Skip to main content
← All Articles

Tag

#ICS

50 articles

Advertisement

VU
CRITICAL
Vulnerabilities

CVE-2026-2417: Pharos Controls RCE via Missing Authentication

Critical vulnerability (CVE-2026-2417) in Pharos Controls Mosaic Show Controller firmware 2.15.3 allows unauthenticated root RCE. Upgrade to 2.16+ immediately.

Runtime Rebel Intel
4 min read·Mar 24, 2026
VU
MEDIUM
Vulnerabilities

CVE-2025-13902: Patching Schneider Electric Modicon Controllers

Schneider Electric Modicon M241 and M251 controllers face XSS risks via CVE-2025-13902. Learn how to patch firmware and secure industrial control networks.

Runtime Rebel Intel
3 min read·Mar 19, 2026
VU
HIGH
Vulnerabilities

CVE-2026-2273: Schneider Electric EcoStruxure Automation Expert RCE

Schneider Electric has addressed a high-severity code injection vulnerability (CVE-2026-2273) in EcoStruxure Automation Expert that risks full system compromise.

Runtime Rebel Intel
3 min read·Mar 19, 2026
VU
HIGH
Vulnerabilities

CVE-2025-13957: Hard-coded Credentials in Schneider EcoStruxure DCE

Hard-coded credentials in Schneider Electric EcoStruxure Data Center Expert v9.0 and prior (CVE-2025-13957) allow information disclosure and RCE if SOCKS Proxy is

Runtime Rebel Intel
5 min read·Mar 17, 2026
VU
HIGH
Vulnerabilities

ICS Patch Tuesday: Siemens, Schneider, Moxa Fix Critical Flaws

Industrial leaders Siemens, Schneider Electric, Moxa, and Mitsubishi Electric address over 40 vulnerabilities in critical ICS hardware and software components.

Runtime Rebel Intel
3 min read·Mar 11, 2026
VU
MEDIUM
Vulnerabilities

CVE-2025-57176: Unauthenticated File Upload in Ceragon Siklu Devices

An unauthenticated file upload vulnerability (CVE-2025-57176) in Ceragon Siklu MultiHaul and EtherHaul series devices poses risks to critical communications

Runtime Rebel Intel
5 min read·Mar 10, 2026
VU
CRITICAL
Vulnerabilities

CVE-2026-3611: Critical Auth Bypass in Honeywell IQ4x BMS Controllers

CISA warns of a critical authentication bypass (CVE-2026-3611) in Honeywell IQ4x BMS Controllers, allowing unauthenticated attackers administrative access and potential

Runtime Rebel Intel
5 min read·Mar 10, 2026
VU
HIGH
Vulnerabilities

CVE-2026-3094: Delta CNCSoft-G2 Out-of-bounds Write RCE

Delta Electronics CNCSoft-G2 is vulnerable to an out-of-bounds write (CVE-2026-3094) allowing remote code execution. Update to V2.1.0.39.

Runtime Rebel Intel
4 min read·Mar 5, 2026
VU
MEDIUM
Vulnerabilities

Multiple DoS/RCE Vulnerabilities in Yokogawa CENTUM VP R6, R7

CISA alerts to multiple medium-severity vulnerabilities in Yokogawa CENTUM VP R6 and R7, allowing DoS and RCE via crafted packets in critical infrastructure

Runtime Rebel Intel
4 min read·Feb 26, 2026
VU
CRITICAL
Vulnerabilities

Critical Authentication Flaws in Chargemap EV Infrastructure

CISA warns of critical vulnerabilities in Chargemap EV charging stations, including unauthenticated WebSocket access and session hijacking (CVE-2026-25851).

Runtime Rebel Intel
3 min read·Feb 26, 2026
Quantitative Scoring for OT Incidents: The Richter Scale Model
INFO
Threat Intel

Quantitative Scoring for OT Incidents: The Richter Scale Model

Analysis of a new logarithmic scoring system designed to quantify the physical magnitude and technical severity of operational technology (OT) cyberattacks.

Runtime Rebel Intel
3 min read·Feb 25, 2026
VU
CRITICAL
Vulnerabilities

Critical RCE Flaws in InSAT MasterSCADA BUK-TS Affect ICS

Two critical vulnerabilities (SQLi, OS Command Injection) in InSAT MasterSCADA BUK-TS lead to remote code execution, impacting critical infrastructure sectors globally.

Runtime Rebel Intel
4 min read·Feb 25, 2026