Rockwell Automation ThinManager

2026-07-24T07:23:29Z39c7c92a69575f683a0b0c89eb298182d5e5977a439afbb74436acd188808f2d
buffer-overflowcisacleartext-storagecredential-exposuredosicsjohnson-controlsmz-automationotpanduitpath-traversalprivilege-escalationrcessrfthinmanagervulnerabilityweintek

What happened

CISA published multiple ICS/OT advisories (23 Jul 2026) covering high‑impact vulnerabilities across several vendors. Affected products include Rockwell Automation ThinManager (path traversal allowing authenticated arbitrary file writes — CVE-2026-11917, CVSSv3 8.1), Weintek cMT3092X (cookie manipulation leading to privilege escalation/credential exposure — CVE-2026-60134, CVSSv3 8.8), Johnson Controls C‑CURE 9000 and victor (SSRF and unnecessary-privilege execution enabling remote code execution — CVE-2026-21655, CVSSv3 9.6), Johnson Controls XAAP Android (cleartext storage of sensitive data —

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ics_advisories
Record identifier
39c7c92a69575f683a0b0c89eb298182d5e5977a439afbb74436acd188808f2d
Enrichment time
2026-07-24T07:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Rockwell Automation ThinManager · Baitaphish