VYPR
AI Brief2026-07-24· generated Jul 24, 2026

ICS Vulnerabilities Pose RCE, Privilege Escalation Risks

Multiple industrial control system vendors, including Johnson Controls, MZ Automation, Weintek, and Panduit, disclosed critical vulnerabilities allowing RCE, privilege escalation, and data exposure.

Critical vulnerabilities in Johnson Controls' C-CURE 9000 and victor applications could allow unauthenticated adjacent network attackers to achieve arbitrary code execution or forge server-side HTTP requests, potentially leading to interaction with internal services. These flaws, including CVE-2026-21655 and CVE-2026-21653, also permit low-privilege users to access unauthorized pages and sensitive system information, as detailed in CISA ICS Advisories.

MZ Automation's libIEC61850 and lib60870 components are affected by several high-severity vulnerabilities. Heap-based buffer overflows and out-of-bounds reads, such as in CVE-2026-49035 and CVE-2026-16002, could lead to remote code execution or denial-of-service conditions. Additionally, NULL pointer dereferences and stack-based buffer overflows (CVE-2026-50032, CVE-2026-50039, CVE-2026-50103) present risks of server crashes and memory corruption, as reported by Vypr Intelligence.

Weintek cMT3092X HMIs are vulnerable to privilege escalation and data exposure through multiple high and medium severity flaws. Attackers can modify tokens or cookies to gain elevated privileges (CVE-2026-61892, CVE-2026-60134), and user account passwords are stored in plaintext (CVE-2026-61886). Some vulnerabilities allow modification of read-only data, as noted in CISA ICS Advisories.

Panduit's Pronetiqs IntraVUE software, versions prior to 3.2.1a14, contains several vulnerabilities including an unintended proxy flaw that could bypass OT segmentation (CVE-2026-42933). Sensitive system information exposure (CVE-2026-28698) and plaintext storage of passwords (CVE-2026-40430) are also present. Inadequate encryption strength could allow for credential theft via weak hashes or pass-the-hash attacks (CVE-2026-50044), as outlined in CISA ICS Advisories.

Rockwell Automation ThinManager software has a path traversal vulnerability (CVE-2026-11917) that allows an authenticated attacker to write arbitrary files to the system due to improper file save operations within the API. This could lead to further compromise of the affected systems, as highlighted by CISA ICS Advisories.

Synthesized by Vypr AI