🇮🇳 India Regulatory Feed
India Regulatory Updates
Live circulars, advisories and policy updates from RBI, SEBI, CERT-In, MeitY, NPCI, and IRDAI — relevant to cybersecurity and data protection compliance.
215 updates
View CSAF
Summary
Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover.
The following versions of Rockwell Automation 1756-ENBT Module are affected:
1756-ENBT module vers:all/* (CVE-2025-10478)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.5
Rockwell Automation
Rockwell Automation 1756-ENBT Module
Improper Check for Unusual or Exceptional Conditions
Background
Critical Infrastructure Sectors: Critical Manufacturing, Food and Agriculture, Transportation Systems, Water and Wastewater
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2025-10478
A denial-of-service security issue exists in the Rockwell Automation 1756-ENBT module which is a ControlLogix EtherNet/IP bridge that enables communication between Logix 5000 controllers and Ethernet devices. An attacker could exploit this vulnerability by sending a crafted CIP packet, causing the module to cras
View CSAF
Summary
Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.
The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected:
TPDIN-Monitor-WEB2 <2.4.5 (CVE-2026-61884, CVE-2026-55985)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.8
Tycon Systems
Tycon Systems TPDIN-Monitor-WEB2
Missing Authentication for Critical Function, Cleartext Storage of Sensitive Information
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-61884
The device ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without
View CSAF
Summary
Successful exploitation of this vulnerability could allow any authenticated user to create projects.
The following versions of Inductive Automation Ignition are affected:
Ignition <=8.1.53 (CVE-2026-77393)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.8
Inductive Automation
Inductive Automation Ignition
Incorrect Default Permissions
Background
Critical Infrastructure Sectors: Critical Manufacturing, Energy, Information Technology
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-77393
In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected.
View CVE Details
Affected Products
Inductive Automation Ignition
Vendor:Inductive
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands.
The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected:
UA-LDS-Installers <1.04.420 (CVE-2026-77477)
CVSS
Vendor
Equipment
Vulnerabilities
v3 4.6
OPCFoundation
OPCFoundation OPC UA LocalDiscoveryServer (LDS)
Execution with Unnecessary Privileges
Background
Critical Infrastructure Sectors: Chemical, Energy, Food and Agriculture, Water and Wastewater, Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-77477
An attacker can intercept a high-privilege console window launched during installation of the LDS. The attacker must be able to launch an installer with elevated privileges and have access to the keyboard and display while the installation is taking place.
View CVE D
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information.
The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected:
TPDIN-Monitor-WEB3 <=2.2.9 (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.8
Tycon Systems
Tycon Systems TPDIN-Monitor-WEB3
Use of Hard-coded Credentials, Cross-Site Request Forgery (CSRF), Missing Authorization
Background
Critical Infrastructure Sectors: Critical Manufacturing, Energy
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-77847
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Use of Hard-coded Credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.
View CVE Details
Affected Produ
View CSAF
Summary
Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution systems. The Easergy MiCOM P30 is a family of multifunction protection and control relays designed for medium, high and extra high voltage electrical networks. The Easergy MiCOM P40 is a protection relay series for Medium Voltage, High Voltage and Extra High Voltage protection. The Easergy MiCOM C264 is a modular and compact substation or bay controller, smart RTU and MV one box solution The EcoStruxure Power Automation System Gateway (EPAS=GTW) is a scalable, interoperable, and rugged communication gateway that helps to remotely monitor and operate electrical processes The EcoStruxure Power Automation System User Interface (EPAS-UI) product is an HMI SCADA designed for electrical networks and substations operations. The EcoStruxure Power Automa
View CSAF
Summary
Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.
The following versions of Rockwell Automation ControlFLASH are affected:
ControlFLASH <=V15.07 (CVE-2026-12663)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.3
Rockwell Automation
Rockwell Automation ControlFLASH
Missing Authentication for Critical Function
Background
Critical Infrastructure Sectors: Critical Manufacturing, Energy, Water and Wastewater
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-12663
A security issue exists within ControlFLASH, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker's
View CSAF
Summary
Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page.
The following versions of Rockwell Automation ArmorStart LT are affected:
ArmorStart LT <=v2.001 (CVE-2026-19471, CVE-2026-19472)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.5
Rockwell Automation
Rockwell Automation ArmorStart LT
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Allocation of Resources Without Limits or Throttling
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-19471
Multiple stored cross-site scripting security issues exist within ArmorStart LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, allowing an attacker
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges.
The following versions of IXON VPN Client are affected:
VPN Client <1.4.7 (CVE-2026-75925)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.6
IXON
IXON VPN Client
Improper Neutralization of CRLF Sequences ('CRLF Injection')
Background
Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy, Information Technology, Water and Wastewater
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Netherlands
Vulnerabilities
Expand All +
CVE-2026-75925
Improper Neutralization of CRLF Sequences (CWE-93) in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralised,
CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to protect sensitive data, authentication systems, and critical assets from emerging quantum computing threats.
The G7 Cyber Security Working Group’s call to action outlines five priorities for a successful transition to PQC:
Raising awareness of quantum risks and the importance of PQC;
Developing national strategies that support PQC adoption and integration;
Advancing research and development for quantum-safe technologies;
Fostering public-private partnerships to share expertise and resources; and
Integrating PQC into cybersecurity requirements and procurement processes.
Please share your thoughts!
We welcome your feedback.
CISA PRODUCT SURVEY
View CSAF
Summary
Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.
The following versions of Pyramid Solutions NetStaX EtherNet/IP Stack are affected:
EtherNet/IP Adapter DLL Kit (EIPA)
EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE)
EtherNet/IP Adapter Development Kit (EADK)
EtherNet/IP Adapter Development Kit with CIP Security (EADK-SECURE)
EtherNet/IP Scanner DLL Kit (EIPS)
EtherNet/IP Scanner DLL Kit with CIP Security (EIPS-SECURE)
EtherNet/IP Scanner Development Kit (ESDK)
EtherNet/IP Scanner Development Kit with CIP Security (ESDK-SECURE)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.8
Pyramid Solutions
Pyramid Solutions NetStaX EtherNet/IP Stack
Stack-based Buffer Overflow
Background
Critical Infrastructure Sectors: Critical Manufacturing, Energy, Water and Wastewater,
[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program]
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create disruption and societal panic even without speculation from end users and the public as added factors. Outages at one organization may cascade across interconnected systems, increasing uncertainty and alarm. The guidance emphasizes clarity, accountability, and transparency as core principles and details key elements of effective crisis messaging to inform affected stakeholders and the public while aligning with legal requirements, operational security, law enforcement, and containment efforts.
CISA’s CI Fortify initiative provides information and resources that help critical infrastructure organizations prep
CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability
CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability
CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability
CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability
CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability
CVE-2026-83548 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
CVE-2026-83549 SonicWall SMA1000 Appliances OS Command Injection Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Br
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product.
The following versions of Rockwell Automation RSLinx Classic are affected:
RSLinx Classic <=4.50 (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.6
Rockwell Automation
Rockwell Automation RSLinx Classic
Integer Overflow or Wraparound, Integer Underflow (Wrap or Wraparound), Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-9621
A denial-of-service security issue exists within RSLinx Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx Classic service to crash, requiring a restart of the se
View CSAF
Summary
Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution.
The following versions of Rockwell Automation Historian ME are affected:
Series B 5.202 (CVE-2025-12768, CVE-2026-12661)
Series C 7.101 (CVE-2025-12768, CVE-2026-12661)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8
Rockwell Automation
Rockwell Automation Historian ME
Out-of-bounds Write, Stack-based Buffer Overflow
Background
Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Food and Agriculture, Healthcare and Public Health, Water and Wastewater Systems
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2025-12768
A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieveremote code execution on the affected device.
View CV
View CSAF
Summary
The following versions of Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix are affected:
ControlLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)
GuardLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)
CompactLogix 5380 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)
Compact GuardLogix 5380 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)
CompactLogix 5480 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.5
Rockwell Automation
Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix
Loop with Unreachable Exit Condition ('Infinite Loop')
Background
Critic
View CSAF
Summary
The following versions of Rockwell Automation Logix Platform are affected:
ControlLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)
CompactLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)
GuardLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)
Compact GuardLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.5
Rockwell Automation
Rockwell Automation Logix Platform
Improper Restriction of Operations within the Bounds of a Memory Buffer
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expan
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges.
The following versions of Rockwell Automation Redundancy Module Configuration Tool are affected:
Redundancy Module Configuration Tool 10.00.00 (CVE-2026-9633)
Redundancy Module Configuration Tool >=9.00.00|<=10.00.00 (CVE-2026-9634)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.3
Rockwell Automation
Rockwell Automation Redundancy Module Configuration Tool
Incorrect Default Permissions
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-9633
A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non administrato
View CSAF
Summary
The following versions of Rockwell Automation FactoryTalk Activation Manager are affected:
FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.8
Rockwell Automation
Rockwell Automation FactoryTalk Activation Manager
Improper Restriction of Excessive Authentication Attempts
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-16675
A privilege escalation vulnerability exists within FactoryTalk Activation Manager. The vulnerability stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack these console windows to obtain a SYSTEM-level command prompt, allowing full access to all files, processes, and system resou
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session &#x26;#xe2;&#x26;#x80;&#x26;#x94; history, filesystem output, working paths, and the agent&#x26;#39;s local tool manifest. The honeypot did not request or cause any tool execution; what the request exposed is what a malicious operator in that position could do.
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for l
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
YARA-X&#x26;#39;s 1.20.0 release brings 14 improvements and 13 bugfixes.
During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files? A couple of months ago, I shared some stats about the trend in 64bits VS. 32bits malware[1]. Can we go a bit further? I (vibe-)coded a Python script based on the pefile library[2] to extract some info from the PE headers. Indeed, the PE file format contains a lot of metadata! They can be accessed using a lot of tools, like Detect It Easy:
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Sources
RBI
0
SEBI
0
CERT-In
0
MeitY
0
NPCI
0
IRDAI
0