A new OT-ISAC vulnerability advisory underscores the breadth and severity of cyber risk across industrial environments, consolidating multiple April 2026 disclosures affecting everything from legacy field controllers and PLC ecosystems to industrial wireless infrastructure, network management platforms, and remote-access systems.
The report identifies several critical issues, including an obsolete BASControl20 controller with no available fix, authorization bypass flaws in AVEVA pipeline simulation software, weak password protections in Horner PLC workflows, and management-plane vulnerabilities across Siemens industrial networking products, all of which expose OT (operational technology) environments to unauthenticated or weakly authenticated access, protocol abuse, and credential compromise.
While no active exploitation had been reported at the time of publication, OT-ISAC warns that the overall risk remains high due to the potential operational impact, spanning process safety, industrial communications, engineering workstations, and OT-adjacent systems such as physical access controls.
Read the rest of the story at Industrial Cyber.


