Threat Brief — 2026-09-17 — ICS advisory flood hits OT
A large batch of CISA ICS advisories landed today covering seven industrial products, with ABB Ability Edgenius standing out because its vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog. Three separate Schneider Electric product lines received advisories in the same batch. Outside ICS, the International Meteor Organisation lost much of its online infrastructure to a cyberattack and has begun emergency recovery.
Top items
- ABB Ability Edgenius — CVE-2026-31431KEV listed in CISA KEV. ABB disclosed a vulnerability ("Copy Fail") in Edgenius with a patch available; CISA has placed CVE-2026-31431KEV in its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. Organisations running affected versions should prioritise the vendor update. (src: CISA ICS Advisory)
- Schneider Electric issued three ICS advisories across distinct product lines. PowerChute Serial Shutdown (UPS management software), Modicon M340 Controller and BMXNOR0200H communication modules, and NetBotz 5 750/755 environmental monitors all received vulnerability disclosures. Successful exploitation ranges from local authentication bypass on Modicon to unauthorised access on NetBotz sensors. No CISA KEV listing was noted for any of these. (src: PowerChute, Modicon M340, NetBotz 5)
- Hitachi Energy FACTS Control Platform (FCP) vulnerabilities disclosed. An attacker exploiting the disclosed vulnerabilities in FCP with GWS component can impact confidentiality, integrity, and availability of the control system. No KEV listing or active exploitation noted. (src: CISA ICS Advisory)
- Mitsubishi Electric GX Works3 and Motion Control Settings — local authentication bypass. A local attacker can authenticate with an invalid block password and modify part of the executable module, enabling unauthorised configuration changes on engineering workstations. (src: CISA ICS Advisory)
- Bransys ELD (Electronic Logging Device) — unauthorised telemetry and firmware access. Multiple CVEs (including CVE-2026-86520) affect Bransys ELD Android versions prior to 11.00.00, potentially exposing vehicle telemetry data and allowing firmware tampering. (src: CISA ICS Advisory)
- International Meteor Organisation (IMO) hit by cyberattack, infrastructure offline. IMO lost access to a significant portion of its online infrastructure and has begun emergency recovery. Details on the attack vector or actor have not been disclosed. (src: SecurityLab)
Themes
ICS/OT advisory batch. Seven CISA ICS advisories were published in a single batch (icsa-26-260-01 through 07), spanning ABB, Schneider Electric (three products), Hitachi Energy, Mitsubishi Electric, and Bransys. The only KEV-listed vulnerability in the group is CVE-2026-31431KEV in ABB Ability Edgenius. The remainder are standard disclosures without evidence of active exploitation, though the breadth of vendors affected in one cycle underscores the persistent attack surface in OT environments.
Microsoft CVE acknowledgement updates continue. Eight Microsoft CVEs received informational acknowledgement updates today (CVE-2026-81957, CVE-2026-69724, CVE-2026-68794, CVE-2026-62819, CVE-2026-55039, CVE-2026-50311, CVE-2026-66809, CVE-2026-33835). These are administrative changes only with no technical impact and no new exploitability information.
===
THREAT-TOPICS===
[{"slug":"abb-edgenius-cve-2026-31431KEV-kev","headline":"ABB Ability Edgenius CVE-2026-31431KEV added to CISA KEV","findingIds":[12136],"status":"new","development":""},
{"slug":"schneider-electric-ics-advisory-batch-sept-2026","headline":"Schneider Electric receives three ICS advisories across PowerChute, Modicon M340, and NetBotz 5","findingIds":[12135,12134,12133],"status":"new","development":""},
{"slug":"hitachi-energy-facts-control-platform-vulnerabilities","headline":"Hitachi Energy FACTS Control Platform vulnerabilities disclosed","findingIds":[12131],"status":"new","development":""},
{"slug":"mitsubishi-electric-gx-works3-auth-bypass","headline":"Mitsubishi Electric GX Works3 local authentication bypass","findingIds":[12130],"status":"new","development":""},
{"slug":"bransys-eld-telemetry-firmware-vulnerabilities","headline":"Bransys ELD vulnerabilities expose telemetry and firmware access","findingIds":[12132],"status":"new","development":""},
{"slug":"imo-cyberattack-website-takedown","headline":"International Meteor Organisation hit by cyberattack, infrastructure offline","findingIds":[12116],"status":"new","development":""}]
