The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Critical Manufacturing
Breach intelligence, attack campaigns, and threat reports targeting the Critical Manufacturing sector.
Explore Other Sectors
Critical Manufacturing Threat Reports
Critical Security Flaws in Anviz Products: Immediate Action Required
In April 2026, multiple critical vulnerabilities were identified in Anviz's CX2 Lite and CX7 firmware, as well as the CrossChex Standard software. These vulnerabilities include missing authorization, command injection, and the use of hard-coded cryptographic keys, potentially allowing attackers to gain unauthorized access, execute arbitrary code, and compromise sensitive data. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory highlighting these issues and recommending immediate mitigations. ([windowsforum.com](https://windowsforum.com/threads/cisa-critical-advisory-anviz-cx2-lite-cx7-firmware-crosschex-risk-cvss-9-8.413734/?utm_source=openai)) The significance of this incident is underscored by the widespread deployment of Anviz products across various critical infrastructure sectors, including commercial facilities, healthcare, and transportation systems. Organizations utilizing these products are urged to assess their exposure and implement recommended security measures promptly to prevent potential exploitation.
5 months ago
Kill Chain
Critical Vulnerability in Contemporary Controls BASC-20T Puts Industrial Systems at Risk
In April 2026, a critical vulnerability (CVE-2025-13926) was identified in Contemporary Controls' BASC-20T unitary controller, widely used in industrial control systems. This flaw allows attackers to intercept and manipulate network traffic, enabling unauthorized actions such as reconfiguring devices, renaming or deleting files, performing file transfers, and executing remote procedure calls. The vulnerability affects BASControl20 version 3.1 and poses significant risks to sectors like commercial facilities, critical manufacturing, and energy. ([building-controls.com](https://www.building-controls.com/products/ccs-basc20t?utm_source=openai)) This incident underscores the escalating threats to industrial control systems, with a notable increase in vulnerabilities and attacks targeting operational technology environments. Organizations must prioritize securing legacy systems, implementing robust network segmentation, and ensuring timely updates to mitigate such risks. ([infosecurity-magazine.com](https://www.infosecurity-magazine.com/news/industrial-control-system-vulns/?utm_source=openai))
5 months ago
Kill Chain
Critical RCE Vulnerability in Hitachi Energy's Ellipse Platform
In early 2026, a critical vulnerability (CVE-2025-10492) was identified in Hitachi Energy's Ellipse enterprise asset management platform, specifically within the JasperReports component used for custom reporting. This Java deserialization flaw allows remote code execution without authentication or user interaction, affecting Ellipse versions 9.0.50 and earlier. The vulnerability poses significant risks to critical infrastructure sectors, including energy and manufacturing, by potentially enabling unauthorized access and control over essential systems. ([windowsforum.com](https://windowsforum.com/threads/hitachi-ellipse-jasperreports-flaw-cve-2025-10492-rce-risk-and-mitigation-steps.409447/?utm_source=openai)) The exploitation of this vulnerability underscores the persistent threat posed by deserialization flaws in widely used third-party libraries. Organizations are urged to assess their exposure, apply available patches, and implement recommended mitigations to safeguard against potential attacks targeting this and similar vulnerabilities.
5 months ago
Kill Chain
Siemens SICAM 8 Vulnerabilities: Protecting Critical Infrastructure
In March 2026, Siemens identified two critical vulnerabilities in its SICAM 8 industrial control products: CVE-2026-27663 and CVE-2026-27664. CVE-2026-27663 is a denial-of-service vulnerability in CPCI85 and RTUM85 devices, where high-volume requests can exhaust system resources, leading to operational disruptions. CVE-2026-27664 is an out-of-bounds write vulnerability in CPCI85 and SICORE systems, exploitable through specially crafted XML inputs, potentially causing service crashes. Siemens has released firmware updates (V26.10 and V26.10.0) to address these issues. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-27663/?utm_source=openai)) These vulnerabilities highlight the ongoing risks in industrial control systems, emphasizing the need for timely patch management and robust network security measures to protect critical infrastructure from potential cyber threats.
5 months ago
Kill Chain
Siemens SICAM SIAPP SDK Vulnerabilities: What You Need to Know
In March 2026, Siemens disclosed multiple vulnerabilities in its SICAM SIAPP SDK versions prior to 2.1.7. These vulnerabilities include out-of-bounds write, stack-based buffer overflow, improper handling of length parameter inconsistency, and external control of file name or path. Exploitation could lead to denial of service, data corruption, or arbitrary code execution. Siemens has released version 2.1.7 to address these issues and recommends users update promptly. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-903736.html?utm_source=openai)) This incident underscores the critical importance of timely software updates and robust input validation in industrial control systems to prevent potential exploitation and ensure operational integrity.
6 months ago
Kill Chain
Critical Vulnerabilities in Siemens RUGGEDCOM APE1808 Devices: What You Need to Know
In March 2026, Siemens disclosed multiple vulnerabilities in its RUGGEDCOM APE1808 devices, which integrate Fortinet's FortiOS. These vulnerabilities include HTTP request smuggling (CVE-2025-55018), improper verification of communication channels (CVE-2025-62439), use of externally-controlled format strings (CVE-2025-64157), and authentication bypass via alternate paths (CVE-2026-24858). Exploitation could allow unauthenticated attackers to execute arbitrary code, bypass authentication mechanisms, or cause denial-of-service conditions. Siemens has released updates to address these issues and recommends users update to the latest firmware versions. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-698820.html?utm_source=openai)) The disclosure underscores the critical need for organizations to promptly apply security patches, especially in industrial control systems. The vulnerabilities highlight the importance of securing supply chain components and ensuring that third-party integrations do not introduce security risks.
6 months ago
Kill Chain
Critical Vulnerabilities in Lantronix EDS3000PS and EDS5000 Devices Threaten Infrastructure Security
In March 2026, multiple critical vulnerabilities were identified in Lantronix EDS3000PS and EDS5000 devices, including OS command injection and authentication bypass issues. Exploitation of these vulnerabilities could allow attackers to execute code with root-level privileges, potentially compromising critical infrastructure sectors such as Communications, Information Technology, and Critical Manufacturing. ([cisa.gov](https://www.cisa.gov/news-events/bulletins/sb22-108?utm_source=openai)) This incident underscores the ongoing risks associated with unpatched vulnerabilities in network devices, highlighting the necessity for organizations to implement robust vulnerability management and regular system updates to mitigate potential threats.
6 months ago
Kill Chain
Critical Vulnerability in Portwell Engineering Toolkits Poses Risks to Industrial Control Systems
In March 2026, a critical vulnerability (CVE-2026-3437) was identified in Portwell Engineering Toolkits version 4.8.2, widely used in industrial control systems. This flaw allows local authenticated attackers to read and write arbitrary kernel memory via the toolkit's driver, potentially leading to privilege escalation or denial-of-service conditions. The vulnerability has a CVSS v3.1 base score of 8.8, indicating high severity. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-3437?utm_source=openai)) The vulnerability underscores the importance of securing engineering workstations in industrial environments, as exploitation could compromise critical manufacturing and energy sectors. Organizations are advised to implement defense-in-depth strategies, restrict access to engineering systems, and monitor for unauthorized activities to mitigate potential risks. ([therealistjuggernaut.com](https://therealistjuggernaut.com/2026/03/03/portwell-engineering-toolkits-vulnerability-raises-privilege-escalation-risks-in-industrial-development-environments/?utm_source=openai))
6 months ago
Kill Chain
GE Vernova Enervista UR Setup Vulnerabilities Disclosed in 2026
In February 2026, GE Vernova disclosed two vulnerabilities in their Enervista UR Setup software versions prior to 8.70. CVE-2026-1762 involves a directory traversal flaw that allows unauthorized file manipulation, while CVE-2026-1763 pertains to a DLL hijacking issue enabling code execution with elevated privileges. Both vulnerabilities require local access for exploitation and have been addressed in version 8.70. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1762?utm_source=openai)) The disclosure underscores the importance of timely software updates and robust local security measures, especially in critical infrastructure sectors where such vulnerabilities can have significant operational impacts.
7 months ago
Kill Chain
Critical RADIUS Vulnerability in Hitachi Energy XMC20 Devices (CVE-2024-3596)
In July 2024, a critical vulnerability (CVE-2024-3596) was identified in the RADIUS protocol, affecting Hitachi Energy's XMC20 devices. This flaw allows an on-path attacker to forge RADIUS server responses by exploiting weaknesses in the MD5-based Response Authenticator, potentially granting unauthorized network access. The vulnerability impacts XMC20 versions R18, R17A, and earlier, particularly when configured for remote RADIUS authentication. ([cisco.com](https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/222287-blast-radius-cve-2024-3596-protocol-sp.html?utm_source=openai)) The discovery underscores the risks associated with legacy cryptographic protocols like MD5. Organizations relying on RADIUS for authentication should promptly implement mitigations, such as enabling the Message-Authenticator attribute, to safeguard against potential exploits. ([cisco.com](https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/222287-blast-radius-cve-2024-3596-protocol-sp.html?utm_source=openai))
7 months ago
Kill Chain
Critical Vulnerability in Hitachi Energy's FOX61x Products (CVE-2024-3596)
In January 2026, Hitachi Energy disclosed a critical vulnerability (CVE-2024-3596) in its FOX61x products, specifically affecting versions R18 and R17A and earlier. This flaw, inherent in the RADIUS protocol under RFC 2865, allows local attackers to modify valid responses through a chosen-prefix collision attack on the MD5 Response Authenticator signature. Exploitation could compromise the confidentiality, integrity, and availability of the affected systems. The vulnerability is particularly relevant when FOX61x devices are configured to use remote RADIUS authentication. ([it4automation.com](https://it4automation.com/security-alerts/hitachi-energy-fox61x-foxcst-and-foxman-un-products/?utm_source=openai)) This incident underscores the persistent risks associated with legacy authentication protocols and the importance of implementing robust security measures. Organizations utilizing FOX61x devices are urged to apply the recommended mitigations promptly to prevent potential exploitation.
7 months ago
Kill Chain
Critical Vulnerability in Mitsubishi Electric's FREQSHIP-mini: CVE-2025-10314
In February 2026, Mitsubishi Electric disclosed a critical vulnerability (CVE-2025-10314) in its FREQSHIP-mini for Windows software, versions 8.0.0 to 8.0.2. The flaw arises from incorrect default permissions during installation, allowing local attackers to replace service executables or DLLs with malicious files. Exploiting this vulnerability enables arbitrary code execution with SYSTEM privileges, potentially leading to unauthorized access, data manipulation, or denial-of-service conditions. This vulnerability is particularly concerning for critical infrastructure sectors, including manufacturing and energy, where FREQSHIP-mini is commonly deployed. Organizations are urged to update to version 8.1.0 or later and implement recommended mitigation measures to prevent exploitation. ([jvn.jp](https://jvn.jp/en/jp/JVN64883963/?utm_source=openai))
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports