Radar
A personal hobby project. Radar aggregates security advisories from CISA, Zero Day Initiative and CERT-EU and adds short editorial highlights on what I find notable from a European infrastructure perspective — not a threat-intel service, not exhaustive, just what catches my eye.
-
ZDI-26-451: Docker Desktop for macOS Inference Server Permissive Allow List Sandbox Escape Vulnerability
Docker Desktop for macOS's model runner sandbox can be escaped by a local attacker who already has low-privileged code execution inside the sandbox.
Read more → -
ZDI-26-452: Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability
The vulnerability is an open redirect in Dify’s oauth_redirect_url parameter.
Read more → -
CISA KEV — Check Point SmartConsole (CVE-2026-16232) +1 more
Check Point SmartConsole and Microsoft SharePoint have been added to the KEV catalog due to active exploitation.
Read more → -
2026-009: Critical Vulnerability in Microsoft SharePoint
Microsoft SharePoint Server is affected by a critical remote code execution vulnerability. Proof-of-concept exploit code and successful attacks have been reported.
Read more → -
Rockwell Automation ThinManager
ThinManager versions prior to 13.0.8, 13.1.6, 13.2.5, and 14.0.3 are vulnerable to an authenticated path-traversal flaw.
Read more → -
Siemens Opcenter X
Siemens Opcenter X versions prior to V2604 are vulnerable to an authentication bypass via JWT header manipulation.
Read more → -
Rockwell Automation FactoryTalk Services Platform
FactoryTalk Directory (FTSP) version 6.60 is affected by a JWT signature validation bypass. The flaw enables impersonation of any authorized user on the FTSP server.
Read more → -
Siemens CADRA
CADRA versions earlier than V2511 are vulnerable to multiple high-severity zlib and Foxit flaws.
Read more → -
Rockwell Automation Studio 5000 Logix Designer
Versions V32.00 through V36.00 of Rockwell Automation Studio 5000 Logix Designer are listed as vulnerable. The advisory cites a path-traversal flaw that can lead to arbitrary file writes.
Read more → -
Rockwell Automation 1718-AENTR/1719-AENTR
Rockwell Automation 1718/1719 Ex I/O version 3.011 is vulnerable to a denial-of-service condition caused by a UDP unicast network storm.
Read more → -
Rockwell Automation 1734 POINT I/O
The 1734 POINT I/O module (v3.023) can be forced into a faulted state by crafted CIP messages, causing a denial-of-service.
Read more → -
Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW
All versions of the Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW are affected by PAN-OS vulnerabilities. The advisory directs customers to apply the workarounds published by Palo Alto Networks.
Read more → -
Siemens IAM Client
The advisory lists specific Siemens product versions vulnerable to an untrusted search path issue that could enable local privilege escalation. Siemens provides updated IAM Client versions for the affected products.
Read more → -
Siemens SIDIS Secured SmartPlug
Versions of Siemens SIDIS Secured SmartPlug earlier than V7.26.0310 are affected by multiple high-severity vulnerabilities.
Read more → -
Tycon Systems TPDIN-Monitor-WEB2
TPDIN-Monitor-WEB2 version 2.3.9 permits authentication bypass by submitting empty credentials.
Read more → -
CISA KEV — DD-WRT (CVE-2021-27137) +3 more
CISA added four actively exploited CVEs—including two WordPress core flaws—to its KEV Catalog.
Read more → -
ZDI-26-445: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability
The advisory notes a local privilege escalation via incorrect authorization in Windows WMI providers.
Read more → -
ZDI-26-446: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability
The advisory notes a local privilege escalation via incorrect authorization in Windows WMI providers.
Read more → -
CISA KEV — Fortinet FortiSandbox (CVE-2026-25089) +2 more
Two FortiSandbox OS command injection flaws and a SharePoint deserialization flaw have been added to the KEV catalog.
Read more → -
Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT
The advisory reports that crafted CIP Implicit Connection packets can cause a denial-of-service condition on the affected modules. Rockwell Automation provides firmware updates for EN2 and EN3 but none for ENBT.
Read more → -
AutomationDirect Productivity Suite
AutomationDirect Productivity Suite versions up to 4.6.2.2 are listed as affected.
Read more → -
Rockwell Automation Arena
Arena versions up to V17.00.00 are vulnerable to out-of-bounds write flaws that could allow arbitrary code execution.
Read more → -
NASA Core Flight System (cFS) Health & Safety (HS) Application
The HS application can crash on a routine Housekeeping Telemetry request, causing denial of service. Versions prior to 7.0.1 are affected.
Read more → -
Rockwell Automation FactoryTalk DataMosaix
FactoryTalk DataMosaix Private Cloud versions up to 8.02 are vulnerable to a stored cross-site scripting issue. An authenticated attacker could inject scripts that execute when other users view workflow pages.
Read more → -
SALTO ProAccess Space
Versions of SALTO ProAccess Space prior to 6.13 are vulnerable when the tenancy (partition) feature is enabled.
Read more → -
Siemens SICAM 8
Siemens SICAM 8 firmware versions prior to 26.20 (CPCI85) and 26.20.0 (SICORE) are vulnerable to denial-of-service via an authenticated HTTP debug interface.
Read more → -
Rockwell Automation Flex 5000 Adapter
Flex 5000 Adapter version 6.011 is vulnerable to a denial-of-service via crafted CIP packets.
Read more → -
Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix
Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix controllers are vulnerable to denial-of-service conditions. The vulnerability affects firmware versions up to V35.015 for several model families.
Read more → -
CISA KEV — KNX Association KNX Protocol Connection Authorization (CVE-2023-4346) +1 more
CISA added CVE-2023-4346 (KNX protocol) and CVE-2026-46817 (Oracle E-Business Suite) to the KEV catalog. Both are identified as actively exploited.
Read more → -
Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers
The guidance is aimed at software manufacturers and online service providers.
Read more → -
ZDI-26-444: 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
Heap-based buffer overflow in 7-Zip’s XZ decompression can lead to remote code execution when a crafted file is opened.
Read more → -
ZDI-26-405: X.Org Server GLX Extension Use-After-Free Privilege Escalation Vulnerability
The GLX extension in X.Org Server contains a use-after-free that enables local privilege escalation.
Read more → -
ZDI-26-406: X.Org Server BitmapScaleBitmaps Integer Overflow Privilege Escalation Vulnerability
An integer overflow in the BitmapScaleBitmaps function of X.Org Server can be leveraged for local privilege escalation.
Read more → -
ZDI-26-407: X.Org Server PCF Font Parsing Heap-based Buffer Overflow Privilege Escalation Vulnerability
Heap-based buffer overflow in X.Org Server's PCF font parser enables local privilege escalation.
Read more → -
ZDI-26-408: X.Org Server ComputeScaledProperties Heap-based Buffer Overflow Privilege Escalation Vulnerability
The advisory notes a heap-based buffer overflow in ComputeScaledProperties of X.Org Server that enables local privilege escalation.
Read more → -
ZDI-26-409: X.Org Server Glamor Font Heap-based Buffer Overflow Privilege Escalation Vulnerability
A heap-based buffer overflow in Glamor font handling of X.Org Server enables local privilege escalation.
Read more → -
ZDI-26-410: NVIDIA NeMo Framework Deserialization of Untrusted Data Remote Code Execution Vulnerability
Exploitation requires the victim to visit a malicious page or open a malicious file.
Read more → -
ZDI-26-411: NVIDIA NVTabular Pickle File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability
NVTabular deserializes untrusted pickle files, enabling remote code execution when a user opens a malicious file or visits a crafted page.
Read more → -
ZDI-26-412: (Pwn2Own) Microsoft SharePoint Deserialization of Untrusted Data Remote Code Execution Vulnerability
Unauthenticated remote code execution via SharePoint deserialization.
Read more → -
ZDI-26-413: (Pwn2Own) Microsoft SharePoint Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability
Unauthenticated remote code execution is possible on Microsoft SharePoint via improper verification of cryptographic signatures.
Read more → -
ZDI-26-414: Microsoft PowerShell Help Directory Traversal Remote Code Execution Vulnerability
PowerShell’s help system can be traversed to achieve remote code execution when a user opens a malicious file or visits a malicious page.
Read more → -
ZDI-26-415: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability
The advisory notes an incorrect authorization issue in Windows WMI providers that enables local privilege escalation.
Read more → -
ZDI-26-416: Microsoft Hyper-V netvsc Out-Of-Bounds Read Local Privilege Escalation Vulnerability
The netvsc driver contains an out-of-bounds read that can be leveraged for local privilege escalation.
Read more → -
ZDI-26-417: Microsoft Windows ServerManager Exposed Dangerous Method Local Privilege Escalation Vulnerability
The advisory describes a local privilege escalation vulnerability in Microsoft Windows Server.
Read more → -
ZDI-26-418: Microsoft SharePoint SPFieldMultiLineText Cross-Site Scripting Vulnerability
The advisory notes that SharePoint's SPFieldMultiLineText component is vulnerable to XSS that can be triggered by a malicious page or file.
Read more → -
ZDI-26-419: Adobe Creative Cloud AdobeUpdateService Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
The advisory notes a local privilege escalation via an uncontrolled search path element in AdobeUpdateService.
Read more → -
ZDI-26-420: Adobe Creative Cloud AGSService Incorrect Permission Assignment Local Privilege Escalation Vulnerability
The advisory notes that AGSService assigns incorrect permissions, allowing local privilege escalation.
Read more → -
ZDI-26-421: Cisco Identity Services Engine validFileNameOrPath Directory Traversal Information Disclosure Vulnerability
Remote authenticated attackers can exploit a directory traversal to disclose files on Cisco Identity Services Engine.
Read more → -
ZDI-26-422: Samsung rlottie Numeric Truncation Remote Code Execution Vulnerability
Remote code execution is possible via numeric truncation in Samsung rlottie.
Read more → -
ZDI-26-423: Synology DiskStation DS925+ MailPlus Redis Weak Cryptography for Passwords Remote Code Execution Vulnerability
Unauthenticated network-adjacent attackers can trigger remote code execution via the MailPlus Redis component on Synology DiskStation DS925+.
Read more → -
ZDI-26-424: Synology DiskStation DS925+ MailPlus Improper Restriction of Communication Channel to Intended Endpoints Vulnerability
Unauthenticated network-adjacent attackers can connect to the Redis service on DS925+ devices.
Read more → -
ZDI-26-425: OpenSSL OCSP Stapling Verification Double Free Remote Code Execution Vulnerability
OpenSSL’s OCSP stapling verification contains a double-free bug that can be triggered by a malicious server response.
Read more → -
ZDI-26-426: OpenSSL X.509 Email Validation Out-Of-Bounds Read Information Disclosure Vulnerability
The advisory notes an out-of-bounds read in OpenSSL’s X.509 email validation that can disclose information without authentication.
Read more → -
ZDI-26-427: WatchGuard FireWare OS iked ike2_hmac Null Pointer Dereference Denial-of-Service Vulnerability
Unauthenticated remote attackers can trigger a null-pointer dereference in the iked ike2_hmac function, causing a denial-of-service on WatchGuard FireWare OS VPN IKEv2.
Read more → -
ZDI-26-428: WatchGuard FireWare OS admd Stack-based Buffer Overflow Remote Code Execution Vulnerability
The admd service in WatchGuard FireWare OS has a stack-based buffer overflow that can be exploited remotely without authentication.
Read more → -
ZDI-26-429: NVIDIA NeMo Framework Deserialization of Untrusted Data Remote Code Execution Vulnerability
Exploitation requires the victim to load a malicious page or file.
Read more → -
ZDI-26-430: MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability
The vulnerability is a local privilege escalation in MSI Center's NTIOLib_X64 component.
Read more → -
ZDI-26-432: G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability
The advisory notes a local privilege escalation in G DATA Total Security (CVE-2026-13268).
Read more → -
ZDI-26-433: (Pwn2Own) Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability
Physical access enables arbitrary code execution on Autel MaxiCharger AC Elite Home EV chargers.
Read more → -
ZDI-26-434: (Pwn2Own) Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability
Physical attackers can bypass authentication on Autel MaxiCharger AC Elite Home EV chargers via USB.
Read more → -
ZDI-26-435: (Pwn2Own) Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability
A stack-based buffer overflow in the charger’s NFC stack can be triggered by a physically present attacker to execute code. No authentication is required.
Read more → -
ZDI-26-436: (Pwn2Own) Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability
Unauthenticated physical attackers can trigger a heap-based buffer overflow on Autel MaxiCharger AC Elite Home EV chargers.
Read more → -
ZDI-26-437: (Pwn2Own) Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability
Unauthenticated remote code execution via an integer underflow in the charger’s WebSockets interface. The issue affects Autel MaxiCharger AC Elite Home EV chargers.
Read more → -
ZDI-26-438: Rockwell Automation Arena Simulation DOE File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
A crafted DOE file can cause an out-of-bounds write in Arena Simulation, enabling remote code execution after a user opens the file or visits a malicious page.
Read more → -
ZDI-26-439: Fuji Electric Tellus pcid64 Driver Exposed Dangerous Method Local Privilege Escalation Vulnerability
The advisory describes a local privilege escalation vulnerability in Fuji Electric Tellus pcid64 Driver. Attackers can escalate privileges after executing low-privileged code.
Read more → -
ZDI-26-440: Fuji Electric Tellus pcid64 Driver Untrusted Pointer Dereference Denial of Service Vulnerability
The pcid64 driver contains an untrusted pointer dereference that can cause a local denial-of-service.
Read more → -
ZDI-26-441: dnsmasq DNS Response Heap-based Buffer Overflow Remote Code Execution Vulnerability
dnsmasq contains a heap-based buffer overflow in DNS response handling that permits remote code execution without authentication.
Read more → -
ZDI-26-442: Linux Kernel CAN ISO-TP Protocol Race Condition Local Privilege Escalation Vulnerability
The advisory reports a race condition in the Linux kernel's CAN ISO-TP protocol implementation.
Read more → -
ZDI-26-443: Linux Kernel vmwgfx Integer Overflow Local Privilege Escalation Vulnerability
The issue is an integer overflow in the Linux kernel vmwgfx driver that enables local privilege escalation.
Read more → -
ZDI-26-404: Delta Electronics DTM Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability
Exploitation requires the victim to open a malicious file or visit a malicious page.
Read more → -
CISA KEV — SonicWall SMA1000 Appliances (CVE-2026-15409) +3 more
SonicWall SMA1000 appliances are listed with both SSRF and code injection vulnerabilities in the KEV catalog.
Read more → -
CISA Urges SharePoint Hardening After New Exploitations
Active exploitation of CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 is targeting on-premises SharePoint Server.
Read more → -
ABB Advant Master Online Builder
ABB Advant Master Online Builder versions up to 6.1.1-3 are vulnerable to CVE-2025-13162.
Read more → -
ABB Ability Edgenius
ABB Ability Edgenius versions 3.2.0.0 through 3.2.4.0 are vulnerable to CVE-2026-31431. An update to version 3.2.4.1 resolves the issue.
Read more → -
Rockwell Automation 1715-AENTR EtherNet/IP Adapter
Versions up to 3.003 of the Rockwell Automation 1715-AENTR EtherNet/IP Adapter are vulnerable. The device exposes an unauthenticated debug port.
Read more → -
ABB T-MAC Plus
ABB T-MAC Plus version 4.0-24 is affected; ABB provides an update to version 4.0-25 that resolves the vulnerabilities.
Read more → -
CISA KEV — Cisco IOS (CVE-2008-4128)
CVE-2008-4128, a cross-site request forgery flaw in Cisco IOS, has been added to CISA’s KEV Catalog. The advisory urges rapid remediation on publicly exposed assets that grant total control.
Read more → -
Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
Russian FSB Center 16 actors are exploiting poorly configured and vulnerable networking devices worldwide.
Read more → -
CISA KEV — iCagenda (CVE-2026-48939) +1 more
CISA added CVE-2026-48939 and CVE-2026-56291 to its KEV Catalog. These vulnerabilities involve unrestricted file uploads with potentially harmful file types.
Read more → -
Schneider Electric Easergy MiCOM Px40 Series
The advisory states that hard-coded credentials in the SNMP protocol could allow unauthorized access to basic device identification.
Read more → -
OpenPLC v3
An authenticated attacker can write arbitrary files via a legacy web UI upload flaw, potentially leading to native code execution through the default compilation process.
Read more → -
Schneider Electric PowerChute Serial Shutdown
The advisory explicitly states that PowerChute Serial Shutdown versions 1.4 and prior are affected by multiple vulnerabilities, including path traversal and CRLF injection.
Read more → -
ZDI-26-398: (0Day) (Pwn2Own) Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability
Unauthenticated attackers on the same network can exploit a format-string flaw in the camera’s CDeviceOperator component to achieve remote code execution.
Read more → -
ZDI-26-399: (0Day) (Pwn2Own) Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability
Network-adjacent attackers can execute arbitrary code on Lorex 2K Indoor Wi-Fi cameras without user interaction.
Read more → -
ZDI-26-400: (0Day) AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability
AnyDesk installations are vulnerable to a local denial-of-service triggered via the screen-recording link feature.
Read more → -
ZDI-26-401: (0Day) AnyDesk Support Information Link Following Denial-of-Service Vulnerability
The vulnerability requires local code execution to trigger a denial-of-service condition via link following in AnyDesk.
Read more → -
ZDI-26-402: (0Day) Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability
The vulnerability involves link following in Glary Utilities that can lead to local privilege escalation.
Read more → -
ZDI-26-403: (0Day) Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability
Unauthenticated attackers can trigger a denial-of-service via the downloadBlob function.
Read more → -
CISA KEV — Adobe ColdFusion (CVE-2026-48282)
CVE-2026-48282 is a path traversal vulnerability in Adobe ColdFusion that has been observed as actively exploited.
Read more → -
CISA KEV — JoomShaper SP Page Builder (CVE-2026-48908) +2 more
The advisory adds three vulnerabilities involving page builders and a low-code platform, all tied to web-facing components with access control or file upload flaws.
Read more → -
Siemens SINEC OS
The advisory states that SINEC OS versions prior to 4.0 contain multiple vulnerabilities, including buffer overflows and improper access control, with a maximum CVSS score of 9.8.
Read more → -
Hitachi Energy PROMOD V
The advisory states that PROMOD V versions 1.0.10 and prior use HTTP instead of HTTPS due to lack of HTTPS support in the third-party Digipede server, exposing data in transit.
Read more → -
Labcenter Proteus 9
The advisory states that Labcenter Proteus 9.1_SP4_Build_42914 is affected by multiple memory corruption vulnerabilities, including out-of-bounds write and stack-based buffer overflow. Successful exploitation could lead to arbitrary code execution.
Read more → -
Hitachi Energy e-mesh EMS
The vulnerability stems from NGINX components in e-mesh EMS using versions v1.30.0 or below, where specific rewrite rule configurations can trigger a heap buffer overflow.
Read more → -
Digi International PortServer TS, Digi One SP IA
The advisory states that affected Digi devices can allow unauthenticated access to restricted resources due to an authorization flaw.
Read more → -
Siemens Mendix Studio Pro
The advisory states that a file parsing vulnerability in Mendix Studio Pro could allow arbitrary code execution when processing a malicious project during the build pipeline.
Read more → -
Hydro-Québec Le Circuit Electrique charging station backend
The advisory states that affected charging station backends allowed unauthenticated websocket connections, potentially enabling privilege escalation.
Read more → -
ST Engineering iDirect iQ-Series Terminals
The advisory states that unauthenticated access to specific API endpoints can expose sensitive device information, including credentials used for satellite network authentication.
Read more → -
Gardyn IoT Hub
The advisory states that unauthenticated access to the iothubowner key could allow full control over managed devices and execution of arbitrary commands on connected devices.
Read more → -
CubeSpace CW0057 Reaction Wheel
The vulnerability requires physical access to upload malicious firmware, and the device can be recovered using the independent bootloader.
Read more →
Page 3 of 9 · 805 advisories