Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
industrial-control-system-vulnerabilitywidely-deployed-product-advisoryendpoint-software-vulnerability

CISA and Canadian Cyber Centre Advisories Highlight Multiple ICS and Enterprise Vulnerabilities

Updated 3mo agoFirst seen Feb 17, 20267 sources

The Canadian Centre for Cyber Security issued multiple advisories summarizing vendor and CISA disclosures from Feb 9–15, urging organizations to patch widely used platforms. This included Linux kernel fixes across supported Ubuntu releases (16.04 through 25.10) and a broad set of Dell and IBM product updates affecting backup/DR, infrastructure, and automation/transaction systems (e.g., Dell Avamar/NetWorker/PowerEdge/IDPA/iDRAC Service Module and IBM Business Automation Workflow, Operational Decision Manager, Sterling components, webMethods Integration, and others).

CISA also published ICS advisories covering several industrial products with potentially high-impact outcomes. Siemens Simcenter Femap and Nastran were reported vulnerable to multiple NDB/XDB file-parsing issues (CVE-2026-23715 through CVE-2026-23720) that can be triggered via malicious files and may lead to crashes or arbitrary code execution (CVSS 7.8), with Siemens recommending upgrades. GE Vernova Enervista UR Setup versions < 8.70 were reported vulnerable to DLL hijacking and path traversal (CVE-2026-1762, CVE-2026-1763; CVSS 7.8), potentially enabling elevated code execution. Separately, CISA advisory ICSA-26-043-10 described a critical unauthenticated remote code execution risk in Airleader Master <= 6.381 due to an unrestricted file upload flaw (CVE-2026-1358; CVSS 9.8); CISA noted no known public exploits at the time and recommended exposure reduction measures such as network segmentation and restricting internet access to control systems.

Share:
CISA and Canadian Cyber Centre Advisories Highlight Multiple ICS and Enterprise Vulnerabilities
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

11 events from the most recent confirmed update back to the earliest known activity.

11 EVENTS
Feb 17, 20264mo ago

Canadian Centre for Cyber Security summarizes recent CISA ICS advisories

On 2026-02-17, the Canadian Centre for Cyber Security published advisory AV26-134 summarizing CISA ICS advisories issued the prior week for multiple industrial vendors. The notice recommended reviewing the linked advisories, implementing mitigations, and applying available updates.

Canadian Centre for Cyber Security issues Ubuntu advisory notice

On 2026-02-17, the Canadian Centre for Cyber Security published advisory AV26-133 about Ubuntu's recent Linux kernel security notices. The notice directed administrators to review the referenced Ubuntu advisories and deploy updates for affected supported releases.

Canadian Centre for Cyber Security issues Dell advisory notice

On 2026-02-17, the Canadian Centre for Cyber Security published advisory AV26-132 summarizing Dell's recent security advisories and recommending that users consult Dell's guidance and remediate affected systems. The notice covered a broad range of Dell and Dell EMC products.

Canadian Centre for Cyber Security issues IBM advisory notice

On 2026-02-17, the Canadian Centre for Cyber Security published advisory AV26-131 summarizing IBM's recent security advisories and urging organizations to apply the necessary updates. The notice highlighted affected enterprise software and integration products across IBM's portfolio.

CISA publishes GE Vernova Enervista UR Setup advisory

On 2026-02-17, CISA published advisory ICSA-26-048-03 for two local vulnerabilities in GE Vernova Enervista UR Setup versions prior to 8.70: a DLL hijacking issue in the installer and a directory traversal flaw in firmware update file handling. CISA said the issues were not remotely exploitable and that no public exploitation had been reported.

CISA republishes Siemens Simcenter vulnerability advisory

On 2026-02-17, CISA published advisory ICSA-26-048-01 covering multiple file-parsing vulnerabilities in Siemens Simcenter Femap and Simcenter Nastran versions earlier than 2512. Siemens had released updated versions, and the flaws could cause crashes or potentially arbitrary code execution when a user opens a crafted NDB or XDB file.

Feb 15, 20264mo ago

CISA publishes multiple ICS advisories for OT vendors

Between 2026-02-09 and 2026-02-15, CISA published multiple ICS advisories covering products from AVEVA, Airleader GmbH, Hitachi Energy, Siemens, Yokogawa, ZLAN Information Technology Co., and ZOLL. The notices included vulnerabilities affecting multiple product lines, including Siemens SINEC NMS issues CVE-2026-25655 and CVE-2026-25656.

Feb 12, 20264mo ago

CISA issues advisory for Airleader Master RCE flaw

On 2026-02-12, CISA published ICS advisory ICSA-26-043-10 for CVE-2026-1358, a critical unrestricted file upload vulnerability in Airleader Master up to version 6.381. The flaw could allow unauthenticated remote code execution on vulnerable servers and systems, though no public exploitation was known at the time.

Feb 9, 20264mo ago

Ubuntu publishes Linux kernel security notices

Between 2026-02-09 and 2026-02-15, Ubuntu published multiple security notices to address Linux kernel vulnerabilities affecting releases from 16.04 LTS through 25.10. Administrators were advised to review the referenced Ubuntu Security Notices and apply the required updates.

Dell publishes multiple security advisories

Between 2026-02-09 and 2026-02-15, Dell issued multiple advisories for vulnerabilities affecting products such as Avamar, NetWorker, iDRAC Service Module, Dell Update Package Framework, PowerEdge systems, and several appliance and private cloud offerings. The advisories included fixed-version guidance for remediation.

IBM publishes multiple product security advisories

Between 2026-02-09 and 2026-02-15, IBM released multiple security advisories covering vulnerabilities in products including Business Automation Workflow, Concert Software, Financial Transaction Manager, Operational Decision Manager, Sterling products, webMethods components, and z/Transaction Processing Facility. The Canadian Centre for Cyber Security later urged administrators to review IBM's notices and apply updates.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

13 LINKEDOpen in app
Affected products
1 linked
Airleader Master
Organizations
9 linked
Airleader GmbHAvevaHitachi EnergySiemensCanonicalYokogawa Electric CorporationZLAN Information Technology Co.ZOLL Medical CorporationInternational Business Machines
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

CISA and Canadian Cyber Centre Advisories Highlight Multiple ICS and Enterprise Vulnerabilities | Mallory