Skip to main content
System Status
Critical 18
|
High 70
|
Medium 1
|
Feed Online
UPDATED: 2026-06-11 00:00 UTC

AVEVA Enterprise SCADA Deserialization Flaw (CVE-2025-7639): What ICSA-26-225-01 Means for Citect-Derived Deployments

CISA advisory ICSA-26-225-01 details a high-severity insecure deserialization vulnerability in AVEVA Enterprise SCADA — the platform formerly known as Citect SCADA — that lets a low-privileged operator escalate to code execution under the DNA Apps security group. Here's the technical breakdown and remediation path.

Siemens SIMATIC IoT2050 Advanced: Maximum-Severity Unauthenticated RCE in Industrial IoT Gateways

Siemens published a maximum-severity advisory in August 2026 Patch Tuesday covering a missing authentication vulnerability in SIMATIC IoT2050 Advanced devices. An unauthenticated remote attacker can execute arbitrary code with elevated privileges on the underlying server — a critical risk for IT/OT bridging deployments where these gateways connect operational technology networks to enterprise IT and cloud systems.

CVE-2026-59310 in OT Environments: Protecting Virtualised SCADA and Historian Infrastructure

VMware vCenter CVE-2026-59310 (CVSS 9.8, actively exploited) presents an acute risk in OT environments where virtualisation hosts historian servers, HMIs, engineering workstations, and SCADA applications. This advisory covers which OT components are most exposed, how vCenter compromise translates to OT network impact, and the OT-specific mitigations that reduce risk while patching proceeds.

CISA ICS Advisories: August 2026 Roundup — Siemens, Honeywell, GE Vernova

CISA published multiple ICS security advisories in the first week of August 2026, covering critical vulnerabilities in Siemens SINEC NMS, Honeywell Experion PKS, and GE Vernova grid management systems. This roundup covers the disclosed vulnerabilities, affected product versions, CVSS scores, and recommended mitigations for OT security teams.

OT Endpoint Security: Deploying EDR and XDR in Industrial Environments Without Disrupting Control Systems

Deploying endpoint detection and response tools on OT assets — PLCs, HMIs, engineering workstations, historians — requires a different approach than IT EDR rollouts. Aggressive scanning, real-time interception, and performance overhead that are acceptable on IT endpoints can destabilise industrial control systems. This guide covers agent versus agentless approaches, deployment sequencing, and what OT-specific EDR products actually monitor.

AVEVA System Platform SCADA Security: Attack Surface, Vulnerabilities, and Hardening Guide

AVEVA System Platform (formerly Wonderware) is one of the most widely deployed SCADA and HMI platforms in industrial environments. This guide covers its attack surface, known vulnerability classes, and hardening practices for security teams and OT engineers.

PROFIBUS Protocol Security: Attack Surface Analysis and Hardening

PROFIBUS is one of the most widely deployed industrial fieldbus protocols, with an installed base spanning decades of manufacturing, chemical, and power generation facilities. Designed before network security was an operational priority, PROFIBUS has no authentication, no encryption, and a physical access model that assumes trusted environments. This guide covers the attack surface and hardening path.

Yokogawa CENTUM VP DCS: Security Vulnerabilities, Attack Surface, and Hardening

Yokogawa's CENTUM VP is one of the most widely deployed distributed control systems in oil and gas, chemical, and power generation. Its VNET/IP communication protocol, Exaopc OPC server, and Windows-based HIS workstations each carry documented security gaps. This guide covers the attack surface and hardening path.

U-Boot Vulnerabilities in Industrial Control Systems: Embedded Firmware Security in 2026

U-Boot is the dominant open-source bootloader for embedded Linux devices — including industrial routers, RTUs, PLCs, and SCADA components. Vulnerabilities in U-Boot's FIT image parsing and boot verification logic have direct implications for OT device firmware integrity and secure boot trust chains.

IEC 61850 Substation Automation Security: Attack Surface and Hardening for Power Grid Operators

IEC 61850 is the dominant protocol for digital substation automation — and it was designed for operational reliability, not security. GOOSE messages carry no authentication. MMS sessions use optional TLS that most deployments skip. This analysis covers the threat model and practical hardening for utilities and grid operators.

ICSA-26-181-02: FUXA SCADA CVE-2026-13207 -- Path Traversal to Unauthenticated RCE

ICS-CERT advisory ICSA-26-181-02 covers a dot-segment path normalization bypass in FUXA open-source SCADA software that allows unauthenticated remote code execution. CVSS v4 score 8.6. Deployments in water, energy, and manufacturing are exposed.

Emerson DeltaV DCS: Authentication Gaps, CISA Advisories, and Zero Trust Remediation

Emerson DeltaV is one of the most widely deployed distributed control systems in oil and gas, pharmaceutical, and chemical manufacturing. Legacy DeltaV communication protocols lack authentication, and multiple CISA advisories document workstation-level vulnerabilities. Here's the current security posture and what operators should do.

Oil and Gas Pipeline Cybersecurity: TSA Directives, OT Threat Landscape, and Compliance Requirements in 2026

The TSA's pipeline cybersecurity directives have fundamentally changed the compliance environment for US pipeline operators. This analysis covers the directive requirements, the OT threat actors specifically targeting oil and gas infrastructure, and the technical controls that actually move the needle.

OPC UA Security: Attack Surface Analysis and Hardening Recommendations for Industrial Environments

OPC Unified Architecture has become the dominant interoperability standard for industrial communication — and a consistent target in ICS-focused threat campaigns. This analysis covers the OPC UA threat model, documented vulnerability classes from recent CVEs, known exploitation by nation-state actors, and the hardening steps that reduce exposure without breaking operational continuity.