Severity: HighAction: Mitigate

Hitachi Energy REB500

View CSAF Summary Hitachi Energy is aware of open-source software vulnerabilities that affect REB500 product versions listed in this document. These vulnerabilities can be exploited to carry out Denial of Service (DoS) attack on the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of Hitachi Energy REB500 are affected: REB500…

Excerpt from the primary source: CISA Cybersecurity Advisories

Who is affected

Developers · Critical infrastructure

What you should do · Mitigate

No complete fix is indicated yet. Apply the vendor's recommended workarounds for the affected products, limit exposure (for example, restrict internet access to management interfaces) and watch for a patch.

Automated guidance based on this story's classification. Check the linked advisories for specifics.

Sources

We link to original and authoritative sources. Headlines and excerpts belong to their publishers.

Government advisory

Hitachi Energy REB500 CISA Cybersecurity Advisories · cisa.gov · Oct 6, 2026 · Primary source
Severity: HighAction: Mitigate

Hitachi Energy Asset Suite

View CSAF Summary Hitachi Energy is aware of unauthenticated servlet access vulnerabilities that affect Asset Suite product versions listed in this document. These vulnerabilities can be exploited to potentially cause confidentiality, integrity and availability impact on the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of…

Mitigate

No complete fix is indicated yet.

Severity: ElevatedAction: Be aware

Johnson Controls EasyIO FG

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device. The following versions of Johnson Controls EasyIO FG are affected: EasyIO FG firmware <=2.0b52 (CVE-2026-27872, CVE-2026-27873) CVSS Vendor Equipment v3 7.7 Johnson Controls EasyIO FG firmware 2 Vulnerabilities Use of Hard-coded Credentials, Improper Privilege…

Severity: HighAction: Review

Savannah lwIP SMTP client

View CSAF Summary Successful exploitation of this vulnerability could crash the device being accessed; a buffer overflow condition may allow remote code execution. The following versions of Savannah lwIP SMTP client are affected: lwIP SMTP client 2.2.1 (CVE-2026-15340) CVSS Vendor Equipment v3 9.8 Savannah lwIP SMTP client 1 Vulnerability Buffer Copy without Checking Size of Input ('Classic Buffer…