The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Industrial Automation
Breach intelligence, attack campaigns, and threat reports targeting the Industrial Automation sector.
Explore Other Sectors
Industrial Automation Threat Reports
Critical Vulnerabilities in ABB T-MAC Plus Threaten Industrial Control Systems
In June 2026, ABB disclosed multiple critical vulnerabilities in its T-MAC Plus system, versions 4.0-24, affecting industrial control systems worldwide. The identified vulnerabilities include CVE-2025-14771 (file disclosure), CVE-2025-14772 (authorization bypass), CVE-2025-14773 (stored cross-site scripting), and CVE-2025-14774 (denial-of-service via insecure network protocol). Exploitation of these flaws could lead to unauthorized access, data exfiltration, and disruption of critical manufacturing operations. ABB has released version 4.0-25 to address these issues and recommends immediate updates. ([library.e.abb.com](https://library.e.abb.com/public/fdc6cdcbc5a14784a640c5f346bb5d5d/9AKK108472A7840_en_A_Vulnerabilities%20in%20T-MAC%20Plus.pdf?x-sign=9BMyAW9U5kVKNEtaWjhiCwtjt5iWMxiwQl8QdxbPx1vwCqNhlozXxFzbtRzs7ZQN&utm_source=openai)) The disclosure underscores the persistent threat landscape targeting industrial control systems, emphasizing the need for robust cybersecurity measures. Organizations are urged to assess their systems for similar vulnerabilities and implement comprehensive security protocols to safeguard against potential exploits.
2 months ago
Kill Chain
Critical Security Alert: Unauthenticated Remote Access Vulnerability in Rockwell Automation 1715-AENTR EtherNet/IP Adapter
In July 2026, a critical vulnerability (CVE-2026-10577) was identified in Rockwell Automation's 1715-AENTR EtherNet/IP Adapter, exposing a network-accessible debug port lacking proper authentication controls. This flaw allows unauthenticated remote attackers to execute intrusive command-line interface commands, including reading or deleting files, stopping tasks, modifying memory, and altering I/O states, thereby compromising the device's confidentiality, integrity, and availability. The vulnerability affects versions up to and including 3.003. Rockwell Automation has released version 3.011 to address this issue. Organizations utilizing these adapters are urged to update promptly to mitigate potential risks. This incident underscores the critical importance of securing industrial control systems against unauthorized access, especially as such vulnerabilities can lead to significant operational disruptions. The exposure of critical functions without authentication highlights the need for stringent security measures in industrial environments to prevent potential exploitation by malicious actors.
2 months ago
Kill Chain
New U-Boot Vulnerabilities Expose Devices to Stealthy Firmware Attacks
In July 2026, six critical vulnerabilities were discovered in the U-Boot bootloader, a widely used open-source component in embedded Linux devices such as enterprise servers, networking equipment, and IoT devices. These flaws, identified by the Binarly Research team, affect the FIT (Flattened Image Tree) signature verification process, potentially allowing attackers to execute malicious code during the device boot sequence. This could lead to stealthy firmware attacks that bypass security protections and install persistent malware, compromising devices before the operating system and its security software are initiated. The discovery underscores the increasing focus on firmware security, highlighting the need for robust verification mechanisms in bootloaders. As attackers continue to exploit vulnerabilities at the firmware level, organizations must prioritize securing their supply chains and implementing comprehensive security measures to protect against such sophisticated threats.
2 months ago
Kill Chain
Critical Vulnerability in Schneider Electric Easergy MiCOM Px40 Series: CVE-2026-4832
In April 2026, Schneider Electric disclosed a vulnerability (CVE-2026-4832) in its Easergy MiCOM Px40 Series protection relays. The flaw involves hard-coded credentials within the SNMP interface, allowing unauthenticated attackers to access sensitive device information. Affected models include Easergy MiCOM P14x, P24x, P341, and others, with versions prior to specific firmware updates being vulnerable. The vulnerability has a CVSS v4.0 score of 6.9, indicating a medium severity level. This incident underscores the critical importance of securing industrial control systems against unauthorized access. The use of hard-coded credentials is a known security risk, and organizations must prioritize updating firmware and implementing network protections to mitigate such vulnerabilities.
2 months ago
Kill Chain
OpenPLC v3 Vulnerability CVE-2026-14480: A Critical Threat to Industrial Control Systems
In July 2026, a critical vulnerability (CVE-2026-14480) was identified in OpenPLC v3, an open-source programmable logic controller widely used in industrial control systems. This flaw allows authenticated attackers to write arbitrary files to the filesystem, potentially leading to remote code execution with the privileges of the OpenPLC runtime user. Exploitation could result in unauthorized control over industrial processes, posing significant risks to critical infrastructure sectors such as manufacturing, energy, transportation, and water systems. The discovery of this vulnerability underscores the ongoing challenges in securing industrial control systems, especially those relying on open-source solutions. As cyber threats targeting critical infrastructure continue to evolve, it is imperative for organizations to proactively assess and mitigate vulnerabilities to prevent potential disruptions and ensure operational resilience.
2 months ago
Kill Chain
Critical Vulnerabilities Discovered in Digi International's PortServer TS and Digi One SP IA Devices
In July 2026, Digi International disclosed two significant vulnerabilities affecting their PortServer TS and Digi One SP IA devices. The first, CVE-2026-12352, allows unauthenticated attackers to bypass authentication mechanisms, granting unauthorized access to restricted resources. The second, CVE-2026-12948, is a stored cross-site scripting (XSS) vulnerability that enables authenticated administrators to inject malicious scripts into system configuration fields, which execute in the browsers of users viewing the affected pages. These vulnerabilities pose risks of unauthorized access, credential theft, and potential system compromise. The disclosure of these vulnerabilities underscores the critical importance of securing networked devices, especially those integral to industrial control systems. Organizations must prioritize timely firmware updates and implement robust network segmentation to mitigate such risks. This incident highlights the ongoing challenges in maintaining the security of legacy systems and the necessity for continuous monitoring and proactive defense strategies.
2 months ago
Kill Chain
Critical Vulnerability in Hitachi Energy e-mesh EMS: CVE-2026-42945
In July 2026, Hitachi Energy disclosed a critical vulnerability (CVE-2026-42945) in its e-mesh EMS versions 4.1.6, 4.4.2, and 4.7.0. This heap-based buffer overflow in the NGINX component's ngx_http_rewrite_module allows unauthenticated attackers to send crafted HTTP requests, potentially leading to application crashes and arbitrary code execution. The vulnerability arises when specific rewrite directives are used with unnamed PCRE captures and replacement strings containing a question mark. ([windowsforum.com](https://windowsforum.com/threads/cve-2026-42945-nginx-heap-overflow-hits-hitachi-energy-e-mesh-ems.435597/?utm_source=openai)) This incident underscores the risks of integrating widely-used web components like NGINX into critical infrastructure systems. Organizations must prioritize patching affected systems and reviewing configurations to mitigate potential exploitation, especially in environments where operational technology intersects with standard web technologies.
2 months ago
Kill Chain
Iranian Hackers Target U.S. Industrial Control Systems in 2026
In early 2026, Iranian state-sponsored hackers launched a series of cyberattacks targeting U.S. critical infrastructure, focusing on industrial control systems (ICS) such as Rockwell Automation's Allen-Bradley programmable logic controllers (PLCs). These attacks exploited vulnerabilities in internet-exposed devices, leading to operational disruptions and potential safety hazards across sectors like water treatment and energy. ([nextgov.com](https://www.nextgov.com/cybersecurity/2026/04/pro-iran-hackers-are-targeting-us-industrial-control-systems-advisory-says/412679/?oref=ng-homepage-river&utm_source=openai)) This incident underscores the escalating threat landscape for ICS environments, highlighting the urgent need for organizations to secure operational technology assets against sophisticated nation-state actors. ([cybersecuritydive.com](https://www.cybersecuritydive.com/news/critical-infrastucture-plcs-iran-hacking-censys/817209/?utm_source=openai))
2 months ago
Kill Chain
Critical Vulnerability in Schneider Electric's License Manager Poses Risks to Industrial Systems
In 2024, a critical vulnerability identified as CVE-2024-2658 was discovered in Schneider Electric's Floating License Manager, specifically within the FlexNet Publisher component. This flaw, classified under CWE-427: Uncontrolled Search Path Element, allows local non-administrative users to manipulate the OpenSSL configuration file, leading to the execution of arbitrary code with elevated privileges. Exploitation of this vulnerability can result in full control over the affected system, including access to sensitive data and potential lateral movement within industrial networks. The urgency to address this vulnerability is heightened by the increasing targeting of industrial control systems by cyber adversaries. Organizations utilizing Schneider Electric's software are advised to implement the recommended mitigations promptly to prevent potential exploitation and safeguard critical infrastructure.
2 months ago
Kill Chain
Kubota Data Breach 2026: A Wake-Up Call for Industrial Cybersecurity
In early 2026, Kubota North America Corporation experienced a significant data breach where unauthorized actors accessed its network systems from March 16 to April 20. The intrusion led to the exposure of sensitive personal information belonging to employees and their dependents, including full names, Social Security numbers, dates of birth, taxpayer IDs, driver's license numbers, direct deposit bank account details, corporate payment card information, and benefits enrollment data. Kubota has since notified affected individuals and offered identity protection services to mitigate potential risks. This incident underscores the escalating threat landscape targeting industrial manufacturers, emphasizing the critical need for robust cybersecurity measures. The breach highlights the importance of proactive security protocols and continuous monitoring to safeguard sensitive employee data against unauthorized access and potential misuse.
2 months ago
Kill Chain
Critical Vulnerabilities in Delta Electronics DVP12SE PLCs: CVE-2026-12819 and CVE-2026-12818
In June 2026, critical vulnerabilities were identified in Delta Electronics DVP12SE Programmable Logic Controllers (PLCs), specifically CVE-2026-12819 and CVE-2026-12818. These flaws allow remote attackers to issue commands, modify operational values, and interfere with control logic without authentication. The vulnerabilities affect all versions of the DVP12SE PLC, potentially enabling unauthorized access to sensitive control functions and causing resource exhaustion through flooding attacks. The discovery of these vulnerabilities underscores the increasing risks associated with industrial control systems (ICS) and the necessity for robust security measures. Organizations utilizing Delta Electronics DVP12SE PLCs should implement recommended mitigations, such as enabling IP filtering, setting up password protection, and ensuring network isolation, to safeguard against potential exploitation.
2 months ago
Kill Chain
Critical XZ Utils Vulnerability Affects B&R Products (CVE-2025-31115)
In June 2026, B&R Industrial Automation GmbH disclosed a critical vulnerability (CVE-2025-31115) in their products due to a flaw in XZ Utils versions 5.3.3alpha to 5.8.0. This race condition within the multithreaded .xz decoder in liblzma could allow attackers to crash the system or corrupt memory data. Affected products include PPC3100, C50, C80, FT50, MT50, T30, T80, and T50, with specific versions listed in the advisory. The vulnerability has a CVSS v3 base score of 7.5, indicating high severity. ([cisa.gov](https://www.cisa.gov/sites/default/files/publications/web-metrics/CISA.gov-Apr-2024-Web-Metrics-508.pdf?utm_source=openai)) This incident underscores the importance of promptly addressing vulnerabilities in widely used open-source libraries. Organizations are advised to update to XZ Utils version 5.8.1 or apply the provided patches to mitigate potential risks. ([cisa.gov](https://www.cisa.gov/sites/default/files/publications/web-metrics/CISA.gov-Apr-2024-Web-Metrics-508.pdf?utm_source=openai))
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports