Today’s updates include multiple CISA ICS advisories for high-risk vulnerabilities in surveillance, maritime, and industrial management products, plus a reported exploitation campaign that targeted internet-facing Gitea instances and impacted industrial software repositories.
CISA issues advisory for Digital Watchdog VMAX DVR and NVR product lineups
CISA published ICS Advisory ICSA-26-258-01 covering six vulnerabilities across all versions of five Digital Watchdog VMAX DVR/NVR product lines that include authentication bypasses, hard-coded credentials, missing authorization, and predictable session-token generation. CISA says successful exploitation could grant full administrative control, access to live and recorded surveillance, configuration changes, and a potential network pivot, and Digital Watchdog released updated firmware; CISA reported no known public exploitation at publication. CISA lists CVE-2026-66890 and CVE-2026-66887 as CVSS v3.1 9.6 Critical, and CISA states that CVE-2026-68070 can let an unauthenticated attacker run received bytes directly as a system command with root execution context.
Source: U.S. Cybersecurity and Infrastructure Security Agency (CISA).
CISA warns of critical hard-coded-key vulnerabilities in Wärtsilä FOS-Onboard
CISA released an ICS advisory for two hard-coded cryptographic-key vulnerabilities in Wärtsilä FOS-Onboard version 5.07.0923.01 that could permit an unauthorized update, code execution, or credential extraction enabling impersonation of a privileged client. Wärtsilä has developed a security patch and directs users to contact it to obtain and install the patch; the vendor says the vulnerabilities are not exploitable when the product is installed as recommended, and CISA reports no known public exploitation. CVE-2026-78225 is a hard-coded server cryptographic-key flaw in the deployer-ng Update Controller component and CVE-2026-81855 is a hard-coded client-authentication-key flaw in the robot testing framework component, with CISA assigning CVSS v3.1 scores of 9.0 and 9.1 respectively.
Source: U.S. Cybersecurity and Infrastructure Security Agency (CISA).
CISA discloses critical unauthenticated access flaws in mySCADA myPRO Manager
CISA published an ICS advisory for two vulnerabilities in mySCADA myPRO Manager versions 2.1 and earlier where an unauthenticated network attacker can access privileged management functions because the command API does not properly enforce authorization and an exposed HTTP endpoint can send arbitrary SMS messages through a connected GSM modem. mySCADA Technologies addressed both issues in version 2.2 and recommends updating; CISA reports no known public exploitation at publication. CVE-2026-73807 is rated CVSS v3.1 9.8 Critical and affects myPRO Manager version 2.1 and earlier, and CVE-2026-82567 exposes an unauthenticated endpoint that accepts a phone number and message and sends the specified SMS through the connected modem.
Source: U.S. Cybersecurity and Infrastructure Security Agency (CISA).
CISA alerts on seven vulnerabilities in CareCam CM2507 IP cameras
CISA issued an ICS advisory covering seven vulnerabilities in CareCam CM2507 IP cameras running HMT.CM2507 firmware v251211.1507 that could expose live video and sensitive device data, enable unauthorized services, permit arbitrary code execution or operational changes, and allow recovery of stored credentials. Remote network-accessible issues include unauthenticated access to video streaming and an empty password for a privileged ONVIF account; CareCam had not responded to CISA’s coordination attempts, and CISA reported no known public exploitation at publication. Notable entries include CVE-2026-88259, which allows an unauthenticated network attacker to retrieve live camera video and is rated CVSS v3.1 7.5, and CVE-2026-84398, which permits privileged ONVIF management access because the device accepts an empty password for a privileged account; CISA also cited a weak fixed root-password hash (CVE-2026-85497) and cleartext storage of Wi-Fi credentials (CVE-2026-81321).
Source: U.S. Cybersecurity and Infrastructure Security Agency (CISA).
Red Heron exploited Gitea RCE in campaign targeting industrial and government organizations
Industrial Cyber reported Acronis Threat Research Unit findings that a Chinese-speaking actor known as Red Heron rapidly exploited CVE-2026-60004, a critical remote-code-execution flaw in internet-facing Gitea instances, soon after public proof-of-concept code appeared. Acronis observed scans of 1,386 instances in seven countries and confirmed compromises across Canada, Argentina, Taiwan, the United States, and Sri Lanka involving source-code theft, credential collection, persistence, and lateral movement; Acronis identified 11 confirmed targets and linked the activity to Red Heron with moderate confidence. Acronis reported that one Taiwanese industrial automation company had hundreds of repositories exfiltrated, including surveillance and monitoring software, a SCADA/HMI tool, IoT integrations, and a network sniffer, and documented a JITTERLY implant with more than 30 post-exploitation commands plus an embedded SIXZUT Linux rootkit that hides files, processes, and network connections and can relaunch the implant.
Source: Industrial Cyber.
Review vendor advisories and apply recommended updates or mitigations where available.