Daily OT Security News: July 19, 2026
Brief summaries of the top operational technology, IoT, and cyber-physical security developments affecting industrial and critical infrastructure environments from the last 24 hours.
CISA adds FortiSandbox and SharePoint flaws to KEV; federal remediation ordered
The U.S. CISA added three critical vulnerabilities to its Known Exploited Vulnerabilities catalog, including two Fortinet FortiSandbox command-injection flaws (CVE-2026-25089, CVE-2026-39808) and a Microsoft SharePoint unauthenticated deserialization RCE (CVE-2026-58644), all rated CVSS 9.8 and tied to active exploitation. CISA’s inclusion and a BOD 22-01 federal remediation deadline emphasize immediate patching, compensating controls, and network segmentation for environments where these products protect OT/ICS networks. OT practitioners should prioritize remediation or isolation of affected appliances and validate detection/response playbooks for exploitation indicators.
Source: Security Affairs
Critical GeoVision GV-I/O Box firmware flaw permits unauthenticated RCE
CVE-2026-12486 (CVSS 9.1) is an unauthenticated OS command injection in GeoVision GV-I/O Box 4E firmware 2.09, a device used for alarm, access control and sensor I/O in video surveillance deployments; related CVEs suggest multiple injection points in the same firmware library. No vendor patch is available, creating an immediate risk that attackers could pivot from perimeter video systems into corporate or OT networks and manipulate physical access or safety systems. Operators should isolate affected devices from internet-facing and flat networks, apply strict ACLs, and treat these devices as high-priority for compensating controls and replacement planning.
Source: TechJack Solutions
SharePoint attack chain analysis shows route from web exploit to AD domain compromise
Resecurity’s analysis of the July 2026 SharePoint cluster details how chained vulnerabilities (including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) lead from unauthenticated RCE to web shell deployment (spinstall0.aspx), IIS machineKey theft, and full Active Directory compromise; the TTPs align with nation-state and ransomware affiliate behavior. The campaign affects on-premises SharePoint Server versions (Subscription Edition, 2019, 2016) and highlights that content-management servers can be a direct path to enterprise and OT domain control. OT/ICS teams should verify segmentation between enterprise and control networks, harden on-premises SharePoint instances or apply vendor mitigations, and validate AD recovery and incident response plans.
Source: Resecurity
Alleged RGT robotics source code leak could expose credentials and vulnerabilities
A threat actor posted claimed proprietary source code for RGT (Robot Global Team) on an underground forum, asserting access to software used in autonomous service and logistics robots. If authentic, the code could reveal hardcoded credentials, API keys, cryptographic secrets and software flaws that enable remote takeover or safety-compromising attacks on deployed robotic systems in industrial environments; RGT has not confirmed the breach. Industrial operators using RGT systems should treat the leak as credible, audit deployments for exposed secrets, and prioritize mitigation and monitoring for anomalous robot behavior.
Source: Daily Dark Web / X
Manufacturing ICS face dual quantum-era risk: cryptographic breakage and HNDL exposure
A new analysis outlines two distinct quantum risks for manufacturing control systems: future cryptographic breakage of OPC UA/SCADA authentication and PLC communications by quantum algorithms, and immediate Harvest Now Decrypt Later (HNDL) threats to long-lived IP (CAD files, process parameters) with multi-decade sensitivity windows. The paper maps PQC migration to NIST CSF 2.0 and NIS 2 obligations and warns that IEC 62443 SL 3 alone does not ensure quantum resilience; manufacturers should inventory sensitive assets, prioritize PQC migration for high-value channels, and mitigate HNDL by reducing long-term ciphertext exposure.
Source: Quantum Security Defence