Signal is active with 1 mentions in latest observed window
Immediate actions
Patch affected systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), RTUM85 RTU Base (All versions < V26.10). The affected application contains denial-of-service (DoS) vulnerability. The remote operation mode is susceptible to a resource exhaustion condition when subjected to a high volume of requests. Sending multiple requests can exhaust resources, preventing parameterization and requiring a reset or reboot to restore functionality.
⚠️ Vulnerabilidades en productos Siemens
❗ CVE-2026-27664
❗ CVE-2026-27663
➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-siemens-4/ https://t.co/jZCIqOCGpF
Post summary
A brief notice lists two Siemens product vulnerabilities (CVE‑2026‑27664 and CVE‑2026‑27663) with links for additional information, but no further details are provided.
⚠️ Vulnerabilidades en productos WatchGuard
❗ CVE-2026-27664
❗ CVE-2026-27663
➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-watchguard-3/ https://t.co/I4LBCNdK6J
Post summary
The post lists two WatchGuard CVEs and links to a site for further details but offers no additional technical information, PoC, exploit, or patch details.
⚠️ **Vulnerability Alert:** Multiple ICS Vulnerabilities: Hitachi Energy Ellipse JasperReports RCE; Siemens SICAM 8 DoS (XML parsing/resource exhaustion); Yokogawa CENTUM VP hard-coded PROG password
📅 **Timeline:** Disclosure: 2025-09-16, Patch: 2026-03-30
🆔 **CVE-2025-10492** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 59.43%
🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories
📂 **Affected Versions:** Hitachi Ellipse ≤9.0.50
🔧 **Fixed Versions:** Vendor guidance via Hitachi PSIRT/CISA (no fixed version listed)
🫨 **Attack Vectors:**
- Java deserialization over network (remote code execution)
📝 **Summary:**
A deserialization flaw in the JasperReports component used by Hitachi Ellipse allows remote code execution, risking full system compromise. Exploitation could disrupt ICS operations, impact safety, and enable lateral movement.
📈 **Impact Scope:** ICS/OT systems — remote code execution, potential operational disruption and safety risks.
🛡️ **Recommended Actions:**
- Inventory Ellipse instances, isolate affected hosts, and follow Hitachi PSIRT/CISA guidance immediately
- Block/validate untrusted deserialization inputs and apply vendor/third‑party library mitigations
🆔 **CVE-2026-27663** | 📊 CVSS: 6.5 (MEDIUM 🟡) | 📈 EPSS: 4.82%
🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories
📂 **Affected Versions:** Siemens CPCI85 <26.10, RTUM85 <26.10, SICORE <26.10.0
🔧 **Fixed Versions:** Siemens update ≥26.10 (SICORE 26.10.0+)
🫨 **Attack Vectors:**
- High-volume request/resource exhaustion in remote operation mode (DoS)
📝 **Summary:**
A resource-exhaustion vulnerability in Siemens SICAM 8 can cause service degradation or reboot via high-volume requests, impacting availability of control systems. Operational disruption risk is significant for exposed or poorly segmented deployments.
📈 **Impact Scope:** ICS/OT systems — denial-of-service affecting availability and operational continuity.
🛡️ **Recommended Actions:**
- Apply Siemens security updates (≥26.10 / SICORE 26.10.0+) and isolate affected devices from untrusted networks
- Implement rate-limiting, request validation, and monitoring for anomalous traffic volumes
🆔 **CVE-2026-27664** | 📊 CVSS: 7.5 (HIGH 🟠) | 📈 EPSS: 15.74%
🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories
📂 **Affected Versions:** Siemens CPCI85 <26.10, RTUM85 <26.10, SICORE <26.10.0
🔧 **Fixed Versions:** Siemens update ≥26.10 (SICORE 26.10.0+)
🫨 **Attack Vectors:**
- Malformed XML over network leading to out-of-bounds write and service crash (DoS)
📝 **Summary:**
A crafted XML input can trigger an out‑of‑bounds write in SICAM 8, causing service crashes and denial-of-service. This threatens availability of monitoring/control functions and may require manual recovery.
📈 **Impact Scope:** ICS/OT systems — denial-of-service and potential operational safety impacts.
🛡️ **Recommended Actions:**
- Patch to Siemens 26.10+ (SICORE 26.10.0+) and restrict XML/protocol exposure via network controls
- Add input validation, monitoring for crashes, and automated restart/detection safeguards
🆔 **CVE-2025-7741** | 📊 CVSS: 2.1 (LOW 🟢) | 📈 EPSS: 4.39%
🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories
📂 **Affected Versions:** CENTUM VP R5.01.00–<R5.04.20, R6.01.00–<R6.12.00, R7.01.00
🔧 **Fixed Versions:** CENTUM VP R7.01.10, use Windows Authentication for R5/R6
🫨 **Attack Vectors:**
- Hard-coded PROG account password allowing authentication with HIS screen/local access
📝 **Summary:**
A hard-coded PROG password in CENTUM VP permits authentication if an attacker can access HIS screens, enabling unauthorized actions and privilege misuse. Risk increases where PROG permissions were elevated or HIS access is insufficiently restricted.
📈 **Impact Scope:** ICS/OT systems — unauthorized access, privilege misuse, and potential operational impact.
🛡️ **Recommended Actions:**
- Patch to R7.01.10 or switch affected R5/R6 branches to Windows Authentication; restrict HIS screen access
- Rotate credentials where possible, enforce least privilege, and monitor PROG account usage
🪢 **Related Resources:**
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-03
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-01
🏷 **Tags:** #Cybersecurity#ICS#OT
Post summary
The advisory announces several critical industrial control system vulnerabilities, outlines specific technical details and impact, and provides patch guidance, but no proof of concept or active exploitation is reported.
⚠️ **Vulnerability Alert:** Multiple ICS Vulnerabilities: Hitachi Ellipse JasperReports RCE; Siemens SICAM 8 DoS/Out-of-bounds; Yokogawa CENTUM VP Hard-coded Password
📅 **Timeline:** Disclosure: unknown, Patch: unknown
🆔 **CVE-2025-10492** | 📊 CVSS: 9.8 (Critical 🔴) | 📈 EPSS: 59.43%
🆔 **CVE-2026-27663** | 📊 CVSS: 6.5 (Medium 🟡) | 📈 EPSS: 4.82%
🆔 **CVE-2026-27664** | 📊 CVSS: 7.5 (High 🟠) | 📈 EPSS: 15.74%
🆔 **CVE-2025-7741** | 📊 CVSS: 4.0 (Low/Medium 🟢) | 📈 EPSS: 4.39%
🛠️ **Exploit Maturity:** Not Available
📂 **Affected Versions:** Hitachi Ellipse ≤9.0.50, Siemens SICAM 8 family (CPCI85/RTUM85/SICORE) <26.10, Yokogawa CENTUM VP R5.x affected (>=R5.01.00 <R5.04.20), Yokogawa CENTUM VP R6.x affected (>=R6.01.00 <R6.12.00), Yokogawa CENTUM VP vR7.01.00
🔧 **Fixed Versions:** Yokogawa: CENTUM VP R7.01.10 (patch) or switch R5/R6 to Windows Auth, Siemens: apply latest SICAM 8 security updates, Hitachi: update Jaspersoft per PSIRT
🫨 **Attack Vectors:**
- Java deserialization via Jaspersoft/JasperReports → remote code execution
- High-volume remote requests causing resource exhaustion (DoS)
- Malformed XML parsing → out-of-bounds write and service crash
- Hard-coded PROG account password usable from HIS screen access (local/admin interface)
📝 **Summary:**
Multiple high-impact ICS flaws affect Hitachi, Siemens and Yokogawa products: CVE-2025-10492 enables full RCE via a vulnerable Jaspersoft component in Hitachi Ellipse; CVE-2026-27663/27664 allow DoS and crashes in Siemens SICAM 8 components; CVE-2025-7741 is a hard-coded PROG password in Yokogawa CENTUM VP that can enable local privilege misuse. These issues threaten operational availability and can lead to full system compromise in critical manufacturing and energy environments.
📈 **Impact Scope:** Industrial control systems in critical manufacturing, energy, and related sectors; impacts include full RCE, denial-of-service/resource exhaustion and crashes, and local privilege misuse via hard-coded account.
🛡️ **Recommended Actions:**
- Apply vendor-provided updates/patches immediately and follow PSIRT advisories
- Isolate ICS/HMI networks, minimize exposure of management interfaces, and implement network-level filtering/throttling
- Hitachi: remediate/upgrade vulnerable Jaspersoft per PSIRT; Siemens: deploy latest SICAM 8 security updates; Yokogawa: apply R7.01.10 patch or switch R5/R6 to Windows Authentication Mode and review PROG permissions
- Monitor for abnormal requests, crashes, and unauthorized logins; test patches in lab before wide deployment
🪢 **Related Resources:**
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-03
- https://www.cve.org/CVERecord?id=CVE-2025-10492
🏷 **Tags:** #Cybersecurity#ICS#OTsecurity (Remove commas and spaces between tags)
Post summary
This advisory details several critical Industrial Control System vulnerabilities, provides explicit patch information and remediation steps, and highlights the technical impact of each CVE, but it does not discuss exploitation or PoC availability.
CVE-2026-27663 A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), RTUM85 RTU Base (All versions < V26.10). The affected applicat… https://www.cve.org/CVERecord?id=CVE-2026-27663
Post summary
The text announces the identification of CVE‑2026‑27663 affecting older versions of CPCI85 and RTUM85, and provides a link to the official CVE record, with no exploit detail or mitigation information.