Vulnerability Advisories

This page offers a comprehensive view of vulnerabilities identified by Nozomi Networks in critical OT, ICS, and IoT environments, showcasing the deep expertise and dedication of our world-class Security Research team.

Each advisory represents our ongoing effort to enhance the protection of industrial systems, identifying emerging threats before they can be exploited. Immediate protection is available through our Threat Intelligence (TI) subscription, supporting a proactive, forward-thinking defense strategy. For more on our responsible approach, refer to the Responsible Disclosure Policy.

Vulnerability Advisories

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Date Published
CVE ID
Vendor
Product
Type
Risk
Details
September 16, 2026
CVE-2026-27564
Pepperl+Fuchs
ICE2-8IOL-K45P-RJ45
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
September 16, 2026
CVE-2026-27563
Pepperl+Fuchs
ICE2-8IOL-K45P-RJ45
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
September 16, 2026
CVE-2026-27562
Pepperl+Fuchs
ICE2-8IOL-K45P-RJ45
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
September 16, 2026
CVE-2026-27561
Pepperl+Fuchs
ICE2-8IOL-K45P-RJ45
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
September 16, 2026
CVE-2026-27560
Pepperl+Fuchs
ICE2-8IOL-K45P-RJ45
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
September 16, 2026
CVE-2026-27559
Pepperl+Fuchs
ICE2-8IOL-K45P-RJ45
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
September 16, 2026
CVE-2026-27558
Pepperl+Fuchs
ICE2-8IOL-K45P-RJ45
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
September 16, 2026
CVE-2026-27557
Pepperl+Fuchs
ICE2-8IOL-K45P-RJ45
Path Traversal
High
September 16, 2026
CVE-2026-27556
Pepperl+Fuchs
ICE2-8IOL-K45P-RJ45
Improper Control of Filename for Include/Require Statement in PHP Program
High
September 16, 2026
CVE-2026-27555
Pepperl+Fuchs
ICE2-8IOL-K45P-RJ45
Improper Control of Filename for Include/Require Statement in PHP Program
High
September 16, 2026
CVE-2026-27554
Pepperl+Fuchs
ICE2-8IOL-K45P-RJ45
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
September 16, 2026
CVE-2026-27553
Pepperl+Fuchs
ICE2-8IOL-K45P-RJ45
Inclusion of Functionality from Untrusted Control Sphere
Medium
September 16, 2026
CVE-2026-27552
Pepperl+Fuchs
ICE2-8IOL-K45P-RJ45
Incorrect Authorization
High
September 16, 2026
CVE-2026-27551
Pepperl+Fuchs
ICE2-8IOL-K45P-RJ45
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
September 16, 2026
CVE-2026-27550
Pepperl+Fuchs
ICE2-8IOL-K45P-RJ45
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
September 16, 2026
CVE-2026-27549
Pepperl+Fuchs
ICE2-8IOL-K45P-RJ45
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
September 16, 2026
CVE-2026-27548
Pepperl+Fuchs
ICE2-8IOL-K45P-RJ45
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
September 16, 2026
CVE-2026-27547
Pepperl+Fuchs
ICE2-8IOL-K45P-RJ45
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
September 16, 2026
CVE-2026-27546
Pepperl+Fuchs
ICE2-8IOL-K45P-RJ45
Authentication Bypass Using an Alternate Path or Channel
Critical
September 16, 2026
CVE-2026-73177
Advantech
EKI-1242EIMS
Insufficient Verification of Data Authenticity
High
September 16, 2026
CVE-2026-73176
Advantech
EKI-1242EIMS
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
September 16, 2026
CVE-2026-73175
Advantech
EKI-1242EIMS
Uncontrolled Resource Consumption
High
September 16, 2026
CVE-2026-73174
Advantech
EKI-1242EIMS
Cleartext Transmission of Sensitive Information
High
September 16, 2026
CVE-2026-73173
Advantech
EKI-1242EIMS
Missing Authentication for Critical Function
High
September 16, 2026
CVE-2026-73172
Advantech
EKI-1242EIMS
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Critical
September 16, 2026
CVE-2026-73171
Advantech
EKI-1242EIMS
External Control of File Name or Path
High
September 16, 2026
CVE-2026-73170
Advantech
EKI-1242EIMS
Improper Control of Generation of Code ('Code Injection')
High
September 16, 2026
CVE-2026-73169
Advantech
EKI-1242EIMS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Medium
September 16, 2026
CVE-2026-73168
Advantech
EKI-1242EIMS
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
September 16, 2026
CVE-2026-73167
Advantech
EKI-1242EIMS
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
September 16, 2026
CVE-2026-73166
Advantech
EKI-1242EIMS
Improper Control of Generation of Code ('Code Injection')
High
September 16, 2026
CVE-2026-73165
Advantech
EKI-1242EIMS
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
September 16, 2026
CVE-2026-73164
Advantech
EKI-1242EIMS
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
September 16, 2026
CVE-2026-73163
Advantech
EKI-1242EIMS
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
September 16, 2026
CVE-2026-19535
Advantech
EKI-1242EIMS
Cross-Site Request Forgery (CSRF)
High
July 6, 2026
CVE-2026-57472
KUNBUS
RevPi Connect 5
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Medium
July 6, 2026
CVE-2026-57471
KUNBUS
RevPi Connect 5
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Medium
July 6, 2026
CVE-2026-57469
KUNBUS
RevPi Connect 5
Cross-Site Request Forgery (CSRF)
Medium
July 6, 2026
CVE-2026-13198
KUNBUS
RevPi Connect 5
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Medium
July 6, 2026
CVE-2026-13197
KUNBUS
RevPi Connect 5
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
High
July 6, 2026
CVE-2026-13196
KUNBUS
RevPi Connect 5
Out-of-bounds Write
High
July 15, 2026
CVE-2026-56136
Tuxera
ntfs-3g
Out-of-bounds Read
Medium
July 15, 2026
CVE-2026-56135
Tuxera
ntfs-3g
Heap-based Buffer Overflow
High
July 15, 2026
CVE-2026-46572
Tuxera
ntfs-3g
Heap-based Buffer Overflow
High
July 15, 2026
CVE-2026-46571
Tuxera
ntfs-3g
Out-of-bounds Read
Medium
July 15, 2026
CVE-2026-46570
Tuxera
ntfs-3g
Heap-based Buffer Overflow
High
July 15, 2026
CVE-2026-46569
Tuxera
ntfs-3g
Heap-based Buffer Overflow
High
July 15, 2026
CVE-2026-42618
Tuxera
ntfs-3g
Off-by-one Error
High
July 15, 2026
CVE-2026-42617
Tuxera
ntfs-3g
Heap-based Buffer Overflow
High
July 15, 2026
CVE-2026-42616
Tuxera
ntfs-3g
Heap-based Buffer Overflow
High
July 20, 2026
CVE-2026-61378
Automationdirect
ADCUP Usb Driver
Divide By Zero
Medium
July 20, 2026
CVE-2026-60073
Automationdirect
ADCUP Usb Driver
Out-of-bounds Read
Medium
July 20, 2026
CVE-2026-57896
Automationdirect
ADCUP Usb Driver
Out-of-bounds Read
Medium
July 20, 2026
CVE-2026-60140
Automationdirect
ADCUP Usb Driver
Out-of-bounds Read
Medium
July 20, 2026
CVE-2026-61389
Automationdirect
ADCUP Usb Driver
Out-of-bounds Write
High
July 20, 2026
CVE-2026-60063
Automationdirect
ADCUP Usb Driver
Out-of-bounds Write
High
July 6, 2026
CVE-2026-13199
Raspberry Pi
Raspberry Pi 5
Insufficient Entropy
Medium
June 26, 2026
CVE-2026-57473
Reolink
Home Hub
Use of Weak Credentials
Medium
May 27, 2026
CVE-2025-41670
Phoenix Contact
PLCnext family
Uncontrolled Search Path Element
High
May 27, 2026
CVE-2025-41669
Phoenix Contact
PLCnext family
Improper Verification of Cryptographic Signature
High
May 29, 2026
CVE-2025-41281
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
May 29, 2026
CVE-2025-41280
Waterfall
WF-500
Relative Path Traversal
High
May 29, 2026
CVE-2025-41279
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
May 29, 2026
CVE-2025-41278
Waterfall
WF-500
Out-of-bounds Read
High
May 29, 2026
CVE-2025-41277
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Critical
May 29, 2026
CVE-2025-41276
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Critical
May 29, 2026
CVE-2025-41275
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Critical
May 29, 2026
CVE-2025-41274
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Critical
May 29, 2026
CVE-2025-41273
Waterfall
WF-500
Authentication Bypass Using an Alternate Path or Channel
Critical
May 29, 2026
CVE-2025-41272
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Critical
May 29, 2026
CVE-2025-41271
Waterfall
WF-500
Relative Path Traversal
High
May 29, 2026
CVE-2025-41270
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Critical
May 29, 2026
CVE-2025-41269
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Critical
May 29, 2026
CVE-2025-41268
Waterfall
WF-500
Relative Path Traversal
High
May 29, 2026
CVE-2025-41267
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
May 29, 2026
CVE-2025-41266
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
May 29, 2026
CVE-2025-41265
Waterfall
WF-500
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
March 24, 2026
CVE-2025-41660
CODESYS
Codesys Control
Incorrect Resource Transfer Between Spheres
High
March 19, 2026
CVE-2026-22323
Phoenix Contact
FL SWITCH TSN 2312-2GC-2SFP
Cross-Site Request Forgery (CSRF)
High
March 19, 2026
CVE-2026-22322
Phoenix Contact
FL SWITCH TSN 2312-2GC-2SFP
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
High
March 19, 2026
CVE-2026-22318
Phoenix Contact
FL SWITCH TSN 2312-2GC-2SFP
Stack-based Buffer Overflow
Medium
March 19, 2026
CVE-2026-22320
Phoenix Contact
FL SWITCH TSN 2312-2GC-2SFP
Stack-based Buffer Overflow
Medium
March 19, 2026
CVE-2026-22317
Phoenix Contact
FL SWITCH TSN 2312-2GC-2SFP
Improper Neutralization of Special Elements used in a Command ('Command Injection')
High
March 19, 2026
CVE-2026-22319
Phoenix Contact
FL SWITCH TSN 2312-2GC-2SFP
Stack-based Buffer Overflow
Medium
March 19, 2026
CVE-2026-22316
Phoenix Contact
FL SWITCH TSN 2312-2GC-2SFP
Stack-based Buffer Overflow
Medium
March 19, 2026
CVE-2026-22321
Phoenix Contact
FL SWITCH TSN 2312-2GC-2SFP
Stack-based Buffer Overflow
Medium
March 10, 2026
CVE-2026-2273
Schneider Electric
EcoStruxure™ Automation Expert
Improper Control of Generation of Code ('Code Injection')
High
March 11, 2026
CVE-2026-22614
Eaton
EasySoft
Insufficiently Protected Credentials
Medium
March 9, 2026
CVE-2026-3588
Ikea
Dirigera
Server Side Request Forgery
High
February 23, 2026
CVE-2026-26098
Owl
opds
Uncontrolled Search Path Element
High
February 23, 2026
CVE-2026-26101
Owl
opds
Incorrect Permission Assignment for Critical Resource
High
February 23, 2026
CVE-2026-26099
Owl
opds
Uncontrolled Search Path Element
High
February 23, 2026
CVE-2026-26100
Owl
opds
Incorrect Permission Assignment for Critical Resource
Medium
February 23, 2026
CVE-2026-26102
Owl
opds
Incorrect Permission Assignment for Critical Resource
High
February 23, 2026
CVE-2026-26096
Owl
opds
Incorrect Permission Assignment for Critical Resource
High
February 23, 2026
CVE-2026-26094
Owl
opds
Use of Hard-coded Cryptographic Key
High
February 23, 2026
CVE-2026-26095
Owl
opds
Incorrect Permission Assignment for Critical Resource
High
February 23, 2026
CVE-2026-26093
Owl
opds
Improper Neutralization of Special Elements used in a Command ('Command Injection')
High
February 23, 2026
CVE-2026-2333
Owl
opds
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Critical
February 23, 2026
CVE-2026-26097
Owl
opds
Uncontrolled Search Path Element
High
CVE ID
CVE-2026-27564
Vendor
Pepperl+Fuchs
Product
ICE2-8IOL-K45P-RJ45
Date Published
September 16, 2026
Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Risk Score
High
CVE ID
CVE-2026-27563
Vendor
Pepperl+Fuchs
Product
ICE2-8IOL-K45P-RJ45
Date Published
September 16, 2026
Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Risk Score
High
CVE ID
CVE-2026-27562
Vendor
Pepperl+Fuchs
Product
ICE2-8IOL-K45P-RJ45
Date Published
September 16, 2026
Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Risk Score
High
CVE ID
CVE-2026-27561
Vendor
Pepperl+Fuchs
Product
ICE2-8IOL-K45P-RJ45
Date Published
September 16, 2026
Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Risk Score
High
CVE ID
CVE-2026-27560
Vendor
Pepperl+Fuchs
Product
ICE2-8IOL-K45P-RJ45
Date Published
September 16, 2026
Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Risk Score
High
CVE ID
CVE-2026-27559
Vendor
Pepperl+Fuchs
Product
ICE2-8IOL-K45P-RJ45
Date Published
September 16, 2026
Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Risk Score
High
CVE ID
CVE-2026-27558
Vendor
Pepperl+Fuchs
Product
ICE2-8IOL-K45P-RJ45
Date Published
September 16, 2026
Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Risk Score
High
CVE ID
CVE-2026-27557
Vendor
Pepperl+Fuchs
Product
ICE2-8IOL-K45P-RJ45
Date Published
September 16, 2026
Type
Path Traversal
Risk Score
High
CVE ID
CVE-2026-27556
Vendor
Pepperl+Fuchs
Product
ICE2-8IOL-K45P-RJ45
Date Published
September 16, 2026
Type
Improper Control of Filename for Include/Require Statement in PHP Program
Risk Score
High
CVE ID
CVE-2026-27555
Vendor
Pepperl+Fuchs
Product
ICE2-8IOL-K45P-RJ45
Date Published
September 16, 2026
Type
Improper Control of Filename for Include/Require Statement in PHP Program
Risk Score
High
CVE ID
CVE-2026-27554
Vendor
Pepperl+Fuchs
Product
ICE2-8IOL-K45P-RJ45
Date Published
September 16, 2026
Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Risk Score
High
CVE ID
CVE-2026-27553
Vendor
Pepperl+Fuchs
Product
ICE2-8IOL-K45P-RJ45
Date Published
September 16, 2026
Type
Inclusion of Functionality from Untrusted Control Sphere
Risk Score
Medium
CVE ID
CVE-2026-27552
Vendor
Pepperl+Fuchs
Product
ICE2-8IOL-K45P-RJ45
Date Published
September 16, 2026
Type
Incorrect Authorization
Risk Score
High
CVE ID
CVE-2026-27551
Vendor
Pepperl+Fuchs
Product
ICE2-8IOL-K45P-RJ45
Date Published
September 16, 2026
Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Risk Score
High
CVE ID
CVE-2026-27550
Vendor
Pepperl+Fuchs
Product
ICE2-8IOL-K45P-RJ45
Date Published
September 16, 2026
Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Risk Score
High

Take the next step.

Discover how easy it is to identify and respond to cyber threats by automating your OT and IoT asset discovery, inventory and management.