Radar
A personal hobby project. Radar aggregates security advisories from CISA, Zero Day Initiative and CERT-EU and adds short editorial highlights on what I find notable from a European infrastructure perspective — not a threat-intel service, not exhaustive, just what catches my eye.
-
Siemens Ruggedcom Rox
This vulnerability allows authenticated attackers to escalate to root command execution via the scheduler. Siemens has released new versions for all affected Ruggedcom Rox products.
Read more → -
Siemens SIMATIC
SIMATIC CN 4100 versions before 5.0 contain 37 distinct vulnerability types. Siemens recommends updating to the latest version.
Read more → -
Siemens gWAP
The vulnerability originates in a third-party Axios library dependency and exploits prototype pollution to escalate into remote code execution. Siemens has released version 3.1.1 to address this issue.
Read more → -
Siemens Siemens ROS#
ROS# file_server before version 2.2.2 contains a relative path traversal vulnerability. The advisory recommends running the service only on trusted networks and with minimal user rights.
Read more → -
Fuji Electric Tellus
The vulnerability involves a kernel driver installed with Tellus that grants all users read and write permissions. This is a privilege escalation issue specific to version 5.0.2.
Read more → -
ABB Automation Builder Gateway for Windows
The Windows gateway listens remotely on port 1217 by default, which may expose PLC networks to scanning. Many users are unaware of this remote access feature as it is typically used locally.
Read more → -
ABB AC500 V3 Multiple Vulnerabilities
The advisory notes that exposed visualization files contain only static data, not live process data. The update is available in firmware version 3.9.0.
Read more → -
ABB WebPro SNMP Card PowerValue Multiple Vulnerabilities
The advisory specifies that these vulnerabilities were internally discovered by ABB. The affected device's Modbus service becomes unavailable until manually rebooted when exploited.
Read more → -
Subnet Solutions PowerSYSTEM Center
Multiple CVEs affect different versions of PowerSYSTEM Center, with the 2020, 2024, and 2026 product lines all impacted. The vendor specifies distinct update versions for each affected product line.
Read more → -
ABB AC500 V3 Stack Buffer Overflow in Cryptographic Message Syntax
A stack buffer overflow occurs during CMS message parsing before authentication, requiring no key material. The vulnerability affects ABB AC500 V3 PLCs used in critical infrastructure sectors.
Read more → -
Software Bill of Materials for AI - Minimum Elements
The advisory introduces supplemental minimum elements for AI-specific Software Bill of Materials. This guidance reflects international consensus from G7 partners and is intended to evolve with AI technology.
Read more → -
ZDI-26-311: Apple macOS CoreSymbolication Out-Of-Bounds Read Information Disclosure Vulnerability
The vulnerability involves an out-of-bounds read in the CoreSymbolication framework, potentially disclosing sensitive information.
Read more → -
ZDI-26-312: Apple Safari Web Inspector WebCore Style Resolver Use-After-Free Remote Code Execution Vulnerability
The vulnerability affects WebCore Style Resolver in Safari's Web Inspector. Exploitation requires user interaction through a malicious page or file.
Read more → -
ZDI-26-313: Apple Safari Regular Expression Duplicate Named Groups Heap-based Buffer Overflow Remote Code Execution Vulnerability
The vulnerability involves a heap-based buffer overflow in Apple Safari due to improper handling of duplicate named groups in regular expressions.
Read more → -
ZDI-26-314: Apple macOS USD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
A vulnerability in Apple macOS's USD library enables remote code execution via an out-of-bounds write.
Read more → -
ZDI-26-315: Apple macOS USD Out-Of-Bounds Read Information Disclosure Vulnerability
A remote out-of-bounds read vulnerability exists in Apple macOS USD library. Attack vectors depend on implementation.
Read more → -
ZDI-26-316: Siemens Simcenter Femap IPT File Parsing Memory Corruption Remote Code Execution Vulnerability
The vulnerability stems from memory corruption during IPT file parsing in Siemens Simcenter Femap, requiring user interaction for exploitation.
Read more → -
ZDI-26-317: Siemens Simcenter Femap IPT File Parsing Memory Corruption Remote Code Execution Vulnerability
The vulnerability stems from memory corruption during IPT file parsing in Siemens Simcenter Femap, requiring user interaction for exploitation.
Read more → -
ZDI-26-309: Microsoft Windows Message Queueing Double Free Local Privilege Escalation Vulnerability
This vulnerability requires a local attacker to first execute low-privileged code. The ZDI has assigned a CVSS rating of 7.8.
Read more → -
ZDI-26-310: Microsoft Windows splwow64 Race Condition Local Privilege Escalation Vulnerability
A race condition in splwow64 enables local privilege escalation when an attacker already has code execution. The vulnerability requires pre-existing access on the target system.
Read more → -
ZDI-26-308: Ivanti Endpoint Manager RemoteControlAuth Exposed Dangerous Method Information Disclosure Vulnerability
The vulnerability involves a method in Ivanti Endpoint Manager's RemoteControlAuth that exposes sensitive information, with authentication normally required but bypassable.
Read more → -
CISA KEV — BerriAI LiteLLM (CVE-2026-42208)
This advisory adds one vulnerability, CVE-2026-42208, to the Known Exploited Vulnerabilities catalog. The vulnerability affects BerriAI's LiteLLM and involves SQL injection.
Read more → -
MAXHUB Pivot Client Application
The advisory notes a hardcoded AES key in the MAXHUB Pivot client application allows decryption of tenant email addresses. An attacker can also cause denial-of-service by enrolling unauthorized devices.
Read more → -
CISA KEV — Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-6973)
CVE-2026-6973 is an improper input validation vulnerability in Ivanti Endpoint Manager Mobile (EPMM) now added to CISA's Known Exploited Vulnerabilities Catalog due to evidence of active exploitation.
Read more → -
CISA KEV — Palo Alto Networks PAN-OS (CVE-2026-0300)
CVE-2026-0300 is an out-of-bounds write vulnerability in Palo Alto Networks PAN-OS that is actively being exploited.
Read more → -
2026-006: Critical Vulnerability in PAN-OS
Palo Alto Networks reports limited exploitation of this vulnerability in the wild. The vulnerability permits unauthenticated attackers to execute arbitrary code with root privileges.
Read more → -
ABB B&R PVI
Logging is disabled by default, limiting the exposure of this vulnerability. The issue only affects PVI client applications, not server components.
Read more → -
Johnson Controls CEM AC2000
The vulnerability affects multiple versions of Johnson Controls CEM AC2000 with a CVSS score of 8.7. The advisory explicitly mentions deployment in critical infrastructure sectors worldwide.
Read more → -
Hitachi Energy PCM600
The vulnerability is a known path traversal flaw in SharpZipLib, designated CVE-2018-1002208. Multiple PCM600 versions, including legacy 2.11 and newer 3.x releases, are affected.
Read more → -
ABB B&R Automation Runtime
An unauthenticated network attacker can trigger a permanent DoS via race condition in ANSL-Server. The advisory notes shorter cycle times in customer projects increase exploitation likelihood.
Read more → -
ABB B&R Automation Studio
The vulnerability allows an attacker to intercept and manipulate data exchanges by exploiting improper certificate validation in the OPC-UA and ANSL over TLS clients.
Read more → -
CISA KEV — Linux Kernel (CVE-2026-31431)
The vulnerability is listed as a 'Linux Kernel Incorrect Resource Transfer Between Spheres' issue. The advisory provides no technical details about the exploit mechanism or affected kernel versions.
Read more → -
Careful Adoption of Agentic AI Services
International collaboration has produced guidance for agentic AI adoption, emphasizing security challenges and risk management integration.
Read more → -
ZDI-26-307: FlowiseAI Flowise Airtable_Agent Code Injection Remote Code Execution Vulnerability
The vulnerability allows remote code execution without authentication. The CVSS rating of 9.8 indicates a high severity.
Read more → -
CISA KEV — WebPros cPanel & WHM and WP2 (CVE-2026-41940)
CVE-2026-41940 affects WebPros cPanel & WHM and WP2, involving a missing authentication mechanism for a critical function.
Read more → -
ABB PCM600
ABB PCM600 versions 1.5 through 2.13 contain a path traversal vulnerability in SharpZip.dll that allows arbitrary code execution via crafted messages. The fix in version 2.14 is incompatible with RE_630 protection relays, requiring separate mitigation.
Read more → -
ABB Ability OPTIMAX
An authentication bypass vulnerability affects ABB Ability OPTIMAX systems integrated with Azure AD SSO. Versions 6.1 and 6.2 are all affected, while specific versions of 6.3 and 6.4 require patching.
Read more → -
ABB System 800xA, Symphony Plus IEC 61850
The vulnerability affects specific ABB automation controllers (CI868, CI850, PM 877) and S+ Operations nodes using IEC 61850 MMS. Exploitation requires network access and causes device faults or communication driver crashes.
Read more → -
ABB Edgenius Management Portal
An authentication bypass vulnerability in ABB Edgenius Management Portal allows full system control via network access. The vendor recommends disabling the portal entirely until patching.
Read more → -
ABB AWIN Gateways
An authentication bypass vulnerability allows unauthenticated querying of system configuration on ABB AWIN Gateways. The advisory notes deployment in critical manufacturing sectors.
Read more → -
ABB Ability Symphony Plus Engineering
The vulnerability originates from PostgreSQL components bundled with ABB's industrial control software. Exploitation requires network access to the S+ Client Server.
Read more → -
2026-005: High Vulnerability in the Linux Kernel ("Copy Fail")
Affects every major Linux distribution with kernels built since 2017. A public exploit is already available.
Read more → -
Adapting Zero Trust Principles to Operational Technology
The advisory states that operational technology systems are increasingly interconnected, reducing the effectiveness of perimeter-based defenses.
Read more → -
CISA KEV — ConnectWise ScreenConnect (CVE-2024-1708) +1 more
Two vulnerabilities involving remote access and system protection mechanisms have been added to the KEV Catalog due to observed exploitation.
Read more → -
NSA GRASSMARLIN
The advisory notes that NSA GRASSMARLIN has been end-of-life since 2017 and will receive no patches. This vulnerability affects all versions of the software.
Read more → -
ZDI-26-306: Oracle VirtualBox SoundBlaster 16 Race Condition Local Privilege Escalation Vulnerability
The vulnerability requires a local attacker to already have high-privileged code execution on the guest system. The ZDI assigned a CVSS rating of 7.5 for this issue.
Read more → -
ZDI-26-305: (0Day) OpenAI Codex Sandbox Escape Vulnerability
OpenAI Codex sandbox escape vulnerability requires user interaction via malicious JavaScript in a repository. The ZDI assigned a CVSS rating of 8.6.
Read more → -
ZDI-26-301: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability
The vulnerability is a use-after-free in Foxit PDF Reader triggered by handling annotations, requiring user interaction to exploit.
Read more → -
ZDI-26-302: Foxit PDF Reader AcroForm Signature Use-After-Free Remote Code Execution Vulnerability
A use-after-free in Foxit PDF Reader's AcroForm signature handling can lead to remote code execution when a malicious file is opened.
Read more → -
ZDI-26-303: Foxit PDF Reader AcroForm Signature Use-After-Free Information Disclosure Vulnerability
This vulnerability enables information disclosure via a malicious PDF file. The assigned CVSS score of 3.3 indicates a low severity rating.
Read more → -
ZDI-26-304: Foxit PDF Reader AcroForm Annotation Use-After-Free Remote Code Execution Vulnerability
Foxit PDF Reader AcroForm Annotation contains a use-after-free vulnerability. The ZDI has assigned a CVSS rating of 7.8.
Read more → -
ZDI-26-300: Flowise AccountService resetPassword Authentication Bypass Vulnerability
The vulnerability enables remote authentication bypass via the AccountService resetPassword function in Flowise without requiring prior authentication.
Read more → -
CISA KEV — Samsung MagicINFO 9 Server (CVE-2024-7399) +3 more
The advisory adds a command injection flaw in D-Link DIR-823X devices, which could allow remote code execution if exploited.
Read more → -
CISA KEV — Marimo Remote Code Execution (CVE-2026-39987)
Marimo is a vulnerability being actively exploited in the wild. The advisory provides no details about the product or attack vector.
Read more → -
SpiceJet Online Booking System
SpiceJet's online booking system allows unauthenticated access to passenger name records and booking details. The vendor did not coordinate with CISA on remediation.
Read more → -
Intrado 911 Emergency Gateway (EGW)
The vulnerability allows network-based attackers to bypass authentication on the Intrado 911 Emergency Gateway management interface. A CVSS 3.1 base score of 9.8 indicates high severity.
Read more → -
Milesight Cameras
Five CVEs affect multiple Milesight camera models with the same firmware versions. The advisory does not specify patch availability or mitigation details.
Read more → -
Yadea T5 Electric Bicycle
The advisory notes that Yadea did not respond to coordination attempts, indicating no patch is available. This affects all versions of the T5 Electric Bicycle through a weak authentication mechanism.
Read more → -
Hangzhou Xiongmai Technology Co., Ltd XM530 IP Camera
The advisory notes that the vendor has not responded to CISA mitigation requests. Unauthenticated access to 31 specific ONVIF endpoints allows full video stream capture.
Read more → -
Carlson Software VASCO-B GNSS Receiver
GNSS receiver lacks authentication for configuration access. The advisory notes deployment in critical manufacturing sectors worldwide.
Read more → -
FIRESTARTER Backdoor
FIRESTARTER is a backdoor targeting Cisco ASA and FTD software on publicly accessible firewall devices. The advisory indicates confirmed successful implants on Cisco Firepower devices running ASA.
Read more → -
Defending Against China-Nexus Covert Networks of Compromised Devices
This joint advisory details a shift toward using large-scale compromised device networks for routing malicious traffic. The guidance focuses on detecting and mitigating infrastructure-based TTPs rather than specific product vulnerabilities.
Read more → -
ZDI-26-296: Delta Electronics ASDA-Soft PAR File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
The vulnerability involves a stack-based buffer overflow triggered by parsing a malicious PAR file in Delta Electronics ASDA-Soft.
Read more → -
ZDI-26-297: Siemens SINEC NMS Improper Authentication Privilege Escalation Vulnerability
The vulnerability requires authentication but allows remote privilege escalation in Siemens SINEC NMS.
Read more → -
ZDI-26-298: Siemens SINEC NMS Authentication Bypass Vulnerability
The advisory notes that authentication is not required to exploit this vulnerability, indicating a full bypass of login requirements.
Read more → -
ZDI-26-299: Docker Desktop Enhanced Container Isolation Exposed Dangerous Function Local Privilege Escalation Vulnerability
The vulnerability requires initial code execution within a container to escalate privileges on Docker Desktop.
Read more → -
CISA KEV — Microsoft Defender (CVE-2026-33825)
The vulnerability involves Microsoft Defender's access control, an unusual target for exploitation. Its inclusion suggests active attacks are leveraging security product weaknesses.
Read more → -
Siemens RUGGEDCOM CROSSBOW Station Access Controller (SAC)
The vulnerability originates from an SQLite dependency in Siemens industrial controllers. This affects versions below 5.8 and enables both code execution and denial of service.
Read more → -
Siemens Industrial Edge Management
The advisory notes that exploitation requires the remote connection feature to be enabled on a device and knowledge of the specific header and port used for connections. This may indicate that disabling the feature entirely could serve as an interim mitigation.
Read more → -
Siemens SINEC NMS
An authenticated attacker can reset any user's password in SINEC NMS by bypassing authorization checks. The advisory notes deployment in critical manufacturing environments worldwide.
Read more → -
Zero Motorcycles Firmware
Zero Motorcycles firmware allows unauthorized Bluetooth pairing when the vehicle is in pairing mode. This enables firmware manipulation by nearby attackers.
Read more → -
Siemens SINEC NMS
The advisory notes that this vulnerability affects critical manufacturing infrastructure. The issue is an authentication bypass in the User Management Component (UMC) due to insufficient identity validation.
Read more → -
Hardy Barth Salia EV Charge Controller
The vendor did not respond to CISA's coordination request. Exploit for the firmware upload vulnerability has been publicly disclosed.
Read more → -
Siemens SCALANCE
Siemens SCALANCE W-700 IEEE 802.11n devices have multiple vulnerabilities affecting versions before 6.6.0. The advisory includes a long list of CVEs spanning several years.
Read more → -
Siemens Analytics Toolkit
The advisory notes that the same vulnerability (CVE-2025-40745) affects multiple Siemens engineering applications through the Analytics Toolkit. Updates are available for each affected product, with specific version targets provided.
Read more → -
SenseLive X3050
Vendor did not respond to coordination requests. Ten distinct CVEs affect a single firmware version.
Read more → -
Siemens TPM 2.0
The vulnerability affects multiple Siemens industrial computing products with TPM 2.0 modules. Fixed versions are available for some products while others remain under investigation.
Read more → -
Siemens RUGGEDCOM CROSSBOW Secure Access Manager Primary
The advisory specifies that this privilege escalation vulnerability affects User Administrators who can administer their own groups. The product is deployed worldwide in critical manufacturing sectors.
Read more → -
Silex Technology SD-330AC and AMC Manager
Multiple vulnerabilities across two Silex products include authentication bypass and code execution risks. The advisory notes a known-affected status but lacks specific remediation details.
Read more → -
ZDI-26-245: (0Day) aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability
This is an unauthenticated command injection vulnerability in AWS CLI's MCP server. It carries a CVSS score of 9.8 and is marked as a 0-day.
Read more → -
ZDI-26-293: (0Day) Microsoft Office URI Handler NTLM Response Information Disclosure Vulnerability
A Microsoft Office URI handler vulnerability enables remote disclosure of NTLM responses. Exploitation requires user interaction via a malicious page or file.
Read more → -
ZDI-26-294: (0Day) Microsoft Windows library-ms NTLM Response Information Disclosure Vulnerability
The vulnerability requires user interaction through viewing a folder with malicious content, which may limit exposure to network-adjacent attackers.
Read more → -
ZDI-26-295: (0Day) PublicCMS getXml Server-Side Request Forgery Information Disclosure Vulnerability
The vulnerability allows unauthenticated remote attackers to disclose sensitive information via SSRF. The advisory notes a CVSS rating of 8.2.
Read more → -
Supply Chain Compromise Impacts Axios Node Package Manager
The advisory describes a supply chain attack that injected a malicious dependency into two specific Axios npm versions. The attack downloads multi-stage payloads including a remote access trojan.
Read more → -
CISA KEV — PaperCut NG/MF (CVE-2023-27351) +7 more
The addition of multiple vulnerabilities in Cisco Catalyst SD-WAN Manager suggests repeated security flaws in a network management platform used for wide-area orchestration.
Read more → -
CISA KEV — Apache ActiveMQ (CVE-2026-34197)
CVE-2026-34197 is an improper input validation issue in Apache ActiveMQ that is already seeing active exploitation.
Read more → -
Anviz Multiple Products
Anviz access control devices are vulnerable to unauthenticated photo capture via front-facing camera. Multiple CVEs affect all versions across three product lines with no patches mentioned.
Read more → -
Horner Automation Cscape and XL4, XL7 PLC
Horner Automation PLCs have weak password requirements allowing network-based brute force attacks. The vendor has released updates for Cscape software and PLC firmware.
Read more → -
Delta Electronics ASDA-Soft
The vulnerability is triggered by parsing a malformed .par file in ASDA-Soft. The advisory explicitly states the product is used in critical manufacturing sectors.
Read more → -
AVEVA Pipeline Simulation
An unauthenticated attacker can escalate to administrative roles in AVEVA Pipeline Simulation by exploiting a missing authorization check. The vulnerability affects simulation parameters, training configuration, and training records.
Read more → -
ZDI-26-258: (0Day) Docker Desktop extension-manager Exposed Dangerous Function Local Privilege Escalation Vulnerability
The vulnerability requires prior execution of high-privileged container code to exploit. The advisory assigns a CVSS rating of 8.2.
Read more → -
ZDI-26-259: (0Day) Docker Desktop cli-plugins Incorrect Permission Assignment Local Privilege Escalation Vulnerability
Local privilege escalation vulnerability in Docker Desktop for Windows requires escaping the container first. The ZDI assigned a CVSS score of 7.8.
Read more → -
ZDI-26-260: (0Day) Docker Desktop System Editor Uncontrolled Search Path Element Privilege Escalation Vulnerability
The vulnerability requires escaping a container and executing code in the Docker Hyper-V VM to escalate privileges.
Read more → -
ZDI-26-261: (0Day) Docker Desktop credentialHelper Directory Traversal Privilege Escalation Vulnerability
The vulnerability requires prior container escape to the Hyper-V VM for exploitation. The advisory assigns a CVSS score of 7.5.
Read more → -
ZDI-26-262: Adobe ColdFusion deleteVersion Directory Traversal Arbitrary File Deletion Vulnerability
The advisory notes authentication is required but can be bypassed, which may expand the pool of potential attackers despite the access control requirement.
Read more → -
ZDI-26-263: Adobe ColdFusion subscribeToEndpoints Authentication Bypass Vulnerability
The vulnerability allows authentication bypass without requiring authentication to exploit. The ZDI has assigned a CVSS rating of 6.5.
Read more → -
ZDI-26-264: Adobe ColdFusion fetchCFSettingFile Directory Traversal Information Disclosure Vulnerability
The vulnerability allows remote attackers to disclose sensitive information without authentication. The ZDI has assigned a CVSS rating of 7.5.
Read more → -
ZDI-26-265: Fortinet FortiWeb cgi_buf_alloc Integer Overflow Denial-of-Service Vulnerability
Authentication is required to exploit this denial-of-service vulnerability in Fortinet FortiWeb.
Read more → -
ZDI-26-266: Fortinet FortiWeb cat_cgi_paths Out-Of-Bounds Write Remote Code Execution Vulnerability
The vulnerability requires authentication for exploitation. The ZDI assigned a CVSS rating of 8.8.
Read more → -
ZDI-26-267: Malwarebytes Anti-Malware Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
The vulnerability requires local execution to escalate privileges. The CVSS rating of 7.8 indicates high severity for local privilege escalation.
Read more →
Page 6 of 9 · 807 advisories