Sunday
2026-10-04Your source for daily security alerts from some of the best experts in the world.
Find the problems, secure your systems now!
Get these alerts in your inbox every morning. Subscribe
CONTENTS
MSRC Unclassified ( 48 )
MS-ISAC Cybersecurity Advisory ( 3 )
TLDR InfoSec
Hacker News ( 22 )
Cisco Talos ( 2 )
Bleeping Computer ( 15 )
CISA ( 7 )
Cisco Advisories ( 2 )
DataBreaches.net ( 10 )
Huntress Blog ( 4 )
CVEMon Intruder ( 10 )
Graham Cluley ( 3 )
Hacking Lab ( 2 )
Schneier on Security ( 4 )
Talos – Vulnerability Reports ( 2 )
Zero Day Initiative-Published
Microsoft-Core Infrastructure
MSRC Unclassified
10/02 TOC Mariner – zlib 1.2.11 through 1.3.2 Heap Buffer Overflow via Stale gzw…
10/03 TOC Mariner – QUIC STREAM Fragment Metadata DoS CVE-2026-54873
10/03 TOC Mariner – NULL Pointer Dereference in CMP Client Revocation Response H…
10/03 TOC Mariner – Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes D…
10/03 TOC Mariner – DTLS Retransmits Handshake Messages From a Stale Buffer Offs…
10/03 TOC Mariner – Excessive Memory Allocation in Relative CRLDP Processing CVE…
10/03 TOC Mariner – Timing Side-Channel in Scalar Multiplication for Non-NIST EC…
10/03 TOC Mariner – Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RIS…
10/03 TOC Mariner – Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC CVE…
10/03 TOC Mariner – QUIC Connection-Level Flow Control is Not Enforced for Strea…
10/03 TOC Mariner – QUIC Unvalidated Amplification Credit may be Over Accounted …
10/03 TOC Mariner – Timing Side-Channel in SM2 Signature Generation CVE-2026-776…
10/03 TOC Mariner – QUIC: Unbounded RETIRE_CONNECTION_ID Backlog CVE-2026-84784
10/03 TOC Mariner – Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handsh…
10/03 TOC Mariner – iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated…
10/03 TOC Mariner – Integer Overflow or Wraparound and Out-of-bounds Write in co…
10/03 TOC Mariner – Libsoup: libsoup: heap buffer overflow during outgoing perme…
10/03 TOC Mariner – Libsoup: libsoup: heap buffer overflow during websocket mess…
10/03 TOC Mariner – Libsoup: libsoup: heap buffer overflow during websocket rece…
10/03 TOC Mariner – Libsoup: libsoup: heap buffer overflow via uninitialized len…
10/03 TOC Mariner – Libsoup: libsoup: heap buffer overflow from websocket pong s…
10/03 TOC Mariner – Libsoup: libsoup: heap buffer overflow during websocket clie…
10/03 TOC Mariner – In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an a…
10/03 TOC Mariner – virtualenv: Command injection via –prompt in activate.bat (…
10/03 TOC Mariner – urllib3: HTTPS proxy TLS configuration may be ignored or ove…
10/03 TOC Mariner – Werkzeug safe_join() allows Windows special device names CVE…
10/03 TOC Mariner – piscina: Prototype-pollution gadget in ThreadPool.options al…
10/03 TOC Mariner – urllib3: HTTPResponse.stream()/read_chunked() buffers an unb…
10/03 TOC Mariner – virtualenv: Downloaded seed wheels (pip/setuptools) are not …
10/03 TOC Mariner – virtualenv bash and fish activation scripts execute commands…
10/03 TOC Mariner – Race condition in tempfile.TemporaryDirectory cleanup allows…
10/03 TOC Mariner – SSLContext.wrap_bio() missing validation of server_hostname …
10/03 TOC Mariner – Use-after-free of a server-side SSLContext when sni_callback…
10/03 TOC Mariner – U-Boot before 2026.10-rc5 Buffer Overflow via NFS READ Reply…
10/03 TOC Mariner – U-Boot before 2026.10-rc5 Buffer Overflow via NFS READLINK C…
10/03 TOC Mariner – U-Boot before 2026.10-rc3 Out-of-Bounds Write in IP Fragment…
10/03 TOC Mariner – U-Boot before 2026.10-rc4 Integer Overflow in SquashFS Direc…
10/03 TOC Mariner – U-Boot through 2026.10-rc5 Out-of-Bounds Write in BMP RLE8 D…
10/03 TOC Mariner – Out-of-bounds write in Das U-Boot CVE-2026-15390
10/03 TOC Mariner – RabbitMQ: Pre-auth AMQP 1.0 array32 zero-width element DoS C…
10/03 TOC Mariner – RabbitMQ: Stored XSS via TLS peer-certificate DN in stream-m…
10/03 TOC Mariner – RabbitMQ: Stored XSS via TLS peer-certificate DN in manageme…
10/03 TOC Mariner – RabbitMQ: Web-MQTT decompression bomb CVE-2026-67232
10/03 TOC Mariner – RabbitMQ: AMQP 0-9-1 body assembly never validates accumulat…
10/03 TOC Mariner – RabbitMQ: CORS * reflects Origin with Allow-Credentials CVE-…
10/03 TOC Mariner – Rpcbind: unbounded memory allocation in rpcbind statistics t…
10/03 TOC Mariner – Rpm: heap-based buffer overflow write in hex2binv() via a mi…
10/03 TOC Mariner – Rpm: rpm: integer overflow in iterreadarchivenext() leads to…
MS-ISAC Cybersecurity Advisory
10/02 TOC A Vulnerability in Fortinet FortiMail Could Allow for Arbitrary Code E…
10/01 TOC A Vulnerability in Kiteworks EPG (Email Security Gateway) Could Allow …A vulnerability has been discovered in Fortinet FortiMail that could allow for arbitrary code execution. Fortinet FortiMail is a secure email gateway that protects organizations from inbound threats including spam, phishing, malware, and business email compromise, while also preventing outbound data loss across physical, virtual, and cloud deployments. Successful exploitation of this vulnerability could allow an unauthenticated attacker to write arbitrary files to the underlying system, which could potentially lead to arbitrary code execution.
10/01 TOC A Vulnerability in WordPress Could Allow for Remote Code ExecutionA vulnerability has been discovered in Kiteworks EPG (Email Security Gateway) that could allow for arbitrary code execution. Kiteworks Email Protection Gateway (EPG) is a cloud-based security solution that automates end-to-end encryption, decryption, and policy enforcement for inbound and outbound enterprise emails. A combination of input-handling flaws in publicly reachable endpoints of the Kiteworks Email Protection Gateway may potentially allow an unauthenticated remote attacker to achieve arbitrary code execution. Successful exploitation of this vulnerability could allow for arbitrary code execution as root, which may lead to the complete compromise of the affected device.
A vulnerability has been discovered in WordPress that could allow arbitrary code on the web server. WordPress is a free, open-source content management system (CMS) that allows you to build and manage websites without needing to write code. Successful exploitation allows an unauthenticated attacker to manipulate the page-template resolution logic to execute local PHP files outside the active theme directory, potentially leading to Remote Code Execution (RCE) under specific conditions.
TLDR InfoSec
10/01 TOC FortiMail 0-day flaw , Zimbra email flaw , Signal Completes Chat Backu…
Hacker News
10/04 TOC ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Id…
A suspected member of the ShinyHunters digital extortion group, who goes by the online alias “Rey,” has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Rey, whose real name is Saif ‌al-Din Khader, is said to have been brought into custody on September 29, 2026, cooperating with the U.S. Federal Bureau of Investigation (FBI) and10/04 TOC China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM…
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a10/03 TOC MI5 Says Chinas MSS Funded Research Involving 100+ U.K.-Linked Academi…
The U.K.’s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing’s state security service. In a “Security Service Espionage Alert” issued on September 30, 2026, MI5 said the “primary purpose of the China General Technology Research Institute (CGTRI) ä¸å›½é€šç”¨æŠ€æœ¯ç ”究院 is to fund research that10/03 TOC Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy…
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. “In the10/03 TOC The State of Cybersecurity in 2026: Key Segments, Insights, and Innova…
Featuring: Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and internet-facing infrastructure, security is shifting toward continuous visibility, control, and the ability to respond to risk at scale. This report examines how core areas of10/02 TOC GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution…
A critical flaw in GitLab’s AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. The flaw10/02 TOC Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espion…
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster10/02 TOC Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kuberne…
Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below – CVE-2026-63688 (CVSS score: 10.0) – A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an10/02 TOC OpenAI Parts Ways With Three Safety Researchers Over Sensitive Informa…
OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. “We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information,” a spokesperson for the company was quoted as saying. “Our investigation confirmed that these10/02 TOC Why CISOs Struggle to Answer the Board’s Three Hardest Questions, and …
The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile them. Someone else is turning that spreadsheet into slides. Then a board member asks three questions: How secure is the organization, overall? What is10/02 TOC Android 17 Advanced Protection Locks Accessibility Services to Verifie…
Google has announced a new security measure that limits access to Android’s accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a10/02 TOC Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthent…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. “An improper10/01 TOC Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomwa…
Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site. Investigators identified him as KillSec’s suspected10/01 TOC ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspec…
This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful for years. That is the lesson running through the list. Attackers do not always need a brilliant new trick. They can10/01 TOC WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database…
Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the “SC_” markers present in the injected content. Sucuri has described the malware as a “self-healing mesh” that’s10/01 TOC How Financial Services Companies Can Modernize Their Software Supply C…
Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. Engineering explains what it would take to upgrade the platform where they live. Somebody prices out the regression testing. Somebody else raises the change-freeze calendar. The finding gets an exception, a compensating control, and a date10/01 TOC OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI As…
OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intelligence (AI) models. A “core cluster of the activity,” going back to the first week of July, has been attributed to individuals associated with Moonshot AI, a Chinese AI company based in Beijing. It did not cite any10/01 TOC CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with10/01 TOC Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guar…
Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. “It delivers frontier performance in complex workflows across real-world software engineering, enterprise knowledge work like legal and finance, and cybersecurity defense,” Koray Kavukcuoglu,10/01 TOC Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible…
Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working10/01 TOC Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurre…
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist. “Their investigation identified malicious activity involving third-party security products, including a zero-day vulnerability, and recovered a customized tool used by the attacker10/01 TOC MetaMask Security Incident Prompts Exit of Affected Ethereum Validator…
MetaMask on Thursday said it’s responding to what it described as an “ongoing security incident” impacting part of its infrastructure. “We are actively addressing and remediating the issue internally, in coordination with external partners and security advisors,” the software cryptocurrency wallet maker said. “At this time, we have identified no immediate threat to MetaMask wallets.” MetaMaskCisco Talos
10/01 TOC Give yourself room to be human
In this week’s edition, Amy reflects on the importance of prioritizing family and personal well-being over the pressure to remain constantly productive.10/01 TOC The Fine Art of Frustrating the Adversary
What really frustrates an adversary? Eight Cisco Talos researchers share practical ways to make their next move slower and riskier. From deception and behavioral detection to breaking attack dependencies and resisting manufactured urgency.Bleeping Computer
10/04 TOC Anthropic asks Claude users to share voice data for AI model training
Anthropic has started asking Claude users to voluntarily share their voice conversations to help train and improve its AI models. […]10/03 TOC Google Gemini could soon get full access to your Macs files, apps and …
Google’s Gemini could soon access any file on your macOS device, open apps, browse the web, and perform actions without asking for permission every time. […]10/03 TOC ShinyHunters hacker reportedly detained in Jordan, aiding FBI
A suspected ShinyHunters hacking group member known online as “Rey” has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. […]10/03 TOC Danish university DTU breach exposes data of up to 200,000 people
The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. […]10/02 TOC Frontline Education breach exposes school district employee data
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. […]10/02 TOC Warlock ransomware breach SharePoint in water, telecom operator attack…
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. […]10/02 TOC GitLab warns of critical RCE vulnerability in AI Gateway service
GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. […]10/02 TOC US sanctions Tren de Aragua gang members in ATM hacks crackdown
The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United States. […]10/02 TOC The EDR blind spot: 3 ways browser attacks evade endpoint telemetry
Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpoint telemetry and why browser-level controls can help close the gap. […]10/02 TOC Dell asks admins to patch max severity CSM flaws as soon as possible
Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments. […]10/02 TOC Microsofts X account hacked in crypto pump-and-dump scheme
On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token. […]10/01 TOC Fortinet warns of critical FortiMail flaw exploited in zero-day attack…
Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. […]10/01 TOC Autonomous AI agents tried to hack US, Canadian government websites
Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. […]10/01 TOC Microsoft says threat actors are ahead in the early AI race
Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. […]10/01 TOC Police dismantle KillSec ransomware gang allegedly led by 16-year-old
An international law enforcement operation dubbed “Operation KillSwitch” seized the KillSec ransomware gang’s data leak site and servers, led to three arrests, and identified a 16-year-old as the group’s alleged administrator. […]CISA
10/01 TOC CISA Malcolm
Summary
The following versions of CISA Malcolm are affected:
- Malcolm
CVSS Vendor Equipment Vulnerabilities v3 8.8 CISA CISA Malcolm Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’), Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’), Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’), Server-Side Request Forgery (SSRF), Authentication Bypass by Spoofing, Missing Authorization, Missing Authentication for Critical Function, Incorrect Authorization, Use of Default Credentials, Improper Certificate Validation, URL Redirection to Untrusted Site (‘Open Redirect’), Dependency on Vulnerable Third-Party Component, Use of Password Hash With Insufficient Computational Effort Background
- Critical Infrastructure Sectors: Energy, Information Technology, Water and Wastewater
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: United States
Vulnerabilities
CVE-2026-90443
A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes arbitrary script in the context of the affected application and can redirect the user’s browser to an arbitrary external site. Successful exploitation could allow an attacker to act with the compromised user’s session privileges within the application.
Affected Products
CISA Malcolm
Vendor:
CISAProduct Version:
CISA Malcolm Product Status:
known_affectedRemediations
Vendor fix
The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.Relevant CWE: CWE-79 Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 5.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N 4.0 5.3 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVE-2026-90444
A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file’s name, allowing an authenticated attacker to embed and execute arbitrary operating system commands with the privileges of that process. This allows an attacker to read and modify ingested log data, and could provide a foothold for further movement within the internal network.
Affected Products
CISA Malcolm
Vendor:
CISAProduct Version:
CISA Malcolm Product Status:
known_affectedRemediations
Vendor fix
The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-90445
An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attacker to craft an archive whose entries traverse outside the destination directory, causing the extraction process to write files to arbitrary locations with the privileges of that process. This could allow an attacker to inject fabricated records into the system’s stored data or tamper with application configuration.
Affected Products
CISA Malcolm
Vendor:
CISAProduct Version:
CISA Malcolm Product Status:
known_affectedRemediations
Vendor fix
The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.Relevant CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N 4.0 7.1 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-90446
An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents. This allows an authenticated attacker to substitute an arbitrary backend path, causing the application’s own elevated service credentials to be used against unintended internal endpoints. This could allow an attacker to enumerate or read internal configuration and administrative data from the backend data store that would otherwise be restricted.
Affected Products
CISA Malcolm
Vendor:
CISAProduct Version:
CISA Malcolm Product Status:
known_affectedRemediations
Vendor fix
The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.Relevant CWE: CWE-918 Server-Side Request Forgery (SSRF)
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 4.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N 4.0 5.3 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-90447
A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user in possession of a shared service credential can set this header to route around the primary role-based authorization check and reach the alternate path’s fixed, elevated role instead. This allows a low-privileged authenticated attacker who knows the shared credential to perform actions reserved for a higher-privileged role.
Affected Products
CISA Malcolm
Vendor:
CISAProduct Version:
CISA Malcolm Product Status:
known_affectedRemediations
Vendor fix
The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.Relevant CWE: CWE-290 Authentication Bypass by Spoofing
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N 4.0 7.1 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-90448
A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed. One such route accepts a request that creates or overwrites a stored record, including an attacker-chosen identifier, using the application’s own elevated backend credentials. This allows an authenticated user on a deployment intended to be read-only to forge or overwrite stored records that should not be modifiable in that deployment mode.
Affected Products
CISA Malcolm
Vendor:
CISAProduct Version:
CISA Malcolm Product Status:
known_affectedRemediations
Vendor fix
The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.Relevant CWE: CWE-862 Missing Authorization
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N 4.0 7.1 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-90449
When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway’s own authentication requirement first. All access control for this administrative interface, which manages the credential store used to gate every other service in the deployment, is delegated entirely to that third-party interface’s own login mechanism. Any authentication weakness in that bundled interface would compromise the credential store protecting the rest of the deployment.
Affected Products
CISA Malcolm
Vendor:
CISAProduct Version:
CISA Malcolm Product Status:
known_affectedRemediations
Vendor fix
The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.Relevant CWE: CWE-306 Missing Authentication for Critical Function
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N 4.0 6.9 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVE-2026-90450
The application’s role-authorization lookup defaults to granting access when a request handler’s name is not present in its table of role requirements, rather than defaulting to deny. Any request handler that is not explicitly registered in this table is reachable by any authenticated user regardless of their assigned role, and any newly added handler is fail-open by default until explicitly added to the table.
Affected Products
CISA Malcolm
Vendor:
CISAProduct Version:
CISA Malcolm Product Status:
known_affectedRemediations
Vendor fix
The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.Relevant CWE: CWE-863 Incorrect Authorization
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 4.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N 4.0 5.3 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-90451
An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration without running the setup routine that regenerates the value will use the known default, allowing an attacker aware of the default to forge valid authentication cookies for that component.
Affected Products
CISA Malcolm
Vendor:
CISAProduct Version:
CISA Malcolm Product Status:
known_affectedRemediations
Vendor fix
The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.Relevant CWE: CWE-1392 Use of Default Credentials
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 5.9 MEDIUM CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N 4.0 8.2 HIGH CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-90452
Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider’s server certificate. An attacker positioned on the network path between the proxy and the identity provider could impersonate the identity provider and issue forged authentication tokens accepted by the deployment.
Affected Products
CISA Malcolm
Vendor:
CISAProduct Version:
CISA Malcolm Product Status:
known_affectedRemediations
Vendor fix
The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.Mitigation
The fix for this issue introduces a KEYCLOAK_SSL_VERIFY configuration variable but does not enable certificate validation by default. In addition to updating to the latest version of Malcolm, affected users should explicitly set KEYCLOAK_SSL_VERIFY to enable certificate validation, particularly in deployments where the identity provider is not co-located on a fully trusted network segment.Relevant CWE: CWE-295 Improper Certificate Validation
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 5.3 MEDIUM CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N 4.0 6 MEDIUM CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-90453
A file-upload handler redirects the authenticated client’s browser to a URL taken directly from that same request’s Referer header, without validating it against the application’s own origin. This allows an authenticated attacker to craft a request that causes another user’s browser to be redirected to an arbitrary external destination after completing an upload.
Affected Products
CISA Malcolm
Vendor:
CISAProduct Version:
CISA Malcolm Product Status:
known_affectedRemediations
Vendor fix
The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.Relevant CWE: CWE-601 URL Redirection to Untrusted Site (‘Open Redirect’)
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 3.5 LOW CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N 4.0 5.1 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVE-2026-90454
A deployment mode intended to expose only read access to a bundled packet-analysis component’s interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tags attached to stored session records, and the proxy configuration otherwise permits the request method those routes use. This allows an authenticated user on a deployment intended to be read-only to add or remove tags on stored session records.
Affected Products
CISA Malcolm
Vendor:
CISAProduct Version:
CISA Malcolm Product Status:
known_affectedRemediations
Vendor fix
The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.Relevant CWE: CWE-862 Missing Authorization
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 4.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N 4.0 5.3 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVE-2026-90455
A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a single fixed, trusted vendor URL at initialization and does not process attacker-controlled input through the library, limiting practical exploitability of the reintroduced version in this context.
Affected Products
CISA Malcolm
Vendor:
CISAProduct Version:
CISA Malcolm Product Status:
known_affectedRemediations
Vendor fix
The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.Relevant CWE: CWE-1395 Dependency on Vulnerable Third-Party Component
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 3.7 LOW CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N 4.0 6.3 MEDIUM CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-90456
An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component’s administrative interface to anyone aware of the default value.
Affected Products
CISA Malcolm
Vendor:
CISAProduct Version:
CISA Malcolm Product Status:
known_affectedRemediations
Vendor fix
The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.Relevant CWE: CWE-1392 Use of Default Credentials
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 8.1 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 9.2 CRITICAL CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-90457
The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash is written with permissions allowing it to be read by any local user. This is inconsistent with a separate, stronger hashing algorithm used for the same password on another authentication path. A party able to read this file, including a local user or a party with access to a configuration backup, could feasibly recover the underlying password through offline computation, compromising the administrative credential across every path that accepts it.
Affected Products
CISA Malcolm
Vendor:
CISAProduct Version:
CISA Malcolm Product Status:
known_affectedRemediations
Vendor fix
The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.Relevant CWE: CWE-916 Use of Password Hash With Insufficient Computational Effort
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 6.2 MEDIUM CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 6.9 MEDIUM CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Acknowledgments
- CISA reported these vulnerabilities.
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.
- Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolating them from business networks.
- When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
CISA also recommends users take the following measures to protect themselves from social engineering attacks:
- Do not click web links or open attachments in unsolicited email messages.
- Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.
- Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.
Revision History
- Initial Release Date: 2026-09-11
Date Revision Summary 2026-09-11 1 Initial Publication 2026-10-01 2 Update A – Including self-reference to Web version
Legal Notice and Terms of Use
10/01 TOC Meari IoT Cloud Platform OpenAPI Service
10/01 TOC Johnson Controls EasyIO Neo Series EC and CW ControllersSummary
Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data without proper authorization.
The following versions of Meari IoT Cloud Platform OpenAPI Service are affected:
- IoT Cloud Platform OpenAPI Service vers:all/* (CVE-2026-101104, CVE-2026-96613)
CVSS Vendor Equipment Vulnerabilities v3 7.7 Meari Meari IoT Cloud Platform OpenAPI Service Missing Authorization Background
- Critical Infrastructure Sectors: Commercial Facilities, Information Technology
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: China
Vulnerabilities
CVE-2026-101104
The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors, without verifying ownership or permissions.
Affected Products
Meari IoT Cloud Platform OpenAPI Service
Vendor:
MeariProduct Version:
Meari IoT Cloud Platform OpenAPI Service: vers:all/*Product Status:
known_affectedRemediations
No fix planned
Meari did not respond to CISA’s coordination attempts. IoT Cloud Platform OpenAPI users are advised to contact Meari for support https://www.meari.com/en/downLoadCenter.Relevant CWE: CWE-862 Missing Authorization
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 7.7 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N 4.0 6.3 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N CVE-2026-96613
The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shadow of any device by specifying its device ID. This vulnerability exposes sensitive information, such as device credentials, owner details, network data, and telemetry, without verifying any relationship between the requester and the target device.
Affected Products
Meari IoT Cloud Platform OpenAPI Service
Vendor:
MeariProduct Version:
Meari IoT Cloud Platform OpenAPI Service: vers:all/*Product Status:
known_affectedRemediations
No fix planned
Meari did not respond to CISA’s coordination attempts. IoT Cloud Platform OpenAPI users are advised to contact Meari for support https://www.meari.com/en/downLoadCenter.Relevant CWE: CWE-862 Missing Authorization
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N 4.0 7.1 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Acknowledgments
- Gabriel Adams reported these vulnerabilities to CISA
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.
- Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolating them from business networks.
- When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.
Revision History
- Initial Release Date: 2026-10-01
Date Revision Summary 2026-10-01 1 Initial Publication
Legal Notice and Terms of Use
10/01 TOC Johnson Controls EasyIO Neo Series EC and CW ControllersSummary
Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data.
The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected:
- EasyIO Neo Series EC Controllers V3.3b62 (CVE-2026-64893)
- EasyIO Neo Series EC Controllers V3.3b63 (CVE-2026-64893)
- EasyIO Neo Series CW Controllers V3.3b24 (CVE-2026-64893)
- EasyIO Neo Series CW Controllers V3.3b25 (CVE-2026-64893)
CVSS Vendor Equipment Vulnerabilities v3 5.4 Johnson Controls Johnson Controls EasyIO Neo Series EC and CW Controllers Cleartext Transmission of Sensitive Information Background
- Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: Ireland
Vulnerabilities
CVE-2026-64893
Johnson Controls is aware of a vulnerability in EasyIO Neo which may allow an attacker to intercept and read sensitive information, including credentials and session data, transmitted in cleartext over the network. Successful exploitation could result in technical or operational impact. EasyIO Neo is a programmable building automation edge controller used to manage and automate HVAC, lighting, and energy systems in commercial buildings through a web-based interface.
Affected Products
Johnson Controls EasyIO Neo Series EC and CW Controllers
Vendor:
Johnson ControlsProduct Version:
Johnson Controls EasyIO Neo Series EC Controllers: V3.3b62, Johnson Controls EasyIO Neo Series EC Controllers: V3.3b63, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b24, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b25Product Status:
known_affectedRemediations
Mitigation
Johnson Controls released fixed versions for EasyIO Neo Series EC and CW Controllers. Users should upgrade to the fixed version or later as soon as operationally feasible. HTTP communication has been disabled by default in the latest version. The fix is available in EC firmware V3.3b64 andCW firmware V3.3b26. Contact your Johnson Controls representative or visitthe Johnson Controls Trust Center.Mitigation
Before applying updates in production ICS/OT environments, users should review operational impact, backup relevant configurations, test updates in a non-production environment where feasible, and follow applicable change-management and safety procedures.Mitigation
If immediate update is not possible, Johnson Controls recommends the following mitigations:Â
- Enable and enforce HTTPS/TLS for all web-based management access to the device.Â
- Disable HTTP access entirely.Â
- Place devices on an isolated, segmented network behind a firewall to limit exposure of management interfaces.Â
- Use a VPN when accessing devices remotely to encrypt all traffic in transit.Â
- Monitor network traffic for unencrypted sensitive data leaving the management interface.Â
- Restrict network access to management interfaces using access control lists (ACLs) to only trusted hosts. Refer to and follow all steps in the product hardening guide or the JCI universal hardening guide found here: https://www.johnsoncontrols.com/trust-center/cybersecurity/resources .Â
These mitigations reduce risk but may not fully remediate the vulnerability. Users should update to the fixed versions when operationally feasible.
ÂMitigation
Users should review logs, network telemetry, device events, and security monitoring tools for activity involving EasyIO NEO versions EC and CW. Relevant detection information may include: Unencrypted HTTP traffic to or from the device management interface on port 80. Network captures showing cleartext credentials or session tokens in HTTP requests. Unexpected devices or IP addresses accessing the web management console. ARP spoofing or other man-in-the-middle indicators on the local network segment. Unauthorized configuration changes that may indicate credential interception.Mitigation
The recommendations provided within Johnson Controls Hardening Guide should always be applied to minimize security risk. Visit the Johnson Controls Trust Center Cybersecurity website to access the latest Hardening Guidelines and cybersecurity best practices – https://www.johnsoncontrols.com/trust-center/cybersecurity/resources.
https://www.johnsoncontrols.com/trust-center/cybersecurity/resourcesMitigation
For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-30.Â
https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisoriesRelevant CWE: CWE-319 Cleartext Transmission of Sensitive Information
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 5.4 MEDIUM CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N 4.0 5.9 MEDIUM CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
Acknowledgments
- Gabriele Gardois reported this vulnerability to Johnson Controls
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability has a high attack complexity.
Revision History
- Initial Release Date: 2026-10-01
Date Revision Summary 2026-10-01 1 Initial Republication of Johnson Controls Product Security Advisory JCI-PSA-2026-30
Legal Notice and Terms of Use
10/01 TOC ABB Protection and Control IED Manager PCM600Summary
Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system.
The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected:
- EasyIO Neo Series EC Controllers V3.3b63 (CVE-2026-64892)
- EasyIO Neo Series EC Controllers V3.3b62 (CVE-2026-64892)
- EasyIO Neo Series CW Controllers V3.3b25 (CVE-2026-64892)
- EasyIO Neo Series CW Controllers V3.3b24 (CVE-2026-64892)
CVSS Vendor Equipment Vulnerabilities v3 3.5 Johnson Controls Johnson Controls EasyIO Neo Series EC and CW Controllers Exposure of Sensitive Information to an Unauthorized Actor Background
- Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: Ireland
Vulnerabilities
CVE-2026-64892
Johnson Controls is aware of a vulnerability in EasyIO Neo Series EC and CW Controllers relating to an attacker gaining access to sensitive information that could be used to conduct further attacks against the system. The EC and CW are programmable edge controllers designed for building automation and control systems, used to manage and automate various building functions including HVAC, lighting, and energy management, supporting open protocols such as BACnet and Modbus for adaptable system connections.
Affected Products
Johnson Controls EasyIO Neo Series EC and CW Controllers
Vendor:
Johnson ControlsProduct Version:
Johnson Controls EasyIO Neo Series EC Controllers: V3.3b63, Johnson Controls EasyIO Neo Series EC Controllers: V3.3b62, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b25, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b24Product Status:
known_affectedRemediations
Mitigation
Johnson Controls released fixed versions for EasyIO Neo Series EC and CW Controllers. Users should upgrade to the fixed version or later as soon as operationally feasible. The fix is available in EC firmware V3.3b64 and CW firmware V3.3b26. Contact your Johnson Controls representative or authorized EasyIO distributor.Mitigation
Before applying updates in production ICS/OT environments, users should review operational impact, backup relevant configurations, test updates in a non-production environment where feasible, and follow applicable change-management and safety procedures.Mitigation
If immediate update is not possible, Johnson Controls recommends the following mitigations:Â
- Implement physical access controls to prevent unauthorized personnel from reaching device debug ports.
- Monitor network traffic to and from affected devices for unusual or unauthorized access attempts.Â
- Apply the principle of least privilege to all accounts and services that interact with the affected devices.Â
- Where possible, apply firmware updates that disable debug interfaces or require authentication before granting debug access.Â
- Implement intrusion detection/prevention systems to monitor for exploitation attempts.Â
- Refer to and follow all steps in the product hardening guide or the JCI universal hardening guide found here: https://www.johnsoncontrols.com/trust-center/cybersecurity/resources .Â
These mitigations reduce risk but may not fully remediate the vulnerability. Users should update to the fixed versions when operationally feasible.
ÂMitigation
For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-20.Â
https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisoriesRelevant CWE: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 3.5 LOW CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:L 4.0 4.8 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
Acknowledgments
- Gabriele Gardois reported this vulnerability to Johnson Controls
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
The recommendations provided within Johnson Controls Hardening Guide should always be applied to minimize security risk. Visit the Johnson Controls Trust Center Cybersecurity website to access the latest Hardening Guidelines and cybersecurity best practices – https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories .
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.
Revision History
- Initial Release Date: 2026-10-01
Date Revision Summary 2026-10-01 1 Initial Republication of Johnson Controls Product Security Advisory JCI-PSA-2026-20
Legal Notice and Terms of Use
10/01 TOC Monta monta.appSummary
Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files.
The following versions of ABB Protection and Control IED Manager PCM600 are affected:
- Protection and Control IED Manager PCM600 <=2.14 (CVE-2026-15952, CVE-2026-15953)
CVSS Vendor Equipment Vulnerabilities v3 6.4 ABB ABB Protection and Control IED Manager PCM600 Incorrect Permission Assignment for Critical Resource, Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) Background
- Critical Infrastructure Sectors: Energy
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: Switzerland
Vulnerabilities
CVE-2026-15952
A vulnerability exists in the Scheduler Service installed with PCM600. The service executes under the LocalSystem account while permissions are granted to standard PCM600 users through membership in the local users group. An attacker with local access and valid user credentials may exploit this vulnerability to elevate privileges and obtain control of the affected host.
Affected Products
ABB Protection and Control IED Manager PCM600
Vendor:
ABBProduct Version:
ABB Protection and Control IED Manager PCM600: <=2.14Product Status:
known_affectedRemediations
Mitigation
ABB recommends the following workaround. Although this workaround does not correct the underlying vulnerability, it reduces the risk of privilege escalation.Mitigation
Configure the appropriate ABBPCMSchedulerService instance to run using the same Windows account that is used to operate PCM600:
- Open Services.msc.
- Locate the ABBPCMSchedulerService corresponding to the installed PCM600 version.
- Open Properties and select the Log On tab.
- The service should be configured to log on with the same Windows user account that is used for the PCM600 application.
- Ensure that this account has the required “Log on as a service” privilege.
Mitigation
When authentication is enabled for the IED, the Scheduler tool must be used with the same Windows account configured as the Scheduler Service logon account.Mitigation
For installations using IED security certificates, the PCM600 setting Always trust IED security certifcates must be enabled only when PCM600-to-IED communication takes place in a secure and trusted environment.Mitigation
For more information, see ABB security advisory 2NGA003170 and 2NGA003179.Relevant CWE: CWE-732 Incorrect Permission Assignment for Critical Resource
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 6.4 MEDIUM CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H 4.0 7.1 HIGH CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-15953
A vulnerability exists in the processing of PCM600 project archives files. Insufficient validation of archive entry paths may permit path traversal during extraction, potentially allowing files to be written to loca tions outside the intended extraction directory.
Affected Products
ABB Protection and Control IED Manager PCM600
Vendor:
ABBProduct Version:
ABB Protection and Control IED Manager PCM600: <=2.14Product Status:
known_affectedRemediations
Mitigation
Configure the appropriate ABBPCMSchedulerService instance to run using the same Windows account that is used to operate PCM600:
- Open Services.msc.
- Locate the ABBPCMSchedulerService corresponding to the installed PCM600 version.
- Open Properties and select the Log On tab.
- The service should be configured to log on with the same Windows user account that is used for the PCM600 application.
- Ensure that this account has the required “Log on as a service” privilege.
Mitigation
When authentication is enabled for the IED, the Scheduler tool must be used with the same Windows account configured as the Scheduler Service logon account.Mitigation
For installations using IED security certificates, the PCM600 setting Always trust IED security certifcates must be enabled only when PCM600-to-IED communication takes place in a secure and trusted environment.Mitigation
For more information, see ABB security advisory 2NGA003170 and 2NGA003179.Relevant CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 5 MEDIUM CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N 4.0 5.6 MEDIUM CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
Acknowledgments
- Abhinav Agarwal reported these vulnerabilities to CISA.
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.
- Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolating them from business networks.
- When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
CISA also recommends users take the following measures to protect themselves from social engineering attacks:
- Do not click web links or open attachments in unsolicited email messages.
- Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.
- Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.
Revision History
- Initial Release Date: 2026-10-01
Date Revision Summary 2026-10-01 1 Initial Publication
Legal Notice and Terms of Use
10/01 TOC Armatura LLC Armatura OneSummary
Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.
The following versions of Monta monta.app are affected:
- monta.app vers:all/* (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474)
CVSS Vendor Equipment Vulnerabilities v3 9.4 Monta Monta monta.app Missing Authentication for Critical Function, Improper Restriction of Excessive Authentication Attempts, Insufficient Session Expiration, Insufficiently Protected Credentials Background
- Critical Infrastructure Sectors: Energy, Transportation Systems
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: Netherlands
Vulnerabilities
CVE-2026-95102
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.
Affected Products
Monta monta.app
Vendor:
MontaProduct Version:
Monta monta.app: vers:all/*Product Status:
known_affectedRemediations
Mitigation
Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) and encourage operators to enable it.Mitigation
Monta states that they have implemented rate limiting and automated connection throttling at the WebSocket layer. Connections exhibiting abusive patterns, including rapid reconnection, ID brute-forcing behavior, or excessive command volume, are automatically identified and blocked.Mitigation
Monta states that their platform handles duplicate connection attempts per the OCPP specification, where a new authenticated connection supersedes an existing session for the same station ID.Relevant CWE: CWE-306 Missing Authentication for Critical Function
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 9.4 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L 4.0 9.3 CRITICAL https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N CVE-2026-97363
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.
Affected Products
Monta monta.app
Vendor:
MontaProduct Version:
Monta monta.app: vers:all/*Product Status:
known_affectedRemediations
Mitigation
Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) and encourage operators to enable it.Mitigation
Monta states that they have implemented rate limiting and automated connection throttling at the WebSocket layer. Connections exhibiting abusive patterns, including rapid reconnection, ID brute-forcing behavior, or excessive command volume, are automatically identified and blocked.Mitigation
Monta states that their platform handles duplicate connection attempts per the OCPP specification, where a new authenticated connection supersedes an existing session for the same station ID.Relevant CWE: CWE-307 Improper Restriction of Excessive Authentication Attempts
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 8.7 HIGH https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-97212
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.
Affected Products
Monta monta.app
Vendor:
MontaProduct Version:
Monta monta.app: vers:all/*Product Status:
known_affectedRemediations
Mitigation
Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) and encourage operators to enable it.Mitigation
Monta states that they have implemented rate limiting and automated connection throttling at the WebSocket layer. Connections exhibiting abusive patterns, including rapid reconnection, ID brute-forcing behavior, or excessive command volume, are automatically identified and blocked.Mitigation
Monta states that their platform handles duplicate connection attempts per the OCPP specification, where a new authenticated connection supersedes an existing session for the same station ID.Relevant CWE: CWE-613 Insufficient Session Expiration
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 7.3 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L 4.0 6.9 MEDIUM https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVE-2026-93474
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Affected Products
Monta monta.app
Vendor:
MontaProduct Version:
Monta monta.app: vers:all/*Product Status:
known_affectedRemediations
Mitigation
Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) and encourage operators to enable it.Mitigation
Monta states that they have implemented rate limiting and automated connection throttling at the WebSocket layer. Connections exhibiting abusive patterns, including rapid reconnection, ID brute-forcing behavior, or excessive command volume, are automatically identified and blocked.Mitigation
Monta states that their platform handles duplicate connection attempts per the OCPP specification, where a new authenticated connection supersedes an existing session for the same station ID.Relevant CWE: CWE-522 Insufficiently Protected Credentials
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N 4.0 6.9 MEDIUM https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Acknowledgments
- An anonymous researcher reported these vulnerabilities to CISA.
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.
- Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.
- Locate control system networks and remote devices behind firewalls and isolating them from business networks.
- When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.
Revision History
- Initial Release Date: 2026-10-01
Date Revision Summary 2026-10-01 1 Initial Publication
Legal Notice and Terms of Use
Summary
Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system.
The following versions of Armatura LLC Armatura One are affected:
- Armatura One <4.7.2 (CVE-2023-46604, CVE-2026-94591, CVE-2026-94592, CVE-2026-94593, CVE-2026-94594)
- Armatura One (USA) <4.6.1 (CVE-2023-46604, CVE-2026-94591, CVE-2026-94592, CVE-2026-94593, CVE-2026-94594)
CVSS Vendor Equipment Vulnerabilities v3 9.8 Armatura LLC Armatura LLC Armatura One Deserialization of Untrusted Data, Use of Hard-coded Cryptographic Key, Use of Hard-coded Credentials, Insertion of Sensitive Information into Log File Background
- Critical Infrastructure Sectors: Communications, Critical Manufacturing, Energy, Transportation Systems
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: United States
Vulnerabilities
CVE-2023-46604
Armatura One embeds Apache ActiveMQ, exposing its OpenWire protocol listener on the network by default. This embedded version is affected by CVE-2023-46604, a deserialization flaw in the OpenWire marshaller that allows an unauthenticated network attacker to trigger deserialization of an arbitrary object graph before authentication is checked. This can result in arbitrary code execution with the highest level of privilege on the host operating system.
Affected Products
Armatura LLC Armatura One
Vendor:
Armatura LLCProduct Version:
Armatura LLC Armatura One: <4.7.2, Armatura LLC Armatura One (USA): <4.6.1Product Status:
known_affectedRemediations
Vendor fix
Armatura LLC Armatura One vers:all/<4.7.2: Armatura LLC has released Armatura One V4.7.2, which resolves this issue. Users should upgrade from V4.7.1 or earlier to V4.7.2.Vendor fix
Armatura LLC Armatura One (USA) vers:all/<4.6.1: Armatura LLC has released Armatura One V4.6.1_USA, which resolves this issue. Users of the USA release line should upgrade from V4.3.1_USA or earlier to V4.6.1_USA.Vendor fix
Armatura LLC recommends contacting official technical support for guidance on obtaining and applying the upgrade.Mitigation
For more information see the associated CISA security advisory ICSA-26-274-01 JSON.
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-274-01.jsonRelevant CWE: CWE-502 Deserialization of Untrusted Data
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-94591
Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across every installation. An attacker with a copy of the installation package can recover this key and initialization vector, and can then decrypt the stored credentials of any specific installation to which the attacker separately obtains the encrypted configuration file.
Affected Products
Armatura LLC Armatura One
Vendor:
Armatura LLCProduct Version:
Armatura LLC Armatura One: <4.7.2, Armatura LLC Armatura One (USA): <4.6.1Product Status:
known_affectedRemediations
Vendor fix
Armatura LLC Armatura One vers:all/<4.7.2: Armatura LLC has released Armatura One V4.7.2, which resolves this issue. Users should upgrade from V4.7.1 or earlier to V4.7.2.Vendor fix
Armatura LLC Armatura One (USA) vers:all/<4.6.1: Armatura LLC has released Armatura One V4.6.1_USA, which resolves this issue. Users of the USA release line should upgrade from V4.3.1_USA or earlier to V4.6.1_USA.Vendor fix
Armatura LLC recommends contacting official technical support for guidance on obtaining and applying the upgrade.Mitigation
For more information see the associated CISA security advisory ICSA-26-274-01 JSON.
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-274-01.jsonRelevant CWE: CWE-321 Use of Hard-coded Cryptographic Key
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 8.4 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 8.6 HIGH CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-94592
Armatura One’s database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where it has not been changed.
Affected Products
Armatura LLC Armatura One
Vendor:
Armatura LLCProduct Version:
Armatura LLC Armatura One: <4.7.2, Armatura LLC Armatura One (USA): <4.6.1Product Status:
known_affectedRemediations
Vendor fix
Armatura LLC Armatura One vers:all/<4.7.2: Armatura LLC has released Armatura One V4.7.2, which resolves this issue. Users should upgrade from V4.7.1 or earlier to V4.7.2.Vendor fix
Armatura LLC Armatura One (USA) vers:all/<4.6.1: Armatura LLC has released Armatura One V4.6.1_USA, which resolves this issue. Users of the USA release line should upgrade from V4.3.1_USA or earlier to V4.6.1_USA.Vendor fix
Armatura LLC recommends contacting official technical support for guidance on obtaining and applying the upgrade.Mitigation
For more information see the associated CISA security advisory ICSA-26-274-01 JSON.
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-274-01.jsonRelevant CWE: CWE-798 Use of Hard-coded Credentials
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 8.4 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 8.6 HIGH CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-94593
Armatura One’s backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access to the server operating system is available.
Affected Products
Armatura LLC Armatura One
Vendor:
Armatura LLCProduct Version:
Armatura LLC Armatura One: <4.7.2, Armatura LLC Armatura One (USA): <4.6.1Product Status:
known_affectedRemediations
Vendor fix
Armatura LLC Armatura One vers:all/<4.7.2: Armatura LLC has released Armatura One V4.7.2, which resolves this issue. Users should upgrade from V4.7.1 or earlier to V4.7.2.Vendor fix
Armatura LLC Armatura One (USA) vers:all/<4.6.1: Armatura LLC has released Armatura One V4.6.1_USA, which resolves this issue. Users of the USA release line should upgrade from V4.3.1_USA or earlier to V4.6.1_USA.Vendor fix
Armatura LLC recommends contacting official technical support for guidance on obtaining and applying the upgrade.Mitigation
For more information see the associated CISA security advisory ICSA-26-274-01 JSON.
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-274-01.jsonRelevant CWE: CWE-532 Insertion of Sensitive Information into Log File
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.5 HIGH CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-94594
Armatura One’s message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the logged credential.
Affected Products
Armatura LLC Armatura One
Vendor:
Armatura LLCProduct Version:
Armatura LLC Armatura One: <4.7.2, Armatura LLC Armatura One (USA): <4.6.1Product Status:
known_affectedRemediations
Vendor fix
Armatura LLC Armatura One vers:all/<4.7.2: Armatura LLC has released Armatura One V4.7.2, which resolves this issue. Users should upgrade from V4.7.1 or earlier to V4.7.2.Vendor fix
Armatura LLC Armatura One (USA) vers:all/<4.6.1: Armatura LLC has released Armatura One V4.6.1_USA, which resolves this issue. Users of the USA release line should upgrade from V4.3.1_USA or earlier to V4.6.1_USA.Vendor fix
Armatura LLC recommends contacting official technical support for guidance on obtaining and applying the upgrade.Mitigation
For more information see the associated CISA security advisory ICSA-26-274-01 JSON.
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-274-01.jsonRelevant CWE: CWE-532 Insertion of Sensitive Information into Log File
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 4 MEDIUM CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N 4.0 5.1 MEDIUM CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Acknowledgments
- Andrew Capobianco of RewCon.co reported these vulnerabilities to CISA
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.
- Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolating them from business networks.
- When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
CISA also recommends users take the following measures to protect themselves from social engineering attacks:
- Do not click web links or open attachments in unsolicited email messages.
- Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.
- Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.
CISA is not aware of exploitation specifically targeting Armatura One in relation to these vulnerabilities. CVE-2023-46604 is listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog and has been used in ransomware campaigns against other Apache ActiveMQ deployments.
Revision History
- Initial Release Date: 2026-10-01
Date Revision Summary 2026-10-01 1 Initial Publication
Legal Notice and Terms of Use
Cisco Advisories
10/02 TOC Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
10/02 TOC Cisco IOS XE Software Security Hardening Release: August 2026A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.
This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Live Protect Shield
Cisco has released a Live Protect shield for CVE-2026-76504 to provide temporary security coverage to allow time for software upgrade planning, including preserving any information that customers may require for governance or compliance purposes.
This shield offers only temporary partial protection. The only way to remediate this vulnerability is to upgrade to the first fixed software release, as noted in the Fixed Releases section of this advisory. Cisco strongly recommends prioritizing system upgrades and scheduling them as soon as possible to ensure remediation.
Before deploying the shield, read the following information:
Side Effects/Limitation: If this shield is applied
A legitimate user with URI encoding might not be able to login to SDWAN Manager.
- For more information about Live Protect for Cisco Catalyst SD-WAN, see https://www.cisco.com/c/en/us/td/docs/routers/sdwan/26x-later/network-monitoring/network-monitoring-guide/live-protect-for-cisco-catalyst-sd-wan.html.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU
Security Impact Rating: Critical
CVE: CVE-2026-76504
As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. Â
These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID).
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ
Security Impact Rating: Critical
CVE: CVE-2026-20267,CVE-2026-20268,CVE-2026-20269,CVE-2026-20270,CVE-2026-20271,CVE-2026-20272,CVE-2026-20273DataBreaches.net
10/03 TOC Italys Data Protection Authority fines IQVIA 7 million over data prote…
The following is a machine translation of a press release by Italy’s privacy guarantor: Healthcare data: The Privacy Guarantor fines IQVIA 7 million euros. The data of one million patients of 800 family doctors are not anonymous. The Italian Data Protection Authority has fined IQVIA Solutions Italy Srl €7 million. The company, part of a…10/03 TOC ShinyHunters hacker Rey, allegedly involved in FBI data theft, detaine…
Jana Winter, Raphael Satter, and A.J. Vicens report: A key member of the ShinyHunters hacking group, ‌which claims to have stolen data on every FBI employee, was detained this week in Jordan, three people familiar with the matter told Reuters. Two of ​the sources said he was cooperating with the FBI to identify ​his fellow…10/03 TOC DHS readies major cyber contract
Justin Doubleday reports: The Department of Homeland Security is preparing this year to award a major cloud, cybersecurity and network services contract aimed at further centralizing the management of IT services across DHS. In a notice posted to Sam.gov last month, DHS laid out the notional timeline for award of the Network, Cloud and Cybersecurity…10/03 TOC OpenAI faces California DOJ subpoena amid growing cybersecurity incide…
IAPP reports: Regulator inquiries into major AI companies’ cybersecurity practices are ramping up. A day after reports surfaced about the likely escalation of a U.S. Federal Trade Commission probe into OpenAI and other developers, California Attorney General Rob Bonta advanced his office’s ongoing OpenAI investigation. Bonta announced the company was served an investigative subpoena to…10/03 TOC Fed employee repeatedly removed sensitive files, watchdog finds
Matt Bracken reports: A Federal Reserve Board staffer mishandled sensitive classified files and triggered hundreds of data loss prevention alerts leading up to their retirement, the agency’s inspector general revealed in a new report. The security issues with the employee were uncovered by the watchdog during its audit of the Fed’s offboarding process, which began…10/03 TOC Over 543,000 valid credentials exposed in public GitHub repositories
Bill Toulas reports: More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform’s security measures to prevent accidental leaks of sensitive data. Data pulled from scanning 224 million repositories and more than 58 billion files show that the median time a unique credential remained publicly accessible was 784…10/03 TOC Senate passes bipartisan bill to bolster hospital cybersecurity
Naomi Diaz reports: The Senate passed the bipartisan Health Care Cybersecurity and Resilience Act by unanimous consent. The legislation aims to help healthcare providers strengthen their cybersecurity defenses and protect patient information, according to an Oct. 1 news release from the Senate Committee on Health, Education, Labor and Pensions. Sens. Bill Cassidy, MD, R-La., Maggie…10/03 TOC Medical records giant Epic pauses product development to fix security …
Zack Whittaker reports: Epic, the software technology giant that makes the widely used MyChart software for accessing patients’ medical data, has paused most of its product development as the company works to protect its software and systems from cyberattacks. Judy Faulkner, the founder and chief executive of Epic, told Modern Healthcare last month that the…10/03 TOC Metamask discloses security incident affecting its infrastructure
Sergiu Gatlan reports: On Thursday, cryptocurrency wallet provider MetaMask has disclosed an ongoing infrastructure security incident affecting some of its infrastructure. The company is working to address the issue internally, with help from external partners and security advisors, and says there is “no immediate threat to MetaMask wallets.†“As a precautionary measure, we are proactively…10/02 TOC City of Vicksburg, Mississippi, shuts down computers after cyberattack…
Joseph Topping reports: The City of Vicksburg, Mississippi, has shut down its computer systems after a ransomware attack, potentially delaying in-person utility payments while emergency response and utility service continue. Mayor Willis Thompson told The Vicksburg Post that the city had disconnected its internet operations. “We had to bring our internet operations down, just for…Huntress Blog
10/02 TOC The First 24 Hours: What Happens When Ransomware Lands
Nazar Tymoshyk from UnderDefense shares his thoughts on what ransomware attacks look like during the all-important opening hours.10/02 TOC Companies Push AI Use But Skip Training and Official Policy
New data shows that many workers have employer-sponsored AI accounts and are encouraged to use them, yet 43% haven’t been trained in AI.10/01 TOC New Huntress View for Security Incident Investigations
See how the Huntress SOC runs security incident investigations from first signal to final resolution, including the ones closed as benign.10/01 TOC Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses
The Huntress Tragic Quadrant ranks the cyber threats hitting businesses most, from RMM abuse to AiTM, ClickFix, using real SOC data.CVEMon Intruder
10/04 TOC CVE-2026-102489
Currently trending CVE – Hype Score: 13 – Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.10/04 TOC CVE-2026-102490
Currently trending CVE – Hype Score: 13 – All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.10/04 TOC CVE-2026-40281
Currently trending CVE – Hype Score: 12 – Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control characters but leaves metadata values unsanitized. A newline character in a metadata value splits the ExifTool stdin line …10/04 TOC CVE-2026-100520
Currently trending CVE – Hype Score: 12 – Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory traversal sequences in the path parameter to …10/04 TOC CVE-2026-96940
Currently trending CVE – Hype Score: 9 – Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.10/04 TOC CVE-2026-61500
Currently trending CVE – Hype Score: 8 – Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, …10/04 TOC CVE-2026-88772
Currently trending CVE – Hype Score: 5 – Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or …10/04 TOC CVE-2026-88771
Currently trending CVE – Hype Score: 5 – Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading …10/04 TOC CVE-2024-58388
Currently trending CVE – Hype Score: 2 – Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply …10/04 TOC CVE-2026-1731
Currently trending CVE – Hype Score: 1 – BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating …Graham Cluley
10/03 TOC N0n ransomware: what you need to know
N0n is a newly-emerged cyber extortion gang. The group was first spotted in the middle of September 2026, and within days it had published on its dark web leak site details of what it claimed to be around a dozen victims. Since then, the tally has continued to grow. Read more in my article on the Fortra blog.10/01 TOC FBI tells ShinyHunters members to turn themselves in, after arrest of …
The FBI has a very simple message for the ShinyHunters gang: give yourselves up. On Tuesday, FBI cyber division assistant director Brett Leatherman released a video, thanking the Dutch police for arresting a 24-year-old man they believe to be a member of the group, and and who is separately suspected of attempting to arrange two murders. Read more in my article on the Hot for Security blog.10/01 TOC ShinyHunters suspect arrested, and is now investigated over alleged mu…
An alleged key figure in the ShinyHunters cybercrime group has been arrested in the Netherlands, and – in a sinister twist – the 24-year-old suspect is also being investigated for attempting to arrange two murders. Read more in my article on the Hot for Security blog.Hacking Lab
11/30 TOC PatchIsland: Orchestration of LLM Agents for Continuous Vulnerability …
10/31 TOC MTEscape: Bypassing Asynchronous Kernel MTE via Conventional Memory Co…
Schneier on Security
10/02 TOC Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing…
10/02 TOC Unidentified Flock Cameras in FloridaThe EU is recommending import controls to combat unregulated squid fishing in the Southwest Atlantic. I’m not optimistic.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
10/02 TOC How American Political Campaigns Are Using AIand What Theyre Spending …St. Lucie County in Florida discovered (alt link) a dozen Flock cameras whose ownership it can’t identify, and that the county government had not permitted.
I am reminded of the decade-old story of StingRay cell phone surveillance devices in Washington, DC, whose operators were also unknown.
My guess is that in the StingRay case, the devices were operated by foreign actors. This Flock case is more likely some local government entity that didn’t bother getting approval. Were I a foreign actor, I would rather hack the existing Flock network—like Israel …
10/01 TOC Connected Cars Are a Surveillance PlatformThis essay was written with Nathan E. Sanders, and originally appeared in The Guardian.
New campaign finance disclosure data shines a light on which US political campaigns are using AI tools and how much they are spending on them.
Candidates’, parties’ and committees’ spending reveals that AI is fast becoming an essential tool of politics. The candidates themselves are quiet about how they are using the technology in their own campaigns. It’s a sensitive issue that we have been tracking closely since we started writing our book, Rewiring Democracy…
Researchers at Northeastern University, in collaboration with Consumer Reports, evaluated how much modern cars spy in their drivers:
The new Northeastern study shows, for the first time, data flowing among the vehicles, the vehicle apps you download when you buy your car, and third-party companies, documenting exactly what kind of data gets siphoned from our vehicles and which companies are receiving that information.
Basically, your car’s manufacturer has you under constant surveillance, and they use that data against you.
The companies on the receiving end of your data, our investigation has found, include car insurers and lenders that are partners in “telematics data exchanges,†which compile driving data on millions of drivers, thousands of data brokers that create personalized risk scores, companies selling infotainment and WiFi hotspot products, and even local and state government agencies working on planning, traffic, and safety initiatives…
Talos – Vulnerability Reports
10/03 TOC Microsoft Windows Cloud Files Mini Filter Driver CldiStreamCompleteReq…
10/03 TOC Microsoft Windows Cloud Files Mini Filter Driver CldiStreamPrepareRequ…
Zero Day Initiative-Published
10/01 TOC ZDI-26-751: Microsoft Windows dxgkrnl Time-Of-Check Time-Of-Use Local …
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-50375.Microsoft-Core Infrastructure
10/02 TOC From Domain Lists to Decisions: Scaling WHOIS Threat Intelligence with…
The real problem isn’t WHOIS. It’s what WHOIS costs you at scale.
Ask any SOC analyst whether WHOIS data is useful and they’ll say yes without hesitation. Registrant emails, creation dates, registrars, and nameservers are among the most durable pivots in domain-based threat intelligence — the threads that tie a single phishing domain back to an entire adversary campaign.
Now ask them how often they actually pull WHOIS for every suspicious domain in an alert. The honest answer is: not always. And that gap is the real problem.
Here’s why. When a campaign surfaces two hundred lookalike domains, manual WHOIS becomes a losing game:
- It’s slow. One-domain-at-a-time portal lookups don’t finish before the incident clock runs out.
- It’s inconsistent. Different analysts capture different fields, so the data can’t be compared or correlated.
- It’s un-auditable. Screenshots and copy-paste don’t hold up in an investigation review months later.
- It loses the pattern. By the time you’ve checked twenty domains by hand, the shared registrant email that connected them has scrolled off the screen.
The outcome of all this friction is the part that should worry a security leader: analysts quietly stop enriching, or enrich only a sample. The pivot that would have collapsed twenty alerts into one campaign never happens. The newly registered domain that should have been escalated gets triaged as routine. The intelligence exists — the process just can’t reach it fast enough.
The outcome we’re actually after
Reframe the goal. This isn’t a project to “run WHOIS.” It’s a project to produce a specific set of outcomes:
- Every suspicious domain gets enriched — not a hand-picked sample.
- Enrichment is consistent and structured, so patterns across domains become visible instead of buried.
- The output is audit-ready — defensible in an investigation and reusable in a report.
- The whole thing is fast enough to happen inside the incident, not the day after.
Get-MDTIWhois.ps1 exists to deliver exactly those outcomes. It reads a list of domains, calls Microsoft Defender Threat Intelligence (MDTI) through Microsoft Graph, and returns both a normalized CSV for immediate triage and the raw JSON for deep investigation — in one pass, read-only, with nothing changed in your environment.
What changes for the analyst
The clearest way to see the value is the before-and-after.
Before: An alert fires on a suspected phishing campaign with two hundred candidate domains. The analyst opens a portal, checks a handful of domains, eyeballs a few registrant fields, and makes a judgment call on incomplete data. Correlation is mental and fragile. Twenty related alerts stay twenty separate alerts.
After: The analyst drops the domains into a text file, runs one command, and gets a spreadsheet where all two hundred are enriched with the same fields. Sorting by registrant email instantly reveals that forty of them share one address, one budget registrar, and creation dates in the same week. Twenty alerts become one campaign. One judgment call becomes one defensible conclusion.
That’s the outcome: not “we ran WHOIS,” but “we saw the campaign the manual process would have missed.”
Where the value shows up
This translates into concrete wins across several SOC workflows:
- Faster campaign triage. Shared registrant emails and nameservers collapse dozens of alerts into a single adversary-infrastructure story — directly reducing mean-time-to-respond.
- Better newly-registered-domain hunting. Enrich domains from DNS or proxy logs, sort by registration date, and surface the freshly registered domains that are disproportionately malicious — before they’re clicked.
- Enrichment that feeds the platform. The normalized CSV drops straight into a Sentinel watchlist, or the same Graph call can be wrapped in a Logic App / Azure Function playbook to auto-enrich domain entities the moment an incident is created.
- Reusable intelligence. Registrant and nameserver pivots become custom indicators and hunting queries — value that compounds over time instead of being thrown away after each investigation.
Why this approach, specifically
There are other ways to get WHOIS. A few reasons this approach earns its place in a modern, Defender-portal-centric SOC:
- It uses first-party intelligence. MDTI is Microsoft’s own threat-intelligence graph, queried natively through Microsoft Graph — no third-party data broker, no separate contract, no data leaving your Microsoft trust boundary.
- It’s read-only by design. The script cannot modify Sentinel, Defender, tenant settings, or domain records. Enrichment tooling should never be able to change the environment it observes — and this one can’t.
- It’s built to survive real-world APIs. Throttling (HTTP 429) and transient 5xx errors are retried with backoff; permanent misses (404) aren’t retried needlessly; a single failed domain never aborts the run. You always get a complete, dependable result set.
- It handles secrets the way you’d want. Client secrets come from an environment variable or a secure prompt — never hard-coded, never committed to source control.
The engineering exists to protect the outcome: a complete, consistent, trustworthy enrichment set every single time, even when the input list is messy or the API is having a bad day.
The output is built for decisions, not just data
Two files, two jobs:
- The normalized CSV is the decision surface. One row per domain, every registrant/registrar/date/nameserver field an analyst pivots on — sortable, filterable, watchlist-ready. This is where twenty alerts become one campaign.
- The raw JSON is the safety net. Full API fidelity per domain, preserved for the audit trail and for the registrar-specific edge cases the normalized view can’t anticipate.
Together they answer both questions a SOC actually asks: “What do I do right now?” (CSV) and “Can I stand behind it later?” (JSON).
What it takes to get there
The barrier to entry is low:
- An Entra ID app registration with the Graph application permission ThreatIntelligence.Read.All (admin-consented), on a tenant with MDTI API access.
- A text file of domains, one per line.
- One command:
$env:MDTI_CLIENT_SECRET = “
“
.\Get-MDTIWhois.ps1 `
   -TenantId “” `
   -ClientId “” `
   -InputTxt “.\domains.txt”Under the covers it authenticates with a client-credentials grant, normalizes and de-duplicates the input, calls GET /security/threatIntelligence/hosts/{domain}/whois per domain, and writes both outputs. Minutes of setup; a repeatable capability afterward.
Use it responsibly
The project is provided as-is, for educational and demonstration purposes, and is not intended for production use without independent review, validation, and monitoring. Keep in mind:
- A 404 means MDTI has no current WHOIS record for that host — not that the domain is safe.
- WHOIS fields vary by registrar — always retain the raw JSON for anything you’ll act on.
- WHOIS can contain personal data — validate your storage and sharing obligations before distributing enrichment output.
- Never commit secrets — use the environment-variable or secure-prompt path.
The bottom line
The value here isn’t that WHOIS is difficult. It’s that the friction of doing WHOIS well, for everything, quietly erodes detection quality — analysts under time pressure enrich less, correlate by memory, and miss the campaign hiding in plain sight.
Get-MDTIWhois.ps1 removes that friction. It turns a flat list of domains into structured, audit-ready intelligence in a single read-only pass, so the pivot that reveals the adversary’s infrastructure actually happens — inside the incident, not after it. That’s the outcome worth automating.
Disclaimer
This article and the referenced tooling are provided “as-is,†for educational and demonstration purposes only, without warranties of any kind, express or implied. They are not intended for production, safety-critical, or regulated use without independent review, testing, validation, and appropriate safeguards. The views expressed are the author’s own and do not necessarily represent those of any employer or of Microsoft. You are solely responsible for how you deploy, modify, or adapt this tooling, and for ensuring compliance with all applicable laws, regulations, licensing terms, privacy obligations, and organizational security policies.
Â
Source: MDTI-WHOIS in the Microsoft Security Operations Toolkit. Provided as-is for educational purposes; test in a controlled environment before production use.
Content on this page is collected from remote sources by IPWorX but is not created by IPWorX. The contents belong to the creators and should be considered theirs for all legal purposes, we have no editorial control or responsibility over them. IPWorX does not represent or endorse the accuracy or reliability of any opinion, statement, or other information provided by any third party.
This page contains links to third-party websites. These links are provided solely for your convenience. IPWorX does not control, maintain, or endorse the content, accuracy, or reliability of any third-party resources, and you access them at your own risk.
Scripts and tools to help manage your network found, managed and
happily shared with documentation on usage at the IP WORk eXchange.
https://www.IPWorX.com
