Braham, Minnesota has identified $22.98 million in water infrastructure needs on a $2.2 million annual city budget. The $10.22 million state bond it received cannot pay for security software, network monitoring or staff.
Reality
- Evidence38
- Adoption18
- Hype gap+32
- Incentives68
- Confidence36
Between March and April 2025 intruders searched an industrial automation firm for "customers" and "SCADA", then bundled about 800 files. FBI and CISA now want least privilege applied to integrator access.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+12
- Incentives38
- Confidence66
CVE-2026-31431 gives Siemens HMI panel owners one target build, 21.0.2.1, across dozens of order numbers, while operators of the SIMATIC AX Runtime Core Linux packages are left with countermeasures until a fix ships.
Reality
- Evidence58
- Adoption20
- Hype gap−5
- Incentives35
- Confidence55
CVE-2026-18963 sits in the Keycloak reset-credentials flow that Siemens embeds in Industrial Edge Management. Siemens closed its own Cloud service on September 2, and owners of self-hosted IEM Pro and IEM Virtual patch or block the path themselves.
Reality
- Evidence72
- Adoption35
- Hype gap−10
- Incentives55
- Confidence70
Joint advisory AA26-231A describes threat actors feeding internet-scan results into AI tools that emit working python-snap7 clients against Siemens S7 controllers. Siemens says the weakness is configuration, not a new vulnerability.
Reality
- Evidence58
- Adoption28
- Hype gap+12
- Incentives45
- Confidence55
CVE-2026-13584 affects every version Mitsubishi Electric shipped of at least 45 parts, including MELSEC MX controllers and remote I/O blocks. The precondition CISA names is access to the same network segment.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap−10
- Incentives30
- Confidence55
CISA's ICSA-26-260-04 gives fixed firmware for four of the six affected Schneider parts and lists the BMXNGD0100 and BMXNOC0401 as affected in every version, with a remediation plan for those still being written.
Reality
- Evidence70
- Adoption25
- Hype gap0
- Incentives58
- Confidence66
CVE-2026-31431 escalates a locally authenticated user or a compromised container workload to root through the Linux kernel's algif_aead interface. ABB has fixed it in Edgenius 3.2.4.1 for the bE100 gateway.
Reality
- Evidence72
- Adoption30
- Hype gap0
- Incentives60
- Confidence66
CISA's advisory covers eleven FACTS Control Platform versions across six product families, and it applies only where the GWS component is present. A utility's first job is establishing which installations have it.
Reality
- Evidence60
- Adoption42
- Hype gap−14
- Incentives35
- Confidence62
Five US agencies told PLC owners that scanners are finding exposed Siemens S7 controllers. ZoomEye puts that surface at 173 assets by product fingerprint, or 161,764 by open port.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+5
- Incentives40
- Confidence55
Abhinav Agarwal's report of insufficiently protected credentials covers every version of seven SCADAPack families. Schneider's answer is role-based access control on the 47x line plus network segmentation and the RTU firewall service.
Reality
- Evidence74
- Adoption
- Insufficient
- Hype gap−12
- Incentives62
- Confidence66
RUGERO Tesla built a PROFINET testbed out of Linux network namespaces and the p-net stack, and the write-up shows where a crafted frame sitting in a capture stops being evidence about the device that received it.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+18
- Incentives20
- Confidence50
ST Engineering's iQ200 answers /api/identity for anyone with network access, handing back the serial number, Device ID and Terminal Private Key identifier that CISA says the platform authenticates with. The fix is 4.5.3.0.
Reality
- Evidence72
- Adoption30
- Hype gap−18
- Incentives20
- Confidence68
CVE-2026-75925 lets anything that reaches the client's local configuration interface plant directives in a file a privileged subprocess later runs. Since 5 August 2026 IXON's cloud has refused clients below 1.4.7, which is what actually breaks the chain.
Reality
- Evidence68
- Adoption40
- Hype gap−10
- Incentives58
- Confidence62
CISA's advisory lists eight Pyramid Solutions development kits below v5.6.1 rather than any finished device, so the fix reaches plant floors only after each device maker rebuilds and ships firmware.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap−18
- Incentives42
- Confidence58
CVE-2026-9633 and CVE-2026-9634 let a standard user on a Windows host plant a DLL where the tool will look for it, then collect Administrator or SYSTEM the next time an admin runs it. Version 10.01.00 fixes both.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap−12
- Incentives50
- Confidence63
Rockwell reported CVE-2026-9637 to CISA itself. A length validation bug in CIP handling drops ControlLogix, CompactLogix and GuardLogix controllers into a major nonrecoverable fault, and clearing it needs a person at the cabinet.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap−14
- Incentives45
- Confidence62
CISA's advisory covers Series B 5.202 and Series C 7.101 across five critical infrastructure sectors, but the published text carries no CVSS vectors and no corrected version numbers for an asset owner to upgrade to.
Reality
- Evidence64
- Adoption
- Insufficient
- Hype gap−12
- Incentives55
- Confidence58
An updated CISA advisory puts CVE-2025-2399 on 18 Mitsubishi Electric CNC model designations. Seventeen of them have a fixed firmware build to chase. The C80 has none, at any version.
Reality
- Evidence80
- Adoption
- Insufficient
- Hype gap0
- Incentives42
- Confidence68
CVE-2025-3511 lets a crafted UDP packet stall CC-Link IE TSN modules. Update D restates the fixed-version thresholds model by model, which is the reconciliation work that three earlier revisions did not force.
Reality
- Evidence64
- Adoption
- Insufficient
- Hype gap−7
- Incentives22
- Confidence55
Earlier coverage
- ASE2000's IEC 104 client accepts a forged peer certificate through version 2.37
Security · August 27, 2026 · 1 publisher
- ICS blocking rate hits a 2022 low, and the global average is now the least useful number
Security · August 27, 2026 · 1 publisher
- CISA's water-sector answer is an inventory: 100-plus exposed systems, most of them PLCs
Security · August 27, 2026 · 1 publisher
- Siemens IoT2050 gateways ship a Node-RED interface that asks nobody for a password
Security · August 25, 2026 · 1 publisher
- CISA's Ebyte advisory carries no fixed version, because the vendor stopped answering
Security · August 25, 2026 · 1 publisher
- IEC 104's real security boundary is the STARTDT handshake, not port 2404
Build · August 25, 2026 · 1 publisher
- U.S. warning on Siemens S7 PLCs: AI-written scripts, borrowed scan data, read access first
Security · August 24, 2026 · 1 publisher
- Johnson Controls console holds passwords in cleartext memory, and the fix line names two versions
Security · August 20, 2026 · 1 publisher
- New Zealand adds 33 names, including two Cyber Army of Russia Reborn operators
Security · August 15, 2026 · 1 publisher