This post summarizes the latest official batch of ICS advisories published on October 1, 2026, and is the most recent CISA advisory set available as of October 4. Each item below condenses CISA’s technical findings, affected products and versions, and vendor guidance where provided.
Critical Armatura One flaws put physical-access control systems at risk
CISA’s advisory notes Armatura One versions before 4.7.2 (and USA versions before 4.6.1) are affected by multiple serious issues, including an Apache ActiveMQ deserialization flaw (CVE-2023-46604, CVSS 9.8), a hard-coded crypto key, hard-coded database-superuser credentials, and credential exposure in logs. Successful exploitation could result in database access, arbitrary code execution at high privilege, or control of the physical access-control system; Armatura released updates 4.7.2 and 4.6.1_USA and CISA says it knows of no exploitation specifically targeting Armatura One.
Source: CISA ICS Advisory ICSA-26-274-01
Monta charging-station platform weaknesses expose EV operations to takeover and disruption
CISA reports that all versions of Monta monta.app are affected by four issues, including an unauthenticated WebSocket endpoint (CVE-2026-95102, CVSS 9.4) that could permit station impersonation and unauthorized actions, plus unlimited authentication attempts, predictable station-session identifiers, and publicly accessible station authentication identifiers. Monta states it supports OCPP 1.6 Security Profile 2 and is moving toward authenticated connections and has implemented rate limiting and connection throttling; CISA reports no known public exploitation.
Source: CISA ICS Advisory ICSA-26-274-02
ABB PCM600 advisory flags privilege escalation and archive path-traversal risks in energy environments
CISA warns that ABB Protection and Control IED Manager PCM600 versions 2.14 and earlier are affected by two vulnerabilities: a Scheduler Service running as LocalSystem that can allow locally authenticated users to escalate privileges (CVE-2026-15952), and project archive processing that may permit path traversal (CVE-2026-15953). ABB recommends running the scheduler service under the same Windows account used for PCM600 and applying certificate-trust safeguards; CISA identifies energy as the affected sector and reports no known public exploitation.
Source: CISA ICS Advisory ICSA-26-274-03
Johnson Controls EasyIO Neo controller advisories call for immediate firmware and TLS hardening
CISA published two advisories covering Johnson Controls EasyIO Neo EC and CW controllers that manage HVAC, lighting and energy functions; specified firmware versions expose sensitive information and allow credentials and session data to traverse the network in cleartext. Johnson Controls advises upgrading to EC 3.3b64 or CW 3.3b26; newer firmware disables HTTP by default and compensating controls include enforcing HTTPS/TLS, disabling HTTP, network segmentation, and monitoring for cleartext management traffic. CISA reports no known public exploitation.
Source: CISA ICS Advisory ICSA-26-274-04; CISA ICS Advisory ICSA-26-274-05
Meari IoT Cloud authorization flaws can expose device credentials, telemetry, and control
CISA states all versions of the Meari IoT Cloud Platform OpenAPI Service are affected by two missing-authorization flaws: authenticated users can manipulate devices they do not own (CVE-2026-101104, CVSS 7.7) and can retrieve device shadows containing credentials, owner details, network data, and telemetry by supplying a device ID (CVE-2026-96613). CISA reports Meari did not respond to coordination attempts and no fix is planned; CISA reports no known public exploitation.
Source: CISA ICS Advisory ICSA-26-274-06
Closing note: Organizations operating affected OT and IoT systems should review the referenced CISA advisories and vendor guidance, prioritize updates and compensating controls stated by vendors, and validate network segmentation, credential management, and monitoring to reduce exposure.