CISA Published 11 ICS Advisories July 30 Covering 27 CVEs Across Nine Vendors
CISA released 11 Industrial Control Systems advisories on July 30, 2026, addressing 27 CVEs in products from Rockwell Automation, Mitsubishi Electric, NASA, MZ Automation, and others; none of the CVEs appear in CISA's Known Exploited Vulnerabilities catalog. A separate Gardyn IoT Hub advisory from July 2 carries a CVSS 10.0 critical flaw in which an exposed privileged key allows unauthenticated access to all connected device credentials and arbitrary command execution. Gardyn states it deployed fixes in February 2026, and no exploitation of any vulnerability across either batch has been reported.