REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
181 reports · page 1 of 5
cisa_alerts · tlp:amber · 7/16/2026, 12:00:00 PM
AutomationDirect Productivity Suite View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with local or physical access to cause memory corruption, unintended information disclosure, application instability, or a denial-of-service condition in the affected product. The following versions of AutomationDirect Productivity Suite are affected: Productivity Suite <=v4.6.2.2 (CVE-2026-60063, CVE-2026-61389, CVE-2026-60140, CVE-2026-57896, CV…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-04cisa_alerts · tlp:amber · 7/16/2026, 12:00:00 PM
Siemens SICAM 8 View CSAF Summary Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: - SICAM A8000 Device firmware - CPCI85 for CP-8031/CP-8050 - SICORE for CP-8010/CP-8012 - SICAM EGS Device firmware - CPCI85 - SICAM S8000 - SICORE Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens SICAM 8 are affected: CPCI85 Central Proc…
cisa_alerts · tlp:amber · 7/16/2026, 12:00:00 PM
NASA Core Flight System (cFS) Health & Safety (HS) Application View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of NASA Core Flight System (cFS) Health & Safety (HS) Application are affected: Core Flight System (cFS) Health & Safety (HS) Application CVSS Vendor Equipment Vulnerabilities v3 7.5 NASA NASA Core Flight System (cFS) Health & Safety (HS) Application NU…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-03cisa_alerts · tlp:amber · 7/16/2026, 12:00:00 PM
CISA Adds Three Known Exploited Vulnerabilities to Catalog CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-25089 Fortinet FortiSandbox OS Command Injection Vulnerability CVE-2026-39808 Fortinet FortiSandbox OS Command Injection Vulnerability CVE-2026-58644 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability These types of vulnerabilities are frequ…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/07/16/cisa-adds-three-known-exploited-vulnerabilities-catalogcisa_alerts · tlp:amber · 7/16/2026, 12:00:00 PM
Rockwell Automation Arena View CSAF Summary Successful exploitation these vulnerabilities could allow an attacker to execute arbitrary code in the context of the current process. The following versions of Rockwell Automation Arena are affected: Arena <=V17.00.00 (CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, CVE-2026-8314) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation Arena Out-of-bounds Write Background Critical Infrastructure Sector…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-01cisa_alerts · tlp:amber · 7/16/2026, 12:00:00 PM
Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT are affected: 1756-EN3 <=V12.001 (CVE-2026-9653) 1756-EN2 <=V12.001 (CVE-2026-9653) 1756-ENBT V6.006 (CVE-2026-9653) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1756-EN2,…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-02cisa_alerts · tlp:amber · 7/16/2026, 12:00:00 PM
SALTO ProAccess Space View CSAF Summary Successful exploitation of this vulnerability allows an authenticated attacker to escalate privileges and access spaces outside their assigned partition, within the same Salto ProAccess Space installation or system. Exploitation requires valid authenticated operator credentials and the partition feature to be enabled; installations without partitioning are not affected. The following versions of SALTO ProAccess Space are affected: ProA…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-07cisa_alerts · tlp:amber · 7/16/2026, 12:00:00 PM
Rockwell Automation Flex 5000 Adapter View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation Flex 5000 Adapter are affected: Flex 5000 Adapter 6.011 (CVE-2026-12659) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation Flex 5000 Adapter Double Free Background Critical Infrastructure Sectors: Critical Ma…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-08cisa_alerts · tlp:amber · 7/16/2026, 12:00:00 PM
Rockwell Automation FactoryTalk DataMosaix View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious scripts on the server. The following versions of Rockwell Automation FactoryTalk DataMosaix are affected: DataMosaix Private Cloud <=8.02 (CVE-2026-9292) CVSS Vendor Equipment Vulnerabilities v3 6.1 Rockwell Automation Rockwell Automation FactoryTalk DataMosaix Improper Neutralization of Input During Web Page …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-09cisa_alerts · tlp:amber · 7/16/2026, 12:00:00 PM
Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix are affected: CompactLogix 5370 <=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) Compact GuardLogix 5370 <=V35.015 (CVE-2025-12011, CVE-2025-1…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-06cisa_alerts · tlp:amber · 7/15/2026, 12:00:00 PM
Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers Developed by CISA, the National Security Agency (NSA) and international partners, this joint guidance contains best practices for software manufacturers and online service providers to design and implement a coordinated vulnerability disclosure (CVD) program for working with external security researchers that includes a clear vulnerability disclosure policy (VDP) and process for tri…
Read original ↗https://www.cisa.gov/resources-tools/resources/establishing-coordinated-vulnerability-disclosure-program-work-security-researcherscisa_alerts · tlp:amber · 7/14/2026, 12:00:00 PM
ABB Ability Edgenius View CSAF Summary ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the atta…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-02cisa_alerts · tlp:amber · 7/14/2026, 12:00:00 PM
Rockwell Automation 1715-AENTR EtherNet/IP Adapter View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device. The following versions of Rockwell Automation 1715-AENTR EtherNet/IP Adapter are affected: 1715-AENTR EtherNet/IP Adapter <=3.003 (CVE-2026-10577) CVSS Vendor Equipment Vulnera…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-04cisa_alerts · tlp:amber · 7/14/2026, 12:00:00 PM
CISA Adds Four Known Exploited Vulnerabilities to Catalog CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability CVE-2026-15410 SonicWall SMA1000 Appliances Code Injection Vulnerability CVE-2026-56155 Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability CVE-20…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-adds-four-known-exploited-vulnerabilities-catalogcisa_alerts · tlp:amber · 7/14/2026, 12:00:00 PM
ABB T-MAC Plus View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. An attacker who successfully exploited any of these vulnerabilities could potentially compromise the system in different ways. The following versions of ABB T-MAC Plus are affected: T-MAC Plus 4.0-24 (CVE-2025-14771, CVE-2025-14772, CVE-2025-14773, CVE-2025-14774) CVSS Vendor Equipme…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-03cisa_alerts · tlp:amber · 7/14/2026, 12:00:00 PM
ABB Advant Master Online Builder View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory, where an incorrect version of Online Builder (ONB) was included in the media. An update is available that resolves the vulnerability, see details in Recommended immediate actions. The following versions of ABB Advant Master Online Builder are affected: Control Builder A <=1.4/4 (CVE-2025-13162) 800xA for Advant Master <=6.0.3…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-01cisa_alerts · tlp:amber · 7/14/2026, 12:00:00 PM
CISA Urges SharePoint Hardening After New Exploitations CISA is aware of active exploitation of vulnerabilities CVE-2026-32201 , CVE-2026-45659 , and CVE-2026-56164 , enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances. These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities, suc…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitationscisa_alerts · tlp:amber · 7/13/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2008-4128 Cisco IOS Cross-Site Request Forgery Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk e…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/07/13/cisa-adds-one-known-exploited-vulnerability-catalog
cisa_alerts · tlp:amber · 7/13/2026, 12:00:00 PM
Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors Executive summary Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. This joint Cybersecurity Advisory (CSA) builds o…
Read original ↗https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194acisa_alerts · tlp:amber · 7/10/2026, 12:00:00 PM
CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-48939 iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-56291 Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant r…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/07/10/cisa-adds-two-known-exploited-vulnerabilities-catalogcisa_alerts · tlp:amber · 7/9/2026, 12:00:00 PM
Schneider Electric Easergy MiCOM Px40 Series View CSAF Summary Schneider Electric is aware of a vulnerability in its Easergy MiCOM Px40 Series products. The [Easergy MiCOM Px40](https://www.se.com/ww/en/product-subcategory/4725-easergy-micom-px40-series/?filter=business-6-medium-voltage-distribution-and-grid-automation) is a protection relay series for Medium Voltage, High Voltage and Extra High Voltage protection. Failure to apply the mitigations provided below may risk una…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-03cisa_alerts · tlp:amber · 7/9/2026, 12:00:00 PM
Schneider Electric PowerChute Serial Shutdown View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to overwrite critical files, forge or inject malicious log data, gain unauthorized account access, trigger denial‑of‑service conditions, truncate or alter logging information, reset user credentials, or expose sensitive information. The following versions of Schneider Electric PowerChute Serial Shutdown are affected: PowerChute Serial Shutdow…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-02cisa_alerts · tlp:amber · 7/9/2026, 12:00:00 PM
OpenPLC v3 View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to the filesystem and escalate this into arbitrary native code execution through the normal OpenPLC program compilation process, potentially resulting in code execution as the OpenPLC runtime user. The following versions of OpenPLC v3 are affected: OpenPLC v3 CVSS Vendor Equipment Vulnerabilities v3 9.9 OpenPLC OpenPLC v3 External Control …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-01cisa_alerts · tlp:amber · 7/7/2026, 12:00:00 PM
Labcenter Proteus 9 View CSAF Summary Successful exploitation of these vulnerabilities could disclose information and allow a malicious user to execute arbitrary code on affected installations. The following versions of Labcenter Proteus 9 are affected: Proteus 9.1_SP4_Build_42914 CVSS Vendor Equipment Vulnerabilities v3 7.8 Labcenter Electronics Labcenter Proteus 9 Out-of-bounds Write, Stack-based Buffer Overflow, Use After Free Background Critical Infrastructure Sectors: C…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-06cisa_alerts · tlp:amber · 7/7/2026, 12:00:00 PM
Hitachi Energy PROMOD V View CSAF Summary Hitachi Energy is aware of insecure HTTP transmission vulnerability in PROMOD V product versions listed in this document. This vulnerability could allow attackers to intercept or manipulate sensitive data in transit, potentially leading to credential theft, session hijacking, or unauthorized access. The following versions of Hitachi Energy PROMOD V are affected: PROMOD V vers:PROMOD_V/<=1.0.10 CVSS Vendor Equipment Vulnerabilities…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-02cisa_alerts · tlp:amber · 7/7/2026, 12:00:00 PM
Hitachi Energy e-mesh EMS View CSAF Summary Hitachi Energy is aware of a buffer overflow vulnerability that affects e-mesh EMS product versions listed in this document. Successful exploitation of this vulnerability could lead to a buffer overflow condition, potentially resulting in application outages (denial of service) and possible arbitrary code execution. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following ver…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-03cisa_alerts · tlp:amber · 7/7/2026, 12:00:00 PM
Digi International PortServer TS, Digi One SP IA View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication and gain access to restricted resources, obtain credentials, and inject malicious scripts. The following versions of Digi International PortServer TS, Digi One SP IA are affected: PortServer TS Digi One SP Digi One SP IA Digi One IA CVSS Vendor Equipment Vulnerabilities v3 5.9 Digi International Digi Internationa…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-07cisa_alerts · tlp:amber · 7/7/2026, 12:00:00 PM
CISA Adds Three Known Exploited Vulnerabilities to Catalog CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-55255 Langflow Authorization Bypass Through User-Controlled Key Vulnerability CVE-2026-56290 Joomlack Page Builder Improper Access Control Vulnerability These typ…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalogcisa_alerts · tlp:amber · 7/7/2026, 12:00:00 PM
Hydro-Québec Le Circuit Electrique charging station backend View CSAF Summary Successful exploitation of these vulnerabilities could lead to privilege escalation, or result in a denial-of-service attack. The following versions of Hydro-Québec Le Circuit Electrique charging station backend are affected: Le Circuit Electrique charging station backend CVSS Vendor Equipment Vulnerabilities v3 9.8 Hydro-Québec Hydro-Québec Le Circuit Electrique charging station backend Improper A…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-01cisa_alerts · tlp:amber · 7/7/2026, 12:00:00 PM
Siemens SINEC OS View CSAF Summary SINEC OS before V4.0 contains multiple vulnerabilities. Siemens has released a new version for RUGGEDCOM RST2428P and recommends to update to the latest version. The following versions of Siemens SINEC OS are affected: RUGGEDCOM RST2428P (6GK6242-6PA00) vers:intdot/<4.0 CVSS Vendor Equipment Vulnerabilities v3 9.8 Siemens Siemens SINEC OS Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Resource Shu…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-05cisa_alerts · tlp:amber · 7/7/2026, 12:00:00 PM
Siemens Mendix Studio Pro View CSAF Summary Mendix Studio Pro versions before V11.12 are affected by a file parsing vulnerability that could be triggered when the application reads specially crafted malicious project during the build pipeline. This could allow an attacker to execute arbitrary code in the context of that user. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versi…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-04cisa_alerts · tlp:amber · 7/2/2026, 12:00:00 PM
ST Engineering iDirect iQ-Series Terminals View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. The following versions of ST Engineering iDirect iQ-Series Terminals are affected: Evolution iQ‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057) 3315‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057) 9‑Series terminals <=4.5.…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-01cisa_alerts · tlp:amber · 7/2/2026, 12:00:00 PM
CubeSpace CW0057 Reaction Wheel View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to upload arbitrary malicious firmware to the device. The following versions of CubeSpace CW0057 Reaction Wheel are affected: CW0057 Reaction Wheel CVSS Vendor Equipment Vulnerabilities v3 6.1 CubeSpace CubeSpace CW0057 Reaction Wheel Improper Verification of Cryptographic Signature Background Critical Infrastructure Sectors: Communications Countries/Areas …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-02cisa_alerts · tlp:amber · 7/2/2026, 12:00:00 PM
Gardyn IoT Hub View CSAF Summary Successful exploitation of these vulnerabilities could allow unauthenticated users to access and control IoT Hub managed devices. The following versions of Gardyn IoT Hub are affected: Home Firmware Studio Firmware Cloud API <2.12.2026 (CVE-2026-13768, CVE-2026-55726, CVE-2026-54477) CVSS Vendor Equipment Vulnerabilities v3 10 Gardyn Gardyn IoT Hub Use of Hard-coded Credentials, Exposure of Sensitive System Information to an Unauthorized C…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-03cisa_alerts · tlp:amber · 7/1/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-45659 Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Securi…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/07/01/cisa-adds-one-known-exploited-vulnerability-catalogcisa_alerts · tlp:amber · 6/30/2026, 12:00:00 PM
StoneFly Storage Concentrator View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to gain broad unauthorized access, execute arbitrary commands with root privileges, steal sensitive data, and perform actions on behalf of legitimate users across interconnected systems. The following versions of StoneFly Storage Concentrator are affected: Storage Concentrator <8.0.4.22 (CVE-2026-56415, CVE-2026-55721, CVE-2026-50040) Storage Concentrator…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-06cisa_alerts · tlp:amber · 6/30/2026, 12:00:00 PM
XZ Utils vulnerability impacting B&R Products View CSAF Summary An update is available that resolves vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the product to stop or corrupt memory data. The following versions of XZ Utils vulnerability impacting B&R Products are affected: PPC3100 <1.8.1, 1.8.1 (CVE-2025-31115) C50 <1.8.0, 1.8.0 (CVE-2025-31115) C80 <1.8.0, 1.8.0…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-05cisa_alerts · tlp:amber · 6/30/2026, 12:00:00 PM
Schneider Electric EasyLogic T150 and Saitel DP RTU View CSAF Summary Successful exploitation of these vulnerabilities can allow an attacker to cause unauthorized access and exposure of sensitive information when the unauthenticated attacker accesses credentials stored within firmware or system files. The following versions of Schneider Electric EasyLogic T150 and Saitel DP RTU are affected: EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller <=11.06…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-04cisa_alerts · tlp:amber · 6/30/2026, 12:00:00 PM
OFFIS DCMTK Toolkit View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to write files, access unauthorized information, exhaust memory, or crash affected DCMTK client or server processes. The following versions of OFFIS DCMTK Toolkit are affected: DCMTK <=3.7.0 (CVE-2026-50003, CVE-2026-50254, CVE-2026-35505, CVE-2026-52868, CVE-2026-44628) CVSS Vendor Equipment Vulnerabilities v3 9.8 OFFIS OFFIS DCMTK Toolkit Improper Limitation of…
Read original ↗https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-181-01cisa_alerts · tlp:amber · 6/30/2026, 12:00:00 PM
Delta Electronics DVP12SE PLC View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to remotely issue commands, modify operational values, interfere with control logic, and alter device behavior without authentication or privilege enforcement. The following versions of Delta Electronics DVP12SE PLC are affected: DVP12SE PLC vers:all/* (CVE-2026-12819, CVE-2026-12818) CVSS Vendor Equipment Vulnerabilities v3 9.8 Delta Electronics Delta Ele…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-07