Today CISA’s NCCIC-ICS published 11 control system security advisories for products from MZ Automation (2), Watchfire, 06 Automation, Mitsubishi Electric, NASA, Rockwell Automation, Schneider Electric, Toptech, Johnson Controls, and MikroTik. They also updated an advisory for products from Hardy Barth.
Advisories
MZ Automation Advisory #1 - This advisory describes two vulnerabilities in the MZ Automation lib60870.
MZ Automation Advisory #2 - This advisory describes eight vulnerabilities in the MZ Automation GmbH libiec61850.
Watchfire Advisory - This advisory describes a hard-coded cryptographic key vulnerability in the Watchfire Controller Software.
06 Automation Advisory - This advisory describes four vulnerabilities in the o6 Automation open62541 OPC UA stack.
Mitsubishi Advisory - This advisory describes an improper enforcement of message integrity during transmission in a communication channel vulnerability in the Mitsubishi CC-Link IE TSN Communication Protocol.
NASA Advisory - This advisory describes a NULL pointer dereference vulnerability in the NASA Core Flight System (cFS) Health & Safety (HS) Application.
NOTE: This vulnerability is related to an incomplete fix for CVE 2026-15352.
Rockwell Advisory - This advisory describes an improper check for certificate revocation vulnerability in the Rockwell CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module.
Schneider Advisory - This advisory describes an out-of-bounds write vulnerability in the Schneider IGSS.
Toptech Advisory - This advisory describes a missing authentication for critical function vulnerability in the Toptech Systems RCU II+ and Multiload II+.
Johnson Controls Advisory - This advisory describes three vulnerabilities in the Johnson Controls OpenBlue Employee smart building ecosystem.
MikroTik Advisory - This advisory describes an insufficient session expiration vulnerability in the MikroTik RouterOS.
Updates
Hardy Barth Update - This update provides additional information on the Salia EV Charge Controller advisory that was originally published on April 21st, 2026.
For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/11-advisories-and-1-update-published-68f - subscription required.