✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Industrial Automation
Breach intelligence, attack campaigns, and threat reports targeting the Industrial Automation sector.
Explore Other Sectors
Industrial Automation Threat Reports
Critical DoS Vulnerability in Rockwell Automation Modules: CVE-2026-9653
In July 2026, a denial-of-service (DoS) vulnerability, identified as CVE-2026-9653, was discovered in Rockwell Automation's 1756-EN2, 1756-EN3, and 1756-ENBT communication modules. This flaw arises from improper validation of CIP Implicit Connection packets, allowing network-based attackers to send crafted packets that can continuously disrupt device connections. Although the devices automatically recover after each disruption, repeated exploitation can lead to significant operational downtime. The affected firmware versions include 1756-EN2 and 1756-EN3 up to V12.001, and 1756-ENBT V6.006. ([rockwellautomation.com](https://www.rockwellautomation.com/de-ch/trust-center/security-advisories.htmlhttps%3A.html?utm_source=openai)) The emergence of CVE-2026-9653 underscores the critical need for robust validation mechanisms in industrial control systems. As cyber threats targeting operational technology (OT) environments become more sophisticated, organizations must prioritize timely firmware updates and implement comprehensive network security measures to mitigate potential disruptions.
4 days ago
Kill Chain
Critical Vulnerabilities in AutomationDirect Productivity Suite Threaten Industrial Control Systems
In July 2026, multiple vulnerabilities were identified in AutomationDirect's Productivity Suite software, affecting versions up to v4.6.2.2. These vulnerabilities include out-of-bounds write and read errors, as well as divide-by-zero flaws, which could allow attackers with local or physical access to cause memory corruption, unintended information disclosure, application instability, or denial-of-service conditions. The affected products are widely used in the critical manufacturing sector globally. The discovery of these vulnerabilities underscores the ongoing challenges in securing industrial control systems (ICS). As ICS environments become increasingly interconnected, the potential impact of such vulnerabilities grows, highlighting the need for continuous monitoring and timely patching to maintain operational integrity and security.
4 days ago
Kill Chain
Critical Vulnerabilities Discovered in Rockwell Automation's Arena® Simulation Software
In July 2026, Rockwell Automation disclosed multiple memory corruption vulnerabilities in its Arena® Simulation software, specifically affecting components such as model.exe, expmt.exe, linker.exe, and siman.exe. These vulnerabilities, identified as CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, and CVE-2026-8314, arise from improper validation of user-supplied data, leading to out-of-bounds write conditions. Exploitation could allow attackers to execute arbitrary code by convincing users to open malicious files. The affected versions include Arena V17.00.00 and prior, with fixes available in version V17.00.01. ([rockwellautomation.com](https://www.rockwellautomation.com/es-es/trust-center/security-advisories/advisory.SD1784.html?utm_source=openai)) This incident underscores the critical importance of timely software updates and user awareness in mitigating risks associated with memory corruption vulnerabilities. As attackers increasingly exploit such flaws to gain unauthorized access, organizations must prioritize patch management and educate users on the dangers of opening untrusted files to maintain robust cybersecurity defenses.
4 days ago
Kill Chain
Daxin and Stupig Malware Resurface in Taiwan Manufacturing Firm
In May 2026, Symantec's Threat Hunter Team identified the re-emergence of Backdoor.Daxin, a sophisticated kernel-mode rootkit previously linked to China-based threat actors, on a compromised host within a Taiwan-based subsidiary of a multinational high-tech manufacturer. Alongside Daxin, researchers discovered a novel backdoor named Stupig, which exploits a trojanized keyboard-layout DLL to execute commands with SYSTEM privileges directly from the Windows logon screen, bypassing standard authentication mechanisms. Both malware samples carry compile timestamps from early 2013, suggesting a prolonged undetected presence of up to 13 years within the victim's network. This incident underscores the persistent and evolving nature of cyber threats targeting critical infrastructure and high-tech industries. The discovery of Stupig's unique pre-authentication execution method highlights the need for continuous vigilance and advanced detection capabilities to identify and mitigate such stealthy intrusions.
4 days ago
Kill Chain
Critical XSS Vulnerability in Rockwell Automation's FactoryTalk DataMosaix (CVE-2026-9292)
In July 2026, Rockwell Automation disclosed a stored cross-site scripting (XSS) vulnerability (CVE-2026-9292) in its FactoryTalk DataMosaix Private Cloud software, versions 8.02 and earlier. This flaw allows authenticated users with high privileges to inject malicious scripts into the Workflows configuration, which are then stored on the server. When other users access the compromised page, these scripts can execute, potentially leading to account takeovers, credential theft, or redirection to malicious websites. Rockwell Automation has released version 8.03 to address this issue and recommends users upgrade promptly. ([rockwellautomation.com](https://www.rockwellautomation.com/es-es/trust-center/security-advisories/advisory.SD1787.html?utm_source=openai)) This incident underscores the persistent threat of XSS vulnerabilities in industrial control systems, emphasizing the need for rigorous input validation and prompt patch management to safeguard critical infrastructure.
4 days ago
Kill Chain
Critical Vulnerabilities in Siemens SICAM 8 Products: Immediate Updates Recommended
In July 2026, Siemens disclosed multiple vulnerabilities in its SICAM 8 products, including CPCI85 Central Processing/Communication and SICORE Base system, affecting versions prior to V26.20 and V26.20.0 respectively. These vulnerabilities encompass issues such as accessible debugging interfaces leading to denial-of-service conditions (CVE-2026-54798), flaws in firmware signature validation allowing malicious firmware installation (CVE-2026-54799), default configurations disabling OPC UA security mechanisms (CVE-2026-54800), and insufficient validation of authentication credentials enabling privilege escalation (CVE-2026-54801). Siemens has released updates to address these vulnerabilities and recommends users upgrade to the latest versions. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-229470.html?utm_source=openai)) The disclosure of these vulnerabilities underscores the critical importance of securing industrial control systems, especially in sectors like energy and manufacturing. The potential for unauthorized access and system compromise highlights the need for organizations to promptly apply security updates and review their system configurations to mitigate risks associated with these vulnerabilities.
4 days ago
Kill Chain
Critical Vulnerabilities in Rockwell Automation's ICS Controllers: What You Need to Know
In 2025, Rockwell Automation identified multiple vulnerabilities in its CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controllers. These flaws, including CVE-2025-12011, CVE-2025-12012, and CVE-2025-11698, could allow remote attackers to cause major non-recoverable faults (MNRF) in affected devices, leading to denial-of-service conditions. The vulnerabilities were found in firmware versions up to V35.015 for certain models, with Rockwell Automation releasing patches in versions V35.016, V36.011, and later to address these issues. ([rockwellautomation.com](https://www.rockwellautomation.com/pt-pt/trust-center/security-advisories.html?utm_source=openai)) The discovery of these vulnerabilities underscores the critical importance of securing industrial control systems (ICS) against remote attacks. As ICS environments become increasingly interconnected, the potential impact of such vulnerabilities grows, highlighting the need for continuous monitoring, timely patching, and adherence to cybersecurity best practices to protect critical infrastructure.
4 days ago
Kill Chain
Critical Denial-of-Service Vulnerability in Rockwell Automation FLEX 5000 Adapters (CVE-2026-12659)
In July 2026, Rockwell Automation disclosed a denial-of-service vulnerability (CVE-2026-12659) in their FLEX 5000® EtherNet/IP Adapters, specifically affecting version 6.011. The vulnerability arises from improper handling of exceptional conditions when processing crafted CIP packets, leading to system instability. Exploitation of this flaw requires a power cycle to restore functionality to the affected module and connected I/O devices. ([rockwellautomation.com](https://www.rockwellautomation.com/en-be/trust-center/security-advisories.html?utm_source=openai)) This incident underscores the critical importance of robust exception handling in industrial control systems. As cyber threats targeting operational technology (OT) environments become more sophisticated, organizations must prioritize timely patch management and implement comprehensive security measures to safeguard critical infrastructure.
4 days ago
Kill Chain
ABB Advant Master Online Builder Vulnerability: CVE-2025-13162
In June 2026, ABB identified a vulnerability (CVE-2025-13162) in its Advant Master Online Builder software, affecting Control Builder A versions up to 1.4/4 and 800xA for Advant Master versions up to 6.2.0-1. The flaw, an uncontrolled search path element, could allow unauthorized code execution if exploited by an attacker with local access. ABB promptly released updates to remediate the issue and advised customers to upgrade to the latest versions to maintain system integrity. This incident underscores the critical importance of timely software updates and vigilant access control in industrial control systems. As cyber threats targeting operational technology environments continue to evolve, organizations must prioritize proactive vulnerability management to safeguard critical infrastructure.
6 days ago
Kill Chain
Critical Vulnerability in ABB Ability Edgenius: Immediate Action Required
In June 2026, ABB disclosed a critical vulnerability (CVE-2026-31431) in its Ability Edgenius platform, stemming from a flaw in the Linux kernel's cryptographic subsystem. This vulnerability allows locally authenticated users or compromised container workloads to escalate privileges to root, granting full control over affected systems. The issue impacts Edgenius versions 3.2.0.0 to 3.2.4.0 across various deployments, including Edgenius Gateway and Server models. ABB has released version 3.2.4.1 to address this vulnerability and recommends immediate updates. ([library.e.abb.com](https://library.e.abb.com/public/7fecf60652de4f8389c65dd3892ad4f0/7PAA024620_A_en%20ABB%20Ability%20Edgenius.pdf?x-sign=CTBqG4CeWrSNfPCZ4%2Bpgxw0qQeqB4l5P1o8dYUUq%2BXJ5ZJyaTAO4yFUHSWMPvOXH&utm_source=openai)) The 'Copy Fail' vulnerability has been actively exploited in the wild, with reports of attackers leveraging it to gain unauthorized root access in cloud environments. Given its widespread impact across multiple Linux distributions and the availability of proof-of-concept exploits, organizations are urged to prioritize patching to mitigate potential security breaches. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/?utm_source=openai))
6 days ago
Kill Chain
Critical Vulnerabilities in ABB T-MAC Plus Threaten Industrial Control Systems
In June 2026, ABB disclosed multiple critical vulnerabilities in its T-MAC Plus system, versions 4.0-24, affecting industrial control systems worldwide. The identified vulnerabilities include CVE-2025-14771 (file disclosure), CVE-2025-14772 (authorization bypass), CVE-2025-14773 (stored cross-site scripting), and CVE-2025-14774 (denial-of-service via insecure network protocol). Exploitation of these flaws could lead to unauthorized access, data exfiltration, and disruption of critical manufacturing operations. ABB has released version 4.0-25 to address these issues and recommends immediate updates. ([library.e.abb.com](https://library.e.abb.com/public/fdc6cdcbc5a14784a640c5f346bb5d5d/9AKK108472A7840_en_A_Vulnerabilities%20in%20T-MAC%20Plus.pdf?x-sign=9BMyAW9U5kVKNEtaWjhiCwtjt5iWMxiwQl8QdxbPx1vwCqNhlozXxFzbtRzs7ZQN&utm_source=openai)) The disclosure underscores the persistent threat landscape targeting industrial control systems, emphasizing the need for robust cybersecurity measures. Organizations are urged to assess their systems for similar vulnerabilities and implement comprehensive security protocols to safeguard against potential exploits.
6 days ago
Kill Chain
Critical Security Alert: Unauthenticated Remote Access Vulnerability in Rockwell Automation 1715-AENTR EtherNet/IP Adapter
In July 2026, a critical vulnerability (CVE-2026-10577) was identified in Rockwell Automation's 1715-AENTR EtherNet/IP Adapter, exposing a network-accessible debug port lacking proper authentication controls. This flaw allows unauthenticated remote attackers to execute intrusive command-line interface commands, including reading or deleting files, stopping tasks, modifying memory, and altering I/O states, thereby compromising the device's confidentiality, integrity, and availability. The vulnerability affects versions up to and including 3.003. Rockwell Automation has released version 3.011 to address this issue. Organizations utilizing these adapters are urged to update promptly to mitigate potential risks. This incident underscores the critical importance of securing industrial control systems against unauthorized access, especially as such vulnerabilities can lead to significant operational disruptions. The exposure of critical functions without authentication highlights the need for stringent security measures in industrial environments to prevent potential exploitation by malicious actors.
6 days ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports