OT-ISAC Advisory Exposes Critical Flaws Across Industrial Control and Management Systems

A new OT-ISAC vulnerability advisory underscores the breadth and severity of cyber risk across industrial environments, consolidating multiple April 2026 disclosures affecting everything from legacy field controllers and PLC ecosystems to industrial wireless infrastructure, network management platforms, and remote-access systems.

The report identifies several critical issues, including an obsolete BASControl20 controller with no available fix, authorization bypass flaws in AVEVA pipeline simulation software, weak password protections in Horner PLC workflows, and management-plane vulnerabilities across Siemens industrial networking products, all of which expose OT (operational technology) environments to unauthenticated or weakly authenticated access, protocol abuse, and credential compromise.

While no active exploitation had been reported at the time of publication, OT-ISAC warns that the overall risk remains high due to the potential operational impact, spanning process safety, industrial communications, engineering workstations, and OT-adjacent systems such as physical access controls.

Read the rest of the story at Industrial Cyber.

The Government Technology & Services Coalition's Homeland Security Today (HSToday) is the premier news and information resource for the homeland security community, dedicated to elevating the discussions and insights that can support a safe and secure nation. A non-profit magazine and media platform, HSToday provides readers with the whole story, placing facts and comments in context to inform debate and drive realistic solutions to some of the nation’s most vexing security challenges.

Related Articles

Latest Articles