These advisories cover systems embedded in critical physical operations: maritime voyage recording, building access control, surveillance infrastructure, EV charging networks, and factory automation. A successful attack on any of these systems could disrupt physical operations, disable safety-critical recording equipment, compromise physical access controls, or halt manufacturing lines. Regulatory exposure is significant for organizations in maritime, energy, and healthcare sectors, where these product types intersect with sector-specific compliance obligations.
You Are Affected If
You operate any of the following in production: MacGregor VDR G4e, ABB EIBPORT, ABB Busch-Welcome 2 Wire Door Opener Actuator, CP Plus 8-Ch NVR, KMW CCTV Security Cameras, Schneider Electric EcoStruxure Machine Expert HVAC, XCharge C6 EV Charger, Fourth Frontier Frontier X or X2, Mitsubishi Electric Factory Automation Engineering Products, or ABB Ability Zenon Remote Transport
Any of the affected devices are network-accessible, either directly on a corporate network or via remote access without strict network segmentation
You have not yet reviewed or applied mitigations from the 11 individual CISA advisories published at cisa.gov/news-events/ics-advisories on May 28, 2026
Your OT/ICS asset inventory (CIS 1.1) does not currently include embedded IoT or industrial device product names and firmware versions, meaning you cannot confirm whether affected models are present
Your organization operates in maritime, building management, physical security, EV infrastructure, or industrial manufacturing sectors where these product families are commonly deployed
Board Talking Points
CISA issued 11 advisories on May 28, 2026, identifying vulnerabilities in systems that control physical operations across maritime, building security, EV charging, and manufacturing environments.
Security teams should audit whether any of the 11 named products are in use and apply CISA-directed mitigations within 30 days, prioritizing internet-accessible systems immediately.
If affected systems are left unpatched and network-accessible, adversaries could disrupt physical operations, compromise access controls, or tamper with safety-critical recorded data.
HIPAA — Fourth Frontier Frontier X and X2 are cardiac monitoring wearables; if deployed in a clinical or patient-care context, any compromise of health data transmission may implicate HIPAA Security Rule obligations
USCG / IMO SOLAS — MacGregor VDR G4e is a maritime voyage data recorder subject to IMO SOLAS requirements; tampering with or disabling VDR functionality may constitute a maritime regulatory violation
NERC CIP — XCharge C6 EV charging infrastructure deployed within bulk electric system environments may fall under NERC CIP electronic security perimeter requirements