Daily OT Security News — Viakoo — September 03, 2026
UK Advances Powers to Restrict High-Risk Technology Suppliers in Critical Infrastructure
SecurityWeek reported September 2 that late amendments to the UK Cyber Security and Resilience Bill, tabled August 24, would give ministers powers to prevent critical-sector organizations from using technology suppliers deemed high risk. The bill has passed the House of Commons and is in the House of Lords; the amendments followed reporting that Iran-linked adversaries forced a small UK energy facility offline for four days, bringing supply-chain risk into focus.
Source: SecurityWeek
SonicWall Confirms Active Exploitation of Critical SMA 1000 Vulnerabilities
SonicWall disclosed CVE-2026-83548, a CVSS 10 pre-authentication SSRF issue in SMA 1000 Work Place, and CVE-2026-83549, a CVSS 7.8 post-authentication command-injection RCE issue in the Appliance Management Console. Researchers said the issues can be chained for unauthenticated RCE and SonicWall confirmed active exploitation. The company directed affected customers to install fixed firmware 12.4.3-03526 or 12.5.0-02952 and to investigate, re-image or redeploy, and reset credentials and TOTP tokens if compromise is found.
Source: Dark Reading
Cisco Patches Critical IOS XR and Nexus 9000 Vulnerabilities
SecurityWeek reported September 3 that Cisco fixed multiple IOS XR issues under seven CVEs, including CVE-2026-20274 and CVE-2026-20279, each rated CVSS 9.8. Cisco also fixed CVE-2026-20212, rated CVSS 9.8, in Nexus 9000 series switches; the report says remote attackers could connect to TCP ports accessible by default and execute code with root privileges.
Source: SecurityWeek
Rockwell Automation Releases Patches and Workarounds for More Than a Dozen Industrial-Product Vulnerabilities
Rockwell Automation released patches or workarounds for more than a dozen vulnerabilities across industrial automation products, including RSLinx Classic, ControlLogix and CompactLogix controllers, FactoryTalk Historian Machine Edition, FactoryTalk Activation Manager, ArmorStart Distributed Motor Controllers, ControlFLASH, and the Redundancy Module Configuration Tool. Reported weaknesses include denial of service, remote code execution, privilege escalation, and cross-site scripting; CISA says it is not aware of exploitation of CVE-2026-9637.
Source: SecurityWeek
Project Watershed 250 Brings Cybersecurity Support to Water Utilities
A September 2 Foundation for Defense of Democracies analysis reports that Project Watershed 250 launched August 31 as a six-month Texas pilot pairing local water utilities with free federal, state, and private-sector cybersecurity services. The analysis also describes water-sector measures including proposed dedicated cybersecurity funding, the Water Watch Center’s threat-intelligence and vulnerability-management support, and hands-on cyber technical assistance, and notes that 90 percent of water utilities are small systems serving fewer than 3,300 people and often have limited cyber budgets and expertise.
Source: Foundation for Defense of Democracies
This concludes today’s briefing.