Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition.
The following versions of ST Engineering iDirect iQ-Series Terminals (Update A) are affected:
Evolution iQ‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058)
3315‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058)
9‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.8
ST Engineering iDirect
ST Engineering iDirect iQ-Series Terminals
Missing Authentication for Critical Function, Cross-Site Request Forgery (CSRF), Missing Authorization, Exposure of Sensitive System Information to an Unauthorized Control Sphere
Background
Critical Infrastructure Sectors: Communications, Defense Industrial Base, Energy, Government Services and
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate date or cause a denial-of-service condition.
The following versions of NextGen Healthcare Mirth Connect are affected:
Mirth Connect <=v4.7.1 (CVE-2026-82583, CVE-2026-78224, CVE-2026-82578)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.3
NextGen Healthcare
NextGen Healthcare Mirth Connect
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), Improper Restriction of XML External Entity Reference
Background
Critical Infrastructure Sectors: Healthcare and Public Health
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-82583
NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary file write, and
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
About a week ago, Proxmox published an advisory revealing a vulnerability in older versions of Proxmox VE, its flagship Virtual Environment product. The vulnerability only affects version 7, which has not been supported for a couple of years now.
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability
CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, spec
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS.
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to take full control of the device.
The following versions of CareCam Pro IP Cameras are affected:
ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26 (CVE-2026-85083)
CVSS
Vendor
Equipment
Vulnerabilities
v3 6.8
CareCam
CareCam Pro IP Cameras
Use of Hard-coded Credentials
Background
Critical Infrastructure Sectors: Commercial Facilities
Countries/Areas Deployed: Worldwide
Company Headquarters Location: China
Vulnerabilities
Expand All +
CVE-2026-85083
The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and potentially resulting in complete device compromise.
View CVE Details
Affected Products
CareCam P
Executive summary
China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models. The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) (hereafter referred to as the authoring agencies) are releasing this joint Cybersecurity Advisory to alert organizations about these malicious activities and techniques and recommend mitigations to reduce their potential impact.
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
CVE-2026-81963 Microsoft Windows Link Following Vulnerability
CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability
CVE-2026-86218 N-able N-central Static Code Injection Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vu
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Understanding why staff use unapproved AI tools is key to managing the security challenges they can create.
Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is installed.
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must chec
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View CSAF
Summary
Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover.
The following versions of Rockwell Automation 1756-ENBT Module are affected:
1756-ENBT module vers:all/* (CVE-2025-10478)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.5
Rockwell Automation
Rockwell Automation 1756-ENBT Module
Improper Check for Unusual or Exceptional Conditions
Background
Critical Infrastructure Sectors: Critical Manufacturing, Food and Agriculture, Transportation Systems, Water and Wastewater
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2025-10478
A denial-of-service security issue exists in the Rockwell Automation 1756-ENBT module which is a ControlLogix EtherNet/IP bridge that enables communication between Logix 5000 controllers and Ethernet devices. An attacker could exploit this vulnerability by sending a crafted CIP packet, causing the module to cras
View CSAF
Summary
Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.
The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected:
TPDIN-Monitor-WEB2 <2.4.5 (CVE-2026-61884, CVE-2026-55985)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.8
Tycon Systems
Tycon Systems TPDIN-Monitor-WEB2
Missing Authentication for Critical Function, Cleartext Storage of Sensitive Information
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-61884
The device ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without
View CSAF
Summary
Successful exploitation of this vulnerability could allow any authenticated user to create projects.
The following versions of Inductive Automation Ignition are affected:
Ignition <=8.1.53 (CVE-2026-77393)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.8
Inductive Automation
Inductive Automation Ignition
Incorrect Default Permissions
Background
Critical Infrastructure Sectors: Critical Manufacturing, Energy, Information Technology
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-77393
In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected.
View CVE Details
Affected Products
Inductive Automation Ignition
Vendor:Inductive
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands.
The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected:
UA-LDS-Installers <1.04.420 (CVE-2026-77477)
CVSS
Vendor
Equipment
Vulnerabilities
v3 4.6
OPCFoundation
OPCFoundation OPC UA LocalDiscoveryServer (LDS)
Execution with Unnecessary Privileges
Background
Critical Infrastructure Sectors: Chemical, Energy, Food and Agriculture, Water and Wastewater, Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-77477
An attacker can intercept a high-privilege console window launched during installation of the LDS. The attacker must be able to launch an installer with elevated privileges and have access to the keyboard and display while the installation is taking place.
View CVE D
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information.
The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected:
TPDIN-Monitor-WEB3 <=2.2.9 (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.8
Tycon Systems
Tycon Systems TPDIN-Monitor-WEB3
Use of Hard-coded Credentials, Cross-Site Request Forgery (CSRF), Missing Authorization
Background
Critical Infrastructure Sectors: Critical Manufacturing, Energy
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-77847
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Use of Hard-coded Credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.
View CVE Details
Affected Produ
View CSAF
Summary
Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution systems. The Easergy MiCOM P30 is a family of multifunction protection and control relays designed for medium, high and extra high voltage electrical networks. The Easergy MiCOM P40 is a protection relay series for Medium Voltage, High Voltage and Extra High Voltage protection. The Easergy MiCOM C264 is a modular and compact substation or bay controller, smart RTU and MV one box solution The EcoStruxure Power Automation System Gateway (EPAS=GTW) is a scalable, interoperable, and rugged communication gateway that helps to remotely monitor and operate electrical processes The EcoStruxure Power Automation System User Interface (EPAS-UI) product is an HMI SCADA designed for electrical networks and substations operations. The EcoStruxure Power Automa
View CSAF
Summary
Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.
The following versions of Rockwell Automation ControlFLASH are affected:
ControlFLASH <=V15.07 (CVE-2026-12663)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.3
Rockwell Automation
Rockwell Automation ControlFLASH
Missing Authentication for Critical Function
Background
Critical Infrastructure Sectors: Critical Manufacturing, Energy, Water and Wastewater
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-12663
A security issue exists within ControlFLASH, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker's
View CSAF
Summary
Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page.
The following versions of Rockwell Automation ArmorStart LT are affected:
ArmorStart LT <=v2.001 (CVE-2026-19471, CVE-2026-19472)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.5
Rockwell Automation
Rockwell Automation ArmorStart LT
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Allocation of Resources Without Limits or Throttling
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-19471
Multiple stored cross-site scripting security issues exist within ArmorStart LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, allowing an attacker
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges.
The following versions of IXON VPN Client are affected:
VPN Client <1.4.7 (CVE-2026-75925)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.6
IXON
IXON VPN Client
Improper Neutralization of CRLF Sequences ('CRLF Injection')
Background
Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy, Information Technology, Water and Wastewater
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Netherlands
Vulnerabilities
Expand All +
CVE-2026-75925
Improper Neutralization of CRLF Sequences (CWE-93) in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralised,
CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to protect sensitive data, authentication systems, and critical assets from emerging quantum computing threats.
The G7 Cyber Security Working Group’s call to action outlines five priorities for a successful transition to PQC:
Raising awareness of quantum risks and the importance of PQC;
Developing national strategies that support PQC adoption and integration;
Advancing research and development for quantum-safe technologies;
Fostering public-private partnerships to share expertise and resources; and
Integrating PQC into cybersecurity requirements and procurement processes.
Please share your thoughts!
We welcome your feedback.
CISA PRODUCT SURVEY
View CSAF
Summary
Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.
The following versions of Pyramid Solutions NetStaX EtherNet/IP Stack are affected:
EtherNet/IP Adapter DLL Kit (EIPA)
EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE)
EtherNet/IP Adapter Development Kit (EADK)
EtherNet/IP Adapter Development Kit with CIP Security (EADK-SECURE)
EtherNet/IP Scanner DLL Kit (EIPS)
EtherNet/IP Scanner DLL Kit with CIP Security (EIPS-SECURE)
EtherNet/IP Scanner Development Kit (ESDK)
EtherNet/IP Scanner Development Kit with CIP Security (ESDK-SECURE)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.8
Pyramid Solutions
Pyramid Solutions NetStaX EtherNet/IP Stack
Stack-based Buffer Overflow
Background
Critical Infrastructure Sectors: Critical Manufacturing, Energy, Water and Wastewater,
[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program]
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create disruption and societal panic even without speculation from end users and the public as added factors. Outages at one organization may cascade across interconnected systems, increasing uncertainty and alarm. The guidance emphasizes clarity, accountability, and transparency as core principles and details key elements of effective crisis messaging to inform affected stakeholders and the public while aligning with legal requirements, operational security, law enforcement, and containment efforts.
CISA’s CI Fortify initiative provides information and resources that help critical infrastructure organizations prep