Daily OT Security News: August 28, 2026

Today’s briefing focuses on a new batch of CISA advisories released August 27, 2026, covering vulnerabilities across industrial fuel-management platforms, autonomous mobile-robot fleet systems, grid and utility communications testing equipment, CNC controls, and a connected device management interface.

Xiiaozet LK100W Vulnerabilities Enable Potential Device Compromise

CISA published advisory ICSA-26-239-01 detailing multiple critical vulnerabilities in Xiiaozet LK100W versions earlier than 2.1.240, including authenticated OS command injection and authentication bypass issues. While these flaws could allow complete device compromise, CISA reports no known public exploitation targeting them and recommends updating to version 2.1.240.

Source: CISA ICS Advisory ICSA-26-239-01

All-Line Equipment Fuel-Boss Systems Face Remote Code Execution Risks

The Fuel-Boss V1 Standard, Portal, Master/Slave, and Backflush Systems using PHP 7.1.5 are affected by vulnerabilities enabling argument injection and remote code execution, as described in CISA advisory ICSA-26-239-02. Fixes exist for Standard and Portal versions, but no patch is planned for Backflush; CISA advises restricting network exposure for unfixed systems.

Source: CISA ICS Advisory ICSA-26-239-02

Rockwell Automation OTTO Fleet Manager Password Hash Weakness Updated

CISA republished advisory ICSA-26-239-03 addressing an insufficient bcrypt work-factor in OTTO Fleet Manager versions 2.36.2 and earlier that lowers the cost of offline brute-force attacks on stored password hashes. This issue is not remotely exploitable, and no public exploitation is known; Rockwell fixed it in version 2.36.3 and provides guidance on encrypted backups.

Source: CISA ICS Advisory ICSA-26-239-03

Applied Systems Engineering ASE2000 V2 Communications Test Set Certificate Validation Flaw

CISA advisory ICSA-26-239-04 reports an XML external entity vulnerability and improper certificate validation in ASE2000 versions 2.25 through 2.37, with the certificate issue specifically affecting 2.35 to 2.37. The flaw could allow an attacker to impersonate a trusted peer and intercept communications; upgrading to version 2.38 mitigates these risks. No known public exploitation has been reported.

Source: CISA ICS Advisory ICSA-26-239-04

Mitsubishi Electric CNC Series Advisory Updated and Republished

CISA updated and republished advisory ICSA-26-078-05 regarding an improper-input-validation vulnerability (CVE-2025-2399) in multiple Mitsubishi Electric CNC models that could cause denial of service via specially crafted packets. This is not a new CVE disclosure but a republication of a prior advisory. Fixed versions are available, and CISA recommends network controls for systems that cannot be immediately patched.

Source: CISA ICS Advisory ICSA-26-078-05

Practitioners should prioritize asset-aware, risk-managed remediation strategies to maintain resilient OT operations.

Share this