Thursday, September 17, 2026

7 Advisories and 1 Update Published – 9-17-26

Today CISA’s NCCIC-ICS published seven control system security advisories for products from Schneider Electric (3), ABB, Hitachi Energy, Mitsubishi Electric, and Bransys. They also updated an advisory for products from Mitsubishi. 

Advisories  

Schneider Advisory #1 - This advisory describes an improper restriction of excessive authentication attempts vulnerability in the Schneider Electric PowerChute Serial Shutdown. The vulnerability was self-reported. 

Schneider Advisory #2 - This advisory describes two vulnerabilities in the Schneider Electric NetBotz 5 750/755. The vulnerabilities were self-reported. 

Schneider Advisory #3 - This advisory describes an improper input validation vulnerability in the Schneider Electric Modicon M340 Controller and Communication Modules. The Schneider advisory notes that the vulnerability was reported by CyManII. 

ABB Advisory - This advisory discusses the Copy-Fail vulnerability in the ABB Ability Edgenius. The vulnerabilities were self-reported. 

Hitachi Energy Advisory - This advisory describes five vulnerabilities in the Hitachi Energy MicroSCADA Pro/X SYS600 product. The vulnerabilities were self-reported. 

Mitsubishi Advisory - This advisory describes an incorrect implementation of authentication algorithm vulnerability in the Mitsubishi Electric GX Works3 and Motion Control Settings products. The vulnerability was reported by Mayeul Fargier, Erwan Cordier, and Noé Flatreaud. 

Bransys Advisory - This advisory describes three vulnerabilities in the Bransys Electronic Logbook (ELB). The vulnerabilities were reported to CISA by Jaime Lightfoot.  

Updates  

Mitsubishi Update - This update provides additional information on the CC-Link IE TSN Communication Protocol advisory that was originally published on July 30th, 2026. The new information includes updating the list of affected products. 

No comments:

 
/* Use this with templates/template-twocol.html */