CISA has issued an advisory for critical buffer overflow vulnerabilities in All-Line Equipment Company's Fuel-Boss fuel management systems that could allow remote attackers to execute arbitrary code, affecting multiple product variants. Fixes are available for Fuel-Boss V1 Standard and Portal versions, but no remediation is planned for Fuel-Boss V1 Backflush Systems; the vendor recommends either disconnecting unfixed products from the Internet or restricting access at the router level.
Vercel has patched two critical unauthenticated remote code execution vulnerabilities in Next.js: one exploitable through maliciously crafted AVIF image files and another via Windows path traversal. Both flaws pose significant risk to unpatched deployments, as they can be triggered without authentication and enable full code execution on affected servers.
Rockwell Automation OTTO Fleet Manager versions 2.36.2 and earlier contain a weak password hashing vulnerability (CVE-2026-75112) that uses insufficient computational effort in its bcrypt implementation, making offline brute-force attacks against stored password hashes significantly easier if an attacker obtains an unencrypted system backup. The vulnerability carries a CVSS score of 6.8 and affects critical infrastructure in manufacturing and transportation sectors worldwide. Rockwell Automation has released version 2.36.3 to address the issue and recommends users enable encrypted system backup as documented in security advisory SD1791.
CISA has disclosed three critical vulnerabilities in Xiiaozet LK100W devices running versions prior to 2.1.240, including OS command injection, missing authentication for critical functions, and authentication bypass flaws that could allow complete device compromise. All three vulnerabilities carry CVSS scores of 9.8 or higher and affect the device's web-based management interface, with Xiiaozet recommending immediate updates to version 2.1.240 as mitigation.
CISA has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2023-49105 (ownCloud authentication flaw), CVE-2026-53362 (Linux kernel vulnerability), and CVE-2026-66384 (JFrog Artifactory path traversal issue). Federal agencies are required under BOD 26-04 to prioritize rapid remediation of these high-risk vulnerabilities on publicly exposed assets, while CISA encourages all organizations to adopt similar risk-based vulnerability management practices. Organizations aware of other exploited vulnerabilities not yet listed can submit nominations to CISA for potential catalog inclusion.