The Containment Era is here. →Explore

Executive Summary

In May 2026, multiple vulnerabilities were identified in Subnet Solutions Inc.'s PowerSYSTEM Center, a critical infrastructure management platform. These vulnerabilities, including CVE-2026-26289, CVE-2026-33570, CVE-2026-35555, and CVE-2026-35504, could allow authenticated attackers to expose sensitive information, perform unauthorized actions, or inject malicious content. The affected versions span PowerSYSTEM Center 2020, 2024, and 2026 releases. Exploitation of these flaws could lead to unauthorized data access, privilege escalation, and potential disruption of critical manufacturing and energy sectors.

The discovery of these vulnerabilities underscores the persistent risks in industrial control systems and the importance of timely software updates. Organizations relying on PowerSYSTEM Center should prioritize applying the recommended patches and reviewing their security protocols to mitigate potential threats.

Why This Matters Now

The identification of these vulnerabilities highlights the ongoing challenges in securing industrial control systems, emphasizing the need for continuous vigilance and prompt remediation to protect critical infrastructure from potential cyber threats.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The affected versions include PowerSYSTEM Center 2020 (<=5.28.x), 2024 (>=6.0.x to <=6.1.x), and 2026 (7.0.x).

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could likely reduce the attacker's ability to escalate privileges, move laterally, and exfiltrate data by enforcing strict segmentation and access controls.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to exploit authorization flaws may have been constrained, limiting unauthorized access to sensitive information.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges could have been limited, reducing the scope of administrative access.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's lateral movement within the network would likely have been constrained, limiting access to other systems and data repositories.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The establishment of command and control channels may have been restricted, reducing the attacker's ability to maintain persistent access.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The exfiltration of sensitive data would likely have been constrained, limiting unauthorized data transfer.

Impact (Mitigations)

The overall impact of unauthorized data access and system disruptions could have been reduced, limiting the attacker's ability to cause significant harm.

Impact at a Glance

Affected Business Functions

  • Device Management
  • Configuration Management
  • Compliance Reporting
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Potential exposure of sensitive device configurations and administrative data.

Recommended Actions

  • Implement Zero Trust Segmentation to enforce least privilege access and prevent unauthorized lateral movement.
  • Deploy East-West Traffic Security controls to monitor and restrict internal traffic flows, mitigating lateral movement risks.
  • Utilize Multicloud Visibility & Control solutions to detect and respond to anomalous activities across cloud environments.
  • Apply Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.
  • Regularly update and patch systems to address known vulnerabilities and reduce the attack surface.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image