<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Critical Manufacturing</title><description>Cybersecurity articles tagged #Critical Manufacturing on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Rockwell RSLinx &lt;4.50.00 RCE via CVE-2020-13573 — Patch Now</title><link>https://runtimerebel.com/blog/rockwell-rslinx-4-50-00-rce-via-cve-2020-13573-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/rockwell-rslinx-4-50-00-rce-via-cve-2020-13573-patch-now</guid><description>Urgent advisory for Rockwell RSLinx Classic users. CVE-2020-13573, a stack-based buffer overflow, enables remote code execution and DoS. Patch &lt;=4.50.00.</description><pubDate>Thu, 18 Jun 2026 09:58:04 GMT</pubDate><category>Rockwell Automation</category><category>RSLinx Classic</category><category>CVE-2020-13573</category><category>Buffer Overflow</category><category>RCE</category><category>Denial of Service</category><category>ICS</category><category>Critical Manufacturing</category><category>Energy</category></item><item><title>CVE-2026-11317: Rockwell Logix DoS via CIP — Patch Critical ICS</title><link>https://runtimerebel.com/blog/cve-2026-11317-rockwell-logix-dos-via-cip-patch-critical-ics</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-11317-rockwell-logix-dos-via-cip-patch-critical-ics</guid><description>Critical Manufacturing faces high-severity DoS risk in Rockwell Automation Logix 5370 &amp; 5570 controllers from CVE-2026-11317. Patch now.</description><pubDate>Thu, 18 Jun 2026 09:57:33 GMT</pubDate><category>CVE-2026-11317</category><category>Rockwell Automation</category><category>Logix 5370</category><category>Logix 5570</category><category>CompactLogix</category><category>ControlLogix</category><category>GuardLogix</category><category>Denial of Service</category><category>ICS</category><category>Critical Manufacturing</category><category>CIP</category></item><item><title>CVE-2021-22291: ABB EIBPORT V3 &lt;3.9.2 Session Hijacking Vulnerability</title><link>https://runtimerebel.com/blog/cve-2021-22291-abb-eibport-v3-3-9-2-session-hijacking-vulnerability</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2021-22291-abb-eibport-v3-3-9-2-session-hijacking-vulnerability</guid><description>ABB EIBPORT V3 devices are vulnerable to CVE-2021-22291 (XSS/session hijacking), allowing unauthenticated access and configuration changes. Patch immediately.</description><pubDate>Thu, 28 May 2026 17:27:09 GMT</pubDate><category>CVE-2021-22291</category><category>ABB EIBPORT</category><category>XSS</category><category>Session Hijacking</category><category>ICS</category><category>Building Automation</category><category>Critical Manufacturing</category></item><item><title>CVE-2022-4304: Hitachi Energy GMS600 Timing Side Channel Vulnerability</title><link>https://runtimerebel.com/blog/cve-2022-4304-hitachi-energy-gms600-timing-side-channel-vulnerability</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2022-4304-hitachi-energy-gms600-timing-side-channel-vulnerability</guid><description>Hitachi Energy GMS600 versions 1.3.0-1.3.1 affected by CVE-2022-4304, an OpenSSL timing side channel leading to TLS decryption. Patch to 1.3.2 now.</description><pubDate>Thu, 21 May 2026 20:43:48 GMT</pubDate><category>CVE-2022-4304</category><category>Hitachi Energy GMS600</category><category>OpenSSL</category><category>Timing Side Channel</category><category>Critical Manufacturing</category><category>ICS</category><category>CWE-203</category></item><item><title>CVE-2026-0300: Siemens RUGGEDCOM APE1808 RCE via PAN-OS Vulnerability</title><link>https://runtimerebel.com/blog/cve-2026-0300-siemens-ruggedcom-ape1808-rce-via-pan-os-vulnerability</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-0300-siemens-ruggedcom-ape1808-rce-via-pan-os-vulnerability</guid><description>Critical RCE (CVE-2026-0300) in Siemens RUGGEDCOM APE1808 devices via PAN-OS User-ID Captive Portal buffer overflow. Unauthenticated root code execution possible.</description><pubDate>Tue, 19 May 2026 20:43:35 GMT</pubDate><category>CVE-2026-0300</category><category>Siemens RUGGEDCOM APE1808</category><category>Palo Alto Networks PAN OS</category><category>Buffer Overflow</category><category>RCE</category><category>Critical Manufacturing</category></item><item><title>CVE-2026-40175: Siemens gWAP RCE via Axios Prototype Pollution</title><link>https://runtimerebel.com/blog/cve-2026-40175-siemens-gwap-rce-via-axios-prototype-pollution</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-40175-siemens-gwap-rce-via-axios-prototype-pollution</guid><description>Siemens gWAP is vulnerable to RCE via CVE-2026-40175, a prototype pollution flaw in the Axios HTTP client library. Update to v3.1.1 or later.</description><pubDate>Thu, 14 May 2026 20:40:58 GMT</pubDate><category>CVE-2026-40175</category><category>Siemens gWAP</category><category>Axios</category><category>RCE</category><category>Prototype Pollution</category><category>Critical Manufacturing</category><category>ICS</category></item><item><title>CVE-2026-41551: Siemens ROS# Path Traversal Remediation Guide</title><link>https://runtimerebel.com/blog/cve-2026-41551-siemens-ros-path-traversal-remediation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-41551-siemens-ros-path-traversal-remediation-guide</guid><description>Critical path traversal vulnerability (CVE-2026-41551) in Siemens ROS# file_server allows arbitrary file access. Immediate update to v2.2.2+ is crucial.</description><pubDate>Thu, 14 May 2026 20:40:37 GMT</pubDate><category>CVE-2026-41551</category><category>Siemens ROS</category><category>Path Traversal</category><category>Critical Manufacturing</category><category>ICS Security</category></item><item><title>CVE-2025-15467: ABB AC500 V3 Stack Buffer Overflow to RCE</title><link>https://runtimerebel.com/blog/cve-2025-15467-abb-ac500-v3-stack-buffer-overflow-to-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-15467-abb-ac500-v3-stack-buffer-overflow-to-rce</guid><description>Critical vulnerability [CVE-2025-15467](https://nvd.nist.gov/vuln/detail/CVE-2025-15467) in ABB AC500 V3 PM5xxx firmware could lead to unauthenticated remote code…</description><pubDate>Tue, 12 May 2026 20:40:45 GMT</pubDate><category>CVE-2025-15467</category><category>ABB AC500 V3</category><category>Stack Buffer Overflow</category><category>ICS Security</category><category>PLC Security</category><category>Out of Bounds Write</category><category>Critical Manufacturing</category><category>Energy</category></item><item><title>ABB B&amp;R Automation Runtime DoS via CVE-2025-11044 — Patch Now</title><link>https://runtimerebel.com/blog/abb-b-r-automation-runtime-dos-via-cve-2025-11044-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/abb-b-r-automation-runtime-dos-via-cve-2025-11044-patch-now</guid><description>An unauthenticated network DoS vulnerability (CVE-2025-11044) affects ABB B&amp;R Automation Runtime, allowing permanent system halts. Immediate patching is critical.</description><pubDate>Wed, 06 May 2026 00:49:26 GMT</pubDate><category>CVE-2025-11044</category><category>ABB</category><category>B R Automation Runtime</category><category>ICS</category><category>DoS</category><category>CWE-770</category><category>Critical Manufacturing</category></item><item><title>CVE-2025-11043: ABB Automation Studio &lt;6.5 Improper Certificate Validation</title><link>https://runtimerebel.com/blog/cve-2025-11043-abb-automation-studio-6-5-improper-certificate-validation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-11043-abb-automation-studio-6-5-improper-certificate-validation</guid><description>Critical manufacturing systems running ABB B&amp;R Automation Studio &lt;6.5 are vulnerable to CVE-2025-11043, allowing data interception and spoofing via improper certificate…</description><pubDate>Wed, 06 May 2026 00:48:57 GMT</pubDate><category>CVE-2025-11043</category><category>ABB B R Automation Studio</category><category>Improper Certificate Validation</category><category>Critical Manufacturing</category><category>ICS</category><category>OPC UA</category><category>ANSL Over TLS</category></item><item><title>CVE-2026-3893: Unauthenticated Access in Carlson VASCO-B GNSS Receiver</title><link>https://runtimerebel.com/blog/cve-2026-3893-unauthenticated-access-in-carlson-vasco-b-gnss-receiver</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-3893-unauthenticated-access-in-carlson-vasco-b-gnss-receiver</guid><description>Critical CVE-2026-3893 in Carlson VASCO-B GNSS Receivers &lt;1.4.0 allows unauthenticated remote alteration of critical system functions. Update to v1.4.0+.</description><pubDate>Thu, 23 Apr 2026 20:26:34 GMT</pubDate><category>CVE-2026-3893</category><category>Carlson Software</category><category>VASCO B GNSS Receiver</category><category>Critical Manufacturing</category><category>Missing Authentication</category><category>ICS Security</category></item><item><title>CVE-2026-5387: AVEVA Pipeline Simulation Privilege Escalation</title><link>https://runtimerebel.com/blog/cve-2026-5387-aveva-pipeline-simulation-privilege-escalation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-5387-aveva-pipeline-simulation-privilege-escalation</guid><description>Unauthenticated attackers can exploit CVE-2026-5387 in AVEVA Pipeline Simulation &lt;=2025_SP1_build_7.1.9497.6351 to modify critical ICS simulation parameters and training…</description><pubDate>Fri, 17 Apr 2026 05:05:22 GMT</pubDate><category>CVE-2026-5387</category><category>AVEVA</category><category>Pipeline Simulation</category><category>ICS</category><category>Critical Manufacturing</category><category>Missing Authorization</category><category>Privilege Escalation</category></item><item><title>Mitsubishi Electric ICS Vulnerabilities Expose SQL Credentials</title><link>https://runtimerebel.com/blog/mitsubishi-electric-ics-vulnerabilities-expose-sql-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/mitsubishi-electric-ics-vulnerabilities-expose-sql-credentials</guid><description>High-severity vulnerabilities (CVE-2025-14815, CVE-2025-14816) in Mitsubishi Electric ICS/SCADA products risk SQL credential exposure and data compromise.</description><pubDate>Tue, 07 Apr 2026 16:31:20 GMT</pubDate><category>CVE-2025-14815</category><category>CVE-2025-14816</category><category>Mitsubishi Electric</category><category>GENESIS64</category><category>ICONICS Suite</category><category>ICS</category><category>SCADA</category><category>Cleartext Storage</category><category>Critical Manufacturing</category><category>SQL Server</category></item><item><title>CVE-2026-4681: Critical RCE in PTC Windchill &amp; FlexPLM</title><link>https://runtimerebel.com/blog/cve-2026-4681-critical-rce-in-ptc-windchill-flexplm</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-4681-critical-rce-in-ptc-windchill-flexplm</guid><description>Critical RCE vulnerability CVE-2026-4681 affects PTC Windchill and FlexPLM via deserialization. Patch now to prevent code injection in critical manufacturing.</description><pubDate>Thu, 26 Mar 2026 16:40:04 GMT</pubDate><category>CVE-2026-4681</category><category>PTC Windchill</category><category>FlexPLM</category><category>RCE</category><category>Code Injection</category><category>Deserialization</category><category>Critical Manufacturing</category></item><item><title>CVE-2026-3094: Delta CNCSoft-G2 Out-of-bounds Write RCE</title><link>https://runtimerebel.com/blog/cve-2026-3094-delta-cncsoft-g2-out-of-bounds-write-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-3094-delta-cncsoft-g2-out-of-bounds-write-rce</guid><description>Delta Electronics CNCSoft-G2 is vulnerable to an out-of-bounds write (CVE-2026-3094) allowing remote code execution. Update to V2.1.0.39.</description><pubDate>Thu, 05 Mar 2026 20:17:47 GMT</pubDate><category>CVE-2026-3094</category><category>Delta Electronics</category><category>CNCSoft G2</category><category>ICS</category><category>OT</category><category>Critical Manufacturing</category><category>Out of Bounds Write</category><category>RCE</category></item><item><title>Multiple DoS/RCE Vulnerabilities in Yokogawa CENTUM VP R6, R7</title><link>https://runtimerebel.com/blog/multiple-dos-rce-vulnerabilities-in-yokogawa-centum-vp-r6-r7</link><guid isPermaLink="true">https://runtimerebel.com/blog/multiple-dos-rce-vulnerabilities-in-yokogawa-centum-vp-r6-r7</guid><description>CISA alerts to multiple medium-severity vulnerabilities in Yokogawa CENTUM VP R6 and R7, allowing DoS and RCE via crafted packets in critical infrastructure…</description><pubDate>Thu, 26 Feb 2026 20:16:44 GMT</pubDate><category>Yokogawa</category><category>CENTUM VP</category><category>ICS</category><category>SCADA</category><category>CVE-2025-1924</category><category>CVE-2025-48019</category><category>CVE-2025-48020</category><category>CVE-2025-48021</category><category>CVE-2025-48022</category><category>CVE-2025-48023</category><category>Denial of Service</category><category>Arbitrary Code Execution</category><category>Critical Manufacturing</category><category>Energy</category><category>Food and Agriculture</category></item><item><title>Critical RCE Flaws in InSAT MasterSCADA BUK-TS Affect ICS</title><link>https://runtimerebel.com/blog/critical-rce-flaws-in-insat-masterscada-buk-ts-affect-ics</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-rce-flaws-in-insat-masterscada-buk-ts-affect-ics</guid><description>Two critical vulnerabilities (SQLi, OS Command Injection) in InSAT MasterSCADA BUK-TS lead to remote code execution, impacting critical infrastructure sectors globally.</description><pubDate>Wed, 25 Feb 2026 04:43:53 GMT</pubDate><category>CVE-2026-21410</category><category>CVE-2026-22553</category><category>InSAT MasterSCADA BUK TS</category><category>SQL Injection</category><category>OS Command Injection</category><category>RCE</category><category>ICS</category><category>SCADA</category><category>Critical Manufacturing</category><category>Energy</category><category>Water and Wastewater</category></item><item><title>Valmet DNA Engineering Web Tools Vulnerable to Path Traversal</title><link>https://runtimerebel.com/blog/valmet-dna-engineering-web-tools-vulnerable-to-path-traversal</link><guid isPermaLink="true">https://runtimerebel.com/blog/valmet-dna-engineering-web-tools-vulnerable-to-path-traversal</guid><description>Unauthenticated attackers can exploit CVE-2025-15577 in Valmet DNA Engineering Web Tools to gain arbitrary file read access across critical infrastructure.</description><pubDate>Tue, 24 Feb 2026 12:25:56 GMT</pubDate><category>CVE-2025-15577</category><category>Valmet</category><category>ICS</category><category>Path Traversal</category><category>CWE-22</category><category>Critical Manufacturing</category><category>Energy</category></item></channel></rss>