On July 7, 2026, CISA published an Industrial Control Systems advisory (ICSA-26-188-07) covering multiple vulnerabilities affecting Digi International PortServer TS and Digi One SP IA serial device servers. According to the official CISA advisory, successful exploitation could allow an attacker to bypass authentication, gain access to restricted resources, obtain credentials, and inject malicious scripts.
PortServer devices are workhorse converters in operational technology networks—they bridge serial devices (legacy sensors, controllers, telemetry systems) to IP networks. Hospitals, utilities, manufacturing plants, and transportation systems rely on them. An authentication bypass in these boxes is a direct threat to the availability and integrity of critical processes that depend on remote access and data flow.
The vulnerability class suggests the devices may accept specially crafted requests that skip login checks or allow credential harvesting before authentication is enforced. Script injection capability indicates potential for persistent compromise—an attacker could modify device behavior, redirect data, or establish a foothold for lateral movement into connected OT networks.
CISA has published a CSAF (Cybersecurity Asset Format) file with technical details at their GitHub repository. Affected organizations should cross-reference their Digi device inventory against the specific version numbers listed in the advisory.
What's notable here is the timing and class of vulnerability in serial-to-IP converters. These devices sit at a trust boundary between legacy, often-unpatched devices and modern networks. They're rarely monitored with the same rigor as firewalls or servers, making them attractive pivot points for persistence. The fact that CISA is flagging authentication bypass combined with script injection suggests this may not be a simple misconfiguration—it points to design-level trust assumptions that need re-evaluation.
Organizations running Digi devices in critical infrastructure should prioritize firmware updates from Digi International and ensure network segmentation limits lateral movement if a device is compromised.

