Tuesday, July 21, 2026

Review – 10 Advisories Published – 7-21-26

Today CISA’s NCCIC-ICS published ten control system security advisories for products from Rockwell Automation (4), Siemens (5), and Tycon Systems. I also take a down-the-rabbit-hole look at exploits for the Siemens CADRA and SIDIS vulnerabilities. 

Advisories  

Rockwell Advisory # 1 - This advisory describes three vulnerabilities in the Rockwell Studio 5000 Logix Designer products. Rockwell published their advisory on July 14th, 2026. 

Rockwell Advisory #2 - This advisory describes an allocation of resources without limit or throttling vulnerability in the Rockwell 1734 POINT I/O. Rockwell published their advisory on July 14th, 2026. 

Rockwell Advisory #3 - This advisory - This advisory describes an allocation of resources without limit or throttling vulnerability in the Rockwell 1718-AENTR/1719-AENTR. Rockwell published their advisory on July 14th, 2026. 

Rockwell Advisory #4 - This advisory describes a weak authentication vulnerability in the Rockwell FactoryTalk Services Platform. Rockwell published their advisory on July 14th, 2026. 

Siemens Advisory #1 - This advisory discusses 11 vulnerabilities in the Siemens CADRA design drafting software. Siemens published their advisory on July 14th, 2026. 

NOTE: See DTRH below for exploitable vulnerabilities. 

Siemens Advisory #2 - This advisory describes an untrusted search path vulnerability in the Siemens IAM Client products. Siemens published their advisory on July 14th, 2026. 

Siemens Advisory #3 - This advisory discusses 12 vulnerabilities in the Siemens SIDIS Secured SmartPlug. Siemens published their advisory on July 14th, 2026. 

NOTE: See DTRH below for exploitable vulnerabilities. 

Siemens Advisory #4 - This advisory describes an improper verification of cryptographic signature vulnerability in the Siemens Opcenter X. Siemens published their advisory on July 14th, 2026. 

Siemens Advisory #5 - This advisory discusses three vulnerabilities in the Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW. Siemens published their advisory on July 14th, 2026. 

Tycon Advisory - This advisory describes two vulnerabilities in the Tycon TPDIN-Monitor-WEB2. 


For more information on these advisories, as well as links for exploits for the Siemens CADRA and SIDIS vulnerabilities, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/10-advisories-published-7-21-26 - subscription required. 

OMB Approves FAA Space Launch Waiver NPRM

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of proposed rulemaking from the FAA on “Waiver of Specified Statutory Requirements for Commercial Space Launch and Reentry Actions”. The NPRM was sent to OIRA on July 7th, 2026.  

This rulemaking was not listed in the just published 2026 Unified Agenda. The rule would almost certainly amend 14 CFR Part 450. Launch and Reentry License Requirements. That Part does not currently include language that deals with the issue of license waivers. Waivers are authorized under 51 USC 50905(b)(3), but that paragraph specifically prohibits the FAA from issuing a waiver “that would permit the launch or reentry of a launch vehicle or a reentry vehicle without a license or permit if a human being will be on board.” 

I expect that the NPRM will be published in the Federal Register in the next week or so. I will almost certainly not provide any detailed coverage of this rulemaking. Under my limited Space Geek coverage, I would, however, expect to announce its publication in the appropriate Short Takes post. 

Monday, July 20, 2026

Review – Bills Introduced – 7-18-26

On Saturday, with neither the House nor Senate in session, there were five bills introduced. One of those bills will receive additional coverage in this blog: 


For more information on these bills, including legislative history for similar bills in the 118th Congress, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bills-introduced-7-18-26 - subscription required. 

Friday, July 17, 2026

CISA Adds 2 FortiGuard Vulnerabilities to KEV Catalog – 7-16-26

Yesterday, CISA announced that it had added two OS command injection vulnerabilities in the FortiGuard FortiSandbox product to the Known Exploited Vulnerabilities (KEV) catalog. 

CVE-2026-25089 – This vulnerability was previously reported by FortiGuard in June. FortiGuard has new versions that mitigate the vulnerability. 

CVE-2026-39808 – This vulnerability was previously reported by FortiGuard in April. FortiGuard has a new version that mitigates the vulnerability. The vulnerability was originally reported by Samuel de Lucas Maroto from KPMG Spain. Proof-of-concept code was published by Samu DeLucas on April 15th, 2026. 

CISA has directed federal agencies using the FortiSandbox product to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. A compliance deadline of July 19th, 2026 has been established. 

 
/* Use this with templates/template-twocol.html */