Manufacturing & OT sector · threat operations

Plant Floor Threat Watch

Live exploited-vulnerability and ICS advisory feeds from CISA, combined with an analyst baseline of active malware families and recently disclosed victims across discrete and process manufacturing.

Sector posture

Elevated — Charlie

11 OT CVEs exploitedSynced Sat, 15 Aug 2026 00:55:22 UTC

OT / ICS CVEs under active exploitation

11

1 tied to known ransomware campaigns

Open control-system advisories

12

Newest CISA ICS advisories in the stream

Malware families tracked

8

5 confirmed active this month

Disclosed manufacturing victims

7

Production impact reported in most cases

Tracked families targeting production networks

Active malware

7 active / 8 tracked

FrostyGoop / BUSTLEBERM

ICS/OT malware · first seen 2024

Active
Hits
Modbus TCP controllers, heating & process skids
Entry
Exposed Modbus/502 over internet-facing routers
Impact
Line stoppage
94/100

Fuxnet

Wiper · first seen 2024

Resurging
Hits
Sensor gateways, RS-485 fieldbus modules
Entry
Compromised engineering workstation, flash wipe payload
Impact
Safety system
88/100

LockBit-derived builders

Ransomware · first seen 2019

Active
Hits
Windows domain, MES/ERP servers, virtual hosts
Entry
Edge VPN appliance exploit, valid account resale
Impact
Line stoppage
91/100

Akira

Ransomware · first seen 2023

Active
Hits
Mid-market discrete manufacturers, ESXi clusters
Entry
SSL VPN without MFA, then ESXi encryption
Impact
Data theft
86/100

PIPEDREAM / INCONTROLLER

ICS/OT malware · first seen 2022

Dormant
Hits
Schneider & Omron PLCs, CODESYS, OPC UA servers
Entry
Protocol-native tooling once inside level 2 network
Impact
Safety system
97/100

SmokeLoader / Amadey

Loader · first seen 2011

Active
Hits
Procurement and quoting inboxes, CAD workstations
Entry
Malicious RFQ attachments and cracked CAD installers
Impact
Data theft
72/100

Play

Ransomware · first seen 2022

Resurging
Hits
Automotive tier-1 and tier-2 suppliers
Entry
Unpatched remote access gateways, ProxyNotShell chains
Impact
Line stoppage
83/100

Sandworm remote access kit

RAT · first seen 2014

Active
Hits
Energy-adjacent process plants, utility interconnects
Entry
Living-off-the-land after supplier network pivot
Impact
Espionage
90/100

CISA known exploited vulnerabilities · OT vendors

Exploited in the wild

live
  • CVE-2025-67038Lantronix · EDS5000

    Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

    added 2026-06-23 · remediate by 2026-06-26

  • CVE-2025-32975Quest · KACE Systems Management Appliance (SMA)

    Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.

    added 2026-04-20 · remediate by 2026-05-04

  • CVE-2021-22681Rockwell · Multiple Products

    Multiple Rockwell products contain an insufficient protected credentials vulnerability. Studio 5000 Logix Designer software may allow a key to be discovered. This key is used to verify Logix controllers are communicating with Rockwell Automation design software. If successfully exploited, this vulnerability could allow an unauthorized application to connect with Logix controllers. To leverage this vulnerability, an unauthorized user would require network access to the controller.

    added 2026-03-05 · remediate by 2026-03-26

  • CVE-2018-4063Sierra Wireless · AirLink ALEOS

    Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

    added 2025-12-12 · remediate by 2026-01-02

  • CVE-2022-43939Hitachi Vantara · Pentaho Business Analytics (BA) Server

    Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass authorization.

    added 2025-03-03 · remediate by 2025-03-24

  • CVE-2022-43769Hitachi Vantara · Pentaho Business Analytics (BA) Server

    Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files, allowing for arbitrary command execution.

    added 2025-03-03 · remediate by 2025-03-24

  • CVE-2023-6448Unitronics · Vision PLC and HMI

    Unitronics Vision Series PLCs and HMIs ship with an insecure default password, which if left unchanged, can allow attackers to execute remote commands.

    added 2023-12-11 · remediate by 2023-12-18

  • CVE-2021-38406Delta Electronics · DOPSoft 2

    Delta Electronics DOPSoft 2 lacks proper validation of user-supplied data when parsing specific project files (improper input validation) resulting in an out-of-bounds write that allows for code execution.

    added 2022-08-25 · remediate by 2022-09-15

  • CVE-2018-7841Schneider Electric · U.motion Builder

    A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.

    added 2022-04-15 · remediate by 2022-05-06

  • CVE-2016-8562Siemens · SIMATIC CP

    An improper privilege management vulnerability exists within the Siemens SIMATIC Communication Processor (CP) that allows a privileged attacker to remotely cause a denial of service.

    added 2022-03-03 · remediate by 2022-03-24

  • CVE-2021-20038SonicWall · SMA 100 Appliancesransomware use

    SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.

    added 2022-01-28 · remediate by 2022-02-11

Disclosed incidents & leak-site postings

Recent victims

last 21 days
  • Tier-1 automotive stamping supplier

    2026-08-06

    Two press lines idled 4 days; shipments air-freighted

    AkiraAutomotiveUS Midwest
  • Industrial valve manufacturer

    2026-08-04

    ERP offline, manual paper picking for 9 days

    PlayHeavy equipmentGermany
  • Contract electronics assembler

    2026-08-02

    SMT scheduling data leaked, customer BOMs exposed

    LockBit-derivedElectronics / PCBMalaysia
  • Food processing group

    2026-07-30

    Cold-chain SCADA isolated, one plant on manual control

    QilinFood & beverageNetherlands
  • Aerospace machining shop

    2026-07-27

    ITAR-adjacent drawings posted to leak site

    Hunters InternationalAerospaceFrance
  • Specialty chemicals plant

    2026-07-24

    Batch historian encrypted; safety interlocks unaffected

    BlackSuitChemicalsTexas, US
  • Packaging & corrugate producer

    2026-07-21

    Converting lines down 36 hours, backlog 3 weeks

    RansomHub affiliatePackagingBrazil

CISA ICS advisory stream

Control system advisories

live
  • Siemens Siveillance Video

    Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions.

    Thu, 13 Aug 26 12:00:00 UTCsiemens
  • ANDRITZ HIPASE-250 and 250 SCALA

    Successful exploitation of these vulnerabilities could allow an attacker to read data from the device or gain access to affected workstations. The following versions of ANDRITZ HIPASE-250 and 250 SCALA are affected: HIPA

    Thu, 13 Aug 26 12:00:00 UTC
  • Siemens Desigo DXR and PXC Controllers

    A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to

    Thu, 13 Aug 26 12:00:00 UTCsiemens
  • Haiwell IoT Cloud HMI Gateway

    Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges. The following versions of Haiwell IoT Cloud HMI Gateway are affected: Haiwell IoT Clou

    Thu, 13 Aug 26 12:00:00 UTChmi
  • Siemens License Server (SLS)

    Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server

    Thu, 13 Aug 26 12:00:00 UTCsiemens
  • Siemens Simcenter Femap

    Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this cou

    Thu, 13 Aug 26 12:00:00 UTCsiemens
  • Johnson Controls Metasys

    Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including

    Thu, 13 Aug 26 12:00:00 UTCjohnson controls
  • Siemens Parasolid

    Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemen

    Thu, 13 Aug 26 12:00:00 UTCsiemens
  • Hitachi Energy APM Edge Product

    Hitachi Energy is aware of Dirty Frag vulnerabilities that affect APM Edge product versions listed in this document. Successful exploitation of these vulnerabilities could result in impact on confidentiality, integrity a

    Thu, 13 Aug 26 12:00:00 UTChitachi
  • Siemens Solid Edge

    Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application

    Thu, 13 Aug 26 12:00:00 UTCsiemens
  • Siemens LOGO! Soft Comfort

    Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them

    Thu, 13 Aug 26 12:00:00 UTCsiemens
  • Johnson Controls Inc. Airwall

    Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized

    Thu, 13 Aug 26 12:00:00 UTCjohnson controls

Share of manufacturing incidents

Sector pressure

Automotive & parts24%
Industrial machinery19%
Electronics & semis16%
Food & beverage13%
Chemicals & plastics11%
Aerospace & defense9%
Metals & mining8%

How intrusions start

Initial access

  • Internet-exposed remote access34%
  • Phishing into IT, pivot to OT26%
  • Supplier / integrator access18%
  • Unpatched OT device on flat VLAN14%
  • Removable media on HMI8%