Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV Catalog
    Cybersecurity

    Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV Catalog

    adminBy adminMarch 8, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV Catalog
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananMar 06, 2026Vulnerability / Network Security

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Hikvision and Rockwell Automation products to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

    The critical-severity vulnerabilities are listed below –

    • CVE-2017-7921 (CVSS score: 9.8) – An improper authentication vulnerability affecting multiple Hikvision products that could allow a malicious user to escalate privileges on the system and gain access to sensitive information. 
    • CVE-2021-22681 (CVSS score: 9.8) – An insufficiently protected credentials vulnerability affecting multiple Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, and Logix Controllers that could allow an unauthorized user with network access to the controller to bypass the verification mechanism and authenticate with it, as well as alter its configuration and/or application code.

    The addition of CVE-2017-7921 to the KEV catalog comes more than four months after the SANS Internet Storm Center disclosed that it had detected exploit attempts against Hikvision cameras susceptible to the flaw. However, there appears to be no public report describing attacks involving CVE-2021-22681.

    In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are recommended to update to the latest supported software versions by March 26, 2026, as part of Binding Operational Directive (BOD) 22-01.

    “These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” CISA said.

    “Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice.”

    Added automation Catalog CISA CVSS Flaws Hikvision KEV Rockwell
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticlePeacock TV: Stream TV & Movies (Samsung Galaxy Apps version) 7.3.10 APK Download by Peacock TV LLC
    Next Article Copilot made my PowerPoint in minutes, but this is what made it look good
    admin
    • Website

    Related Posts

    A Webinar Guide to Auditing Modern Agentic Workflows

    March 10, 2026

    Armadin secures $189.9 million to counter AI-driven cyber threats

    March 10, 2026

    APT28 hackers deploy customized variant of Covenant open-source tool

    March 10, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Why SEO now requires distribution

    March 10, 2026

    Google Gemini on Wear OS picks up a revamped weather card

    March 10, 2026

    Cisco blends Splunk analytics, security with core data center management

    March 10, 2026

    A Webinar Guide to Auditing Modern Agentic Workflows

    March 10, 2026
    Categories
    • Blogging (36)
    • Cybersecurity (696)
    • Privacy & Online Earning (97)
    • SEO & Digital Marketing (433)
    • Tech Tools & Mobile / Apps (862)
    • WiFi / Internet & Networking (115)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Why SEO now requires distribution

    March 10, 2026

    Google Gemini on Wear OS picks up a revamped weather card

    March 10, 2026

    Cisco blends Splunk analytics, security with core data center management

    March 10, 2026
    Most Popular
    • Why SEO now requires distribution
    • Google Gemini on Wear OS picks up a revamped weather card
    • Cisco blends Splunk analytics, security with core data center management
    • A Webinar Guide to Auditing Modern Agentic Workflows
    • How to Analyze & Compare Competitor Website Traffic in 2026
    • ANBERNIC reveals full spec sheet for PlayStation Vita clones
    • Armadin secures $189.9 million to counter AI-driven cyber threats
    • How I Use My iPhone’s Focus Modes to Stop Getting Distracted at the Gym
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.