This day 02:02 06:02 10:02 14:03 18:03 22:04
⚠ exploit status: CVE-2026-31431 · KEV
Info  2026-09-17 18:03Z · last 4h · 28 findings · glm-5.2:cloud

Threat Brief — 2026-09-17 — ICS advisory flood hits OT

A large batch of CISA ICS advisories landed today covering seven industrial products, with ABB Ability Edgenius standing out because its vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog. Three separate Schneider Electric product lines received advisories in the same batch. Outside ICS, the International Meteor Organisation lost much of its online infrastructure to a cyberattack and has begun emergency recovery.

Top items

Themes

ICS/OT advisory batch. Seven CISA ICS advisories were published in a single batch (icsa-26-260-01 through 07), spanning ABB, Schneider Electric (three products), Hitachi Energy, Mitsubishi Electric, and Bransys. The only KEV-listed vulnerability in the group is CVE-2026-31431KEV in ABB Ability Edgenius. The remainder are standard disclosures without evidence of active exploitation, though the breadth of vendors affected in one cycle underscores the persistent attack surface in OT environments.

Microsoft CVE acknowledgement updates continue. Eight Microsoft CVEs received informational acknowledgement updates today (CVE-2026-81957, CVE-2026-69724, CVE-2026-68794, CVE-2026-62819, CVE-2026-55039, CVE-2026-50311, CVE-2026-66809, CVE-2026-33835). These are administrative changes only with no technical impact and no new exploitability information.

===

THREAT-TOPICS===

[{"slug":"abb-edgenius-cve-2026-31431KEV-kev","headline":"ABB Ability Edgenius CVE-2026-31431KEV added to CISA KEV","findingIds":[12136],"status":"new","development":""},

{"slug":"schneider-electric-ics-advisory-batch-sept-2026","headline":"Schneider Electric receives three ICS advisories across PowerChute, Modicon M340, and NetBotz 5","findingIds":[12135,12134,12133],"status":"new","development":""},

{"slug":"hitachi-energy-facts-control-platform-vulnerabilities","headline":"Hitachi Energy FACTS Control Platform vulnerabilities disclosed","findingIds":[12131],"status":"new","development":""},

{"slug":"mitsubishi-electric-gx-works3-auth-bypass","headline":"Mitsubishi Electric GX Works3 local authentication bypass","findingIds":[12130],"status":"new","development":""},

{"slug":"bransys-eld-telemetry-firmware-vulnerabilities","headline":"Bransys ELD vulnerabilities expose telemetry and firmware access","findingIds":[12132],"status":"new","development":""},

{"slug":"imo-cyberattack-website-takedown","headline":"International Meteor Organisation hit by cyberattack, infrastructure offline","findingIds":[12116],"status":"new","development":""}]

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db