NEW#0001
CISAabout 7 hours ago5 min▣LLM reporthigh Four vulnerabilities in AVEVA Pipeline Integrity Monitor enable information disclosure, password hash brute-forcing, unauthorized reads, and XSS; update to 2025 SP1 P2 immediately.
AVEVA Pipeline Integrity Monitor versions through 2025 SP1 P1 build 7.1.9580.8513 contain four vulnerabilities spanning hard-coded crypto keys, weak hashing, missing authorization, and stored XSS. Two CVEs score 8.4 HIGH allowing local attackers to decrypt project files and brute-force user passwords for privilege escalation. The remaining two enable unauthenticated information disclosure and browser-session code execution via social engineering.
NEW#0002
CISAabout 7 hours ago4 min▣LLM reportcritical CISA added two actively exploited MikroTik RouterOS vulnerabilities to the KEV Catalog: a missing-authentication flaw and a command-injection flaw, both enabling device takeover.
Two MikroTik RouterOS vulnerabilities are under active exploitation: CVE-2026-67277 (missing authentication for a critical function) and CVE-2026-86060 (command argument delimiter injection). Both allow unauthenticated attackers to gain control of affected routers. CISA requires FCEB agencies to remediate per BOD 26-04 and urges all organizations to patch immediately.
NEW#0003
CISAabout 15 hours ago4 min▣LLM reporthigh Orthanc DICOM Server versions below 1.13.0 contain an integer overflow (CVE-2026-87020) enabling authenticated remote attackers to crash the service via crafted PNG images.
An authenticated remote attacker can exploit an integer overflow in Orthanc DICOM Server's image decoding to trigger a heap out-of-bounds write. The vulnerability affects versions before 1.13.0 and results in process crash and denial-of-service.
NEW#0004
CISAabout 18 hours ago5 min▣LLM reporthigh Four vulnerabilities in ST Engineering iDirect iQ-Series satellite terminals enable unauthenticated data theft, credential exposure, privilege escalation, and CSRF-driven denial of service.
Affected terminal families include Evolution, 3315, and 9-Series at firmware <=4.5.2.1. CVE-2026-38059 exposes satellite authentication identifiers without credentials; CVE-2026-38058 leaks MD5-crypt root password hashes to authenticated users. A factory pre-configured account enables local privilege escalation (CVE-2026-38056), and CSRF on /api/reboot causes satellite link loss (CVE-2026-38057).
NEW#0005
CISAabout 19 hours ago4 min▣LLM reporthigh NextGen Healthcare Mirth Connect <=4.7.1 has three critical SQL injection and XXE vulnerabilities enabling data exfiltration, arbitrary file write, and denial of service; patch to v4.7.2+.
An authenticated SQL injection in the Database Connector API allows arbitrary SQL execution, credential disclosure, and file write (CVE-2026-82583). Two unauthenticated XXE flaws in XSLT and XML batch processing enable data exfiltration and DoS (CVE-2026-78224, CVE-2026-82578). All require Mirth Connect upgrade to v4.7.2 or later.
NEW#0006
CISA1 day ago5 min▣LLM reportcritical CISA added four actively exploited vulnerabilities to the KEV Catalog affecting Fortinet, Citrix NetScaler, Google Chromium V8, and Cisco Firewall Management Center products.
All four CVEs show evidence of active exploitation in the wild. Two are authentication bypasses on perimeter devices (Citrix NetScaler, Cisco FMC), one is a heap overflow in Fortinet products, and one is a V8 out-of-bounds write in Chromium. Patch all affected products immediately and investigate for pre-patch compromise.
NEW#0007
CISA3 days ago5 min▣LLM reporthigh CISA added four actively exploited vulnerabilities to the KEV Catalog spanning Adobe Commerce, Microsoft Windows, and N-able N-central, requiring urgent patching.
Four CVEs across Adobe Commerce, Microsoft Windows, and N-able N-central were added to CISA's KEV Catalog with confirmed active exploitation. The vulnerabilities span template injection, link following, heap overflow, and static code injection. All organizations should prioritize patching and check for prior compromise.
NEW#0008
CISA3 days ago5 min▣LLM reporthigh China-based AI firms are conducting industrial-scale knowledge distillation against U.S. frontier AI models via API abuse and proxy networks to steal proprietary capabilities.
China-based AI companies use fraudulent accounts, API proxies, and automated metadata sanitization to extract billions of tokens from U.S. frontier models. They employ prompt injection and jailbreaks to elicit hidden chain-of-thought reasoning. This undermines U.S. technological leadership and causes economic harm.
NEW#0009
CISA3 days ago4 min▣LLM reportmedium CareCam Pro IP cameras ship with hard-coded bootloader credentials exploitable via physical access, enabling full device compromise; vendor is unresponsive.
CVE-2026-85083 affects ANJIA AJL33PC0801 IP cameras running firmware linuxlinux202008261138_svn13796 with U-Boot bootloader. An attacker with physical access authenticates to the bootloader using hard-coded credentials, then modifies firmware and system configuration for complete device compromise. The flaw is not remotely exploitable.
NEW#0010
CISA6 days ago5 min▣LLM reporthigh Tycon Systems TPDIN-Monitor-WEB3 firmware versions 2.2.9 and prior are vulnerable to hard-coded credentials, CSRF, and missing authorization flaws. Exploitation enables attackers to intercept sensitive data, force state changes, or extract credentials and configurations from the device. Firmware version 2.4.2 is available to remediate these issues.
NEW#0011
CISA7 days ago7 min▣LLM reportcritical CVE-2026-78012 is a critical stack-based buffer overflow (CVSS 9.8) in Pyramid Solutions NetStaX EtherNet/IP Stack prior to v5.6.1. An attacker can send a large Class 3 explicit-message request that exceeds the application-side receive buffer without triggering a CIP error, causing memory corruption or a device crash. The vulnerability affects eight Adapter and Scanner kit variants used in Critical Manufacturing, Energy, Water and Wastewater, and Chemical sectors worldwide.
NEW#0012
CISA7 days ago5 min▣LLM reporthigh CISA added CVE-2026-85046, a Google Chromium V8 type confusion vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. Type confusion vulnerabilities in browser engines are frequent attack vectors and can allow attackers to achieve code execution. FCEB agencies are required to remediate this under BOD 26-04, and CISA recommends all organizations prioritize patching.
#0013
CISA7 days ago7 min▣LLM reportcritical Tycon Systems TPDIN-Monitor-WEB2 (Update A) devices running firmware prior to 2.4.5 contain two vulnerabilities: a critical missing authentication flaw (CVE-2026-61884, CVSS 9.8) that exposes the web management interface without login on unconfigured units, and a medium-severity cleartext credential storage issue (CVE-2026-55985). An attacker with network access to an unconfigured device can manipulate power relays and physical equipment, posing a safety risk. Firmware 2.4.5 resolves both issues.
#0014
CISA8 days ago6 min▣LLM reporthigh Inductive Automation Ignition versions 8.1.53 and earlier ship with a blank default value for the Gateway 'Create Project Role(s)' setting. This configuration error allows any authenticated user with the ability to execute gateway scripts to create projects. The vulnerability is classified as CWE-276 (Incorrect Default Permissions) with a CVSS v3.1 score of 8.8. The vendor fixed the issue in version 8.1.54 by restricting project creation to Designer sessions and removing reliance on the setting.
#0015
CISA8 days ago6 min▣LLM reporthigh CVE-2025-10478 is a network-exploitable denial-of-service vulnerability in the Rockwell Automation 1756-ENBT EtherNet/IP bridge module. An unauthenticated attacker can send a crafted CIP packet to crash the device, which then requires a manual restart. All versions of the 1756-ENBT hardware are affected, and the vendor recommends replacing the module with a 1756-EN2T or 1756-EN4TR.
#0016
CISA8 days ago3 min▣LLM reportlow CISA and the G7 Cyber Security Working Group published a strategic advisory urging organizations and governments to transition to post-quantum cryptography (PQC). The advisory outlines five priorities for adoption, including raising awareness, developing national strategies, advancing R&D, fostering partnerships, and integrating PQC into procurement. The goal is to protect sensitive data and critical assets from future quantum computing threats.
#0017
CISA8 days ago3 min▣LLM reportlow CISA, FBI, and international partners published guidance on crisis communications during IT and OT outages. The guidance emphasizes clarity, accountability, and transparency to manage stakeholder expectations during service disruptions caused by cyber incidents or other hazards. It recommends critical infrastructure organizations prepare backup communication methods, assuming telecom services may be unreliable.
#0018
CISA8 days ago6 min▣LLM reporthigh CISA added seven vulnerabilities to the Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The vulnerabilities span multiple products and include SQL injection, HTTP request smuggling, OS command injection, improper authentication, and SSRF. FCEB agencies are required to remediate these under BOD 26-04, and CISA encourages all organizations to prioritize patching.
#0019
CISA10 days ago5 min▣LLM reporthigh A denial of service vulnerability (CVE-2021-42260) affects multiple Rockwell Automation industrial controllers. The flaw allows remote attackers to trigger an infinite loop via crafted data, causing a major nonrecoverable fault (MNRF) that requires a program download or stage 2 reset to recover. The CVSS v3.1 base score is 7.5 (High).
#0020
CISA10 days ago5 min▣LLM reporthigh Rockwell Automation FactoryTalk Historian ME contains an out-of-bounds write vulnerability (CVE-2025-12768) and a stack-based buffer overflow vulnerability (CVE-2026-12661). CVE-2025-12768 permits remote code execution with low-level authentication. CVE-2026-12661 permits denial of service with high-level authentication. Both vulnerabilities affect Series B 5.202 and Series C 7.101.