CERT@VDE (Germany)
certvde · A · active
https://www.certvde.com/en/advisories/
CERT@VDE — Germany's OT/ICS coordinating CERT and CNA for industrial-automation vendors (WAGO, Phoenix Contact, etc.). Per-advisory pages at /en/advisories/VDE-YYYY-NNN/. Discovered 2026-07-13 via ENISA EUVD pivot (EUVD-2026-43297 -> VDE-2026-031, WAGO I/O System Field CVE-2026-4769); contributed a published vulnerability entry. High-value OT/ICS primary for the energy/water additional sectors; promote toward essential after the 3-contributing-run candidate window.
Cited in 5 entries
Citation cadence
Citation days per ISO week (3 weeks of coverage span, total 3).
- Both standard prioritisation feeds failed in the same week — an exploited flaw absent from KEV, and four critical flaws with no fix to apply2026-08-02
- 2026-W31 looking ahead — items already in motion: a committed firmware date of 12 August, WebSphere fix packs not due before 3Q2026, an extortion campaign between exfiltration and publication, three flaws with no fix at all, and the CRA reporting clock at six weeks2026-08-02
- CVE-2026-7849 and 19 more — Phoenix Contact CHARX SEC-3xxx EV charging controllers: unauthenticated command injection as root, unsigned firmware updates, and no fix released at disclosure2026-08-02
- OT/ICS carried a full week of high-severity advisories across energy, water, transport and manufacturing — a CVSS-10 debug-port takeover, a persistent-root switch chain, an early-boot coupler backdoor, and a KEV-listed building-automation lockout with no software fix2026-07-19
- CVE-2026-4769 — WAGO I/O System Field: undocumented early-boot interface allows unauthenticated full compromise (CVSS 9.8)2026-07-13