DEV Community

Max Bayern
Max Bayern

Posted on Originally published at ot-cyber.de

OT Security Weekly DACH – KW 41/2026: Edge Devices Under Fire

The threat level for OT operators in Germany, Austria and Switzerland stays high in KW 41/2026. Once again, the biggest risks did not come through the PLCs. They came through the edge devices and the remote access in front of the control network. A zero-day in Citrix NetScaler was actively exploited, and Cisco Catalyst SD-WAN Manager has a critical authentication bypass with no workaround. Patching alone is not enough this week: if you don't also hunt for signs of compromise, you may miss webshells and backdoors that are already in place.

Key developments this week

1. Citrix NetScaler: SAML zero-day CVE-2026-88779 also hits devices that were already patched (SANS ICS Critical Control: CC4 – Secure Remote Access)
Attackers are targeting NetScaler Gateways with a SAML configuration. Citrix describes the issue as a denial of service. The flaw also affects devices that had been patched shortly before against earlier vulnerabilities. The patch was released early on 04.10., and reboots were also reported on build 14.1-73.37. Check your configuration for add authentication samlAction or samlIdPProfile and update right away to 14.1-73.41 or 13.1-64.28 (FIPS: 14.1-73.41 FIPS or 13.1-37282). After that, hunt for webshells, new local accounts and foreign sessions. Check for nsaaad crashes since 02.10. Reset sessions and credentials. If you find signs of compromise, rebuild the device and cut its access to the control systems until then.
Source: BleepingComputer

2. Cisco Catalyst SD-WAN Manager: auth bypass CVE-2026-76504 (CVSS 9.8), no workaround (CC2 – Defensible Architecture)
The vulnerability allows attackers to bypass authentication, and there is no workaround. Update to the fixed releases listed in the advisory and review your admin accounts. Take the management interface off the internet and allow access only from a dedicated management network.
Source: Cisco Security Advisory

What it means per sector

Power & grids: For energy suppliers in DACH, the main danger came through edge devices again. Remote access and perimeter systems such as NetScaler and Cisco SD-WAN Manager are affected; the NetScaler attacks were broad and not aimed at any specific sector. Grid operators and municipal utilities often run their remote maintenance through such systems. A recent analysis also found control and login systems in European wind and solar parks openly reachable from the internet (Help Net Security). Check your own public IP ranges for exposed systems. Full report (German)

Food & beverage: In KW 41 we found no publicly confirmed cyberattack on a food or beverage manufacturer in DACH. The situation is still tense, because dairies, breweries and bottlers use the same edge devices for remote maintenance, site networking, mail and remote access. Your business impact analysis and emergency plan should cover how production and shipping keep running if cloud, ERP or logistics IT is down for 3–7 days. That means offline recipes, batch lists, manual delivery notes and cold-storage emergency processes. Practice these procedures (CC1). Also agree on reporting channels, recovery times and backups with your service providers in the contract. For OT remote maintenance, allow access only through a separate jump host with MFA. Full report (German)

Machine builders: Machine builders and system integrators often use the same kind of edge devices for remote maintenance that are affected this week. If you provide remote access to customer plants through NetScaler or Cisco SD-WAN, you need to patch this week and rotate credentials. Build remote maintenance sessions only with MFA and customer approval. Separate the mail gateway from the internal network and from development environments. Check whether your OT segments stay isolated even without the SD-WAN policy. Full report (German)

What to do now

  • Patch the edge right away: NetScaler (14.1-73.41 / 13.1-64.28), Cisco Catalyst SD-WAN Manager (fixed releases per the advisory).
  • Hunt for compromise after patching: look for webshells, new local and API accounts and suspicious sessions. Check for nsaaad crashes since 02.10. If you find evidence, start incident response according to your plan (CC1).
  • Reset sessions and credentials: kill all VPN and admin sessions, rotate passwords and enforce phishing-resistant MFA for every remote access path (CC4).
  • Take management interfaces off the internet: NetScaler, SD-WAN Manager and other edge devices such as firewalls and mail gateways should be reachable only from a dedicated management network (CC2).
  • Inventory your end-of-life field devices: find field devices running end-of-life firmware and restrict their interfaces until you can upgrade (CC5).

Full sector reports (German)


Max Gilg is an OT cybersecurity consultant based in Rosenheim, Germany (OT-Cyber.de).

Top comments (0)