(TLP:CLEAR) CISA ICS Advisories, Additional Alerts, Updates, and Bulletins – July 23, 2026
Created: Thursday, July 23, 2026 - 15:42
Categories: Cybersecurity, Federal & State Resources, OT-ICS Security
The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS security advisories, along with additional alerts, updates, and bulletins:
ICS Advisories:
On July 23, 2026, CISA Released Seven Industrial Control Systems Advisories for products used across multiple sectors, please check these latest advisories for specific equipment used across your ICS/SCADA environments and address accordingly:
- Johnson Controls C-CURE 9000 and Victor application server
- Johnson Controls XAAP Android
- Weintek cMT3092X
- Panduit Intravue – Used in Water and Wastewater Systems and Energy
- Rockwell Automation ThinManager – Used in Water and Wastewater Systems and Energy
- MZ Automation libIEC61850 – Used in Energy
- MZ Automation lib60870 – Used in Water and Wastewater Systems and Energy
On July 21, 2026, CISA Released 11 Industrial Control Systems Advisories for products used across multiple sectors, please check these latest advisories for specific equipment used across your ICS/SCADA environments and address accordingly:
- Rockwell Automation ThinManager – Used in Water and Wastewater Systems and Energy
- Rockwell Automation Studio 5000 Logix Designer
- Rockwell Automation 1734 POINT I/O
- Rockwell Automation 1718-AENTR/1719-AENTR
- Rockwell Automation FactoryTalk Services Platform
- Siemens CADRA – Used in Energy
- Siemens IAM Client – Used in Energy
- Siemens SIDIS Secured SmartPlug
- Siemens Opcenter X
- Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW
- Tycon Systems TPDIN-Monitor-WEB2
Additional Alerts, Updates, and Bulletins:
- July 22 – CISA Adds Two Known Exploited Vulnerabilities to Catalog
- July 21 – CISA Adds Four Known Exploited Vulnerabilities to Catalog
- July 16 – CISA Adds Three Known Exploited Vulnerability to Catalog
- Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
- Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
