ctipilot.ch
← Back to Weekly 2026-W29
NOTABLEexploitedNATOA1synthesis

OT/ICS carried a full week of high-severity advisories across energy, water, transport and manufacturing — a CVSS-10 debug-port takeover, a persistent-root switch chain, an early-boot coupler backdoor, and a KEV-listed building-automation lockout with no software fix

discovered 2026-07-19 23:54 UTCrun 2026-07-19T2310Z-weekly4 sourcesmulti-source

The week's OT/ICS advisories are worth reading as a set because they hit every sector the constituency defends and because the fixes are not uniformly "patch." The most severe newly-disclosed item is Rockwell's 1715-AENTR EtherNet/IP adapter (CVE-2026-10577, CVSS 10.0): a network-reachable debug port with no authentication lets an unauthenticated attacker read and delete files, stop tasks, modify memory and change I/O states on an adapter deployed in energy and water plants, with Rockwell fixing it in firmware 3.011 and naming network isolation as the interim control (CISA ICSA-26-195-04, 2026-07-14). The same CISA batch carried the ABB T-MAC Plus fuel/chemical terminal-management chain (led by CVE-2025-14771).

Siemens RUGGEDCOM ROX II — a routing/security boundary inside rail, utility, water and manufacturing networks across Europe — drew a full Unit 42 exploit chain: file disclosure via a root-privileged xz misuse (CVE-2025-40948), command injection in the feature-key signature-verification path (CVE-2025-40947), and task-scheduler command injection for persistent, reboot-surviving root (CVE-2025-40949), all fixed in firmware V2.17.1 (Unit 42, 2026-07-17). WAGO's I/O System Field couplers exposed a hidden early-boot diagnostic interface reachable without authentication during the boot window (CVE-2026-4769, CVSS 9.8, CERT@VDE VDE-2026-031, 2026-07-13), fixed per-model in firmware.

The one confirmed-exploited item is the outlier that matters most operationally: CISA KEV-listed the KNX Connection Authorization Option-1 account-lockout flaw (CVE-2023-4346) three years after disclosure — an attacker with network or physical access to a KNX installation can purge unprotected devices and set a BCU key, permanently locking legitimate operators out with no software patch, only procedural hardening (CISA, 2026-07-15). It is directly relevant to any Swiss/EU CI or public-sector estate running KNX for HVAC, lighting, access control or building management.

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.1

Initial Access TA0001
T1190Exploit Public-Facing Application

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.