Radar
A personal hobby project. Radar aggregates security advisories from CISA, Zero Day Initiative and CERT-EU and adds short editorial highlights on what I find notable from a European infrastructure perspective — not a threat-intel service, not exhaustive, just what catches my eye.
-
Schneider Electric Modicon Network Managed Switches
The vulnerability only affects devices where the RADIUS Server Message Authenticator option is disabled, as the default configuration is not vulnerable.
Read more → -
Schneider Electric EcoStruxure Panel Server
The advisory states that affected EcoStruxure Panel Server versions may revert to initial credentials in rare circumstances, potentially allowing unauthorized authentication.
Read more → -
Siemens KACO Blueplanet Inverters
The advisory states that serial numbers from affected inverters can be used to derive credentials, enabling unauthorized access. This affects a wide range of KACO blueplanet inverter models across multiple product lines.
Read more → -
ZDI-26-347: Adobe Acrobat Reader DC Multimedia Rendition Use-After-Free Remote Code Execution Vulnerability
The vulnerability is triggered by user interaction with a malicious file or page, indicating delivery likely depends on social engineering.
Read more → -
ZDI-26-348: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
The vulnerability is a use-after-free in Adobe Acrobat Reader DC related to annotation handling, requiring user interaction to trigger.
Read more → -
ZDI-26-349: Adobe Acrobat Pro DC Annots.api Use-After-Free Remote Code Execution Vulnerability
A use-after-free vulnerability exists in Adobe Acrobat Pro DC's Annots.api component, requiring user interaction to trigger.
Read more → -
ZDI-26-350: Adobe USD-Fileformat-plugins Heap-based Buffer Overflow Remote Code Execution Vulnerability
A heap-based buffer overflow exists in Adobe USD-Fileformat-plugins that could allow remote code execution upon interaction with the USD library.
Read more → -
ZDI-26-351: Adobe USD-Fileformat-plugins Heap-based Buffer Overflow Remote Code Execution Vulnerability
The vulnerability involves a heap-based buffer overflow in Adobe USD-Fileformat-plugins that requires interaction with the USD library for exploitation.
Read more → -
ZDI-26-352: Adobe Acrobat Pro DC AcroForm Use-After-Free Remote Code Execution Vulnerability
The vulnerability is a use-after-free in Adobe Acrobat Pro DC's AcroForm functionality, requiring user interaction to trigger.
Read more → -
ZDI-26-353: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
The vulnerability is a use-after-free in Adobe Acrobat Reader DC related to annotation handling, requiring user interaction to trigger.
Read more → -
ZDI-26-354: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
The vulnerability is a use-after-free in Adobe Acrobat Reader DC related to annotation handling, requiring user interaction to trigger via a malicious file or page.
Read more → -
ZDI-26-333: X.Org Server XkbSetCompatMap Integer Underflow Privilege Escalation Vulnerability
The vulnerability involves an integer underflow in X.Org Server's XkbSetCompatMap function, which can be triggered by a local attacker to escalate privileges.
Read more → -
ZDI-26-334: X.Org Server CheckSetGeom Out-Of-Bounds Read Information Disclosure Vulnerability
The vulnerability is an out-of-bounds read in the CheckSetGeom function of X.Org Server, potentially disclosing sensitive information to local attackers.
Read more → -
ZDI-26-335: X.Org Server SyncAwaitFence Use-After-Free Privilege Escalation Vulnerability
A use-after-free in X.Org Server's SyncAwaitFence function may allow local privilege escalation.
Read more → -
ZDI-26-336: X.Org Server CheckKeyActions Out-Of-Bounds Read Information Disclosure Vulnerability
The vulnerability is a local out-of-bounds read in the CheckKeyActions function of X.Org Server, potentially disclosing sensitive information.
Read more → -
ZDI-26-337: X.Org Server CheckKeyTypes Buffer Overflow Privilege Escalation Vulnerability
A buffer overflow in X.Org Server's CheckKeyTypes function may allow local privilege escalation.
Read more → -
ZDI-26-338: NVIDIA Transformers4Rec Model.load Deserialization of Untrusted Data Remote Code Execution Vulnerability
The vulnerability requires user interaction, such as opening a malicious file or visiting a malicious page, to trigger remote code execution.
Read more → -
ZDI-26-339: Microsoft Windows Narrator Braille Support brlapi Exposed Dangerous Function Local Privilege Escalation Vulnerability
The vulnerability affects Microsoft Windows systems with Braille support for Narrator enabled, requiring local code execution and specific feature installation for exploitation.
Read more → -
ZDI-26-340: Progress Software Kemp LoadMaster dodelapikey Uninitialized Memory Remote Code Execution Vulnerability
The vulnerability requires authentication and involves uninitialized memory in the dodelapikey function, potentially leading to remote code execution.
Read more → -
ZDI-26-341: Progress Software Kemp LoadMaster dolistapikeys Uninitialized Memory Remote Code Execution Vulnerability
The vulnerability requires authentication and affects the dolistapikeys functionality in Progress Software Kemp LoadMaster.
Read more → -
ZDI-26-342: Progress Software Kemp LoadMaster apiuser Uninitialized Memory Remote Code Execution Vulnerability
The vulnerability affects the apiuser component in Progress Software Kemp LoadMaster and can be exploited remotely without authentication.
Read more → -
ZDI-26-343: Adobe Acrobat Reader DC TIF File Parsing Integer Overflow Remote Code Execution Vulnerability
The vulnerability stems from an integer overflow during TIF file parsing in Adobe Acrobat Reader DC, requiring user interaction to trigger.
Read more → -
ZDI-26-344: Adobe Acrobat Reader DC Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability
The vulnerability involves an out-of-bounds read in the Doc object within Adobe Acrobat Reader DC, potentially disclosing sensitive information.
Read more → -
ZDI-26-345: Adobe Acrobat Reader DC Font Handling Use-After-Free Remote Code Execution Vulnerability
The vulnerability is triggered through malicious file or page interaction, indicating an attack vector dependent on user action.
Read more → -
ZDI-26-346: Adobe Acrobat Reader DC Annotation Use-After-Free Information Disclosure Vulnerability
The vulnerability is a use-after-free in Adobe Acrobat Reader DC related to annotation handling, requiring user interaction to trigger.
Read more → -
ZDI-26-332: QEMU calc_image_hostmem Integer Overflow Local Privilege Escalation Vulnerability
The vulnerability involves an integer overflow in QEMU's calc_image_hostmem function, potentially allowing local privilege escalation within the guest environment.
Read more → -
CISA KEV — BerriAI LiteLLM (CVE-2026-42271) +1 more
CVE-2026-42271 involves command injection in BerriAI LiteLLM, indicating potential for unauthorized command execution where the software is deployed.
Read more → -
CISA KEV — SolarWinds Serv-U (CVE-2026-28318)
CVE-2026-28318 is an uncontrolled resource consumption vulnerability in SolarWinds Serv-U, now listed in CISA's KEV Catalog due to evidence of active exploitation.
Read more → -
Hitachi Energy RTU500
The advisory lists multiple overlapping version ranges for the RTU500 series CMU firmware, with repeated CVEs across entries, which may indicate consolidated reporting of previously disclosed issues.
Read more → -
B&R PPT30 Operating System
The vulnerability affects the OPC-UA server in B&R PPT30 Operating System versions prior to 1.8.0 and could be exploited by an unauthenticated network-based attacker to block access to the service.
Read more → -
Hitachi Energy ITT600 Explorer
The affected ITT600 Explorer versions include those prior to 2.1 SP6 and specifically 2.1 SP6 itself, with a patch available in 2.1 SP6 HF1.
Read more → -
Hitachi Energy MACH HiDraw
The vulnerability affects MACH HiDraw versions 9.22 and prior, with exploitation requiring authenticated local access and a specially crafted XML file.
Read more → -
NAVTOR NavBox
The advisory states that hard-coded credentials in NavBox's SOAP implementation could allow a local attacker to bypass authentication and access privileged file operations.
Read more → -
ZDI-26-329: (Pwn2Own) Microsoft Edge Origin Validation Error Security Bypass Vulnerability
The vulnerability requires user interaction, such as visiting a malicious page, to exploit a security bypass in Microsoft Edge.
Read more → -
ZDI-26-330: (Pwn2Own) Microsoft Edge Navigation Handling Universal Cross-Site Scripting Vulnerability
The vulnerability requires user interaction to visit a malicious page or open a malicious file, indicating execution depends on social engineering.
Read more → -
ZDI-26-331: (Pwn2Own) Microsoft Edge Feedback Log File Handling Directory Traversal Remote Code Execution Vulnerability
The vulnerability involves directory traversal in Microsoft Edge's feedback log file handling, potentially enabling remote code execution with user interaction.
Read more → -
ZDI-26-328: ASUS Business Manager Service Client-Side Authentication Local Privilege Escalation Vulnerability
The vulnerability involves client-side authentication in the ASUS Business Manager Service, which may allow local privilege escalation if exploited.
Read more → -
CISA KEV — Mirasvit Full Page Cache Warmer (CVE-2026-45247)
The added vulnerability involves deserialization of untrusted data in a Magento extension, a flaw type often exploited to achieve remote code execution.
Read more → -
ZDI-26-327: Docker Desktop grpcfuse Kernel Module Uncontrolled Recursion Denial-of-Service Vulnerability
The vulnerability resides in the Docker Desktop grpcfuse kernel module, which can be triggered by low-privileged code running inside a container.
Read more → -
CISA KEV — Linux Kernel (CVE-2022-0492) +1 more
CVE-2022-0492 involves improper authentication in the Linux kernel, a component present in many enterprise and embedded systems. Its inclusion in the KEV catalog indicates observed exploitation despite its 2022 publication date.
Read more → -
CISA and Partners Urge Hardening Automatic Tank Gauge Systems
The advisory states that internet-exposed ATG systems are being targeted via hardcoded credentials and command execution. Removing these systems from public networks is explicitly recommended.
Read more → -
CISA KEV — Oracle WebLogic Server Unspecified (CVE-2024-21182)
CVE-2024-21182 is an unspecified vulnerability in Oracle WebLogic Server now confirmed as actively exploited.
Read more → -
CISA KEV — Palo Alto Networks PAN-OS (CVE-2026-0257)
CVE-2026-0257 is an authentication bypass vulnerability in Palo Alto Networks PAN-OS that CISA has observed being actively exploited.
Read more → -
Supply Chain Compromises Impact Nx Console and GitHub Repositories
The malicious Nx Console extension (18.95.0) was distributed via VS Code’s automatic update mechanism, potentially affecting systems without user interaction.
Read more → -
MacGregor Voyage Data Recorder (VDR) G4e
The advisory states that default credentials are present without enforced password changes, and authenticated users can extract password hashes via backup files.
Read more → -
KMW CCTV Security Cameras
The advisory states that affected KMW cameras allow unauthenticated password resets, enabling full access to camera feeds and settings.
Read more → -
XCharge C6
The advisory states that XCharge C6 devices with firmware prior to May 22, 2026, are affected by multiple critical vulnerabilities, including firmware update mechanisms that lack cryptographic validation.
Read more → -
CP Plus 8 Ch. Network Video Recorder
The advisory specifies a stored XSS vulnerability that persists in the device backend and executes when users access affected pages.
Read more → -
Fourth Frontier Frontier X Mobile Application, Frontier X2
The advisory states that unauthenticated BLE access allows read/write of critical GATT characteristics, and the mobile app does not authenticate the connected device, enabling spoofing and data injection.
Read more → -
ABB Busch-Welcome 2 Wire Door Opener Actuator
The advisory states that toggling the mode switch and restarting power can recalibrate the system to correct the misconfiguration.
Read more → -
Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter
The advisory states that hard-coded administrative credentials are present in the firmware of the affected device, which can be extracted and used to gain unauthorized access.
Read more → -
ABB EIBPORT
The advisory states that affected ABB EIBPORT devices can expose session IDs and allow configuration changes if exploited. A firmware update is available to address the vulnerabilities.
Read more → -
ZDI-26-320: TrendAI Vision One Security Agent Origin Validation Error Local Privilege Escalation Vulnerability
The vulnerability requires an attacker to already have the ability to execute low-privileged code on the system.
Read more → -
ZDI-26-321: TrendAI Vision One Security Agent Origin Validation Error Local Privilege Escalation Vulnerability
The vulnerability requires prior execution of low-privileged code to enable local privilege escalation within TrendAI Vision One Security Agent.
Read more → -
ZDI-26-322: TrendAI Vision One Security Agent Origin Validation Error Local Privilege Escalation Vulnerability
The vulnerability requires prior execution of low-privileged code to enable local privilege escalation.
Read more → -
ZDI-26-323: TrendAI Vision One Security Agent Origin Validation Error Local Privilege Escalation Vulnerability
The vulnerability requires prior execution of low-privileged code to enable local privilege escalation.
Read more → -
ZDI-26-324: TrendAI Vision One Security Agent Origin Validation Error Local Privilege Escalation Vulnerability
The vulnerability is a local privilege escalation in TrendAI Vision One Security Agent due to origin validation error.
Read more → -
ZDI-26-325: TrendAI Vision One Security Agent Origin Validation Error Local Privilege Escalation Vulnerability
The vulnerability requires prior execution of low-privileged code to enable local privilege escalation in TrendAI Vision One Security Agent.
Read more → -
ZDI-26-326: TrendAI Vision One Security Agent Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability
The vulnerability is a time-of-check to time-of-use (TOCTOU) issue in the TrendAI Vision One Security Agent that can be exploited by local attackers to escalate privileges.
Read more → -
CISA KEV — Daemon Tools Lite Embedded Malicious Code (CVE-2026-8398) +2 more
The advisory adds two vulnerabilities involving embedded malicious code in developer tools, which may indicate supply chain compromise.
Read more → -
CISA KEV — LiteSpeed cPanel Plugin (CVE-2026-48172)
CVE-2026-48172 is a privilege escalation vulnerability in the LiteSpeed cPanel plugin, now added to CISA's KEV Catalog due to evidence of active exploitation.
Read more → -
ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM)
The advisory states that the System Diagnostics Manager (SDM) is disabled by default in Automation Runtime 6 and not intended to be enabled outside secured production networks.
Read more → -
ABB AC500 V2
The advisory states that fragments of previous Modbus responses may be exposed due to a buffer over-read when unsupported function codes are sent to the AC500 V2 Modbus server.
Read more → -
ABB AbilityTM Zenon Remote Transport Vulnerability
The vulnerability allows unauthorized reboot of the system via the Remote Transport Service due to missing authentication, but requires prior network access.
Read more → -
Eppendorf BioFlo 320
The advisory states that all versions of the Eppendorf BioFlo 320 bioreactor are affected due to a hard-coded password in a VNC server, which could allow full access if remote access is enabled.
Read more → -
ABB Ability Camera Connect
The advisory states that an outdated VLC media player component in ABB Ability Camera Connect versions up to 1.5.0.14 contains multiple memory-related vulnerabilities, with a CVSS score of 9.8.
Read more → -
ABB LVS MConfig
The advisory states that sensitive information, including passwords, may be stored in cleartext in memory during runtime and exposed via memory dump files.
Read more → -
ABB Terra AC
The advisory states that unencrypted OCPP communications can enable exploitation of a heap-based buffer overflow, potentially allowing remote firmware manipulation.
Read more → -
CISA KEV — Drupal Core (CVE-2026-9082)
CVE-2026-9082 is an SQL injection vulnerability in Drupal Core that is already being exploited in the wild.
Read more → -
CISA KEV — Langflow Origin Validation Error (CVE-2025-34291) +1 more
CVE-2026-34926 affects Trend Micro Apex One (On-Premise), a locally deployed endpoint security solution, and is actively exploited.
Read more → -
ABB B&R PCs
The advisory states that multiple ABB B&R PC models are affected by several vulnerabilities allowing remote code execution, DoS, DNS cache poisoning, or information disclosure.
Read more → -
ABB B&R Automation Runtime
The advisory states that the System Diagnostic Manager (SDM) is disabled by default in Automation Runtime 6 and is not intended to be enabled outside secure environments.
Read more → -
ABB B&R Automation Studio
The advisory lists 23 CVEs affecting ABB B&R Automation Studio versions prior to 6.5, primarily tied to outdated components like SQLite, with a CVSS score of 9.8.
Read more → -
Hitachi Energy GMS600
The advisory states that affected GMS600 versions use a vulnerable OpenSSL component enabling potential plaintext recovery via timing attacks.
Read more → -
ABB Terra AC Wallbox
The advisory states that exploitation requires prior Bluetooth hijacking, and communication is encrypted, which may limit attack feasibility.
Read more → -
ZDI-26-318: Progress Software Kemp LoadMaster ssodomain_killsession Command Injection Remote Code Execution Vulnerability
Authentication is required to exploit the command injection vulnerability in Kemp LoadMaster's ssodomain_killsession function.
Read more → -
ZDI-26-319: Progress Software Kemp LoadMaster addcountry Command Injection Remote Code Execution Vulnerability
Authentication is required to exploit the command injection vulnerability in Kemp LoadMaster's addcountry function.
Read more → -
Schnieider Electric EcoStruxure Machine Expert HVAC (SEVD-2026-132-01)
The advisory states that versions of EcoStruxure Machine Expert HVAC prior to 1.10.0 store sensitive information in cleartext, potentially exposing protected source code during editing or compiling.
Read more → -
CISA KEV — Microsoft Windows (CVE-2008-4250) +6 more
The advisory includes two recently added vulnerabilities in Microsoft Defender, a security product with broad deployment across federal systems.
Read more → -
ZKTeco CCTV Cameras
An undocumented, unauthenticated configuration export port on affected ZKTeco cameras can expose camera account credentials and service information.
Read more → -
ScadaBR
The advisory states that ScadaBR 1.2.0 is affected by multiple vulnerabilities, including unauthenticated remote code execution. Notably, the vendor has not responded to CISA's outreach for coordination.
Read more → -
ABB CoreSense HM and CoreSense M10
The advisory states that unauthenticated users can exploit a path traversal vulnerability to access restricted directories, potentially leading to full system compromise.
Read more → -
Siemens RUGGEDCOM APE1808 Devices
The advisory states that all versions of the Siemens RUGGEDCOM APE1808 are affected due to a buffer overflow in the User-ID Authentication Portal service inherited from Palo Alto Networks' PAN-OS software.
Read more → -
Kieback & Peter DDC Building Controllers
The advisory states that multiple Kieback & Peter DDC building controllers are affected by a cross-site scripting vulnerability allowing JavaScript execution in the victim's browser.
Read more → -
CISA KEV — Microsoft Exchange Server (CVE-2026-42897)
CVE-2026-42897 is a cross-site scripting vulnerability in Microsoft Exchange Server now added to the KEV Catalog due to evidence of active exploitation.
Read more → -
CISA KEV — Cisco Catalyst SD-WAN Controller (CVE-2026-20182)
CISA has added a Cisco Catalyst SD-WAN Controller authentication bypass vulnerability (CVE-2026-20182) to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation.
Read more → -
Siemens SIPROTEC 5
Session identifier entropy issue in Siemens SIPROTEC 5 protection relays affects numerous hardware variants. The advisory notes that not all product endpoints use the vulnerable session mechanism.
Read more → -
Siemens SIMATIC
Unprotected help links on Siemens HMI panels allow unauthenticated web browser access. This may enable attackers to find backdoors and cause misconfigurations.
Read more → -
Siemens Industrial Devices
A single denial-of-service vulnerability (CVE-2025-40833 affects over 20 distinct Siemens industrial network devices. Patches are available for some products, while countermeasures are recommended for others awaiting fixes.
Read more → -
Siemens SIMATIC S7 PLC Web Server
SIMATIC S7 PLC web servers contain cross-site scripting vulnerabilities affecting multiple controller models. Siemens has released patches for some products and recommends mitigation for others.
Read more → -
Siemens Ruggedcom Rox
An authenticated attacker can read arbitrary files from the underlying OS filesystem via the web server's JSON-RPC interface. The advisory explicitly states these devices are used in critical manufacturing.
Read more → -
Siemens Opcenter RDnL
The advisory states that an unauthenticated attacker on an adjacent network can force a broker to connect to a rogue broker. The advisory notes that message integrity impact is low due to a missing auto refresh feature.
Read more → -
Siemens SENTRON 7KT PAC1261 Data Manager
The advisory states the vulnerability permits request smuggling in the web server of an energy sector device. This can lead to administrative control via stolen authorization tokens.
Read more → -
Siemens Solid Edge
Two vulnerabilities in Siemens Solid Edge allow arbitrary code execution via crafted PAR files. The advisory notes deployment in critical manufacturing sectors worldwide.
Read more → -
Siemens Teamcenter
Teamcenter V2312 and V2406 incorporate a vulnerable PDF.js component (CVE-2024-4367) from Firefox/Thunderbird. Multiple versions across the product line are affected by three distinct CVEs.
Read more → -
Siemens Ruggedcom Rox
An authenticated remote attacker can execute arbitrary commands as root via feature key installation. The vulnerability affects multiple Ruggedcom Rox models in versions prior to 2.17.1.
Read more → -
Universal Robots Polyscope 5
An unauthenticated attacker can execute code via OS command injection in Universal Robots Polyscope 5 Dashboard Server. Versions below 5.25.1 are affected.
Read more → -
Siemens Simcenter Femap
The advisory states that Simcenter Femap has a heap-based buffer overflow when reading IPT files. Siemens recommends updating to version 2512.0003 or later.
Read more → -
Siemens Ruggedcom Rox
Siemens Ruggedcom Rox before v2.17.1 bundles multiple third-party vulnerabilities spanning 2019 to 2025. The advisory explicitly recommends updating to the latest versions.
Read more → -
Siemens Ruggedcom Rox
This vulnerability allows authenticated attackers to escalate to root command execution via the scheduler. Siemens has released new versions for all affected Ruggedcom Rox products.
Read more →
Page 5 of 9 · 806 advisories