OT Intelligence · OT

CISA scored lwIP MQTT 9.8. The fix is a git commit. The exploited device this week is a Zyxel, not a PLC.

18–25 September 2026. ICSA-26-265-01 puts the lwIP MQTT client at CVSS 9.8 — versions 2.0.1 through 2.2.1, no product list, remediation is a Savannah commit. Same CISA day: Siemens IEM Keycloak reset (CVE-2026-18963, 9.1) becomes an ICSA, Siveillance OIS file-upload-to-root, SIMOVE/SIPLANT unauth file read, Copy Fail on Unified HMI / IoT2050 / S7-1500 TM MFP, Desigo CC V6/V7 with no fix. OpenPLC v3 is EOL. The KEV is Zyxel GS1900, then F5 APM.

RWP Ventures · 2026-09-25 · 18 min read · priority 8.4

Bottom line up front

CONFIRMED This week’s public OT calendar was CISA’s 22 September nine-advisory drop (ICSA-26-265-01 through -09), plus two consumer ICSAs and a revoked Mendix note on the 24th — not a named plant-floor malware event and not a new Stage 2 ICS kill-chain case.

The finding that belongs at the top of an OT queue is not last week’s Hitachi FACTS GWS. On 22 September CISA published ICSA-26-265-01 on the lwIP MQTT client application, versions 2.0.1 through 2.2.1. Headline CVSS v3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) on CVE-2026-87121 (CWE-787 out-of-bounds write). CISA’s summary sentence is the operator one: successful exploitation “could allow an attacker to gain full code execution on the device.” The vendor named on the page is lwIP. The equipment named on the page is lwIP. There is no OEM, no SKU, no firmware train. Remediation is a commit on Savannah: f89407ea711879c04d91c92b35d67be78bbaf0f1. Shahriyar Jalayeri (ByteRay) reported it. No known public exploitation.

Same CISA day, the Siemens stack that ProductCERT shipped on 8 September (WTV on 16 September) becomes a federal/contractor ICSA pile. The one you can actually ticket tonight, if you run it, is Industrial Edge Management:

The only CONFIRMED in-the-wild activity with an 18–25 September timestamp that OT operators should treat as a live ticket is not a PLC. On 21 September CISA added CVE-2026-7273 (Zyxel GS1900 CGI command execution) to KEV, federal due 24 September. GreyNoise’s public count, as covered in the [22 September Daily Top](/posts/2026-09-22-zyxel-gs1900-cve-2026-7273-kev/), is 996 switches in 48 countries. That is an access-switch / plant-edge path. It is not confirmation that a controller was reprogrammed. F5 APM CVE-2026-94127 (KEV 22 September, due 25 September) is the plant-VPN analogue if APM is the OAuth authorization server.

Do not upgrade this week’s ICSA pile into FrostyGoop. Last week’s live OT threat is unchanged: internet-reachable PLCs and engineering-client abuse named in AA26-097A and AA26-231A. CVE-2026-3869 on M580 / M580 Safety still has no CISA ICSA as of 25 September morning. Hitachi FACTS FCP/GWS still has no versioned patch in last week’s ICSA.

OT threat posture

Exposure, engineering-path abuse, and now a KEV’d access switch remain higher confidence than novel ICS malware. Ransomware still hurts plants by killing the Windows and hypervisors OT depends on — vCenter CVE-2026-59310 remains KEV with ransomware Known; that is a hypervisor story, not a ladder-logic story. No public primary source this week documented a new ladder-logic change or a new ICS-specific wiper.

1. Most significant development

lwIP MQTT client CVE-2026-87121, because CISA scored unauthenticated network code execution 9.8 on a TCP/IP stack that is compiled into other people’s firmware, named no products, and pointed operators at a git commit instead of a firmware pull.

Why this outranked the rest of the week: IEM CVE-2026-18963 is more actionable (unauthenticated, network, three versioned fixes, a WAF path you can cut tonight). It is also last week’s Siemens note with an ICSA stamped on it. Siveillance CVE-2026-50093 is file-upload-to-root on a physical-security server — adjacent, low privilege, patched. SIMOVE/SIPLANT CVE-2026-67367 is unauthenticated file read of keys. Copy Fail on Unified HMI / IoT2050 / S7-1500 TM MFP is the only CVE in the Siemens batch with a KEV history, and it is local. Zyxel GS1900 is the exploited box — it is not an ICS product. Score for the week: 8.4. IEM-as-lead would have been ~8.2 as a republication. Zyxel-only belongs in the IT briefing and in section 5 here. lwIP-only on actionability is a supplier question, not a flash; it still wins on novelty and on how many OT networks will silently carry MQTT clients built on 2.0.1–2.2.1.

2. Adversary / campaign activity

No new joint USG OT campaign advisory this week. Continuing, still the current hunt set:

CONFIRMED (non-ICS, this week): Zyxel GS1900 CVE-2026-7273, CISA KEV 21 September, federal due 24 September, forensic triage under BOD 26-04. GreyNoise campaign telemetry is in the Daily Top, not here. F5 BIG-IP APM CVE-2026-94127, KEV 22 September, due 25 September — data-plane heap overflow when APM is an OAuth authorization server; appliance mode is in; closing the management port does not close the virtual server. WSO2 CVE-2026-5430, KEV 24 September, due 27 September — JWT algorithm mismatch, not a file-upload RCE; identity plane.

UNKNOWN an 18–25 September named victim with a confirmed ladder-logic, protection-setting, FACTS-GWS, or IEM-account change.

3. Vulnerabilities and active exploitation

CONFIRMED (CISA ICS, 22 September — original CISA work)

AdvisoryProductCVEWhat it actually is
ICSA-26-265-01lwIP MQTT client app 2.0.1–2.2.1CVE-2026-87121Out-of-bounds write, unauthenticated network, full code execution. CVSS 9.8 / 9.3 (v4). Fix = Savannah commit f89407ea711879c04d91c92b35d67be78bbaf0f1. No tagged product firmware. No known public exploitation.
ICSA-26-265-02lwIP API 2.0.1–2.2.1CVE-2026-91018Double free. CVSS 8.8 AV:A. CISA: “not exploitable remotely.” Crash / DoS / memory corruption / possible code execution. Fix = commit f873b6295933e4149a2132adf3e9a2d2a676a5ec on cgit. Eric Evenchick (Tetrel) reported it. No known public exploitation.
ICSA-26-265-09Autonomy Logic OpenPLC Runtime v3CVE-2026-88020Reflected XSS on a query-string route. CVSS 6.1 UI:R. CISA’s impact sentence is process-level: session-cookie hijack, state-changing requests as the operator, “control the programmable logic controller and the physical processes it drives.” Vendor: v3 is end-of-life; move to v4. No v3 patch. Rajivarnan R. and Shirshak (Secnora). No known public exploitation.

CONFIRMED (CISA ICS, 22 September — Siemens ProductCERT republications)

CISA’s own disclaimer on each of these pages: verbatim conversion of the Siemens CSAF, “as-is.” Revision 1 is the Siemens date; revision 2 (22 September) is the CISA republication.

AdvisoryProductCVEWhat it actually is
ICSA-26-265-06IEM Cloud (all); Pro V1 ≥1.14.9 <1.15.20; Pro V2 ≥2.2.0 <2.2.2; Virtual ≥2.6.0 <2.9.1CVE-2026-18963Keycloak weak password-recovery. Unauthenticated remote account takeover. CVSS 9.1. SSA-503852 dated 8 September. Cloud already patched. On-prem versioned fixes plus internet-off / WAF / Forgot-password-off.
ICSA-26-265-03Siveillance Control / Control Pro V3.0 and V4.0 trains listedCVE-2026-50093OIS web module unrestricted file upload → root on the OIS host. CVSS 9.0 AV:A/PR:L/S:C. SSA-254516. Fixes: Control Pro 3.0.12.2173 / 4.0.9.2178; Control 3.0.22.2177 / 4.0.11.2177.
ICSA-26-265-07SIMOVE Fleetmanager 3.1–4.0 trains; SIPLANT 1.7, 2.2, 3.0 (all), 3.1 <3.1.4CVE-2026-67367Unauthenticated path traversal on the embedded HTTP file-serving endpoint. Read of credential stores, private keys, configuration. CVSS 8.6 S:C. SSA-517424. Fleetmanager has versioned fixes. SIPLANT 1.7 / 2.2 / 3.0: contact siplant-support.de@siemens.com.
ICSA-26-265-04SIPLUS / SIMATIC Unified HMI <21.0.2.1, CN 4100 <6.0, AX Runtime (all listed), IoT2050 Advanced all, S7-1500 TM MFP all, IED-OS allCVE-2026-31431Linux kernel “Copy Fail” (algif_aead in-place). Local privilege escalation. CVSS 7.8 AV:L/PR:L. SSA-328642. HMI fix is V21 Update 2 SR1; CN 4100 → 6.0. IoT2050 Advanced and S7-1500 TM MFP: CISA lists vers:all/*. Same kernel CVE last week’s ABB Edgenius ICSA already named. KEV catalog has carried Copy Fail since spring; that is kernel exploitation, not a Siemens-specific in-the-wild claim.
ICSA-26-265-05Desigo CC family V6 and V7, all versionsCVE-2026-34223Client code execution via scripts in user-defined graphics documents. CVSS 8.2 AV:L/PR:L/UI:R/S:C. SSA-330084. Michelin CERT to Siemens. Currently no fix. Mitigation: least-privilege on the Graphics application.
ICSA-26-265-08WTV676-HB6035 web <3.94; WTV776-HB6035 web <4.17CVE-2026-89207Unauthenticated input from backend services forces protection mode; remote Web Access dies. CVSS 6.5. Energy sector tag. SSA-823812 dated 16 September. Fixes V3.94 / V4.17.

CONFIRMED (CISA ICS, 24 September — not process control)

AdvisoryProductCVEWhat it actually is
ICSA-26-267-01Botslab G980H dashcam two firmware trainsThirteen CVEs, headline 8.8Session confusion, predictable IDs, replay, weak Wi-Fi password, UART root on one train, hardcoded crypto. Vendor has not responded to CISA. Transportation-sector tag. Adjacent-network consumer camera, not a PAC.
ICSA-26-267-02Eufy Omni C20 / X10 Pro <1.6.4CVE-2026-93289 / 93290 / 93291Pairing-time command injection; hardcoded credentials; missing cert validation (C20 9.4). Fix 1.6.4. IT-sector tag. Robot vacuum, not a controller. Jared (Somerset Recon). No known public exploitation.
ICSA-26-209-02 Update ASiemens Mendix RuntimeCVE-2026-7891 rejectedAdvisory revoked. Siemens re-investigation: expected platform configuration, protected attribute not exposed. Product status not_affected. Do not open a Mendix Runtime 9.1 ticket from this ICSA. Last week’s Mendix SAML CVE-2026-80465 (ICSA-26-258-06) is a different module and is not revoked.

CONFIRMED (active exploitation, not ICS): Zyxel GS1900 CVE-2026-7273, KEV 21 September. F5 APM CVE-2026-94127, KEV 22 September (one of four rows that day). WSO2 API Manager CVE-2026-5430, KEV 24 September. Linux kernel trio (kTLS / ebtables / af_alg) was 18 September, due 21 September — IT. Cisco ISE CVE-2026-76460 remains last week’s identity KEV (due 19 September). vCenter CVE-2026-59310 remains KEV with ransomware Known. MikroTik RouterOS CVE-2026-67277 / CVE-2026-86060 remains the 11 September edge-router hunt; no new industrial-ASN confirmation in this window.

Still missing from CISA ICS: Schneider CVE-2026-3869 on M580 / M580 Safety. Two-week watch item. As of 25 September morning the ICS index still does not list it. Primary source remains SEVD-2026-251-04. Hitachi FACTS ICSA-26-260-03 still names no patched FCP version.

4. ICS / SCADA impact

No CONFIRMED new loss-of-view or loss-of-control event dated 18–25 September in CISA ICS, FBI/EPA, Siemens ProductCERT, or the lwIP project page.

What would become process impact, if exploited on an exposed or poorly segmented box:

Prior water PLC tampering (July) and the UK small-generator outage (late July, disclosed August) remain the last well-sourced availability hits. They are not this week’s news.

5. IT-to-OT exposure

Five doors this week, in the order operators can actually hunt:

  1. Zyxel GS1900 on a plant, contractor, or camera VLAN. CVE-2026-7273 is unauthenticated CGI command execution, KEV, due 24 September. Vendor scored it AV:A. GreyNoise’s 996-switch collection is what you get when that CGI is on the internet, on a VPN that is not the LAN you think it is, or still on admin. Firmware 2.90(*.2)C0 shipped 16 June. Patching without asking who still has factory-default credentials is incomplete — see the Daily Top.
  2. F5 BIG-IP APM that is an OAuth authorization server for contractor or plant remote access. CVE-2026-94127 is unauthenticated data-plane RCE on the virtual server, KEV, due 25 September. Appliance mode is in. Closing the management GUI is not the fix. Inventory the role, not the APM checkbox. iRule on the affected VIP, then the engineering hotfix. [23 September Daily Top](/posts/2026-09-23-f5-big-ip-apm-cve-2026-94127-kev/).
  3. Cisco ISE / ISE-PIC from last week. Due date was 19 September. Hunt access.log. CCCS AL26-021 is still the operator checklist. A patched ISE that was reachable is a forensics problem, not a closed ticket.
  4. VMware vCenter that hosts historians, HMIs, or engineering VMs. CVE-2026-59310 remains KEV with ransomware Known. Encrypting the appliance is an OT outage without a single S7 packet.
  5. WSO2 API Manager / Control Plane / Universal Gateway if that is how plant APIs or partner integrations authenticate. CVE-2026-5430 is JWT alg confusion (CWE-347), KEV 24 September, due 27 September. CISA’s catalog title says path traversal; WSO2’s advisory says JWT. Hunt forged admin tokens, then patch. [25 September Daily Top](/posts/2026-09-25-wso2-cve-2026-5430-kev/).

Ignition, engineering workstations, and internet-facing 44818/102/502/2222 remain the standing hunt from AA26-097A / AA26-231A. That hunt does not reset because CISA republished IEM.

6. Sector impact

7. Defensive priorities

  1. Internet-facing PLC eradication — still number one. VPN or jump host, never the controller. AA26-097A / AA26-231A have not been withdrawn.
  2. IEM: if Pro or Virtual is reachable from an untrusted network, take it off today. Then patch to 1.15.20 / 2.2.2 / 2.9.1. Cloud tenants needed no action after 2 September. WAF the reset-credentials path only if you cannot isolate.
  3. lwIP: do not file a “patch lwIP” change request against a PLC that does not have a version string. Ask every MQTT-speaking OEM whether the image includes 2.0.1–2.2.1. Until they answer, MQTT from untrusted networks is the control.
  4. Zyxel GS1900: firmware, then hunt admin. Due date was yesterday for FCEB. Plant and camera VLANs are in scope even when the switch is “just access.”
  5. F5 APM: inventory OAuth authorization server virtual servers. iRule, hotfix, hunt. Management-port closure is the wrong ticket.
  6. Siveillance OIS to the listed builds. SIMOVE to the listed builds. SIPLANT: open the support case; three lines have no version in the ICSA.
  7. Copy Fail: Unified HMI to V21 Update 2 SR1. CN 4100 to 6.0. IoT2050 Advanced and S7-1500 TM MFP — compensating controls (local access, no untrusted shell) until Siemens publishes a build. This is local; it does not outrank an internet PLC.
  8. Desigo CC V6/V7: least privilege on Graphics. There is no patch in SSA-330084.
  9. OpenPLC: if v3 is still a controller, it is EOL. Move to v4 or replace. Do not wait for a v3 XSS fix Autonomy Logic has said will not ship.
  10. Hitachi FACTS GWS and mySCADA 2.2 and Wärtsilä FOS-Onboard remain last week’s open tickets. CVE-2026-3869 on M580 still has no ICSA — SEVD-2026-251-04 is still the primary.
  11. Do not wait for ICS-specific malware. Dragos already told you ransomware did not need Stage 2.

8. What changed from last week

Last week (ending 18 September) was CISA converting the prior vendor stack into ICSAs, plus a grid FACTS 9.9 with no firmware string, a marine update-controller key, an unauthenticated mySCADA manager, GX Works3 security-version-2, and a no-fix CC-Link IE TSN protocol note. The exploited identity box was Cisco ISE.

This week CISA’s original work is lwIP (two advisories, commit-ID remediations, no product list) and OpenPLC v3 EOL. The rest of 22 September is CISA stamping ICSAs on Siemens ProductCERT notes from 8 and 16 September — IEM, Siveillance, SIMOVE/SIPLANT, Copy Fail on the Unified HMI / IoT2050 / TM MFP estate, Desigo CC with no fix, WTV Web Access DoS. 24 September added a revoked Mendix Runtime CVE and two consumer ICSAs. CVE-2026-3869 on M580 still has no ICSA. FACTS GWS still has no versioned patch. No new USG PLC campaign update. No new FBI/EPA water PSA. No new industrial-ransomware quarter. The exploited edge box moved from ISE (16 September) to Zyxel GS1900 (21 September), with F5 APM OAuth on the 22nd if that is how contractors get in. AA26-231A is five weeks old.

9. What OT defenders should watch next

Whether any OEM maps lwIP 2.0.1–2.2.1 onto a named meter, RTU, or gateway firmware, or whether ICSA-26-265-01 stays a stack advisory with a commit ID. Whether IEM on-prem instances that were internet-reachable show reset-credentials abuse in Keycloak logs. Whether Siemens publishes builds for IoT2050 Advanced and S7-1500 TM MFP Copy Fail, and for Desigo CC V6/V7. Whether CISA finally republishes CVE-2026-3869. Whether Hitachi publishes a versioned FCP/GWS patch. Whether Zyxel or F5 APM compromise is observed on industrial access and contractor-VPN estates, not only enterprise campuses. Q3 industrial ransomware counts. Any AA26-097A or water-PSA refresh.

10. RWP assessment

High confidence: this week is CISA’s 22 September nine-pack — two original lwIP notes whose “fix” is a git commit, one EOL OpenPLC XSS, and six Siemens republications — plus a revoked Mendix Runtime CVE and two consumer ICSAs on the 24th. High confidence: exposed controllers and engineering paths in AA26-097A / AA26-231A remain the incident class that has evidence. High confidence: an IEM Pro/Virtual instance on the internet is a 9.1 account-takeover until 1.15.20 / 2.2.2 / 2.9.1, and Desigo CC V6/V7 has no patch. Moderate confidence: a non-trivial MQTT-speaking OT estate is running an lwIP client in the 2.0.1–2.2.1 window and will not learn that from the asset register. Moderate confidence: GS1900 and F5 APM OAuth are the IT-to-OT doors that will produce this week’s actual tickets. Low confidence: a new OT malware family dropped in the last seven days. Labeling a manufacturer ransomware victim, a Zyxel access switch, an Eufy vacuum, or a Botslab dashcam as “OT compromise” without process evidence remains a briefing error.

This assessment covers 18–25 September 2026 and was published 25 September 2026.

Sources

  1. CISA — ICS Advisories index 25 September 2026
  2. CISA — ICSA-26-265-01 lwIP TCP/IP Stack MQTT Client Application
  3. CISA — ICSA-26-265-02 lwIP (Lightweight IP)
  4. CISA — ICSA-26-265-03 Siemens Siveillance Control
  5. CISA — ICSA-26-265-04 Siemens SIPLUS and SIMATIC Products
  6. CISA — ICSA-26-265-05 Siemens Desigo CC family
  7. CISA — ICSA-26-265-06 Siemens Industrial Edge Management
  8. CISA — ICSA-26-265-07 Siemens SIMOVE Fleetmanager and SIPLANT
  9. CISA — ICSA-26-265-08 Siemens WTV676 and WTV776
  10. CISA — ICSA-26-265-09 OpenPLC Runtime v3
  11. CISA — ICSA-26-209-02 Siemens Mendix Runtime (Update A, revoked)
  12. CISA — ICSA-26-267-01 Botslab G980H Dashcams
  13. CISA — ICSA-26-267-02 Eufy Omni C20, Omni X10 Pro
  14. Siemens ProductCERT — SSA-503852 Industrial Edge Management
  15. Siemens ProductCERT — SSA-254516 Siveillance OIS
  16. Siemens ProductCERT — SSA-328642 Copy Fail
  17. Siemens ProductCERT — SSA-330084 Desigo CC
  18. Siemens ProductCERT — SSA-517424 SIMOVE Fleetmanager and SIPLANT
  19. Siemens ProductCERT — SSA-823812 WTV676 and WTV776
  20. lwIP project — Savannah repository
  21. CISA — Adds one KEV CVE-2026-7273
  22. CISA — Adds four KEV including CVE-2026-94127
  23. CISA — Adds two KEV including CVE-2026-5430
  24. CISA — Known Exploited Vulnerabilities Catalog
  25. CISA — AA26-231A Defending against an active threat to Siemens S7
  26. CISA — AA26-097A Iranian-affiliated actors exploit PLCs
  27. RWP — Weekly OT 18 September 2026
  28. RWP — Daily Top Zyxel GS1900 CVE-2026-7273
  29. RWP — Daily Top F5 BIG-IP APM CVE-2026-94127
  30. RWP — Daily Top WSO2 CVE-2026-5430
  31. RWP — Weekly IT 21 September 2026