Daily OT Security News: August 15, 2026

Daily OT Security News: August 15, 2026

This briefing reviews five OT, ICS, and connected-device security developments surfaced in the past day. Several underlying CISA advisories were released on August 13; the summaries below distinguish those advisory dates from the more recent coverage and database updates that brought them to attention.

Haiwell IoT Cloud HMI Gateway: CVSS 10 Root-Level Command Injection Requires Immediate Patching

CISA’s advisory for CVE-2026-19188 identifies a critical OS command-injection vulnerability in Haiwell IoT Cloud HMI Gateway version 3.40.1.12. The Net Check function can pass unsanitized input to the operating system, allowing arbitrary commands to run with root privileges. Because the product is relevant to energy, critical manufacturing, and water and wastewater environments, asset owners should identify exposed deployments, restrict control-system network access, and evaluate Haiwell’s Scada-v3.50.1.19 patch through an OT-safe change process. CISA reported no known public exploitation at publication.

Source: CISA ICS Advisory ICSA-26-225-02

ANDRITZ HIPASE-250 and 250 SCALA: Four Flaws Expose Credentials, Data, and Workstations

CISA disclosed four vulnerabilities affecting ANDRITZ HIPASE-250 and 250 SCALA versions through 7.20. The issues include recoverable password storage, unauthenticated access to live values and configuration, unauthenticated logging changes that could weaken audit visibility, and a fixed VNC password used during workstation provisioning. The findings matter for energy-sector environments because a combination of accessible process data, weak credentials, and impaired logging can erode operational visibility. ANDRITZ recommends updating to HIPASE-250 V8.15.00; CISA reported no known public exploitation.

Source: CISA ICS Advisory ICSA-26-225-05

AVEVA Enterprise SCADA: Authenticated Deserialization Flaw Can Lead to Code Execution

A current CISA advisory details CVE-2025-7639, a high-severity insecure-deserialization vulnerability affecting listed AVEVA Enterprise SCADA and HMI releases. An authenticated user holding the “DNA Authority – Operator” privilege could tamper with serialized data and potentially trigger code execution under the “DNA Apps” security group. The attack has an authenticated, high-complexity precondition, but affected organizations should still review operator permissions, apply AVEVA’s supported updates, and complete the vendor’s move from Binary Formatter to JSON serialization. CISA reported no known public exploitation.

Source: CISA ICS Advisory ICSA-26-225-01

Johnson Controls Metasys: Persistent XSS Risks Administrator Sessions in Building Automation

Recent coverage highlighted CISA advisory ICSA-26-225-14 for CVE-2026-34491, a CVSS 8.0 persistent cross-site-scripting issue in Johnson Controls Metasys versions 12 through 15. A low-privilege user can use a crafted URL to inject a persistent payload that runs in another user’s session, including an administrator’s session, potentially enabling session hijacking or unauthorized access. Building-automation operators should validate applicable updates, reduce internet exposure, keep control networks segmented from business networks, and use appropriately secured remote-access paths. CISA reported no known public exploitation.

Source: CISA ICS Advisory ICSA-26-225-14

Johnson Controls OpenBlue Airwall: Update the IoT and Building-Automation Protection Layer

ISSSource reported two vulnerabilities affecting Johnson Controls OpenBlue Airwall versions through 4.0.4: a hard-coded key issue tracked as CVE-2026-64887 and an arbitrary file-read issue tracked as CVE-2026-34492. Airwall is designed to protect critical-infrastructure, IoT, and building-automation assets, making weaknesses in the protective layer notable even when they are not directly exploitable remotely. The report states that no exploit is currently known and recommends updating to version 4.1.0 or later, together with the vendor’s hardening guidance.

Source: ISSSource

Operational note: Prioritize remediation according to asset criticality, connectivity, compensating controls, and safety/change-management requirements. Test patches and configuration changes before production deployment where operationally feasible.

Share this