Daily OT Security News: September 04, 2026

Summary of five ICS advisories published in CISA’s September 3, 2026 advisory batch; review each item and follow vendor recommendations or mitigations as available.

CISA Flags OPC UA LocalDiscoveryServer Installation Privilege Issue

CISA advisory ICSA-26-246-01 (published September 3, 2026) covers CVE-2026-77477 in OPC Foundation UA-LDS-Installers before 1.04.420. An attacker who can launch an elevated installer and interact with the keyboard and display during installation could intercept a high-privilege console window and run arbitrary commands. OPC Foundation recommends updating to 1.04.420 or later; CISA reports the issue is not remotely exploitable and has no known public exploitation.

Source: CISA

Critical IXON VPN Client Flaw Can Lead to Elevated Remote Code Execution

CISA republished advisory ICSA-26-246-02 (September 3, 2026) covering CVE-2026-75925, a critical CRLF-injection flaw in IXON VPN Client versions before 1.4.7 with a CVSS v3.1 score of 9.6. Unauthenticated configuration changes can be written to a file later used by a privileged subprocess, potentially allowing commands to run as root or SYSTEM; injected configuration can persist across reboots and may produce no visible behavior change. IXON recommends updating all installations to 1.4.7 or later or uninstalling if not needed, and its cloud rejects clients older than 1.4.7; CISA reports no known public exploitation.

Source: CISA

Rockwell Automation Releases ControlFLASH Fix for Arbitrary Code Execution Risk

CISA advisory ICSA-26-246-03 (published September 3, 2026) covers CVE-2026-12663 in Rockwell Automation ControlFLASH 15.07 and earlier. The installer grants the Everyone group write permissions to a product-installation directory, which can allow arbitrary code execution at the logged-in user’s permission level; Rockwell fixed the issue in ControlFLASH 15.08. For environments that cannot immediately upgrade, the vendor recommends removing the Everyone group from the affected directory permissions; CISA reports no known public exploitation and says the issue is not remotely exploitable.

Source: CISA

Inductive Automation Ignition Default Permissions Expose Project Creation Controls

CISA advisory ICSA-26-246-06 (published September 3, 2026) covers CVE-2026-77393 in Inductive Automation Ignition 8.1.53 and earlier and is rated high severity with a CVSS v3.1 score of 8.8. The Gateway Create Project Role(s) setting shipped blank, which can permit any authenticated user who can execute gateway scripts to create projects. The vendor recommends updating to 8.1.54 or the 8.3 line, and users remaining on older 8.1 can remediate by setting Create Project Role(s) to their Designer Role; CISA reports no known public exploitation.

Source: CISA

Tycon TPDIN-Monitor-WEB3 Missing Authorization Issue Risks Sensitive Device Data

CISA included Tycon Systems TPDIN-Monitor-WEB3 in its September 3, 2026 advisory batch as ICSA-26-246-08, and the related CVE-2026-82684 entry notes versions 2.2.9 and earlier have a missing-authorization vulnerability. The entry says the weakness could allow an attacker to extract system credentials, configurations, or flash contents. The advisory entry was published September 3, 2026; refer to the vendor and the linked listing for details.

Source: Tenable

Operators should track vendor advisories, apply available updates or mitigations, and validate configurations and inventories for affected components.

Share this