161,764 Assets on Port 102: Sizing the Industrial Control Surface That AA26-231A Described
161,764 Assets on Port 102: Sizing the Industrial Control Surface That AA26-231A Described Joint Cybersecurity Advisory AA26-231A warned in August 2026 that threat actors were using internet scanning services to locate exposed Siemens S7 programmable logic controllers. The advisory did not include a count. ZoomEye can supply one, provided the scope of each query is stated as carefully as the…
Joint Cybersecurity Advisory AA26-231A reported in August 2026 that threat actors were scanning the internet for exposed Siemens S7 programmable logic controllers. The advisory did not provide a specific count of these assets. However, ZoomEye, a cybersecurity data provider, can supply such a number, provided the scope of the query is clearly defined.
The advisory, issued on 2026-08-19 by the NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency, described threat actors using scanning services to locate internet-exposed or poorly protected PLCs running outdated software. These attackers then used AI-generated scripts to read and write PLC memory, configuration data, and ladder logic over the S7comm protocol, typically on TCP port 102.
The affected PLC families included S7-200, S7-300, S7-400, S7-1200, and S7-1500, as well as F-series safety controllers. The advisory did not provide specific CVE identifiers or indicators of compromise, but instead focused on known vulnerabilities and misconfigurations in exposed devices. Four measurements were made using different query parameters, each yielding different counts of assets.
The narrowest query, identifying assets as Siemens S7, returned 173 assets. A broader query for assets with the Siemens SIMATIC fingerprint returned 10,160 assets. A query based on port 102 reachability returned 161,764 assets. A device-class query, identifying assets as PLCs, returned 95,395 assets. The advisory's focus on external exposure and the need for organizations to reduce their exposure to these risks is consistent with the broader port-based query, which suggests that any service responding on port 102 should be inspected.
The advisory did not claim that the advisory described a new vulnerability in the S7 series, but rather that known vulnerabilities and misconfigurations in exposed devices were the primary concern.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.