Radar
A personal hobby project. Radar aggregates security advisories from CISA, Zero Day Initiative and CERT-EU and adds short editorial highlights on what I find notable from a European infrastructure perspective — not a threat-intel service, not exhaustive, just what catches my eye.
-
ABB Ability Edgenius
ABB Ability Edgenius versions 3.2.0.0 through 3.2.4.0 are listed as affected by CVE-2026-31431. ABB provides an update to version 3.2.4.1 that resolves the issue.
Read more → -
Schneider Electric PowerChute Serial Shutdown
Versions ≤1.5 and 1.6 of PowerChute Serial Shutdown are vulnerable to CVE-2026-13348.
Read more → -
Schneider Electric Modicon M340 Controller and Communication Modules
The advisory reports a denial-of-service vulnerability in Schneider Electric Modicon M340 controllers and several communication modules.
Read more → -
Schneider Electric NetBotz 5 750/755
NetBotz 5 750/755 devices running firmware 5.5.2 or earlier are vulnerable to OS command injection and Hibernate SQL injection.
Read more → -
Bransys ELD
Bransys ELD versions prior to Android 11.00.00 and iOS 1.1.54 contain hard-coded MQTT credentials and transmit data in cleartext. These flaws could let an attacker read telemetry data and firmware.
Read more → -
Hitachi Energy FACTS Control Platform (FCP)
Hitachi Energy FACTS Control Platform versions 3.4.0 through 4.1.1 with the GWS component are vulnerable, scoring 9.9 CVSS.
Read more → -
Mitsubishi Electric GX Works3 and Motion Control Settings
All versions of Mitsubishi Electric GX Works3 and Motion Control Settings are affected by CVE-2026-15688. A local attacker can bypass the block password and modify the program memory.
Read more → -
ZDI-26-714: Samsung rlottie Stack-based Buffer Overflow Remote Code Execution Vulnerability
A stack-based buffer overflow in Samsung rlottie enables remote code execution.
Read more → -
CISA KEV — Cisco Identity Services Engine (CVE-2026-76460) +1 more
Cisco Identity Services Engine and Acronis Backup have been added to CISA’s Known Exploited Vulnerabilities catalog.
Read more → -
Using Cyber Decoys to Strengthen Detection and Response
Cyber decoys provide high-fidelity alerts that can reveal adversaries using legitimate credentials and living-off-the-land tools.
Read more → -
CISA KEV — Google Pixel (CVE-2026-58704)
CISA added CVE-2026-58704, an improper authorization vulnerability affecting Google Pixel devices, to its Known Exploited Vulnerabilities catalog.
Read more → -
ZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability
Unauthenticated remote code execution via CommandSinkRmi deserialization in Cisco Secure Firewall Management Center.
Read more → -
ZDI-26-710: NoMachine mDNS Heap-based Buffer Overflow Remote Code Execution Vulnerability
Unauthenticated remote code execution via a heap-based buffer overflow in NoMachine's mDNS handling.
Read more → -
ZDI-26-711: NoMachine Redis Improper Authentication Local Privilege Escalation Vulnerability
The vulnerability permits local privilege escalation on NoMachine installations via improper authentication in the Redis component.
Read more → -
ZDI-26-712: NoMachine nxhtd Server-Side Request Forgery Information Disclosure Vulnerability
Unauthenticated attackers can exploit an SSRF flaw in NoMachine’s nxhtd service to issue arbitrary server-side requests.
Read more → -
ZDI-26-713: GIMP APNG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
GIMP's APNG parser contains a stack-based buffer overflow.
Read more → -
ZDI-26-703: (0Day) Airbyte SharePoint Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability
The Airbyte SharePoint connector’s _get_shared_drive_object endpoint can be abused for SSRF.
Read more → -
ZDI-26-704: (0Day) Airbyte OneDrive Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability
Airbyte's OneDrive connector can be abused for SSRF when authenticated.
Read more → -
ZDI-26-705: (0Day) BusyBox libarchive Symlink Directory Traversal Arbitrary File Creation Vulnerability
BusyBox's libarchive component can be abused via a symlink directory traversal to create arbitrary files.
Read more → -
ZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution Vulnerability
Remote attackers can execute code by loading a malicious agent configuration.
Read more → -
ZDI-26-707: (0Day) MindsDB OpenBBtable Code Injection Remote Code Execution Vulnerability
Remote code execution is possible on MindsDB OpenBBtable installations, but exploitation requires authentication.
Read more → -
ZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability
Local privilege escalation via the Windows HTTP Proxy component.
Read more → -
CareCam CM2507
CareCam CM2507 firmware v251211.1507 lacks authentication for its video streaming service, permitting unauthenticated retrieval of live video.
Read more → -
Siemens Reyrolle 7SR5
Versions of Siemens Reyrolle 7SR5 earlier than V2.70 contain multiple high-severity vulnerabilities. Siemens provides an update to V2.70 or later.
Read more → -
Wärtsilä FOS-Onboard
Wärtsilä FOS-Onboard version 5.07.0923.01 contains hard-coded cryptographic keys. Wärtsilä has released a security patch for the issue.
Read more → -
Siemens Mendix SAML
Versions of Siemens Mendix SAML earlier than 4.2.3 (Mendix 10/11) or 3.6.27 (Mendix 9.24) are vulnerable to CVE-2026-80465. The flaw allows unauthenticated remote attackers to hijack a user session in specific SSO configurations.
Read more → -
Siemens Teamcenter
A reflected cross-site scripting vulnerability exists in the /auth/ redirect flow of Siemens Teamcenter.
Read more → -
Schneider Electric SCADAPack x70 Products
All listed SCADAPack x70 models are affected by CVE-2026-81861. The advisory recommends using RBAC instead of the Secure Lock feature.
Read more → -
mySCADA myPRO Manager
Versions ≤ 2.1 of mySCADA myPRO Manager lack authentication for privileged functions, allowing unauthenticated access.
Read more → -
Digital Watchdog VMAX DVR and NVR Product Lineups
All firmware versions of Digital Watchdog VMAX DVR and NVR models are listed as vulnerable. The vulnerabilities could give an unauthenticated attacker full administrative control.
Read more → -
Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers
The report advises agencies and cloud providers to inventory and secure token validation and secret management processes. It emphasizes detection at scale for token misuse.
Read more → -
CISA KEV — Cisco Secure Email Gateway (CVE-2026-76461)
CVE-2026-76461 is a SQL injection vulnerability in Cisco Secure Email Gateway now listed in CISA’s KEV catalog.
Read more → -
ZDI-26-680: Linux Kernel Crypto Subsystem Use-After-Free Local Privilege Escalation Vulnerability
A use-after-free in the Linux kernel crypto subsystem enables local privilege escalation.
Read more → -
ZDI-26-681: Linux Kernel FUSE Subsystem Race Condition Local Privilege Escalation Vulnerability
A race condition in the Linux kernel FUSE subsystem permits local privilege escalation.
Read more → -
ZDI-26-682: Linux Kernel IPv6 Neighbour Discovery Uninitialized Memory Information Disclosure Vulnerability
Local exploitation requires high-privileged code execution to disclose information.
Read more → -
ZDI-26-683: Linux Kernel IPv6 VTI Subsystem Use-After-Free Local Privilege Escalation Vulnerability
The advisory reports a use-after-free flaw in the Linux kernel IPv6 VTI subsystem (CVE-2026-72463) with a CVSS score of 7.5.
Read more → -
ZDI-26-684: Linux Kernel KSMBD Query Directory Request Race Condition Remote Code Execution Vulnerability
Remote code execution is possible without authentication on Linux kernels with KSMBD enabled.
Read more → -
ZDI-26-685: Linux Kernel NFC NCI UART Driver Race Condition Local Privilege Escalation Vulnerability
A race condition in the Linux kernel NFC NCI UART driver can be used for local privilege escalation.
Read more → -
ZDI-26-686: Linux Kernel nftables Race Condition Local Privilege Escalation Vulnerability
A race condition in the nftables subsystem of the Linux kernel enables local privilege escalation.
Read more → -
ZDI-26-687: Linux Kernel Open vSwitch Flow Delete Use-After-Free Information Disclosure Vulnerability
A use-after-free in the Linux kernel's Open vSwitch flow-delete path can disclose kernel memory to a local low-privileged attacker.
Read more → -
ZDI-26-688: Linux Kernel OpenvSwitch Race Condition Local Privilege Escalation Vulnerability
The vulnerability is a race condition in the Linux kernel's OpenvSwitch component that enables local privilege escalation.
Read more → -
ZDI-26-689: Linux Kernel SCTP Subsystem Race Condition Information Disclosure Vulnerability
A race condition in the Linux kernel SCTP subsystem can disclose information to a local low-privileged attacker.
Read more → -
ZDI-26-690: Linux Kernel MCTP Routing Uninitialized Memory Information Disclosure Vulnerability
Local attackers can read sensitive data if they have high-privileged code execution on the target Linux kernel.
Read more → -
ZDI-26-691: Linux Kernel Netlink-based Wireless Configuration Integer Overflow Local Privilege Escalation Vulnerability
Integer overflow in the Linux kernel netlink-based wireless configuration can lead to local privilege escalation. Exploitation requires the attacker to have already executed code with high privileges.
Read more → -
ZDI-26-692: Linux Kernel eMPIA USB Device Driver Race Condition Code Execution Vulnerability
The vulnerability is a race condition in the eMPIA USB device driver that allows physically present attackers to execute arbitrary code.
Read more → -
ZDI-26-693: Linux Kernel ksmbd Share Configuration Race Condition Remote Code Execution Vulnerability
Only Linux kernels with ksmbd enabled are vulnerable, and exploitation requires authentication.
Read more → -
ZDI-26-694: Linux Kernel Net Scheduler Clsact Qdisc Use-After-Free Local Privilege Escalation Vulnerability
The advisory reports a use-after-free in the Linux kernel’s net scheduler clsact qdisc. It enables local privilege escalation.
Read more → -
ZDI-26-695: Linux Kernel NFSv4 Server Race Condition Remote Code Execution Vulnerability
The vulnerability allows remote attackers to execute arbitrary code on Linux Kernel installations with nfsd enabled, but authentication is required.
Read more → -
ZDI-26-696: Linux Kernel NTFS3 Journal Heap-based Buffer Overflow Code Execution Vulnerability
Local low-privilege code can trigger a heap-based overflow in the NTFS3 journal handling.
Read more → -
ZDI-26-697: Linux Kernel NTFS3 Out-Of-Bounds Read Information Disclosure Vulnerability
The NTFS3 driver in the Linux kernel has an out-of-bounds read that can disclose kernel memory.
Read more → -
ZDI-26-698: Linux Kernel NTFS3 Out-Of-Bounds Read Information Disclosure Vulnerability
The vulnerability is an out-of-bounds read in the Linux kernel's NTFS3 driver.
Read more → -
ZDI-26-699: Linux Kernel NTFS3 Out-of-Bounds Read Information Disclosure Vulnerability
The NTFS3 driver in the Linux kernel contains an out-of-bounds read that can disclose kernel memory.
Read more → -
ZDI-26-700: Linux Kernel QFQ Plus Scheduler Use-After-Free Local Privilege Escalation Vulnerability
The advisory reports a use-after-free bug in the Linux kernel’s QFQ Plus scheduler that enables local privilege escalation.
Read more → -
ZDI-26-701: Linux Kernel TLS Protocol Out-Of-Bounds Read Information Disclosure Vulnerability
The vulnerability permits local attackers to read sensitive data from the Linux kernel after obtaining high-privileged execution. It is identified as CVE-2026-64046.
Read more → -
ZDI-26-702: Linux Kernel usbnet Driver Race Condition Privilege Escalation Vulnerability
The vulnerability allows physically present attackers to elevate privileges on affected Linux Kernel installations. Authentication is not required to exploit.
Read more → -
CISA KEV — GitLab Community Edition and Enterprise Edition (CVE-2026-85706)
GitLab Community Edition and Enterprise Edition are listed in the KEV catalog for an actively exploited path-traversal flaw (CVE-2026-85706).
Read more → -
CISA KEV — JFrog Artifactory (CVE-2026-42016) +2 more
CISA added two JFrog Artifactory and one ConnectWise ScreenConnect CVEs to the KEV Catalog. The advisory notes they are actively exploited.
Read more → -
CISA KEV — MikroTik RouterOS (CVE-2026-67277) +1 more
CISA added two MikroTik RouterOS vulnerabilities to its KEV catalog.
Read more → -
AVEVA Pipeline Integrity Monitor
Versions of AVEVA Pipeline Integrity Monitor up to 2025 SP1 P1 build 7.1.9580.8513 are affected.
Read more → -
NextGen Healthcare Mirth Connect
Mirth Connect versions up to 4.7.1 are vulnerable to SQL injection and XXE flaws. The advisory recommends updating to version 4.7.2 or later.
Read more → -
Orthanc DICOM Server
Orthanc DICOM Server versions prior to 1.13.0 can be crashed via a crafted PNG or JPEG image.
Read more → -
2026-012: Critical Vulnerabilities in Check Point Products
Two CVSS 9.8 vulnerabilities affect Check Point Security Gateway, Management Server, and Spark Firewall when VPN is enabled. An unauthenticated remote attacker could execute arbitrary code.
Read more → -
ZDI-26-648: (Pwn2Own) OpenAI Codex External Control of System or Configuration Setting Remote Code Execution Vulnerability
Remote code execution in OpenAI Codex requires the victim to visit a malicious page or open a malicious file.
Read more → -
ZDI-26-649: (Pwn2Own) OpenAI Codex Improper Neutralization of Control Sequences Remote Code Execution Vulnerability
Exploitation requires the victim to open a crafted folder, leading to remote code execution.
Read more → -
ZDI-26-650: (Pwn2Own) OpenAI Codex External Control of Configuration Setting Remote Code Execution Vulnerability
Exploitation requires the victim to visit a malicious page or open a malicious file.
Read more → -
ZDI-26-651: (Pwn2Own) OpenAI Codex External Control of System or Configuration Setting Remote Code Execution Vulnerability
Remote code execution is possible when a user opens a crafted folder.
Read more → -
ZDI-26-652: TrendAI Apex One Security Agent Cache Mechanism Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability
The advisory notes a TOCTOU flaw in the cache mechanism of TrendAI Apex One Security Agent that enables local privilege escalation.
Read more → -
ZDI-26-653: TrendAI Apex One Security Agent Cache Mechanism Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability
A TOCTOU flaw in the Apex One Security Agent cache mechanism permits local privilege escalation.
Read more → -
ZDI-26-654: TrendAI Apex One Incomplete Cleanup Local Privilege Escalation Vulnerability
The vulnerability enables local privilege escalation after an attacker can run low-privileged code on the system.
Read more → -
ZDI-26-655: PAPPL Printer IPP Processing Stack-based Buffer Overflow Local Privilege Escalation Vulnerability
PAPPL's IPP processing stack contains a stack-based buffer overflow that can be used for local privilege escalation.
Read more → -
ZDI-26-656: PAPPL Job Processing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Unauthenticated remote code execution via a heap-based buffer overflow in PAPPL job processing.
Read more → -
ZDI-26-657: ASUS Control Center Express Agent Missing Authentication Remote Code Execution Vulnerability
ASUS Control Center Express Agent can be remotely exploited without authentication.
Read more → -
ZDI-26-658: Adobe Acrobat Pro DC JPEG Parsing Integer Overflow Remote Code Execution Vulnerability
An integer overflow in JPEG parsing can be triggered by a malicious PDF or web page, leading to remote code execution.
Read more → -
ZDI-26-659: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Adobe Acrobat Reader DC can disclose data via an out-of-bounds read when parsing JPEG2000 files.
Read more → -
ZDI-26-660: Adobe Acrobat Reader DC Font Parsing Use-After-Free Information Disclosure Vulnerability
Adobe Acrobat Reader DC can disclose sensitive information via a font-parsing use-after-free when a user opens a crafted PDF or visits a malicious page.
Read more → -
ZDI-26-661: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
The use-after-free occurs in Acrobat Reader DC’s annotation handling and requires a user to open a malicious file or visit a crafted page.
Read more → -
ZDI-26-662: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Exploitation requires the victim to open a crafted PDF or load a malicious webpage.
Read more → -
ZDI-26-663: Adobe Acrobat Pro DC Annotation Use-After-Free Remote Code Execution Vulnerability
Exploitation requires the victim to open a crafted PDF file or visit a malicious webpage.
Read more → -
ZDI-26-664: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Exploitation requires the victim to open a crafted PDF file or load a malicious webpage.
Read more → -
ZDI-26-665: Adobe Acrobat Reader DC Annots Report Use-After-Free Remote Code Execution Vulnerability
Exploitation requires the victim to open a malicious PDF file or visit a malicious web page.
Read more → -
ZDI-26-666: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Adobe Acrobat Reader DC may disclose memory contents when parsing crafted JPEG2000 files.
Read more → -
ZDI-26-667: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Exploitation requires the victim to open a malicious PDF or visit a malicious web page.
Read more → -
ZDI-26-668: Adobe Acrobat Reader DC Annotation Use-After-Free Information Disclosure Vulnerability
Exploitation requires the victim to open a malicious file or visit a malicious web page.
Read more → -
ZDI-26-669: Adobe Acrobat Reader DC JBIG2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
The flaw is an out-of-bounds read in the JBIG2 parser of Adobe Acrobat Reader DC.
Read more → -
ZDI-26-670: Adobe Acrobat Pro DC Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability
Adobe Acrobat Pro DC can disclose sensitive information via an out-of-bounds read.
Read more → -
ZDI-26-671: Adobe Acrobat Reader DC Dialog Object Type Confusion Remote Code Execution Vulnerability
Exploitation requires the victim to open a malicious PDF or visit a crafted web page.
Read more → -
ZDI-26-672: Adobe Acrobat Reader DC PDF File Parsing Integer Underflow Information Disclosure Vulnerability
An integer underflow in PDF parsing can disclose sensitive information.
Read more → -
ZDI-26-673: Adobe Acrobat Pro DC Doc Object Use-After-Free Remote Code Execution Vulnerability
Exploitation requires the victim to open a malicious file or visit a malicious web page.
Read more → -
ZDI-26-674: Adobe Acrobat Reader DC Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability
Exploitation requires the victim to open a malicious PDF file or load a malicious web page.
Read more → -
ZDI-26-675: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Exploitation requires the victim to open a crafted PDF or visit a malicious webpage.
Read more → -
ZDI-26-676: Adobe Acrobat Reader DC DigSig Use-After-Free Remote Code Execution Vulnerability
Exploitation requires the victim to open a malicious PDF file or load a malicious webpage.
Read more → -
ZDI-26-677: Adobe Photoshop DCM JPEG-LS Image Parsing Integer Overflow Remote Code Execution Vulnerability
Exploitation requires a user to open a malicious JPEG-LS file or visit a crafted page.
Read more → -
ZDI-26-678: Adobe Photoshop DCM File Parsing Integer Overflow Remote Code Execution Vulnerability
An integer overflow in Photoshop’s DCM file parser can enable remote code execution.
Read more → -
ZDI-26-679: Adobe Photoshop DCM JPEG Image Parsing Integer Overflow Remote Code Execution Vulnerability
Exploitation requires the victim to open a malicious JPEG file or visit a crafted page.
Read more → -
2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server
The advisory reports two remotely exploitable vulnerabilities affecting the SAP Kernel and NetWeaver Message Server. Both can lead to arbitrary OS command execution under the SAP installation account.
Read more → -
CISA KEV — Fortinet Multiple Products (CVE-2025-25249) +3 more
Four actively exploited CVEs affecting Fortinet, Citrix NetScaler, Google Chromium V8, and Cisco FMC have been added to CISA’s KEV Catalog.
Read more → -
ZDI-26-636: Oracle Outside In Technology PostScript File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Exploitation requires the victim to open a malicious file or visit a crafted web page.
Read more → -
ZDI-26-637: Oracle Outside In Technology GEM File Parsing Integer Overflow Remote Code Execution Vulnerability
Integer overflow in GEM file parsing can lead to remote code execution when a malicious file is opened.
Read more → -
ZDI-26-638: Oracle Outside In Technology WPS File Parsing Memory Corruption Remote Code Execution Vulnerability
Remote code execution is possible but requires the victim to visit a malicious page or open a malicious file.
Read more → -
ZDI-26-639: Oracle VirtualBox VMSVGA Heap-based Buffer Overflow Local Privilege Escalation Vulnerability
The issue is a heap-based buffer overflow in VirtualBox’s VMSVGA driver.
Read more →
Page 1 of 11 · 1,012 advisories