Daily OT Security News: August 15, 2026

This briefing covers five current IoT, OT, ICS, and critical‑infrastructure cybersecurity developments.

CISA Advisory Flags Critical Command Injection in Haiwell IoT Cloud HMI Gateway

CISA advisory ICSA-26-225-02 covers CVE-2026-19188 in Haiwell IoT Cloud HMI Gateway 3.40.1.12. The Net Check cmdPing Socket.io event does not properly sanitize input, which can allow arbitrary OS command execution with root privileges.

Source: CISA

CISA Warns of Metasys Building-Automation Vulnerability

CISA advisory ICSA-26-225-14 covers CVE-2026-34491 in Johnson Controls Metasys versions 12 through 15. The issue can let a low-privilege authenticated user use a crafted URL to insert persistent malicious payloads, creating risks including session compromise and unauthorized building-operations control.

Source: CISA

Siemens Desigo Controllers Face BACnet Denial-of-Service Risk

CISA advisory ICSA-26-225-08 covers CVE-2026-59693 in Siemens Desigo DXR and PXC building-automation controllers. A network-adjacent unauthenticated attacker can send a malformed BACnet packet that crashes a controller and requires manual reboot, potentially affecting HVAC, access control, or other building systems.

Source: CISA

Critical Johnson Controls Airwall Flaw Can Enable File Manipulation

CISA advisory ICSA-26-225-03 covers CVE-2026-34492, an external control of file name or path issue in Johnson Controls Airwall versions earlier than 4.1. Tenable lists the vulnerability as published on August 14, 2026 and reports a CVSS 3.1 score of 9.8.

Source: CISA

CSIS Assesses Broad Cyber Campaign Targeting U.S. Water Utilities

CSIS reports that a recent campaign affected at least 12 states and 100 municipalities. The analysis says attribution to Iran has not been confirmed by the U.S. government, notes indicators pointing to Iran, and describes the activity as opportunistic disruption exploiting default passwords, internet-connected OT, and absent authentication.

Source: CSIS

Organizations should verify affected assets, prioritize vendor guidance, and preserve operational continuity.

Share this