Skip to main content
System Status
Critical 18
|
High 70
|
Medium 1
|
Feed Online
UPDATED: 2026-06-11 00:00 UTC

Johnson Controls C·CURE 9000 RCE Vulnerability: ICSA-26-204-01 Advisory and Mitigation

CISA published ICSA-26-204-01 on August 11, 2026, disclosing CVE-2026-21655, a remotely exploitable code execution vulnerability in Johnson Controls C·CURE 9000 physical access control systems. With a CVSS score of 9.8 and no authentication required, the flaw affects C·CURE 9000 versions prior to 3.0.3 deployed in enterprise and critical infrastructure physical security management. This advisory covers the vulnerability details, affected versions, exploitation risk in OT-adjacent environments, and recommended mitigations.

BACnet/IP Security: Attack Surface Analysis and Hardening for Building Automation Systems

BACnet/IP has no authentication in its base protocol and tens of thousands of internet-exposed devices. An attacker with network access can read from or write to HVAC, fire suppression, lighting, and access control systems without credentials. This guide covers the attack surface, real-world incident patterns, and hardening steps.

GhostLock CVE-2026-43499: Advisory for OT Environments Running Linux-Based Historian and SCADA Systems

The GhostLock Linux kernel vulnerability (CVE-2026-43499) enables local privilege escalation to root in approximately five seconds with 97% reliability. OT environments running Linux-based historian servers, OPC-UA gateways, and SCADA platforms are directly affected. Patching and mitigation guidance for industrial operators.

Healthcare IoMT and Medical Device Cybersecurity: FDA Requirements and the Current Threat Landscape

Ransomware groups are actively targeting hospital networks via unpatched medical devices running legacy operating systems. This analysis covers the FDA's post-market cybersecurity framework, the IoMT attack surface, and practical segmentation approaches for healthcare OT environments.

Building Automation System Security: BACnet, BMS Hardening, and the OT-IT Convergence Risk

Building automation systems control HVAC, lighting, access control, and fire suppression across commercial and industrial facilities. As BAS deployments converge with IP networks, legacy protocols like BACnet and Modbus are now internet-adjacent — with predictable results for attack surface.

Claroty 2026 State of XIoT Security: OT Vulnerability Disclosures Hit New High

Claroty's annual State of XIoT Security report documents record-high vulnerability disclosures across operational technology, IoT, and connected medical devices. OT vulnerabilities now account for the majority of disclosed flaws, with critical infrastructure sectors facing compounded exposure from legacy device lifecycles and the accelerating advisory pace.