Today CISA’s NCCIC-ICS published one control system security advisory for products from AVEVA, and two medical device security advisories for products from Orthanc and NextGen. They also updated a control system advisory for products from ST Engineering.
Advisories
Aveva Advisory - This advisory describes four vulnerabilities in the AVEVA Pipeline Integrity Monitor. Two of the vulnerabilities were reported by Adham Khairy Ramadan via HackerOne.
Orthanc Advisory - This advisory describes an integer overflow or wraparound vulnerability in the Orthanc DICOM Server. The vulnerability was reported to CISA by Andrej Tomci
NextGen Advisory - This advisory describes three vulnerabilities in the NextGen Healthcare Mirth Connect. The vulnerabilities were reported to CISA by Abhinav Agarwal
Updates
ST Engineering Update - This update provides additional information on the iDirect iQ-Series Terminals advisory that was originally on July 2nd, 2026. The new information includes adding two vulnerabilities.
For more information on these advisories, including DTRH looks at exploits in the wild and POC, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-and-1-update-published-091 - subscription required.