CISA has issued an advisory for Applied Systems Engineering ASE2000 V2 Communications Test Set versions 2.25 through 2.37, disclosing two critical vulnerabilities. CVE-2018-1285 is an XXE (XML External Entity) injection flaw inherited from Apache log4net versions prior to 2.0.10, allowing attackers to read/write arbitrary files or trigger outbound network requests. CVE-2026-18717 is an improper certificate validation vulnerability affecting versions 2.35 through 2.37, enabling TLS impersonation and interception of protected communications. Both vulnerabilities carry CVSS v3.1 scores of 9.8 and 7.4 respectively, with CVSS v4.0 scores of 9.2 and 9.1. The affected product is deployed worldwide across critical infrastructure sectors including Chemical, Critical Manufacturing, Energy, and Water and Wastewater. The vendor, ASE/Kalkitech, has released version 2.38 as a fix, upgrading the log4net library and correcting TLS certificate validation logic. Interim mitigations include restricting write access to installation directories, network segmentation, and firewall protection. No known public exploitation has been reported at this time.