REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
181 reports · page 4 of 5
cisa_alerts · tlp:amber · 5/22/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-9082 Drupal Core SQL Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnera…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/05/22/cisa-adds-one-known-exploited-vulnerability-catalogcisa_alerts · tlp:amber · 5/21/2026, 12:00:00 PM
CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-34291 Langflow Origin Validation Error Vulnerability CVE-2026-34926 Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. B…
cisa_alerts · tlp:amber · 5/21/2026, 12:00:00 PM
ABB Terra AC Wallbox View CSAF Summary ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the pollution of heap memory which potentially takes remote control of the product and performs a write operation to the flash memory to alter the firmware behavior. The following versions of ABB Terra AC Wallbox are affected: Terra AC wallbox (JP) <=1.8.33, 1.8.36 (CVE-2025…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-141-05cisa_alerts · tlp:amber · 5/21/2026, 12:00:00 PM
ABB B&R PCs View CSAF Summary ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is now available that addresses and remediates the vulnerability. A network attacker could exploit the vulnerabilities to execute remote code, initiate DoS attacks, conduct DNS cache poisoning, or extract sensitive information. The following versions of ABB B&R PCs are affected: APC4100 <1.09, 1.09 (CVE-2023-45229, CVE-2023-45230, CVE-2…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-141-02cisa_alerts · tlp:amber · 5/20/2026, 12:00:00 PM
CISA Adds Seven Known Exploited Vulnerabilities to Catalog CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2008-4250 Microsoft Windows Buffer Overflow Vulnerability CVE-2009-1537 Microsoft DirectX NULL Byte Overwrite Vulnerability CVE-2009-3459 Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability CVE-2010-0249 Microsoft Internet Explorer Use-After-Free Vulnerability CVE…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/05/20/cisa-adds-seven-known-exploited-vulnerabilities-catalogcisa_alerts · tlp:amber · 5/19/2026, 12:00:00 PM
ZKTeco CCTV Cameras View CSAF Summary Successful exploitation of this vulnerability could result in information disclosure, including capture of camera account credentials. The following versions of ZKTeco CCTV Cameras are affected: SSC335-GC2063-Face-0b77 Solution CVSS Vendor Equipment Vulnerabilities v3 9.1 ZKTeco ZKTeco CCTV Cameras Authentication Bypass Using an Alternate Path or Channel Background Critical Infrastructure Sectors: Commercial Facilities Countries/Areas De…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-04cisa_alerts · tlp:amber · 5/19/2026, 12:00:00 PM
ScadaBR View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to perform unauthenticated remote code execution. The following versions of ScadaBR are affected: ScadaBR 1.2.0 (CVE-2026-8602, CVE-2026-8603, CVE-2026-8604, CVE-2026-8605) CVSS Vendor Equipment Vulnerabilities v3 9.1 ScadaBR ScadaBR Missing Authentication for Critical Function, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Cross-Si…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-03cisa_alerts · tlp:amber · 5/19/2026, 12:00:00 PM
ABB CoreSense HM and CoreSense M10 View CSAF Summary An update is available that resolves vulnerability in the product versions listed as affected in this advisory. A path traversal vulnerability in these products can allow unauthenticated users to gain access to restricted directories. Exploiting this vulnerability can lead to complete system compromise and exposure of sensitive information. The following versions of ABB CoreSense HM and CoreSense M10 are affected: CoreSens…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-01cisa_alerts · tlp:amber · 5/19/2026, 12:00:00 PM
Siemens RUGGEDCOM APE1808 Devices View CSAF Summary A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. Siemens is preparing fix versions and recommends countermeasures for products where fixes are not, or not yet available. Customer…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-02cisa_alerts · tlp:amber · 5/19/2026, 12:00:00 PM
Kieback & Peter DDC Building Controllers View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of the victim's browser. The following versions of Kieback & Peter DDC Building Controllers are affected: DDC4002 <=1.12.14 (CVE-2026-4293) DDC4100 <=1.12.14 (CVE-2026-4293) DDC4200 <=1.12.14 (CVE-2026-4293) DDC4200-L <=1.12.14 (CVE-2026-4293) DDC4400 <=1.12.14 (CVE-2026-4293) DDC4002e <=1.23.4 (CVE-2026-4293) …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-05cisa_alerts · tlp:amber · 5/15/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-42897 Microsoft Exchange Server Cross-Site Scripting Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of K…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/05/15/cisa-adds-one-known-exploited-vulnerability-catalogcisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Universal Robots Polyscope 5 View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication and execute code. The following versions of Universal Robots Polyscope 5 are affected: Polyscope 5 <5.25.1 CVSS Vendor Equipment Vulnerabilities v3 9.8 Universal Robots Universal Robots Polyscope 5 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Background Critical Infrastructure S…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-17cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens Siemens ROS# View CSAF Summary ROS# contains a ROS service file_server, that before version 2.2.2 contains a path traversal vulnerability which could allow an attacker to access, i.e. read and write, arbitrary files, which are accessible with the user rights of the user that runs the service, on the system that hosts service. Siemens has released a new version for ROS# and recommends to update to the latest version. The following versions of Siemens Siemens ROS# are …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-08cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens Industrial Devices View CSAF Summary Multiple industrial devices contain a vulnerability that could allow an attacker to cause a denial of service condition. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens Industrial Devices are affec…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-06cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens SIPROTEC 5 View CSAF Summary The SIPROTEC 5 devices do not use sufficiently random numbers to generate session identifiers. This could facilitate a brute-force attack against a valid session identifier which could allow an unauthenticated remote attacker to hijack a valid user session. The affected session identifiers are only used in a subset of the endpoints that are provided by the affected products. Siemens is preparing fix versions and recommends countermeasures…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-13cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens SIMATIC View CSAF Summary SIMATIC HMI Unified Comfort Panels before V21.0 are affected by a vulnerability that allows an unauthenticated attacker to access the web browser via the help link. This vulnerability allows an attacker to access the web browser through the Control Panel if it is not protected by the corresponding security mechanisms. This opens the possibility for the attacker to find backdoors, which might lead to unwanted misconfigurations. Siemens has re…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-07cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-20182 Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Note: Please ad…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/05/14/cisa-adds-one-known-exploited-vulnerability-catalogcisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens SIMATIC S7 PLC Web Server View CSAF Summary SIMATIC S7 PLCs contain multiple vulnerabilities in the web server that could allow an attacker to perform cross-site scripting attacks. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIMAT…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-15cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens Ruggedcom Rox View CSAF Summary Ruggedcom Rox contains an improper access control vulnerability that could allow an authenticated remote attacker to read arbitrary files with root privileges from the underlying operating system's filesystem. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Ruggedcom Rox are affected: RUGGEDCOM ROX MX5000 vers:intdot/<2.17.1 RUGGEDCOM ROX …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-02cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens Opcenter RDnL View CSAF Summary Opcenter RDnL is affected by missing authentication in critical function in ‘ActiveMQ Artemis’. An unauthenticated attacker within the adjacent network could use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker. This could potentially result in availability impacts or message injection into any queue via the rogue broker. Breaking the integrity of a me…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-09cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens SENTRON 7KT PAC1261 Data Manager View CSAF Summary The web server in SENTRON 7KT PAC1261 Data Manager Before V2.1.0 contains a request smuggling vulnerability in the Go Project's net/http package that could allow an attacker to retrieve authorization tokens that can be used to gain administrative control over the device. Siemens has released a new version for SENTRON 7KT PAC1261 Data Manager and recommends to update to the latest version. The following versions of Si…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-14cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens Solid Edge View CSAF Summary Solid Edge SE2026 before Update 5 is affected by two file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released a new version for Solid Edge SE2026 and recommends to update to the latest version. The following versions of Siemens Solid Edge are affected: Solid Edge vers:intdot/&l…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-03cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens Teamcenter View CSAF Summary Siemens Teamcenter is affected by multiple vulnerabilities which could potentially lead to a compromise in availability, integrity and confidentiality. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Teamcenter are affected: Teamcenter V2312 vers:intdot/<2312.0014, vers:intdot/<2312.0009 (CVE-2026-33862, CVE-2026-33893, CVE-2024-4367) Team…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-04cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens Ruggedcom Rox View CSAF Summary Ruggedcom Rox contains an input validation vulnerability in the feature key installation process that could allow an authenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Ruggedcom Rox are affected: RUGGEDCOM ROX MX5000 vers:intdot/&…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-11cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens Simcenter Femap View CSAF Summary Simcenter Femap is affected by heap based buffer overflow vulnerability in Datakit library that could be triggered when the application reads files in IPT format. If a user is tricked to open a malicious file with the affected application, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released a new version for Simcenter Femap and recommends to update …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-05cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens Ruggedcom Rox View CSAF Summary Ruggedcom Rox before v2.17.1 contain multiple third-party vulnerabilities. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Ruggedcom Rox are affected: RUGGEDCOM ROX MX5000 vers:intdot/<2.17.1 (CVE-2019-13103, CVE-2019-13104, CVE-2019-13106, CVE-2019-14192, CVE-2019-14193, CVE-2019-14194, CVE-2019-14195, CVE-2019-14196, CVE-2019-14197, CVE-…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-16cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens Ruggedcom Rox View CSAF Summary Ruggedcom Rox contains an input validation vulnerability in the Scheduler functionality that could allow an authenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Ruggedcom Rox are affected: RUGGEDCOM ROX MX5000 vers:intdot/<2.17.1…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-12cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens SIMATIC View CSAF Summary SIMATIC CN 4100 contains multiple vulnerabilities which could potentially lead to a compromise in availability, integrity and confidentiality. Siemens has released a new version for SIMATIC CN 4100 and recommends to update to the latest version. The following versions of Siemens SIMATIC are affected: SIMATIC CN 4100 vers:intdot/<5.0 CVSS Vendor Equipment Vulnerabilities v3 9.6 Siemens Siemens SIMATIC NULL Pointer Dereference, Reacha…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens gWAP View CSAF Summary Siemens gPROMS Web Applications Publisher (gWAP) is affected by a remote code execution vulnerability introduced through a third-party component, namely the Axios HTTP client library. The vulnerability stems from a specific "Gadget" attack chain that allows prototype pollution in other third-party libraries, potentially allowing an attacker to execute arbitrary code. Siemens has released a new version for gWAP and recommends to update to the la…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-01cisa_alerts · tlp:amber · 5/12/2026, 12:00:00 PM
ABB Automation Builder Gateway for Windows View CSAF Summary ABB became aware of severe vulnerability in the products versions listed as affected in the advisory. The Windows gateway is accessible remotely by default. Unauthenticated attackers can therefore search for PLCs, but the user management of the PLCs prevents the actual access to the PLCs – unless it is disabled The following versions of ABB Automation Builder Gateway for Windows are affected: Automation Builder <…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-132-04cisa_alerts · tlp:amber · 5/12/2026, 12:00:00 PM
Software Bill of Materials for AI - Minimum Elements CISA and the Group of Seven (G7) international partners—Germany, Canada, France, Italy, Japan, the United Kingdom, and the European Union—have released joint guidance, Software Bill of Materials for AI – Minimum Elements , to help public and private sector stakeholders improve transparency in their artificial intelligence (AI) systems and supply chains. A software bill of materials (SBOM) acts as an “ingredients list…
Read original ↗https://www.cisa.gov/resources-tools/resources/software-bill-materials-ai-minimum-elementscisa_alerts · tlp:amber · 5/12/2026, 12:00:00 PM
ABB WebPro SNMP Card PowerValue Multiple Vulnerabilities View CSAF Summary ABB became aware of multiple internally discovered vulnerabilities in the WebPro SNMP card PowerValue for the product versions listed as affected in the advisory. Depending upon the vulnerability, an attacker with access to local network who successfully exploited this vulnerability could have - Unauthorized access - Insufficient Session Expiration leading to resource unavailability - Uncontrolled Res…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-132-06cisa_alerts · tlp:amber · 5/12/2026, 12:00:00 PM
Subnet Solutions PowerSYSTEM Center View CSAF Summary Successful exploitation of these vulnerabilities could allow an authenticated attacker to expose sensitive information or cause a CRLF injection. The following versions of Subnet Solutions PowerSYSTEM Center are affected: PowerSYSTEM Center 2020 <=5.28.x (CVE-2026-35504) PowerSYSTEM Center 2020 >=5.8.x|<=5.28.x (CVE-2026-26289) PowerSYSTEM Center 2020 >=5.11.x|<=5.28.x (CVE-2026-33570) PowerSYSTEM Center 20…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-132-02cisa_alerts · tlp:amber · 5/12/2026, 12:00:00 PM
Fuji Electric Tellus View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to elevate privileges from user to system, which may then enable the attacker to cause a temporary denial of service, open files, or delete files. The following versions of Fuji Electric Tellus are affected: Tellus 5.0.2 CVSS Vendor Equipment Vulnerabilities v3 7.8 Fuji Electric Fuji Electric Tellus Exposed Dangerous Method or Function Background Critical Infrastructu…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-132-01cisa_alerts · tlp:amber · 5/12/2026, 12:00:00 PM
ABB AC500 V3 Multiple Vulnerabilities View CSAF Summary ABB became aware of severe vulnerability in the products versions listed as affected in the advisory. An update is available that resolves these vulnerabilities. An attacker who successfully exploited these vulnerabilities could bypass the user management and read visualization files (CVE-2025-2595), read and write certificates and keys (CVE-2025-41659) or cause a denial-of-service (DoS) (CVE-2025-41691). The following …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-132-03cisa_alerts · tlp:amber · 5/12/2026, 12:00:00 PM
ABB AC500 V3 Stack Buffer Overflow in Cryptographic Message Syntax View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves publicly reported vulnerability. An attacker who successfully exploited these vulnerabilities could cause a crash, denial-of-service (DoS), or potentially remote code execution. The following versions of ABB AC500 V3 Stack Buffer Overflow in Cryptographic Messag…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-132-05cisa_alerts · tlp:amber · 5/8/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-42208 BerriAI LiteLLM SQL Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (B…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/05/08/cisa-adds-one-known-exploited-vulnerability-catalogcisa_alerts · tlp:amber · 5/7/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-6973 Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: …
Read original ↗https://www.cisa.gov/news-events/alerts/2026/05/07/cisa-adds-one-known-exploited-vulnerability-catalogcisa_alerts · tlp:amber · 5/7/2026, 12:00:00 PM
MAXHUB Pivot Client Application View CSAF Summary Successful exploitation of this vulnerability may enable an attacker to access tenant email addresses and associated information in cleartext or cause a denial-of-service condition. The following versions of MAXHUB Pivot client application are affected: MAXHUB Pivot client application CVSS Vendor Equipment Vulnerabilities v3 7.3 MAXHUB MAXHUB Pivot client application Use of a Broken or Risky Cryptographic Algorithm Background…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-127-01cisa_alerts · tlp:amber · 5/6/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-0300 Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Signi…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/05/06/cisa-adds-one-known-exploited-vulnerability-catalog