Daily OT Security News: July 24, 2026

Today’s OT cybersecurity briefing highlights significant recent vulnerabilities and threats impacting critical infrastructure sectors worldwide, from exploited PLC devices linked to Iranian actors to multiple zero-day flaws in widely used industrial control systems and HMIs. Federal agencies continue to update guidance to help organizations mitigate these risks as threat actors increase their sophistication and targeting.

Updated Federal Advisory on Iranian-Affiliated PLC Exploitation Expands Scope

CISA recently updated its advisory on Iranian-affiliated cyber actors exploiting programmable logic controllers (PLCs), now including Schneider Electric, Siemens, and Rockwell Automation devices. The guidance emphasizes detection of malicious code manipulations and restricting direct internet access to OT devices across government, water, and energy sectors.

Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a

Critical Remote Code Execution Vulnerability Found in Johnson Controls C-CURE 9000

CISA issued an advisory detailing multiple vulnerabilities in the Johnson Controls C-CURE 9000 and Victor application server, including a severe SSRF flaw allowing unauthenticated remote code execution on adjacent networks. These vulnerabilities primarily affect the critical manufacturing sector globally.

Source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01

Unintended Proxy Flaw in Panduit IntraVUE Enables OT Segmentation Bypass

CISA disclosed a critical proxy vulnerability in Panduit IntraVUE versions 3.2.1a14 and earlier that allows attackers to bypass OT network segmentation, alongside weaknesses like plaintext password storage. These issues affect multiple sectors including manufacturing, energy, IT, and water systems.

Source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-04

Privilege Escalation and Credential Exposure in Weintek cMT3092X HMIs

Four distinct vulnerabilities were identified in Weintek’s cMT3092X HMIs that enable non-privileged users to escalate privileges by manipulating cookies or tokens and expose plaintext passwords. The vendor has released patches to address these critical manufacturing sector risks.

Source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-03

Cleartext Data Storage Vulnerability Found in Johnson Controls XAAP Android App

A low-severity flaw in the Johnson Controls XAAP Android application was reported, where sensitive data is stored unencrypted locally, exposing it to anyone who gains physical and compromised access to the device. Updating to version 1.53 or later and employing strong mobile device management policies is recommended.

Source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-02

As threats to OT environments continue to evolve, staying abreast of vendor patches and federal advisories remains critical for securing industrial control systems against increasingly sophisticated cyber attacks.

Share this