vulnerability Rockwell Automation 1734 POINT I/O Rockwell Automation’s 1734 POINT I/O module is vulnerable to a denial-of-service attack due to improper handling of crafted CIP messages, potentially causing a system fault and requiring a restart. CISA urges organizatio… CISA Advisories · Jul 21, 2026 Medium CVE-2026-10573USvulnerabilitydenial-of-servicecontrol systems
vulnerability Siemens Opcenter X Siemens Opcenter X versions prior to V2604 contain a critical authentication bypass vulnerability, allowing an unauthenticated attacker to gain full unauthorized access to the application. Siemens has released a new vers… CISA Advisories · Jul 21, 2026 Critical CVE-2026-56451DEauthenticationjwtcwe-347
vulnerability Siemens CADRA Siemens CADRA is affected by multiple vulnerabilities within the zlib library, primarily stemming from improper input validation and integer overflows. These vulnerabilities could lead to denial-of-service crashes, heap… CISA Advisories · Jul 21, 2026 High CVE-2005-2096CVE-2016-9840CVE-2016-9841zlibvulnerabilitybuffer overflow
vulnerability Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW Palo Alto Networks has identified vulnerabilities in PAN-OS software affecting Siemens RUGGEDCOM APE1808 devices when used with their Virtual NGFW solution. These vulnerabilities include cross-site scripting, privilege e… CISA Advisories · Jul 21, 2026 High CVE-2026-0266CVE-2026-0272CVE-2026-0273GEvulnerabilityindustrial control systemscybersecurity
vulnerability Rockwell Automation Studio 5000 Logix Designer Rockwell Automation has issued security advisories regarding multiple vulnerabilities in Studio 5000 Logix Designer, primarily due to path traversal and unquoted search path issues. These vulnerabilities could allow a lo… CISA Advisories · Jul 21, 2026 High CVE-2026-9108CVE-2026-9127CVE-2026-9128path traversalunquoted search pathremote code execution
vulnerability Rockwell Automation 1718-AENTR/1719-AENTR Rockwell Automation has issued a security advisory regarding a denial-of-service vulnerability in its 1718-AENTR and 1719-AENTR products. Exploitation could lead to a denial-of-service condition, requiring a power cycle… CISA Advisories · Jul 21, 2026 High CVE-2026-9140USdenial-of-servicecontrol systemsrockwell automation
vulnerability Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data A security researcher discovered a critical vulnerability in Meta's Horizon Managed Solutions platform, allowing an attacker to access sensitive customer support data and manipulate support workflows. Meta patched the is… SecurityWeek · Jul 21, 2026 High idroraccess controlbug bounty
vulnerability Exploitation of ServiceNow Vulnerability Seen Days After Disclosure A critical remote code execution vulnerability (CVE-2026-6875) in ServiceNow’s AI platform is being actively exploited in the wild by cybersecurity researchers, not malicious attackers. ServiceNow initially denied active… SecurityWeek · Jul 21, 2026 High CVE-2026-6875remote code executionsandbox escapepatching
vulnerability Zimbra Update Patches Critical Vulnerabilities Zimbra has released a critical security update to address several vulnerabilities, including a command injection flaw and XSS defects, that could allow attackers to execute commands and steal emails. The update is essent… SecurityWeek · Jul 21, 2026 Critical CVE-2026-50055CVE-2026-10631CVE-2026-50054command injectionxssssrf
vulnerability Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution A critical security vulnerability in ServiceNow's AI Platform is being actively exploited, allowing unauthenticated code execution and potentially a complete compromise of ServiceNow instances. ServiceNow has released p… The Hacker News · Jul 21, 2026 Critical CVE-2026-6875vulnerabilitycode executionsandbox
vulnerability ISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Struts, potentially allowing for remote code execution via a deserialization attack. This vulnerability is actively being exploite… SANS Internet Storm Center · Jul 21, 2026 Critical apachestrutsvulnerability
vulnerability Multiples vulnérabilités dans Tenable Security Center (21 juillet 2026) Multiple vulnerabilities have been discovered within Tenable Security Center, including remote code execution, SQL injection, and policy bypass. These vulnerabilities, spanning from 2026-06 to 2026-07, allow attackers to… CERT-FR · Jul 21, 2026 High CVE-2025-11187CVE-2025-14179CVE-2025-15467vulnerabilitysql injectionremote code execution
vulnerability OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability A denial-of-service vulnerability, dubbed ‘HollowByte,’ in OpenSSL allows attackers to exhaust server memory by crafting a small payload that triggers excessive buffer allocations. This can lead to complete system lockup… SecurityWeek · Jul 20, 2026 High denial-of-servicebuffer overflowmemory exhaustion
vulnerability New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction A vulnerability (CVE-2026-14266) in 7-Zip’s XZ archive handling allows an attacker to execute code on a victim machine by crafting a malicious XZ archive. The vulnerability stems from a buffer overflow when processing XZ… The Hacker News · Jul 20, 2026 High CVE-2026-14266CVE-2026-48095buffer overflowremote code executionarchive handling
vulnerability Chrome 150 Update Patches Severe Memory Safety Bugs Google released Chrome 150 to address seven memory safety vulnerabilities, including critical use-after-free flaws within components like CameraCapture and GPU. While no exploits have been reported, Google urges users to… SecurityWeek · Jul 20, 2026 High memory-safetyvulnerabilitychrome
vulnerability Multiples vulnérabilités dans Microsoft Edge (20 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, potentially leading to data integrity compromise and an unspecified security issue. These vulnerabilities, identified through various CVEs (2026-15764 thro… CERT-FR · Jul 20, 2026 High CVE-2026-15764CVE-2026-15765CVE-2026-15766vulnerabilitybrowsermicrosoft
vulnerability Multiples vulnérabilités dans WordPress (20 juillet 2026) Multiple vulnerabilities have been discovered in WordPress, allowing attackers to execute arbitrary code remotely and bypass security policies. The CERT-FR has a public proof of concept demonstrating the impact. Users of… CERT-FR · Jul 20, 2026 High CVE-2026-60137CVE-2026-63030wordpressvulnerabilitysql injection
vulnerability Multiples vulnérabilités dans Mattermost Server (20 juillet 2026) Multiple vulnerabilities have been discovered in Mattermost Server, requiring users to update to a patched version to mitigate potential security issues. The exact nature of these vulnerabilities is not specified by the… CERT-FR · Jul 20, 2026 Medium mattermostvulnerabilitysecurity update
vulnerability Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution A critical vulnerability (CVE-2026-42533) in NGINX allows unauthenticated remote code execution, potentially due to a heap buffer overflow triggered by a specific configuration involving regex-based maps. The vulnerabili… The Hacker News · Jul 19, 2026 High CVE-2026-42533CVE-2026-42945CVE-2026-9256heap-overflowregexremote-code-execution
vulnerability New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code A critical vulnerability (RCE) exists in WordPress core versions 6.9 through 6.9.4 and 7.0 through 7.0.1, allowing unauthenticated attackers to execute code via a batch request. While no CVE has been assigned yet, WordPr… The Hacker News · Jul 17, 2026 Critical wordpressrcevulnerability