Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability
CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability
CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability
CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability
CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability
CVE-2026-83548 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
CVE-2026-83549 SonicWall SMA1000 Appliances OS Command Injection Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Br
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product.
The following versions of Rockwell Automation RSLinx Classic are affected:
RSLinx Classic <=4.50 (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.6
Rockwell Automation
Rockwell Automation RSLinx Classic
Integer Overflow or Wraparound, Integer Underflow (Wrap or Wraparound), Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-9621
A denial-of-service security issue exists within RSLinx Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx Classic service to crash, requiring a restart of the se
View CSAF
Summary
Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution.
The following versions of Rockwell Automation Historian ME are affected:
Series B 5.202 (CVE-2025-12768, CVE-2026-12661)
Series C 7.101 (CVE-2025-12768, CVE-2026-12661)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8
Rockwell Automation
Rockwell Automation Historian ME
Out-of-bounds Write, Stack-based Buffer Overflow
Background
Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Food and Agriculture, Healthcare and Public Health, Water and Wastewater Systems
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2025-12768
A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieveremote code execution on the affected device.
View CV
View CSAF
Summary
The following versions of Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix are affected:
ControlLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)
GuardLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)
CompactLogix 5380 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)
Compact GuardLogix 5380 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)
CompactLogix 5480 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.5
Rockwell Automation
Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix
Loop with Unreachable Exit Condition ('Infinite Loop')
Background
Critic
View CSAF
Summary
The following versions of Rockwell Automation Logix Platform are affected:
ControlLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)
CompactLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)
GuardLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)
Compact GuardLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.5
Rockwell Automation
Rockwell Automation Logix Platform
Improper Restriction of Operations within the Bounds of a Memory Buffer
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expan
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges.
The following versions of Rockwell Automation Redundancy Module Configuration Tool are affected:
Redundancy Module Configuration Tool 10.00.00 (CVE-2026-9633)
Redundancy Module Configuration Tool >=9.00.00|<=10.00.00 (CVE-2026-9634)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.3
Rockwell Automation
Rockwell Automation Redundancy Module Configuration Tool
Incorrect Default Permissions
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-9633
A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non administrato
View CSAF
Summary
The following versions of Rockwell Automation FactoryTalk Activation Manager are affected:
FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.8
Rockwell Automation
Rockwell Automation FactoryTalk Activation Manager
Improper Restriction of Excessive Authentication Attempts
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-16675
A privilege escalation vulnerability exists within FactoryTalk Activation Manager. The vulnerability stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack these console windows to obtain a SYSTEM-level command prompt, allowing full access to all files, processes, and system resou
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Introduction
One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session &#x26;#xe2;&#x26;#x80;&#x26;#x94; history, filesystem output, working paths, and the agent&#x26;#39;s local tool manifest. The honeypot did not request or cause any tool execution; what the request exposed is what a malicious operator in that position could do.
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for l
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
YARA-X&#x26;#39;s 1.20.0 release brings 14 improvements and 13 bugfixes.
During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files? A couple of months ago, I shared some stats about the trend in 64bits VS. 32bits malware[1]. Can we go a bit further? I (vibe-)coded a Python script based on the pefile library[2] to extract some info from the PE headers. Indeed, the PE file format contains a lot of metadata! They can be accessed using a lot of tools, like Detect It Easy:
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View CSAF
Summary
Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes.
The following versions of Rockwell Automation OTTO Fleet Manager are affected:
OTTO Fleet Manager <=V2.36.2 (CVE-2026-75112)
CVSS
Vendor
Equipment
Vulnerabilities
v3 6.8
Rockwell Automation
Rockwell Automation OTTO Fleet Manager
Use of Password Hash With Insufficient Computational Effort
Background
Critical Infrastructure Sectors: Critical Manufacturing, Transportation Systems
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-75112
A security issue exists within OTTO Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to take control over the device.
The following versions of Xiiaozet LK100W are affected:
LK100W <2.1.240 (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.8
Xiiaozet
Xiiaozet LK100W
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Missing Authentication for Critical Function, Authentication Bypass Using an Alternate Path or Channel
Background
Critical Infrastructure Sectors: Information Technology
Countries/Areas Deployed: Worldwide
Company Headquarters Location: China
Vulnerabilities
Expand All +
CVE-2026-78037
Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or comp
View CSAF
Summary
Successful exploitation of this vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products.
The following versions of Mitsubishi Electric CNC Series (Update A) are affected:
Mitsubishi Electric M800VW (BND-2051W000) <=BB (CVE-2025-2399)
Mitsubishi Electric M800VS (BND-2052W000) <=BB (CVE-2025-2399)
Mitsubishi Electric M80V (BND-2053W000) <=BB (CVE-2025-2399)
Mitsubishi Electric M80VW (BND-2054W000) <=BB (CVE-2025-2399)
Mitsubishi Electric M800W (BND-2005W000) <=FM (CVE-2025-2399)
Mitsubishi Electric M800S (BND-2006W000) <=FM (CVE-2025-2399)
Mitsubishi Electric M80 (BND-2007W000) <=FM (CVE-2025-2399)
Mitsubishi Electric M80W (BND-2008W000) <=FM (CVE-2025-2399)
Mitsubishi Electric E80 (BND-2009W000) <=FM (CVE-2025-2399)
Mitsubishi Electric C80 (BND-2036W000) vers:all/* (CVE-2025-2399)
Mitsubishi Electric M750VW (BND-1015W002) <=LJ (CVE-2025-2399)
Mitsubishi Electric M730VW (BND-1015W00
View CSAF
Summary
Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition, a timeout error, or a communication delay by sending a specially crafted UDP packet to the product.
The following versions of Mitsubishi Electric Multiple FA Products (Update D) are affected:
Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32D <=09 (CVE-2025-3511)
Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32T <=09 (CVE-2025-3511)
Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32TE <=09 (CVE-2025-3511)
Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32DT <=09 (CVE-2025-3511)
Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32DTE <=09 (CVE-2025-3511)
Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32D <=09 (CVE-2025-3511)
Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32T <=09 (CVE-2025-3511)
Mitsubishi Electric CC-Link IE TSN Remote I/O module N
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2023-49105 ownCloud Improper Authentication Vulnerability
CVE-2026-53362 Linux Kernel Unspecified Vulnerability
CVE-2026-66384 JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total co
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to fully compromise the device.
The following versions of Ebyte NA111-M are affected:
NA111-M Firmware 9013-2-17 (CVE-2026-73125, CVE-2026-76179, CVE-2026-75814, CVE-2026-76940, CVE-2026-77966, CVE-2026-73809, CVE-2026-71187, CVE-2026-75548, CVE-2026-69658, CVE-2026-76133, CVE-2026-73819, CVE-2026-77975, CVE-2026-77977)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.8
Ebyte
Ebyte NA111-M
Missing Authentication for Critical Function, Use of GET Request Method With Sensitive Query Strings, Cross-Site Request Forgery (CSRF), Improper Restriction of Excessive Authentication Attempts, Missing Authorization, Cleartext Transmission of Sensitive Information, Use of Client-Side Authentication, Improper Restriction of Rendered UI Layers or Frames, Use of a Broken or Risky Cryptographic Algorithm, Weak Authentication, Cleartext Storage of Sensitive Information
Background
Critical Infrastructure S
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems.
The following versions of All-Line Equipment Company Fuel-Boss are affected:
Fuel-Boss V1 Standard >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)
Fuel-Boss V1 Portal >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)
Fuel-Boss V1 Master/Slave >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)
Fuel-Boss V1 Backflush Systems >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.7
All-Line Equipment Company
All-Line Equipment Company Fuel-Boss
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'), Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Background
Critical Infrastructure Sectors: Critical Manufacturing, Defense Industrial Base, Emergency Services, Transportation Systems
Countries/Areas Deployed: Worldwide
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications.
The following versions of Applied Systems Engineering ASE2000 V2 Communications Test Set are affected:
ASE2000 >=2.25|<=2.37 (CVE-2018-1285, CVE-2026-18717)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.8
Applied Systems Engineering
Applied Systems Engineering ASE2000 V2 Communications Test Set
Improper Restriction of XML External Entity Reference, Improper Certificate Validation
Background
Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy, Water and Wastewater
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2018-1285
ASE2000 versions 2.25 through 2.37 is vuln
As I've mentioned before in some of my diaries, from time to time, I like to go over phishing messages that get caught in my various spam traps or sent to us here at the Internet Storm Center.
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
A common thing that folks should "worry" about in Entra (or any platform really) is "who has rights to administer"&#x26;#x3f;&#x26;#xc2;&#x26;#xa0; Who can delete or change key things, or modify them in ways that might not be obvious (accidentally or on purpose).&#x26;#xc2;&#x26;#xa0; Yes, we trust our people, but if they&#x26;#39;ve moved on to other roles or to other organizations, they change from "our people" to "used to be our people".&#x26;#xc2;&#x26;#xa0;&#x26;#xc2;&#x26;#xa0;
 Also, it&#x26;#39;s common to have too many admins.&#x26;#xc2;&#x26;#xa0; For instance, entry level support folks might need rights to change passwords, but they likely shouldn&#x26;#39;t have rights to change your intune policies or be global admins.&#x26;#xc2;&#x26;#xa0; The "too many admins" question is a common one that auditors will zero i
CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability
CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2021-23758 Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
CVE-2022-0995 Linux Kernel Out-of-Bounds Write Vulnerability
CVE-2026-8452 Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces th
Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and organizations can reduce their risk by addressing these underlying weaknesses and prioritizing vulnerabilities for action based on the risk they pose.
The CISA Vulnerability Review provides organizations with critical insights into the root causes of insecure software and practical steps they can take to address these flaws to prevent exploitation. Analyzing CISA and open source data from fiscal years 2024 and 2025, the review establishes a baseline of today’s vulnerability landscape before AI-enabled vulnerability discovery becomes more widespread. The review demonstrates the importance of Secure by Design principles in shifting cybersecurity efforts from reacting to threat actors to proactively fixing preventable software flaws.
The review also ident