CISA scored Hitachi FACTS 9.9. The exploited device this week is still Cisco ISE, not a PLC.
11–18 September 2026. CISA ICSA-26-260-03 puts Hitachi Energy FACTS Control Platform (STATCOM, SVC, series capacitors) at CVSS 9.9 when the GWS component is present — 2024 CVEs, no versioned fix in the ICSA. Same week: Wärtsilä FOS-Onboard hardcoded update keys (CVE-2026-78225 / CVE-2026-81855), mySCADA myPRO Manager unauthenticated command API (CVE-2026-73807, 9.8), Mitsubishi GX Works3 block-password bypass on all versions (CVE-2026-15688), and CC-Link IE TSN with no fix planned. CISA republished last week’s Reyrolle 7SR5 and SCADAPack notes. No new Stage 2 ICS malware. The KEV is Cisco ISE.
Bottom line up front
CONFIRMED This week’s public OT calendar was two CISA ICS drops — eight advisories on 15 September, seven new plus one update on 17 September — not a named plant-floor malware event and not a new Stage 2 ICS kill-chain case.
The product that belongs at the top of a transmission operator’s queue is not last week’s Modicon M580. On 17 September CISA published ICSA-26-260-03 on Hitachi Energy FACTS Control Platform with the GWS component. Headline CVSS v3.1 9.9 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) on CVE-2024-4872 and CVE-2024-3980. Affected trains: FCP 3.4.0 through 4.1.1. Hitachi’s own scope, as republished by CISA: SVC Light (STATCOM), fixed series capacitor, thyristor-controlled series capacitor, static var compensator, static watt compensator, hybrid synchronous condensers — deployments from 2020 onward if GWS is present. Deployments without GWS are out. The ICSA does not name a patched FCP version. Remediation is “follow general mitigation factors” and Hitachi advisory 8DBD000229. SSVC on the CISA page is E:N — no exploitation recorded.
Same CISA week, two remotely reachable ICS-management issues that are easier to ticket than a FACTS GWS estate:
- Wärtsilä FOS-Onboard 5.07.0923.01 (ICSA-26-258-02, 15 September). CVE-2026-78225 is a hardcoded cryptographic server key in the deployer-ng Update Controller (CVSS 9.0 / 9.5). CVE-2026-81855 is a hardcoded client authentication key in the robot testing framework (CVSS 9.1 / 9.3). CISA’s summary sentence is the operator one: successful exploitation could let an attacker “deliver an unauthorized update, execute code, or extract credentials.” Cydome reported it. Wärtsilä says the bugs are not exploitable when the product is installed as recommended, and the patch is obtained by contacting Wärtsilä — not a public firmware pull. No known public exploitation.
- mySCADA myPRO Manager ≤2.1 (ICSA-26-258-03, 15 September). CVE-2026-73807 (CVSS 9.8): the command API does not enforce authentication for privileged management functions. CVE-2026-82567: an unauthenticated HTTP endpoint will send arbitrary SMS through a connected GSM modem. Fix is 2.2. Sectors CISA lists: critical manufacturing, energy, food and agriculture, transportation, water and wastewater. No known public exploitation.
The only CONFIRMED in-the-wild activity with an 11–18 September timestamp that OT operators should treat as a live ticket is not a PLC. On 16 September CISA added CVE-2026-76460 (Cisco ISE / ISE-PIC unauthenticated privileged-API bypass) to KEV, federal due 19 September, forensic triage under BOD 26-04. That is an identity-control-plane compromise class. It is an IT-to-OT path where the plant NAC, 802.1X, or contractor VPN terminates on ISE. It is not confirmation that a controller was reprogrammed.
Do not upgrade this week’s ICSA pile into FrostyGoop. Last week’s live OT threat is unchanged: internet-reachable PLCs and engineering-client abuse named in AA26-097A and AA26-231A. CVE-2026-3869 on M580 / M580 Safety still has no CISA ICSA as of 18 September morning.
OT threat posture
Exposure, engineering-path abuse, and now a KEV’d identity appliance remain higher confidence than novel ICS malware. Ransomware still hurts plants by killing the Windows and hypervisors OT depends on — vCenter CVE-2026-59310 is on KEV with a ransomware flag; that is a hypervisor story, not a ladder-logic story. No public primary source this week documented a new ladder-logic change or a new ICS-specific wiper.
1. Most significant development
Hitachi Energy FACTS Control Platform with GWS, because it is transmission-level process control (STATCOM / SVC / series compensation), CISA scored the authenticated injection and path-traversal issues 9.9 with changed scope, and the ICSA gives operators no firmware train to flash.
Why this outranked the rest of the week: mySCADA CVE-2026-73807 is more exploitable on paper (unauthenticated 9.8) and will hit more water and food sites than a FACTS GWS install base. Wärtsilä’s update-controller key is the cleaner “unauthorized firmware” failure mode. Neither is a grid FACTS controller sitting on reactive power and series compensation. Reyrolle 7SR5 CVE-2026-62645 is as severe as last week and now has an ICSA, but it is last week’s ProductCERT note, not a new finding. Cisco ISE is the exploited box — it is not an ICS product. Score for the week: 8.5. mySCADA-only would have been ~8.4 on actionability and ~8.0 on grid consequence. Wärtsilä-only belongs in marine and in section 6. ISE-only belongs in the IT briefing and in section 5 here.
2. Adversary / campaign activity
No new joint USG OT campaign advisory this week. Continuing, still the current hunt set:
- AA26-097A (April, updated 22 July): Iran-affiliated actors using Studio 5000 / EcoStruxure Control Expert / TIA Portal against internet PLCs (CompactLogix, Micro850, Modicon M340, S7-1200). CONFIRMED as USG. This week’s M340 FTP DoS (CVE-2025-6625) is a same-family product ticket, not new attribution, and it is availability via FTP — not the engineering-client path in the advisory.
- FBI/EPA 30 July water PSA: MicroLogix 1100/1400, seven states. CONFIRMED as PSA. Not this week’s news.
- AA26-231A (19 August): recon and capability development on US S7-200/300/400/1200 using internet scans and AI-generated “monitoring” scripts. CONFIRMED as USG wording. Thirty days old. No new victim set this window.
CONFIRMED (non-ICS, this week): Cisco ISE CVE-2026-76460, CISA KEV 16 September, CCCS AL26-021 17 September. Cisco has confirmed exploitation. Federal due 19 September. Hunt is in the 17 September Daily Top, not here.
UNKNOWN an 11–18 September named victim with a confirmed ladder-logic, protection-setting, or FACTS-GWS change.
3. Vulnerabilities and active exploitation
CONFIRMED (CISA ICS, 17 September)
| Advisory | Product | CVE | What it actually is |
|---|---|---|---|
| ICSA-26-260-03 | Hitachi Energy FACTS FCP with GWS, 3.4.0–4.1.1 | CVE-2024-4872, CVE-2024-3980 (9.9); CVE-2024-3982 (8.2); CVE-2024-7940 (8.3); CVE-2024-7941 (4.3) | Authenticated injection into persistent data; authenticated path traversal; local session hijack if logging enabled; unauthenticated bind of a local-only service; open redirect. No patched version in the ICSA. 2024 CVE IDs, 17 September 2026 publication. |
| ICSA-26-260-02 | Mitsubishi GX Works3 / Motion Control Settings, all versions | CVE-2026-15688 | Incorrect authentication algorithm. Local attacker authenticates with an invalid block password, patches the process in memory, then views, tampers, destroys, or deletes control programs. CVSS 8.8 / 9.2. Workaround: GX Works3 1.096A or later and security version 2; Motion Control Settings 1.070Y or later and security version 2. Installing the build without flipping security version is not the Mitsubishi fix. |
| ICSA-26-211-07 Update A | Mitsubishi CC-Link IE TSN protocol — MELSEC MX, remote I/O including safety NZ2GNSS2, MELSERVO-J5, FR-A/E800, GOT3000, CR800 robots | CVE-2026-13584 | CWE-924. Same-segment attacker, crafted packets, specific timing: tamper with control I/O, DoS, or incorrect operation. CVSS 7.1. No fix planned. Mitigate: physical / cabinet / port lock, trusted segment, firewall. Nozomi (Di Pinto, Gentilini, Cremona, Quagliarella) reported it. |
| ICSA-26-260-04 | Schneider Modicon M340 + X80 Ethernet / RTU / FactoryCast / M580 Global Data | CVE-2025-6625 | Crafted FTP command → DoS. CVSS 7.5. FTP is disabled by default. Fixes: M340 SV3.70, BMXNOE0100 3.60, BMXNOE0110 6.80, BMXNOR0200H SV1.7 IR27. All-version products (M580 Global Data, some X80 / RTU) have a “remediation plan” and the same FTP-off / 21/TCP block. SEVD-2025-224-05. |
| ICSA-26-260-06 | ABB Ability Edgenius ≥3.2.0.0 <3.2.4.1 on bE100 gateway | CVE-2026-31431 | “Copy Fail” Linux kernel local root. Fix 3.2.4.1. Same kernel CVE Siemens rolled into industrial products last week. |
| ICSA-26-260-05 | Schneider NetBotz 5 750/755 ≤5.5.2 | CVE-2026-13336, CVE-2026-13337 | OS command injection on restore of a malicious backup (6.4); Hibernate SQLi when logged in (4.6). Fix 5.6.0. Data-center environmental monitor, not a PLC. |
| ICSA-26-260-07 | Schneider PowerChute Serial Shutdown ≤1.5 | CVE-2026-13348 | Excessive authentication attempts, CVSS 5.3. Fix 1.6. UPS helper, not process control. |
| ICSA-26-260-01 | Bransys ELD Android <11.00.00 / iOS <1.1.54 | CVE-2026-86520, CVE-2026-86689, CVE-2026-77960 | Hardcoded MQTT credentials (read of live telematics across a subset of carriers), cleartext broker, hardcoded FTP. Transportation ELD, United States. App-store update. Not a plant controller. |
CONFIRMED (CISA ICS, 15 September)
| Advisory | Product | CVE | What it actually is |
|---|---|---|---|
| ICSA-26-258-02 | Wärtsilä FOS-Onboard 5.07.0923.01 | CVE-2026-78225, CVE-2026-81855 | Hardcoded update-controller server key; hardcoded robot-test client key. Unauthorized update / impersonation. Patch via vendor contact. |
| ICSA-26-258-03 | mySCADA myPRO Manager ≤2.1 | CVE-2026-73807 (9.8), CVE-2026-82567 (6.3) | Unauthenticated privileged command API; unauthenticated SMS via GSM modem. Fix 2.2. |
| ICSA-26-258-05 | Siemens Reyrolle 7SR5 < V2.70 | CVE-2026-62645 (9.8) plus 62646–62654 and bundled Mongoose | CISA republication of SSA-142885 (8 September). Session-ID calculation, low-entropy sessions, unauthenticated DoS, RBAC bypass. Fix V2.70. Last week’s lead; this week it becomes a federal/contractor ICSA ticket. |
| ICSA-26-258-04 | Schneider SCADAPack 47x/57x/3xx/32, all versions listed | CVE-2026-81861 (6.5) | CISA republication of SEVD-2026-251-03. Insufficiently protected credentials on Secure Lock. Schneider’s mitigation is RBAC instead of Secure Lock, plus the RTU firewall — not a firmware flash. |
| ICSA-26-258-01 | Digital Watchdog VMAX A1 G4 / IP G4 / PLUS, all versions listed | CVE-2026-66890 / 66887 (9.6) and related | Hardcoded FTP-as-root, missing CGI authorization, predictable sessions, unauthenticated credential disclosure. CISA: full admin, live/recorded video, network pivot. Scot Berner (TrustedSec). Firmware at digital-watchdog.com/downloads. Physical-security recorder, not a PAC. |
| ICSA-26-258-06 | Siemens Mendix SAML <4.2.3 / <3.6.27 | CVE-2026-80465 (8.7) | SAML response signature not validated; account hijack in specific SSO configs. SSA-887643 dated 3 September; CISA republication 15 September. |
| ICSA-26-258-07 | Siemens Teamcenter V2412–V2606 trains listed | CVE-2026-58113 (6.1) | Reflected XSS in /auth/ redirect. SSA-157465 dated 8 September; CISA republication 15 September. PLM, not a controller. |
| ICSA-26-258-08 | CareCam CM2507 firmware v251211.1507 | CVE-2026-88259 and six others | Unauthenticated live video; empty ONVIF password; credential recovery. Commercial-facilities camera. Follow-on to last week’s CareCam Pro physical-bootloader note, different model. |
CONFIRMED (active exploitation, not ICS): Cisco ISE CVE-2026-76460, KEV 16 September. Acronis Backup CVE-2026-87886 the same day — cPanel/Plesk plugin, not OT. vCenter CVE-2026-59310 remains KEV with ransomware Known from 16 September’s Daily Top. ScreenConnect CVE-2026-84869 and GitLab CVE-2026-85706 were last week’s IT KEV clock (due 14 September). MikroTik RouterOS CVE-2026-67277 / CVE-2026-86060 remains last week’s edge-router hunt; no new industrial-ASN confirmation in this window.
NOT this week’s OT story: Check Point CVE-2026-91843 (16 September, CVSS 9.8, unauthenticated stack overflow on Security Management / Log Server, LivePatch Take 28/29). Vendor reports no exploitation; not on KEV catalog 2026.09.16. It becomes an IT-to-OT path if that manager pushes policy onto the plant firewall. That is the 18 September Daily Top, not a PLC advisory.
Still missing from CISA ICS: Schneider CVE-2026-3869 on M580 / M580 Safety. Last week’s watch item. As of 18 September the ICS index still does not list it. Primary source remains SEVD-2026-251-04.
4. ICS / SCADA impact
No CONFIRMED new loss-of-view or loss-of-control event dated 11–18 September in CISA ICS, FBI/EPA, Hitachi Energy’s FACTS notice, Wärtsilä, mySCADA, Mitsubishi PSIRT, or Siemens ProductCERT.
What would become process impact, if exploited on an exposed or poorly segmented box:
- FACTS GWS authenticated injection / path traversal → confidentiality, integrity, and availability of the FACTS control system that is running STATCOM, SVC, or series compensation. That is reactive power and line compensation, not a building HMI. It still requires a valid credential for the 9.9 pair, and GWS must be present.
- Wärtsilä unauthorized update → integrity of onboard engine/ICS software. Marine. Vendor’s “installed as recommended” clause is the compensating control until the patch is applied; treat “recommended install” as a configuration audit, not a wish.
- mySCADA unauthenticated command API → privileged management of the SCADA manager. Water, food, and small manufacturing that put myPRO Manager on a reachable VLAN.
- GX Works3 invalid block password → integrity of the project on the engineering workstation. Local. This is the Studio 5000 / Control Expert / TIA class of problem on a Mitsubishi desk.
- CC-Link IE TSN same-segment I/O tamper → incorrect operation or DoS on a very large Mitsubishi motion/safety/HMI/robot estate, with no firmware coming. Architecture (segmentation, cabinet, port lock) is the fix.
- Reyrolle 7SR5 session bypass → still last week’s protection-relay ticket; CISA ICSA now exists.
- M340 FTP DoS → availability of a PAC that AA26-097A already named. FTP should already be off.
Prior water PLC tampering (July) and the UK small-generator outage (late July, disclosed August) remain the last well-sourced availability hits. They are not this week’s news.
5. IT-to-OT exposure
Four doors this week, in the order operators can actually hunt:
- Cisco ISE / ISE-PIC with the management interface reachable. Plant 802.1X, contractor VPN, and jump-host admission often terminate here. CVE-2026-76460 is unauthenticated privileged-API bypass, KEV, due 19 September, forensic triage required for FCEB. Patching without hunting
access.logis not remediation — see the Daily Top. CCCS AL26-021 is the operator checklist (3.1 P12 / 3.2 P11 / 3.3 P12 / 3.4 P7 / 3.5 P4). - VMware vCenter that hosts historians, HMIs, or engineering VMs. CVE-2026-59310 is KEV with ransomware Known. Encrypting the appliance is an OT outage without a single S7 packet. Image, then patch.
- ScreenConnect and other RMM that still have a plant session. CVE-2026-84869 due date was 14 September. Huntress’s worm-like VBScript propagation is an IT finding that becomes an OT finding the moment a session is open to an HMI or an engineering laptop. Client ≥ 26.6.5; reinstall the host client, do not trust “cloud, no action.”
- Check Point Security Management / Log Server (CVE-2026-91843) and leftover MikroTik WAN SSH (last week’s
ops/user added by ssh:-2@). Management-plane root and CPE root are how a commodity IT session becomes a machine session without touching a coil.
Ignition, engineering workstations, and internet-facing 44818/102/502/2222 remain the standing hunt from AA26-097A / AA26-231A. That hunt does not reset because CISA republished Reyrolle.
6. Sector impact
- Electric / transmission: Hitachi FACTS FCP with GWS is the sector-specific lead. Reyrolle 7SR5 now has an ICSA — protection engineering still owns V2.70. AA26-231A S7 exposure is still the Siemens PLC lead. Do not conflate a FACTS GWS web tier, a protection-relay web UI, and an S7-300 on port 102.
- Process manufacturing: GX Works3 security version 2, CC-Link IE TSN segmentation (no firmware is coming), mySCADA 2.2. M340 FTP-off is hygiene on a PAC Iran-affiliated actors already know how to reach.
- Water / food / small SCADA: mySCADA myPRO Manager 2.2. Unauthenticated management API plus an SMS modem is the internet-facing RTU pattern with a different logo.
- Marine / transportation: Wärtsilä FOS-Onboard — call the vendor, get the patch, audit whether the install matches “as recommended.” Bransys ELD is telematics credential hygiene for US carriers, not engine control.
- Oil and gas midstream: Last week’s AVEVA PIM ticket is still open if 2025 SP1 P2 and project-file migration are not done. No new midstream ICSA this window.
- Building / data center: NetBotz 5.6.0; PowerChute 1.6; ABB Edgenius 3.2.4.1. Winnipeg HVAC (August) is still the last well-sourced availability case in this class.
- Physical security / cameras: Digital Watchdog VMAX (pivot, hardcoded FTP-as-root) and CareCam CM2507 (unauth stream). Treat as recon and jump-host risk, not process control.
7. Defensive priorities
- Internet-facing PLC eradication — still number one. VPN or jump host, never the controller. AA26-097A / AA26-231A have not been withdrawn.
- Hitachi FACTS: inventory GWS. If GWS is present on FCP 3.4.0–4.1.1, open 8DBD000229 with the Hitachi service organization. Do not wait for a version string CISA did not publish. Restrict GWS to the engineering VLAN; it is not an internet service.
- mySCADA myPRO Manager to 2.2. If you cannot patch this week, take the command API and the SMS gateway off every untrusted segment. An unauthenticated privileged API on a water SCADA manager is the ticket.
- Wärtsilä FOS-Onboard: contact Wärtsilä for the ICS patch, then prove the running image is the patched one. “Installed as recommended” is an audit finding until it is a screenshot.
- GX Works3: 1.096A+ and project security version 2. Same for Motion Control Settings 1.070Y+. Local engineering-workstation control. Lock physical access; this CVE is AV:L.
- CC-Link IE TSN: there is no firmware. Cabinet locks, port locks, no untrusted host on the TSN segment. Safety remote modules are in the affected list — tell the safety engineer, not just the Windows patcher.
- Reyrolle 7SR5 to V2.70 if last week’s window slipped. SCADAPack: RBAC instead of Secure Lock; enable the RTU firewall.
- M340: confirm FTP is off (default). Flash the modules that have a build; firewall 21/TCP for the rest.
- ISE: patch plus hunt. vCenter: patch plus hunt. ScreenConnect host client: reinstall. MikroTik: still hunt
ops. - Do not wait for ICS-specific malware. Dragos already told you ransomware did not need Stage 2.
8. What changed from last week
Last week (ending 11 September) was vendor Patch Tuesday — Schneider M580 Safety auth, Siemens Reyrolle and IEM, AVEVA PIM via CISA on the 10th, and a KEV on MikroTik. This week CISA republished Reyrolle (ICSA-26-258-05) and SCADAPack (ICSA-26-258-04), and added a grid FACTS 9.9, a marine update-controller key, an unauthenticated mySCADA manager, an all-versions GX Works3 engineering bypass, and a no-fix CC-Link IE TSN protocol note. CVE-2026-3869 on M580 still has no ICSA. No new USG PLC campaign update. No new FBI/EPA water PSA. No new industrial-ransomware quarter. The exploited identity box moved from FMC (9 September) to ISE (16 September). AA26-231A is 30 days old.
9. What OT defenders should watch next
Whether Hitachi publishes a versioned FCP/GWS patch, or whether 8DBD000229 stays mitigations-only. Whether mySCADA 9.8 or Wärtsilä’s update key grows an in-the-wild note. Whether CISA finally republishes CVE-2026-3869. Whether CC-Link IE TSN CVE-2026-13584 stays “no fix planned” after Update A. Whether ISE compromise is observed on industrial 802.1X estates, not only enterprise campuses. Q3 industrial ransomware counts. Any AA26-097A or water-PSA refresh.
10. RWP assessment
High confidence: this week is CISA converting last week’s vendor stack into ICSAs, plus a grid FACTS 9.9, a marine update key, and an unauthenticated SCADA-manager API. High confidence: exposed controllers and engineering paths in AA26-097A / AA26-231A remain the incident class that has evidence. High confidence: GX Works3 without security version 2, and CC-Link IE TSN without segmentation, are unfixed even after the operator “applied the advisory.” Moderate confidence: a non-trivial number of water and food sites still have myPRO Manager ≤2.1 reachable from a jump VLAN. Moderate confidence: FACTS GWS is a small population, but it is the wrong small population to leave on a 9.9 with no firmware string. Low confidence: a new OT malware family dropped in the last seven days. Labeling a manufacturer ransomware victim, an ISE appliance, or a Digital Watchdog NVR as “OT compromise” without process evidence remains a briefing error.
This assessment covers 11–18 September 2026 and was published 18 September 2026.
Sources
- CISA — ICS Advisories index 17 September 2026
- CISA — ICSA-26-260-03 Hitachi Energy FACTS Control Platform (FCP)
- Hitachi Energy — Security advisory 8DBD000229
- CISA — ICSA-26-258-02 Wärtsilä FOS-Onboard
- CISA — ICSA-26-258-03 mySCADA myPRO Manager
- CISA — ICSA-26-260-02 Mitsubishi Electric GX Works3 and Motion Control Settings
- Mitsubishi Electric — PSIRT 2026-007 GX Works3
- CISA — ICSA-26-211-07 Mitsubishi Electric CC-Link IE TSN (Update A)
- Mitsubishi Electric — PSIRT 2026-005 CC-Link IE TSN
- CISA — ICSA-26-260-04 Schneider Electric Modicon M340 Controller and Communication Modules
- Schneider Electric — SEVD-2025-224-05 Modicon M340
- CISA — ICSA-26-258-05 Siemens Reyrolle 7SR5
- CISA — ICSA-26-258-04 Schneider Electric SCADAPack x70 Products
- CISA — ICSA-26-258-01 Digital Watchdog VMAX DVR and NVR
- CISA — ICSA-26-258-06 Siemens Mendix SAML
- CISA — ICSA-26-258-07 Siemens Teamcenter
- CISA — ICSA-26-258-08 CareCam CM2507
- CISA — ICSA-26-260-01 Bransys ELD
- CISA — ICSA-26-260-05 Schneider Electric NetBotz 5 750/755
- CISA — ICSA-26-260-06 ABB Ability Edgenius
- CISA — ICSA-26-260-07 Schneider Electric PowerChute Serial Shutdown
- CISA — Adds two KEVs 16 September 2026 (Cisco ISE, Acronis)
- Canadian Centre for Cyber Security — AL26-021 Cisco ISE
- Siemens ProductCERT — SSA-142885 Reyrolle 7SR5
- CISA — AA26-231A Defending against an active threat to Siemens S7
- CISA — AA26-097A Iranian-affiliated actors exploit PLCs
- RWP — Weekly OT 11 September 2026
- RWP — Daily Top Cisco ISE CVE-2026-76460
- RWP — Daily Top Check Point CVE-2026-91843
- RWP — Daily Top VMware vCenter CVE-2026-59310
- ICS Advisory Project — Dashboards 15 and 17 September 2026