Daily OT Security News — October 08, 2026. This advisory roundup summarizes five CISA-published OT/ICS advisories (published Oct 6) involving Johnson Controls, Savannah lwIP, and multiple Hitachi Energy products. The items below present the verified facts and suggested operational priorities; consult the listed vendor and CISA advisories for full technical guidance.
1. Johnson Controls EasyIO FG: hard-coded credentials and privilege-management vulnerabilities (CVE-2026-27872, CVE-2026-27873)
CISA lists Johnson Controls EasyIO FG firmware <= 2.0b52 as affected by two issues: CVE-2026-27872 (improper privilege management associated with brute force) and CVE-2026-27873 (hard-coded credentials associated with password spraying). CISA states successful exploitation could provide full unauthorized device access, but also notes the issues are not remotely exploitable and CISA reported no known public exploitation at advisory time. CISA directs readers to Johnson Controls advisory JCI-PSA-2026-12 for detailed mitigation; CISA did not name a patched firmware version in its advisory.
- Inventory EasyIO FG devices and validate firmware scope with Johnson Controls.
- Keep control devices off the public internet; use firewall boundaries and OT/IT segmentation.
- Use a maintained VPN for necessary remote access and assess operational impact before changes.
Sources: CISA advisory (ICS-ALERT/ICSA-26-279-01); CVE record (CVE-2026-27872).
2. Savannah lwIP SMTP client: critical buffer-overflow exposure (CVE-2026-15340)
CISA identifies Savannah lwIP SMTP client 2.2.1 as affected by a buffer-copy without input-size checking (CVE-2026-15340). CISA lists a CVSS v3 score of 9.8 and says successful exploitation could crash the accessed device and that the condition may allow remote code execution. CISA notes energy, water, and wastewater sectors as relevant but does not identify affected installations; CISA’s reviewed text does not name a fixed version. A secondary report identifies a patch that organizations should validate with the supplier before relying on it.
- Ask suppliers whether their devices embed Savannah lwIP SMTP client 2.2.1.
- Reduce reachable attack surface and use firewall-backed segmentation.
- Validate a supplier-approved fix in a controlled process before deployment.
Sources: CISA advisory (ICS-ALERT/ICSA-26-279-02); secondary report.
3. Hitachi Energy Asset Suite: unauthenticated servlet-access weaknesses (CVE-2026-7395, CVE-2026-11796)
CISA and Hitachi Energy identify Asset Suite versions 9.9.0 and earlier as affected. CVE-2026-7395 concerns unauthenticated access to a test servlet that can permit configuration-file upload, with potential information-disclosure and integrity impact. CVE-2026-11796 concerns unauthenticated access to reload/cache servlets and may affect availability depending on application configuration. CISA republished the vendor advisory on October 6, following Hitachi Energy’s September 29 advisory; CISA does not confirm availability of a patched Asset Suite version and advises organizations to confirm remediation with Hitachi Energy or their provider.
- Inventory Asset Suite versions and prioritize 9.9.0 and earlier for review.
- Restrict remote reachability; firewall and isolate control-system networks.
- Validate vendor guidance and operational effects before configuration or upgrade changes.
Sources: CISA advisory (ICS-ALERT/ICSA-26-279-03); Hitachi Energy PSIRT.
4. Hitachi Energy SOI: Apache ActiveMQ remote-code-execution advisory (CVE-2026-34197)
CISA’s advisory covers the Apache ActiveMQ component in Hitachi Energy System 800xA System Operations Infrastructure (SOI) versions 2.0.0 through 2.2.0. CISA characterizes CVE-2026-34197 as code injection / remote code execution and lists a vendor CVSS v3 score of 8.8. CISA says the vulnerability can affect confidentiality, integrity, and availability. CISA republished Hitachi Energy’s September 29 advisory on October 6; the CISA advisory does not state a product-specific SOI fixed version, so organizations should confirm remediation with Hitachi Energy or their provider.
- Check whether SOI versions 2.0.0 through 2.2.0 are present.
- Keep control systems off the internet and separate OT from business networks.
- Use maintained VPN access where needed and conduct impact/risk analysis before changes.
Sources: CISA advisory (ICS-ALERT/ICSA-26-279-04); Hitachi Energy PSIRT.
5. Hitachi Energy RTU500: end-of-life CMU firmware vulnerabilities (CVE-2026-8065, CVE-2026-8066, CVE-2026-8067)
The advisory concerns RTU500 series CMU firmware 11.x and prior, which Hitachi Energy describes as end-of-life. CISA’s advisory lists six CVEs, including CVE-2026-8065, CVE-2026-8066, and CVE-2026-8067. Documented effects include unauthorized firmware upload or arbitrary file changes and a reboot that can temporarily affect availability. Hitachi Energy states that currently supported RTU500 CMU firmware is not affected by the reported findings and strongly recommends upgrading end-of-life firmware to a currently supported version with installation-specific planning and validation.
- Identify RTU500 CMU devices running 11.x or earlier.
- Plan tested upgrades to supported firmware with Hitachi Energy or the provider.
- Reduce network exposure and apply site-specific risk and change-control review.
Sources: CISA advisory (ICS-ALERT/ICSA-26-279-06); Hitachi Energy PSIRT.