OT/IoT/ICS Security News Briefing – July 05, 2026
Today’s briefing highlights critical vulnerabilities and breaches impacting the OT, IoT, and ICS landscapes, underscoring ongoing challenges in securing embedded devices and industrial systems. From pervasive firmware flaws to ransomware campaigns and data breaches in medical device manufacturers, organizations must remain vigilant and proactive in patching and risk mitigation.
Seven FatFs CVEs Expose Millions of Embedded IoT and OT Devices to Code Execution
Security researchers at runZero disclosed seven new vulnerabilities (CVE-2026-38192 through CVE-2026-38198) in FatFs, an open-source FAT/exFAT filesystem driver embedded in a wide range of microcontroller-based devices including industrial controllers and medical devices. These flaws allow attackers to craft malicious filesystem images triggering denial-of-service and remote code execution through buffer overflows and out-of-bounds writes. Since FatFs is integrated as source code in device firmware, patching requires firmware updates from each manufacturer, a process that is rarely executed, leaving many devices exposed indefinitely.
Source: Threat Modeling / Vulnerability Intelligence Report
Seiko SkyBridge Enterprise IoT Routers Hit With Permanent OS Command Injection — No Patch Ever
JPCERT/CC and Japan’s IPA disclosed CVE-2026-50043, a high-severity OS command injection vulnerability affecting Seiko Solutions SkyBridge MB-A100 and MB-A110 enterprise IoT routers. The vendor confirmed no firmware patch will be released due to the product’s end-of-support status. Given active exploitation indicators from prior vulnerabilities, organizations using these devices are advised to disable WebUI access, restrict WAN-side exposure, and plan for immediate hardware replacement.
Source: TechTimes / JPCERT/CC Advisory JVN#20721579
CISA Confirms Active Exploitation of SharePoint RCE CVE-2026-45659; Storm-2603 Deploys Warlock Ransomware
CISA added CVE-2026-45659, a deserialization remote code execution vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog, setting a July 4 patch deadline for federal agencies. The flaw requires only standard site-member credentials to exploit, making insider threats and compromised accounts significant risks. This vulnerability has been actively exploited by the threat actor Storm-2603 to deploy Warlock ransomware against critical infrastructure, prompting urgent patching and retrospective compromise assessments.
Source: Hard2bit / CISA KEV Catalog
PTC Windchill and FlexPLM Hit With Critical RCE Flaw; Attackers Deploy Persistent JSP Web Shells
CISA confirmed active exploitation of CVE-2026-12569, a critical remote code execution vulnerability in PTC Windchill PDMLink and FlexPLM, widely used in industrial manufacturing sectors. Attackers exploit unsafe deserialization and improper input validation to install persistent JSP web shells, enabling ongoing remote command execution and data exfiltration. The breach risks exposure of intellectual property, engineering data, and supply chain integrations, with a remediation deadline already passed as of June 28, 2026.
Source: Penligent / CISA KEV / SecurityWeek
Medtronic Data Breach Exposes 3.8 Million Pacemaker Patients After ShinyHunters Attack
Medtronic disclosed a breach by the ShinyHunters group affecting its corporate IT systems and exposing personal and medical information of 3.8 million patients with implantable devices. While the devices themselves remain uncompromised, stolen data includes sensitive patient identifiers and medical details, revealing a cybersecurity gap where patient data protection lags behind connected device security. This incident stresses the need for holistic cybersecurity strategies in healthcare environments.
Source: GetCyberRight / SecurityWeek
As embedded and industrial systems continue to underpin critical infrastructure and healthcare, these developments highlight the growing complexity and risk landscape in OT and IoT security. Organizations must prioritize timely patching, decommissioning unsupported devices, and comprehensive data protection to mitigate emerging threats and safeguard operational continuity.