DEV Community

Max Bayern
Max Bayern

Posted on Originally published at ot-cyber.de

OT Security Weekly DACH – KW 40/2026: Edge Zero-Days in Remote Access

The threat level for OT operators in Germany, Austria and Switzerland stays high in KW 40/2026. Once again the biggest risk comes through edge devices used for remote access and for connecting sites. Citrix NetScaler ADC/Gateway has zero-days under active exploitation, and Cisco Catalyst SD-WAN Manager has a critical flaw. Both sit right at the boundary that many operators rely on to reach their OT.

Key developments this week

1. Citrix NetScaler ADC/Gateway: two RCE zero-days under active exploitation (CVE-2026-88771, CVE-2026-88772)
Both flaws allow unauthenticated Remote Code Execution. CISA has added both to the KEV catalog. Fixed builds are listed in the Citrix security bulletin.
Source: CISA alert · SANS ICS Critical Control: CC4 – Secure Remote Access

2. Cisco Catalyst SD-WAN Manager: critical flaw grants admin rights without authentication (CVE-2026-76504, CVSS 9.8)
A patch is available, but there is no workaround.
Source: Cisco Security Advisory · SANS ICS Critical Control: CC2 – Defensible Architecture

3. MikroTik RouterOS: pre-auth RCE in the web management
Update RouterOS to the fixed version listed in the advisory.
Source: CISA ICS Advisory · SANS ICS Critical Control: CC5 – Risk-Based Vulnerability Management

4. Lantronix G520 LTE gateway: root code execution through an insecure firmware update chain
An attacker can inject firmware that runs with root privileges. Install the fixed firmware version listed in the advisory.
Source: CISA ICS Advisory · SANS ICS Critical Control: CC5 – Risk-Based Vulnerability Management

5. Ransomware: activity against the industrial sector remains high
Source: Industrial Cyber · SANS ICS Critical Control: CC1 – ICS Incident Response

What it means per sector

Power & grids: The biggest risk this week was remote access, meaning the edge devices used for Remote Access and for connecting sites. In our experience, municipal utilities and grid operators commonly use Citrix NetScaler and Cisco SD-WAN to connect service providers for Fernwartung (remote maintenance), as well as control centres and outstations. These devices also enforce segmentation all the way into the OT. If an attacker takes over one of them, they are standing directly in front of the grid control systems. CISA has added the Citrix zero-days to the KEV catalog. Full report (German)

Food & beverage: Many plants route the remote maintenance that machine builders provide for filling, packaging and refrigeration lines through exactly these systems. The same systems often connect plants, bottling sites, warehouses and cold stores. Patches exist for both Citrix and Cisco, but Cisco has no workaround. On top of that come flaws in MikroTik routers and Lantronix cellular gateways. Edge devices like these often sit unnoticed in outlying warehouses, cold stores, collection points and on machines. Ransomware pressure remains high. Full report (German)

Machine builders: Machine and plant builders deliver remote maintenance and connect their sites through exactly the edge devices being targeted. Besides Citrix and Cisco, three other issues matter for remote maintenance:

  • vulnerabilities in TeamViewer
  • the MikroTik RouterOS pre-auth RCE
  • the manipulable firmware update chain in the Lantronix G520

These components are often built into remote maintenance boxes, control cabinets and industrial PCs in plants already delivered to customers. Search your Asset-Inventar and product SBOMs, roll out the updates and tell your customers. In your own products, check that updates only run over TLS with a verified signature. Full report (German)

What to do now

  • Citrix NetScaler: Before you patch, back up logs and snapshots and hunt for IoCs, including the ones Citrix provides through the NetScaler Console. Then update to the fixed builds listed in the Citrix security bulletin. After patching, kill all sessions and rotate the credentials used through the gateway, especially those of remote maintenance accounts. Hunt for webshells and unexplained gaps in logging. Check which customer or OT systems were reachable through the gateway. If you find signs of compromise, check your reporting obligations under NIS2/BSIG.
  • Cisco SD-WAN Manager: Patch immediately and make the Manager reachable only from an admin network. Search the Manager's access logs for requests with malformed URI encoding and check the full Cisco advisory for the exact IoCs. If you get hits, start Incident Response. Then compare the SD-WAN configuration against a known-good version to spot unplanned routing changes.
  • Edge inventory: Use network scans to find MikroTik and Lantronix G520 devices that are missing from the Asset-Inventar. Update MikroTik and the G520 to the fixed versions from the vendor advisories, prioritising by how critical each station is. Expose management interfaces only to a dedicated management network, and install firmware only through a verified path from a trusted source.
  • Remote access architecture: Route Fernwartung into the OT through a central, logged Jump Host with MFA and approval per session, not directly through the gateway. Remove shadow access via LTE routers.
  • Incident readiness: Define and rehearse an OT Incident Response playbook for running without MES/ERP. Test restoring PLC programs, HMI projects and MES databases from offline backups at least once a quarter. In Austria, check whether the NISG 2026 applies to you and decide who submits the 24-hour early warning.

Full sector reports (German)


Max Gilg is an OT cybersecurity consultant based in Rosenheim, Germany (OT-Cyber.de).

Top comments (0)