Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryindustrial-control-system-vulnerabilityembedded-device-vulnerabilitytelecommunications-sector-threat

Canadian Cyber Centre Flags Broad Vendor Patch Wave Across Enterprise and ICS Products

Updated 16h agoFirst seen Mar 16, 202613 sources

The Canadian Centre for Cyber Security issued a series of advisories highlighting a broad patch wave from major technology vendors, spanning enterprise infrastructure, operating systems, and industrial environments. IBM released updates for products including AIX, MQ, QRadar Suite Software, Cloud Pak for Security, multiple IBM Verify offerings, and other middleware and cloud components, while Dell published fixes affecting Avamar Data Store Gen5A, Connectrix B-Series FOS and SANnav, PowerSwitch E3200-ON Series, PowerSwitch Z9664F-ON, and Secure Connect Gateway. Red Hat and Ubuntu also pushed Linux kernel-related updates, with Red Hat covering several RHEL and CodeReady Linux Builder variants and Ubuntu addressing kernel issues in Ubuntu 22.04 LTS and 24.04 LTS, including NVIDIA-related vulnerabilities referenced in USN-8060-7 and USN-8059-8.

Industrial and telecom systems were also affected. CISA advisories cited vulnerabilities across products from Apeman, Ceragon, Honeywell, Inductive Automation, Lantronix, Siemens, and Trane, impacting industrial control systems, building management platforms, EV chargers, networking devices, and industrial software. Separately, HPE disclosed a remote buffer overflow in HPE Telco Service Orchestrator affecting versions prior to v4.2.12 under bulletin HPESBNW05029 revision 1. The Cyber Centre urged organizations to review vendor guidance, implement recommended mitigations, and apply updates promptly to reduce exposure across both IT and OT environments.

Share:
Canadian Cyber Centre Flags Broad Vendor Patch Wave Across Enterprise and ICS Products
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

12 events from the most recent confirmed update back to the earliest known activity.

12 EVENTS
Jun 22, 20261d ago

Red Hat published Linux kernel security advisories

Between June 15 and 21, 2026, Red Hat published security advisories addressing Linux kernel vulnerabilities across multiple offerings, including Red Hat CodeReady Linux Builder, Red Hat Enterprise Linux, Red Hat Enterprise Linux Server, and Red Hat Enterprise Linux for Real Time. The Canadian Centre for Cyber Security urged users and administrators to review the referenced Red Hat advisories and apply the necessary updates.

Red Hat security advisory (AV26-621) - Canadian Centre for Cyber Security

Ubuntu published Linux kernel security notices for Ubuntu 16.04, 20.04, and 22.04 LTS

Between June 15 and 21, 2026, Ubuntu published security notices addressing Linux kernel vulnerabilities affecting Ubuntu 16.04 LTS, 20.04 LTS, and 22.04 LTS. The Canadian Centre for Cyber Security advised users and administrators to review the referenced Ubuntu Security Notices and apply the necessary updates.

Ubuntu security advisory (AV26-618) - Canadian Centre for Cyber Security
Jun 15, 20268d ago

Ubuntu published Linux kernel security notices for Ubuntu 20.04 and 22.04 LTS

Between June 8 and 14, 2026, Ubuntu published security notices addressing Linux kernel vulnerabilities affecting Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. The Canadian Centre for Cyber Security advised users and administrators to review the referenced Ubuntu Security Notices and apply the necessary updates.

Ubuntu security advisory (AV26-599) - Canadian Centre for Cyber Security

Red Hat published Linux kernel security advisories

Between June 8 and 14, 2026, Red Hat published security advisories addressing Linux kernel vulnerabilities across multiple offerings, including Red Hat CodeReady Linux Builder, Red Hat Enterprise Linux, Red Hat Enterprise Linux Server, and Red Hat Enterprise Linux for Real Time. The Canadian Centre for Cyber Security advised users and administrators to review the referenced Red Hat advisories and apply the necessary updates.

Red Hat security advisory (AV26-601) - Canadian Centre for Cyber Security
Jun 8, 202615d ago

Ubuntu published Linux kernel security notices for multiple releases

Between June 1 and June 7, 2026, Ubuntu published security notices addressing Linux kernel vulnerabilities across multiple Ubuntu releases, from Ubuntu 14.04 LTS through Ubuntu 26.04 LTS. The Canadian Centre for Cyber Security advised users and administrators to review the referenced Ubuntu Security Notices and apply the necessary updates.

Ubuntu security advisory (AV26-555) - Canadian Centre for Cyber Security

Red Hat published Linux kernel security advisories

Between June 1 and June 7, 2026, Red Hat published security advisories addressing Linux kernel vulnerabilities across multiple offerings, including Red Hat CodeReady Linux Builder, Red Hat Enterprise Linux, Red Hat Enterprise Linux Server, and Red Hat Enterprise Linux for Real Time. The Canadian Centre for Cyber Security advised users and administrators to review the referenced Red Hat advisories and apply the necessary updates.

Red Hat security advisory (AV26-557) - Canadian Centre for Cyber Security
Mar 16, 20263mo ago

Red Hat published Linux kernel security advisories

Between March 9 and 15, 2026, Red Hat published security advisories addressing Linux kernel vulnerabilities across multiple offerings, including Red Hat Enterprise Linux variants and CodeReady Linux Builder. The updates applied to several versions and platforms.

Red Hat security advisory (AV26-242) - Canadian Centre for Cyber Security

CISA published ICS advisories for multiple industrial vendors

Between March 9 and 15, 2026, CISA released a set of ICS advisories covering vulnerabilities in products from vendors including Apeman, Ceragon, Honeywell, Inductive Automation, Lantronix, Siemens, and Trane. The disclosures spanned industrial control systems, building management systems, EV chargers, networking devices, and industrial software.

[Control systems] CISA ICS security advisories (AV26-241) - Canadian Centre for Cyber Security

Ubuntu published Linux kernel security notices for LTS releases

Between March 9 and 15, 2026, Ubuntu issued security notices for Linux kernel vulnerabilities affecting Ubuntu 22.04 LTS and 24.04 LTS. The notices specifically referenced NVIDIA-related kernel issues via USN-8060-7 and USN-8059-8.

Ubuntu security advisory (AV26-239) - Canadian Centre for Cyber Security

IBM published security advisories across multiple product lines

Between March 9 and 15, 2026, IBM published a broad set of security advisories affecting products such as AIX, MQ, QRadar Suite Software, Cloud Pak for Security, IBM Verify offerings, and other enterprise software. Users were urged to review IBM PSIRT guidance and apply the relevant fixes.

IBM security advisory (AV26-237) - Canadian Centre for Cyber Security

Dell published multiple enterprise product security advisories

Between March 9 and 15, 2026, Dell published security advisories covering vulnerabilities in multiple products including Avamar Data Store Gen5A, Connectrix B-Series FOS and SANnav, PowerSwitch platforms, and Secure Connect Gateway. The advisories identified affected version ranges and directed customers to apply updates.

Dell security advisory (AV26-238) - Canadian Centre for Cyber Security

HPE disclosed Telco Service Orchestrator buffer overflow flaw

On March 16, 2026, HPE published security advisory HPESBNW05029 revision 1 for a remote buffer overflow vulnerability in HPE Telco Service Orchestrator. The issue affects versions prior to v4.2.12 and customers were advised to apply the vendor's updates.

HPE security advisory (AV26-244) - Canadian Centre for Cyber Security
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
Affected products
2 linked
Red Hat Enterprise LinuxRed Hat Enterprise Linux Server
Organizations
4 linked
Hewlett Packard EnterpriseRed HatNvidiaCanonical
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.