The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Water and Wastewater Systems
Breach intelligence, attack campaigns, and threat reports targeting the Water and Wastewater Systems sector.
Explore Other Sectors
Water and Wastewater Systems Threat Reports
Critical lwIP MQTT Vulnerability Threatens Global Critical Infrastructure
A critical out-of-bounds write vulnerability (CVE-2026-87121) was discovered in the lwIP TCP/IP Stack MQTT Client Application versions 2.0.1 through 2.2.1, affecting industrial control systems across multiple critical infrastructure sectors worldwide. The vulnerability carries a CVSS score of 9.8 and enables remote attackers to achieve full code execution without authentication, potentially compromising devices in chemical, energy, healthcare, transportation, and water systems. The flaw was discovered by Shahriyar Jalayeri of ByteRay Ltd. and reported to CISA, with fixes available through the lwIP repository. This vulnerability highlights the growing threat landscape facing industrial IoT devices and embedded systems, as attackers increasingly target foundational networking components to gain persistent access to critical infrastructure networks.
2 days ago
Kill Chain
Critical mySCADA Vulnerabilities Expose Global Industrial Control Systems to Attack
Critical vulnerabilities CVE-2026-73807 and CVE-2026-82567 were discovered in mySCADA myPRO Manager versions 2.1 and earlier, affecting industrial control systems worldwide. The first vulnerability (CVSS 9.8) allows unauthenticated attackers with network access to bypass authentication and access privileged management functions through the command API. The second vulnerability (CVSS 6.3) exposes an unauthenticated HTTP endpoint that enables attackers to send arbitrary SMS messages through connected GSM modems. These flaws impact critical infrastructure sectors including energy, manufacturing, transportation, and water systems globally. These vulnerabilities highlight the growing threat to industrial control systems as attackers increasingly target operational technology environments. With critical infrastructure under heightened scrutiny following recent nation-state campaigns, organizations must urgently address authentication gaps in SCADA systems that could enable devastating disruptions to essential services.
1 week ago
Kill Chain
Critical Vulnerabilities in MZ Automation's lib60870: CVE-2026-61893 and CVE-2026-63033
In July 2026, MZ Automation's lib60870 library, widely used in industrial control systems, was found to have critical vulnerabilities identified as CVE-2026-61893 and CVE-2026-63033. These flaws, present in version 2.4.0, could be exploited by attackers to crash the parsing process, leading to a denial of service. The vulnerabilities stem from out-of-bounds read errors triggered by specially crafted IEC 60870-5-104 I-frames, allowing unauthorized access to memory beyond allocated buffers. ([windowsforum.com](https://windowsforum.com/security-alerts.84/cve-2026-16002-lib60870-2-4-1-fixes-scada-denial-of-service-risk.440185/?utm_source=openai)) Given the widespread deployment of lib60870 in critical infrastructure sectors such as energy, water, and manufacturing, these vulnerabilities pose significant operational risks. Organizations are urged to update to version 2.4.1 or later to mitigate potential threats. ([windowsforum.com](https://windowsforum.com/security-alerts.84/cve-2026-16002-lib60870-2-4-1-fixes-scada-denial-of-service-risk.440185/?utm_source=openai))
1 month ago
Kill Chain
Critical Authentication Bypass Vulnerability in ABB Ability OPTIMAX (CVE-2025-14510)
In January 2026, ABB disclosed a critical vulnerability (CVE-2025-14510) in its Ability OPTIMAX software, widely used in industrial optimization. The flaw, stemming from an incorrect implementation of the authentication algorithm, affects versions 6.1, 6.2, 6.3.0 before 6.3.1-251120, and 6.4.0 before 6.4.1-251120. Exploitation could allow remote attackers to bypass authentication, potentially compromising confidentiality, integrity, and availability of industrial control systems. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2025-14510/?utm_source=openai)) This incident underscores the escalating risks in industrial control systems due to authentication vulnerabilities. With increasing integration of such systems into broader networks, the potential for unauthorized access and operational disruption grows, highlighting the need for robust security measures and timely patch management.
4 months ago
Kill Chain
Critical Vulnerability in ABB's IEC 61850 Communication Stack (CVE-2025-3756)
In April 2026, ABB disclosed a vulnerability (CVE-2025-3756) in the IEC 61850 communication stack used in its System 800xA and Symphony Plus products. An attacker with access to the IEC 61850 network could exploit this flaw by sending specially crafted packets, causing the PM 877, CI850, and CI868 modules to enter a fault state, or rendering the S+ Operations 61850 connectivity unavailable, leading to a denial-of-service condition. The overall functionality of the S+ Operations node remains unaffected; only the IEC 61850 communication function is impacted. Affected versions include AC800M (System 800xA) from 6.0.0x through 6.2.0006.0, Symphony Plus SD Series versions A_0 through B_0.005, Symphony Plus MR versions 3.10 through 3.52, and S+ Operations versions 2.1 through 3.3. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-3756?utm_source=openai)) This vulnerability underscores the critical importance of securing industrial control systems, especially those utilizing the IEC 61850 protocol. As cyber threats targeting operational technology environments continue to evolve, organizations must prioritize timely patching, network segmentation, and robust access controls to mitigate potential risks.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports