PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-35504 Subnet Solutions CVE debrief

CVE-2026-35504 affects Subnet Solutions PowerSYSTEM Center’s email notification service when SMTPS is used. CISA’s advisory says the issue is a CRLF injection vulnerability, and the vendor recommends updating to fixed releases and tightening access to notification-related settings.

Vendor
Subnet Solutions
Product
PowerSYSTEM Center 2020
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-12
Advisory published
2026-05-12
Advisory updated
2026-05-12

Who should care

Organizations running Subnet Solutions PowerSYSTEM Center 2020, 2024, or 2026 deployments that use the email notification service over SMTPS. Administrators responsible for notification settings, activity monitoring, and email routing should prioritize review.

Technical summary

The advisory identifies a CRLF injection condition in the PowerSYSTEM Center email notification service during SMTPS communication. CRLF injection (CWE-93) can allow attacker-controlled line breaks to alter email headers or message structure if the affected input is not properly handled. The supplied advisory assigns CVSS 3.1 5.5/Medium and includes SSVC metadata, but no KEV listing is present in the supplied corpus.

Defensive priority

Medium. The issue is publicly disclosed and vendor-fixed, but the supplied corpus does not indicate KEV inclusion or active exploitation. Systems that expose or rely on the affected notification service should be updated promptly.

Recommended defensive actions

  • Update to the vendor-fixed releases listed in the advisory: PSC 2020 Update 29, PSC 2024 Update 2, or PSC 2026 GA Hotfix, as applicable to your deployment.
  • Restrict access to Notification Settings to trusted administrators.
  • Monitor the "Send from Address" setting and Activity Records for unexpected changes.
  • Monitor user activity records to confirm users are following acceptable application-use policies.
  • Configure a notification rule that triggers on bulk account export activity.
  • Follow CISA ICS recommended practices for operational hardening and monitoring.

Evidence notes

Primary evidence comes from the CISA CSAF advisory (ICSA-26-132-02) published 2026-05-12 and mirrored in the supplied source item. The advisory explicitly states: "PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communication." It also provides vendor mitigations and remediation versions. The supplied enrichment shows no KEV entry and no ransomware-campaign association.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-35504 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-35504

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-35504 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-35504

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-132-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-132-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.