INTEL_REPORT
CISA Cybersecurity Advisories · published 6/18/2026, 12:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Rockwell Automation FactoryTalk Historian Site Edition View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to obtain a valid authentication token, perform a denial of service, or crash the system. The following versions of Rockwell Automation FactoryTalk Historian Site Edition are affected: FactoryTalk Historian SE 11 (CVE-2025-13036) FactoryTalk Historian SE <=11.00 (CVE-2025-44019) FactoryTalk Historian SE <=11.00 (CVE-2025-3653…
https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-03
sha256:71e8e771f231670e7e27faeae6df31be81713b9ca84396669e68bf0781d7d354
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| domain |
| advisory.sd1773.html |
| Open → |
| url | https://support.rockwellautomation.com/app/answers/answer_view/a_id/1157978/loc/en_US | Open → |
| url | https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1773.html | Open → |
| cve | CVE-2025-13036 | Open → |
| cve | CVE-2025-44019 | Open → |
| cve | CVE-2025-36539 | Open → |
| cve | CVE-2025-44109 | Open → |