Daily OT Security News: July 19, 2026

Welcome to today’s OT/ICS/IoT cybersecurity news briefing for July 19, 2026. We cover critical developments affecting operational technology and enterprise security, including ransomware disruptions, zero-day vulnerabilities, and detailed attack analyses impacting vital infrastructure and industrial systems.

Coca-Cola Halts Fairlife US Production After Ransomware Attack on OT Systems

Coca-Cola has confirmed a ransomware attack on its Fairlife dairy subsidiary that compromised production-related OT systems, resulting in a temporary halt of all US dairy operations. Canadian facilities remain unaffected. Law enforcement agencies have been notified, and cybersecurity experts are assisting with incident response and recovery efforts.

Source: Fairlife Pauses US Production After Cyberattack Breached Milk / ABC News

CISA Adds Fortinet FortiSandbox and Microsoft SharePoint Critical Flaws to Known Exploited Vulnerabilities Catalog

The US Cybersecurity and Infrastructure Security Agency (CISA) has added three critical vulnerabilities to its Known Exploited Vulnerabilities catalog, affecting Fortinet FortiSandbox and Microsoft SharePoint. These include OS command injection bugs in FortiSandbox and an unauthenticated deserialization RCE in SharePoint, all with CVSS scores of 9.8. Federal agencies must remediate by July 19, 2026, due to confirmed active exploitation.

Source: U.S. CISA Adds Fortinet FortiSandbox and Microsoft SharePoint Flaws / Security Affairs

CISA ICS Advisory: Hitachi Energy PROMOD V Energy Planning Platform Harbors Multiple Vulnerabilities

CISA released advisory ICSA-26-188-02 detailing multiple vulnerabilities in Hitachi Energy’s PROMOD V platform, widely used by electric utilities. The flaws include path traversal, authentication weaknesses, and insecure direct object references, posing risks due to PROMOD V’s integration with energy management systems. Hitachi Energy has issued patches, and CISA recommends limiting network access as a temporary mitigation.

Source: Hitachi Energy PROMOD V ICSA-26-188-02 Supply Chain Advisory / OT Security Wire

Critical Unauthenticated RCE Vulnerability Disclosed in GeoVision Physical Security IoT Device Firmware

Researchers disclosed CVE-2026-12486, a critical unauthenticated OS command injection vulnerability in GeoVision GV-I/O Box 4E firmware version 2.09. This physical security device integrates alarms and sensor I/O with surveillance systems. Attackers with network access can execute arbitrary commands without authentication, and no vendor patch is currently available. The EPSS score of 74.6% suggests high exploitation probability.

Source: CVE-2026-12486 Multiple OS Command Injection Vulnerabilities / TechJack Solutions

Researchers Detail Full Enterprise Compromise Chain in July 2026 Microsoft SharePoint Attack Campaign

Cybersecurity firm Resecurity published an in-depth analysis of a July 2026 SharePoint attack campaign chaining six critical vulnerabilities to achieve unauthenticated remote code execution and full Active Directory compromise. Several CVEs involved in the attack are confirmed actively exploited and listed in CISA’s KEV catalog. Attackers deploy persistent web shells and steal IIS machine keys to maintain long-term access within compromised enterprises.

Source: From Web Request to Domain Compromise: Understanding the July 2026 SharePoint Attacks / Resecurity

These developments underscore the persistent and evolving threats targeting OT and enterprise environments. Continuous vigilance, timely patching, and comprehensive incident response remain essential for securing critical infrastructure and operational systems.

Share this