(TLP:CLEAR) CISA ICS Advisories, Additional Alerts, Updates, and Bulletins – September 17, 2026
Created: Thursday, September 17, 2026 - 15:17
Categories: Cybersecurity, Federal & State Resources, OT-ICS Security
The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS security advisories, along with additional alerts, updates, and bulletins:
ICS Advisories:
On September 17, 2026, CISA Released Eight Industrial Control Systems Advisories for products used across multiple sectors, please check these latest advisories for specific equipment used across your ICS/SCADA environments and address accordingly:
- Bransys ELD
- Mitsubishi Electric GX Works3
- Hitachi Energy FACTS Control Platform (FCP) – Used in Energy
- Schneider Electric Modicon M340 Controller and Communication Modules – Used in Water and Wastewater Systems and Energy
- Schneider Electric NetBotz 5 750/755
- ABB Ability Edgenius – Used in Water and Wastewater Systems and Energy
- Schneider Electric PowerChute Serial Shutdown – Used in Energy
- Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)
On September 15, 2026, CISA Released Eight Industrial Control Systems Advisories for products used across multiple sectors, please check these latest advisories for specific equipment used across your ICS/SCADA environments and address accordingly:
- Digital Watchdog VMAX, DVR and NVR Product Lineups
- Wärtsilä FOS-Onboard
- mySCADA myPRO Manager – Used in Water and Wastewater Systems and Energy
- Schneider Electric SCADAPack x70 Products – Used in Energy
- Siemens Reyrolle 7SR5 – Used in Energy
- Siemens Mendix SAML
- Siemens Teamcenter
- CareCam CM2507
Additional Alerts, Updates, and Bulletins:
- September 16 – CISA Adds Two Known Exploited Vulnerabilities to Catalog
- September 16 – CISA Adds One Known Exploited Vulnerability to Catalog
- September 14 – CISA Adds One Known Exploited Vulnerability to Catalog
- September 11 – CISA Adds One Known Exploited Vulnerability to Catalog
- September 11 – CISA Adds Three Known Exploited Vulnerabilities to Catalog
- September 10 – CISA Adds Two Known Exploited Vulnerabilities to Catalog
- Using Cyber Decoys to Strengthen Detection and Response
- Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers
