Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code.
The following versions of CISA Malcolm are affected:
Malcolm <26.06.1 (CVE-2026-55676)
Malcolm <26.07.0 (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177)
Malcolm <=26.07.1 (CVE-2026-19670, CVE-2026-19671)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.8
CISA
CISA Malcolm
Allocation of Resources Without Limits or Throttling, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangerous Type, Incorrect Authorization, Improper Handling of Highly Compressed Data (Data Amplification)
Background
Critical Infrastructure Sectors: Information Technology
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-63133
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, safe-extract.py
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
CVE-2026-55040 Microsoft SharePoint Weak Authentication Vulnerability
CVE-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerability
CVE-2026-65400 Apple macOS Improper Authentication Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS.
About 20 years ago, with macOS 10.5 (Leopard), Apple introduced screen sharing. Apple did not invent a new protocol for screen sharing. Instead, it used the established VNC protocol. VNC is a pretty simple, unencrypted protocol using TCP port 5900. Historically, the protocol used a simple global password for authentication. Apple adapted the protocol for its own use, but overall, left the VNC protocol itself alone.
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check w
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Wireshark release 4.6.8 fixes 28 vulnerabilities and 25 bugs.
View CSAF
Summary
Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.
The following versions of Siemens Parasolid are affected:
Parasolid V38.0 vers:intdot/<38.0.235 (CVE-2026-64629)
Parasolid V38.1 vers:intdot/<38.1.230 (CVE-2026-64629)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.8
Siemens
Siemens Parasolid
Out-of-bounds Read
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-64629
The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current proces
View CSAF
Summary
Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version.
The following versions of Siemens License Server (SLS) are affected:
Siemens License Server (SLS) vers:intdot/<5.1, vers:intdot/<5.3 (CVE-2026-69108, CVE-2026-69109)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.5
Siemens
Siemens License Server (SLS)
Incorrect Permission Assignment for Critical Resource, Path Traversal: '.../...//'
Background
Critical Infrastructure Sectors: Information Technology
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-69108
The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and p
View CSAF
Summary
A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions.
The following versions of Siemens Desigo DXR and PXC Controllers are affected:
Desigo DXR2 vers:intdot/<01.21.233.16-7862 (CVE-2026-59693)
Desigo PXC3 vers:intdot/<01.21.233.16-7862 (CVE-2026-59693)
Desigo PXC4 vers:intdot/<02.21.194.36-2715 (CVE-2026-59693)
Desigo PXC5.E003 vers:intdot/<02.21.194.36-2715 (CVE-2026-59693)
Desigo PXC5.E24 vers:intdot/<02.21.194.36-2715 (CVE-2026-59693)
Desigo PXC7 vers:intdot/<02.21.194.36-2715 (CVE-2026-59693)
CVSS
Vendor
Equipment
Vulnerabilities
v3 4.3
Siemens
Siemens Desigo DXR and PXC Controllers
Improper Check for Unusual or Exceptional Conditions
Background
Crit
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized access to protected system resources.
The following versions of Johnson Controls Inc. Airwall are affected:
Airwall <=4.0.4 (CVE-2026-64887, CVE-2026-34492)
CVSS
Vendor
Equipment
Vulnerabilities
v3 6.8
Johnson Controls Inc.
Johnson Controls Inc. Airwall
Use of Hard-coded Cryptographic Key, External Control of File Name or Path
Background
Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Ireland
Vulnerabilities
Expand All +
CVE-2026-64887
A hardcoded password or cryptographic key was identified in the Airwall application. A hardcoded credential leads to a significant authe
View CSAF
Summary
Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access.
The following versions of Johnson Controls Metasys are affected:
Metasys 12 vers:all/* (CVE-2026-34491)
Metasys 13 vers:all/* (CVE-2026-34491)
Metasys 14
Metasys 15
CVSS
Vendor
Equipment
Vulnerabilities
v3 8
Johnson Controls Inc
Johnson Controls Metasys
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Background
Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Ireland
Vulnerabilities
Expand All +
CVE-2026-34491
A low-privilege user can inject a malicious XSS p
View CSAF
Summary
Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions.
The following versions of Siemens Siveillance Video are affected:
Siveillance Video V2023 R3 vers:intdot/<23.3.27 (CVE-2026-3014)
Siveillance Video V2024 R1 vers:intdot/<24.1.16 (CVE-2026-3014)
Siveillance Video V2025 vers:intdot/<25.1.15 (CVE-2026-3014)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.1
Siemens
Siemens Siveillance Video
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Background
Critical Infrastructure Sectors: Critical Manufacturing, Communications, Commercial Facilities
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-3014
Milestone has released a new version of XProtect® (and several cumulative patch updates) whi
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to manipulate brain stimulation parameters and override safety limits.
The following versions of Flow Neuroscience FL-100 are affected:
Flow Neuroscience FL-100
Halo Neuroscience FL-100
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.1
Flow Neuroscience
Flow Neuroscience FL-100
Use of Hard-coded Credentials
Background
Critical Infrastructure Sectors: Healthcare and Public Health
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Sweden
Vulnerabilities
Expand All +
CVE-2026-18164
An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth range to arbitrarilymanipulate brain stimulation parameters and state.
View CVE Details
Affected Products
Flow Neuroscience FL-100
Vendor:Flow Neuroscience
Product Version:Flow Neuroscience Flow Neuroscience FL-100: <July_20
View CSAF
Summary
Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt project data or remove project passwords. The lack of password salting enables offline dictionary or brute-force attacks against the password hashes. Successful exploitation could result in unauthorized access to, or modification of, sensitive project logic and configurations. Siemens has released a new version for LOGO! Soft Comfort and recommends to update to the latest version.
The following versions of Siemens LOGO! Soft Comfort are affected:
LOGO! Soft Comfort vers:intdot/<9 (CVE-2026-57262, CVE-2026-57263)
CVSS
Vendor
Equipment
Vulnerabilities
v3 6.8
Siemens
Siemens LOGO! Soft Comfort
Use of Hard-coded Cryptographic Key, Use of a One-Way Hash without a Salt
Background
Critical Infrastructure Sectors: Commercial Facilitie
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to read data from the device or gain access to affected workstations.
The following versions of ANDRITZ HIPASE-250 and 250 SCALA are affected:
HIPASE-250 <=7.20 (CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, CVE-2026-65313)
250 SCALA <=7.20 (CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, CVE-2026-65313)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.1
ANDRITZ
ANDRITZ HIPASE-250 and 250 SCALA
Storing Passwords in a Recoverable Format, Missing Authentication for Critical Function, Use of Hard-coded Credentials
Background
Critical Infrastructure Sectors: Energy
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Austria
Vulnerabilities
Expand All +
CVE-2026-65309
ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the creden
View CSAF
Summary
Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.
The following versions of Siemens Solid Edge are affected:
Solid Edge SE2025 vers:intdot/<225.0.15 (CVE-2026-50058, CVE-2026-50059, CVE-2026-50060, CVE-2026-50061, CVE-2026-50062, CVE-2026-50063, CVE-2026-50064)
Solid Edge SE2026 vers:intdot/<226.0.7 (CVE-2026-50058, CVE-2026-50059, CVE-2026-50060, CVE-2026-50061, CVE-2026-50062, CVE-2026-50063, CVE-2026-50064)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.8
Siemens
Siemens Solid Edge
Out-of-bounds Read, Out-of-bounds Write, Use After Free
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquar
View CSAF
Summary
Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for Simcenter Femap and recommends to update to the latest version.
The following versions of Siemens Simcenter Femap are affected:
Simcenter Femap vers:intdot/<2606.0001 (CVE-2026-59700, CVE-2026-59701)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.8
Siemens
Siemens Simcenter Femap
Out-of-bounds Read
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-59700
The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attac
View CSAF
Summary
Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges.
The following versions of Haiwell IoT Cloud HMI Gateway are affected:
Haiwell IoT Cloud HMI Gateway 3.40.1.12 (CVE-2026-19188)
CVSS
Vendor
Equipment
Vulnerabilities
v3 10
Haiwell
Haiwell IoT Cloud HMI Gateway
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Background
Critical Infrastructure Sectors: Energy, Critical Manufacturing, Water and Wastewater
Countries/Areas Deployed: Worldwide
Company Headquarters Location: China
Vulnerabilities
Expand All +
CVE-2026-19188
A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying ope
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization.
The following versions of AVEVA Enterprise SCADA are affected:
Enterprise SCADA 2025 (CVE-2025-7639)
Enterprise SCADA >=2024|<=2024_SP1_P01 (CVE-2025-7639)
Enterprise SCADA >=2023|<=2023_SP1 (CVE-2025-7639)
Enterprise SCADA >=2022|<=2022_SP2_P2 (CVE-2025-7639)
Enterprise SCADA <=2021_SP2_P5 (CVE-2025-7639)
Enterprise SCADA HMI 2024|2024|R2 (CVE-2025-7639)
Enterprise SCADA HMI <=2023_P1 (CVE-2025-7639)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.1
AVEVA
AVEVA Enterprise SCADA
Deserialization of Untrusted Data
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United Kingdom
Vulnerabilities
Expand All +
CVE-2025-7639
The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority
View CSAF
Summary
Hitachi Energy is aware of Dirty Frag vulnerabilities that affect APM Edge product versions listed in this document. Successful exploitation of these vulnerabilities could result in impact on confidentiality, integrity and availability of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.
The following versions of Hitachi Energy APM Edge Product are affected:
APM Edge vers:APM_Edge/<=6.10 (CVE-2026-43284, CVE-2026-43500)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.8
Hitachi Energy
Hitachi Energy APM Edge Product
Write-what-where Condition, Out-of-bounds Write
Background
Critical Infrastructure Sectors: Energy
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Switzerland
Vulnerabilities
Expand All +
CVE-2026-43284
CWE-123: Write-what-where Condition A vulnerability exists in the IPsec ESP subsystem (esp4, esp6) of the Linux kernel used in APM Edge that allows a local unpri
Using a PIN mitigates many BitLocker vulnerabilities. Make sure you’re ready for the next one...
View CSAF
Summary
Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens recommends to contact customer support for additional information, and follow Fortinet advisory for workarounds and mitigation measures.
The following versions of Siemens RUGGEDCOM APE1808 are affected:
RUGGEDCOM APE1808 vers:all/* (CVE-2026-23573, CVE-2026-59839)
CVSS
Vendor
Equipment
Vulnerabilities
v3 6.1
Siemens
Siemens RUGGEDCOM APE1808
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Background
Critical Infrastructure Sectors: Critical Manufacturing, Energy, Transportation Systems
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-23573
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
The NCSC wants to collaborate with organisations developing technologies and approaches for secure, resilient and deployable private 5G
New guidance is the first content authored by the Industrial Control System COI to appear on ncsc.gov.uk.
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to use hidden commands to disable electrical safety mechanisms or modify other stimulation output settings.
The following versions of Pulsetto Vagus Nerve Stimulator are affected:
Pulsetto Vagus Nerve Stimulator vers:all/* (CVE-2026-18844)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.1
Pulsetto
Pulsetto Vagus Nerve Stimulator
Hidden Functionality
Background
Critical Infrastructure Sectors: Healthcare and Public Health
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Lithuania
Vulnerabilities
Expand All +
CVE-2026-18844
The firmware of the affected product accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully processed by the device when it is powered on.
View CVE Details
Affected Products
Pulsetto Vagu
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability
CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
CVE-2026-72898 Metabase SQL Injection Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token information, and obtain control of user accounts.
The following versions of Mira Hormone Monitor, Mira Android App are affected:
Mira Monitor Firmware 1.7.1.47 (CVE-2026-66875, CVE-2026-66098, CVE-2026-67558, CVE-2026-67568, CVE-2026-68067, CVE-2026-66340, CVE-2026-64934, CVE-2026-66832)
Mira Android App 4.5.15.4 (CVE-2026-66875, CVE-2026-66098, CVE-2026-67558, CVE-2026-67568, CVE-2026-68067, CVE-2026-66340, CVE-2026-64934, CVE-2026-66832)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.8
Quanovate Tech Inc. (operating as Mira / Mira Care)
Mira Hormone Monitor, Mira Android App
Missing Authentication for Critical Function, Authentication Bypass by Spoofing, Use of Hard-coded Credentials, Weak Authentication, Improper Restriction of Excessive Authe
Advisory at a Glance
Title
#StopRansomware: Gunra Ransomware
Original Publication
August 10, 2026
Executive Summary
Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid. This advisory provides technical details of the activity, as well as tailored detection and mitigation guidance to protect at-risk organizations from Gunra.
Key Actions
Prioritize patching known exploited vulnerabilities in internet-facing systems, including virtual private network (VPN) gateways and remote desktop protocol (RDP)-exposed infrastructure.
Implement and test offline, immutable backups stored in a physically separate, segmented location to ensure recoverability