[Control systems] CISA ICS security advisories (AV26-297)

Serial number: AV26-297
Date: March 30, 2026

Between March 23 and 29, 2026, CISA published ICS advisories to address vulnerabilities in the following products:

  • Grassroots DICOM (GDCM) – version 3.2.2
  • Pharos Controls Mosaic Show Controller – firmware version 2.15.3
  • OpenCode Systems OC Messaging and USSD Gateway – version 6.32.2
  • PTC Windchill Product Lifecycle Management – multiple versions and models
  • Schneider Electric EcoStruxure Foxboro DCS – versions prior to CS8.1
  • Schneider Electric Plant iT/Brewmaxx – version 9.60_and_above
  • WAGO GmbH & Co. KG Industrial Managed Switches – multiple firmware version

The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.

Date modified: