Daily OT Security News: September 10, 2026

Cisco FMC Flaw Added to CISA’s Known Exploited Vulnerabilities Catalog

SecurityWeek reported that Cisco and CISA flagged active exploitation of CVE-2026-20079, a critical authentication-bypass vulnerability in Cisco Secure Firewall Management Center that can let a remote unauthenticated attacker execute malicious scripts and obtain root access. CISA added the flaw to its Known Exploited Vulnerabilities catalog and set a September 12 remediation deadline for federal agencies. Cisco Talos reported three activity clusters exploiting CVE-2026-20079 and CVE-2026-20316, including clusters associated with Sandworm and Qilin. The source recommends installing patches and avoiding internet exposure of FMC.

Source: SecurityWeek

SANS Survey Highlights IT-to-OT Pivot Paths and Safety Consequences

Dark Reading covered the SANS State of ICS/OT Cybersecurity 2024 survey: nearly 19% of respondents reported one or more security incidents in the prior year. Initial compromise paths included external remote services and internet-accessible devices (23.7% each), employee workstations and removable media (20.3% each), supply-chain compromise (20.3%), and spear-phishing attachments (18.6%). Among ransomware victims, 28.6% reported OT/ICS impact, 21% both IT and OT/ICS, and 38.1% reliability or safety compromise. Defenders should prioritize hardening remote access, reducing internet exposure, and controlling removable media and supply-chain risk.

Source: Dark Reading

Manufacturing Survey Shows OT Incidents Often Chain Across Attack Types

Manufacturing Business Technology reported that 82% of surveyed organizations experienced at least one cyber incident in the past 12 months and 57% reported direct OT impact. Incident types included malware affecting OT operations (43.1%), network intrusion or lateral movement (34.5%), unauthorized remote access (31.9%), and supply-chain or third-party compromise (31%). Among respondents reporting malware that affected OT, 56% also reported a network intrusion and 40% a supply-chain compromise. Defenders should anticipate multi-stage chains linking malware, intrusion, and supply-chain vectors.

Source: Manufacturing Business Technology

ONEKEY Report Tracks Cyber Resilience Act Readiness for IoT and OT Products

Disaster Recovery Journal announced ONEKEY’s IoT and OT Cybersecurity Report 2026, which focuses on Cyber Resilience Act readiness, binary firmware auditing, software bills of materials, and continuous post-release monitoring. For companies with broad OT and IoT product portfolios the article reports 28% assigned teams of up to 10 people to prepare for and implement the Cyber Resilience Act, 16% managed with three or fewer specialists, and 19% had assigned no one. The announcement suggests organizations review resourcing and compliance priorities.

Source: Disaster Recovery Journal

Share this