🇮🇳 India Regulatory Feed
India Regulatory Updates
Live circulars, advisories and policy updates from RBI, SEBI, CERT-In, MeitY, NPCI, and IRDAI — relevant to cybersecurity and data protection compliance.
215 updates
View CSAF
Summary
Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes.
The following versions of Rockwell Automation OTTO Fleet Manager are affected:
OTTO Fleet Manager <=V2.36.2 (CVE-2026-75112)
CVSS
Vendor
Equipment
Vulnerabilities
v3 6.8
Rockwell Automation
Rockwell Automation OTTO Fleet Manager
Use of Password Hash With Insufficient Computational Effort
Background
Critical Infrastructure Sectors: Critical Manufacturing, Transportation Systems
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-75112
A security issue exists within OTTO Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to take control over the device.
The following versions of Xiiaozet LK100W are affected:
LK100W <2.1.240 (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.8
Xiiaozet
Xiiaozet LK100W
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Missing Authentication for Critical Function, Authentication Bypass Using an Alternate Path or Channel
Background
Critical Infrastructure Sectors: Information Technology
Countries/Areas Deployed: Worldwide
Company Headquarters Location: China
Vulnerabilities
Expand All +
CVE-2026-78037
Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or comp
View CSAF
Summary
Successful exploitation of this vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products.
The following versions of Mitsubishi Electric CNC Series (Update A) are affected:
Mitsubishi Electric M800VW (BND-2051W000) <=BB (CVE-2025-2399)
Mitsubishi Electric M800VS (BND-2052W000) <=BB (CVE-2025-2399)
Mitsubishi Electric M80V (BND-2053W000) <=BB (CVE-2025-2399)
Mitsubishi Electric M80VW (BND-2054W000) <=BB (CVE-2025-2399)
Mitsubishi Electric M800W (BND-2005W000) <=FM (CVE-2025-2399)
Mitsubishi Electric M800S (BND-2006W000) <=FM (CVE-2025-2399)
Mitsubishi Electric M80 (BND-2007W000) <=FM (CVE-2025-2399)
Mitsubishi Electric M80W (BND-2008W000) <=FM (CVE-2025-2399)
Mitsubishi Electric E80 (BND-2009W000) <=FM (CVE-2025-2399)
Mitsubishi Electric C80 (BND-2036W000) vers:all/* (CVE-2025-2399)
Mitsubishi Electric M750VW (BND-1015W002) <=LJ (CVE-2025-2399)
Mitsubishi Electric M730VW (BND-1015W00
View CSAF
Summary
Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition, a timeout error, or a communication delay by sending a specially crafted UDP packet to the product.
The following versions of Mitsubishi Electric Multiple FA Products (Update D) are affected:
Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32D <=09 (CVE-2025-3511)
Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32T <=09 (CVE-2025-3511)
Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32TE <=09 (CVE-2025-3511)
Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32DT <=09 (CVE-2025-3511)
Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32DTE <=09 (CVE-2025-3511)
Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32D <=09 (CVE-2025-3511)
Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32T <=09 (CVE-2025-3511)
Mitsubishi Electric CC-Link IE TSN Remote I/O module N
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2023-49105 ownCloud Improper Authentication Vulnerability
CVE-2026-53362 Linux Kernel Unspecified Vulnerability
CVE-2026-66384 JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total co
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to fully compromise the device.
The following versions of Ebyte NA111-M are affected:
NA111-M Firmware 9013-2-17 (CVE-2026-73125, CVE-2026-76179, CVE-2026-75814, CVE-2026-76940, CVE-2026-77966, CVE-2026-73809, CVE-2026-71187, CVE-2026-75548, CVE-2026-69658, CVE-2026-76133, CVE-2026-73819, CVE-2026-77975, CVE-2026-77977)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.8
Ebyte
Ebyte NA111-M
Missing Authentication for Critical Function, Use of GET Request Method With Sensitive Query Strings, Cross-Site Request Forgery (CSRF), Improper Restriction of Excessive Authentication Attempts, Missing Authorization, Cleartext Transmission of Sensitive Information, Use of Client-Side Authentication, Improper Restriction of Rendered UI Layers or Frames, Use of a Broken or Risky Cryptographic Algorithm, Weak Authentication, Cleartext Storage of Sensitive Information
Background
Critical Infrastructure S
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems.
The following versions of All-Line Equipment Company Fuel-Boss are affected:
Fuel-Boss V1 Standard >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)
Fuel-Boss V1 Portal >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)
Fuel-Boss V1 Master/Slave >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)
Fuel-Boss V1 Backflush Systems >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.7
All-Line Equipment Company
All-Line Equipment Company Fuel-Boss
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'), Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Background
Critical Infrastructure Sectors: Critical Manufacturing, Defense Industrial Base, Emergency Services, Transportation Systems
Countries/Areas Deployed: Worldwide
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications.
The following versions of Applied Systems Engineering ASE2000 V2 Communications Test Set are affected:
ASE2000 >=2.25|<=2.37 (CVE-2018-1285, CVE-2026-18717)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.8
Applied Systems Engineering
Applied Systems Engineering ASE2000 V2 Communications Test Set
Improper Restriction of XML External Entity Reference, Improper Certificate Validation
Background
Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy, Water and Wastewater
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2018-1285
ASE2000 versions 2.25 through 2.37 is vuln
As I've mentioned before in some of my diaries, from time to time, I like to go over phishing messages that get caught in my various spam traps or sent to us here at the Internet Storm Center.
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
A common thing that folks should "worry" about in Entra (or any platform really) is "who has rights to administer"&#x26;#x3f;&#x26;#xc2;&#x26;#xa0; Who can delete or change key things, or modify them in ways that might not be obvious (accidentally or on purpose).&#x26;#xc2;&#x26;#xa0; Yes, we trust our people, but if they&#x26;#39;ve moved on to other roles or to other organizations, they change from "our people" to "used to be our people".&#x26;#xc2;&#x26;#xa0;&#x26;#xc2;&#x26;#xa0;
 Also, it&#x26;#39;s common to have too many admins.&#x26;#xc2;&#x26;#xa0; For instance, entry level support folks might need rights to change passwords, but they likely shouldn&#x26;#39;t have rights to change your intune policies or be global admins.&#x26;#xc2;&#x26;#xa0; The "too many admins" question is a common one that auditors will zero i
CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability
CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2021-23758 Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
CVE-2022-0995 Linux Kernel Out-of-Bounds Write Vulnerability
CVE-2026-8452 Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces th
Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and organizations can reduce their risk by addressing these underlying weaknesses and prioritizing vulnerabilities for action based on the risk they pose.
The CISA Vulnerability Review provides organizations with critical insights into the root causes of insecure software and practical steps they can take to address these flaws to prevent exploitation. Analyzing CISA and open source data from fiscal years 2024 and 2025, the review establishes a baseline of today’s vulnerability landscape before AI-enabled vulnerability discovery becomes more widespread. The review demonstrates the importance of Secure by Design principles in shifting cybersecurity efforts from reacting to threat actors to proactively fixing preventable software flaws.
The review also ident
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
It is pretty obvious that hostnames can replace IP addresses. Pretty much any software accepting an IP address will also accept a hostname as an argument. Last week, I wrote about scans for the cloud metadata service listening at 169.254.169.254. These scans attempted to exploit Server Side Request Forgery (SSRF) vulnerability. One way to prevent these types of exploits is to filter requests that contain the string "169.254.169.254" or to add this IP to a blocklist of URLs that should not be accessed.
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized administrative access, disclose sensitive information, modify device configuration, hijack authenticated sessions, and disrupt device operation.
The following versions of Ebyte NE2-D11 are affected:
NE2-D11 Firmware FW-9167-0-11
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.8
Ebyte
Ebyte NE2-D11
Missing Authentication for Critical Function, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials, Use of Client-Side Authentication, Use of GET Request Method With Sensitive Query Strings, Cross-Site Request Forgery (CSRF), Improper Restriction of Excessive Authentication Attempts, Improper Restriction of Rendered UI Layers or Frames, Missing Authorization
Background
Critical Infrastructure Sectors: Critical Manufacturing, Energy
Countries/Areas Deployed: Worldwide
Company Headquarters Location: China
Vulnerabilities
Expand All +
CVE-
Advisory at a Glance
Title
A Tale of Two SOCs: Insights From Two Red Team Assessments
Original Publication
August 25, 2026
Executive Summary
The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A failed to detect or contain the activity, but Organization B rapidly identified initial compromise attempts, isolated affected systems, and forced the red team into an assume breach model.
This advisory details the red team’s activity and organizations’ defensive actions, offering lessons learned and mitigations to help critical infrastructure organizations strengthen detection, response, and protections in IT, cloud, and operational technology (OT) environments.
Lessons Learned
Untuned detection tools lead to missed
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to access sensitive information and override user permissions.
The following versions of Rently Smart Home are affected:
Smart Home <=20.1.0
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.1
Rently
Rently Smart Home
Insufficiently Protected Credentials
Background
Critical Infrastructure Sectors: Commercial Facilities, Communications, Information Technology
Countries/Areas Deployed: United States, India
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-75960
Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.
View CVE Details
Affected Products
Rently Smart Home
Vendor:Rently
Product Version:Rently Smart Home: <=20.1.0
Product Status:known_affected
Remediations
MitigationRently
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-60004 Gitea Code Injection Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether thr
View CSAF
Summary
Successful exploitation of this vulnerability could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify the device to cause a denial of service, or alter a devices displayed image.
The following versions of PayRange API are affected:
PayRange API vers:all/*
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.8
PayRange
PayRange API
Missing Authorization
Background
Critical Infrastructure Sectors: Commercial Facilities
Countries/Areas Deployed: United States, Canada
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-18965
The affected product is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account.
View CVE Details
Affected Products
PayRange API
Vendor:PayRange
Product Version:PayRange PayRange API: vers:all/*
Product Status:known_affected
Re
View CSAF
Summary
Successful exploitation of this vulnerability could result in full Remote Code Execution (RCE) as the web server user.
The following versions of Zoneminder are affected:
Zoneminder 1.37.48|1.38.3
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.8
Zoneminder
Zoneminder
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Background
Critical Infrastructure Sectors: Information Technology
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-76060
An authenticated OS Command Injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server.
View CVE Details
Affected Products
Zoneminder
Vendor:Zoneminder
Product Version
View CSAF
Summary
SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released a new version for SIMATIC IoT2050 Advanced and strongly recommends to update to the latest version.
The following versions of Siemens SIMATIC IoT2050 Advanced are affected:
SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) vers:intdot/<4.3.4.1
CVSS
Vendor
Equipment
Vulnerabilities
v3 10
Siemens
Siemens SIMATIC IoT2050 Advanced
Missing Authentication for Critical Function
Background
Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy, Transportation Systems
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-58115
Affected devices do not enforce
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to alter device settings.
The following versions of FURUNO FA-50 Class B AIS Transponder are affected:
FURUNO FA-50 Class B AIS Transponder vers:all/*
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.1
FURUNO ELECTRIC CO.,LTD.
FURUNO FA-50 Class B AIS Transponder
Use of Hard-coded Credentials, Missing Authentication for Critical Function
Background
Critical Infrastructure Sectors: Transportation Systems
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Japan
Vulnerabilities
Expand All +
CVE-2026-59769
An attacker, who knows the credentials and has access to the in-vessel network to which the device is connected to, may operate the settings screen using that credentials to alter the settings of the device.
View CVE Details
Affected Products
FURUNO FA-50 Class B AIS Transponder
Vendor:FURUNO ELECTRIC CO.,LTD.
Product Version:FURUNO FA-50 Class B AIS Transponder: ver
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to cause the loss of ABS functions, steering assist, speedometer, shifting capabilities, or disable automatic traction control.
The following versions of Bendix EC80 Brake ECU are affected:
EC80ESP+ J1708 Z228999
EC80ESP+ 6S/6M Z228999
EC80ESP+ PLC Z228999
EC80ESP+ 2nd CAN Z228999
EC80ESP+ Integrated TPMS Z228999
EC80ESP 6S/6M Z266494
EC80ESP PLC Z266494
EC80ESP 2nd CAN Z266494
EC80ESP CAN Gateway Z266494
EC80ESP 4S/4M Z286098
EC80ESP PLC Z286098
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.5
Bendix
Bendix EC80 Brake ECU
Stack-based Buffer Overflow, Out-of-bounds Write, Use of Hard-coded Credentials
Background
Critical Infrastructure Sectors: Transportation Systems
Countries/Areas Deployed: United States, Canada
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-67560
The affected product is vulnerable to a stack-based buffer overflow,
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-21962 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establis
New malware that uses steganography always gets my attention, but I was disappointed when I looked at the latest DOUBLECUP write-up. It doesn&#x26;#39;t use real steganography:
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-73570 Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for whe
Sources
RBI
0
SEBI
0
CERT-In
0
MeitY
0
NPCI
0
IRDAI
0