Rockwell Automation ThinManager
2026-07-24T07:23:29Z•39c7c92a69575f683a0b0c89eb298182d5e5977a439afbb74436acd188808f2d
buffer-overflowcisacleartext-storagecredential-exposuredosicsjohnson-controlsmz-automationotpanduitpath-traversalprivilege-escalationrcessrfthinmanagervulnerabilityweintek
What happened
CISA published multiple ICS/OT advisories (23 Jul 2026) covering high‑impact vulnerabilities across several vendors. Affected products include Rockwell Automation ThinManager (path traversal allowing authenticated arbitrary file writes — CVE-2026-11917, CVSSv3 8.1), Weintek cMT3092X (cookie manipulation leading to privilege escalation/credential exposure — CVE-2026-60134, CVSSv3 8.8), Johnson Controls C‑CURE 9000 and victor (SSRF and unnecessary-privilege execution enabling remote code execution — CVE-2026-21655, CVSSv3 9.6), Johnson Controls XAAP Android (cleartext storage of sensitive data —
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ics_advisories
- Record identifier
- 39c7c92a69575f683a0b0c89eb298182d5e5977a439afbb74436acd188808f2d
- Enrichment time
- 2026-07-24T07:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.