<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://exploit-radar.com/en/flux/categories/ot.xml</id>
  <title>Exploit Radar: Industrial and building systems</title>
  <subtitle>The latest additions to CISA’s catalog of exploited vulnerabilities in the “Industrial and building systems” category (indicative classification).</subtitle>
  <link rel="self" type="application/atom+xml" href="https://exploit-radar.com/en/flux/categories/ot.xml"/>
  <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/produits/ot/"/>
  <updated>2026-07-15T00:00:00Z</updated>
  <author><name>Exploit Radar</name></author>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-4346/</id>
    <title>CVE-2023-4346 — KNX Association Protocole KNX</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-4346/"/>
    <updated>2026-07-15T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from KNX Association; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on July 15, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-67038/</id>
    <title>CVE-2025-67038 — Lantronix EDS5000</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-67038/"/>
    <updated>2026-06-23T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Lantronix; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on June 23, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-22681/</id>
    <title>CVE-2021-22681 — Rockwell Automation Logix (PLCs, Studio 5000)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-22681/"/>
    <updated>2026-03-05T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Rockwell Automation; if none are available, stop using the product. For cloud services, follow the guidance from Rockwell Automation. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 5, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-26828/</id>
    <title>CVE-2021-26828 — OpenPLC ScadaBR</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-26828/"/>
    <updated>2025-12-03T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from OpenPLC; if none are available, stop using the product. For cloud services, follow the guidance from OpenPLC. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on December 3, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-26829/</id>
    <title>CVE-2021-26829 — OpenPLC ScadaBR</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-26829/"/>
    <updated>2025-11-28T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from OpenPLC; if none are available, stop using the product. For cloud services, follow the guidance from OpenPLC. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on November 28, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-38950/</id>
    <title>CVE-2023-38950 — ZKTeco BioTime</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-38950/"/>
    <updated>2025-05-19T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from ZKTeco; if none are available, stop using the product. For cloud services, follow the guidance from ZKTeco. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on May 19, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-23748/</id>
    <title>CVE-2022-23748 — Audinate Dante Discovery</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-23748/"/>
    <updated>2025-02-06T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Audinate; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on February 6, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2019-7256/</id>
    <title>CVE-2019-7256 — Nice (Linear) Linear eMerge E3-Series</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2019-7256/"/>
    <updated>2024-03-25T00:00:00Z</updated>
    <summary type="text">Specific CISA instructions: see the vulnerability page. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 25, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-36380/</id>
    <title>CVE-2021-36380 — Sunhillo SureLine</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-36380/"/>
    <updated>2024-03-05T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Sunhillo; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 5, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-6448/</id>
    <title>CVE-2023-6448 — Unitronics Vision PLC and HMI</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-6448/"/>
    <updated>2023-12-11T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Unitronics; if none are available, stop using the product. CISA deadline: 7 days. Added to CISA’s catalog of exploited vulnerabilities on December 11, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-29303/</id>
    <title>CVE-2022-29303 — CONTEC (SolarView) SolarView Compact</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-29303/"/>
    <updated>2023-07-13T00:00:00Z</updated>
    <summary type="text">Apply the update from CONTEC (SolarView); if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on July 13, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-38406/</id>
    <title>CVE-2021-38406 — Delta Electronics DOPSoft 2</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-38406/"/>
    <updated>2022-08-25T00:00:00Z</updated>
    <summary type="text">This product has reached end of life: no patch is coming. Remove it or isolate it from the network. CISA deadline: 21 days. End of life: remove it. Added to CISA’s catalog of exploited vulnerabilities on August 25, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2014-0780/</id>
    <title>CVE-2014-0780 — InduSoft Web Studio</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2014-0780/"/>
    <updated>2022-04-15T00:00:00Z</updated>
    <summary type="text">Apply the security update from InduSoft. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on April 15, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2019-3929/</id>
    <title>CVE-2019-3929 — Crestron AirMedia (AM-100, AM-101)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2019-3929/"/>
    <updated>2022-04-15T00:00:00Z</updated>
    <summary type="text">Apply the security update from Crestron. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on April 15, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2016-4523/</id>
    <title>CVE-2016-4523 — Trihedral VTScada (formerly VTS)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2016-4523/"/>
    <updated>2022-04-15T00:00:00Z</updated>
    <summary type="text">Apply the security update from Trihedral. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on April 15, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2018-7841/</id>
    <title>CVE-2018-7841 — Schneider Electric U.motion Builder</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2018-7841/"/>
    <updated>2022-04-15T00:00:00Z</updated>
    <summary type="text">This product has reached end of life: no patch is coming. Remove it or isolate it from the network. CISA deadline: 21 days. End of life: remove it. Added to CISA’s catalog of exploited vulnerabilities on April 15, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2016-8562/</id>
    <title>CVE-2016-8562 — Siemens SIMATIC CP</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2016-8562/"/>
    <updated>2022-03-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Siemens. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 3, 2022.</summary>
  </entry>
</feed>
