Cyberattack Law and Disclosure Digest for 2026-09-24
Key Facts
- Primary record digest compiled for 2026-09-24.
- Aggregates official announcements from DOJ, CISA, SEC EDGAR, and allied cyber agencies.
- All cited documents are in the public domain or official government publications.
Summary of official government advisories, court filings, and sanctions published on 2026-09-24.
CISA Adds Two Known Exploited Vulnerabilities to Catalog ↗
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-5430 WSO2 Multiple Products Path Traversal Vulnerability
- CVE-2026-71362 Adobe Commerce and Mage
CISA Adds Two Known Exploited Vulnerabilities to Catalog ↗
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-76460 Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
- CVE-2026-87886 A
CISA Adds Two Known Exploited Vulnerabilities to Catalog ↗
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2025-39964 Linux Kernel Race Condition Vulnerability
- CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vuln
Siemens Siveillance Control ↗
Summary
A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server. Siemens has released p
Siemens Industrial Edge Management ↗
Summary
Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification. Siemens has released new versions for the affected products and recommends to update to the latest versio
lwIP (Lightweight IP) ↗
Summary
Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system.
The following versions of lwIP (Lightweight IP) are affected:
- API >=2.0.1|<=2.2.1 (CVE-2026-91018)
## [Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators](https://www.cisa.gov/resources-tools/resources/considerations-critical-infrastructure-operators-working-third-party-ics-integrators) Source: CISA Advisory
Introduction
The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) - hereafter referred to as the “authoring agencies” - have published this fact sheet to highlight considerations for critical infrastructure entities to reduce risk and minimize vulnerabilities when working with third-party industrial control system (ICS) integrators.
ICS is an umbrella term referring to integrated networks of hardware and software de
Siemens WTV676 and WTV776 ↗
Summary
The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices. Siemens has released new versions for the affected products and recommends to update to the late
Botslab G980H Dashcams ↗
Summary
Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication controls, gain unauthorized access to sensitive data and privileged device functionality, modify device configuration, disrupt device operation.
The following versions of Botslab G980H Dashcams are affected:
Siemens Desigo CC family ↗
Summary
A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances
lwIP TCP/IP Stack MQTT Client Application ↗
Summary
Successful exploitation of this vulnerability could allow an attacker to gain full code execution on the device.
The following versions of lwIP TCP/IP Stack MQTT Client Application are affected:
- MQTT Client Application >=2.0.1|<=2.2.1 (CVE-2026-87121)