Radar
A personal hobby project. Radar aggregates security advisories from CISA, Zero Day Initiative and CERT-EU and adds short editorial highlights on what I find notable from a European infrastructure perspective — not a threat-intel service, not exhaustive, just what catches my eye.
-
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an…
Read more → -
Panduit IntraVUE
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider…
Read more → -
Johnson Controls C-CURE 9000 and Victor application server
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. The following versions of Johnson Controls C-CURE 9000 and Victor…
Read more → -
MZ Automation lib60870
View CSAF Summary Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service. The following versions of MZ Automation lib60870 are affected: lib60870…
Read more → -
MZ Automation libIEC61850
View CSAF Summary Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising…
Read more → -
Johnson Controls XAAP Android
View CSAF Summary Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device. The following versions of Johnson Controls XAAP Android are affected: XAAP…
Read more → -
Weintek cMT3092X
View CSAF Summary Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users. The following versions of Weintek cMT3092X are…
Read more → -
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Executive summary A group of Russian state-supported cyber actors has been targeting and compromising…
Read more → -
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-16232 Check Point SmartConsole Improper Authentication…
Read more → -
Rockwell Automation ThinManager
View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory. The…
Read more → -
Siemens Opcenter X
View CSAF Summary Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter…
Read more → -
Rockwell Automation FactoryTalk Services Platform
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations. The following…
Read more → -
Siemens CADRA
View CSAF Summary CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and…
Read more → -
Rockwell Automation Studio 5000 Logix Designer
View CSAF Summary Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code. The following versions of Rockwell…
Read more → -
Rockwell Automation 1718-AENTR/1719-AENTR
View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. The following versions of Rockwell Automation 1718-AENTR/1719-AENTR are…
Read more → -
Rockwell Automation 1734 POINT I/O
View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. The following versions of Rockwell Automation 1734 POINT I/O are…
Read more → -
Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW
View CSAF Summary Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to…
Read more → -
Siemens IAM Client
View CSAF Summary Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new…
Read more → -
Siemens SIDIS Secured SmartPlug
View CSAF Summary SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version…
Read more → -
Tycon Systems TPDIN-Monitor-WEB2
View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could…
Read more → -
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability CVE-2026-0770…
Read more → -
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-25089 Fortinet FortiSandbox OS Command Injection Vulnerability  …
Read more → -
Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT are…
Read more → -
AutomationDirect Productivity Suite
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with local or physical access to cause memory corruption, unintended information disclosure, application instability, or a…
Read more → -
Rockwell Automation Arena
View CSAF Summary Successful exploitation these vulnerabilities could allow an attacker to execute arbitrary code in the context of the current process. The following versions of Rockwell Automation Arena are affected…
Read more → -
NASA Core Flight System (cFS) Health & Safety (HS) Application
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of NASA Core Flight System (cFS) Health & Safety (HS)…
Read more → -
Rockwell Automation FactoryTalk DataMosaix
View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious scripts on the server. The following versions of Rockwell Automation FactoryTalk DataMosaix are…
Read more → -
SALTO ProAccess Space
View CSAF Summary Successful exploitation of this vulnerability allows an authenticated attacker to escalate privileges and access spaces outside their assigned partition, within the same Salto ProAccess Space…
Read more → -
Siemens SICAM 8
View CSAF Summary Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: - SICAM A8000 Device firmware - CPCI85 for CP-8031/CP-8050 - SICORE for CP-8010/CP-8012…
Read more → -
Rockwell Automation Flex 5000 Adapter
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation Flex 5000 Adapter…
Read more → -
Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation CompactLogix, ControlLogix, Compact…
Read more → -
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1 Overly…
Read more → -
Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers
Developed by CISA, the National Security Agency (NSA) and international partners, this joint guidance contains best practices for software manufacturers and online service providers to design and implement a…
Read more → -
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery…
Read more → -
CISA Urges SharePoint Hardening After New Exploitations
CISA is aware of active exploitation of vulnerabilities CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances. These…
Read more → -
ABB Advant Master Online Builder
View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory, where an incorrect version of Online Builder (ONB) was included in the media. An update is available that…
Read more → -
ABB Ability Edgenius
View CSAF Summary ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported…
Read more → -
Rockwell Automation 1715-AENTR EtherNet/IP Adapter
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity…
Read more → -
ABB T-MAC Plus
View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. An attacker who successfully exploited…
Read more → -
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2008-4128 Cisco IOS Cross-Site Request Forgery Vulnerability This type of…
Read more → -
Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors Executive summary Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly…
Read more → -
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-48939 iCagenda Unrestricted Upload of File with Dangerous Type…
Read more → -
Schneider Electric Easergy MiCOM Px40 Series
The advisory states that hard-coded credentials in the SNMP protocol could allow unauthorized access to basic device identification.
Read more → -
OpenPLC v3
An authenticated attacker can write arbitrary files via a legacy web UI upload flaw, potentially leading to native code execution through the default compilation process.
Read more → -
Schneider Electric PowerChute Serial Shutdown
The advisory explicitly states that PowerChute Serial Shutdown versions 1.4 and prior are affected by multiple vulnerabilities, including path traversal and CRLF injection.
Read more → -
CISA Adds One Known Exploited Vulnerability to Catalog
CVE-2026-48282 is a path traversal vulnerability in Adobe ColdFusion that has been observed as actively exploited.
Read more → -
CISA Adds Three Known Exploited Vulnerabilities to Catalog
The advisory adds three vulnerabilities involving page builders and a low-code platform, all tied to web-facing components with access control or file upload flaws.
Read more → -
Siemens SINEC OS
The advisory states that SINEC OS versions prior to 4.0 contain multiple vulnerabilities, including buffer overflows and improper access control, with a maximum CVSS score of 9.8.
Read more → -
Hitachi Energy PROMOD V
The advisory states that PROMOD V versions 1.0.10 and prior use HTTP instead of HTTPS due to lack of HTTPS support in the third-party Digipede server, exposing data in transit.
Read more → -
Labcenter Proteus 9
The advisory states that Labcenter Proteus 9.1_SP4_Build_42914 is affected by multiple memory corruption vulnerabilities, including out-of-bounds write and stack-based buffer overflow. Successful exploitation could lead to arbitrary code execution.
Read more → -
Hitachi Energy e-mesh EMS
The vulnerability stems from NGINX components in e-mesh EMS using versions v1.30.0 or below, where specific rewrite rule configurations can trigger a heap buffer overflow.
Read more → -
Digi International PortServer TS, Digi One SP IA
The advisory states that affected Digi devices can allow unauthenticated access to restricted resources due to an authorization flaw.
Read more → -
Siemens Mendix Studio Pro
The advisory states that a file parsing vulnerability in Mendix Studio Pro could allow arbitrary code execution when processing a malicious project during the build pipeline.
Read more → -
Hydro-Québec Le Circuit Electrique charging station backend
The advisory states that affected charging station backends allowed unauthenticated websocket connections, potentially enabling privilege escalation.
Read more → -
ST Engineering iDirect iQ-Series Terminals
The advisory states that unauthenticated access to specific API endpoints can expose sensitive device information, including credentials used for satellite network authentication.
Read more → -
Gardyn IoT Hub
The advisory states that unauthenticated access to the iothubowner key could allow full control over managed devices and execution of arbitrary commands on connected devices.
Read more → -
CubeSpace CW0057 Reaction Wheel
The vulnerability requires physical access to upload malicious firmware, and the device can be recovered using the independent bootloader.
Read more → -
CISA Adds One Known Exploited Vulnerability to Catalog
The advisory states that CVE-2026-45659 in Microsoft SharePoint Server is being actively exploited, involving deserialization of untrusted data.
Read more → -
Delta Electronics DVP12SE PLC
The advisory states that all versions of the Delta Electronics DVP12SE PLC are affected by vulnerabilities allowing unauthenticated remote access to critical control functions via Modbus TCP.
Read more → -
XZ Utils vulnerability impacting B&R Products
The vulnerability stems from a race condition in the multithreaded .xz decoder within liblzma, which could lead to memory corruption or service disruption if exploited.
Read more → -
Frangoteam FUXA SCADA/HMI
The advisory states that unauthenticated remote attackers can exploit a path normalization flaw to access sensitive user and role data via the REST API.
Read more → -
StoneFly Storage Concentrator
The advisory identifies hardcoded credentials in a configuration file that can be decoded to plaintext, exposing access to multiple internal services.
Read more → -
Schneider Electric EcoStruxure IT Data Center Expert
The advisory states that affected versions of EcoStruxure IT Data Center Expert are susceptible to XML external entity reference exploitation, which could lead to server-side file disclosure when crafted payloads are submitted via SOAP endpoints.
Read more → -
Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M
The advisory states that a heap-based buffer overflow in the 7-Zip component of MELSOFT Update Manager could allow local attackers to execute arbitrary code via a specially crafted archive file.
Read more → -
OFFIS DCMTK Toolkit
The advisory states that DCMTK versions <=3.7.0 are affected by multiple vulnerabilities, including path traversal and memory management issues.
Read more → -
Schneider Electric EasyLogic T150 and Saitel DP RTU
Credentials are stored in firmware or system files without authentication requirements, exposing them to unauthenticated access.
Read more → -
CISA Adds One Known Exploited Vulnerability to Catalog
CVE-2026-48558 is an authentication bypass vulnerability in SimpleHelp that has been added to CISA's KEV Catalog due to evidence of active exploitation.
Read more → -
Russian Intelligence Services Continue to Target Commercial Messaging Applications
The advisory updates previous reporting on Russian Intelligence Services targeting messaging app accounts, adding new phishing message samples and observed tactics.
Read more → -
CISA Adds Two Known Exploited Vulnerabilities to Catalog
The advisory adds a server-side request forgery (SSRF) flaw in Cisco Unified Communications Manager and an input validation issue in PTC Windchill and FlexPLM to the KEV Catalog due to active exploitation.
Read more → -
EVoke Systems Charging Station Management System
The advisory states that all versions of EVoke CSMS are affected due to unauthenticated WebSocket endpoints that allow attackers to impersonate charging stations.
Read more → -
Horner Automation Cscape
The vulnerability affects Cscape versions prior to 10.2 SP3 and is triggered by parsing malicious CSP files, potentially leading to information disclosure and arbitrary code execution.
Read more → -
Yokogawa FAST/TOOLS and CI Server
The advisory states that affected versions of Yokogawa FAST/TOOLS and CI Server may transmit CI Server settings in cleartext, potentially enabling further attacks.
Read more → -
Schneider Electric PowerLogic P7
The advisory states that affected PowerLogic P7 devices may suffer loss of HMI operability and configuration functionality due to multiple vulnerabilities, including OS command injection and NULL pointer dereference.
Read more → -
pydicom pynetdicom Library
The vulnerability stems from unsanitized use of attacker-supplied data in file path operations within the qrscp application's C-STORE handler.
Read more → -
H.VIEW HV-500S6 IP Camera
The advisory states that command injection and unrestricted file upload vulnerabilities exist in the certificate generation and upload interfaces of the affected IP camera model.
Read more → -
OHIF Viewers DICOM
The advisory states that a server-side request forgery (SSRF) vulnerability in OHIF DICOM Web Viewer Framework versions up to v3.12.0 could result in unauthorized exfiltration of authenticated clinicians' OIDC Bearer tokens.
Read more → -
Delta Electronics DTM Soft
The advisory states that all versions of Delta Electronics DTM Soft are affected by a deserialization vulnerability. Exploitation requires user interaction to open a malicious project file.
Read more → -
Daktronics Controller Firmware
The advisory states that multiple Daktronics controller models are affected by vulnerabilities allowing unauthenticated root-level access, including path traversal and hardcoded credentials.
Read more → -
Using SASE in a Modern TIC 3.0 Solution
The advisory is informational guidance on integrating SASE with TIC 3.0, not a security vulnerability or mitigation notice.
Read more → -
CISA Adds Four Known Exploited Vulnerabilities to Catalog
The advisory adds four actively exploited vulnerabilities, three of which affect Ubiquiti UniFi OS, indicating a cluster of issues in the same product.
Read more → -
Siemens SINEC INS
The advisory states that SINEC INS before version 1.0 SP2 Update 6 is affected by an OS command injection vulnerability via the /api/sftp/uploadFiles endpoint, where crafted directory names can lead to arbitrary command execution.
Read more → -
Siemens Products using OpenSSL
The vulnerability affects multiple Siemens industrial communication products using OpenSSL, with a focus on router and server devices used in network infrastructure.
Read more → -
Hubbell Aclara Metrum Cellular Web Interface
The advisory states that critical functions in the Aclara Metrum Cellular Web Interface lack authentication, allowing unauthenticated attackers to alter settings and restart the device.
Read more → -
ABB Freelance Security Lock
The advisory notes that undocumented or special key combinations on modern keyboards could allow bypass of Freelance Operations, potentially granting access to underlying OS functions despite Security Lock being enabled.
Read more → -
Impact of Linux Kernel vulnerabilities on B&R products
The advisory identifies local privilege escalation risks in B&R products using affected Linux kernel versions, with public proof-of-concept exploits available.
Read more → -
Siemens SIPROTEC 5 Using DIGSI5 Protocol
The advisory states that authenticated users may exploit the DIGSI 5 protocol to upload arbitrary files, potentially leading to permanent denial of service. A new allow-list feature in updated versions restricts file uploads to mitigate the vulnerability.
Read more → -
Siemens WinCC Certificate Manager
The advisory states that WinCC Certificate Manager stores key material with insufficient protection, potentially allowing extraction of sensitive information.
Read more → -
CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure
The advisory states that approximately 74,000 Fortinet devices may have had credentials exposed, with active exploitation reported on internet-accessible systems.
Read more → -
CISA Adds One Known Exploited Vulnerability to Catalog
The added vulnerability allows total control of affected systems post-exploitation and is already being actively exploited.
Read more → -
Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products
The advisory mentions PowerChute Serial Shutdown in the summary but lists vulnerabilities affecting Easergy, EcoStruxture, PowerLogic, and Saitel products, with no explicit link between them in the provided text.
Read more → -
Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module
The advisory states that all versions of the FX5-ENET/IP module are affected by a DoS vulnerability due to excessive packet processing. No fix is planned for this product.
Read more → -
Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT
The device transmits sensitive health data in cleartext over Bluetooth, exposing glucose measurements to interception by nearby attackers.
Read more → -
Rockwell Automation FactoryTalk Historian Site Edition
The advisory identifies a race condition that could allow attackers to obtain a valid authentication token by repeatedly sending requests to the login endpoint.
Read more → -
Schneider Electric EasyLogic T150 and Saitel DP
The same path traversal vulnerability (CVE-2026-6865) affects two related Schneider Electric remote terminal units, potentially allowing unauthorized access to sensitive files.
Read more → -
AzeoTech DAQFactory
The advisory states that loading untrusted .ctl files in AzeoTech DAQFactory <=21.1 may lead to arbitrary code execution due to a type confusion vulnerability.
Read more → -
Mitsubishi Electric MELSEC iQ-F Series
The affected module may enter a denial-of-service state due to improper handling of rapid TCP connections, leading to memory access issues.
Read more → -
AVer PTC cameras
The advisory states that all versions of the affected AVer PTC camera models are vulnerable to arbitrary code execution via a crafted web request.
Read more → -
CISA Adds One Known Exploited Vulnerability to Catalog
The vulnerability allows improper access control in the Widget Factory Joomla Content Editor, potentially enabling full system control post-exploitation.
Read more → -
Rockwell Automation CompactLogix
The advisory states that exposed Connection IDs on the web interface can be abused to trigger a denial-of-service condition via improper validation of CIP protocol fields.
Read more → -
Rockwell Automation FactoryTalk Analytics PavilionX
The advisory states that affected versions of FactoryTalk Analytics PavilionX lack proper authorization controls on API endpoints, potentially allowing unauthenticated attackers to perform administrative actions.
Read more →