official data

CISA OT drop: Ignition CVSS 8.8 plus Rockwell ENBT DoS — Sep 3 ICS batch

Lane: aiWashington, District of Columbia, USA

The Cybersecurity and Infrastructure Security Agency published multiple industrial control systems advisories dated 3 September 2026, including ICSA-26-246-06 for Inductive Automation Ignition and ICSA-26-246-05 for the Rockwell Automation 1756-ENBT Module, plus other OT products such as Tycon and IXON VPN Client. ICSA-26-246-06 covers Ignition versions ≤8.1.53 (CVE-2026-77393, Incorrect Default Permissions): the Gateway “Create Project Role(s)” setting shipped blank, permitting any authenticated user to create projects if they can execute gateway scripts; CVSS v3 score 8.8 (HIGH); affected sectors include Critical Manufacturing, Energy, and Information Technology worldwide. Inductive Automation fixed the issue in 8.1.54 and later (8.3 series not affected); users on earlier 8.1 releases can remediate by setting Create Project Role(s) to match Designer Role. ICSA-26-246-05 covers Rockwell 1756-ENBT module all versions (CVE-2025-10478): a crafted CIP packet can crash the ControlLogix EtherNet/IP bridge and require a restart; CVSS v3 7.5; Rockwell recommends upgrade to 1756-EN2T or 1756-EN4TR. Both advisories state that no known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.

Assumed place pin at Washington, D.C. — CISA ICS advisory publisher location; not an exploited-site coordinate. Source map

Key facts

Batch date
CISA ICS advisories dated 3 Sep 2026
Ignition (ICSA-26-246-06)
≤8.1.53; CVE-2026-77393 Incorrect Default Permissions; CVSS v3 8.8 HIGH; fixed in 8.1.54+
Ignition issue
Gateway “Create Project Role(s)” shipped blank — authenticated users able to create projects if they can execute gateway scripts
Rockwell ENBT (ICSA-26-246-05)
1756-ENBT all versions; CVE-2025-10478; crafted CIP packet can crash EtherNet/IP bridge; CVSS v3 7.5; upgrade to 1756-EN2T or 1756-EN4TR
Exploitation status
No known public exploitation specifically targeting these vulnerabilities reported to CISA at this time
Sectors (Ignition advisory)
Critical Manufacturing, Energy, IT — worldwide

Note

Primary source preference: CISA ICSA-26-246-06 and ICSA-26-246-05. CVE identifiers, CVSS scores, and remediation lines are from those advisories. Doom Signals does not invent exploit status beyond CISA’s “no known public exploitation” statement.

Distinct from cisa-kev-litellm-sonicwall-sma1000-2026-09-02 (active-exploitation KEV) and cisa-communicating-under-pressure-ot-outages-2026-09-02 (comms playbook): this note centers the fresh 3 Sep ICS/OT batch on widely deployed Ignition SCADA and Rockwell ENBT.

  • Advisories: ICSA-26-246-06 / ICSA-26-246-05
  • Place pin: Washington, District of Columbia, USA (CISA)
  • Coords basis: estimated_centroid 38.9072, −77.0369

Why it matters

Brand-new 3 Sep 2026 CISA ICS/OT advisory batch — Ignition CVSS 8.8 default-permissions flaw plus Rockwell ENBT remote DoS — an AI/OT lane signal beyond the Sep 2 KEV catalog add and OT communications playbook.

Sources

Official data. Not a forecast.

← Daily board