PatchSiren cyber security CVE debrief
CVE-2026-35504 Subnet Solutions CVE debrief
CVE-2026-35504 affects Subnet Solutions PowerSYSTEM Center’s email notification service when SMTPS is used. CISA’s advisory says the issue is a CRLF injection vulnerability, and the vendor recommends updating to fixed releases and tightening access to notification-related settings.
- Vendor
- Subnet Solutions
- Product
- PowerSYSTEM Center 2020
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-12
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-12
Who should care
Organizations running Subnet Solutions PowerSYSTEM Center 2020, 2024, or 2026 deployments that use the email notification service over SMTPS. Administrators responsible for notification settings, activity monitoring, and email routing should prioritize review.
Technical summary
The advisory identifies a CRLF injection condition in the PowerSYSTEM Center email notification service during SMTPS communication. CRLF injection (CWE-93) can allow attacker-controlled line breaks to alter email headers or message structure if the affected input is not properly handled. The supplied advisory assigns CVSS 3.1 5.5/Medium and includes SSVC metadata, but no KEV listing is present in the supplied corpus.
Defensive priority
Medium. The issue is publicly disclosed and vendor-fixed, but the supplied corpus does not indicate KEV inclusion or active exploitation. Systems that expose or rely on the affected notification service should be updated promptly.
Recommended defensive actions
- Update to the vendor-fixed releases listed in the advisory: PSC 2020 Update 29, PSC 2024 Update 2, or PSC 2026 GA Hotfix, as applicable to your deployment.
- Restrict access to Notification Settings to trusted administrators.
- Monitor the "Send from Address" setting and Activity Records for unexpected changes.
- Monitor user activity records to confirm users are following acceptable application-use policies.
- Configure a notification rule that triggers on bulk account export activity.
- Follow CISA ICS recommended practices for operational hardening and monitoring.
Evidence notes
Primary evidence comes from the CISA CSAF advisory (ICSA-26-132-02) published 2026-05-12 and mirrored in the supplied source item. The advisory explicitly states: "PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communication." It also provides vendor mitigations and remediation versions. The supplied enrichment shows no KEV entry and no ransomware-campaign association.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-35504 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-35504
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-35504 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-35504
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-132-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-132-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.