VYPR
Vypr IntelligenceAI-generatedOct 9, 2026· 18 CVEs

Cisagov: 18 Vulnerabilities Across N-Tron, openPDC, and Malcolm Disclosed Together

Cisagov products, including Red Lion N-Tron switches and Grid Protection Alliance software, were hit with 18 vulnerabilities on Oct 8-9, 2026, ranging from critical to medium severity.

Key findings

  • 18 vulnerabilities disclosed across Cisagov products (N-Tron, openPDC, openHistorian, Malcolm) on Oct 8-9, 2026.
  • Critical and High severity flaws include hardcoded credentials, unauthenticated RCE, and DoS in industrial and security software.
  • Red Lion N-Tron switches suffer from plaintext credentials and unauthenticated admin actions via SNMP/TFTP.
  • Grid Protection Alliance's openPDC/openHistorian have critical flaws in Docker image, component loading, and service console.
  • Malcolm toolkit affected by auth bypass, CSRF, and insecure file upload vulnerabilities.
  • Patches and mitigations are available; users urged to consult CISA advisories for affected versions.

On October 8-9, 2026, a significant batch of 18 vulnerabilities was disclosed across multiple products from Cisagov, impacting industrial control systems and network infrastructure. These vulnerabilities, spanning critical to medium severity, highlight systemic weaknesses in authentication, data handling, and access control mechanisms. The disclosures were coordinated, with many CVEs published on the same day, indicating a focused disclosure event by security researchers and coordinating bodies like CISA. The affected products include Red Lion Controls N-Tron 700 Series switches, Grid Protection Alliance's openPDC and openHistorian software, and components within the Malcolm security analysis toolkit.

The Red Lion Controls N-Tron 700 Series switches are affected by seven vulnerabilities, primarily concerning insecure storage of credentials and unauthenticated administrative actions. CVE-2026-39460 and CVE-2026-28745 detail how usernames and passwords, including default factory credentials, are stored in plaintext or weakly encrypted within configuration files, making them accessible via CLI or TFTP. CVE-2026-33367 allows unauthenticated administrative actions via SNMP, including configuration retrieval and firmware updates. Additionally, CVE-2026-39453 enables a denial-of-service condition by causing the switch to reboot when a specific URL is accessed. CVE-2026-32645 and CVE-2026-33272 point to persistent default factory credentials that can be exploited for administrative access, even after new accounts are configured. Finally, CVE-2026-29797 allows unauthenticated firmware updates using SNMP/TFTP. These issues were patched in firmware version 700 Series <=Firmware_3.11.0 and bootloader version <=Bootloader_2.0.6.1. N2

Grid Protection Alliance's openPDC and openHistorian software are impacted by five vulnerabilities, with critical severity ratings for several. CVE-2026-105278 involves a hardcoded administrative credential in the openPDC Docker image, allowing administrative control without forced change on first use. CVE-2026-105281 permits unauthenticated retrieval of system topology data by connecting to the internal data publisher. CVE-2026-104629 describes a component loading mechanism that allows arbitrary code execution with elevated privileges if an attacker can place a file on the host. A critical vulnerability, CVE-2026-100730, allows unauthenticated network attackers to exploit a service console interface that deserializes client-supplied data, leading to remote code execution on systems without Windows Authentication. These vulnerabilities affect openPDC versions prior to 2.9.477 and 2.9.482, and openHistorian versions prior to 2.8.580 and 2.8.585. N1

The Malcolm security analysis toolkit is affected by six vulnerabilities, primarily related to authentication bypass and insecure handling of user-provided data. CVE-2026-107362, using the FilePond PHP server, allows arbitrary URL downloads due to an exposed fetch API route. CVE-2026-107361 enables automatic user creation with full access by exploiting the X-Forwarded-User header in the Arkime live capture service. CVE-2026-107337 allows arbitrary management commands, including data wiping, via CSRF attacks on the kiosk Flask application. CVE-2026-107336 points to a case-insensitive path matching issue in the front nginx proxy, potentially evading rewrites. CVE-2026-107335 details limits not being applied to single-stream compressed archives in the upload-processing pipeline. Lastly, CVE-2026-107333 describes a URL path normalization inconsistency in the nginx Lua RBAC layer, allowing authenticated users to bypass restrictions.

The coordinated disclosure of these vulnerabilities across multiple Cisagov products underscores the importance of timely patching and secure configuration, particularly in critical infrastructure and security analysis environments. The range of issues, from hardcoded credentials and plaintext passwords to unauthenticated remote code execution and denial-of-service conditions, presents a broad attack surface for adversaries. Users are strongly advised to consult the specific advisories for affected versions and apply available patches and mitigations promptly to protect their systems from potential compromise. The CISA advisories provide detailed information and versioning for the affected Red Lion Controls N-Tron 700 Series, openPDC, and openHistorian products. N1, N2

AI-written article. Grounded in 18 CVE records listed below.