The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Industrial Automation
Breach intelligence, attack campaigns, and threat reports targeting the Industrial Automation sector.
Explore Other Sectors
Industrial Automation Threat Reports
Critical Path Traversal Flaw Exposes Siemens Industrial Systems to Remote File Access
Siemens SIMOVE Fleetmanager and SIPLANT industrial management systems contain a critical path traversal vulnerability (CVE-2026-67367) with a CVSS score of 8.6. The flaw allows unauthenticated remote attackers to read arbitrary files from the underlying operating system through improper validation of directory traversal sequences in the embedded HTTP server's file-serving endpoint. Affected systems span multiple product versions deployed worldwide in critical manufacturing sectors, potentially exposing sensitive data including credential stores, private keys, and configuration secrets. This vulnerability highlights the persistent security challenges in industrial control systems and operational technology environments. As organizations increasingly digitize their manufacturing operations and connect OT systems to corporate networks, path traversal vulnerabilities in critical infrastructure components represent a growing attack surface that demands immediate attention and systematic security controls.
3 days ago
Kill Chain
Critical Copy Fail Vulnerability Exposes Siemens Industrial Control Systems
In September 2026, CISA disclosed CVE-2026-31431, known as the "Copy Fail" vulnerability, affecting multiple Siemens SIPLUS and SIMATIC industrial control products. The vulnerability stems from incorrect resource transfer between spheres in the Linux kernel's crypto subsystem, specifically in the algif_aead component. With a CVSS score of 7.8, the flaw allows local attackers with low privileges to potentially achieve high confidentiality, integrity, and availability impacts on affected systems. Siemens has released patches for most affected products, updating them to version 21.2.1 or later, while recommending specific countermeasures for products where fixes are not yet available. This incident highlights the growing sophistication of attacks targeting industrial control systems and the critical importance of maintaining updated security patches in operational technology environments. As industrial networks become increasingly connected and digitized, vulnerabilities like Copy Fail demonstrate the urgent need for comprehensive security frameworks that can protect critical infrastructure from both known and emerging threats.
3 days ago
Kill Chain
Siemens Industrial Control Vulnerability Exposes Critical Infrastructure to Denial of Service Attacks
Siemens has disclosed a critical vulnerability (CVE-2026-89207) affecting WTV676 and WTV776 industrial control devices used in energy infrastructure worldwide. The vulnerability allows unauthenticated remote attackers to exploit improper input validation from backend services, forcing devices into protection mode and disabling remote connectivity functions. This denial of service attack vector poses significant operational risks to critical infrastructure, particularly in energy sectors where these devices are deployed globally. The CVSS 6.5 rated vulnerability affects WTV676-HB6035 Web Interface versions below 3.94 and WTV776-HB6035 Web Interface versions below 4.17. This incident highlights the ongoing challenge of securing industrial control systems as cyber threats increasingly target critical infrastructure. With growing concerns about nation-state actors and ransomware groups focusing on operational technology environments, vulnerabilities in widely-deployed industrial devices represent escalating risks to essential services and national security.
3 days ago
Kill Chain
Critical Authentication Bypass in Siemens Industrial Edge Management Exposes Global Manufacturing Infrastructure
In September 2026, CISA published an advisory regarding a critical authentication bypass vulnerability (CVE-2026-18963) affecting Siemens Industrial Edge Management systems worldwide. The vulnerability, with a CVSS score of 9.1, allows unauthenticated remote attackers to perform complete account takeovers by exploiting the password reset mechanism without requiring email verification. The flaw affects multiple versions of Industrial Edge Management Cloud, Pro V1, Pro V2, and Virtual editions used in critical manufacturing environments globally. Siemens has released patches and implemented firewall rules to mitigate the threat. This incident highlights the growing threat landscape targeting industrial control systems and critical infrastructure, particularly as organizations increasingly adopt cloud-connected industrial IoT platforms. The vulnerability's high severity and potential for complete account compromise underscores the urgent need for robust authentication mechanisms and zero-trust security models in operational technology environments.
3 days ago
Kill Chain
Critical XSS Vulnerability in OpenPLC Runtime v3 Threatens Industrial Control Systems
A critical cross-site scripting (XSS) vulnerability (CVE-2026-88020) was discovered in OpenPLC Runtime v3, an open-source programmable logic controller platform used across critical infrastructure sectors including manufacturing, energy, transportation, and water systems. The vulnerability allows attackers to hijack session cookies and issue state-changing requests as operators, potentially enabling unauthorized control of industrial processes and physical systems. With a CVSS score of 6.1, the flaw stems from improper input neutralization in the web interface's query string parameter handling, affecting the end-of-life OpenPLC v3 platform deployed worldwide. This vulnerability highlights the growing cybersecurity risks facing industrial control systems as they become increasingly connected to corporate networks and the internet. The convergence of IT and OT security challenges continues to expand the attack surface for critical infrastructure, making legacy industrial systems attractive targets for nation-state actors and cybercriminals seeking to disrupt essential services.
3 days ago
Kill Chain
Critical Vulnerabilities Disclosed in Hitachi Energy Power Grid Control Systems
CISA published advisory ICSA-26-260-03 disclosing critical vulnerabilities in Hitachi Energy's FACTS Control Platform (FCP) affecting multiple versions from 3.4.0 to 4.1.1 when deployed with the GWS component. The vulnerabilities include SQL injection (CVE-2024-4872), path traversal (CVE-2024-3980), session hijacking (CVE-2024-3982), missing authentication (CVE-2024-7940), and open redirect (CVE-2024-7941) with CVSS scores ranging from 4.3 to 9.9. These flaws could allow authenticated attackers to execute code injection, access critical system files, hijack sessions, and redirect users to malicious sites, potentially compromising the confidentiality, integrity, and availability of critical power grid infrastructure. This disclosure highlights the growing cybersecurity challenges facing operational technology in the energy sector, particularly as industrial control systems become increasingly connected and targeted by sophisticated threat actors seeking to disrupt critical infrastructure operations.
1 week ago
Kill Chain
Critical Authentication Bypass in Mitsubishi Electric GX Works3 Exposes Industrial Control Systems
In September 2026, CISA disclosed CVE-2026-15688, a critical authentication bypass vulnerability in Mitsubishi Electric's GX Works3 and Motion Control Settings software used in industrial control systems worldwide. The vulnerability, scored 8.8 (CVSS v3.1) and 9.2 (CVSS v4.0), allows local attackers to bypass block password authentication by modifying executable modules in memory, enabling unauthorized access to view, tamper with, destroy, or delete control programs in critical manufacturing environments. This incident highlights the growing threat landscape targeting industrial control systems as cyber adversaries increasingly focus on critical infrastructure. With ICS environments becoming more connected and the rise of sophisticated state-sponsored attacks on manufacturing facilities, authentication vulnerabilities in widely-deployed engineering software represent significant risks to operational technology security and industrial resilience.
1 week ago
Kill Chain
Critical Siemens Reyrolle 7SR5 Vulnerabilities Threaten Power Grid Security
Siemens Reyrolle 7SR5 protection relay systems before version 2.70 are affected by 14 critical vulnerabilities, including authentication bypass, session hijacking, and buffer overflow conditions. These vulnerabilities in the Cesanta Mongoose Web Server component allow unauthenticated remote attackers to gain administrative access, execute arbitrary code, and cause denial-of-service conditions on critical power grid protection equipment deployed worldwide. The highest severity vulnerability (CVE-2026-62645) achieves a CVSS score of 9.8, enabling complete system compromise through predictable session identifiers and missing authentication controls. These vulnerabilities highlight the growing cybersecurity risks in operational technology (OT) environments, particularly as critical infrastructure becomes increasingly connected and exposed to network-based attacks targeting industrial control systems.
1 week ago
Kill Chain
Critical XSS Vulnerability in Siemens Teamcenter Exposes Manufacturing Systems to Web-Based Attacks
A reflected cross-site scripting (XSS) vulnerability (CVE-2026-58113) was discovered in Siemens Teamcenter's authentication redirect flow, affecting multiple versions across V2412, V2506, V2512, and V2606 product lines. The vulnerability allows unauthenticated remote attackers to inject malicious JavaScript into authenticated user sessions through crafted URLs, potentially enabling data theft and unauthorized actions within victims' Teamcenter sessions. Siemens has released patches for all affected versions and recommends immediate updates to mitigate the CVSS 6.1 rated vulnerability. This incident highlights the persistent threat of web application vulnerabilities in critical manufacturing systems, particularly as organizations increasingly rely on web-based PLM platforms for sensitive industrial operations and intellectual property management.
1 week ago
Kill Chain
Critical Vulnerability in Schneider Electric SCADAPack x70 Systems Exposes Industrial Infrastructure
Schneider Electric disclosed a critical vulnerability (CVE-2026-81861) affecting all versions of its SCADAPack x70 Remote Terminal Units used in critical infrastructure worldwide. The insufficiently protected credentials vulnerability could allow unauthorized access to RTU configuration through the legacy Secure Lock functionality, potentially compromising confidentiality of industrial control systems. The vulnerability affects SCADAPack 47x, 47xi, 47xd, 470R, 57x, 3xx, and 32 products deployed globally in critical manufacturing and energy sectors. Industrial control system vulnerabilities continue to represent a significant threat vector as critical infrastructure increasingly becomes a target for nation-state actors and ransomware groups seeking to disrupt essential services and cause maximum societal impact.
1 week ago
Kill Chain
Microsoft Warns of Critical Security Gaps in Edge AI Deployments
Microsoft published a comprehensive security advisory in September 2024 addressing critical vulnerabilities in Edge AI deployments where machine learning models execute on customer-owned infrastructure. The advisory highlights fundamental security model changes when AI systems move from centralized cloud services to edge environments, exposing organizations to prompt injection attacks, model tampering, and malicious firmware updates. Customer-owned Edge AI deployments face increased attack surfaces as models, credentials, and sensitive data operate in potentially hostile environments outside cloud providers' direct security controls. This advisory emerges as organizations rapidly adopt Edge AI for cost optimization, data sovereignty, and reduced latency, creating new attack vectors that traditional software security controls cannot adequately address.
2 weeks ago
Kill Chain
Critical Buffer Overflow Vulnerability CVE-2026-78012 Threatens Industrial Control Systems
In September 2026, CISA disclosed CVE-2026-78012, a critical stack-based buffer overflow vulnerability in Pyramid Solutions NetStaX EtherNet/IP Stack affecting versions prior to 5.6.1. The vulnerability allows attackers to send large Class 3 explicit-message requests that exceed application-side receive buffers without generating error warnings, potentially leading to memory corruption, device crashes, or remote code execution. With a CVSS score of 9.8, this flaw impacts multiple industrial control systems across critical infrastructure sectors including manufacturing, energy, water treatment, and chemical facilities worldwide. The vulnerability represents a significant threat to operational technology environments where these industrial communication stacks are widely deployed. This incident highlights the growing cybersecurity risks facing industrial control systems as OT networks become increasingly connected and targeted by sophisticated threat actors, making secure industrial communication protocols and robust buffer management critical for protecting critical infrastructure.
3 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports