Radar
A personal hobby project. Radar aggregates security advisories from CISA, Zero Day Initiative and CERT-EU and adds short editorial highlights on what I find notable from a European infrastructure perspective — not a threat-intel service, not exhaustive, just what catches my eye.
-
ABB Ability Edgenius
ABB Ability Edgenius versions 3.2.0.0 through 3.2.4.0 are listed as affected by CVE-2026-31431. ABB provides an update to version 3.2.4.1 that resolves the issue.
Read more → -
Schneider Electric PowerChute Serial Shutdown
Versions ≤1.5 and 1.6 of PowerChute Serial Shutdown are vulnerable to CVE-2026-13348.
Read more → -
Schneider Electric Modicon M340 Controller and Communication Modules
The advisory reports a denial-of-service vulnerability in Schneider Electric Modicon M340 controllers and several communication modules.
Read more → -
Schneider Electric NetBotz 5 750/755
NetBotz 5 750/755 devices running firmware 5.5.2 or earlier are vulnerable to OS command injection and Hibernate SQL injection.
Read more → -
Bransys ELD
Bransys ELD versions prior to Android 11.00.00 and iOS 1.1.54 contain hard-coded MQTT credentials and transmit data in cleartext. These flaws could let an attacker read telemetry data and firmware.
Read more → -
Hitachi Energy FACTS Control Platform (FCP)
Hitachi Energy FACTS Control Platform versions 3.4.0 through 4.1.1 with the GWS component are vulnerable, scoring 9.9 CVSS.
Read more → -
Mitsubishi Electric GX Works3 and Motion Control Settings
All versions of Mitsubishi Electric GX Works3 and Motion Control Settings are affected by CVE-2026-15688. A local attacker can bypass the block password and modify the program memory.
Read more → -
CISA KEV — Cisco Identity Services Engine (CVE-2026-76460) +1 more
Cisco Identity Services Engine and Acronis Backup have been added to CISA’s Known Exploited Vulnerabilities catalog.
Read more → -
Using Cyber Decoys to Strengthen Detection and Response
Cyber decoys provide high-fidelity alerts that can reveal adversaries using legitimate credentials and living-off-the-land tools.
Read more → -
CISA KEV — Google Pixel (CVE-2026-58704)
CISA added CVE-2026-58704, an improper authorization vulnerability affecting Google Pixel devices, to its Known Exploited Vulnerabilities catalog.
Read more → -
CareCam CM2507
CareCam CM2507 firmware v251211.1507 lacks authentication for its video streaming service, permitting unauthenticated retrieval of live video.
Read more → -
Siemens Reyrolle 7SR5
Versions of Siemens Reyrolle 7SR5 earlier than V2.70 contain multiple high-severity vulnerabilities. Siemens provides an update to V2.70 or later.
Read more → -
Wärtsilä FOS-Onboard
Wärtsilä FOS-Onboard version 5.07.0923.01 contains hard-coded cryptographic keys. Wärtsilä has released a security patch for the issue.
Read more → -
Siemens Mendix SAML
Versions of Siemens Mendix SAML earlier than 4.2.3 (Mendix 10/11) or 3.6.27 (Mendix 9.24) are vulnerable to CVE-2026-80465. The flaw allows unauthenticated remote attackers to hijack a user session in specific SSO configurations.
Read more → -
Siemens Teamcenter
A reflected cross-site scripting vulnerability exists in the /auth/ redirect flow of Siemens Teamcenter.
Read more → -
Schneider Electric SCADAPack x70 Products
All listed SCADAPack x70 models are affected by CVE-2026-81861. The advisory recommends using RBAC instead of the Secure Lock feature.
Read more → -
mySCADA myPRO Manager
Versions ≤ 2.1 of mySCADA myPRO Manager lack authentication for privileged functions, allowing unauthenticated access.
Read more → -
Digital Watchdog VMAX DVR and NVR Product Lineups
All firmware versions of Digital Watchdog VMAX DVR and NVR models are listed as vulnerable. The vulnerabilities could give an unauthenticated attacker full administrative control.
Read more → -
Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers
The report advises agencies and cloud providers to inventory and secure token validation and secret management processes. It emphasizes detection at scale for token misuse.
Read more → -
CISA KEV — Cisco Secure Email Gateway (CVE-2026-76461)
CVE-2026-76461 is a SQL injection vulnerability in Cisco Secure Email Gateway now listed in CISA’s KEV catalog.
Read more → -
CISA KEV — GitLab Community Edition and Enterprise Edition (CVE-2026-85706)
GitLab Community Edition and Enterprise Edition are listed in the KEV catalog for an actively exploited path-traversal flaw (CVE-2026-85706).
Read more → -
CISA KEV — JFrog Artifactory (CVE-2026-42016) +2 more
CISA added two JFrog Artifactory and one ConnectWise ScreenConnect CVEs to the KEV Catalog. The advisory notes they are actively exploited.
Read more → -
CISA KEV — MikroTik RouterOS (CVE-2026-67277) +1 more
CISA added two MikroTik RouterOS vulnerabilities to its KEV catalog.
Read more → -
AVEVA Pipeline Integrity Monitor
Versions of AVEVA Pipeline Integrity Monitor up to 2025 SP1 P1 build 7.1.9580.8513 are affected.
Read more → -
NextGen Healthcare Mirth Connect
Mirth Connect versions up to 4.7.1 are vulnerable to SQL injection and XXE flaws. The advisory recommends updating to version 4.7.2 or later.
Read more → -
Orthanc DICOM Server
Orthanc DICOM Server versions prior to 1.13.0 can be crashed via a crafted PNG or JPEG image.
Read more → -
CISA KEV — Fortinet Multiple Products (CVE-2025-25249) +3 more
Four actively exploited CVEs affecting Fortinet, Citrix NetScaler, Google Chromium V8, and Cisco FMC have been added to CISA’s KEV Catalog.
Read more → -
CISA KEV — Adobe Commerce and Magento (CVE-2026-75650) +3 more
Four CVEs affecting Adobe Commerce/Magento, Microsoft Windows, and N-able N-central have been added to CISA’s KEV Catalog.
Read more → -
China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
China-based AI firms have extracted billions of tokens from U.S. frontier AI models via industrial-scale knowledge distillation.
Read more → -
CareCam Pro IP Cameras
The affected CareCam Pro IP Cameras use a hard-coded bootloader credential.
Read more → -
CISA KEV — Google Chromium V8 (CVE-2026-85046)
CISA added CVE-2026-85046, a type confusion vulnerability in Google Chromium V8, to its KEV catalog.
Read more → -
Pyramid Solutions NetStaX EtherNet/IP Stack
A large Class 3 explicit-message request can overflow the receive buffer, causing memory corruption or device crash.
Read more → -
IXON VPN Client
IXON VPN Client versions prior to 1.4.7 are vulnerable to CRLF injection that can lead to remote code execution with root or SYSTEM privileges.
Read more → -
Rockwell Automation ArmorStart LT
ArmorStart LT versions up to 2.001 are vulnerable to stored cross-site scripting.
Read more → -
Rockwell Automation ControlFLASH
ControlFLASH versions up to 15.07 grant write permissions to the Everyone group on the installation directory, enabling arbitrary code execution.
Read more → -
Tycon Systems TPDIN-Monitor-WEB3
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and earlier are vulnerable. Tycon provides firmware v2.4.2 to remediate the issues.
Read more → -
OPCFoundation OPC UA LocalDiscoveryServer (LDS)
OPCFoundation OPC UA LocalDiscoveryServer installers earlier than version 1.04.420 are vulnerable to privilege escalation during installation.
Read more → -
Inductive Automation Ignition
Versions 8.1.53 and earlier of Inductive Automation Ignition allow any authenticated user to create projects because the default "Create Project Role(s)" setting is blank. The issue is resolved in version 8.1.54 and later.
Read more → -
Rockwell Automation 1756-ENBT Module
All versions of the Rockwell Automation 1756-ENBT module are vulnerable to a crafted CIP packet that can cause a crash.
Read more → -
Preparing for the Post-Quantum Era: A Call to Action
CISA and the G7 Cyber Security Working Group issue a call to begin transitioning to post-quantum cryptography.
Read more → -
CISA KEV — Sangoma Switchvox (CVE-2026-9586) +6 more
CISA added seven actively exploited CVEs to its KEV catalog, covering Switchvox, Starlette, Kestra OSS, BerriAI LiteLLM, JFrog Artifactory, and SonicWall SMA1000 appliances.
Read more → -
Communicating Under Pressure: Best Practices for Service Providers
The advisory offers communication best-practice guidance for service providers during IT and OT outages.
Read more → -
Rockwell Automation FactoryTalk Activation Manager
FactoryTalk Activation Manager versions 5.02 and earlier are vulnerable to privilege escalation via installer console windows.
Read more → -
Rockwell Automation Redundancy Module Configuration Tool
The advisory identifies a DLL search-path permission issue in Rockwell Automation’s Redundancy Module Configuration Tool versions 9.00.00 through 10.00.00.
Read more → -
Rockwell Automation Logix Platform
The advisory lists specific Logix firmware versions that are vulnerable to a denial-of-service condition. Exploitation can cause a major nonrecoverable fault requiring a power cycle.
Read more → -
Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix
ControlLogix, CompactLogix, GuardLogix and Compact GuardLogix controllers with firmware below 34.015 (and related patch levels) are vulnerable to a denial-of-service condition. The flaw can trigger a major non-recoverable fault that requires a program download or a stage-2 reset to recover.
Read more → -
Rockwell Automation Historian ME
Series B 5.202 and Series C 7.101 of Rockwell Automation Historian ME are listed as vulnerable.
Read more → -
Rockwell Automation RSLinx Classic
RSLinx Classic versions up to 4.50 are vulnerable to denial-of-service via malformed CIP packets.
Read more → -
CISA KEV — PaperCut NG/MF (CVE-2026-81578) +1 more
PaperCut NG/MF is listed with two KEV vulnerabilities (CVE-2026-81578 and CVE-2026-82078).
Read more → -
CISA KEV — ownCloud (CVE-2023-49105) +2 more
CISA added CVE-2023-49105 (ownCloud), CVE-2026-53362 (Linux kernel) and CVE-2026-66384 (JFrog Artifactory) to the KEV Catalog.
Read more → -
Mitsubishi Electric CNC Series (Update A)
The advisory lists multiple Mitsubishi Electric CNC models (Update A) as vulnerable to CVE-2025-2399. Exploitation may cause an out-of-bounds read leading to denial-of-service.
Read more → -
Xiiaozet LK100W
Xiiaozet LK100W devices with firmware earlier than 2.1.240 are vulnerable to OS command injection and unauthenticated management functions.
Read more → -
Rockwell Automation OTTO Fleet Manager
OTTO Fleet Manager versions up to 2.36.2 use a low bcrypt work factor, easing offline password-hash cracking.
Read more → -
Ebyte NA111-M
The NA111-M firmware 9013-2-17 is listed as affected by multiple high-severity CVEs.
Read more → -
All-Line Equipment Company Fuel-Boss
Fuel-Boss V1 products running PHP 7.1.5 are vulnerable to remote command execution via crafted IMAP server names.
Read more → -
Applied Systems Engineering ASE2000 V2 Communications Test Set
ASE2000 V2 Communications Test Set versions 2.25-2.37 are vulnerable to XML external entity attacks and improper TLS certificate validation. The vendor recommends upgrading to version 2.38.
Read more → -
Mitsubishi Electric Multiple FA Products (Update D)
A crafted UDP packet can cause denial-of-service, timeout, or communication delay on Mitsubishi CC-Link IE TSN Remote I/O modules version ≤ 09.
Read more → -
CISA KEV — Red Hat Libuser (CVE-2015-3246) +5 more
CISA added six actively exploited CVEs to its KEV Catalog, including a Citrix NetScaler ADC buffer vulnerability.
Read more → -
CISA Vulnerability Review
CISA notes that most compromises stem from exposed, well-known software flaws rather than advanced techniques. It advises using the BOD 26-04 risk-based framework to prioritize remediation.
Read more → -
Bendix EC80 Brake ECU
A stack-based buffer overflow in the Bendix EC80 Brake ECU could allow remote code execution on the CAN bus.
Read more → -
FURUNO FA-50 Class B AIS Transponder
All versions of the FURUNO FA-50 Class B AIS Transponder are affected by hard-coded credentials and missing authentication for critical functions.
Read more → -
Siemens SIMATIC IoT2050 Advanced
Unauthenticated attackers can create malicious Node-RED flows via the HTTP interface. Siemens recommends updating to firmware version 4.3.4.1 or later.
Read more → -
Zoneminder
An authenticated user with View Events permission can exploit an OS command injection via the exportFile parameter.
Read more → -
PayRange API
All versions of the PayRange API are missing proper authorization on management endpoints. This permits unauthenticated disclosure, modification, or denial-of-service of device data.
Read more → -
Rently Smart Home
Rently Smart Home versions up to 20.1.0 are affected by CVE-2026-75960, an insufficiently protected credentials flaw.
Read more → -
Ebyte NE2-D11
The NE2-D11 firmware FW-9167-0-11 does not enforce authentication on its web management interface.
Read more → -
CISA KEV — Gitea (CVE-2026-60004)
CVE-2026-60004, a code injection flaw in Gitea, has been added to CISA’s KEV catalog.
Read more → -
A Tale of Two SOCs: Insights From Two Red Team Assessments
CISA conducted red team assessments at two organizations, observing different defensive outcomes. One organization failed to detect or contain the red team's activity, while the other rapidly identified and isolated initial compromise attempts.
Read more → -
CISA KEV — Oracle HTTP Server and Oracle Weblogic (CVE-2026-21962)
CISA added CVE-2026-21962, an improper access-control flaw in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, to the KEV catalog. The vulnerability is being actively exploited.
Read more → -
CISA KEV — Zimbra Collaboration Suite (ZCS) (CVE-2026-73570)
CISA added CVE-2026-73570, an OS command injection in Zimbra Collaboration Suite, to the KEV catalog.
Read more → -
CISA KEV — TrueConf Server (CVE-2026-72529) +1 more
CISA added CVE-2026-72529 and CVE-2026-72530 to its KEV Catalog due to evidence of active exploitation. These vulnerabilities affect TrueConf Server.
Read more → -
Johnson Controls Simplex Incident Manager
Simplex Incident Manager versions up to V2.01 store user credentials in cleartext memory.
Read more → -
CISA KEV — MLflow (CVE-2026-64849)
CVE-2026-64849, an SSRF flaw in MLflow, has been added to CISA’s KEV catalog due to active exploitation.
Read more → -
Defending Against an Active Threat to Siemens S7 Series PLCs
The advisory details an active cyber threat targeting Siemens S7 Series programmable logic controllers (PLCs). Malicious individuals are using AI-generated scripts disguised as monitoring tools to scan for vulnerable PLCs.
Read more → -
CISA KEV — Microsoft Internet Key Exchange (IKE) Service (CVE-2026-33824) +3 more
Four CVEs affecting Microsoft IKE, SharePoint, Broadcom VMware vCenter, and Apple macOS have been added to CISA’s KEV catalog.
Read more → -
CISA Malcolm
Versions of Malcolm prior to 26.07.0 allow unbounded archive extraction, which can exhaust filesystem resources and cause denial of service.
Read more → -
Siemens Simcenter Nastran
Simcenter Nastran and Simcenter Femap versions earlier than V2606 are vulnerable to CVE-2026-59086.
Read more → -
CISA Adds One Known Exploited Vulnerability to Catalog
CISA added CVE-2025-62593, a Ray Project vulnerability, to its KEV Catalog due to evidence of active exploitation. The advisory references Binding Operational Directive (BOD) 26-04, which requires FCEB agencies to prioritize remediation of high-risk vulnerabilities.
Read more → -
Hitachi Energy APM Edge Product
Hitachi Energy's APM Edge product versions 6.10 and earlier are affected by Dirty Frag vulnerabilities. These vulnerabilities could allow a local, unprivileged user to escalate privileges to root.
Read more → -
AVEVA Enterprise SCADA
Authenticated users with DNA Authority – Operator privilege can modify serialized data, potentially leading to code execution. The issue affects AVEVA Enterprise SCADA versions from 2021 SP2 P5 through 2025.
Read more → -
Haiwell IoT Cloud HMI Gateway
Haiwell IoT Cloud HMI Gateway version 3.40.1.12 is vulnerable to OS command injection via the /setting endpoint.
Read more → -
Siemens Simcenter Femap
Simcenter Femap versions earlier than V2606.0001 are vulnerable to out-of-bounds reads in BMP parsing.
Read more → -
Siemens Solid Edge
Solid Edge versions prior to V225.0.15 and V226.0.7 contain file-parsing bugs that may allow code execution when opening crafted PAR, PSM, or DFT files. Siemens advises updating to the latest releases to remediate the issue.
Read more → -
ANDRITZ HIPASE-250 and 250 SCALA
HIPASE-250 and 250 SCALA versions up to 7.20 store passwords in a reversible format.
Read more → -
Siemens LOGO! Soft Comfort
LOGO! Soft Comfort versions earlier than 9 use a hard-coded AES master key and unsalted password hashes.
Read more → -
Flow Neuroscience FL-100
The Flow Neuroscience FL-100 devices contain a hard-coded credential that bypasses authentication over Bluetooth. Firmware updates are available through the Flow app to remediate the issue.
Read more → -
Siemens Siveillance Video
Siemens Siveillance Video Management Servers are affected by an OS Command Injection vulnerability. The advisory states that this could allow a Remote Code Execution attack.
Read more → -
Johnson Controls Metasys
Metasys versions 12-15 are vulnerable to a persistent cross-site scripting flaw (CVE-2026-34491). The flaw allows a low-privilege user to inject a payload that runs in other users' sessions.
Read more → -
Johnson Controls Inc. Airwall
Airwall versions up to 4.0.4 contain a hard-coded cryptographic key that can decrypt stored configuration data.
Read more → -
Siemens Desigo DXR and PXC Controllers
Malformed BACnet packets can trigger a denial-of-service condition on Siemens Desigo DXR and PXC controllers.
Read more → -
Siemens License Server (SLS)
Versions of Siemens License Server earlier than 5.1 and 5.3 are vulnerable to privilege escalation and path-traversal flaws.
Read more → -
Siemens Parasolid
Parasolid versions earlier than V38.0.235 and V38.1.230 are vulnerable to an out-of-bounds read in X_T file parsing.
Read more → -
Siemens RUGGEDCOM APE1808
Siemens RUGGEDCOM APE1808 devices that include a Fortinet NGFW are listed as affected by cross-site scripting (CVE-2026-23573) and path-traversal (CVE-2026-59839) vulnerabilities.
Read more → -
CISA KEV — Cisco Secure Firewall Adaptive Security Appliance (CVE-2026-20349) +2 more
CISA added CVE-2026-20349 (Cisco ASA/FTD Heap Inspection Vulnerability), CVE-2026-68820 (Microsoft WinSock Use-After-Free Vulnerability), and CVE-2026-72898 (Metabase SQL Injection Vulnerability) to its KEV Catalog.
Read more → -
Pulsetto Vagus Nerve Stimulator
All versions of the Pulsetto Vagus Nerve Stimulator are affected by CVE-2026-18844.
Read more → -
Mira Hormone Monitor, Mira Android App
Mira Hormone Monitor firmware 1.7.1.47 and Mira Android App 4.5.15.4 are vulnerable to eight CVEs, including remote BLE authentication bypass.
Read more → -
#StopRansomware: Gunra Ransomware
Gunra ransomware uses a double-extortion model, encrypting data and threatening to publish exfiltrated files. It is offered as ransomware-as-a-service targeting government and critical-infrastructure organizations.
Read more → -
CPDLC over ATN-B1 Vulnerabilities
All ATN-B1 CPDLC versions are listed as affected. The vulnerabilities enable unauthenticated message injection and denial-of-service conditions.
Read more → -
CISA KEV — Progress LoadMaster (CVE-2026-8037)
CISA added CVE-2026-8037, a command-injection flaw in Progress LoadMaster, to its KEV catalog.
Read more → -
ABB Ability Zenon
ABB Ability Zenon IIoT services with MongoDB 4.2 are listed as affected. The advisory cites CVE-2025-14847, a mismatch in Zlib compressed protocol headers that could allow an unauthenticated client to read uninitialized heap memory.
Read more →
Page 1 of 4 · 375 advisories