Today’s briefing highlights a mix of active exploitation, expanded regulatory pressure, and guidance to tame expanding attack surfaces as IT and OT converge. A first-known in-the-wild PLM exploit and a suite of CISA ICS advisories underscore urgent patching needs, while NIST draft guidance and the EU Cyber Resilience Act raise the bar for procurement and product lifecycle security. Operational realities in manufacturing emphasize that technical fixes must be paired with governance and cross-functional processes.
First confirmed in-the-wild exploit targets PTC Windchill (CVE-2026-12569)
Security researchers have observed the first real-world exploitation of CVE-2026-12569, an input validation flaw in PTC Windchill and FlexPLM that allows unauthenticated remote code execution via crafted requests. PTC has released patches and published IoCs after attackers deployed persistent JSP webshells for remote command execution and data exfiltration. CISA added the vulnerability to its KEV catalog and instructed federal agencies to remediate rapidly, highlighting the risk to automotive, aerospace, defense, and other critical supply-chain sectors that rely on PLM systems.
CISA publishes 10 new ICS advisories covering major automation and imaging vendors
On June 25, CISA released ten ICS advisories addressing vulnerabilities in products from Yokogawa, Schneider Electric, Delta Electronics, Horner Automation, Daktronics, Evoke Systems, H.VIEW IP cameras, AzeoTech DAQFactory, and medical imaging libraries such as pydicom/OHIF viewers. The affected products span industrial automation, power-management systems, and healthcare imaging stacks, creating cross-sector exposure for operations technology environments. Administrators are urged to review the technical details and apply recommended mitigations without delay.
Read more at CISA / OpenText Cybersecurity Community
NIST issues draft SP 800-213 Rev. 1 to treat IoT as full “products” in federal procurement
NIST released the initial public draft of SP 800-213 Rev. 1, expanding focus from individual IoT devices to comprehensive “IoT products” that include hardware, firmware, cloud services, mobile apps, and vendor-managed components. The draft advises federal agencies to evaluate connected products as part of system-level risk management before purchase and deployment, and it is open for public comment through August 24, 2026. The guidance is expected to influence enterprise procurement practices and vendor security expectations beyond the federal government.
IT/OT convergence widens patch management gaps in manufacturing
A new analysis shows Industry 4.0 integration is exacerbating patching challenges in manufacturing, as legacy OT designs, vendor-dependent update timelines, 24/7 production demands, and cultural divides delay remediation. The report notes that organizational negligence remains a major factor in breaches and recommends risk-based patch prioritization, comprehensive asset inventories, and strengthened IT–OT collaboration. Network segmentation and virtual patching are highlighted as pragmatic compensating controls for unpatchable legacy assets.
Read more at Manufacturing Tomorrow
EU Cyber Resilience Act enforces mandatory IoT/OT security and reporting timelines
The EU Cyber Resilience Act, in force since December 2024, imposes mandatory cybersecurity requirements on hardware and software products sold in the EU, including IoT and OT devices regardless of the manufacturer’s origin. From September 11, 2026, companies must comply with vulnerability and incident reporting obligations, with full compliance required by December 11, 2027; the law covers product lifecycle, updates, and vulnerability management. The IEC 62443 framework is recommended as a practical baseline for gap analysis and demonstrating compliance across product classes.