official data
CISA OT drop: Ignition CVSS 8.8 plus Rockwell ENBT DoS — Sep 3 ICS batch
The Cybersecurity and Infrastructure Security Agency published multiple industrial control systems advisories dated 3 September 2026, including ICSA-26-246-06 for Inductive Automation Ignition and ICSA-26-246-05 for the Rockwell Automation 1756-ENBT Module, plus other OT products such as Tycon and IXON VPN Client. ICSA-26-246-06 covers Ignition versions ≤8.1.53 (CVE-2026-77393, Incorrect Default Permissions): the Gateway “Create Project Role(s)” setting shipped blank, permitting any authenticated user to create projects if they can execute gateway scripts; CVSS v3 score 8.8 (HIGH); affected sectors include Critical Manufacturing, Energy, and Information Technology worldwide. Inductive Automation fixed the issue in 8.1.54 and later (8.3 series not affected); users on earlier 8.1 releases can remediate by setting Create Project Role(s) to match Designer Role. ICSA-26-246-05 covers Rockwell 1756-ENBT module all versions (CVE-2025-10478): a crafted CIP packet can crash the ControlLogix EtherNet/IP bridge and require a restart; CVSS v3 7.5; Rockwell recommends upgrade to 1756-EN2T or 1756-EN4TR. Both advisories state that no known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.
Key facts
- Batch date
- CISA ICS advisories dated 3 Sep 2026
- Ignition (ICSA-26-246-06)
- ≤8.1.53; CVE-2026-77393 Incorrect Default Permissions; CVSS v3 8.8 HIGH; fixed in 8.1.54+
- Ignition issue
- Gateway “Create Project Role(s)” shipped blank — authenticated users able to create projects if they can execute gateway scripts
- Rockwell ENBT (ICSA-26-246-05)
- 1756-ENBT all versions; CVE-2025-10478; crafted CIP packet can crash EtherNet/IP bridge; CVSS v3 7.5; upgrade to 1756-EN2T or 1756-EN4TR
- Exploitation status
- No known public exploitation specifically targeting these vulnerabilities reported to CISA at this time
- Sectors (Ignition advisory)
- Critical Manufacturing, Energy, IT — worldwide
Note
Primary source preference: CISA ICSA-26-246-06 and ICSA-26-246-05. CVE identifiers, CVSS scores, and remediation lines are from those advisories. Doom Signals does not invent exploit status beyond CISA’s “no known public exploitation” statement.
Distinct from cisa-kev-litellm-sonicwall-sma1000-2026-09-02 (active-exploitation KEV) and cisa-communicating-under-pressure-ot-outages-2026-09-02 (comms playbook): this note centers the fresh 3 Sep ICS/OT batch on widely deployed Ignition SCADA and Rockwell ENBT.
- Advisories: ICSA-26-246-06 / ICSA-26-246-05
- Place pin: Washington, District of Columbia, USA (CISA)
- Coords basis: estimated_centroid 38.9072, −77.0369
Why it matters
Brand-new 3 Sep 2026 CISA ICS/OT advisory batch — Ignition CVSS 8.8 default-permissions flaw plus Rockwell ENBT remote DoS — an AI/OT lane signal beyond the Sep 2 KEV catalog add and OT communications playbook.
Sources
Official data. Not a forecast.