Updated just now · 12 advisories
An attacker with local access to a system during OPC UA LDS installation could execute arbitrary commands with elevated privileges, potentially compromising the integrity of the system and any connected industrial devices.
Any user with access to the Ignition gateway can create new projects without authorization, potentially allowing unauthorized modifications to control logic, data flows, or HMI screens that direct plant operations.
An attacker could send a crafted EtherNet/IP message to cause memory corruption or crash a device running the vulnerable NetStaX stack, potentially disrupting automation control or data collection without any error indication to the receiving device.
An attacker could intercept monitoring data, reset the device to factory defaults, erase credentials, or access sensitive configuration and system information. This could compromise visibility into critical infrastructure operations and allow unauthorized reconfiguration of monitoring parameters.
An attacker can crash the 1756-ENBT module remotely, causing your control network to lose connectivity until the device is manually restarted. This disrupts communication between your PLCs and engineering workstations, halting automated processes.
An attacker could gain unauthorized access to the OPC UA server component in mapp Audit, potentially allowing them to read process data, modify control parameters, or disrupt operations on connected manufacturing systems.
An attacker could delete files with system privileges, overwrite license server configuration, crash the CodeMeter licensing service and leak sensitive data from process memory (including cryptographic canaries), or read license information. For ABB automation engineers, this means unauthorized changes to system files, potential service outages for license management, and information disclosure that could aid further attacks.
An unauthenticated attacker could hijack user accounts in Mendix applications that use SAML for single sign-on authentication, potentially gaining unauthorized access to sensitive operational data and applications.
An attacker with network access to an IOS XR device could exploit these vulnerabilities to gain unauthorized access, execute code, or cause the device to become unavailable, potentially disrupting routing and network operations across your infrastructure.
An attacker could crash the 1756-ENBT Ethernet module, causing a complete loss of network communication for any CompactLogix or ControlLogix PLC connected to it. This would stop all remote monitoring and control operations until the module is manually rebooted.
An attacker with network access to an ArmorStart LT device could execute arbitrary code or disrupt its soft starter functionality, potentially causing uncontrolled motor starts or process interruptions in production equipment.
An attacker on your network could connect directly to ControlFLASH and perform unauthorized firmware updates or configuration changes without credentials, potentially compromising controller logic and causing uncontrolled process behavior or shutdown.
An attacker with network access to a Rockwell Historian device could execute arbitrary code on the device, potentially taking control of your historical data logging and reporting system or causing it to crash and stop recording process data.
A remote attacker can send specially crafted network packets to a Rockwell Automation controller (ControlLogix, CompactLogix, GuardLogix) causing the device to stop responding and halt production or safety-critical processes until manually restarted.
An attacker with local access to a workstation running FactoryTalk Activation Manager could exploit weak credential storage to gain access to factory automation systems and potentially modify or disable production controls.
An attacker with network access to a ControlLogix, CompactLogix, GuardLogix, or Compact GuardLogix controller could cause a denial of service by crashing the PLC firmware, halting production and control logic execution until the device is manually restarted.
An attacker on the network could crash RSLinx Classic, disrupting communication with programmable logic controllers (PLCs) and halting real-time monitoring and control of industrial processes until the service is manually restarted.
An attacker with local access to a machine running the Redundancy Module Configuration Tool could escalate privileges and run commands as an administrator, potentially allowing them to modify redundancy settings, disable failover protection, or compromise PLC configurations.
An attacker who reaches the NA111-M device over the network could execute arbitrary commands with full device privileges, potentially compromising measurements, communications, or control functions depending on how the device is integrated into your operations.
An attacker with network access could read or modify files on the ASE2000 system, intercept and alter communications with connected devices, or force the system to make unauthorized outbound network requests. This could compromise the integrity of process data or allow command injection into connected IEC 60870-5-104 devices.
An attacker could execute arbitrary commands on your Fuel-Boss system, potentially allowing them to modify fuel dispensing parameters, alter transaction records, or disrupt refueling operations at your facility.
An attacker with network access to the LK100W could gain full remote control of the device, allowing them to manipulate device settings, alter operational parameters, or disable normal function without authentication.
An operator viewing a malicious map link in Element maps-ng could have their browser session compromised, allowing an attacker to steal credentials, modify plant data displays, or inject false operator commands.
This is an advance notice only; actual vulnerabilities and impacts are not yet disclosed. Until the September 2, 2026 advisories are published, affected Cisco products (IOS XR, Nexus 9000 switches, Secure Email, and SIP software) carry unknown security risks that could potentially impact network infrastructure and communications systems.
An attacker could alter AIS transponder settings on your vessel or offshore asset, potentially disabling or spoofing maritime position and identification broadcast. This could affect navigation safety, collision avoidance, and regulatory compliance for vessel tracking.
An attacker with network access could gain administrative control of the NE2-D11 device, read sensitive configuration data, modify network or process settings, or take the device offline entirely. This could disrupt communications or control functions across connected industrial systems.
An attacker could disable critical safety functions in the vehicle braking system, including ABS, steering assist, traction control, and speedometer, creating immediate risk of loss of control and collision.
An attacker with network access could read sensitive data from PayRange payment terminals, disable them, or alter what they display to customers—disrupting payment processing and potentially tampering with transaction information.
An attacker with user-level web access could run arbitrary commands on your Zoneminder server with the permissions of the web server process, allowing them to access recorded video, modify system configurations, or disrupt video surveillance operations.
An attacker with valid user credentials could access sensitive information stored in the Smart Home system and bypass permission controls, potentially exposing tenant or property data and allowing unauthorized modifications to access rules.
A local attacker with low privileges could extract user credentials from system memory, potentially gaining unauthorized access to the Incident Manager and connected building systems. This could allow them to alter alarm configurations, disable alerts, or access other networked systems that depend on this application.
An attacker with access to the OTTO Fleet Manager database could crack user passwords due to weak hashing, potentially gaining unauthorized access to the fleet management system and the autonomous mobile robots it controls.
An authenticated attacker could inject malicious code into the switch's web interface that executes when other authorized users access it, potentially allowing them to capture credentials or perform unauthorized configuration changes to your network switches.
An attacker could flood your IE 1000 Series Switch with traffic, making the management interface (web, SSH, or API) unavailable. Your operators would be unable to configure the switch or monitor its status, but data traffic through the switch would continue normally.
An attacker with network access to the TLS connection could potentially cause a denial-of-service condition by forcing repetitive TLS renegotiations, disrupting communication with the affected device. Data confidentiality and integrity are not compromised by this issue.
An attacker with valid credentials could execute arbitrary code on the Malcolm system or cause it to become unavailable, potentially disrupting network traffic analysis and security monitoring operations.
An attacker within Bluetooth range could manipulate brain stimulation settings and bypass safety limits on the FL-100 device, potentially causing harmful electrical stimulation or device malfunction.
An attacker with low-privilege access could inject malicious code into Metasys that runs in other users' sessions, including administrators, potentially allowing them to hijack accounts and gain unauthorized control of building automation systems.
An attacker on the local network could read sensitive data from the HIPASE-250 device or compromise connected engineering workstations, potentially exposing control system configuration or process parameters.
An attacker with local access to an Airwall device could decrypt sensitive data and bypass authentication controls, potentially reading arbitrary files or accessing protected system resources.
An attacker could run commands with root-level access on your HMI gateway, potentially allowing them to modify process parameters, stop production systems, or compromise other connected industrial devices on your network.
An attacker with engineering workstation credentials could tamper with serialized data sent to AVEVA Enterprise SCADA servers, leading to arbitrary code execution and potential control of industrial processes including shutdowns or unsafe setpoint changes.
This is an advance notification only; no vulnerabilities have been disclosed yet. Cisco will publish security advisories on August 19, 2026 for multiple products including firewalls, contact center systems, network switches, and collaboration platforms. Impact will be determined when the full advisories are released.
An attacker without authentication could run commands on PLCnext controllers, disrupt operations through denial of service, or bypass access controls—affecting production lines, water treatment processes, or power distribution automation. Integrity and confidentiality of control logic and operational data are at risk.
An attacker with network access to FortiManager could bypass authentication and issue commands that make it accept unauthorized Fortinet devices, allowing the attacker to masquerade as a trusted firewall and intercept or redirect traffic destined for your protected networks.
An attacker can send specially crafted HTTP/2 requests to cause a denial of service, making the affected gateway or access control device unavailable and disrupting network traffic or administrative access to critical systems.
An authenticated admin on FortiSIEM could use the vulnerability to make unauthorized requests to internal systems and cloud services that the FortiSIEM server can reach, potentially accessing sensitive data or triggering unintended actions on those systems.
An attacker could overflow a buffer in the WAD (Web Application Delivery) service to crash the FortiGate appliance or potentially execute arbitrary code, disrupting network connectivity and security services for your facility.
An attacker can send specially crafted network requests to cause the FortiGate web management interface to become unresponsive, preventing administrators from accessing the firewall's configuration and monitoring capabilities.
An attacker positioned on the network between a user and the VPN gateway could intercept and modify GlobalProtect app communications, potentially stealing credentials or session tokens used for authentication. VPN tunnel traffic itself remains encrypted and is not affected.