[Control systems] CISA ICS security advisories (AV26-718)
Serial number: AV26–718 Date: July 20, 2026 Between July 13 and 19, 2026, CISA published ICS advisories to address vulnerabilities in the following products: ABB 800xA for Advant Master – multiple versions ABB Ability Edgenius – multiple versions and models ABB Control Builder A – version 1.4/4 and prior ABB T-MAC Plus – version 4.0-24 AutomationDirect Productivity Suite – version v4.6.2.2 and prior NASA Core Flight System (cFS) Health & Safety (HS) Application – versions prior to v7.0.1 Rockwell Automation 1715-AENTR EtherNet/IP Adapter – version 3.003 and prior Rockwell Automation 1756-EN2 – version V12.001 and prior Rockwell Automation 1756-EN3 – version V12.001 and prior Rockwell Automation 1756-ENBT – version V6.006 Rockwell Automation Arena – version V17.00.00 and prior Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix – multiple versions and models Rockwell Automation FactoryTalk DataMosaix Private Cloud – version 8.02 and prior Rockwell Automation Flex 5000 Adapter – version 6.011 SALTO ProAccess Space – versions prior to 6.13 Siemens SICAM 8 CPCI85 Central Processing/Communication – versions prior to 26.20 Siemens SICAM 8 SICORE Base system – versions prior to 26.20.0 The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations, and apply the necessary updates if available. CISA ICS Advisories
CSIRTS triage
- What
- Multiple vulnerabilities have been identified in various control systems.
- Who is affected
- Users and administrators of affected control systems.
- Urgency
- Urgency is unclear due to unknown severity.
- Action
- Review the advisory and apply necessary updates.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/control-systems-cisa-ics-security-advisories-av26-718
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-768)2026-07-31
- unknownRails security advisory (AV26-767)2026-07-31
- unknownSolarWinds security advisory (AV26-766)2026-07-31
- unknownGladinet security advisory (AV26-765)2026-07-30
- unknownPHP Group security advisory (AV26-764)2026-07-30