OT Intelligence · OT

CISA scored Hitachi FACTS 9.9. The exploited device this week is still Cisco ISE, not a PLC.

11–18 September 2026. CISA ICSA-26-260-03 puts Hitachi Energy FACTS Control Platform (STATCOM, SVC, series capacitors) at CVSS 9.9 when the GWS component is present — 2024 CVEs, no versioned fix in the ICSA. Same week: Wärtsilä FOS-Onboard hardcoded update keys (CVE-2026-78225 / CVE-2026-81855), mySCADA myPRO Manager unauthenticated command API (CVE-2026-73807, 9.8), Mitsubishi GX Works3 block-password bypass on all versions (CVE-2026-15688), and CC-Link IE TSN with no fix planned. CISA republished last week’s Reyrolle 7SR5 and SCADAPack notes. No new Stage 2 ICS malware. The KEV is Cisco ISE.

RWP Ventures · 2026-09-18 · 16 min read · priority 8.5

Bottom line up front

CONFIRMED This week’s public OT calendar was two CISA ICS drops — eight advisories on 15 September, seven new plus one update on 17 September — not a named plant-floor malware event and not a new Stage 2 ICS kill-chain case.

The product that belongs at the top of a transmission operator’s queue is not last week’s Modicon M580. On 17 September CISA published ICSA-26-260-03 on Hitachi Energy FACTS Control Platform with the GWS component. Headline CVSS v3.1 9.9 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) on CVE-2024-4872 and CVE-2024-3980. Affected trains: FCP 3.4.0 through 4.1.1. Hitachi’s own scope, as republished by CISA: SVC Light (STATCOM), fixed series capacitor, thyristor-controlled series capacitor, static var compensator, static watt compensator, hybrid synchronous condensers — deployments from 2020 onward if GWS is present. Deployments without GWS are out. The ICSA does not name a patched FCP version. Remediation is “follow general mitigation factors” and Hitachi advisory 8DBD000229. SSVC on the CISA page is E:N — no exploitation recorded.

Same CISA week, two remotely reachable ICS-management issues that are easier to ticket than a FACTS GWS estate:

The only CONFIRMED in-the-wild activity with an 11–18 September timestamp that OT operators should treat as a live ticket is not a PLC. On 16 September CISA added CVE-2026-76460 (Cisco ISE / ISE-PIC unauthenticated privileged-API bypass) to KEV, federal due 19 September, forensic triage under BOD 26-04. That is an identity-control-plane compromise class. It is an IT-to-OT path where the plant NAC, 802.1X, or contractor VPN terminates on ISE. It is not confirmation that a controller was reprogrammed.

Do not upgrade this week’s ICSA pile into FrostyGoop. Last week’s live OT threat is unchanged: internet-reachable PLCs and engineering-client abuse named in AA26-097A and AA26-231A. CVE-2026-3869 on M580 / M580 Safety still has no CISA ICSA as of 18 September morning.

OT threat posture

Exposure, engineering-path abuse, and now a KEV’d identity appliance remain higher confidence than novel ICS malware. Ransomware still hurts plants by killing the Windows and hypervisors OT depends on — vCenter CVE-2026-59310 is on KEV with a ransomware flag; that is a hypervisor story, not a ladder-logic story. No public primary source this week documented a new ladder-logic change or a new ICS-specific wiper.

1. Most significant development

Hitachi Energy FACTS Control Platform with GWS, because it is transmission-level process control (STATCOM / SVC / series compensation), CISA scored the authenticated injection and path-traversal issues 9.9 with changed scope, and the ICSA gives operators no firmware train to flash.

Why this outranked the rest of the week: mySCADA CVE-2026-73807 is more exploitable on paper (unauthenticated 9.8) and will hit more water and food sites than a FACTS GWS install base. Wärtsilä’s update-controller key is the cleaner “unauthorized firmware” failure mode. Neither is a grid FACTS controller sitting on reactive power and series compensation. Reyrolle 7SR5 CVE-2026-62645 is as severe as last week and now has an ICSA, but it is last week’s ProductCERT note, not a new finding. Cisco ISE is the exploited box — it is not an ICS product. Score for the week: 8.5. mySCADA-only would have been ~8.4 on actionability and ~8.0 on grid consequence. Wärtsilä-only belongs in marine and in section 6. ISE-only belongs in the IT briefing and in section 5 here.

2. Adversary / campaign activity

No new joint USG OT campaign advisory this week. Continuing, still the current hunt set:

CONFIRMED (non-ICS, this week): Cisco ISE CVE-2026-76460, CISA KEV 16 September, CCCS AL26-021 17 September. Cisco has confirmed exploitation. Federal due 19 September. Hunt is in the 17 September Daily Top, not here.

UNKNOWN an 11–18 September named victim with a confirmed ladder-logic, protection-setting, or FACTS-GWS change.

3. Vulnerabilities and active exploitation

CONFIRMED (CISA ICS, 17 September)

AdvisoryProductCVEWhat it actually is
ICSA-26-260-03Hitachi Energy FACTS FCP with GWS, 3.4.0–4.1.1CVE-2024-4872, CVE-2024-3980 (9.9); CVE-2024-3982 (8.2); CVE-2024-7940 (8.3); CVE-2024-7941 (4.3)Authenticated injection into persistent data; authenticated path traversal; local session hijack if logging enabled; unauthenticated bind of a local-only service; open redirect. No patched version in the ICSA. 2024 CVE IDs, 17 September 2026 publication.
ICSA-26-260-02Mitsubishi GX Works3 / Motion Control Settings, all versionsCVE-2026-15688Incorrect authentication algorithm. Local attacker authenticates with an invalid block password, patches the process in memory, then views, tampers, destroys, or deletes control programs. CVSS 8.8 / 9.2. Workaround: GX Works3 1.096A or later and security version 2; Motion Control Settings 1.070Y or later and security version 2. Installing the build without flipping security version is not the Mitsubishi fix.
ICSA-26-211-07 Update AMitsubishi CC-Link IE TSN protocol — MELSEC MX, remote I/O including safety NZ2GNSS2, MELSERVO-J5, FR-A/E800, GOT3000, CR800 robotsCVE-2026-13584CWE-924. Same-segment attacker, crafted packets, specific timing: tamper with control I/O, DoS, or incorrect operation. CVSS 7.1. No fix planned. Mitigate: physical / cabinet / port lock, trusted segment, firewall. Nozomi (Di Pinto, Gentilini, Cremona, Quagliarella) reported it.
ICSA-26-260-04Schneider Modicon M340 + X80 Ethernet / RTU / FactoryCast / M580 Global DataCVE-2025-6625Crafted FTP command → DoS. CVSS 7.5. FTP is disabled by default. Fixes: M340 SV3.70, BMXNOE0100 3.60, BMXNOE0110 6.80, BMXNOR0200H SV1.7 IR27. All-version products (M580 Global Data, some X80 / RTU) have a “remediation plan” and the same FTP-off / 21/TCP block. SEVD-2025-224-05.
ICSA-26-260-06ABB Ability Edgenius ≥3.2.0.0 <3.2.4.1 on bE100 gatewayCVE-2026-31431“Copy Fail” Linux kernel local root. Fix 3.2.4.1. Same kernel CVE Siemens rolled into industrial products last week.
ICSA-26-260-05Schneider NetBotz 5 750/755 ≤5.5.2CVE-2026-13336, CVE-2026-13337OS command injection on restore of a malicious backup (6.4); Hibernate SQLi when logged in (4.6). Fix 5.6.0. Data-center environmental monitor, not a PLC.
ICSA-26-260-07Schneider PowerChute Serial Shutdown ≤1.5CVE-2026-13348Excessive authentication attempts, CVSS 5.3. Fix 1.6. UPS helper, not process control.
ICSA-26-260-01Bransys ELD Android <11.00.00 / iOS <1.1.54CVE-2026-86520, CVE-2026-86689, CVE-2026-77960Hardcoded MQTT credentials (read of live telematics across a subset of carriers), cleartext broker, hardcoded FTP. Transportation ELD, United States. App-store update. Not a plant controller.

CONFIRMED (CISA ICS, 15 September)

AdvisoryProductCVEWhat it actually is
ICSA-26-258-02Wärtsilä FOS-Onboard 5.07.0923.01CVE-2026-78225, CVE-2026-81855Hardcoded update-controller server key; hardcoded robot-test client key. Unauthorized update / impersonation. Patch via vendor contact.
ICSA-26-258-03mySCADA myPRO Manager ≤2.1CVE-2026-73807 (9.8), CVE-2026-82567 (6.3)Unauthenticated privileged command API; unauthenticated SMS via GSM modem. Fix 2.2.
ICSA-26-258-05Siemens Reyrolle 7SR5 < V2.70CVE-2026-62645 (9.8) plus 62646–62654 and bundled MongooseCISA republication of SSA-142885 (8 September). Session-ID calculation, low-entropy sessions, unauthenticated DoS, RBAC bypass. Fix V2.70. Last week’s lead; this week it becomes a federal/contractor ICSA ticket.
ICSA-26-258-04Schneider SCADAPack 47x/57x/3xx/32, all versions listedCVE-2026-81861 (6.5)CISA republication of SEVD-2026-251-03. Insufficiently protected credentials on Secure Lock. Schneider’s mitigation is RBAC instead of Secure Lock, plus the RTU firewall — not a firmware flash.
ICSA-26-258-01Digital Watchdog VMAX A1 G4 / IP G4 / PLUS, all versions listedCVE-2026-66890 / 66887 (9.6) and relatedHardcoded FTP-as-root, missing CGI authorization, predictable sessions, unauthenticated credential disclosure. CISA: full admin, live/recorded video, network pivot. Scot Berner (TrustedSec). Firmware at digital-watchdog.com/downloads. Physical-security recorder, not a PAC.
ICSA-26-258-06Siemens Mendix SAML <4.2.3 / <3.6.27CVE-2026-80465 (8.7)SAML response signature not validated; account hijack in specific SSO configs. SSA-887643 dated 3 September; CISA republication 15 September.
ICSA-26-258-07Siemens Teamcenter V2412–V2606 trains listedCVE-2026-58113 (6.1)Reflected XSS in /auth/ redirect. SSA-157465 dated 8 September; CISA republication 15 September. PLM, not a controller.
ICSA-26-258-08CareCam CM2507 firmware v251211.1507CVE-2026-88259 and six othersUnauthenticated live video; empty ONVIF password; credential recovery. Commercial-facilities camera. Follow-on to last week’s CareCam Pro physical-bootloader note, different model.

CONFIRMED (active exploitation, not ICS): Cisco ISE CVE-2026-76460, KEV 16 September. Acronis Backup CVE-2026-87886 the same day — cPanel/Plesk plugin, not OT. vCenter CVE-2026-59310 remains KEV with ransomware Known from 16 September’s Daily Top. ScreenConnect CVE-2026-84869 and GitLab CVE-2026-85706 were last week’s IT KEV clock (due 14 September). MikroTik RouterOS CVE-2026-67277 / CVE-2026-86060 remains last week’s edge-router hunt; no new industrial-ASN confirmation in this window.

NOT this week’s OT story: Check Point CVE-2026-91843 (16 September, CVSS 9.8, unauthenticated stack overflow on Security Management / Log Server, LivePatch Take 28/29). Vendor reports no exploitation; not on KEV catalog 2026.09.16. It becomes an IT-to-OT path if that manager pushes policy onto the plant firewall. That is the 18 September Daily Top, not a PLC advisory.

Still missing from CISA ICS: Schneider CVE-2026-3869 on M580 / M580 Safety. Last week’s watch item. As of 18 September the ICS index still does not list it. Primary source remains SEVD-2026-251-04.

4. ICS / SCADA impact

No CONFIRMED new loss-of-view or loss-of-control event dated 11–18 September in CISA ICS, FBI/EPA, Hitachi Energy’s FACTS notice, Wärtsilä, mySCADA, Mitsubishi PSIRT, or Siemens ProductCERT.

What would become process impact, if exploited on an exposed or poorly segmented box:

Prior water PLC tampering (July) and the UK small-generator outage (late July, disclosed August) remain the last well-sourced availability hits. They are not this week’s news.

5. IT-to-OT exposure

Four doors this week, in the order operators can actually hunt:

  1. Cisco ISE / ISE-PIC with the management interface reachable. Plant 802.1X, contractor VPN, and jump-host admission often terminate here. CVE-2026-76460 is unauthenticated privileged-API bypass, KEV, due 19 September, forensic triage required for FCEB. Patching without hunting access.log is not remediation — see the Daily Top. CCCS AL26-021 is the operator checklist (3.1 P12 / 3.2 P11 / 3.3 P12 / 3.4 P7 / 3.5 P4).
  2. VMware vCenter that hosts historians, HMIs, or engineering VMs. CVE-2026-59310 is KEV with ransomware Known. Encrypting the appliance is an OT outage without a single S7 packet. Image, then patch.
  3. ScreenConnect and other RMM that still have a plant session. CVE-2026-84869 due date was 14 September. Huntress’s worm-like VBScript propagation is an IT finding that becomes an OT finding the moment a session is open to an HMI or an engineering laptop. Client ≥ 26.6.5; reinstall the host client, do not trust “cloud, no action.”
  4. Check Point Security Management / Log Server (CVE-2026-91843) and leftover MikroTik WAN SSH (last week’s ops / user added by ssh:-2@). Management-plane root and CPE root are how a commodity IT session becomes a machine session without touching a coil.

Ignition, engineering workstations, and internet-facing 44818/102/502/2222 remain the standing hunt from AA26-097A / AA26-231A. That hunt does not reset because CISA republished Reyrolle.

6. Sector impact

7. Defensive priorities

  1. Internet-facing PLC eradication — still number one. VPN or jump host, never the controller. AA26-097A / AA26-231A have not been withdrawn.
  2. Hitachi FACTS: inventory GWS. If GWS is present on FCP 3.4.0–4.1.1, open 8DBD000229 with the Hitachi service organization. Do not wait for a version string CISA did not publish. Restrict GWS to the engineering VLAN; it is not an internet service.
  3. mySCADA myPRO Manager to 2.2. If you cannot patch this week, take the command API and the SMS gateway off every untrusted segment. An unauthenticated privileged API on a water SCADA manager is the ticket.
  4. Wärtsilä FOS-Onboard: contact Wärtsilä for the ICS patch, then prove the running image is the patched one. “Installed as recommended” is an audit finding until it is a screenshot.
  5. GX Works3: 1.096A+ and project security version 2. Same for Motion Control Settings 1.070Y+. Local engineering-workstation control. Lock physical access; this CVE is AV:L.
  6. CC-Link IE TSN: there is no firmware. Cabinet locks, port locks, no untrusted host on the TSN segment. Safety remote modules are in the affected list — tell the safety engineer, not just the Windows patcher.
  7. Reyrolle 7SR5 to V2.70 if last week’s window slipped. SCADAPack: RBAC instead of Secure Lock; enable the RTU firewall.
  8. M340: confirm FTP is off (default). Flash the modules that have a build; firewall 21/TCP for the rest.
  9. ISE: patch plus hunt. vCenter: patch plus hunt. ScreenConnect host client: reinstall. MikroTik: still hunt ops.
  10. Do not wait for ICS-specific malware. Dragos already told you ransomware did not need Stage 2.

8. What changed from last week

Last week (ending 11 September) was vendor Patch Tuesday — Schneider M580 Safety auth, Siemens Reyrolle and IEM, AVEVA PIM via CISA on the 10th, and a KEV on MikroTik. This week CISA republished Reyrolle (ICSA-26-258-05) and SCADAPack (ICSA-26-258-04), and added a grid FACTS 9.9, a marine update-controller key, an unauthenticated mySCADA manager, an all-versions GX Works3 engineering bypass, and a no-fix CC-Link IE TSN protocol note. CVE-2026-3869 on M580 still has no ICSA. No new USG PLC campaign update. No new FBI/EPA water PSA. No new industrial-ransomware quarter. The exploited identity box moved from FMC (9 September) to ISE (16 September). AA26-231A is 30 days old.

9. What OT defenders should watch next

Whether Hitachi publishes a versioned FCP/GWS patch, or whether 8DBD000229 stays mitigations-only. Whether mySCADA 9.8 or Wärtsilä’s update key grows an in-the-wild note. Whether CISA finally republishes CVE-2026-3869. Whether CC-Link IE TSN CVE-2026-13584 stays “no fix planned” after Update A. Whether ISE compromise is observed on industrial 802.1X estates, not only enterprise campuses. Q3 industrial ransomware counts. Any AA26-097A or water-PSA refresh.

10. RWP assessment

High confidence: this week is CISA converting last week’s vendor stack into ICSAs, plus a grid FACTS 9.9, a marine update key, and an unauthenticated SCADA-manager API. High confidence: exposed controllers and engineering paths in AA26-097A / AA26-231A remain the incident class that has evidence. High confidence: GX Works3 without security version 2, and CC-Link IE TSN without segmentation, are unfixed even after the operator “applied the advisory.” Moderate confidence: a non-trivial number of water and food sites still have myPRO Manager ≤2.1 reachable from a jump VLAN. Moderate confidence: FACTS GWS is a small population, but it is the wrong small population to leave on a 9.9 with no firmware string. Low confidence: a new OT malware family dropped in the last seven days. Labeling a manufacturer ransomware victim, an ISE appliance, or a Digital Watchdog NVR as “OT compromise” without process evidence remains a briefing error.

This assessment covers 11–18 September 2026 and was published 18 September 2026.

Sources

  1. CISA — ICS Advisories index 17 September 2026
  2. CISA — ICSA-26-260-03 Hitachi Energy FACTS Control Platform (FCP)
  3. Hitachi Energy — Security advisory 8DBD000229
  4. CISA — ICSA-26-258-02 Wärtsilä FOS-Onboard
  5. CISA — ICSA-26-258-03 mySCADA myPRO Manager
  6. CISA — ICSA-26-260-02 Mitsubishi Electric GX Works3 and Motion Control Settings
  7. Mitsubishi Electric — PSIRT 2026-007 GX Works3
  8. CISA — ICSA-26-211-07 Mitsubishi Electric CC-Link IE TSN (Update A)
  9. Mitsubishi Electric — PSIRT 2026-005 CC-Link IE TSN
  10. CISA — ICSA-26-260-04 Schneider Electric Modicon M340 Controller and Communication Modules
  11. Schneider Electric — SEVD-2025-224-05 Modicon M340
  12. CISA — ICSA-26-258-05 Siemens Reyrolle 7SR5
  13. CISA — ICSA-26-258-04 Schneider Electric SCADAPack x70 Products
  14. CISA — ICSA-26-258-01 Digital Watchdog VMAX DVR and NVR
  15. CISA — ICSA-26-258-06 Siemens Mendix SAML
  16. CISA — ICSA-26-258-07 Siemens Teamcenter
  17. CISA — ICSA-26-258-08 CareCam CM2507
  18. CISA — ICSA-26-260-01 Bransys ELD
  19. CISA — ICSA-26-260-05 Schneider Electric NetBotz 5 750/755
  20. CISA — ICSA-26-260-06 ABB Ability Edgenius
  21. CISA — ICSA-26-260-07 Schneider Electric PowerChute Serial Shutdown
  22. CISA — Adds two KEVs 16 September 2026 (Cisco ISE, Acronis)
  23. Canadian Centre for Cyber Security — AL26-021 Cisco ISE
  24. Siemens ProductCERT — SSA-142885 Reyrolle 7SR5
  25. CISA — AA26-231A Defending against an active threat to Siemens S7
  26. CISA — AA26-097A Iranian-affiliated actors exploit PLCs
  27. RWP — Weekly OT 11 September 2026
  28. RWP — Daily Top Cisco ISE CVE-2026-76460
  29. RWP — Daily Top Check Point CVE-2026-91843
  30. RWP — Daily Top VMware vCenter CVE-2026-59310
  31. ICS Advisory Project — Dashboards 15 and 17 September 2026