Category index

Cyber Security

4276 articles

4276 ARTICLES

FEATURED REPORT

Mitsubishi Electric CC-Link IE TSN Communication Protocol

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly. The following versions of Mitsubishi Electric CC-Link IE TSN Communication Protocol are affected: Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-16 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-32 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-64 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-128 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-256 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-N32 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-P32 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-N32 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-P32 vers:all/* (CVE-2026-13584) Mitsubishi Electric Master/local module RJ71GN11-T2 vers:all/* (CVE-2026-13584) Mitsubishi Electric Master/local module RJ71GN11-SX vers:all/* (CVE-2026-13584) Mitsubishi Electric Master/local module RJ71GN11-EIP vers:all/* (CVE-2026-13584) Mitsubishi Electric Master/local module FX5-CCLGN-MS vers:all/* (CVE-2026-13584) Mitsubishi Electric CC-Link IE TSN interface board NZ81GN11-SX vers:all/* (CVE-2026-13584) Mitsubishi Electric CC-Link IE TSN interface board NZ81GN11-T2 vers:all/* (CVE-2026-13584) Mitsubishi Electric Motion module RD78G4 vers:all/* (CVE-2026-13584) Mitsubishi Electric Motion module RD78G8 vers:all/* (CVE-2026-13584) Mitsubishi Electric Motion module RD78G16 vers:all/* (CVE-2026-13584) Mitsubishi Electric Motion module RD78G64 vers:all/* (CVE-2026-13584) Mitsubishi Electric Motion module RD78GHV vers:all/* (CVE-2026-13584) Mitsubishi Electric Motion module RD78GHW vers:all/* (CVE-2026-13584) Mitsubishi Electric Motion module FX5-40SSC-G vers:all/* (CVE-2026-13584) Mitsubishi Electric Motion module FX5-80SSC-G vers:all/* (CVE-2026-13584) Mitsubishi Electric Motion Control Board MR-EM441G vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GN2S1-32D vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GN2S1-32T vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GN2S1-32TE vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GN2S1-32DT vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GN2S1-32DTE vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GN2B1-32D vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GN2B1-32T vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GN2B1-32TE vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GN2B1-32DT vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GN2B1-32DTE vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GNCF1-32D vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GNCF1-32T vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GNCE3-32D vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GNCE3-32DT vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GN12A4-16D vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GN12A4-16DE vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GN12A2-16T vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GN12A2-16TE vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GN12A42-16DT vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GN12A42-16DTE vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GN2S1-16D vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GN2S1-16T vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GN2S1-16TE vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GN2B1-16D vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GN2B1-16T vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module NZ2GN2B1-16TE vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8D vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8D-K vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8TE vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8TE-K vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-16DTE vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-16DTE-K vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module with safety functions NZ2GNS12A2-14DT vers:all/* (CVE-2026-13584) Mitsubishi Electric Block-type remote module with safety functions NZ2GNS12A2-16DTE vers:all/* (CVE-2026-13584) Mitsubishi Electric Analog-Digital converter module NZ2GN2S-60AD4 vers:all/* (CVE-2026-13584) Mitsubishi Electric Analog-Digital converter module NZ2GN2B-60AD4 vers:all/* (CVE-2026-13584) Mitsubishi Electric Digital-Analog converter module NZ2GN2S-60DA4 vers:all/* (CVE-2026-13584) Mitsubishi Electric Digital-Analog converter module NZ2GN2B-60DA4 vers:all/* (CVE-2026-13584) Mitsubishi Electric CC-Link IE TSN compatible coupler NZ2FT-GN vers:all/* (CVE-2026-13584) Mitsubishi Electric FPGA module NZ2GN2S-D41P01 vers:all/* (CVE-2026-13584) Mitsubishi Electric FPGA module NZ2GN2S-D41D01 vers:all/* (CVE-2026-13584) Mitsubishi Electric FPGA module NZ2GN2S-D41PD02 vers:all/* (CVE-2026-13584) Mitsubishi Electric Tension meter LM7-1LG vers:all/* (CVE-2026-13584) Mitsubishi Electric Tension meter LM7-2LG vers:all/* (CVE-2026-13584) Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G vers:all/* (CVE-2026-13584) Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5W-G vers:all/* (CVE-2026-13584) Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-HS vers:all/* (CVE-2026-13584) Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-RJ vers:all/* (CVE-2026-13584) Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-LL vers:all/* (CVE-2026-13584) Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5D-G4 vers:all/* (CVE-2026-13584) Mitsubishi Electric AC Servo MELSERVO-J5 MR-MD333G vers:all/* (CVE-2026-13584) Mitsubishi Electric AC Servo MELSERVO-JET MR-JET-G vers:all/* (CVE-2026-13584) Mitsubishi Electric AC Servo MELSERVO-JET MR-JET-G4-HS vers:all/* (CVE-2026-13584) Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A8NCG vers:all/* (CVE-2026-13584) Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A8NCG-S vers:all/* (CVE-2026-13584) Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A800-GN vers:all/* (CVE-2026-13584) Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-E800-E vers:all/* (CVE-2026-13584) Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-E800-SCE vers:all/* (CVE-2026-13584) Mitsubishi Electric Industrial Robot CR800-D series controller Network Base Card 2F-DQ535-TSN vers:all/* (CVE-2026-13584) Mitsubishi Electric CC-Link IE TSN expansion unit FCU8-EX569 vers:all/* (CVE-2026-13584) Mitsubishi Electric CC-Link IE TSN-CC-Link IE Field Network bridge module NZ2GN-GFB vers:all/* (CVE-2026-13584) Mitsubishi Electric CC-Link IE TSN-AnyWireASLINK bridge module NZ2AW1GNAL vers:all/* (CVE-2026-13584) Mitsubishi Electric Energy Measuring Unit CC-Link IE TSN Communication Unit EMU4-CM-TSN vers:all/* (CVE-2026-13584) Mitsubishi Electric Industrial Computer MELIPC series MI2532-W vers:all/* (CVE-2026-13584) Mitsubishi Electric Industrial Computer MELIPC series MI2332-W vers:all/* (CVE-2026-13584) Mitsubishi Electric GOT3000 Series GT3715-FHCBD vers:all/* (CVE-2026-13584) Mitsubishi Electric GOT3000 Series GT3712-WXCBD vers:all/* (CVE-2026-13584) Mitsubishi Electric GOT3000 Series GT3715-XRBA vers:all/* (CVE-2026-13584) Mitsubishi Electric GOT3000 Series GT3715-XRBD vers:all/* (CVE-2026-13584) Mitsubishi Electric GOT3000 Series GT3712-XRBA vers:all/* (CVE-2026-13584) Mitsubishi Electric GOT3000 Series GT3712-XRBD vers:all/* (CVE-2026-13584) Mitsubishi Electric GOT3000 Series GT3710-XRBA vers:all/* (CVE-2026-13584) Mitsubishi Electric GOT3000 Series GT3710-XRBD vers:all/* (CVE-2026-13584) Mitsubishi Electric GOT3000 Series GT3708-XRBA vers:all/* (CVE-2026-13584) Mitsubishi Electric GOT3000 Series GT3708-XRBD vers:all/* (CVE-2026-13584) Mitsubishi Electric CC-Link IE TSN Communication Unit GT25-J71GN13-T2 vers:all/* (CVE-2026-13584) Mitsubishi Electric Motion Control Software SWM-G vers:all/* (CVE-2026-13584) Mitsubishi Electric Motion Control Software SWM-G-N1 vers:all/* (CVE-2026-13584) Mitsubishi Electric CC-Link IE TSN Communication Software for Windows SW1DND-CCIETCT-M vers:all/* (CVE-2026-13584) Mitsubishi Electric Master/Local module Designated communication LSI DeviceKit NZ2KT-NPETNG51 vers:all/* (CVE-2026-13584) Mitsubishi Electric Master/Local module Designated communication LSI NZ2GACP610-60 vers:all/* (CVE-2026-13584) Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP620-60 vers:all/* (CVE-2026-13584) Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP620-300 vers:all/* (CVE-2026-13584) Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP621-90 vers:all/* (CVE-2026-13584) Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP621-720 vers:all/* (CVE-2026-13584) Mitsubishi Electric CC-Link IE TSN Master/Local module Designated communication LSI SDK SW1DNN-GN610SRC-M vers:all/* (CVE-2026-13584) Mitsubishi Electric Remote station software development kit SW1DNC-GNSDK1S-M vers:all/* (CVE-2026-13584) Mitsubishi Electric Remote station software development kit SW1DNC-GNSDK2S-M vers:all/* (CVE-2026-13584) Mitsubishi Electric Liner Track System MTR-S series Linear track control module MTR-SCU00-4G vers:all/* (CVE-2026-13584) Mitsubishi Electric Liner Track System MTR-S series Linear track control module MTR-SCU00-PG vers:all/* (CVE-2026-13584) Mitsubishi Electric Analysis Support Software MELSOFT VIMA SW1DNN-VIMA-M vers:all/* (CVE-2026-13584) CVSS Vendor Equipment Vulnerabilities v3 7.1 Mitsubishi Electric Mitsubishi Electric CC-Link IE TSN Communication Protocol Improper Enforcement of Message Integrity During Transmission in a Communication Channel Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Japan Vulnerabilities Expand All + CVE-2026-13584 Improper Enforcement of Message Integrity During Transmission in a Communication Channel (CWE-924) vulnerability exists in the CC-Link IE TSN communication protocol. This vulnerability could allow an attacker with access to the same network segment to tamper with communication data, such as control input and output values, by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly. View CVE Details Affected Products Mitsubishi Electric CC-Link IE TSN Communication Protocol Vendor: Mitsubishi Electric Product Version: Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-16: vers:all/, Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-32: vers:all/, Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-64: vers:all/, Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-128: vers:all/, Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-256: vers:all/, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-N32: vers:all/, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-P32: vers:all/, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-N32: vers:all/, Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-P32: vers:all/, Mitsubishi Electric Master/local module RJ71GN11-T2: vers:all/, Mitsubishi Electric Master/local module RJ71GN11-SX: vers:all/, Mitsubishi Electric Master/local module RJ71GN11-EIP: vers:all/, Mitsubishi Electric Master/local module FX5-CCLGN-MS: vers:all/, Mitsubishi Electric CC-Link IE TSN interface board NZ81GN11-SX: vers:all/, Mitsubishi Electric CC-Link IE TSN interface board NZ81GN11-T2: vers:all/, Mitsubishi Electric Motion module RD78G4: vers:all/, Mitsubishi Electric Motion module RD78G8: vers:all/, Mitsubishi Electric Motion module RD78G16: vers:all/, Mitsubishi Electric Motion module RD78G64: vers:all/, Mitsubishi Electric Motion module RD78GHV: vers:all/, Mitsubishi Electric Motion module RD78GHW: vers:all/, Mitsubishi Electric Motion module FX5-40SSC-G: vers:all/, Mitsubishi Electric Motion module FX5-80SSC-G: vers:all/, Mitsubishi Electric Motion Control Board MR-EM441G: vers:all/, Mitsubishi Electric Block-type remote module NZ2GN2S1-32D: vers:all/, Mitsubishi Electric Block-type remote module NZ2GN2S1-32T: vers:all/, Mitsubishi Electric Block-type remote module NZ2GN2S1-32TE: vers:all/, Mitsubishi Electric Block-type remote module NZ2GN2S1-32DT: vers:all/, Mitsubishi Electric Block-type remote module NZ2GN2S1-32DTE: vers:all/, Mitsubishi Electric Block-type remote module NZ2GN2B1-32D: vers:all/, Mitsubishi Electric Block-type remote module NZ2GN2B1-32T: vers:all/, Mitsubishi Electric Block-type remote module NZ2GN2B1-32TE: vers:all/, Mitsubishi Electric Block-type remote module NZ2GN2B1-32DT: vers:all/, Mitsubishi Electric Block-type remote module NZ2GN2B1-32DTE: vers:all/, Mitsubishi Electric Block-type remote module NZ2GNCF1-32D: vers:all/, Mitsubishi Electric Block-type remote module NZ2GNCF1-32T: vers:all/, Mitsubishi Electric Block-type remote module NZ2GNCE3-32D: vers:all/, Mitsubishi Electric Block-type remote module NZ2GNCE3-32DT: vers:all/, Mitsubishi Electric Block-type remote module NZ2GN12A4-16D: vers:all/, Mitsubishi Electric Block-type remote module NZ2GN12A4-16DE: vers:all/, Mitsubishi Electric Block-type remote module NZ2GN12A2-16T: vers:all/, Mitsubishi Electric Block-type remote module NZ2GN12A2-16TE: vers:all/, Mitsubishi Electric Block-type remote module NZ2GN12A42-16DT: vers:all/, Mitsubishi Electric Block-type remote module NZ2GN12A42-16DTE: vers:all/, Mitsubishi Electric Block-type remote module NZ2GN2S1-16D: vers:all/, Mitsubishi Electric Block-type remote module NZ2GN2S1-16T: vers:all/, Mitsubishi Electric Block-type remote module NZ2GN2S1-16TE: vers:all/, Mitsubishi Electric Block-type remote module NZ2GN2B1-16D: vers:all/, Mitsubishi Electric Block-type remote module NZ2GN2B1-16T: vers:all/, Mitsubishi Electric Block-type remote module NZ2GN2B1-16TE: vers:all/, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8D: vers:all/, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8D-K: vers:all/, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8TE: vers:all/, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8TE-K: vers:all/, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-16DTE: vers:all/, Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-16DTE-K: vers:all/, Mitsubishi Electric Block-type remote module with safety functions NZ2GNS12A2-14DT: vers:all/, Mitsubishi Electric Block-type remote module with safety functions NZ2GNS12A2-16DTE: vers:all/, Mitsubishi Electric Analog-Digital converter module NZ2GN2S-60AD4: vers:all/, Mitsubishi Electric Analog-Digital converter module NZ2GN2B-60AD4: vers:all/, Mitsubishi Electric Digital-Analog converter module NZ2GN2S-60DA4: vers:all/, Mitsubishi Electric Digital-Analog converter module NZ2GN2B-60DA4: vers:all/, Mitsubishi Electric CC-Link IE TSN compatible coupler NZ2FT-GN: vers:all/, Mitsubishi Electric FPGA module NZ2GN2S-D41P01: vers:all/, Mitsubishi Electric FPGA module NZ2GN2S-D41D01: vers:all/, Mitsubishi Electric FPGA module NZ2GN2S-D41PD02: vers:all/, Mitsubishi Electric Tension meter LM7-1LG: vers:all/, Mitsubishi Electric Tension meter LM7-2LG: vers:all/, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G: vers:all/, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5W-G: vers:all/, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-HS: vers:all/, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-RJ: vers:all/, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-LL: vers:all/, Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5D-G4 : vers:all/, Mitsubishi Electric AC Servo MELSERVO-J5 MR-MD333G: vers:all/, Mitsubishi Electric AC Servo MELSERVO-JET MR-JET-G: vers:all/, Mitsubishi Electric AC Servo MELSERVO-JET MR-JET-G4-HS: vers:all/, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A8NCG: vers:all/, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A8NCG-S: vers:all/, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A800-GN: vers:all/, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-E800-E: vers:all/, Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-E800-SCE: vers:all/, Mitsubishi Electric Industrial Robot CR800-D series controller Network Base Card 2F-DQ535-TSN: vers:all/, Mitsubishi Electric CC-Link IE TSN expansion unit FCU8-EX569: vers:all/, Mitsubishi Electric CC-Link IE TSN-CC-Link IE Field Network bridge module NZ2GN-GFB: vers:all/, Mitsubishi Electric CC-Link IE TSN-AnyWireASLINK bridge module NZ2AW1GNAL: vers:all/, Mitsubishi Electric Energy Measuring Unit CC-Link IE TSN Communication Unit EMU4-CM-TSN: vers:all/, Mitsubishi Electric Industrial Computer MELIPC series MI2532-W: vers:all/, Mitsubishi Electric Industrial Computer MELIPC series MI2332-W: vers:all/, Mitsubishi Electric GOT3000 Series GT3715-FHCBD: vers:all/, Mitsubishi Electric GOT3000 Series GT3712-WXCBD: vers:all/, Mitsubishi Electric GOT3000 Series GT3715-XRBA: vers:all/, Mitsubishi Electric GOT3000 Series GT3715-XRBD: vers:all/, Mitsubishi Electric GOT3000 Series GT3712-XRBA: vers:all/, Mitsubishi Electric GOT3000 Series GT3712-XRBD: vers:all/, Mitsubishi Electric GOT3000 Series GT3710-XRBA: vers:all/, Mitsubishi Electric GOT3000 Series GT3710-XRBD: vers:all/, Mitsubishi Electric GOT3000 Series GT3708-XRBA: vers:all/, Mitsubishi Electric GOT3000 Series GT3708-XRBD: vers:all/, Mitsubishi Electric CC-Link IE TSN Communication Unit GT25-J71GN13-T2: vers:all/, Mitsubishi Electric Motion Control Software SWM-G: vers:all/, Mitsubishi Electric Motion Control Software SWM-G-N1: vers:all/, Mitsubishi Electric CC-Link IE TSN Communication Software for Windows SW1DND-CCIETCT-M: vers:all/, Mitsubishi Electric Master/Local module Designated communication LSI DeviceKit NZ2KT-NPETNG51: vers:all/, Mitsubishi Electric Master/Local module Designated communication LSI NZ2GACP610-60: vers:all/, Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP620-60: vers:all/, Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP620-300: vers:all/, Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP621-90: vers:all/, Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP621-720: vers:all/, Mitsubishi Electric CC-Link IE TSN Master/Local module Designated communication LSI SDK SW1DNN-GN610SRC-M: vers:all/, Mitsubishi Electric Remote station software development kit SW1DNC-GNSDK1S-M: vers:all/, Mitsubishi Electric Remote station software development kit SW1DNC-GNSDK2S-M: vers:all/, Mitsubishi Electric Liner Track System MTR-S series Linear track control module MTR-SCU00-4G: vers:all/, Mitsubishi Electric Liner Track System MTR-S series Linear track control module MTR-SCU00-PG: vers:all/, Mitsubishi Electric Analysis Support Software MELSOFT VIMA SW1DNN-VIMA-M: vers:all/* Product Status: known_affected Remediations No fix planned For customers using the affected products, please refer to Mitsubishi Electric’s security advisory, “https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-005_en.pdf" and take the measures described there. https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-005_en.pdf Mitigation For customers of the affected products, Mitsubishi Electric recommends restricting physical access to the affected products and the CC-Link IE TSN network to which the affected products are connected by taking measures such as the following: (a) managing access to and from the site where the affected products are installed, (b) locking the control panel in which the affected products and/or the network devices are installed, and (c) locking the Ethernet ports such as with port lock accessories, to minimize the risk of exploitation of this vulnerability. Mitigation For customers of the affected products, Mitsubishi Electric recommends using the affected products within a trusted network where communication with untrusted networks and hosts is blocked by a firewall or similar measures, to minimize the risk of exploitation of this vulnerability. Mitigation For customers of the affected products, Mitsubishi Electric recommends appropriately configuring credentials and access privileges for network devices installed at the boundary between trusted networks and external networks, to minimize the risk of exploitation of this vulnerability. Relevant CWE: CWE-924 Improper Enforcement of Message Integrity During Transmission in a Communication Channel Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.1 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L 4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N Acknowledgments Alessandro Di Pinto, Giovanni Dini Gentilini, Luca Cremona, and Gabriele Quagliarella of Nozomi Networks, Inc. reported this vulnerability to Mitsubishi Electric Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Mitsubishi Electric 2026-005 from a direct conversion of the vendor’s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA’s website as a means of increasing visibility and is provided “as-is” for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Mitsubishi Electric directly for any questions regarding this advisory. Revision History Initial Release Date: 2026-07-30 Date Revision Summary 2026-07-30 1 Initial Publication 2026-07-30 2 Initial CISA Republication of Mitsubishi Electric 2026-005 advisory Legal Notice and Terms of Use

BY CISA
MIN READ 13 MIN READ
EXPLORE north_east
Mitsubishi Electric CC-Link IE TSN Communication Protocol
MZ Automation GmbH libiec61850
CYBERSECURITY

MZ Automation GmbH libiec61850

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device. The following versions of MZ Automation GmbH libiec61850 are affected: libiec61850 <1.6.2 (CVE-2026-66720, CVE-2026-66369, CVE-2026-63550, CVE-2026-65421, CVE-2026-66364, CVE-2026-66349, CVE-2026-56758, CVE-2026-66360) CVSS Vendor Equipment Vulnerabilities v3 7.5 MZ Automation GmbH MZ Automation GmbH libiec61850 Out-of-bounds Read Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-66720 The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and resulting in a denial-of-service condition. View CVE Details Affected Products MZ Automation GmbH libiec61850 Vendor: MZ Automation GmbH Product Version: MZ Automation GmbH libiec61850: <1.6.2 Product Status: known_affected Remediations Mitigation MZ Automation GmbH recommends that users update to version 1.6.2. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-66369 The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly, resulting in a heap out-of-bounds read. On affected platforms, this condition reliably terminates the subscriber process and causes a denial-of-service. View CVE Details Affected Products MZ Automation GmbH libiec61850 Vendor: MZ Automation GmbH Product Version: MZ Automation GmbH libiec61850: <1.6.2 Product Status: known_affected Remediations Mitigation MZ Automation GmbH recommends that users update to version 1.6.2. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-63550 The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over an established MMS session (TCP port 102), the decoder may advance its internal read position incorrectly, leading to a heap out-of-bounds read. This condition causes the MMS handling process to terminate unexpectedly, resulting in a denial-of-service. View CVE Details Affected Products MZ Automation GmbH libiec61850 Vendor: MZ Automation GmbH Product Version: MZ Automation GmbH libiec61850: <1.6.2 Product Status: known_affected Remediations Mitigation MZ Automation GmbH recommends that users update to version 1.6.2. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H 4.0 7.1 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-65421 The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service process and a denial-of-service condition. View CVE Details Affected Products MZ Automation GmbH libiec61850 Vendor: MZ Automation GmbH Product Version: MZ Automation GmbH libiec61850: <1.6.2 Product Status: known_affected Remediations Mitigation MZ Automation GmbH recommends that users update to version 1.6.2. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-66364 The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an attacker controlled inner element length may exceed its enclosing length, causing the parser to over read by one byte. This out-of-bounds read reliably terminates the subscriber process, resulting in a denial-of-service condition. View CVE Details Affected Products MZ Automation GmbH libiec61850 Vendor: MZ Automation GmbH Product Version: MZ Automation GmbH libiec61850: <1.6.2 Product Status: known_affected Remediations Mitigation MZ Automation GmbH recommends that users update to version 1.6.2. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-66349 The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established session, the decoder may advance its internal buffer incorrectly due to a missing bounds check. This results in a one byte heap out-of-bounds read and causes the MMS service process to terminate, leading to a denial-of-service condition. View CVE Details Affected Products MZ Automation GmbH libiec61850 Vendor: MZ Automation GmbH Product Version: MZ Automation GmbH libiec61850: <1.6.2 Product Status: known_affected Remediations Mitigation MZ Automation GmbH recommends that users update to version 1.6.2. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 6.9 MEDIUM CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-56758 The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain fields within the calling AP title, an attacker controlled length value of zero or one may cause the parser to read past the end of a heap buffer. View CVE Details Affected Products MZ Automation GmbH libiec61850 Vendor: MZ Automation GmbH Product Version: MZ Automation GmbH libiec61850: <1.6.2 Product Status: known_affected Remediations Mitigation MZ Automation GmbH recommends that users update to version 1.6.2. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 6.9 MEDIUM CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-66360 The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of the encoded presentation data allows an attacker controlled field with a zero length value to trigger a bounded heap over read. This condition occurs before MMS session establishment, a crafted TCP/102 connection attempt can trigger the issue. The resulting over read causes the process to terminate, leading to a denial of service condition. View CVE Details Affected Products MZ Automation GmbH libiec61850 Vendor: MZ Automation GmbH Product Version: MZ Automation GmbH libiec61850: <1.6.2 Product Status: known_affected Remediations Mitigation MZ Automation GmbH recommends that users update to version 1.6.2. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Acknowledgments Arun Babu of Central Power Research Institute reported these vulnerabilities to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-07-30 Date Revision Summary 2026-07-30 1 Initial Publication Legal Notice and Terms of Use

7 MIN READ arrow_forward
MZ Automation lib60870
CYBERSECURITY

MZ Automation lib60870

View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed. The following versions of MZ Automation lib60870 are affected: lib60870 2.4.0 (CVE-2026-61893, CVE-2026-63033) CVSS Vendor Equipment Vulnerabilities v3 6.5 MZ Automation GmbH MZ Automation lib60870 Out-of-bounds Read Background Critical Infrastructure Sectors: Energy, Water and Wastewater, Critical Manufacturing, Chemical Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-61893 A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer. View CVE Details Affected Products MZ Automation lib60870 Vendor: MZ Automation GmbH Product Version: MZ Automation GmbH lib60870: 2.4.0 Product Status: known_affected Remediations Mitigation MZ Automation recommends users update to version 2.4.1 when available. Vendor fix See MZ Automation advisories for more information: https://github.com/mz-automation/lib60870/security/advisories/GHSA-g3w7-x5rx-83xm https://github.com/mz-automation/lib60870/security/advisories/GHSA-g3w7-x5rx-83xm Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L 4.0 6.9 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N CVE-2026-63033 A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationObject_ParseObjectAddress to read one byte past the end of the heap-allocated message buffer. View CVE Details Affected Products MZ Automation lib60870 Vendor: MZ Automation GmbH Product Version: MZ Automation GmbH lib60870: 2.4.0 Product Status: known_affected Remediations Mitigation MZ Automation recommends users update to version 2.4.1 when available. Vendor fix See MZ Automation advisory for more information: https://github.com/mz-automation/lib60870/security/advisories/GHSA-7v97-jmwv-w5j7 https://github.com/mz-automation/lib60870/security/advisories/GHSA-7v97-jmwv-w5j7 Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L 4.0 6.9 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N Acknowledgments arun babu puthuparambil of Central Power Research Institute, Bengaluru, India reported these vulnerabilities to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-07-30 Date Revision Summary 2026-07-30 1 Initial Publication Legal Notice and Terms of Use

3 MIN READ arrow_forward
NASA Core Flight System (cFS) Health & Safety (HS) Application
CYBERSECURITY

NASA Core Flight System (cFS) Health & Safety (HS) Application

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of NASA Core Flight System (cFS) Health & Safety (HS) Application are affected: Core Flight System (cFS) Health & Safety (HS) Application <=v7.0.1 (CVE-2026-18064) CVSS Vendor Equipment Vulnerabilities v3 7.5 NASA NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-18064 An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a denial-of-service condition and processor reset. View CVE Details Affected Products NASA Core Flight System (cFS) Health & Safety (HS) Application Vendor: NASA Product Version: NASA Core Flight System (cFS) Health & Safety (HS) Application: <=v7.0.1 Product Status: known_affected Remediations Mitigation NASA reports that an official fix is currently under development and is expected to be included in a future software release. Mitigation As an interim mitigation, users can update their HS app from the HS repo (https://github.com/nasa/HS) to the latest dev branch. The fix is in the dev branch starting at commit 828855f971db4b6714367ed0a970f52dbeab2965 https://github.com/nasa/HS Relevant CWE: CWE-476 NULL Pointer Dereference Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 8.2 HIGH CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Acknowledgments Michael Holmquist of Hasp Labs reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-07-30 Date Revision Summary 2026-07-30 1 Initial Publication Legal Notice and Terms of Use

3 MIN READ arrow_forward
Open Source Software: Security Principles and Practices
CYBERSECURITY

Open Source Software: Security Principles and Practices

Open source software (OSS) is embedded in nearly every modern system, from business applications to critical infrastructure. Our new Open Source Software: Security Principles and Practices guidance helps agencies securely use, evaluate, and publish open source software. It covers OSS risk management across the full lifecycle, introduces the C4 Framework for trust assessment, and provides specific recommendations for vulnerability management, software bill of materials use, secure development, and handling open source artificial intelligence systems. Visit CISA’s Open Source Security webpage for more resources. CISA is committed to providing access to our web pages and documents for individuals with disabilities, both members of the public and federal employees. If the format of any elements or content within this document interferes with your ability to access the information, as defined in the Rehabilitation Act, please email opensource@cisa.dhs.gov. To enable us to respond in a manner most helpful to you, please indicate the nature of your accessibility problem and the preferred format in which to receive the material. Please share your thoughts! We welcome your feedback. CISA Product Survey

1 MIN READ arrow_forward
Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module
CYBERSECURITY

Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module are affected: ControlLogix 5580 >=V36|<=V37 (CVE-2026-9636) CompactLogix 5380 >=V36|<=V37 (CVE-2026-9636) GuardLogix 5580 >=V36|<=V37 (CVE-2026-9636) Compact GuardLogix 5380 >=V36|<=V37 (CVE-2026-9636) 1756-EN4TR V6.001 (CVE-2026-9636) 1756-EN4TR V7.001 (CVE-2026-9636) CVSS Vendor Equipment Vulnerabilities v3 5.9 Rockwell Automation Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module Improper Check for Certificate Revocation Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-9636 A security issue exists within CompactLogix 5380, ControlLogix 5580, and EN4TR communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate certificate that has been revoked via a Certificate Revocation List (CRL). This could allow a network-based attacker to establish a connection using a certificate that should be untrusted, potentially bypassing CIP Security protections. View CVE Details Affected Products Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module Vendor: Rockwell Automation Product Version: Rockwell Automation ControlLogix 5580: >=V36|<=V37, Rockwell Automation CompactLogix 5380: >=V36|<=V37, Rockwell Automation GuardLogix 5580: >=V36|<=V37, Rockwell Automation Compact GuardLogix 5380: >=V36|<=V37, Rockwell Automation 1756-EN4TR: V6.001, Rockwell Automation 1756-EN4TR: V7.001 Product Status: known_affected Remediations Vendor fix Rockwell Automation recommend users update to the following versions: ControlLogix 5580: Update to V38.011 Vendor fix CompactLogix 5380: Update to V38.011 Vendor fix GuardLogix 5580: Update to V38.011 Vendor fix Compact GuardLogix 5380: Update to V38.011 Vendor fix 1756-EN4TR: Update to V8.001 Relevant CWE: CWE-299 Improper Check for Certificate Revocation Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.9 MEDIUM CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 8.2 HIGH CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Acknowledgments Rockwell Automation reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-07-30 Date Revision Summary 2026-07-30 1 Initial Publication Legal Notice and Terms of Use

3 MIN READ arrow_forward
Schneider Electric IGSS
CYBERSECURITY

Schneider Electric IGSS

View CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The IGSS product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. The IGSS Definition module is a design-time component used by system integrators to create mimic diagrams for plant personnel, enabling them to monitor and control the SCADA system. Failure to apply the remediation provided below may risk loss of data or arbitrary code execution, which could result in the loss of control of the system. The following versions of Schneider Electric IGSS are affected: IGSS () IGSS Definition (Def.exe) module vers:intdot/<=18.0.0.26124, 18.0.0.26125 () CVSS Vendor Equipment Vulnerabilities v3 7.8 Schneider Electric Schneider Electric IGSS Out-of-bounds Write Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: France Vulnerabilities Expand All + CVE-2026-12927 An out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file is imported to IGSS Definition. View CVE Details Affected Products Schneider Electric IGSS Vendor: Schneider Electric Product Version: Product Status: fixed, known_affected Remediations Vendor fix Version 18.0.0.26125 of the IGSS Definition module includes a fix for this vulnerability and is available for download through IGSS Master > Update IGSS Software or here: https://igss.schneider-electric.com/igss/igssupdates/v180/IGSSUPDATE.ZIP https://igss.schneider-electric.com/igss/igssupdates/v180/IGSSUPDATE.ZIP Mitigation If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: Avoid executing commands, importing or opening files from untrusted sources. Relevant CWE: CWE-787 Out-of-bounds Write Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Acknowledgments Schneider Electric reported this vulnerability to CISA. Michael Heinzl reported this vulnerability to CISA. General Security Recommendations We strongly recommend the following industry cybersecurity best practices. * Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network. * Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks. * Place all controllers in locked cabinets and never leave them in the “Program” mode. * Never connect programming software to any network other than the network intended for that device. * Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks. * Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation. * Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet. * When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices. For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document. For More Information This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process. For further information related to cybersecurity in Schneider Electric’s products, visit the company’s cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp LEGAL DISCLAIMER THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS “NOTIFICATION”) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN “AS-IS” BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION About Schneider Electric Schneider’s purpose is to create Impact by empowering all to make the most of our energy and resources, bridging progress and sustainability for all. We call this Life Is On. Our mission is to be the trusted partner in sustainability and efficiency. We are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart industries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep domain expertise, we provide integrated end-to-end lifecycle AI enabled industrial IoT solutions with connected products, automation, software and services, delivering digital twins to enable profitable growth for our customers. We are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries to ensure proximity to our customers and stakeholders. We embrace diversity and inclusion in everything we do, guided by our meaningful purpose of a sustainable future for all. www.se.com Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Schneider Electric SEVD-2026-195-01 from a direct conversion of the vendor’s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA’s website as a means of increasing visibility and is provided “as-is” for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric directly for any questions regarding this advisory. Revision History Initial Release Date: 2026-07-14 Date Revision Summary 2026-07-14 1 Original Release 2026-07-30 2 Initial CISA Republication of Schneider Electric SEVD-2026-195-01 advisory Legal Notice and Terms of Use

7 MIN READ arrow_forward
Toptech Systems RCU II+ and Multiload II+
CYBERSECURITY

Toptech Systems RCU II+ and Multiload II+

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources. The following versions of Toptech Systems RCU II+ and Multiload II+ are affected: RCU II+ <2025-11-24 (CVE-2026-12562) Multiload II+ <2025-11-24 (CVE-2026-12562) CVSS Vendor Equipment Vulnerabilities v3 8.8 Toptech Systems Toptech Systems RCU II+ and Multiload II+ Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-12562 The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the embedded system. This vulnerability stems from a network-accessible port running a Target Communications Framework (TCF) service that does not require any authentication, allowing an attacker to directly interact with the Linux environment that powers the device. Once connected, an attacker can freely view and modify the filesystem, manipulate running processes, and control network interfaces, enabling deep alteration of system behavior. View CVE Details Affected Products Toptech Systems RCU II+ and Multiload II+ Vendor: Toptech Systems Product Version: Toptech Systems RCU II+: <2025-11-24, Toptech Systems Multiload II+: <2025-11-24 Product Status: known_affected Remediations Mitigation Toptech Systems provides two methods for remediating affected RCU II+ and Multiload II+ units: First, move the device to a closed or segmented network without untrusted access. Mitigation Run one of the RCU II+/Multiload II+ Vulnerability Removal Tools (VRT) available at https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.zip, https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.gz. - This option does not require breaking Weights and Measures seals and has the least operational impact. https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.zip Mitigation Run one of the RCU II+/Multiload II+ Vulnerability Removal Tools (VRT) available at https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.zip, https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.gz. - This option does not require breaking Weights and Measures seals and has the least operational impact. https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.gz Mitigation This option does not require breaking Weights and Measures seals and has the least operational impact. Mitigation Install the latest firmware from https://s3.amazonaws.com/docs.toptech.com/index.html#downloads/Firmware/RCUII+_MLII+_SMPII+/. - This method requires stopping the bay and breaking the W&M seal. Be sure to back up the current ML configuration before performing the firmware update. https://s3.amazonaws.com/docs.toptech.com/index.html#downloads/Firmware/RCUII+_MLII+_SMPII+/ Mitigation This method requires stopping the bay and breaking the W&M seal. Be sure to back up the current ML configuration before performing the firmware update. Mitigation For questions, contact Toptech Systems Support at security@toptech.com. Additional details are available in Toptech System’s firmware vulnerability notice: https://s3.amazonaws.com/docs.toptech.com/nonpublic/2025%2012%2001%20RCU%20IIPlus%20MultiLoad%20IIPlus%20Vulnerability%20Notice.pdf. mailto:security@toptech.com Mitigation For questions, contact Toptech Systems Support at security@toptech.com. Additional details are available in Toptech System’s firmware vulnerability notice: https://s3.amazonaws.com/docs.toptech.com/nonpublic/2025%2012%2001%20RCU%20IIPlus%20MultiLoad%20IIPlus%20Vulnerability%20Notice.pdf. https://s3.amazonaws.com/docs.toptech.com/nonpublic/2025%2012%2001%20RCU%20IIPlus%20MultiLoad%20IIPlus%20Vulnerability%20Notice.pdf Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments Donald Green of Southwest Research Institute reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely. Revision History Initial Release Date: 2026-07-30 Date Revision Summary 2026-07-30 1 Initial Publication Legal Notice and Terms of Use

4 MIN READ arrow_forward
Watchfire Controller Software
CYBERSECURITY

Watchfire Controller Software

View CSAF Summary Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller. The following versions of Watchfire Controller Software are affected: BC550 12.30 (CVE-2026-5846) BC750 11.33|12.35 (CVE-2026-5846) BC760 12.38|13.00 (CVE-2026-5846) BC760DC 12.39 (CVE-2026-5846) CVSS Vendor Equipment Vulnerabilities v3 5.7 Watchfire Watchfire Controller Software Use of Hard-coded Cryptographic Key Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Healthcare and Public Health, Financial Services Countries/Areas Deployed: United States, Dominican Republic, Canada, Peru, El Salvador Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-5846 The affected product contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller’s built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire’s Remote Support filestore. View CVE Details Affected Products Watchfire Controller Software Vendor: Watchfire Product Version: Watchfire BC550: 12.30, Watchfire BC750: 11.33|12.35, Watchfire BC760: 12.38|13.00, Watchfire BC760DC: 12.39 Product Status: known_affected Remediations Mitigation Watchfire has applied the required security patch to all affected controllers under its management. Watchfire recommends users verify their controller software version and upgrade to one of the approved versions below, if they are not already on an approved patch level. Vendor fix Watchfire has issued patches to disable the use of the existing certificate as follows: BC550 12.30: Patch to 12.31 SP1BC750 11.33: Patch to 11.34BC750 12.35: Patch to 12.36 SP1BC760 12.38: Patch to 12.41 SP1BC760 13.00: Patch to 14.00 SP1BC760DC 12.39: Patch to 12.41 SP1 Relevant CWE: CWE-321 Use of Hard-coded Cryptographic Key Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.7 MEDIUM CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N 4.0 7.6 HIGH CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N Acknowledgments James Tillson reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability has a high attack complexity. Revision History Initial Release Date: 2026-07-30 Date Revision Summary 2026-07-30 1 Initial Publication Legal Notice and Terms of Use

3 MIN READ arrow_forward
Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
CYBERSECURITY

Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after reporting it to Microsoft. In his proof of concept, the internally generated file triggered the same behavior when it was used in a second Copilot drafting session. Måløy’s

1 MIN READ arrow_forward
Orca Security secures AI-built and developer-created applications
CYBERSECURITY

Orca Security secures AI-built and developer-created applications

Orca Security has announced two new AI-powered capabilities: Orca AI AppGen Security, which discovers and secures AI applications built outside the development pipeline on AI-powered platforms like Claude, Supabase, and Lovable, and AI Code Security Auditor, which delivers deep AI-driven static analysis for code developed within traditional pipelines. The capabilities extend the Orca Platform to secure software across the full spectrum of application development, from professional engineering teams to the growing population of AI-assisted builders. … More → The post Orca Security secures AI-built and developer-created applications appeared first on Help Net Security.

1 MIN READ arrow_forward
The Network Has Become the Control Plane for AI Security
CYBERSECURITY

The Network Has Become the Control Plane for AI Security

Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and breaches. And for decades, network security teams have built controls around a relatively stable model: users connect to applications, applications exchange data, and security tools inspect packets, protocols, and destinations. Firewalls

1 MIN READ arrow_forward