Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
View CSAF
Summary
OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.
The following versions of Siemens Desigo CC are affected:
Desigo CC family V7 vers:all/* (CVE-2025-15467)
Desigo CC family V8 vers:all/* (CVE-2025-15467)
Desigo CC family V9 vers:intdot/<9.0.1 (CVE-2025-15467)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.8
Siemens
Siemens Desigo CC
Out-of-bounds Write
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2025-15467
Issue summary: Parsing CMS AuthEnvelopedData messag
View CSAF
Summary
Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services.
The following versions of igloohome Smart Lock Mobile Application are affected:
Smart Lock Mobile Application (Android) 3.2.3 (CVE-2026-16581)
CVSS
Vendor
Equipment
Vulnerabilities
v3 5.3
igloohome
igloohome Smart Lock Mobile Application
Inclusion of Sensitive Information in Source Code
Background
Critical Infrastructure Sectors: Commercial Facilities
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Singapore
Vulnerabilities
Expand All +
CVE-2026-16581
In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls.
View CVE Details
Affected Products
igloohome Smart Lock Mobile Application
Vendor:igloohome
Produ
View CSAF
Summary
SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
The following versions of Siemens SIMATIC S7-PLCSIM Advanced are affected:
SIMATIC S7-PLCSIM Advanced vers:all/* (CVE-2026-54429)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.4
Siemens
Siemens SIMATIC S7-PLCSIM Advanced
Allocation of Resources Without Limits or Throttling
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-54429
Affected devices do not properly handle high-volume multicast network traffic, which can exhaust available memory resources in the affected application. This could allow an unauthenticated attacker on the local network segment to cause a denial-of-servic
View CSAF
Summary
Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely. This documentation gap may lead application developers to unknowingly apply overly permissive access rules to System.User, resulting in unintended exposure of sensitive user data or privilege escalation within deployed Mendix applications. A common misconfiguration identified is with the anonymous user role with a System.User entity to gain access to all stored records, even though no access rights are explicitly configured on that role. Siemens recommends Mendix developers to review their access rules based on updated documentation.
The following versions of Siemens Mendix Runtime are affected:
Mendix Runtime vers:all/* (CVE-2026-7891)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.1
Siemens
Siemens Mendix Runtime
Insecure Inherited Permissions
Background
Critic
View CSAF
Summary
Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system access.
The following versions of MikroTik RouterOS and Cloud Hosted Router are affected:
RouterOS vers:all/* (CVE-2026-16347)
Cloud Hosted Router vers:all/* (CVE-2026-16347)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.8
MikroTik
MikroTik RouterOS and Cloud Hosted Router
Improper Restriction of Excessive Authentication Attempts
Background
Critical Infrastructure Sectors: Information Technology, Commercial Facilities
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Latvia
Vulnerabilities
Expand All +
CVE-2026-16347
MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without
A highly disruptive incident can feel overwhelming. New guidance provides a framework for response and recovery.
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users.
The following versions of Weintek cMT3092X are affected:
cMT3092X firmware <20210218
EasyWeb <v2.1.20
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.8
Weintek
Weintek cMT3092X
Reliance on Cookies without Validation and Integrity Checking in a Security Decision, Incorrect Permission Assignment for Critical Resource, Plaintext Storage of a Password, Incorrect User Management
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Taiwan
Vulnerabilities
Expand All +
CVE-2026-60134
Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
View CVE Details
Affected Products
Weintek cMT3092X
Vendor:Weintek
Product Version:Weintek cMT3092X firmware: <20210218, Weintek EasyWeb: <v2.
View CSAF
Summary
Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory.
The following versions of Rockwell Automation ThinManager are affected:
ThinManager >=13.0.0|<13.0.7, >=13.1.0|<13.1.5, >=13.2.0|<13.2.4, >=14.0.0|<14.0.2
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.1
Rockwell Automation
Rockwell Automation ThinManager
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Background
Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy, Food and Agriculture, Water and Wastewater
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-11917
A path traversal security issue exists within Rockwell Automation ThinManager software due to improper limitation of file save operations within the API. An authe
View CSAF
Summary
Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service.
The following versions of MZ Automation lib60870 are affected:
lib60870 <=2.4.0
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.2
MZ Automation
MZ Automation lib60870
Out-of-bounds Read
Background
Critical Infrastructure Sectors: Chemical, Energy, Water and Wastewater
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-16002
The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service.
View CVE Details
Affected Products
MZ Automation lib60870
Vendor:MZ Automation
Product Version:MZ Automation lib60870: <=2.4.0
Product Status:known_affected
Remediations
Vendor fixMZ automation recommends users update to version 2.4.1 or later. Documentation can be found at https://github.com/
View CSAF
Summary
Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device.
The following versions of Johnson Controls XAAP Android are affected:
XAAP Android <1.53
CVSS
Vendor
Equipment
Vulnerabilities
v3 3.3
Johnson Controls
Johnson Controls XAAP Android
Cleartext Storage of Sensitive Information
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Ireland
Vulnerabilities
Expand All +
CVE-2026-34490
A cleartext storage weakness exists in the Fire Solutions Android application, which stores application data locally on the device without encryption. An attacker with physical access to the device and one able to compromise the device through a separate, unrelated flaw, could potentially read this data in plaintext. Exploitation does not require network access and is limited to the local device environment.
View CVE De
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution.
The following versions of Johnson Controls C-CURE 9000 and Victor application server are affected:
C-CURE 9000 and victor <=v2.90_v3.0
victor Web <=v7.1
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.6
Johnson Controls
Johnson Controls C-CURE 9000 and Victor application server
Server-Side Request Forgery (SSRF), Execution with Unnecessary Privileges
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Ireland
Vulnerabilities
Expand All +
CVE-2026-21655
Under certain circumstances, successful exploitation of this vulnerability could allow an unauthenticated attacker on the adjacent network to achieve arbitrary code execution on the C-CURE 9000 or victor application server, as well as connected clients (e.g., workstations of physica
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider knowledge, or advanced tooling.
The following versions of Panduit IntraVUE are affected:
IntraVUE <=3.2.1a14
CVSS
Vendor
Equipment
Vulnerabilities
v3 10
Pronetiqs
Panduit IntraVUE
Plaintext Storage of a Password, Unintended Proxy or Intermediary ('Confused Deputy'), Exposure of Sensitive System Information to an Unauthorized Control Sphere, Inadequate Encryption Strength
Background
Critical Infrastructure Sectors: Critical Manufacturing, Energy, Information Technology, Water and Wastewater
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Netherlands
Vulnerabilities
Expand All +
CVE-2026-40430
Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credenti
GCHQ’s National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR’ cyber threat group exposed for targeted phishing campaign
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions.
The following versions of MZ Automation libIEC61850 are affected:
libIEC61850 >=v1.0.0|<=v1.6.1
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.1
MZ Automation
MZ Automation libIEC61850
Stack-based Buffer Overflow, Heap-based Buffer Overflow, Improper Handling of Syntactically Invalid Structure, NULL Pointer Dereference
Background
Critical Infrastructure Sectors: Critical Manufacturing, Energy, Transportation Systems
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-50039
The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause a memory corruption via a ReadRequest.
View CVE Details
Affected Products
No organisation can navigate the migration alone; key takeaways from our first PQC migration workshop.
Cyber Advisors are offering free 30-minute consultations to help small businesses get started with cyber security.
New advisory highlights Russian state cyber actors’ global exploitation of poorly configured routers
An alternative path to Cyber Essentials Plus certification, without compromising the integrity of the scheme.
Why the UK is pioneering an initiative to develop a national scale, sovereign defence capability
Pen testers suggest what organisations can do to make their job more difficult.
Five Eyes cyber security agencies urge organisations to act on rapidly transforming cyber risk.
Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.