🇮🇳 India Regulatory Feed
India Regulatory Updates
Live circulars, advisories and policy updates from RBI, SEBI, CERT-In, MeitY, NPCI, and IRDAI — relevant to cybersecurity and data protection compliance.
215 updates
In June 2026 the IETF published RFC 10008[1], defining a new HTTP method: "QUERY". The HTTP protocol faced already by changes (HTTP/2, HTTP/3) but it's the first new standard HTTP verb since "PATCH" in 2010!
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2025-39964 Linux Kernel Race Condition Vulnerability
CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 furth
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectation
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached requirements and provide a price quotation for a fiber optic system and appeared to impersonate an employee of a legitimate company.
 
 The receiving gateway quarantined the message because it detected malicious content in the attachment, though even if it didn’t, the e-mail would not have gotten much further due to failed SPF and DMARC checks.
View CSAF
Summary
Successful exploitation of this vulnerability could allow a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, destroy, or delete control programs.
The following versions of Mitsubishi Electric GX Works3 and Motion Control Settings are affected:
Mitsubishi Electric GX Works3 vers:all/* (CVE-2026-15688)
Mitsubishi Electric Motion Control Settings (Software packaged with GX Works3) vers:all/* (CVE-2026-15688)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.8
Mitsubishi Electric
Mitsubishi Electric GX Works3 and Motion Control Settings
Incorrect Implementation of Authentication Algorithm
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Japan
Vulnerabilities
Expand All +
CVE-2026-15688
Incorrect Implementati
View CSAF
Summary
Hitachi Energy is aware of vulnerabilities that affect the FACTS Control systems with GWS component listed in this document. An attacker exploiting these vulnerabilities can cause impact on confidentiality, integrity and availability of the product. Following FACTS Control systems with GWS component deployed from year 2020 onwards are likely affected by the above vulnerabilities. Product deployments without GWS component are not affected. • SVC Light (STATCOM) • Fixed Series Capacitor • Thyristor Controlled Series Capacitor • Static Var Compensator • Static Watt Compensator • Hybrid Synchronous Condensers Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The affected FCP versions are only applicable if GWS component is present.
The following versions of Hitachi Energy FACTS Control Platform (FCP) are affected:
FACTS Control Platform (FCP) 3.4.0, 3.7.0, 3.8.0, 3.10.0, 3.12.0, 3.14.0, 3.15.0, 4.0.0, 4.0.1, 4
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware.
The following versions of Bransys ELD are affected:
Android <11.00.00 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960)
iOS <1.1.54 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.5
Bransys
Bransys ELD
Use of Hard-coded Credentials, Cleartext Transmission of Sensitive Information
Background
Critical Infrastructure Sectors: Transportation Systems
Countries/Areas Deployed: United States
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-86520
The affected product is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.
View CVE Details
Affected Products
Bransys ELD
Vendor:Bransys
Product Version:Bransys Android: <11.00.00, Bransys
View CSAF
Summary
Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 – 750/755 products.The NetBotz 5 – 750/755 products are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capabilities. Failure to apply the remediation provided below may risk arbitrary or remote code execution over the local network, which could result in device manipulation and unauthorized data access.
The following versions of Schneider Electric NetBotz 5 750/755 are affected:
NetBotz 5 750 vers:intdot/<=5.5.2 (CVE-2026-13336, CVE-2026-13337)
NetBotz 5 755 vers:intdot/<=5.5.2 (CVE-2026-13336, CVE-2026-13337)
CVSS
Vendor
Equipment
Vulnerabilities
v3 6.4
Schneider Electric
Schneider Electric NetBotz 5 750/755
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), SQL Injection: Hibernate
Background
Critical Infrastructure Sectors: Commercial Facilities, Critical
View CSAF
Summary
Schneider Electric is aware of a vulnerability in its Modicon M340 https://www.se.com/ww/en/product-range/1468-modicon-m340-pac/, BMXNOR0200H https://www.se.com/us/en/product/BMXNOR0200H/communication-module-modicon-m340-iec-608705101-104-dnp3-for-severe-environments/: Modicon M340 X80 Ethernet Communication Modules, BMXNGD0100 https://www.se.com/us/en/product/BMXNGD0100/communication-module-modicon-m580-global-data-service/: M580 Global Data module, BMXNOC0401 https://www.se.com/us/en/product/BMXNOC0401/network-module-modicon-m340-ethernet-ip-and-modbus-tcp-4-x-rj45/?pageType=product&sourceId=BMXNOC0401: Modicon M340 X80 Ethernet Communication modules, BMXNOE0100 https://www.se.com/ww/en/product/BMXNOE0100/network-module-modicon-m340-modbus-tcp-1-x-rj45-flash-memory-card/?pageType=product&sourceId=BMXNOE0100: Modbus/TCP Ethernet Modicon M340 module, BMXNOE0110 https://www.se.com/ww/en/product/BMXNOE0110/ethernet-tcp-ip-network-module-modicon-m340-automation-platform-
View CSAF
Summary
Schneider Electric is aware of vulnerabilities in its PowerChute Serial Shutdown product. The PowerChute Serial Shutdown product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktops, servers and workstations. Failure to apply the remediation provided below may risk improper authentication validation which could result in disruption of operations and access to system data.
The following versions of Schneider Electric PowerChute Serial Shutdown are affected:
PowerChute Serial Shutdown vers:intdot/<=1.5, 1.6 (CVE-2026-13348)
CVSS
Vendor
Equipment
Vulnerabilities
v3 5.3
Schneider Electric
Schneider Electric PowerChute Serial Shutdown
Improper Restriction of Excessive Authentication Attempts
Background
Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy, Information Technology
Countries/Areas Deployed: Worldwide
Company Headquarters Location: France
Vulnerabilities
View CSAF
Summary
ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete control of the system
The following versions of ABB Ability Edgenius are affected:
Ability Edgenius >=3.2.0.0|<3.2.4.1, 3.2.4.1 (CVE-2026-31431)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.8
ABB
ABB Ability Edgenius
Incorrect Resource Transfer Between Spheres
Background
Critical Infrastructure Sectors: Critical Manufacturing, Energy, Water and Wastewater, Chemical
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Switzerland
Vulnerabilities
Expand All +
CVE-20
Our view of good cyber adversary simulation – and how assured providers can deliver it.
Adversary simulation ('red teaming') tests your ability to prevent, detect and respond to cyber attacks.
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Earlier today, I noted an odd request showing up in our "First Seen" report:
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-58704 Google Pixel Improper Authorization Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-76460 Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
CVE-2026-87886 Acronis Backup Incorrect Default Permissions Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action
CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data. Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to distract adversaries, detect their presence, or facilitate collection of cyber threat intelligence (CTI). As organizations adopt Zero Trust models, they should assume that a malicious threat actor may gain some level of access to their environment and plan accordingly.
Cyber decoys complement Zero Trust by:
Supporting continuous monitoring and verification,
Creating high-fidelity alerts for suspicious activity,
Reducing alert fatigue, and
Helping defenders detect p
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
I have not done this type of diary in a while: What traffic will you see from a system on boot, before a user logs in? I just took a quick look at macOS 27 "Golden Gate" to see what traffic you should expect. Here are some of the highlights:
Developed by the National Institute of Standards and Technology (NIST) and CISA, this interagency report provides federal agencies and cloud service providers with guidelines to protect the identity assertions, access tokens, and cryptographic mechanisms that support modern authentication and authorization. As agencies adopt hybrid and multi-cloud environments, single sign-on, federation, and application programming interface (API)-based access increasingly depend on signed tokens and assertions that adversaries may target for forgery, theft, and misuse to move laterally across enterprise networks and access sensitive data.
This final report updates the initial public draft and incorporates feedback on token validation, secrets management, and detection at scale, as well as input from government and industry experts that CISA gathered through its Joint Cyber Defense Collaborative. The report expands on NIST Special Publication Security and Privacy Controls for Information Systems and O
View CSAF
Summary
Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a network pivot point.
The following versions of Digital Watchdog VMAX DVR and NVR Product Lineups are affected:
VMAX A1 G4 DVRs vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372)
VMAX IP G4 NVRs vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372)
VMAX A1 PLUS vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372)
VA1G4 Recorder vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372)
VG4 Recorder vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372)
CVSS
Vendor
Equipment
Vulnerabilit
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem.
The following versions of mySCADA myPRO Manager are affected:
mySCADA myPRO Manager <=2.1 (CVE-2026-73807, CVE-2026-82567)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.8
mySCADA Technologies
mySCADA myPRO Manager
Missing Authorization, Missing Authentication for Critical Function
Background
Critical Infrastructure Sectors: Critical Manufacturing, Energy, Food and Agriculture, Transportation Systems, Water and Wastewater
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Czechia
Vulnerabilities
Expand All +
CVE-2026-73807
The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management func
View CSAF
Summary
Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and SCADAPack 57x products are Remote Terminal Units that provide communication capabilities for remote monitoring and control. Failure to apply the mitigations provided below may increase the risk of unauthorized access to RTU configuration through the Secure Lock functionality, potentially resulting in a loss of confidentiality.
The following versions of Schneider Electric SCADAPack x70 Products are affected:
SCADAPack 47x vers:all/* (CVE-2026-81861)
SCADAPack 47xi vers:all/* (CVE-2026-81861)
SCADAPack 47xd vers:all/* (CVE-2026-81861)
SCADAPack 470R vers:all/* (CVE-2026-81861)
SCADAPack 57x vers:all/* (CVE-2026-81861)
SCADAPack 3xx vers:all/* (CVE-2026-81861)
SCADAPack 32 vers:all/* (CVE-2026-81861)
CVSS
Vendor
Equipment
Vulnerabilities
v3 6.5
Schneider Electric
Schneider Electric SCADAPack x70 Products
Insufficien
View CSAF
Summary
A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user's session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim's Teamcenter session. Siemens has released new versions for the affected products and recommends to update to the latest versions.
The following versions of Siemens Teamcenter are affected:
Teamcenter V2412 vers:intdot/<2412.0013 (CVE-2026-58113)
Teamcenter V2506 vers:intdot/<2506.0010 (CVE-2026-58113)
Teamcenter V2512 vers:intdot/<2512.2607 (CVE-2026-58113)
Teamcenter V2606 vers:intdot/<2606.2607 (CVE-2026-58113)
CVSS
Vendor
Equipment
Vulnerabilities
v3 6.1
Siemens
Siemens Teamcenter
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Background
Critical Infrastructure Sectors: Critical Manufa
View CSAF
Summary
Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version.
The following versions of Siemens Mendix SAML are affected:
Mendix SAML (Mendix 10 compatible) vers:intdot/<4.2.3 (CVE-2026-80465)
Mendix SAML (Mendix 11 compatible) vers:intdot/<4.2.3 (CVE-2026-80465)
Mendix SAML (Mendix 9.24 compatible) vers:intdot/<3.6.27 (CVE-2026-80465)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.7
Siemens
Siemens Mendix SAML
Improper Verification of Cryptographic Signature
Background
Critical Infrastructure Sectors: Critical Manufacturing, Information Technology
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-80465
Affected versions of the module do not properly validate the SAML response signature. This could al
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to deliver an unauthorized update, execute code, or extract credentials to allow the attacker to impersonate a privileged client.
The following versions of Wärtsilä FOS-Onboard are affected:
FOS-Onboard 5.07.0923.01 (CVE-2026-78225, CVE-2026-81855)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.1
Wärtsilä
Wärtsilä FOS-Onboard
Use of Hard-coded Cryptographic Key
Background
Critical Infrastructure Sectors: Transportation Systems
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Finland
Vulnerabilities
Expand All +
CVE-2026-78225
A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.
View CVE Details
Affected Products
Wärtsilä FOS-Onboard
Vendor:Wärtsilä
Product Version:Wärtsilä FOS-Onboard: 5.07.0923.01
Product Status:known_affected
Remediations
MitigationWärtsilä states t
View CSAF
Summary
Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version.
The following versions of Siemens Reyrolle 7SR5 are affected:
Reyrolle 7SR5 vers:intdot/<2.70 (CVE-2024-42384, CVE-2024-42385, CVE-2024-42386, CVE-2024-42391, CVE-2024-42392, CVE-2026-62645, CVE-2026-62646, CVE-2026-62647, CVE-2026-62648, CVE-2026-62649, CVE-2026-62650, CVE-2026-62652, CVE-2026-62653, CVE-2026-62654)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.8
Siemens
Siemens Reyrolle 7SR5
Integer Overflow or Wraparound, Improper Neutralization of Delimiters, Use of Out-of-range Pointer Offset, Missing Authentication for Critical Function, Insufficient Entropy, Improper Input Validation, Out-of-bounds Write, Allocation of Resources Without Limits or Throttling, Authentication Bypass Using an Alternate Path or Channel, Insertion of Sensitive Information Into Debugging Code, Download o
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to access live video and sensitive device information, enable unauthorized services, execute arbitrary code, modify device operation, and recover stored credentials.
The following versions of CareCam CM2507 are affected:
HMT.CM2507 Firmware v251211.1507 (CVE-2026-88259, CVE-2026-84398, CVE-2026-84400, CVE-2026-81305, CVE-2026-85478, CVE-2026-85497, CVE-2026-81321)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.5
CareCam
CareCam CM2507
Missing Authentication for Critical Function, Empty Password in Configuration File, Inclusion of Functionality from Untrusted Control Sphere, Use of Password Hash With Insufficient Computational Effort, Cleartext Storage of Sensitive Information
Background
Critical Infrastructure Sectors: Commercial Facilities
Countries/Areas Deployed: Worldwide
Company Headquarters Location: China
Vulnerabilities
Expand All +
CVE-2026-88259
CareCam CM2507 IP cameras
Sources
RBI
0
SEBI
0
CERT-In
0
MeitY
0
NPCI
0
IRDAI
0