Siemens, Tycon, Rockwell, Libssh Vulnerabilities Disclosed
Critical vulnerabilities disclosed in Siemens, Tycon Systems, and Rockwell Automation products, alongside multiple libssh flaws.

A critical vulnerability in Siemens Opcenter X (CVE-2026-56451) allows unauthenticated remote attackers to forge arbitrary JSON Web Tokens (JWTs) by exploiting improper validation of the algorithm specified in the JWT header. This could lead to bypassing authentication mechanisms and impersonating users, posing a significant risk to system integrity. The issue was detailed in a CISA ICS Advisory, highlighting its potential impact on industrial control systems.
Rockwell Automation products are affected by six disclosed vulnerabilities, including critical flaws in FactoryTalk Services Platform (CVE-2026-10714) and Studio 5000 Logix Designer (CVE-2026-9128, CVE-2026-9127). The FactoryTalk vulnerability allows bypassing JWT signature validation, while Studio 5000 suffers from unquoted search paths and incorrect authorization, both potentially leading to code execution. Additionally, a denial-of-service vulnerability affects the 1719-AENTR device (CVE-2026-9140) due to improper handling of UDP storms. These issues were collectively reported by Vypr Intelligence and detailed in CISA ICS Advisories.
A batch of eleven vulnerabilities in libssh, ranging in severity, have been disclosed, including an authentication bypass via a missing GSSAPI principal check (CVE-2026-59851) and multiple denial-of-service flaws (CVE-2026-59843, CVE-2026-59844, CVE-2026-59848, CVE-2026-59850). Other vulnerabilities include a stack buffer overflow (CVE-2026-15370), an integrity downgrade via OpenSSL AES-GCM tag verification (CVE-2026-59847), and a use-after-free vulnerability (CVE-2026-59850). These collectively present a broad attack surface for libssh deployments, as reported by Vypr Intelligence.
Tycon Systems TPDIN-Monitor-WEB2 devices are impacted by two vulnerabilities: a critical authentication bypass (CVE-2026-61884) due to a lack of server-side credential validation on the web management interface, and a medium-severity issue where system credentials are stored in cleartext (CVE-2026-55985). The authentication bypass allows unauthenticated attackers to gain access, while the cleartext credential storage exposes sensitive information to authenticated users. Both issues were highlighted in a CISA ICS Advisory.
Red Hat's ansible-core is affected by an argument injection vulnerability (CVE-2026-16493) within the ansible-galaxy collection install command when using git clone. This is noted as an incomplete fix for a previous vulnerability, CVE-2026-11332, indicating a persistent risk of command injection if not properly addressed.
Siemens IAM Client SDK contains a medium-severity vulnerability (CVE-2025-40945) where an untrusted search path could allow an authenticated user to escalate privileges via local access. This was detailed in a CISA ICS Advisory.
Dracut, a utility for creating initial RAM file systems, has a critical vulnerability (CVE-2026-16445) allowing root code execution through command injection in its NetworkManager initrd module via DHCP options. This could enable attackers to gain elevated privileges during the boot process.