WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships (TLP:CLEAR) CISA ICS Advisories, Additional Alerts, Updates, and Bulletins – November 20, 2025
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) CISA ICS Advisories, Additional Alerts, Updates, and Bulletins – November 20, 2025

TLP:CLEAR

Author: Alec Davison

Created: Thursday, November 20, 2025 - 16:15

Categories: Cybersecurity, Federal & State Resources, Security Preparedness

The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS security advisories, along with additional alerts, updates, and bulletins:

ICS Advisories:

On November 20, 2025, CISA Released Six Industrial Control Systems Advisories for products used across multiple sectors, please check these latest advisories for specific equipment used across your ICS/SCADA environments and address accordingly:

  • Automated Logic WebCTRL Premium Server
  • ICAM365 CCTV Camera Multiple Models
  • Opto 22 GRV-EPIC and GRV-RIO
  • Festo MSE6-C2M/D2M/E2M
  • Festo Didactic products – Used in Energy
  • Emerson Appleton UPSMON-PRO

On November 18, 2025, CISA Released Six Industrial Control Systems Advisories for products used across multiple sectors, please check these latest advisories for specific equipment used across your ICS/SCADA environments and address accordingly:

  • Schneider Electric EcoStruxure Machine SCADA Expert & Pro-face BLUE Open Studio – Used in Energy
  • Shelly Pro 4PM
  • Shelly Pro 3EM
  • Schneider Electric PowerChute Serial Shutdown
  • METZ CONNECT EWIO2
  • Schneider Electric EcoStruxure (Update B) – Used in Energy

Additional Alerts, Updates, and Bulletins:

  • November 19 – CISA Adds One Known Exploited Vulnerability to Catalog
  • November 19 – CISA Releases Guide to Mitigate Risks from Bulletproof Hosting Providers
  • November 18 – CISA Adds One Known Exploited Vulnerability to Catalog
  • November 14 – Fortinet Releases Security Advisory for Relative Path Traversal Vulnerability Affecting FortiWeb Products
  • November 14 – CISA Adds One Known Exploited Vulnerability to Catalog

Related Resources

(TLP:CLEAR) FIRESTARTER Backdoor and Updated Emergency Directive for CISCO Firepower and Secure Firewall Devices

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:GREEN) FBI FLASH – Newly Observed Ransomware Variant Black Shrantac Threat to U.S. Entities

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Likely PRC State-Sponsored Activity Observed in the Water Sector – DocuSign Phishing Tactics Identified

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar