CISA published an ICS advisory for Inductive Automation Ignition versions 8.1.53 and earlier, affected by CVE-2026-77393, a high-severity vulnerability with a CVSS v3.1 score of 8.8. The vulnerability stems from the 'Create Project Role(s)' gateway setting shipping blank by default, allowing any authenticated user with gateway script execution capability to create projects. This is classified as CWE-276 (Incorrect Default Permissions). Affected sectors include Critical Manufacturing, Energy, and Information Technology. Remediation includes upgrading to Ignition 8.1.54 or later, or populating the 'Create Project Role(s)' setting to restrict project creation to authorized roles. The 8.3 series is not affected. No known public exploitation has been reported. The vulnerability was reported by Christopher Lusk of North Echo Security Research and independently confirmed by Elhussain Fathy (0xSphinx).