— 2026-10-01 — ICS Advisory Flood, Authlib Trust Bypass
CISA published a wave of seven ICS advisories spanning physical access control, EV charging, building automation, and IoT platforms. The most consequential is Armatura One, which inherits CVE-2023-46604KEV·R — an actively exploited flaw with documented ransomware use — placing physical-security infrastructure directly in the blast radius. Separately, CISA formally added Cisco Catalyst SD-WAN Manager CVE-2026-76504KEV to its Known Exploited Vulnerabilities catalog, and a new report details an Authlib flaw allowing trusted-data forgery without a cryptographic key.
Top items
- CISA adds Cisco Catalyst SD-WAN Manager CVE-2026-76504KEV to Known Exploited Vulnerabilities catalog. This unauthenticated remote hex-encoding vulnerability grants admin-level access to affected SD-WAN Manager instances. CISA's formal KEV listing confirms active in-the-wild exploitation. This story was first reported on 2026-09-30 by BleepingComputer; the KEV catalog addition is the new development. A public exploit is already available given KEV listing status. (src: CISA KEV)
- CISA advisory for Armatura One references CVE-2023-46604KEV·R (Apache ActiveMQ), which is in CISA KEV with known ransomware use. Armatura One — a physical access control system — ships with the vulnerable component, meaning exploitation could yield database access, arbitrary code execution at highest privilege, or control of physical door systems. CVE-2023-46604KEV·R has documented ransomware exploitation in the wild. (src: CISA ICS Advisory)
- Authlib trust-bypass flaw allows forged signatures without a cryptographic key. An attacker can impersonate trusted identity providers by exploiting a logic flaw in Authlib's verification path, bypassing the need for any signing key entirely. This undermines OAuth/OIDC trust chains in any application relying on vulnerable Authlib versions. (src: SecurityLab.ru)
- CISA publishes six additional ICS advisories for industrial and IoT systems. The batch covers: ABB PCM600 (privilege escalation / file overwrite, ICSA-26-274-03); Johnson Controls EasyIO Neo Series across two advisories (credential and session interception, ICSA-26-274-05 and ICSA-26-274-04); Meari IoT Cloud Platform OpenAPI (device credential and owner data exposure, ICSA-26-274-06); Monta EV charging platform (unauthorized administrative control over charging stations and DoS, ICSA-26-274-02); and CISA Malcolm (XSS, CVSS 8.8, ICSA-26-254-01). (src: CISA ICS Advisory – ABB · Johnson Controls 274-05 · Johnson Controls 274-04 · Meari · Monta · CISA Malcolm)
- Kiteworks releases patches for 126 vulnerabilities including max-severity Email Protection Gateway code injection. This is a genuine development in a story first reported on 2026-09-25, when Kiteworks urged a six-hour server shutdown over potential zero-day attacks. The patches are now available, and the max-severity EPG code injection flaw is resolved. (src: BleepingComputer)
Themes
ICS and OT exposure season. Seven advisories in a single day — touching EV charging, building controllers, physical access control, and IoT cloud platforms — reinforce that OT-adjacent infrastructure remains a soft target. The Armatura One advisory is particularly notable because it inherits a CVE already weaponised by ransomware operators, demonstrating how a known vulnerability propagates into unexpected product categories through embedded components.
Authentication trust-chain erosion. The Authlib signature bypass and the Cisco SD-WAN hex-encoding flaw both target the authentication layer — one at the application identity-provider level, the other at the network management plane. Neither requires credentials to exploit, reinforcing that unauthenticated trust-path attacks remain a primary vector.
