Radar
A personal hobby project. Radar aggregates security advisories from CISA, Zero Day Initiative and CERT-EU and adds short editorial highlights on what I find notable from a European infrastructure perspective — not a threat-intel service, not exhaustive, just what catches my eye.
-
Watchfire Controller Software
Watchfire Controller Software versions BC550 12.30, BC750 11.33/12.35, BC760 12.38/13.00, and BC760DC 12.39 are listed as affected by CVE-2026-5846. The vulnerability is caused by hard-coded RSA private keys embedded in the firmware.
Read more → -
Toptech Systems RCU II+ and Multiload II+
RCU II+ and Multiload II+ units released before 2025-11-24 expose an unauthenticated debug interface.
Read more → -
MikroTik RouterOS
All MikroTik RouterOS versions with the API enabled are affected by CVE-2026-14227.
Read more → -
Schneider Electric IGSS
The IGSS Definition module (Def.exe) versions up to 18.0.0.26124 are vulnerable to an out-of-bounds write via a crafted CGF file. Schneider Electric provides a fix in version 18.0.0.26125.
Read more → -
Mitsubishi Electric CC-Link IE TSN Communication Protocol
All listed Mitsubishi Electric CC-Link IE TSN controllers, modules, and interface boards are affected regardless of firmware version. Exploitation requires an attacker on the same network segment to send precisely timed packets.
Read more → -
NASA Core Flight System (cFS) Health & Safety (HS) Application
Versions up to 7.0.1 of NASA’s Core Flight System (cFS) Health & Safety (HS) application are vulnerable to a NULL pointer dereference that can cause a denial-of-service.
Read more → -
Open Source Software: Security Principles and Practices
CISA released guidance on securely using, evaluating, and publishing open source software. The guidance covers OSS risk management and vulnerability management.
Read more → -
ZDI-26-502: (Pwn2Own) Phoenix Contact CHARX SEC-3150 user-applications Link Following Local Privilege Escalation Vulnerability
The advisory notes a local privilege escalation on Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-503: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Race Condition Firewall Bypass Vulnerability
Unauthenticated network-adjacent attackers can bypass firewall rules on Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-504: (Pwn2Own) Phoenix Contact CHARX SEC-3150 CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability
Unauthenticated remote code execution is possible on Phoenix Contact CHARX SEC-3150 devices via configuration injection.
Read more → -
ZDI-26-505: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx-system-config-manager Service CRLF Injection Firewall Bypass Vulnerability
Unauthenticated network-adjacent attackers can bypass firewall rules on Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-506: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Insertion of Sensitive Information into Log File Authentication Bypass Vulnerability
Authentication can be bypassed without credentials on Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-507: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Privilege Defined With Unsafe Actions Local Privilege Escalation Vulnerability
Local privilege escalation on Phoenix Contact CHARX SEC-3150 requires prior low-privileged code execution.
Read more → -
ZDI-26-508: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx_set_ip_address Improper Input Validation Local Privilege Escalation Vulnerability
Improper input validation in charx_set_ip_address enables local privilege escalation on Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-509: (Pwn2Own) Phoenix Contact CHARX SEC-3150 OCPP Missing Authentication for Critical Function Authentication Bypass Vulnerability
Unauthenticated network-adjacent attackers can modify configuration on Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-510: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Missing Cryptographic Signature Remote Code Execution Vulnerability
Network-adjacent attackers can bypass firmware validation on Phoenix Contact CHARX SEC-3150 devices without authentication.
Read more → -
ZDI-26-511: (Pwn2Own) Phoenix Contact CHARX SEC-3150 user-applications Symlink Following Local Privilege Escalation Vulnerability
The advisory notes a local privilege escalation via symlink following on Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-512: (Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability
Unauthenticated network-adjacent attackers can cause a denial-of-service on the Phoenix Contact CHARX SEC-3150 ModBus server.
Read more → -
ZDI-26-513: (Pwn2Own) Phoenix Contact CHARX SEC-3150 update2-upload Arbitrary File Upload Vulnerability
Authenticated, network-adjacent attackers can upload arbitrary files to Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-514: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Failing Open Authentication Bypass Vulnerability
Authentication can be bypassed without credentials on Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-515: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx-jupicore Missing Authentication Configuration Modification Vulnerability
Unauthenticated configuration modification is possible on Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-516: (Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability
Unauthenticated attackers can trigger a denial-of-service on Phoenix Contact CHARX SEC-3150 ModBus servers.
Read more → -
ZDI-26-517: (Pwn2Own) Phoenix Contact CHARX SEC-3150 BackendURL WebSocket Command Injection Remote Code Execution Vulnerability
The advisory notes that authentication can be bypassed, enabling remote code execution via a WebSocket BackendURL command injection.
Read more → -
ZDI-26-518: (Pwn2Own) Phoenix Contact CHARX SEC-3150 MQTT Service Server-Side Request Forgery Remote Code Execution Vulnerability
Unauthenticated network-adjacent attackers can exploit an SSRF flaw in the MQTT service of Phoenix Contact CHARX SEC-3150 devices. The issue is identified as CVE-2026-44091 with a CVSS score of 6.3.
Read more → -
ZDI-26-519: (Pwn2Own) Phoenix Contact CHARX SEC-3150 CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability
Unauthenticated remote code execution is possible on Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-520: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Jupicore External Control of Path Remote Code Execution Vulnerability
Unauthenticated remote code execution is possible on Phoenix Contact CHARX SEC-3150 devices.
Read more → -
ZDI-26-521: Phoenix Contact CHARX SEC-3000 Command Injection Remote Code Execution Vulnerability
Authentication is required to exploit the command injection on CHARX SEC-3000 devices.
Read more → -
ZDI-26-522: Phoenix Contact CHARX SEC-3000 Insertion of Sensitive Information into Log File Information Disclosure Vulnerability
Unauthenticated network-adjacent attackers can retrieve sensitive data from the CHARX SEC-3000 log file.
Read more → -
ZDI-26-523: Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability
Deserialization of untrusted checkpoint files can lead to remote code execution.
Read more → -
CISA KEV — Cisco Secure Firewall Management Center (CVE-2026-20316)
CISA added CVE-2026-20316 for Cisco Secure Firewall Management Center to the KEV catalog due to active exploitation.
Read more → -
2026 Minimum Elements for a Software Bill of Materials (SBOM)
The guidance updates the NTIA 2021 minimum elements for SBOMs and incorporates 2025 stakeholder feedback.
Read more → -
ZDI-26-487: (Pwn2Own) Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability
The udhcpd daemon on Kenwood DNR1007XR devices has an incorrect permission assignment that enables local privilege escalation.
Read more → -
ZDI-26-488: (Pwn2Own) Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution Vulnerability
The vulnerability is a heap-based buffer overflow in the vCardParser of Kenwood DNR1007XR.
Read more → -
ZDI-26-489: (Pwn2Own) Kenwood DNR1007XR startUpdateProcess Command Injection Vulnerability
Unauthenticated command injection in startUpdateProcess enables arbitrary code execution on Kenwood DNR1007XR devices.
Read more → -
ZDI-26-490: (Pwn2Own) Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability
The advisory notes that the vulnerability stems from incorrect default USB permissions on the Kenwood DNR1007XR, allowing local privilege escalation. Exploitation requires a low-privileged code execution step and physical presence.
Read more → -
ZDI-26-491: Apple macOS CoreAudio Out-Of-Bounds Write Remote Code Execution Vulnerability
Exploitation requires the victim to open a malicious file or visit a malicious webpage.
Read more → -
ZDI-26-492: Apple macOS ImageIO Numeric Truncation Remote Code Execution Vulnerability
The issue is a numeric truncation flaw in macOS’s ImageIO library.
Read more → -
ZDI-26-493: Apple macOS USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Exploitation requires interaction with the macOS USD library and triggers a heap-based buffer overflow.
Read more → -
ZDI-26-494: Apple macOS USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Exploitation requires interaction with the macOS USD library and triggers a heap-based buffer overflow.
Read more → -
ZDI-26-495: (Pwn2Own) VMware ESXi VMXNET3 espQueueMask Out-Of-Bounds Write Local Privilege Escalation Vulnerability
The advisory notes a local privilege escalation vulnerability in VMware ESXi.
Read more → -
ZDI-26-496: Trend AI Cleaner One Pro Link Following Arbitrary File Deletion Vulnerability
Local low-privileged code can delete arbitrary files via the link-following feature in Trend Micro Cleaner One Pro.
Read more → -
ZDI-26-497: TrendAI Vision One Service Gateway Logs Information Disclosure Vulnerability
Remote authenticated attackers can obtain sensitive information from TrendAI Vision One Service Gateway logs.
Read more → -
ZDI-26-498: TrendAI Vision One Incorrect Privilege Assignment Privilege Escalation Vulnerability
Remote authenticated attackers can elevate privileges on TrendAI Vision One.
Read more → -
ZDI-26-499: WatchGuard FireWare OS cli Token Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability
Authentication is required to exploit a stack-based buffer overflow in the WatchGuard FireWare OS CLI token parser.
Read more → -
ZDI-26-500: WatchGuard FireWare OS networkd network_wireless_kick_off_user_cb Stack-based Buffer Overflow Remote Code Execution Vulnerability
Exploitation requires valid authentication credentials.
Read more → -
ZDI-26-501: WatchGuard FireWare OS sigd comp_start_cb Directory Traversal Arbitrary File Creation Vulnerability
Remote authenticated attackers can create arbitrary files via the sigd comp_start_cb directory traversal in WatchGuard FireWare OS.
Read more → -
ZDI-26-453: GIMP HDR File Parsing Integer Overflow Remote Code Execution Vulnerability
Exploitation requires a user to open a malicious HDR file or visit a crafted webpage.
Read more → -
ZDI-26-454: GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability
Integer overflow in GIMP's PSD file parser can lead to remote code execution.
Read more → -
ZDI-26-455: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
GIMP’s TIF parser contains a heap-based buffer overflow that can be triggered by a crafted TIF file.
Read more → -
ZDI-26-456: GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
The flaw is a stack-based buffer overflow in GIMP’s TIF parser that requires the victim to open a crafted file or page.
Read more → -
ZDI-26-457: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability
GIMP’s TIF parser contains an integer overflow that can be triggered by a crafted TIF file.
Read more → -
ZDI-26-458: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability
The flaw is an integer overflow in GIMP’s TIF parser that can be triggered by a crafted file. Exploitation requires the victim to open the file or view it via a malicious page.
Read more → -
ZDI-26-459: GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability
The flaw is an integer overflow in GIMP's SGI file parser that requires the victim to open a crafted file or page.
Read more → -
ZDI-26-460: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Exploitation requires a user to open a crafted TIF file or view it via a malicious web page. The vulnerability is a heap-based buffer overflow in GIMP’s TIF parser.
Read more → -
ZDI-26-461: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability
GIMP’s TIF file parser contains an integer overflow that can be triggered by a crafted TIF file, leading to remote code execution. Exploitation requires the victim to open the malicious file or load a page hosting it.
Read more → -
ZDI-26-462: GIMP APNG File Parsing Integer Overflow Remote Code Execution Vulnerability
Exploitation requires a user to open a crafted APNG file or visit a page delivering it.
Read more → -
ZDI-26-463: GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Exploitation requires the victim to open a malicious file or visit a malicious page.
Read more → -
ZDI-26-464: GStreamer MRF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Exploitation requires a victim to open a malicious file or visit a malicious page.
Read more → -
ZDI-26-465: GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
Exploitation requires a user to open a malicious OGG file or visit a crafted page.
Read more → -
ZDI-26-466: GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
GStreamer’s PNG parser suffers a heap-based buffer overflow.
Read more → -
ZDI-26-467: GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability
The advisory notes a use-after-free in GStreamer’s rtpsbcdepay element that can be remotely triggered.
Read more → -
ZDI-26-468: Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote Code Execution Vulnerability
Remote code execution is possible via deserialization of untrusted data in Aeon's load_rehab_pile_dataset function, requiring the victim to load a malicious page or file.
Read more → -
ZDI-26-469: Aeon load_human_activity_segmentation_datasets Code Injection Remote Code Execution Vulnerability
Remote code execution is possible if a user visits a malicious page or opens a malicious file while using aeon.
Read more → -
ZDI-26-470: Aeon load_time_series_segmentation_benchmark Code Injection Remote Code Execution Vulnerability
Exploitation requires the victim to load a malicious page or file. The flaw permits remote code execution with a CVSS score of 7.8.
Read more → -
ZDI-26-471: (Pwn2Own) Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability
The exploit requires a malicious Bluetooth device to be paired before information disclosure can occur.
Read more → -
ZDI-26-472: (Pwn2Own) Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability
Unauthenticated attackers on the same network can trigger a buffer overflow via the RTSP SETUP command.
Read more → -
ZDI-26-473: (Pwn2Own) Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability
Physically present attackers can exploit the vulnerability without authentication. The advisory assigns a CVSS score of 3.9.
Read more → -
ZDI-26-474: (Pwn2Own) Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnerability
Exploitation requires a successful Bluetooth pairing before the heap overflow can be triggered.
Read more → -
ZDI-26-475: (Pwn2Own) Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability
The heap-based buffer overflow resides in the AVRCP_Br_Response_Parser of the Sony XAV-9500ES. Exploitation requires a Bluetooth device to be paired with the unit.
Read more → -
ZDI-26-476: (Pwn2Own) Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability
Physical attackers can bypass authorization on Sony XAV-9500ES devices via the udev USB rules.
Read more → -
ZDI-26-477: (Pwn2Own) Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation Vulnerability
The advisory reports a local privilege escalation via command injection in the crash dump handler of Sony XAV-9500ES.
Read more → -
ZDI-26-478: Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability
Adminer installations are vulnerable to remote code execution due to an incorrect check of the multi_query function’s return value.
Read more → -
ZDI-26-479: Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability
Authentication is required to exploit the uploadJar directory traversal RCE in Heimdall Data Database Proxy.
Read more → -
ZDI-26-480: OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability
OSNEXUS QuantaStor can be remotely compromised without authentication.
Read more → -
ZDI-26-481: Progress Software Kemp LoadMaster access Missing Authorization Privilege Escalation Vulnerability
Remote attackers can gain higher privileges on Progress Software Kemp LoadMaster after authenticating.
Read more → -
ZDI-26-482: Progress Software Kemp LoadMaster enablexroot Use of Hard-Coded Cryptographic Key Privilege Escalation Vulnerability
Remote authenticated attackers can gain higher privileges on Kemp LoadMaster due to a hard-coded cryptographic key.
Read more → -
ZDI-26-483: NoMachine getstat Command Injection Remote Code Execution Vulnerability
Exploitation of the NoMachine getstat command requires authentication.
Read more → -
ZDI-26-484: (Pwn2Own) Kenwood DNR1007XR Firmware Update Link Following Code Execution Vulnerability
Unauthenticated code execution is possible via the firmware update link on Kenwood DNR1007XR devices.
Read more → -
ZDI-26-485: (Pwn2Own) Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerability
The advisory reports a command injection in JKGenService that enables local privilege escalation on Kenwood DNR1007XR devices.
Read more → -
ZDI-26-486: (Pwn2Own) Kenwood DNR1007XR tchdr_bytestream_read Out-Of-Bounds Write Code Execution Vulnerability
Unauthenticated physically present attackers can achieve arbitrary code execution on Kenwood DNR1007XR devices.
Read more → -
igloohome Smart Lock Mobile Application
Version 3.2.3 and earlier of the igloohome Smart Lock Mobile Application for Android contain source code that includes sensitive information, potentially allowing unauthorized access to backend services.
Read more → -
ABB KNX Update Tool
ABB KNX Update Tool versions ≤ 2.0.175 lack firmware integrity checks and can be rendered unusable via physical bus access.
Read more → -
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
The advisory lists dozens of CVEs affecting the GNU/Linux subsystem of firmware V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP.
Read more → -
Siemens Desigo CC
Siemens Desigo CC V7, V8, and V9 versions prior to 9.0.1 are vulnerable to CVE-2025-15467.
Read more → -
Siemens SIMATIC S7-PLCSIM Advanced
The vulnerability allows an unauthenticated attacker on the local network to cause a denial-of-service condition via high-volume multicast traffic. Siemens is preparing fix versions and recommends mitigation steps.
Read more → -
MikroTik RouterOS and Cloud Hosted Router
All MikroTik RouterOS and Cloud Hosted Router versions are affected by CVE-2026-16347, which permits rapid password guessing due to missing rate-limiting.
Read more → -
Siemens Mendix Runtime
Developers may unintentionally grant the anonymous role access to all System.User records. This can expose sensitive user data or enable privilege escalation.
Read more → -
CI Fortify – Advice for isolating vital systems
The guidance advises critical infrastructure organizations to isolate vital operational technology and enabling systems from all other networks during disruptions.
Read more → -
CISA KEV — Fortinet FortiOS (CVE-2025-68686) +1 more
Fortinet FortiOS and Arista VeloCloud Orchestrator on-prem have been added to CISA’s KEV catalog due to active exploitation. The advisory advises rapid remediation for publicly exposed assets.
Read more → -
Panduit IntraVUE
IntraVUE versions up to 3.2.1a14 store passwords in cleartext via the API. The same versions also allow an attacker to act as an active proxy, bypassing OT segmentation.
Read more → -
Johnson Controls C-CURE 9000 and Victor application server
Versions of C-CURE 9000 and Victor up to v2.90_v3.0 (and Victor Web up to v7.1) are vulnerable to unauthenticated remote code execution. The flaw can be triggered from an adjacent network and affect physical-security workstations.
Read more → -
MZ Automation lib60870
Versions of MZ Automation lib60870 up to 2.4.0 are vulnerable to an out-of-bounds read that can cause a denial-of-service. The vendor recommends updating to 2.4.1 or later.
Read more → -
MZ Automation libIEC61850
libIEC61850 versions 1.0.0 through 1.6.1 are affected by stack- and heap-based buffer overflows. The advisory advises updating to the latest build.
Read more → -
Johnson Controls XAAP Android
Versions of the Johnson Controls XAAP Android app prior to 1.53 store data in cleartext on the device.
Read more → -
Weintek cMT3092X
Versions of the cMT3092X firmware earlier than 20210218 and EasyWeb earlier than v2.1.20 are vulnerable to privilege escalation via cookie manipulation.
Read more → -
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
The advisory notes a view-based exploit in Zimbra Collaboration Suite that can exfiltrate recent email and address data when a malicious email is viewed.
Read more → -
ZDI-26-447: Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability
Remote code execution is possible via a CRLF injection in generateFileContent, but authentication is required. The advisory assigns a CVSS score of 7.2.
Read more → -
ZDI-26-448: Bitdefender Total Security Shredder Link Following Local Privilege Escalation Vulnerability
The vulnerability enables privilege escalation from a low-privileged process on Bitdefender Total Security.
Read more → -
ZDI-26-449: AzeoTech DAQFactory CTL File Parsing Type Confusion Remote Code Execution Vulnerability
Exploitation requires a victim to load a malicious CTL file via a web page or local file.
Read more → -
ZDI-26-450: AzeoTech DAQFactory CTL File Parsing Use-After-Free Remote Code Execution Vulnerability
Exploitation requires a victim to open a crafted CTL file or visit a malicious page, triggering a use-after-free.
Read more →
Page 2 of 9 · 805 advisories