CISA scored lwIP MQTT 9.8. The fix is a git commit. The exploited device this week is a Zyxel, not a PLC.
18–25 September 2026. ICSA-26-265-01 puts the lwIP MQTT client at CVSS 9.8 — versions 2.0.1 through 2.2.1, no product list, remediation is a Savannah commit. Same CISA day: Siemens IEM Keycloak reset (CVE-2026-18963, 9.1) becomes an ICSA, Siveillance OIS file-upload-to-root, SIMOVE/SIPLANT unauth file read, Copy Fail on Unified HMI / IoT2050 / S7-1500 TM MFP, Desigo CC V6/V7 with no fix. OpenPLC v3 is EOL. The KEV is Zyxel GS1900, then F5 APM.
Bottom line up front
CONFIRMED This week’s public OT calendar was CISA’s 22 September nine-advisory drop (ICSA-26-265-01 through -09), plus two consumer ICSAs and a revoked Mendix note on the 24th — not a named plant-floor malware event and not a new Stage 2 ICS kill-chain case.
The finding that belongs at the top of an OT queue is not last week’s Hitachi FACTS GWS. On 22 September CISA published ICSA-26-265-01 on the lwIP MQTT client application, versions 2.0.1 through 2.2.1. Headline CVSS v3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) on CVE-2026-87121 (CWE-787 out-of-bounds write). CISA’s summary sentence is the operator one: successful exploitation “could allow an attacker to gain full code execution on the device.” The vendor named on the page is lwIP. The equipment named on the page is lwIP. There is no OEM, no SKU, no firmware train. Remediation is a commit on Savannah: f89407ea711879c04d91c92b35d67be78bbaf0f1. Shahriyar Jalayeri (ByteRay) reported it. No known public exploitation.
Same CISA day, the Siemens stack that ProductCERT shipped on 8 September (WTV on 16 September) becomes a federal/contractor ICSA pile. The one you can actually ticket tonight, if you run it, is Industrial Edge Management:
- IEM Cloud / Pro / Virtual (ICSA-26-265-06, republication of SSA-503852). CVE-2026-18963, CVSS 9.1 (
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). Keycloakreset-credentialsdoes not require the email-verification click. Unauthenticated account takeover. Cloud was firewalled 26 August and patched 2 September — no customer action. On-prem: Pro V1 → 1.15.20, Pro V2 → 2.2.2, Virtual → 2.9.1. Until then: take the instance off the internet, or WAF/auth/realms/customer/login-actions/reset-credentials, or turn Forgot password off in the realm. This CVE was last week’s ProductCERT note. This week it is an ICSA.
The only CONFIRMED in-the-wild activity with an 18–25 September timestamp that OT operators should treat as a live ticket is not a PLC. On 21 September CISA added CVE-2026-7273 (Zyxel GS1900 CGI command execution) to KEV, federal due 24 September. GreyNoise’s public count, as covered in the [22 September Daily Top](/posts/2026-09-22-zyxel-gs1900-cve-2026-7273-kev/), is 996 switches in 48 countries. That is an access-switch / plant-edge path. It is not confirmation that a controller was reprogrammed. F5 APM CVE-2026-94127 (KEV 22 September, due 25 September) is the plant-VPN analogue if APM is the OAuth authorization server.
Do not upgrade this week’s ICSA pile into FrostyGoop. Last week’s live OT threat is unchanged: internet-reachable PLCs and engineering-client abuse named in AA26-097A and AA26-231A. CVE-2026-3869 on M580 / M580 Safety still has no CISA ICSA as of 25 September morning. Hitachi FACTS FCP/GWS still has no versioned patch in last week’s ICSA.
OT threat posture
Exposure, engineering-path abuse, and now a KEV’d access switch remain higher confidence than novel ICS malware. Ransomware still hurts plants by killing the Windows and hypervisors OT depends on — vCenter CVE-2026-59310 remains KEV with ransomware Known; that is a hypervisor story, not a ladder-logic story. No public primary source this week documented a new ladder-logic change or a new ICS-specific wiper.
1. Most significant development
lwIP MQTT client CVE-2026-87121, because CISA scored unauthenticated network code execution 9.8 on a TCP/IP stack that is compiled into other people’s firmware, named no products, and pointed operators at a git commit instead of a firmware pull.
Why this outranked the rest of the week: IEM CVE-2026-18963 is more actionable (unauthenticated, network, three versioned fixes, a WAF path you can cut tonight). It is also last week’s Siemens note with an ICSA stamped on it. Siveillance CVE-2026-50093 is file-upload-to-root on a physical-security server — adjacent, low privilege, patched. SIMOVE/SIPLANT CVE-2026-67367 is unauthenticated file read of keys. Copy Fail on Unified HMI / IoT2050 / S7-1500 TM MFP is the only CVE in the Siemens batch with a KEV history, and it is local. Zyxel GS1900 is the exploited box — it is not an ICS product. Score for the week: 8.4. IEM-as-lead would have been ~8.2 as a republication. Zyxel-only belongs in the IT briefing and in section 5 here. lwIP-only on actionability is a supplier question, not a flash; it still wins on novelty and on how many OT networks will silently carry MQTT clients built on 2.0.1–2.2.1.
2. Adversary / campaign activity
No new joint USG OT campaign advisory this week. Continuing, still the current hunt set:
- AA26-097A (April, updated 22 July): Iran-affiliated actors using Studio 5000 / EcoStruxure Control Expert / TIA Portal against internet PLCs (CompactLogix, Micro850, Modicon M340, S7-1200). CONFIRMED as USG. No new victim set this window.
- FBI/EPA 30 July water PSA: MicroLogix 1100/1400, seven states. CONFIRMED as PSA. Not this week’s news.
- AA26-231A (19 August): recon and capability development on US S7-200/300/400/1200 using internet scans and AI-generated “monitoring” scripts. CONFIRMED as USG wording. Now five weeks old. No new victim set this window.
CONFIRMED (non-ICS, this week): Zyxel GS1900 CVE-2026-7273, CISA KEV 21 September, federal due 24 September, forensic triage under BOD 26-04. GreyNoise campaign telemetry is in the Daily Top, not here. F5 BIG-IP APM CVE-2026-94127, KEV 22 September, due 25 September — data-plane heap overflow when APM is an OAuth authorization server; appliance mode is in; closing the management port does not close the virtual server. WSO2 CVE-2026-5430, KEV 24 September, due 27 September — JWT algorithm mismatch, not a file-upload RCE; identity plane.
UNKNOWN an 18–25 September named victim with a confirmed ladder-logic, protection-setting, FACTS-GWS, or IEM-account change.
3. Vulnerabilities and active exploitation
CONFIRMED (CISA ICS, 22 September — original CISA work)
| Advisory | Product | CVE | What it actually is |
|---|---|---|---|
| ICSA-26-265-01 | lwIP MQTT client app 2.0.1–2.2.1 | CVE-2026-87121 | Out-of-bounds write, unauthenticated network, full code execution. CVSS 9.8 / 9.3 (v4). Fix = Savannah commit f89407ea711879c04d91c92b35d67be78bbaf0f1. No tagged product firmware. No known public exploitation. |
| ICSA-26-265-02 | lwIP API 2.0.1–2.2.1 | CVE-2026-91018 | Double free. CVSS 8.8 AV:A. CISA: “not exploitable remotely.” Crash / DoS / memory corruption / possible code execution. Fix = commit f873b6295933e4149a2132adf3e9a2d2a676a5ec on cgit. Eric Evenchick (Tetrel) reported it. No known public exploitation. |
| ICSA-26-265-09 | Autonomy Logic OpenPLC Runtime v3 | CVE-2026-88020 | Reflected XSS on a query-string route. CVSS 6.1 UI:R. CISA’s impact sentence is process-level: session-cookie hijack, state-changing requests as the operator, “control the programmable logic controller and the physical processes it drives.” Vendor: v3 is end-of-life; move to v4. No v3 patch. Rajivarnan R. and Shirshak (Secnora). No known public exploitation. |
CONFIRMED (CISA ICS, 22 September — Siemens ProductCERT republications)
CISA’s own disclaimer on each of these pages: verbatim conversion of the Siemens CSAF, “as-is.” Revision 1 is the Siemens date; revision 2 (22 September) is the CISA republication.
| Advisory | Product | CVE | What it actually is |
|---|---|---|---|
| ICSA-26-265-06 | IEM Cloud (all); Pro V1 ≥1.14.9 <1.15.20; Pro V2 ≥2.2.0 <2.2.2; Virtual ≥2.6.0 <2.9.1 | CVE-2026-18963 | Keycloak weak password-recovery. Unauthenticated remote account takeover. CVSS 9.1. SSA-503852 dated 8 September. Cloud already patched. On-prem versioned fixes plus internet-off / WAF / Forgot-password-off. |
| ICSA-26-265-03 | Siveillance Control / Control Pro V3.0 and V4.0 trains listed | CVE-2026-50093 | OIS web module unrestricted file upload → root on the OIS host. CVSS 9.0 AV:A/PR:L/S:C. SSA-254516. Fixes: Control Pro 3.0.12.2173 / 4.0.9.2178; Control 3.0.22.2177 / 4.0.11.2177. |
| ICSA-26-265-07 | SIMOVE Fleetmanager 3.1–4.0 trains; SIPLANT 1.7, 2.2, 3.0 (all), 3.1 <3.1.4 | CVE-2026-67367 | Unauthenticated path traversal on the embedded HTTP file-serving endpoint. Read of credential stores, private keys, configuration. CVSS 8.6 S:C. SSA-517424. Fleetmanager has versioned fixes. SIPLANT 1.7 / 2.2 / 3.0: contact siplant-support.de@siemens.com. |
| ICSA-26-265-04 | SIPLUS / SIMATIC Unified HMI <21.0.2.1, CN 4100 <6.0, AX Runtime (all listed), IoT2050 Advanced all, S7-1500 TM MFP all, IED-OS all | CVE-2026-31431 | Linux kernel “Copy Fail” (algif_aead in-place). Local privilege escalation. CVSS 7.8 AV:L/PR:L. SSA-328642. HMI fix is V21 Update 2 SR1; CN 4100 → 6.0. IoT2050 Advanced and S7-1500 TM MFP: CISA lists vers:all/*. Same kernel CVE last week’s ABB Edgenius ICSA already named. KEV catalog has carried Copy Fail since spring; that is kernel exploitation, not a Siemens-specific in-the-wild claim. |
| ICSA-26-265-05 | Desigo CC family V6 and V7, all versions | CVE-2026-34223 | Client code execution via scripts in user-defined graphics documents. CVSS 8.2 AV:L/PR:L/UI:R/S:C. SSA-330084. Michelin CERT to Siemens. Currently no fix. Mitigation: least-privilege on the Graphics application. |
| ICSA-26-265-08 | WTV676-HB6035 web <3.94; WTV776-HB6035 web <4.17 | CVE-2026-89207 | Unauthenticated input from backend services forces protection mode; remote Web Access dies. CVSS 6.5. Energy sector tag. SSA-823812 dated 16 September. Fixes V3.94 / V4.17. |
CONFIRMED (CISA ICS, 24 September — not process control)
| Advisory | Product | CVE | What it actually is |
|---|---|---|---|
| ICSA-26-267-01 | Botslab G980H dashcam two firmware trains | Thirteen CVEs, headline 8.8 | Session confusion, predictable IDs, replay, weak Wi-Fi password, UART root on one train, hardcoded crypto. Vendor has not responded to CISA. Transportation-sector tag. Adjacent-network consumer camera, not a PAC. |
| ICSA-26-267-02 | Eufy Omni C20 / X10 Pro <1.6.4 | CVE-2026-93289 / 93290 / 93291 | Pairing-time command injection; hardcoded credentials; missing cert validation (C20 9.4). Fix 1.6.4. IT-sector tag. Robot vacuum, not a controller. Jared (Somerset Recon). No known public exploitation. |
| ICSA-26-209-02 Update A | Siemens Mendix Runtime | CVE-2026-7891 rejected | Advisory revoked. Siemens re-investigation: expected platform configuration, protected attribute not exposed. Product status not_affected. Do not open a Mendix Runtime 9.1 ticket from this ICSA. Last week’s Mendix SAML CVE-2026-80465 (ICSA-26-258-06) is a different module and is not revoked. |
CONFIRMED (active exploitation, not ICS): Zyxel GS1900 CVE-2026-7273, KEV 21 September. F5 APM CVE-2026-94127, KEV 22 September (one of four rows that day). WSO2 API Manager CVE-2026-5430, KEV 24 September. Linux kernel trio (kTLS / ebtables / af_alg) was 18 September, due 21 September — IT. Cisco ISE CVE-2026-76460 remains last week’s identity KEV (due 19 September). vCenter CVE-2026-59310 remains KEV with ransomware Known. MikroTik RouterOS CVE-2026-67277 / CVE-2026-86060 remains the 11 September edge-router hunt; no new industrial-ASN confirmation in this window.
Still missing from CISA ICS: Schneider CVE-2026-3869 on M580 / M580 Safety. Two-week watch item. As of 25 September morning the ICS index still does not list it. Primary source remains SEVD-2026-251-04. Hitachi FACTS ICSA-26-260-03 still names no patched FCP version.
4. ICS / SCADA impact
No CONFIRMED new loss-of-view or loss-of-control event dated 18–25 September in CISA ICS, FBI/EPA, Siemens ProductCERT, or the lwIP project page.
What would become process impact, if exploited on an exposed or poorly segmented box:
- lwIP MQTT OOB write → code execution on whatever embedded device compiled that client. You will not see “lwIP” in the asset register. The question is to the OEM: which of our MQTT-speaking meters, RTUs, sensors, or gateways shipped 2.0.1–2.2.1. Until that answer exists, internet-facing MQTT is the compensating control.
- lwIP 6LoWPAN double-free → adjacent-network only, per CISA. Radio-mesh / 6LoWPAN segments, not the WAN.
- IEM account takeover → integrity of the edge-management plane that deploys apps onto Industrial Edge devices. That is not a PLC rewrite. It is how an unauthenticated session becomes a trusted app-store admin.
- Siveillance OIS root → compromise of the physical-security / PSIM server. Pivot risk into the same VLAN as BMS or video. Not a PAC.
- SIMOVE/SIPLANT file read → AGV fleet-manager and plant-simulation credentials and keys. Manufacturing. SIPLANT lines without a versioned fix stay in “call support.”
- Copy Fail on Unified Comfort/Basic, IoT2050, S7-1500 TM MFP → local root on a Linux-based Siemens box once someone already has a low-priv shell. The HMI estate is the large population; the TM MFP / IoT2050 “all versions” rows are the ones with no flash in the ICSA.
- Desigo CC graphics CCE → building-management engineering client. User must open the document. No firmware is coming for V6/V7.
- OpenPLC v3 XSS → only if you still run the EOL runtime as a controller. CISA wrote the process-impact sentence; the score is 6.1 with a user click. Treat v3 as out of support, not as this week’s plant-floor incident.
- WTV protection-mode DoS → loss of Web Access on those energy web interfaces, not trip of a feeder.
Prior water PLC tampering (July) and the UK small-generator outage (late July, disclosed August) remain the last well-sourced availability hits. They are not this week’s news.
5. IT-to-OT exposure
Five doors this week, in the order operators can actually hunt:
- Zyxel GS1900 on a plant, contractor, or camera VLAN. CVE-2026-7273 is unauthenticated CGI command execution, KEV, due 24 September. Vendor scored it
AV:A. GreyNoise’s 996-switch collection is what you get when that CGI is on the internet, on a VPN that is not the LAN you think it is, or still onadmin. Firmware2.90(*.2)C0shipped 16 June. Patching without asking who still has factory-default credentials is incomplete — see the Daily Top. - F5 BIG-IP APM that is an OAuth authorization server for contractor or plant remote access. CVE-2026-94127 is unauthenticated data-plane RCE on the virtual server, KEV, due 25 September. Appliance mode is in. Closing the management GUI is not the fix. Inventory the role, not the APM checkbox. iRule on the affected VIP, then the engineering hotfix. [23 September Daily Top](/posts/2026-09-23-f5-big-ip-apm-cve-2026-94127-kev/).
- Cisco ISE / ISE-PIC from last week. Due date was 19 September. Hunt
access.log. CCCS AL26-021 is still the operator checklist. A patched ISE that was reachable is a forensics problem, not a closed ticket. - VMware vCenter that hosts historians, HMIs, or engineering VMs. CVE-2026-59310 remains KEV with ransomware Known. Encrypting the appliance is an OT outage without a single S7 packet.
- WSO2 API Manager / Control Plane / Universal Gateway if that is how plant APIs or partner integrations authenticate. CVE-2026-5430 is JWT
algconfusion (CWE-347), KEV 24 September, due 27 September. CISA’s catalog title says path traversal; WSO2’s advisory says JWT. Hunt forged admin tokens, then patch. [25 September Daily Top](/posts/2026-09-25-wso2-cve-2026-5430-kev/).
Ignition, engineering workstations, and internet-facing 44818/102/502/2222 remain the standing hunt from AA26-097A / AA26-231A. That hunt does not reset because CISA republished IEM.
6. Sector impact
- Electric / transmission: Last week’s Hitachi FACTS FCP with GWS is still the sector-specific lead and still has no versioned firmware in the ICSA. WTV676/776 Web Access DoS is this week’s energy-tagged Siemens note — availability of the web UI, not a protection-element rewrite. Reyrolle 7SR5 V2.70 from two weeks ago is still the protection-relay ticket if that window slipped. AA26-231A S7 exposure is still the Siemens PLC lead.
- Process manufacturing: IEM off the internet and onto 1.15.20 / 2.2.2 / 2.9.1. SIMOVE Fleetmanager to the listed builds; SIPLANT via support. Copy Fail: Unified HMI to V21 Update 2 SR1; treat IoT2050 Advanced and S7-1500 TM MFP as unfixed in this ICSA. lwIP MQTT is a supplier letter, not a TIA flash.
- Building / commercial facilities: Desigo CC V6/V7 — no fix; lock Graphics configuration to the people who need it. Siveillance Control / Control Pro to the OIS builds above. Do not wait for a V6/V7 patch that Siemens has not published.
- Water / food / small SCADA: Last week’s mySCADA myPRO Manager 2.2 is still the unauthenticated-management ticket. OpenPLC v3 only if a lab or a small utility actually runs it — then it is an EOL replacement, not a CVE race.
- Marine / transportation: Last week’s Wärtsilä FOS-Onboard patch-via-vendor remains open. Botslab G980H is a dashcam with a transportation tag and a non-responsive vendor; treat as consumer IoT on a vehicle network, not engine control.
- Oil and gas midstream: AVEVA PIM 2025 SP1 P2 from 10 September is still open if project-file migration is not done. No new midstream ICSA this window.
- Physical security / cameras / consumer IoT: Botslab (no vendor response) and Eufy Omni 1.6.4. Last week’s Digital Watchdog VMAX and CareCam CM2507 remain the plant-camera pivot notes. Eufy is a vacuum. Do not brief it as ICS compromise.
7. Defensive priorities
- Internet-facing PLC eradication — still number one. VPN or jump host, never the controller. AA26-097A / AA26-231A have not been withdrawn.
- IEM: if Pro or Virtual is reachable from an untrusted network, take it off today. Then patch to 1.15.20 / 2.2.2 / 2.9.1. Cloud tenants needed no action after 2 September. WAF the reset-credentials path only if you cannot isolate.
- lwIP: do not file a “patch lwIP” change request against a PLC that does not have a version string. Ask every MQTT-speaking OEM whether the image includes 2.0.1–2.2.1. Until they answer, MQTT from untrusted networks is the control.
- Zyxel GS1900: firmware, then hunt
admin. Due date was yesterday for FCEB. Plant and camera VLANs are in scope even when the switch is “just access.” - F5 APM: inventory OAuth authorization server virtual servers. iRule, hotfix, hunt. Management-port closure is the wrong ticket.
- Siveillance OIS to the listed builds. SIMOVE to the listed builds. SIPLANT: open the support case; three lines have no version in the ICSA.
- Copy Fail: Unified HMI to V21 Update 2 SR1. CN 4100 to 6.0. IoT2050 Advanced and S7-1500 TM MFP — compensating controls (local access, no untrusted shell) until Siemens publishes a build. This is local; it does not outrank an internet PLC.
- Desigo CC V6/V7: least privilege on Graphics. There is no patch in SSA-330084.
- OpenPLC: if v3 is still a controller, it is EOL. Move to v4 or replace. Do not wait for a v3 XSS fix Autonomy Logic has said will not ship.
- Hitachi FACTS GWS and mySCADA 2.2 and Wärtsilä FOS-Onboard remain last week’s open tickets. CVE-2026-3869 on M580 still has no ICSA — SEVD-2026-251-04 is still the primary.
- Do not wait for ICS-specific malware. Dragos already told you ransomware did not need Stage 2.
8. What changed from last week
Last week (ending 18 September) was CISA converting the prior vendor stack into ICSAs, plus a grid FACTS 9.9 with no firmware string, a marine update-controller key, an unauthenticated mySCADA manager, GX Works3 security-version-2, and a no-fix CC-Link IE TSN protocol note. The exploited identity box was Cisco ISE.
This week CISA’s original work is lwIP (two advisories, commit-ID remediations, no product list) and OpenPLC v3 EOL. The rest of 22 September is CISA stamping ICSAs on Siemens ProductCERT notes from 8 and 16 September — IEM, Siveillance, SIMOVE/SIPLANT, Copy Fail on the Unified HMI / IoT2050 / TM MFP estate, Desigo CC with no fix, WTV Web Access DoS. 24 September added a revoked Mendix Runtime CVE and two consumer ICSAs. CVE-2026-3869 on M580 still has no ICSA. FACTS GWS still has no versioned patch. No new USG PLC campaign update. No new FBI/EPA water PSA. No new industrial-ransomware quarter. The exploited edge box moved from ISE (16 September) to Zyxel GS1900 (21 September), with F5 APM OAuth on the 22nd if that is how contractors get in. AA26-231A is five weeks old.
9. What OT defenders should watch next
Whether any OEM maps lwIP 2.0.1–2.2.1 onto a named meter, RTU, or gateway firmware, or whether ICSA-26-265-01 stays a stack advisory with a commit ID. Whether IEM on-prem instances that were internet-reachable show reset-credentials abuse in Keycloak logs. Whether Siemens publishes builds for IoT2050 Advanced and S7-1500 TM MFP Copy Fail, and for Desigo CC V6/V7. Whether CISA finally republishes CVE-2026-3869. Whether Hitachi publishes a versioned FCP/GWS patch. Whether Zyxel or F5 APM compromise is observed on industrial access and contractor-VPN estates, not only enterprise campuses. Q3 industrial ransomware counts. Any AA26-097A or water-PSA refresh.
10. RWP assessment
High confidence: this week is CISA’s 22 September nine-pack — two original lwIP notes whose “fix” is a git commit, one EOL OpenPLC XSS, and six Siemens republications — plus a revoked Mendix Runtime CVE and two consumer ICSAs on the 24th. High confidence: exposed controllers and engineering paths in AA26-097A / AA26-231A remain the incident class that has evidence. High confidence: an IEM Pro/Virtual instance on the internet is a 9.1 account-takeover until 1.15.20 / 2.2.2 / 2.9.1, and Desigo CC V6/V7 has no patch. Moderate confidence: a non-trivial MQTT-speaking OT estate is running an lwIP client in the 2.0.1–2.2.1 window and will not learn that from the asset register. Moderate confidence: GS1900 and F5 APM OAuth are the IT-to-OT doors that will produce this week’s actual tickets. Low confidence: a new OT malware family dropped in the last seven days. Labeling a manufacturer ransomware victim, a Zyxel access switch, an Eufy vacuum, or a Botslab dashcam as “OT compromise” without process evidence remains a briefing error.
This assessment covers 18–25 September 2026 and was published 25 September 2026.
Sources
- CISA — ICS Advisories index 25 September 2026
- CISA — ICSA-26-265-01 lwIP TCP/IP Stack MQTT Client Application
- CISA — ICSA-26-265-02 lwIP (Lightweight IP)
- CISA — ICSA-26-265-03 Siemens Siveillance Control
- CISA — ICSA-26-265-04 Siemens SIPLUS and SIMATIC Products
- CISA — ICSA-26-265-05 Siemens Desigo CC family
- CISA — ICSA-26-265-06 Siemens Industrial Edge Management
- CISA — ICSA-26-265-07 Siemens SIMOVE Fleetmanager and SIPLANT
- CISA — ICSA-26-265-08 Siemens WTV676 and WTV776
- CISA — ICSA-26-265-09 OpenPLC Runtime v3
- CISA — ICSA-26-209-02 Siemens Mendix Runtime (Update A, revoked)
- CISA — ICSA-26-267-01 Botslab G980H Dashcams
- CISA — ICSA-26-267-02 Eufy Omni C20, Omni X10 Pro
- Siemens ProductCERT — SSA-503852 Industrial Edge Management
- Siemens ProductCERT — SSA-254516 Siveillance OIS
- Siemens ProductCERT — SSA-328642 Copy Fail
- Siemens ProductCERT — SSA-330084 Desigo CC
- Siemens ProductCERT — SSA-517424 SIMOVE Fleetmanager and SIPLANT
- Siemens ProductCERT — SSA-823812 WTV676 and WTV776
- lwIP project — Savannah repository
- CISA — Adds one KEV CVE-2026-7273
- CISA — Adds four KEV including CVE-2026-94127
- CISA — Adds two KEV including CVE-2026-5430
- CISA — Known Exploited Vulnerabilities Catalog
- CISA — AA26-231A Defending against an active threat to Siemens S7
- CISA — AA26-097A Iranian-affiliated actors exploit PLCs
- RWP — Weekly OT 18 September 2026
- RWP — Daily Top Zyxel GS1900 CVE-2026-7273
- RWP — Daily Top F5 BIG-IP APM CVE-2026-94127
- RWP — Daily Top WSO2 CVE-2026-5430
- RWP — Weekly IT 21 September 2026