Skip to content
Index
  • About
  • Articles
  • Radar
  • Contact

Radar

A personal hobby project. Radar aggregates security advisories from CISA, Zero Day Initiative and CERT-EU and adds short editorial highlights on what I find notable from a European infrastructure perspective — not a threat-intel service, not exhaustive, just what catches my eye.

All (617) CISA (245) ZDI (357) CERT-EU (15)
  • CISA 2026-07-27

    CISA Adds Two Known Exploited Vulnerabilities to Catalog

    CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an…

    Read more →
  • CISA 2026-07-23

    Panduit IntraVUE

    View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider…

    Read more →
  • CISA 2026-07-23

    Johnson Controls C-CURE 9000 and Victor application server

    View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. The following versions of Johnson Controls C-CURE 9000 and Victor…

    Read more →
  • CISA 2026-07-23

    MZ Automation lib60870

    View CSAF Summary Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service. The following versions of MZ Automation lib60870 are affected: lib60870…

    Read more →
  • CISA 2026-07-23

    MZ Automation libIEC61850

    View CSAF Summary Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising…

    Read more →
  • CISA 2026-07-23

    Johnson Controls XAAP Android

    View CSAF Summary Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device. The following versions of Johnson Controls XAAP Android are affected: XAAP…

    Read more →
  • CISA 2026-07-23

    Weintek cMT3092X

    View CSAF Summary Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users. The following versions of Weintek cMT3092X are…

    Read more →
  • CISA 2026-07-23

    Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

    Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Executive summary  A group of Russian state-supported cyber actors has been targeting and compromising…

    Read more →
  • CISA 2026-07-22

    CISA Adds Two Known Exploited Vulnerabilities to Catalog

    CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2026-16232 Check Point SmartConsole Improper Authentication…

    Read more →
  • CISA 2026-07-21

    Rockwell Automation ThinManager

    View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory. The…

    Read more →
  • CISA 2026-07-21

    Siemens Opcenter X

    View CSAF Summary Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter…

    Read more →
  • CISA 2026-07-21

    Rockwell Automation FactoryTalk Services Platform

    View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations. The following…

    Read more →
  • CISA 2026-07-21

    Siemens CADRA

    View CSAF Summary CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and…

    Read more →
  • CISA 2026-07-21

    Rockwell Automation Studio 5000 Logix Designer

    View CSAF Summary Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code. The following versions of Rockwell…

    Read more →
  • CISA 2026-07-21

    Rockwell Automation 1718-AENTR/1719-AENTR

    View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. The following versions of Rockwell Automation 1718-AENTR/1719-AENTR are…

    Read more →
  • CISA 2026-07-21

    Rockwell Automation 1734 POINT I/O

    View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. The following versions of Rockwell Automation 1734 POINT I/O are…

    Read more →
  • CISA 2026-07-21

    Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW

    View CSAF Summary Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to…

    Read more →
  • CISA 2026-07-21

    Siemens IAM Client

    View CSAF Summary Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new…

    Read more →
  • CISA 2026-07-21

    Siemens SIDIS Secured SmartPlug

    View CSAF Summary SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version…

    Read more →
  • CISA 2026-07-21

    Tycon Systems TPDIN-Monitor-WEB2

    View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could…

    Read more →
  • CISA 2026-07-21

    CISA Adds Four Known Exploited Vulnerabilities to Catalog

    CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability CVE-2026-0770…

    Read more →
  • CISA 2026-07-16

    CISA Adds Three Known Exploited Vulnerabilities to Catalog

    CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-25089 Fortinet FortiSandbox OS Command Injection Vulnerability &nbsp…

    Read more →
  • CISA 2026-07-16

    Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT

    View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT are…

    Read more →
  • CISA 2026-07-16

    AutomationDirect Productivity Suite

    View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with local or physical access to cause memory corruption, unintended information disclosure, application instability, or a…

    Read more →
  • CISA 2026-07-16

    Rockwell Automation Arena

    View CSAF Summary Successful exploitation these vulnerabilities could allow an attacker to execute arbitrary code in the context of the current process. The following versions of Rockwell Automation Arena are affected…

    Read more →
  • CISA 2026-07-16

    NASA Core Flight System (cFS) Health & Safety (HS) Application

    View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of NASA Core Flight System (cFS) Health & Safety (HS)…

    Read more →
  • CISA 2026-07-16

    Rockwell Automation FactoryTalk DataMosaix

    View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious scripts on the server. The following versions of Rockwell Automation FactoryTalk DataMosaix are…

    Read more →
  • CISA 2026-07-16

    SALTO ProAccess Space

    View CSAF Summary Successful exploitation of this vulnerability allows an authenticated attacker to escalate privileges and access spaces outside their assigned partition, within the same Salto ProAccess Space…

    Read more →
  • CISA 2026-07-16

    Siemens SICAM 8

    View CSAF Summary Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: - SICAM A8000 Device firmware - CPCI85 for CP-8031/CP-8050 - SICORE for CP-8010/CP-8012…

    Read more →
  • CISA 2026-07-16

    Rockwell Automation Flex 5000 Adapter

    View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation Flex 5000 Adapter…

    Read more →
  • CISA 2026-07-16

    Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix

    View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation CompactLogix, ControlLogix, Compact…

    Read more →
  • CISA 2026-07-15

    CISA Adds Two Known Exploited Vulnerabilities to Catalog

    CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1 Overly…

    Read more →
  • CISA 2026-07-15

    Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers

    Developed by CISA, the National Security Agency (NSA) and international partners, this joint guidance contains best practices for software manufacturers and online service providers to design and implement a…

    Read more →
  • CISA 2026-07-14

    CISA Adds Four Known Exploited Vulnerabilities to Catalog

    CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery…

    Read more →
  • CISA 2026-07-14

    CISA Urges SharePoint Hardening After New Exploitations

    CISA is aware of active exploitation of vulnerabilities CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances. These…

    Read more →
  • CISA 2026-07-14

    ABB Advant Master Online Builder

    View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory, where an incorrect version of Online Builder (ONB) was included in the media. An update is available that…

    Read more →
  • CISA 2026-07-14

    ABB Ability Edgenius

    View CSAF Summary ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported…

    Read more →
  • CISA 2026-07-14

    Rockwell Automation 1715-AENTR EtherNet/IP Adapter

    View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity…

    Read more →
  • CISA 2026-07-14

    ABB T-MAC Plus

    View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. An attacker who successfully exploited…

    Read more →
  • CISA 2026-07-13

    CISA Adds One Known Exploited Vulnerability to Catalog

    CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2008-4128 Cisco IOS Cross-Site Request Forgery Vulnerability This type of…

    Read more →
  • CISA 2026-07-13

    Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting

    Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors Executive summary Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly…

    Read more →
  • CISA 2026-07-10

    CISA Adds Two Known Exploited Vulnerabilities to Catalog

    CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-48939 iCagenda Unrestricted Upload of File with Dangerous Type…

    Read more →
  • CISA 2026-07-09

    Schneider Electric Easergy MiCOM Px40 Series

    The advisory states that hard-coded credentials in the SNMP protocol could allow unauthorized access to basic device identification.

    Read more →
  • CISA 2026-07-09

    OpenPLC v3

    An authenticated attacker can write arbitrary files via a legacy web UI upload flaw, potentially leading to native code execution through the default compilation process.

    Read more →
  • CISA 2026-07-09

    Schneider Electric PowerChute Serial Shutdown

    The advisory explicitly states that PowerChute Serial Shutdown versions 1.4 and prior are affected by multiple vulnerabilities, including path traversal and CRLF injection.

    Read more →
  • CISA 2026-07-07

    CISA Adds One Known Exploited Vulnerability to Catalog

    CVE-2026-48282 is a path traversal vulnerability in Adobe ColdFusion that has been observed as actively exploited.

    Read more →
  • CISA 2026-07-07

    CISA Adds Three Known Exploited Vulnerabilities to Catalog

    The advisory adds three vulnerabilities involving page builders and a low-code platform, all tied to web-facing components with access control or file upload flaws.

    Read more →
  • CISA 2026-07-07

    Siemens SINEC OS

    The advisory states that SINEC OS versions prior to 4.0 contain multiple vulnerabilities, including buffer overflows and improper access control, with a maximum CVSS score of 9.8.

    Read more →
  • CISA 2026-07-07

    Hitachi Energy PROMOD V

    The advisory states that PROMOD V versions 1.0.10 and prior use HTTP instead of HTTPS due to lack of HTTPS support in the third-party Digipede server, exposing data in transit.

    Read more →
  • CISA 2026-07-07

    Labcenter Proteus 9

    The advisory states that Labcenter Proteus 9.1_SP4_Build_42914 is affected by multiple memory corruption vulnerabilities, including out-of-bounds write and stack-based buffer overflow. Successful exploitation could lead to arbitrary code execution.

    Read more →
  • CISA 2026-07-07

    Hitachi Energy e-mesh EMS

    The vulnerability stems from NGINX components in e-mesh EMS using versions v1.30.0 or below, where specific rewrite rule configurations can trigger a heap buffer overflow.

    Read more →
  • CISA 2026-07-07

    Digi International PortServer TS, Digi One SP IA

    The advisory states that affected Digi devices can allow unauthenticated access to restricted resources due to an authorization flaw.

    Read more →
  • CISA 2026-07-07

    Siemens Mendix Studio Pro

    The advisory states that a file parsing vulnerability in Mendix Studio Pro could allow arbitrary code execution when processing a malicious project during the build pipeline.

    Read more →
  • CISA 2026-07-07

    Hydro-Québec Le Circuit Electrique charging station backend

    The advisory states that affected charging station backends allowed unauthenticated websocket connections, potentially enabling privilege escalation.

    Read more →
  • CISA 2026-07-02

    ST Engineering iDirect iQ-Series Terminals

    The advisory states that unauthenticated access to specific API endpoints can expose sensitive device information, including credentials used for satellite network authentication.

    Read more →
  • CISA 2026-07-02

    Gardyn IoT Hub

    The advisory states that unauthenticated access to the iothubowner key could allow full control over managed devices and execution of arbitrary commands on connected devices.

    Read more →
  • CISA 2026-07-02

    CubeSpace CW0057 Reaction Wheel

    The vulnerability requires physical access to upload malicious firmware, and the device can be recovered using the independent bootloader.

    Read more →
  • CISA 2026-07-01

    CISA Adds One Known Exploited Vulnerability to Catalog

    The advisory states that CVE-2026-45659 in Microsoft SharePoint Server is being actively exploited, involving deserialization of untrusted data.

    Read more →
  • CISA 2026-06-30

    Delta Electronics DVP12SE PLC

    The advisory states that all versions of the Delta Electronics DVP12SE PLC are affected by vulnerabilities allowing unauthenticated remote access to critical control functions via Modbus TCP.

    Read more →
  • CISA 2026-06-30

    XZ Utils vulnerability impacting B&R Products

    The vulnerability stems from a race condition in the multithreaded .xz decoder within liblzma, which could lead to memory corruption or service disruption if exploited.

    Read more →
  • CISA 2026-06-30

    Frangoteam FUXA SCADA/HMI

    The advisory states that unauthenticated remote attackers can exploit a path normalization flaw to access sensitive user and role data via the REST API.

    Read more →
  • CISA 2026-06-30

    StoneFly Storage Concentrator

    The advisory identifies hardcoded credentials in a configuration file that can be decoded to plaintext, exposing access to multiple internal services.

    Read more →
  • CISA 2026-06-30

    Schneider Electric EcoStruxure IT Data Center Expert

    The advisory states that affected versions of EcoStruxure IT Data Center Expert are susceptible to XML external entity reference exploitation, which could lead to server-side file disclosure when crafted payloads are submitted via SOAP endpoints.

    Read more →
  • CISA 2026-06-30

    Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M

    The advisory states that a heap-based buffer overflow in the 7-Zip component of MELSOFT Update Manager could allow local attackers to execute arbitrary code via a specially crafted archive file.

    Read more →
  • CISA 2026-06-30

    OFFIS DCMTK Toolkit

    The advisory states that DCMTK versions <=3.7.0 are affected by multiple vulnerabilities, including path traversal and memory management issues.

    Read more →
  • CISA 2026-06-30

    Schneider Electric EasyLogic T150 and Saitel DP RTU

    Credentials are stored in firmware or system files without authentication requirements, exposing them to unauthenticated access.

    Read more →
  • CISA 2026-06-29

    CISA Adds One Known Exploited Vulnerability to Catalog

    CVE-2026-48558 is an authentication bypass vulnerability in SimpleHelp that has been added to CISA's KEV Catalog due to evidence of active exploitation.

    Read more →
  • CISA 2026-06-26

    Russian Intelligence Services Continue to Target Commercial Messaging Applications

    The advisory updates previous reporting on Russian Intelligence Services targeting messaging app accounts, adding new phishing message samples and observed tactics.

    Read more →
  • CISA 2026-06-25

    CISA Adds Two Known Exploited Vulnerabilities to Catalog

    The advisory adds a server-side request forgery (SSRF) flaw in Cisco Unified Communications Manager and an input validation issue in PTC Windchill and FlexPLM to the KEV Catalog due to active exploitation.

    Read more →
  • CISA 2026-06-25

    EVoke Systems Charging Station Management System

    The advisory states that all versions of EVoke CSMS are affected due to unauthenticated WebSocket endpoints that allow attackers to impersonate charging stations.

    Read more →
  • CISA 2026-06-25

    Horner Automation Cscape

    The vulnerability affects Cscape versions prior to 10.2 SP3 and is triggered by parsing malicious CSP files, potentially leading to information disclosure and arbitrary code execution.

    Read more →
  • CISA 2026-06-25

    Yokogawa FAST/TOOLS and CI Server

    The advisory states that affected versions of Yokogawa FAST/TOOLS and CI Server may transmit CI Server settings in cleartext, potentially enabling further attacks.

    Read more →
  • CISA 2026-06-25

    Schneider Electric PowerLogic P7

    The advisory states that affected PowerLogic P7 devices may suffer loss of HMI operability and configuration functionality due to multiple vulnerabilities, including OS command injection and NULL pointer dereference.

    Read more →
  • CISA 2026-06-25

    pydicom pynetdicom Library

    The vulnerability stems from unsanitized use of attacker-supplied data in file path operations within the qrscp application's C-STORE handler.

    Read more →
  • CISA 2026-06-25

    H.VIEW HV-500S6 IP Camera

    The advisory states that command injection and unrestricted file upload vulnerabilities exist in the certificate generation and upload interfaces of the affected IP camera model.

    Read more →
  • CISA 2026-06-25

    OHIF Viewers DICOM

    The advisory states that a server-side request forgery (SSRF) vulnerability in OHIF DICOM Web Viewer Framework versions up to v3.12.0 could result in unauthorized exfiltration of authenticated clinicians' OIDC Bearer tokens.

    Read more →
  • CISA 2026-06-25

    Delta Electronics DTM Soft

    The advisory states that all versions of Delta Electronics DTM Soft are affected by a deserialization vulnerability. Exploitation requires user interaction to open a malicious project file.

    Read more →
  • CISA 2026-06-25

    Daktronics Controller Firmware

    The advisory states that multiple Daktronics controller models are affected by vulnerabilities allowing unauthenticated root-level access, including path traversal and hardcoded credentials.

    Read more →
  • CISA 2026-06-24

    Using SASE in a Modern TIC 3.0 Solution

    The advisory is informational guidance on integrating SASE with TIC 3.0, not a security vulnerability or mitigation notice.

    Read more →
  • CISA 2026-06-23

    CISA Adds Four Known Exploited Vulnerabilities to Catalog

    The advisory adds four actively exploited vulnerabilities, three of which affect Ubiquiti UniFi OS, indicating a cluster of issues in the same product.

    Read more →
  • CISA 2026-06-23

    Siemens SINEC INS

    The advisory states that SINEC INS before version 1.0 SP2 Update 6 is affected by an OS command injection vulnerability via the /api/sftp/uploadFiles endpoint, where crafted directory names can lead to arbitrary command execution.

    Read more →
  • CISA 2026-06-23

    Siemens Products using OpenSSL

    The vulnerability affects multiple Siemens industrial communication products using OpenSSL, with a focus on router and server devices used in network infrastructure.

    Read more →
  • CISA 2026-06-23

    Hubbell Aclara Metrum Cellular Web Interface

    The advisory states that critical functions in the Aclara Metrum Cellular Web Interface lack authentication, allowing unauthenticated attackers to alter settings and restart the device.

    Read more →
  • CISA 2026-06-23

    ABB Freelance Security Lock

    The advisory notes that undocumented or special key combinations on modern keyboards could allow bypass of Freelance Operations, potentially granting access to underlying OS functions despite Security Lock being enabled.

    Read more →
  • CISA 2026-06-23

    Impact of Linux Kernel vulnerabilities on B&R products

    The advisory identifies local privilege escalation risks in B&R products using affected Linux kernel versions, with public proof-of-concept exploits available.

    Read more →
  • CISA 2026-06-23

    Siemens SIPROTEC 5 Using DIGSI5 Protocol

    The advisory states that authenticated users may exploit the DIGSI 5 protocol to upload arbitrary files, potentially leading to permanent denial of service. A new allow-list feature in updated versions restricts file uploads to mitigate the vulnerability.

    Read more →
  • CISA 2026-06-23

    Siemens WinCC Certificate Manager

    The advisory states that WinCC Certificate Manager stores key material with insufficient protection, potentially allowing extraction of sensitive information.

    Read more →
  • CISA 2026-06-18

    CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure

    The advisory states that approximately 74,000 Fortinet devices may have had credentials exposed, with active exploitation reported on internet-accessible systems.

    Read more →
  • CISA 2026-06-18

    CISA Adds One Known Exploited Vulnerability to Catalog

    The added vulnerability allows total control of affected systems post-exploitation and is already being actively exploited.

    Read more →
  • CISA 2026-06-18

    Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products

    The advisory mentions PowerChute Serial Shutdown in the summary but lists vulnerabilities affecting Easergy, EcoStruxture, PowerLogic, and Saitel products, with no explicit link between them in the provided text.

    Read more →
  • CISA 2026-06-18

    Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module

    The advisory states that all versions of the FX5-ENET/IP module are affected by a DoS vulnerability due to excessive packet processing. No fix is planned for this product.

    Read more →
  • CISA 2026-06-18

    Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT

    The device transmits sensitive health data in cleartext over Bluetooth, exposing glucose measurements to interception by nearby attackers.

    Read more →
  • CISA 2026-06-18

    Rockwell Automation FactoryTalk Historian Site Edition

    The advisory identifies a race condition that could allow attackers to obtain a valid authentication token by repeatedly sending requests to the login endpoint.

    Read more →
  • CISA 2026-06-18

    Schneider Electric EasyLogic T150 and Saitel DP

    The same path traversal vulnerability (CVE-2026-6865) affects two related Schneider Electric remote terminal units, potentially allowing unauthorized access to sensitive files.

    Read more →
  • CISA 2026-06-18

    AzeoTech DAQFactory

    The advisory states that loading untrusted .ctl files in AzeoTech DAQFactory <=21.1 may lead to arbitrary code execution due to a type confusion vulnerability.

    Read more →
  • CISA 2026-06-18

    Mitsubishi Electric MELSEC iQ-F Series

    The affected module may enter a denial-of-service state due to improper handling of rapid TCP connections, leading to memory access issues.

    Read more →
  • CISA 2026-06-18

    AVer PTC cameras

    The advisory states that all versions of the affected AVer PTC camera models are vulnerable to arbitrary code execution via a crafted web request.

    Read more →
  • CISA 2026-06-16

    CISA Adds One Known Exploited Vulnerability to Catalog

    The vulnerability allows improper access control in the Widget Factory Joomla Content Editor, potentially enabling full system control post-exploitation.

    Read more →
  • CISA 2026-06-16

    Rockwell Automation CompactLogix

    The advisory states that exposed Connection IDs on the web interface can be abused to trigger a denial-of-service condition via improper validation of CIP protocol fields.

    Read more →
  • CISA 2026-06-16

    Rockwell Automation FactoryTalk Analytics PavilionX

    The advisory states that affected versions of FactoryTalk Analytics PavilionX lack proper authorization controls on API endpoints, potentially allowing unauthenticated attackers to perform administrative actions.

    Read more →
Knut Michael Haugland © 2026
  • LinkedIn
  • GitHub
  • Contact
  • Atom