ICS Vulnerabilities Plague Rockwell, AutomationDirect, NASA
Industrial control systems from Rockwell Automation and AutomationDirect face multiple denial-of-service and privilege escalation vulnerabilities, alongside flaws in NASA's flight software.

Rockwell Automation controllers (5380/5480/5580, 5370/5570, and communication modules 1756-EN2, EN3, and ENBT) are affected by several denial-of-service vulnerabilities. Flaws in handling invalid file data or CIP Implicit Connection packets could lead to a major nonrecoverable fault (MNRF) or device crash, requiring a power cycle for recovery. These issues impact a wide range of Rockwell Automation's industrial control systems, potentially disrupting operations. CVEs include CVE-2025-11698, CVE-2025-12011, CVE-2025-12012, CVE-2026-9653, and CVE-2026-12659.
Multiple memory corruption vulnerabilities exist in Rockwell Automation's Arena Simulation software, specifically within the Siman component (siman.exe, expmt.exe, linker.exe, model.exe). These flaws stem from improper validation of user-supplied data, leading to out-of-bounds writes. Successful exploitation could result in privilege escalation or system instability. The affected versions and specific components are detailed in CISA ICS Advisory ICSA-26-197-01, covering CVEs CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, and CVE-2026-8314.
AutomationDirect's Productivity Suite is vulnerable to privilege escalation due to out-of-bounds write flaws in its kernel driver. Local attackers can trigger these vulnerabilities via crafted IOCTL requests, potentially leading to kernel memory corruption, system instability, or elevated privileges. CISA ICS Advisory ICSA-26-197-04 and Vypr Intelligence highlight these issues, identified as CVE-2026-60063 and CVE-2026-61389.
A critical vulnerability in NASA's Core Flight System (cFS) Health & Safety (HS) application allows for a denial-of-service condition. Processing a routine Housekeeping Telemetry request with crafted data can trigger a segmentation fault, crashing the application. This impacts the reliability of flight systems, as detailed in CISA ICS Advisory ICSA-26-197-03, covering CVE-2026-15352.
Siemens SICAM 8 devices are susceptible to multiple vulnerabilities, including insufficient validation of authentication credentials, improper TLS hostname verification, and flaws in the firmware update mechanism. These issues could allow authenticated attackers to bypass security controls, gain unauthorized access, execute arbitrary SQL, disclose information, or install malicious firmware, leading to persistent code execution. CISA ICS Advisories ICSA-26-197-05 covers CVEs CVE-2026-54798, CVE-2026-54799, and CVE-2026-54801.
PyTorch Lightning, a popular deep learning framework, has a remote code execution vulnerability when handling malicious checkpoint files. This could allow an attacker to compromise systems running PyTorch Lightning by tricking users into loading a specially crafted checkpoint file. CVE-2026-58659 is associated with this risk.
PHP versions prior to 8.0.28, 8.1.16, and 8.2.3 contain a flaw in the password_verify() function. This function may incorrectly accept certain invalid Blowfish hashes as valid. If such an invalid hash is present in a password database, it could lead to application authentication bypass, potentially allowing unauthorized access. This vulnerability is tracked as CVE-2023-0567.
Ansible Automation Platform Gateway (aap-gateway) has a missing request header validation that allows for a Transport Layer Security (TLS) bypass. By spoofing the Subject header, an attacker could potentially bypass mutual TLS authentication, gaining unauthorized access to sensitive systems. This is identified as CVE-2026-12382.
SALTO ProAccess Space software, utilizing its tenancy feature, is vulnerable to privilege escalation. An authenticated attacker could exploit this flaw to gain access to logically partitioned spaces they should not have access to, compromising the security of access control systems. This is covered by CISA ICS Advisory ICSA-26-197-07 and CVE-2026-11889.
Snowflake Connector for Python is vulnerable to arbitrary SQL execution and information disclosure due to improper TLS hostname verification. This could allow an attacker to intercept communications or manipulate data processed by the connector. CVE-2026-15925 is associated with this vulnerability.