
US Warns of AI-Powered Attacks on Siemens PLCs in Critical Infrastructure
U.S. agencies warn of AI-driven attacks targeting Siemens PLCs in critical infrastructure, including manufacturing, energy, and water systems.
Stories tagged “Industrial Control Systems.”
30 stories

U.S. agencies warn of AI-driven attacks targeting Siemens PLCs in critical infrastructure, including manufacturing, energy, and water systems.
Siemens Parasolid Vulnerability Exposes Industrial Control Systems to Out-of-Bounds Read Attacks
Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Parasolid are affected: Parasolid V38.0 vers:intdot/<38.0.235 (CVE-2026-64629) Parasolid V38.1 vers:intdot/<38.1.230 (CVE-2026-64…
Siemens License Server (SLS) Vulnerabilities Allow Privilege Escalation and File Access
Siemens License Server (SLS) is affected by multiple vulnerabilities that could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest v…
Siemens Desigo DXR and PXC Controllers Vulnerable to Denial-of-Service Attacks
A vulnerability in Siemens Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality.
Johnson Controls Metasys Vulnerability Exposes Users to Persistent Malicious Payloads
A vulnerability in Johnson Controls Metasys allows a low-privilege user to inject a persistent malicious payload via a crafted URL, potentially leading to session hijacking and unauthorized access.
Siemens Siveillance Video Management Servers Vulnerability Advisory ICSA-26-225-09
Siemens releases new versions to fix vulnerabilities in its Siveillance Video management servers, which could allow remote code execution attacks.
Flow Neuroscience FL-100
Critical vulnerability in Flow Neuroscience FL-100 devices detected by CISA.
Johnson Controls Inc. TL280 Vulnerability Exposes Sensitive Information
A vulnerability in Johnson Controls Inc. TL280 firmware allows attackers to access sensitive information. The affected versions are TL280 <5.63. Users are advised to apply firmware update 5.63 and implement defensive measures.
ABB Ability Zenon Vulnerabilities Expose Industrial Control Systems to Attacks
CISA has issued an advisory warning of vulnerabilities in ABB Ability Zenon, a widely used industrial control system. The flaws, which affect IIoT services with MongoDB (4.2) installed on ABB Ability Zenon, could allow attackers to bypass security, crash systems, execute …
Siemens Mendix Runtime Vulnerability Exposes Sensitive User Data
A vulnerability in Siemens Mendix Runtime allows developers to unknowingly apply overly permissive access rules to System.User, exposing sensitive user data or privilege escalation within deployed Mendix applications.
Siemens SIMATIC S7-PLCSIM Advanced Vulnerability
Siemens SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
CISA has issued an advisory for multiple vulnerabilities found in the GNU/Linux subsystem of Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP firmware version V3.1.6. Siemens is preparing fixes and recommends countermeasures for affected products.
ABB KNX Update Tool
A vulnerability (CVE-2026-12705) in ABB KNX Update Tool affects legacy KNX devices, allowing an attacker with physical access to cause product unresponsiveness or alter behavior due to missing firmware integrity checks. ABB has no software fix planned for these older devi…
Johnson Controls XAAP Android
A vulnerability in Johnson Controls XAAP Android allows an attacker to obtain confidential information from the device. The affected versions are XAAP Android <1.53.
CISA Advisory: Multiple Vulnerabilities in MZ Automation libIEC61850
CISA has issued an advisory detailing multiple high-severity vulnerabilities in MZ Automation's libIEC61850 library, affecting versions up to v1.6.1.
MZ Automation lib60870
CISA has issued an advisory for MZ Automation lib60870, warning of an out-of-bounds read vulnerability (CVE-2026-16002) that could lead to a denial of service in critical infrastructure sectors. Users are advised to update to version 2.4.1 or later to mitigate the risk.
Panduit IntraVUE Vulnerabilities Exposed: Multiple Flaws in Industrial Control System
CISA has identified multiple vulnerabilities in Panduit IntraVUE, a industrial control system. The vulnerabilities, including plaintext storage of a password, unintended proxy or intermediary, exposure of sensitive system information, and inadequate encryption strength, c…
Tycon Systems TPDIN-Monitor-WEB2 Vulnerabilities Expose Critical Infrastructure to Remote Attacks
CISA has issued an advisory warning of two critical vulnerabilities in Tycon Systems' TPDIN-Monitor-WEB2, which could allow remote attackers to access sensitive credentials, disrupt connected infrastructure, or manipulate physical equipment.
Siemens IAM Client Vulnerability Exposes Industrial Control Systems to Privilege Escalation
A vulnerability in Siemens IAM Client allows an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends updating to the latest versions.
Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW
CISA has issued an ICS advisory for vulnerabilities in Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW. The advisory lists three vulnerabilities: CVE-2026-0266, CVE-2026-0272, and CVE-2026-0273. Customers are advised to consult and implement the workarounds…
Rockwell Automation 1734 POINT I/O
CISA advisory warns of a high-severity denial-of-service flaw in Rockwell Automation 1734 POINT I/O modules that can be triggered remotely via crafted CIP messages, requiring a restart to recover.
Rockwell Automation 1718-AENTR/1719-AENTR Denial-of-Service Vulnerability
CISA has issued an advisory regarding a denial-of-service vulnerability (CVE-2026-9140) affecting Rockwell Automation 1718-AENTR/1719-AENTR products, specifically version 3.011.
Rockwell Automation Studio 5000 Logix Designer Vulnerabilities
CISA has identified vulnerabilities in Rockwell Automation Studio 5000 Logix Designer that could allow for arbitrary code execution, path traversal, and incorrect authorization.
Siemens SICAM 8 Vulnerabilities Expose Critical Infrastructure to Denial of Service and System Compromise
Siemens SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service and system compromise. The vulnerabilities are present in the CPCI85 Central Processing/Communication and SICORE Base system firmware. Siemens has released new versions …
CISA Warns of Stored XSS Flaw in Rockwell Automation FactoryTalk DataMosaix
CISA issued advisory ICSA-26-197-09 for a stored cross-site scripting vulnerability in Rockwell Automation FactoryTalk DataMosaix Private Cloud versions 8.02 and earlier, allowing privileged authenticated users to inject malicious scripts.
CISA Warns of Four High-Severity Flaws in Rockwell Automation Arena Simulation Software
CISA issued advisory ICSA-26-197-01 flagging four out-of-bounds write vulnerabilities in Rockwell Automation Arena ≤V17.00.00 that could let attackers execute arbitrary code via a malicious file.
Rockwell Automation Flex 5000 Adapter
CISA has issued an advisory detailing a denial-of-service vulnerability (CVE-2026-12659) in Rockwell Automation Flex 5000 Adapter version 6.011, which can be exploited by specially crafted CIP packets.
AutomationDirect Productivity Suite
CISA has issued an advisory detailing multiple vulnerabilities in AutomationDirect Productivity Suite <=v4.6.2.2, including out-of-bounds write/read and divide-by-zero flaws. Exploitation could lead to memory corruption, information disclosure, application instability, or…
ABB Ability Edgenius Vulnerability CVE-2026-31431
A vulnerability in the ABB Ability Edgenius product versions listed as affected in the advisory may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems.
ABB T-MAC Plus Vulnerabilities Addressed by ABB
ABB has addressed vulnerabilities in the ABB T-MAC Plus, including file disclosure, broken access controls, and stored cross-site scripting. The company recommends applying the update at the earliest convenience to ensure adequate protection for customers.