CISA issued three ICS advisories spanning widely deployed energy and communications technologies, Canada flagged a Johnson Controls camera software command-injection flaw, and a joint U.S. advisory outlined Chinese government-linked data-theft activity affecting multiple sectors including critical manufacturing.
CISA advisory lists high-severity vulnerability classes in Grid Protection Alliance openPDC and openHistorian
CISA published ICSA-26-281-02 on October 8 covering Grid Protection Alliance’s openPDC and openHistorian, deployed worldwide in the Energy sector. The advisory attributes a vendor-equipment CVSS v3 score of 9.8 and groups issues as deserialization of untrusted data, missing authentication, SSRF, hard-coded credentials, and unsafe reflection. Affected releases include openPDC versions below 2.9.477 and 2.9.482 and openHistorian versions below 2.8.580 and 2.8.585; the listed openPDC Docker image includes one additional CVE. CISA reported no known public exploitation at publication. The accessible text does not map specific CVEs to technical detail or provide an explicit upgrade directive. Recommended actions include identifying affected installations and container images, validating product-specific remediation with the vendor, and minimizing exposure through segmentation and secure remote access.
Sources: Primary source · Corroborating source.
CISA warns of seven vulnerabilities in Red Lion N-Tron 700 Series switches
CISA’s ICSA-26-281-01 details seven vulnerabilities in Red Lion N-Tron 700 Series switches running firmware 3.11.0 and earlier and bootloader 2.0.6.1 and earlier. Findings include hard-coded or insufficiently protected credentials, recoverable passwords, missing authentication, unchecked code download, a reachable assertion, and alternate-path authentication bypass. CISA says exploitation could enable administrative access to view, edit, and upload configuration files, and that a specific URL can trigger a reboot that could be scripted continuously; repeated reboots may disrupt dependent connectivity. The vendor guidance reproduced by CISA is to upgrade firmware to 3.11.1 or later, configure or disable SNMP communities, and disable web-GUI access. CISA reported no known public exploitation at publication.
Sources: Primary source · Corroborating source.
CISA advisory flags multiple vulnerabilities in Satel Netco Design; version 2.1.7 is the cited fix
CISA’s ICSA-26-281-03 highlights multiple vulnerabilities in Satel Netco Design used in the communications sector, with an overall vendor-equipment CVSS v3 score of 8.8. The advisory cites cross-site scripting, inefficient regular-expression complexity, and relative path traversal; successful exploitation could run browser scripts, consume excessive resources, enumerate files, create or modify files, and potentially execute arbitrary code. Expanded text lists four CVEs affecting versions before 2.1.7 and notes that all listed paths require authenticated access with varying roles. Satel’s cited fix is to update to Netco Design 2.1.7. CISA reported no known public exploitation at publication. Recommended actions include identifying installations, validating versions, coordinating a risk-assessed update, and minimizing exposure with segmentation and secure remote access.
Sources: Primary source · Corroborating source.
Canadian advisory flags command-injection vulnerability affecting Johnson Controls Illustra Standard – L4L China before version 6.0.0.66394
Canada’s AV26-1010 advisory and the associated NVD entry describe CVE-2026-34498, an improper input validation flaw enabling OS command injection in Johnson Controls Illustra Standard – L4L China for Windows, affecting versions before 6.0.0.66394. The NVD record lists Johnson Controls as the CVE source but remains awaiting enrichment and does not yet include CVSS metrics. The available sources do not detail attack prerequisites, observed exploitation, or impacts on video operations, and the vendor’s public index did not expose CVE-specific remediation text at retrieval. Canadian guidance directs users and administrators to review linked vendor information and apply necessary updates as they become available.
Sources: Primary source · Corroborating source.
U.S. agencies warn of Chinese government-linked actors stealing sensitive data from organizations, including critical manufacturing victims
A joint U.S. advisory based on multiple FBI investigations details data-theft activity enabled by China-based Integrity Technology Group, which the agencies say has links to the Chinese government. Victims included organizations in Government Services and Facilities, Critical Manufacturing, Healthcare and Public Health, and Information Technology, with additional victims outside the U.S. Reported techniques include automated scanning, command-line exploitation, cross-site scripting to harvest credentials, and password spraying or guessing against Microsoft Exchange interfaces and accounts. For persistence, actors installed SoftEther VPN clients configured to reconnect at startup, and they collected and exfiltrated email and credentials. The advisory does not report a specific OT compromise or disruption.
Sources: Primary source · Corroborating source.