Daily OT Security News: September 2, 2026

Daily OT Security News — September 2, 2026. This briefing presents four concise operational summaries drawn from reported items relevant to industrial control and operational technology security.

SonicWall warns of exploited SMA1000 zero-days

SonicWall has warned of two SMA1000 zero-days affecting SMA1000 6210, 7210, and 8200v appliances: CVE-2026-83548, described as a CVSS 10 pre-authentication SSRF flaw, and CVE-2026-83549, an operating-system command-injection flaw. SecurityWeek reports the flaws can be chained for unauthenticated remote code execution and that exploitation has been observed in the wild. SonicWall lists hotfixes 12.4.3-03526, 12.5.0-02952 and later versions. Operationally, these details indicate exposed SMA1000 appliances could be subject to remote compromise if not updated.

Source: SecurityWeek

NIST seeks feedback on a planned federal IoT requirement-catalog update

NIST has posted a pre-draft call for comments to begin revising Special Publication 800-213A, the Internet of Things Device Cybersecurity Guidance for the Federal Government: IoT Device Cybersecurity Requirement Catalog. Inside Cybersecurity reports the stated purpose is to help federal agencies make IoT cybersecurity decisions, incorporate lessons learned, and align the catalog with recent frameworks. For operational audiences, the revision process signals potential changes in federal IoT expectations and offers a formal opportunity for stakeholders to provide input.

Source: Inside Cybersecurity

Research shows AI can accelerate porting of known PLC exploits

Forescout research reported by CSO Online shows AI assistance reduced the time needed to port a known PLC exploit between product models to about 8.5 hours, using CVE-2021-31886 on Wago PLC models. The test required substantial human-researcher input. The article cautions that AI could lower effort for experienced attackers to assess product-family variants or adapt known exploit paths, while noting it does not make ICS zero‑day discovery easy for unskilled actors. Operationally, AI-assisted workflows may change attacker effort profiles.

Source: CSO Online

CISA round-up flags a new batch of industrial-control advisories

CFSN Detailed Analysis reports that CISA NCCIC-ICS published six control-system security advisories for Rockwell Automation products and updated two advisories involving Rockwell and Mitsubishi products. The accessible portion of the post does not identify individual CVEs, severities, or mitigations. Operationally, the round-up indicates a set of public advisories and updates relevant to industrial-control stakeholders; the post notes that individual CVEs, severities, or mitigations are not identified in the accessible portion.

Source: CFSN Detailed Analysis

Share this