The Cybersecurity and Infrastructure Security Agency (CISA) released a coordinated set of 18 Industrial Control Systems (ICS) advisories, detailing newly discovered vulnerabilities across a range of products from vendors such as Siemens, Mitsubishi Electric, AVEVA, Brightpick AI, and General Industrial Controls. These advisories highlight critical and high-severity issues including improper authentication, buffer overflows, weak cryptography, DLL hijacking, and improper certificate validation, many of which are remotely exploitable and could lead to code execution, privilege escalation, denial-of-service, or unauthorized access to sensitive systems. Affected products span widely used ICS components such as Siemens LOGO! 8 BM Devices, AVEVA Edge, Brightpick Mission Control, and General Industrial Controls Lynx+ Gateway, with several vulnerabilities assigned CVSS v4 scores above 8, indicating significant risk to industrial environments.
CISA urges organizations to review the technical details and apply mitigations as recommended in the advisories to reduce exposure to these threats. The advisories provide actionable intelligence for asset owners and operators, including lists of affected product versions, vulnerability descriptions, and remediation steps. This coordinated disclosure underscores the ongoing targeting of ICS environments and the need for timely patching and robust security practices to protect critical infrastructure from exploitation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
CISA issued a roundup notice stating it had released 18 Industrial Control Systems advisories on that date, including multiple vendor-specific advisories published or republished the same day.
CISA republished Siemens ProductCERT advisory SSA-682326 covering two high-severity COMOS vulnerabilities that could enable arbitrary code execution or data infiltration in affected deployments. The advisory states the issues are fixed in COMOS v10.4.5 or later and that no known public exploitation had been reported at publication.
CISA published advisory ICSA-25-317-17 for CVE-2025-40827, an uncontrolled search path element flaw that could allow DLL hijacking and arbitrary code execution on Siemens Software Center versions before 3.5 and Solid Edge SE2025 versions before V225.0 Update 10. Siemens recommended updating to fixed versions, and CISA said the flaw was not remotely exploitable and had no known public exploitation.
CISA republished a Siemens advisory describing three vulnerabilities in LOGO! 8 BM devices: CVE-2025-40815, a buffer overflow that could enable remote code execution or denial of service, and CVE-2025-40816 and CVE-2025-40817, missing-authentication flaws that could allow unauthorized configuration changes. Siemens said no fix is available for CVE-2025-40815 and no fixes are planned for the other two issues, instead providing mitigations such as strong passwords and restricting access to UDP port 10006.
CISA republished a Mitsubishi Electric advisory for CVE-2025-10259, a remotely exploitable denial-of-service flaw in MELSEC iQ-F Series CPU modules that can disconnect targeted TCP communications. Mitsubishi recommended mitigations including VPN use and restricting physical and LAN access, and CISA said no public exploitation was known.
Siemens addressed CVE-2023-45133 affecting COMOS Web deployments and CVE-2024-0056 affecting COMOS installations using the COMOS Snapshots component by recommending updates to COMOS v10.4.5 or later.
The Siemens COMOS advisory notes that, as of 2023-01-10, CISA will no longer update Siemens ICS advisories beyond their initial publication and directs users to Siemens ProductCERT for the latest information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.