CISA released a coordinated set of advisories detailing critical vulnerabilities affecting a range of industrial control system (ICS) products from major vendors, including Inductive Automation, Schneider Electric, Mitsubishi Electric, Siemens, Rockwell Automation, and Axis Communications. The vulnerabilities span a variety of attack vectors, such as improper privilege management, deserialization of untrusted data, OS command injection, and flaws in network protocol implementations. Exploitation of these vulnerabilities could result in severe outcomes, including SYSTEM-level code execution, denial-of-service conditions, information tampering, information disclosure, authentication bypass, and remote code execution across affected ICS platforms.
Vendors have issued patches and mitigation guidance for impacted products, urging organizations in critical infrastructure sectors to update their systems promptly. The advisories highlight the global deployment of these products in sectors such as manufacturing, energy, and commercial facilities, underscoring the potential for widespread impact if left unaddressed. CISA encourages administrators to review the technical details and apply recommended remediations to reduce the risk of exploitation and maintain operational resilience.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
CISA announced the release of nine industrial control systems advisories covering products from Inductive Automation, Schneider Electric, National Instruments, Mitsubishi Electric, Siemens, Advantech, Rockwell Automation, and Axis Communications. The agency urged operators to review the advisories and apply recommended mitigations to reduce risk to critical infrastructure.
CISA published advisory ICSA-25-352-07 for CVE-2025-13823 and CVE-2025-13824 affecting Rockwell Automation Micro820, Micro850, and Micro870 controllers. The vulnerabilities could be exploited to trigger denial-of-service conditions in widely used industrial controllers.
CISA published advisory ICSA-25-352-05 covering CVE-2025-40820 in Siemens products using the Interniche IP-Stack. The issue stems from improper TCP sequence number validation and could enable denial-of-service attacks against TCP-based services.
CISA published advisory ICSA-25-352-04 for CVE-2025-11774 affecting multiple Mitsubishi Electric Iconics Digital Solutions products. The vulnerability could allow arbitrary code execution, denial of service, tampering, or information disclosure through local configuration-file manipulation.
CISA published advisory ICSA-25-352-02 for CVE-2025-59287 affecting Schneider Electric EcoStruxure Foxboro DCS Advisor via WSUS. The critical vulnerability could allow remote code execution with system-level privileges if unpatched.
CISA published advisory ICSA-25-352-01 for CVE-2025-13911 in Inductive Automation Ignition 8.1.x and 8.3.x. The flaw allows authenticated administrators to upload malicious project files whose Python scripts execute with SYSTEM privileges on Windows hosts.
Siemens published fixes for some affected products and workarounds for others in response to CVE-2025-40820 in the Interniche IP-Stack. The vulnerability could let an unauthenticated attacker disrupt TCP connection setup and cause denial of service in numerous Siemens industrial products.
Rockwell Automation released firmware updates and mitigation guidance for CVE-2025-13823 and CVE-2025-13824 affecting Micro820, Micro850, and Micro870 controllers. Successful exploitation could cause denial-of-service conditions that leave controllers unresponsive or in a fault state.
Mitsubishi Electric released patches for most affected Iconics Digital Solutions products impacted by CVE-2025-11774, and advised MC Works64 users to upgrade to a fixed product version. The flaw is an OS command injection issue in the keypad function that could enable arbitrary code execution with local access.
Microsoft released security updates KB5070882 and KB5070884 to address CVE-2025-59287, a critical deserialization flaw in Windows Server Update Services used by Schneider Electric EcoStruxure Foxboro DCS Advisor. Schneider Electric later directed customers to apply these patches.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.