Radar
A personal hobby project. Radar aggregates security advisories from CISA, Zero Day Initiative and CERT-EU and adds short editorial highlights on what I find notable from a European infrastructure perspective — not a threat-intel service, not exhaustive, just what catches my eye.
-
OpenPLC v3
An authenticated attacker can write arbitrary files via a legacy web UI upload flaw, potentially leading to native code execution through the default compilation process.
Read more → -
Schneider Electric PowerChute Serial Shutdown
The advisory explicitly states that PowerChute Serial Shutdown versions 1.4 and prior are affected by multiple vulnerabilities, including path traversal and CRLF injection.
Read more → -
CISA KEV — Adobe ColdFusion (CVE-2026-48282)
CVE-2026-48282 is a path traversal vulnerability in Adobe ColdFusion that has been observed as actively exploited.
Read more → -
CISA KEV — JoomShaper SP Page Builder (CVE-2026-48908) +2 more
The advisory adds three vulnerabilities involving page builders and a low-code platform, all tied to web-facing components with access control or file upload flaws.
Read more → -
Siemens SINEC OS
The advisory states that SINEC OS versions prior to 4.0 contain multiple vulnerabilities, including buffer overflows and improper access control, with a maximum CVSS score of 9.8.
Read more → -
Hitachi Energy PROMOD V
The advisory states that PROMOD V versions 1.0.10 and prior use HTTP instead of HTTPS due to lack of HTTPS support in the third-party Digipede server, exposing data in transit.
Read more → -
Labcenter Proteus 9
The advisory states that Labcenter Proteus 9.1_SP4_Build_42914 is affected by multiple memory corruption vulnerabilities, including out-of-bounds write and stack-based buffer overflow. Successful exploitation could lead to arbitrary code execution.
Read more → -
Hitachi Energy e-mesh EMS
The vulnerability stems from NGINX components in e-mesh EMS using versions v1.30.0 or below, where specific rewrite rule configurations can trigger a heap buffer overflow.
Read more → -
Digi International PortServer TS, Digi One SP IA
The advisory states that affected Digi devices can allow unauthenticated access to restricted resources due to an authorization flaw.
Read more → -
Siemens Mendix Studio Pro
The advisory states that a file parsing vulnerability in Mendix Studio Pro could allow arbitrary code execution when processing a malicious project during the build pipeline.
Read more → -
Hydro-Québec Le Circuit Electrique charging station backend
The advisory states that affected charging station backends allowed unauthenticated websocket connections, potentially enabling privilege escalation.
Read more → -
ST Engineering iDirect iQ-Series Terminals
The advisory states that unauthenticated access to specific API endpoints can expose sensitive device information, including credentials used for satellite network authentication.
Read more → -
Gardyn IoT Hub
The advisory states that unauthenticated access to the iothubowner key could allow full control over managed devices and execution of arbitrary commands on connected devices.
Read more → -
CubeSpace CW0057 Reaction Wheel
The vulnerability requires physical access to upload malicious firmware, and the device can be recovered using the independent bootloader.
Read more → -
CISA KEV — Microsoft SharePoint Server (CVE-2026-45659)
The advisory states that CVE-2026-45659 in Microsoft SharePoint Server is being actively exploited, involving deserialization of untrusted data.
Read more → -
Delta Electronics DVP12SE PLC
The advisory states that all versions of the Delta Electronics DVP12SE PLC are affected by vulnerabilities allowing unauthenticated remote access to critical control functions via Modbus TCP.
Read more → -
XZ Utils vulnerability impacting B&R Products
The vulnerability stems from a race condition in the multithreaded .xz decoder within liblzma, which could lead to memory corruption or service disruption if exploited.
Read more → -
Frangoteam FUXA SCADA/HMI
The advisory states that unauthenticated remote attackers can exploit a path normalization flaw to access sensitive user and role data via the REST API.
Read more → -
StoneFly Storage Concentrator
The advisory identifies hardcoded credentials in a configuration file that can be decoded to plaintext, exposing access to multiple internal services.
Read more → -
Schneider Electric EcoStruxure IT Data Center Expert
The advisory states that affected versions of EcoStruxure IT Data Center Expert are susceptible to XML external entity reference exploitation, which could lead to server-side file disclosure when crafted payloads are submitted via SOAP endpoints.
Read more → -
Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M
The advisory states that a heap-based buffer overflow in the 7-Zip component of MELSOFT Update Manager could allow local attackers to execute arbitrary code via a specially crafted archive file.
Read more → -
OFFIS DCMTK Toolkit
The advisory states that DCMTK versions <=3.7.0 are affected by multiple vulnerabilities, including path traversal and memory management issues.
Read more → -
Schneider Electric EasyLogic T150 and Saitel DP RTU
Credentials are stored in firmware or system files without authentication requirements, exposing them to unauthenticated access.
Read more → -
CISA KEV — SimpleHelp (CVE-2026-48558)
CVE-2026-48558 is an authentication bypass vulnerability in SimpleHelp that has been added to CISA's KEV Catalog due to evidence of active exploitation.
Read more → -
Russian Intelligence Services Continue to Target Commercial Messaging Applications
The advisory updates previous reporting on Russian Intelligence Services targeting messaging app accounts, adding new phishing message samples and observed tactics.
Read more → -
CISA KEV — PTC Windchill and FlexPLM (CVE-2026-12569) +1 more
The advisory adds a server-side request forgery (SSRF) flaw in Cisco Unified Communications Manager and an input validation issue in PTC Windchill and FlexPLM to the KEV Catalog due to active exploitation.
Read more → -
EVoke Systems Charging Station Management System
The advisory states that all versions of EVoke CSMS are affected due to unauthenticated WebSocket endpoints that allow attackers to impersonate charging stations.
Read more → -
Horner Automation Cscape
The vulnerability affects Cscape versions prior to 10.2 SP3 and is triggered by parsing malicious CSP files, potentially leading to information disclosure and arbitrary code execution.
Read more → -
Yokogawa FAST/TOOLS and CI Server
The advisory states that affected versions of Yokogawa FAST/TOOLS and CI Server may transmit CI Server settings in cleartext, potentially enabling further attacks.
Read more → -
Schneider Electric PowerLogic P7
The advisory states that affected PowerLogic P7 devices may suffer loss of HMI operability and configuration functionality due to multiple vulnerabilities, including OS command injection and NULL pointer dereference.
Read more → -
pydicom pynetdicom Library
The vulnerability stems from unsanitized use of attacker-supplied data in file path operations within the qrscp application's C-STORE handler.
Read more → -
H.VIEW HV-500S6 IP Camera
The advisory states that command injection and unrestricted file upload vulnerabilities exist in the certificate generation and upload interfaces of the affected IP camera model.
Read more → -
OHIF Viewers DICOM
The advisory states that a server-side request forgery (SSRF) vulnerability in OHIF DICOM Web Viewer Framework versions up to v3.12.0 could result in unauthorized exfiltration of authenticated clinicians' OIDC Bearer tokens.
Read more → -
Delta Electronics DTM Soft
The advisory states that all versions of Delta Electronics DTM Soft are affected by a deserialization vulnerability. Exploitation requires user interaction to open a malicious project file.
Read more → -
Daktronics Controller Firmware
The advisory states that multiple Daktronics controller models are affected by vulnerabilities allowing unauthenticated root-level access, including path traversal and hardcoded credentials.
Read more → -
Using SASE in a Modern TIC 3.0 Solution
The advisory is informational guidance on integrating SASE with TIC 3.0, not a security vulnerability or mitigation notice.
Read more → -
CISA KEV — Lantronix EDS5000 (CVE-2025-67038) +3 more
The advisory adds four actively exploited vulnerabilities, three of which affect Ubiquiti UniFi OS, indicating a cluster of issues in the same product.
Read more → -
Siemens SINEC INS
The advisory states that SINEC INS before version 1.0 SP2 Update 6 is affected by an OS command injection vulnerability via the /api/sftp/uploadFiles endpoint, where crafted directory names can lead to arbitrary command execution.
Read more → -
Siemens Products using OpenSSL
The vulnerability affects multiple Siemens industrial communication products using OpenSSL, with a focus on router and server devices used in network infrastructure.
Read more → -
Hubbell Aclara Metrum Cellular Web Interface
The advisory states that critical functions in the Aclara Metrum Cellular Web Interface lack authentication, allowing unauthenticated attackers to alter settings and restart the device.
Read more → -
ABB Freelance Security Lock
The advisory notes that undocumented or special key combinations on modern keyboards could allow bypass of Freelance Operations, potentially granting access to underlying OS functions despite Security Lock being enabled.
Read more → -
Impact of Linux Kernel vulnerabilities on B&R products
The advisory identifies local privilege escalation risks in B&R products using affected Linux kernel versions, with public proof-of-concept exploits available.
Read more → -
Siemens SIPROTEC 5 Using DIGSI5 Protocol
The advisory states that authenticated users may exploit the DIGSI 5 protocol to upload arbitrary files, potentially leading to permanent denial of service. A new allow-list feature in updated versions restricts file uploads to mitigate the vulnerability.
Read more → -
Siemens WinCC Certificate Manager
The advisory states that WinCC Certificate Manager stores key material with insufficient protection, potentially allowing extraction of sensitive information.
Read more → -
CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure
The advisory states that approximately 74,000 Fortinet devices may have had credentials exposed, with active exploitation reported on internet-accessible systems.
Read more → -
CISA KEV — Splunk Enterprise (CVE-2026-20253)
The added vulnerability allows total control of affected systems post-exploitation and is already being actively exploited.
Read more → -
Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products
The advisory mentions PowerChute Serial Shutdown in the summary but lists vulnerabilities affecting Easergy, EcoStruxture, PowerLogic, and Saitel products, with no explicit link between them in the provided text.
Read more → -
Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module
The advisory states that all versions of the FX5-ENET/IP module are affected by a DoS vulnerability due to excessive packet processing. No fix is planned for this product.
Read more → -
Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT
The device transmits sensitive health data in cleartext over Bluetooth, exposing glucose measurements to interception by nearby attackers.
Read more → -
Rockwell Automation FactoryTalk Historian Site Edition
The advisory identifies a race condition that could allow attackers to obtain a valid authentication token by repeatedly sending requests to the login endpoint.
Read more → -
Schneider Electric EasyLogic T150 and Saitel DP
The same path traversal vulnerability (CVE-2026-6865) affects two related Schneider Electric remote terminal units, potentially allowing unauthorized access to sensitive files.
Read more → -
AzeoTech DAQFactory
The advisory states that loading untrusted .ctl files in AzeoTech DAQFactory <=21.1 may lead to arbitrary code execution due to a type confusion vulnerability.
Read more → -
Mitsubishi Electric MELSEC iQ-F Series
The affected module may enter a denial-of-service state due to improper handling of rapid TCP connections, leading to memory access issues.
Read more → -
AVer PTC cameras
The advisory states that all versions of the affected AVer PTC camera models are vulnerable to arbitrary code execution via a crafted web request.
Read more → -
CISA KEV — Widget Factory Joomla Content Editor (CVE-2026-48907)
The vulnerability allows improper access control in the Widget Factory Joomla Content Editor, potentially enabling full system control post-exploitation.
Read more → -
Rockwell Automation CompactLogix
The advisory states that exposed Connection IDs on the web interface can be abused to trigger a denial-of-service condition via improper validation of CIP protocol fields.
Read more → -
Rockwell Automation FactoryTalk Analytics PavilionX
The advisory states that affected versions of FactoryTalk Analytics PavilionX lack proper authorization controls on API endpoints, potentially allowing unauthenticated attackers to perform administrative actions.
Read more → -
Rockwell Automation FLEX I/O EtherNet/IP Adapters
The advisory states that exploitation could lead to unauthorized access and loss of availability due to memory handling and authentication flaws in specific FLEX I/O adapter versions.
Read more → -
Rockwell Automation RSLinx
The advisory states that exploitation can cause a denial of service where the application becomes unresponsive and does not recover automatically.
Read more → -
Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP
Devices with less memory are more likely to experience a major nonrecoverable fault when a crafted CIP message is sent.
Read more → -
CISA KEV — Cisco Catalyst SD-WAN Manager Directory or (CVE-2026-20262) +1 more
Two vulnerabilities involving path traversal in network and web management tools are now in the KEV catalog due to observed exploitation.
Read more → -
CISA KEV — Oracle PeopleSoft Enterprise PeopleTools (CVE-2026-35273)
The added vulnerability affects Oracle PeopleSoft Enterprise PeopleTools and involves missing authentication for a critical function.
Read more → -
CISA KEV — Ivanti Sentry (CVE-2026-10520)
The added vulnerability allows OS command injection, which the advisory explicitly states grants total control of the affected asset post-exploitation.
Read more → -
Brickcom Cameras
The advisory states that live video snapshots can be accessed without authentication via the /ONVIF endpoint on affected Brickcom camera models.
Read more → -
Naxclow IoT Platform
The advisory states that all versions of multiple Naxclow IoT devices are affected by an authorization bypass vulnerability allowing silent device reassignment via replayed onboarding sequences.
Read more → -
Yarbo Android/iOS Mobile Application and Cloud Infrastructure
Hard-coded credentials in the Yarbo mobile app grant access to all robot telemetry and command topics via the cloud MQTT infrastructure.
Read more → -
CISA KEV — Arista Extensible Operating System Incomplete Comparison (CVE-2026-7473) +2 more
The addition of a network infrastructure vulnerability in Arista's Extensible Operating System may indicate interest in targeting backbone devices.
Read more → -
Schneider Electric Modicon Network Managed Switches
The vulnerability only affects devices where the RADIUS Server Message Authenticator option is disabled, as the default configuration is not vulnerable.
Read more → -
Schneider Electric EcoStruxure Panel Server
The advisory states that affected EcoStruxure Panel Server versions may revert to initial credentials in rare circumstances, potentially allowing unauthorized authentication.
Read more → -
Siemens KACO Blueplanet Inverters
The advisory states that serial numbers from affected inverters can be used to derive credentials, enabling unauthorized access. This affects a wide range of KACO blueplanet inverter models across multiple product lines.
Read more → -
CISA KEV — BerriAI LiteLLM (CVE-2026-42271) +1 more
CVE-2026-42271 involves command injection in BerriAI LiteLLM, indicating potential for unauthorized command execution where the software is deployed.
Read more → -
CISA KEV — SolarWinds Serv-U (CVE-2026-28318)
CVE-2026-28318 is an uncontrolled resource consumption vulnerability in SolarWinds Serv-U, now listed in CISA's KEV Catalog due to evidence of active exploitation.
Read more → -
Hitachi Energy RTU500
The advisory lists multiple overlapping version ranges for the RTU500 series CMU firmware, with repeated CVEs across entries, which may indicate consolidated reporting of previously disclosed issues.
Read more → -
B&R PPT30 Operating System
The vulnerability affects the OPC-UA server in B&R PPT30 Operating System versions prior to 1.8.0 and could be exploited by an unauthenticated network-based attacker to block access to the service.
Read more → -
Hitachi Energy ITT600 Explorer
The affected ITT600 Explorer versions include those prior to 2.1 SP6 and specifically 2.1 SP6 itself, with a patch available in 2.1 SP6 HF1.
Read more → -
Hitachi Energy MACH HiDraw
The vulnerability affects MACH HiDraw versions 9.22 and prior, with exploitation requiring authenticated local access and a specially crafted XML file.
Read more → -
NAVTOR NavBox
The advisory states that hard-coded credentials in NavBox's SOAP implementation could allow a local attacker to bypass authentication and access privileged file operations.
Read more → -
CISA KEV — Mirasvit Full Page Cache Warmer (CVE-2026-45247)
The added vulnerability involves deserialization of untrusted data in a Magento extension, a flaw type often exploited to achieve remote code execution.
Read more → -
CISA KEV — Linux Kernel (CVE-2022-0492) +1 more
CVE-2022-0492 involves improper authentication in the Linux kernel, a component present in many enterprise and embedded systems. Its inclusion in the KEV catalog indicates observed exploitation despite its 2022 publication date.
Read more → -
CISA and Partners Urge Hardening Automatic Tank Gauge Systems
The advisory states that internet-exposed ATG systems are being targeted via hardcoded credentials and command execution. Removing these systems from public networks is explicitly recommended.
Read more → -
CISA KEV — Oracle WebLogic Server Unspecified (CVE-2024-21182)
CVE-2024-21182 is an unspecified vulnerability in Oracle WebLogic Server now confirmed as actively exploited.
Read more → -
CISA KEV — Palo Alto Networks PAN-OS (CVE-2026-0257)
CVE-2026-0257 is an authentication bypass vulnerability in Palo Alto Networks PAN-OS that CISA has observed being actively exploited.
Read more → -
Supply Chain Compromises Impact Nx Console and GitHub Repositories
The malicious Nx Console extension (18.95.0) was distributed via VS Code’s automatic update mechanism, potentially affecting systems without user interaction.
Read more → -
MacGregor Voyage Data Recorder (VDR) G4e
The advisory states that default credentials are present without enforced password changes, and authenticated users can extract password hashes via backup files.
Read more → -
KMW CCTV Security Cameras
The advisory states that affected KMW cameras allow unauthenticated password resets, enabling full access to camera feeds and settings.
Read more → -
XCharge C6
The advisory states that XCharge C6 devices with firmware prior to May 22, 2026, are affected by multiple critical vulnerabilities, including firmware update mechanisms that lack cryptographic validation.
Read more → -
CP Plus 8 Ch. Network Video Recorder
The advisory specifies a stored XSS vulnerability that persists in the device backend and executes when users access affected pages.
Read more → -
Fourth Frontier Frontier X Mobile Application, Frontier X2
The advisory states that unauthenticated BLE access allows read/write of critical GATT characteristics, and the mobile app does not authenticate the connected device, enabling spoofing and data injection.
Read more → -
ABB Busch-Welcome 2 Wire Door Opener Actuator
The advisory states that toggling the mode switch and restarting power can recalibrate the system to correct the misconfiguration.
Read more → -
Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter
The advisory states that hard-coded administrative credentials are present in the firmware of the affected device, which can be extracted and used to gain unauthorized access.
Read more → -
ABB EIBPORT
The advisory states that affected ABB EIBPORT devices can expose session IDs and allow configuration changes if exploited. A firmware update is available to address the vulnerabilities.
Read more → -
CISA KEV — Daemon Tools Lite Embedded Malicious Code (CVE-2026-8398) +2 more
The advisory adds two vulnerabilities involving embedded malicious code in developer tools, which may indicate supply chain compromise.
Read more → -
CISA KEV — LiteSpeed cPanel Plugin (CVE-2026-48172)
CVE-2026-48172 is a privilege escalation vulnerability in the LiteSpeed cPanel plugin, now added to CISA's KEV Catalog due to evidence of active exploitation.
Read more → -
ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM)
The advisory states that the System Diagnostics Manager (SDM) is disabled by default in Automation Runtime 6 and not intended to be enabled outside secured production networks.
Read more → -
ABB AC500 V2
The advisory states that fragments of previous Modbus responses may be exposed due to a buffer over-read when unsupported function codes are sent to the AC500 V2 Modbus server.
Read more → -
ABB AbilityTM Zenon Remote Transport Vulnerability
The vulnerability allows unauthorized reboot of the system via the Remote Transport Service due to missing authentication, but requires prior network access.
Read more → -
Eppendorf BioFlo 320
The advisory states that all versions of the Eppendorf BioFlo 320 bioreactor are affected due to a hard-coded password in a VNC server, which could allow full access if remote access is enabled.
Read more → -
ABB Ability Camera Connect
The advisory states that an outdated VLC media player component in ABB Ability Camera Connect versions up to 1.5.0.14 contains multiple memory-related vulnerabilities, with a CVSS score of 9.8.
Read more → -
ABB LVS MConfig
The advisory states that sensitive information, including passwords, may be stored in cleartext in memory during runtime and exposed via memory dump files.
Read more → -
ABB Terra AC
The advisory states that unencrypted OCPP communications can enable exploitation of a heap-based buffer overflow, potentially allowing remote firmware manipulation.
Read more →
Page 2 of 4 · 302 advisories