Full Report
[Control systems] CISA ICS security advisories (AV26–102)
Analysis Summary
This summary synthesizes the vulnerabilities highlighted in CISA ICS Advisory AV26-102, covering various products across multiple vendors.
# Vulnerability: Multiple Vulnerabilities in Various Industrial Control Systems (CISA AV26-102)
## CVE Details
*Note: Specific CVE identifiers and CVSS scores are *not* provided in the CISA advisory summary. This information is typically detailed in the linked CISA advisories.*
- CVE ID: N/A (Multiple required review)
- CVSS Score: N/A
- CWE: N/A
## Affected Systems
- Products:
* Aviation Light Engine Pro
* Hitachi Energy FOX61x
* Hitachi Energy XMC20
* Ilevia EVE X1 Server
* Mitsubishi Electric MELSEC iQ-R R08/16/32/120PCPU
* Mitsubishi Electric FREQSHIP-mini for Windows
* o6 Automation GmbH Open62541
* RISS SRL MOMA Seismic Station
* Synectix LAN 232 TRIO
* TP-Link Systems Inc. VIGI Series IP Camera
- Versions:
* Aviation Light Engine Pro: All versions
* Hitachi Energy FOX61x: Versions R18 and R17A and prior
* Hitachi Energy XMC20: Versions R17A and prior
* Ilevia EVE X1 Server: Prior to 4.7.18.0
* Mitsubishi Electric MELSEC iQ-R R08/16/32/120PCPU: Firmware version 48 and prior
* Mitsubishi Electric FREQSHIP-mini for Windows: Versions 8.0.0 to 8.0.2
* o6 Automation GmbH Open62541: Versions 1.5-rc1 to versions prior to 1.5-rc2
* RISS SRL MOMA Seismic Station: Versions 2.4.2520 and prior
* Synectix LAN 232 TRIO: All versions
* TP-Link Systems Inc. VIGI Series IP Camera: Multiple versions and models
- Configurations: N/A (Varies by specific product vulnerability)
## Vulnerability Description
CISA published multiple ICS security advisories between February 2 and February 8, 2026 (AV26-102), addressing various security flaws impacting the listed control system products. The technical details, including specific flaw types (e.g., RCE, buffer overflows), are contained within the individual advisories linked by CISA.
## Exploitation
- Status: Under review (Specific statuses for each CVE are not detailed in the summary, users must check individual advisories.)
- Complexity: N/A
- Attack Vector: N/A
## Impact
*Note: Impact levels are product and vulnerability dependent and require consulting the CISA advisories.*
- Confidentiality: N/A
- Integrity: N/A
- Availability: N/A
## Remediation
### Patches
Users are strongly encouraged to review the linked CISA advisories to identify and apply available updates/patches for their specific affected products. (Specific patch versions are not listed in this summary overview.)
### Workarounds
Users should perform suggested mitigations as outlined in the linked CISA advisories if immediate patching is not possible.
## Detection
- Indicators of compromise: N/A (Requires consulting specific advisories)
- Detection methods and tools: N/A
## References
- Vendor advisories: Not provided directly, rely on CISA list.
- Relevant links - defanged:
* CISA ICS Advisories: hxxps://www.cisa.gov/news-events/cybersecurity-advisories
* CISA Advisory AV26-102 Source: (Link not provided in the clean text subset, refer to the original source for navigation)