VulnerabilityCISA Advisories·1 week ago

Hitachi Energy APM Edge Product

Hitachi Energy APM Edge product versions 6.10 and prior contain two critical Linux kernel vulnerabilities (CVE-2026-43284 and CVE-2026-43500) affecting the IPsec ESP and RxRPC subsystems that allow local unprivileged users to escalate privileges to root by exploiting write-what-where and out-of-bounds write conditions. Both vulnerabilities carry CVSS scores of 8.8 and 7.8 respectively, with mitigation available through disabling the vulnerable kernel modules (esp4, esp6, and rxrpc). The flaws affect critical infrastructure worldwide and are exploitable by any local user with the ability to load these kernel modules.

VulnerabilityCISA Advisories·1 week ago

AVEVA Enterprise SCADA

CISA has published an advisory for CVE-2025-7639 affecting AVEVA Enterprise SCADA versions 2022 through 2025, a deserialization vulnerability in the Binary Formatter that could allow authenticated attackers to execute code. AVEVA recommends disabling Binary Formatter serialization, migrating to JSON-based serialization, and implementing defensive measures including permission audits and network perimeter hardening, with detailed mitigation steps available in KB117814.

VulnerabilityCISA Advisories·1 week ago

Siemens Siveillance Video

Siemens Siveillance Video Management Servers contain a critical OS command injection vulnerability (CVE-2026-3014, CVSS 9.1) affecting versions V2023 R3, V2024 R1, and V2025, which could allow users with edit permissions to execute arbitrary code. Siemens has released patched versions and recommends immediate updates to V23.3.27, V24.1.16, or V25.1.15 respectively. CISA advises protecting network access to affected systems and implementing defense-in-depth strategies to minimize exploitation risk.

VulnerabilityCISA Advisories·1 week ago

Siemens License Server (SLS)

Siemens License Server (SLS) contains two critical vulnerabilities: CVE-2026-69108, a local privilege escalation flaw in versions before 5.1 that could allow root-level command execution, and CVE-2026-69109, a path traversal vulnerability in versions before 5.3 that permits remote arbitrary file access. Siemens recommends immediate patching to the latest versions and advises restricting network access to the affected systems as a precautionary measure.

VulnerabilityCISA Advisories·1 week ago

Flow Neuroscience FL-100

CISA has issued an advisory for CVE-2026-18164 affecting Flow Neuroscience FL-100 brain stimulation devices, which contain hard-coded credentials that allow attackers within Bluetooth range to manipulate stimulation parameters and override safety limits. The vulnerability, with a CVSS score of 8.1, impacts devices manufactured before July 2026 and requires physical proximity to exploit. Users are advised to install the latest firmware updates via the Flow app to remediate the issue.

VulnerabilityCISA Advisories·1 week ago

Siemens Solid Edge

Siemens Solid Edge versions SE2025 (before V225.0.15) and SE2026 (before V226.0.7) are vulnerable to seven high-severity file parsing flaws affecting PAR, PSM, and DFT file formats, each with a CVSS score of 7.8. These vulnerabilities—including out-of-bounds read/write and use-after-free conditions—can be exploited by local attackers to execute arbitrary code or crash the application through specially crafted files. Siemens has released patched versions and strongly recommends immediate updates to mitigate risk in critical manufacturing environments.

VulnerabilityCISA Advisories·1 week ago

Johnson Controls Metasys

A persistent cross-site scripting vulnerability in Johnson Controls Metasys building automation systems (CVE-2026-34491) allows low-privilege users to inject malicious payloads via crafted URLs that execute in other users' sessions, including administrators, with a CVSS score of 8. Affected versions include Metasys 12 and 13 (end of support), Metasys 14 prior to v14.1.5, and Metasys 15 prior to v15.0.1, while patches or fixes are available for later versions. CISA recommends restricting network access to the Metasys UI, implementing network segmentation, enforcing least-privilege access, and deploying web application firewalls to mitigate exploitation risk.

VulnerabilityCISA Advisories·1 week ago

Siemens Simcenter Femap

Siemens Simcenter Femap versions prior to V2606.0001 contain two out-of-bounds read vulnerabilities in BMP file parsing that could allow arbitrary code execution if a user opens a malicious file. With a CVSS score of 7.8, the vulnerabilities affect critical manufacturing infrastructure worldwide, and Siemens has released version V2606.0001 as the fix. Organizations should update immediately and restrict network access to affected systems pending remediation.

VulnerabilityDark Reading·1 week ago

Belgium's eID Authentication Opens Citizen Accounts to RCE

Belgium's electronic ID system suffered a critical compromise when severe vulnerabilities in a key browser extension undermined the trust framework protecting citizen authentication, enabling remote code execution attacks. The incident highlights systemic weaknesses in how browser extensions are secured and managed within critical authentication infrastructure.

VulnerabilityThe Register·1 week ago

Chinese Loongson processors have leaky caches, researchers find

Researchers have discovered cache side-channel vulnerabilities in Chinese Loongson processors that could allow attackers to extract sensitive data. The vulnerability is particularly concerning because it can be exploited even from within a guest virtual machine, expanding the potential attack surface for threat actors.

VulnerabilityThe Register·1 week ago

Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible

Researchers have demonstrated that RISC-V processors are vulnerable to Spectre attacks, revealing that the microarchitectural threat persists across different CPU instruction set architectures. The finding underscores that speculative execution vulnerabilities continue to pose security challenges nearly a decade after Spectre was first disclosed, suggesting that architectural defenses remain incomplete across diverse processor designs.

VulnerabilityCISA Advisories·1 week ago

Siemens RUGGEDCOM APE1808

All versions of Siemens RUGGEDCOM APE1808 are affected by two Fortinet vulnerabilities: a cross-site scripting flaw (CVE-2026-23573, CVSS 6.1) that allows authenticated remote users to execute code via crafted requests, and a path traversal vulnerability (CVE-2026-59839, CVSS 5.5) exploitable by privileged authenticated attackers with physical access to delete the file system. Siemens recommends contacting customer support and following Fortinet's mitigation guidance, while CISA advises minimizing network exposure and isolating control system networks from the internet.

VulnerabilityWired Security·1 week ago

This Coin-Sized Device Can Hack a Boeing 737

Security researchers demonstrated a vulnerability in Boeing 737 aircraft where a small, coin-sized device can be physically inserted into an external hatch in under 60 seconds to compromise critical flight systems. The attack allows an attacker to redirect the aircraft's autopilot or modify its flight plan, highlighting a significant physical security gap in commercial aviation.

VulnerabilityInfosecurity Magazine·1 week ago

Microsoft Fixes 400 Flaws on August Patch Tuesday

Microsoft addressed 400 vulnerabilities across its product portfolio in its August Patch Tuesday release. The substantial update volume underscores the ongoing volume of security issues requiring remediation across Microsoft's software ecosystem.

VulnerabilityQualys·1 week ago

Microsoft and Adobe Patch Tuesday, August 2026 Security Update Review

Microsoft's August 2026 Patch Tuesday release addresses 421 vulnerabilities across its product portfolio, including 62 critical and 357 important-severity issues, with three zero-day vulnerabilities patched—two publicly disclosed and one actively exploited in the wild. The update underscores the ongoing threat landscape where timely patching remains essential for enterprises to reduce exposure and mitigate attack surface.

VulnerabilityDark Reading·1 week ago

Microsoft's Patch Tuesday Deluge Continues With August Updates

Microsoft's August Patch Tuesday release includes CVE-2026-62878, a critical remote code execution vulnerability in Windows DNS Server with a CVSS score of 9.8 that requires no user interaction. This RCE flaw represents a significant risk to organizations running affected DNS Server infrastructure and should be prioritized for immediate patching.

VulnerabilityKrebs on Security·1 week ago

Microsoft Plugs Nearly 400 Security Holes

Microsoft released patches for nearly 400 security vulnerabilities across Windows operating systems and supported software, addressing multiple flaws that posed immediate risk to users. The update included at least one vulnerability already under active exploitation and two additional weaknesses that had been publicly disclosed before the patch release.

VulnerabilityRapid7 Blog·1 week ago

Patch Tuesday - August 2026

August 2026 Patch Tuesday brings 421 vulnerabilities including a critical SharePoint RCE chain discovered by Rapid7 researchers and an actively exploited Windows Ancillary Function Driver elevation-of-privilege flaw, while the pseudonymous researcher "Nightmare Eclipse" continues a pattern of late-cycle disclosures with ShieldBreak, a patch bypass for previously patched Defender vulnerabilities. Microsoft Edge received delayed security patches compared to Chrome, with a five-day gap between Chrome and Edge updates marking an unusual slowdown in the browser's typical patching cadence.

VulnerabilityTenable·1 week ago

Microsoft's August 2026 Patch Tuesday addresses 398 CVEs (CVE-2026-68820)

Microsoft's August 2026 Patch Tuesday addressed 398 CVEs across a broad range of products, with 42 rated critical and three zero-days including one actively exploited in the wild. Notable vulnerabilities include a critical remote code execution flaw in Windows Deployment Services TFTP Server with a CVSS score of 9.8, a critical Windows DHCP Server RCE affecting unauthenticated remote attackers, and the actively exploited Windows Ancillary Function Driver for WinSock elevation of privilege vulnerability. Elevation of privilege vulnerabilities accounted for 40.7% of this month's patches, followed by remote code execution vulnerabilities at 27.1%.

Load more