What you need to know today.
CISA issues ICS alerts for critical vulnerabilities in Panduit, Johnson Controls, Weintek, MZ Automation, and Rockwell Automation products.

CISA has issued a series of ICS advisories detailing vulnerabilities across multiple industrial control system vendors. Panduit's Pronetiqs IntraVUE is affected by several flaws, including an unintended proxy vulnerability (CVE-2026-42933) that could bypass OT segmentation, and a sensitive information exposure vulnerability (CVE-2026-28698) that could expose the underlying host filesystem. Additionally, plaintext storage of passwords (CVE-2026-40430) and inadequate encryption strength (CVE-2026-50044) could lead to credential theft. These vulnerabilities, affecting versions 3.2.1a14 and prior, pose significant risks to operational technology environments. As reported by CISA ICS Advisories, patches or mitigations should be applied promptly.
Johnson Controls products are impacted by multiple critical and high-severity vulnerabilities. The XAAP Android application has a cleartext storage weakness (CVE-2026-34490) that could expose local application data to attackers with physical device access. More broadly, the C-CURE 9000 and Victor application server are susceptible to SSRF (CVE-2026-21653), arbitrary code execution (CVE-2026-21655), and unauthorized page access (CVE-2026-34496). These flaws could allow attackers to forge requests, gain control of servers, and access sensitive system information. CISA ICS Advisories provide further details on affected versions and remediation.
Weintek's cMT3092X HMI is affected by several privilege escalation and information disclosure vulnerabilities. Attackers can modify tokens (CVE-2026-61892) or cookies (CVE-2026-60134) to escalate privileges, and user account passwords are stored in plaintext (CVE-2026-61886). Additionally, a vulnerability allows modification of read-only data (CVE-2026-60135). These issues could lead to unauthorized access and control of the HMI system. CISA ICS Advisories detail the scope of these vulnerabilities.
MZ Automation's libIEC61850 and lib60870 libraries contain several vulnerabilities, including heap-based buffer overflows (CVE-2026-49035) and out-of-bounds reads (CVE-2026-16002), which could lead to remote code execution or denial of service. NULL pointer dereferences in MMS handlers (CVE-2026-50032, CVE-2026-50039) and L2 GOOSE and R-GOOSE parsers (CVE-2026-50103) could also result in application crashes. These flaws, detailed in CISA ICS Advisories and https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-07, impact the integrity and availability of systems using these libraries.
Rockwell Automation's ThinManager software has a path traversal vulnerability (CVE-2026-11917) that could allow an authenticated attacker to write arbitrary files to the system. This could lead to system compromise or the execution of malicious code. CISA ICS Advisories provide details on affected versions and recommend applying available patches.
Netty, a network application framework, has a vulnerability in its OcspClient (CVE-2026-56820) where it fails to validate the CertificateID in an OCSP response. This could potentially allow for man-in-the-middle attacks or other security bypasses in applications using affected versions of Netty. The vulnerability impacts versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final.