Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV Catalog
    Cybersecurity

    Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV Catalog

    adminBy adminMarch 8, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV Catalog
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananMar 06, 2026Vulnerability / Network Security

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Hikvision and Rockwell Automation products to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

    The critical-severity vulnerabilities are listed below –

    • CVE-2017-7921 (CVSS score: 9.8) – An improper authentication vulnerability affecting multiple Hikvision products that could allow a malicious user to escalate privileges on the system and gain access to sensitive information. 
    • CVE-2021-22681 (CVSS score: 9.8) – An insufficiently protected credentials vulnerability affecting multiple Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, and Logix Controllers that could allow an unauthorized user with network access to the controller to bypass the verification mechanism and authenticate with it, as well as alter its configuration and/or application code.

    The addition of CVE-2017-7921 to the KEV catalog comes more than four months after the SANS Internet Storm Center disclosed that it had detected exploit attempts against Hikvision cameras susceptible to the flaw. However, there appears to be no public report describing attacks involving CVE-2021-22681.

    In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are recommended to update to the latest supported software versions by March 26, 2026, as part of Binding Operational Directive (BOD) 22-01.

    “These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” CISA said.

    “Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice.”

    Added automation Catalog CISA CVSS Flaws Hikvision KEV Rockwell
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticlePeacock TV: Stream TV & Movies (Samsung Galaxy Apps version) 7.3.10 APK Download by Peacock TV LLC
    Next Article Copilot made my PowerPoint in minutes, but this is what made it look good
    admin
    • Website

    Related Posts

    Encryption Consulting launches CertSecure Manager v3.3 with zero-touch certificate renewals

    May 20, 2026

    GitHub confirms breach of 3,800 repos via malicious VSCode extension

    May 20, 2026

    Grafana GitHub Breach Exposes Source Code via TanStack npm Attack

    May 20, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    AI-powered WAF, virtual patching: How F5 is hardening networks against frontier threats

    June 10, 2026

    The 702 Ultimatum: Warrant Requirement or Bust

    June 10, 2026

    Schema.org now shows you how many sites are using each schema type

    June 10, 2026

    Using AI to Support and Defend Your Brand

    June 10, 2026
    Categories
    • Blogging (92)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (250)
    • SEO & Digital Marketing (1,439)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (346)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    AI-powered WAF, virtual patching: How F5 is hardening networks against frontier threats

    June 10, 2026

    The 702 Ultimatum: Warrant Requirement or Bust

    June 10, 2026

    Schema.org now shows you how many sites are using each schema type

    June 10, 2026
    Most Popular
    • AI-powered WAF, virtual patching: How F5 is hardening networks against frontier threats
    • The 702 Ultimatum: Warrant Requirement or Bust
    • Schema.org now shows you how many sites are using each schema type
    • Using AI to Support and Defend Your Brand
    • 6 Ways to Automate International Marketing with Agent A
    • What Is Network Experience Management? A Guide for IT Teams
    • Google Search Sends 23% Of Queries To The Open Web
    • Residential proxies are hiding in plain sight inside enterprise networks
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.