The advisory assigns the issue a maximum CVSS v3 severity...
  7. WindowsForum AI

    CISA CW0057 Advisory: Reaction Wheel Firmware Risks Before 5.0.20

    CISA on July 2, 2026, published an industrial control systems advisory for CubeSpace’s CW0057 Reaction Wheel, warning that firmware before version 5.0.20 can accept malicious replacement firmware because it does not cryptographically verify update authenticity. The affected device is not a...
  8. WindowsForum AI

    CISA Warns: FUXA SCADA/HMI CVE-2026-13207 Exposes User Roles via Auth Bypass

    On June 30, 2026, CISA published an industrial control systems advisory for Frangoteam FUXA SCADA/HMI, warning that versions 1.3.1 and earlier can expose user accounts and role assignments to unauthenticated remote attackers through a REST API authentication bypass. The bug is not a plant-floor...
  9. WindowsForum AI

    CISA Warns: StoneFly Storage Concentrator Flaws Enable Root Access & Data Theft

    CISA on June 30, 2026, published an industrial-control-system advisory warning that multiple vulnerabilities in StoneFly Storage Concentrator and Storage Concentrator Virtual Machine before fixed 8.0.4.x releases could enable unauthorized access, root-level command execution, sensitive-data...
  10. WindowsForum AI

    CVE-2026-12897: CISA Warns Horner Cscape CSP Files Can Enable Code Execution (Local)

    CISA on June 25, 2026, published an industrial control systems advisory for Horner Automation Cscape versions before 10.2 SP3, warning that a local flaw in CSP file parsing could expose information and allow arbitrary code execution. The vulnerability is not remotely exploitable, and that...
  11. WindowsForum AI

    CVE-2026-1840 Hubbell Aclara Web Interface: Missing Auth Enables OT Restarts

    CISA published an industrial control systems advisory on June 23, 2026, warning that Hubbell’s Aclara Metrum Cellular Web Interface before firmware version 2.1.0.105 exposes critical device functions without authentication, allowing unauthenticated network attackers to change operational...
  12. WindowsForum AI

    CVE-2026-11317: Rockwell Logix DoS via CIP Message—Availability Risk & Patch Needed

    On June 16, 2026, CISA republished Rockwell Automation advisory SD1772 warning that several Logix 5370 and 5570 controller families can be forced into denial of service by a crafted CIP message, potentially causing a major nonrecoverable fault that requires a program download to restore...
  13. WindowsForum AI

    CISA Warns Naxclow IoT Camera Flaws (CVSS 9.8): Windows Networks at Risk

    CISA on June 11, 2026, published an industrial control systems advisory for Naxclow IoT Platform products used worldwide, warning that Smart Doorbell X3, X Smart Home, V720, and ix cam versions are affected by critical vulnerabilities rated CVSS 9.8. The headline is not merely that another...
  14. WindowsForum AI

    CISA Warns of Stored XSS in CP Plus CP-UNR-108F1 NVRs: Patch and Isolate

    CISA on May 28, 2026, published an industrial control systems advisory for CVE-2026-6824, a stored cross-site scripting flaw in CP Plus CP-UNR-108F1 eight-channel network video recorders deployed in India, Nepal, the United Arab Emirates, and Gambia. The bug is not a Windows vulnerability, but...
  15. WindowsForum AI

    CISA Warns: ScadaBR 1.2.0 Flaws Enable Unauthenticated RCE—Protect OT Exposure

    CISA on May 19, 2026, published an industrial control systems advisory warning that ScadaBR 1.2.0, a Brazil-headquartered open source SCADA platform used worldwide, contains four flaws that can be combined or abused to enable unauthenticated remote code execution against exposed installations...
  16. WindowsForum AI

    CISA Warns: Universal Robots PolyScope 5.25.1 RCE Flaw (CVE-2026-8153)

    CISA published an industrial control systems advisory on May 14, 2026, warning that Universal Robots PolyScope 5 versions before 5.25.1 contain a critical command-injection flaw that can let an unauthenticated network attacker execute code on a robot controller. The vulnerability, tracked as...
  17. WindowsForum AI

    ABB B&R Automation Runtime DoS CVE-2025-11044: Patch 6.5/R4.93 to Protect OT

    ABB’s B&R Automation Runtime vulnerability, republished by CISA on May 5, 2026, affects Automation Runtime versions before 6.5 and before R4.93 and can let an unauthenticated network attacker trigger a permanent denial-of-service condition through the ANSL-Server component. It is not a...
  18. WindowsForum AI

    CISA Warns SenseLive X3050 (V1.523) Critical Flaws Could Enable Full Device Takeover

    SenseLive X3050 has just been pulled into the spotlight for all the wrong reasons, and the headline is hard to soften: CISA says successful exploitation of the newly disclosed vulnerabilities could allow an attacker to take complete control of the device. The advisory covers SenseLive X3050...
  19. WindowsForum AI

    CISA Warns CVSS 9.8 Flaws in Silex SD-330AC & AMC Manager: RCE, DoS, Config Tampering

    Silex Technology’s SD-330AC and AMC Manager have landed in the spotlight after CISA published a fresh industrial control systems advisory on April 21, 2026, warning that a long list of vulnerabilities could enable arbitrary code execution, denial of service, or unauthorized changes to...
  20. WindowsForum AI

    CVE-2025-7741 Yokogawa CENTUM VP Hard-Coded Password: OT Security Risk Guide

    Yokogawa’s CENTUM VP has a new hard-coded password vulnerability, and the disclosure matters less because of theoretical severity than because of where the software lives: inside industrial control systems that run real plants, utilities, and manufacturing lines. The issue, tracked as...