Daily OT Security News: July 09, 2026

Today’s threat landscape shows a mix of high-severity zero-days, undocumented backdoors, and OT/IoT-focused risk growth. Critical vendors are issuing emergency patches, while researchers highlight systemic weaknesses in edge devices, firmware, and legacy equipment that can disrupt industrial operations. Expect defenders to prioritize rapid remediation, asset inventory, and network segmentation to limit blast exposure across CPS/IoT environments.

Ubiquiti Patches Seven Critical UniFi Flaws, Including Maximum-Severity CVE

Ubiquiti has released emergency security updates addressing seven critical vulnerabilities across its UniFi product line — including UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS. The most severe flaw, CVE-2026-50746 (CVSS 10.0), is an improper access control vulnerability in UniFi Connect Application that could allow any network-adjacent attacker to execute arbitrary commands on the host without authentication. The patch bundle also covers six other CVEs with scores ranging from 9.0 to 9.9, including SQL injection, SSRF, and command injection across the UniFi ecosystem. The disclosure underscores the CPS/IoT risk posed by building automation platforms in connected environments and follows CISA’s Known Exploited Vulnerabilities additions from last month. Organizations should update to patched versions immediately to reduce exposure.

Read more: The Hacker News — July 8, 2026

Unpatched Backdoor in Tenda Firmware Grants Unauthenticated Admin Access

CERT/CC at Carnegie Mellon University has disclosed an undocumented backdoor (CVE-2026-11405) embedded in the login function of multiple Tenda router, switch, and networking device firmware versions. The flaw allows any attacker to bypass authentication entirely: the login mechanism validates only a hardcoded password stored in plaintext in the device configuration, while completely ignoring the supplied username. Successful exploitation grants full administrative control — enabling configuration changes, disabling security features, and potentially pivoting into connected OT/ICS networks. No patch has been released, and CERT/CC was unable to coordinate disclosure with the vendor. As an interim measure, administrators are advised to disable remote web management and change the default LAN IP address. In a related disclosure, CERT/CC also revealed an unpatched missing-authorization flaw (CVE-2026-13753) in HP Deskjet 2800 series printers that exposes Wi-Fi credentials and admin configuration data via unauthenticated API calls.

Read more: SecurityWeek — July 9, 2026

CVE-2026-38973: Out-of-Bounds Read in mruby/c VM Threatens IoT Edge Devices and Factory Sensors

A newly disclosed design weakness (CVE-2026-38973) in mruby/c through release 3.4.1 exposes a broad range of IoT edge devices and industrial sensors to memory-corruption attacks. The mruby/c virtual machine — designed to run on as little as 20 KB of RAM — is widely deployed in resource-constrained IoT hardware and Japanese factory automation equipment. The vulnerability resides in the builtin missing-method lookup inside mrbc_find_method(): when a method lookup fails, the VM processes bytecode execution pointers without explicit boundary checks, allowing malicious or malformed bytecode to trigger an out-of-bounds read. Exploitation could corrupt memory on embedded microcontrollers such as the ESP32, potentially leading to denial-of-service or arbitrary code execution on industrial sensor nodes. The fix requires pulling updated code from the official mruby/c GitHub repository and recompiling custom firmware.

Read more: Tenable / AntiHackingOnline — July 9, 2026

Trend Micro 2026 Cyber Risk Report: Mining and Utilities Enter Top OT Risk Sectors as Ransomware Groups Hit 3,300 Industrial Organizations

Trend Micro’s TrendAI 2026 Cyber Risk Report reveals that the mining sector has entered the top risk rankings for the first time, driven by rapid OT digitization that is expanding the attack surface faster than security controls can be established. Utilities also entered the top 10 for the first time, with the convergence of OT and IT networks exposing industrial control systems originally designed for reliability rather than security. The global Cyber Risk Index improved marginally from 38.5 to 35.8 year-over-year, yet every organization in the telemetry remains in the ‘medium risk’ band. Attackers are now prioritizing defense evasion as a first-stage objective — disabling antivirus software before attempting credential dumping or lateral movement. Separately, Dragos data cited in the report confirms that 119 ransomware groups impacted 3,300 industrial organizations in 2025, with manufacturing accounting for more than two-thirds of victims. Attackers increasingly encrypt Windows-based HMIs, historians, and engineering workstations to halt production without ever touching a PLC.

Read more: Trend Micro — July 8, 2026

Cisco RV-Series Routers Receive New CVEs for OS Command Injection via IPv6 Parameter

Two new CVE entries — CVE-2026-24699 and CVE-2026-24697 — were published to the NVD on July 8, 2026, documenting OS command injection vulnerabilities in end-of-life Cisco RV130, RV130W, and RV110W small-business routers. The flaws reside in the ‘rc’ binary: CVE-2026-24699 affects the sub_34984() function where the lan_ipv6_prefixlen configuration parameter is not properly sanitized, while CVE-2026-24697 targets the start_bonjour() function. An authenticated remote attacker can exploit either flaw to execute arbitrary OS commands with root privileges. These devices are commonly deployed as edge routers in small industrial and OT environments. Because Cisco has designated these models as unsupported and will not release patches, operators relying on them for network segmentation in ICS environments are urged to replace the devices or isolate them behind a compensating control immediately.

Read more: NIST NVD — July 8, 2026

Best regards,

The IoT Security Editorial Team

Share this