vulnerability Frangoteam FUXA SCADA/HMI This advisory details a critical vulnerability in Frangoteam FUXA SCADA/HMI software versions up to 1.3.1, allowing unauthenticated remote attackers to enumerate user accounts and role assignments. The vulnerability stem… CISA Advisories · Jun 30, 2026 Critical CVE-2026-13207WOauthentication bypassscadahmi
vulnerability OFFIS DCMTK Toolkit This CISA advisory details vulnerabilities within the OFFIS DCMTK Toolkit (<=3.7.0) that could allow an attacker to perform actions like file writing, unauthorized data access, memory exhaustion, and system crashes. The… CISA Advisories · Jun 30, 2026 High CVE-2026-50003CVE-2026-50254CVE-2026-35505DEpath traversalmemory leakcve-2026-50003
vulnerability Schneider Electric EasyLogic T150 and Saitel DP RTU This advisory details vulnerabilities in Schneider Electric's EasyLogic T150 and Saitel DP RTU devices, specifically versions through 11.06.37. These vulnerabilities, classified as CWE-522 and CWE-732, allow for unauthor… CISA Advisories · Jun 30, 2026 Medium CVE-2026-9650CVE-2026-9651FRcredentialsfirmwareiot
vulnerability Exploitation of Recent Oracle E-Business Suite Vulnerability Begins The critical-severity defect allows unauthenticated attackers to take over the E-Business Suite’s Payments product. The post Exploitation of Recent Oracle E-Business Suite Vulnerability Begins appeared first on SecurityW… SecurityWeek · Jun 30, 2026 Medium CVE-2026-46817
vulnerability AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks Researchers have identified six security flaws in AirDrop and Quick Share, wireless file-sharing features used on Apple and Samsung devices. These vulnerabilities allow an attacker within range to trigger crashes, bypass… The Hacker News · Jun 30, 2026 High CVE-2024-38271CVE-2024-38272CVE-2024-10668USGBairdropquicksharecrash
vulnerability Critical SimpleHelp Vulnerability Exploited for Malware Delivery A critical vulnerability (CVE-2026-48558) in SimpleHelp RMM software allowed unauthorized access and subsequent malware deployment. The flaw, related to OpenID Connect authentication, enabled attackers to gain full techn… SecurityWeek · Jun 30, 2026 Critical CVE-2026-48558USoidcauthenticationmalware
vulnerability Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth A critical vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster allows unauthenticated attackers to execute arbitrary commands as root by manipulating API requests. The flaw stems from a lack of proper sanitization… The Hacker News · Jun 30, 2026 Critical CVE-2026-8037CVE-2026-33691CVE-2024-1212CAcommand-injectionrootapi
vulnerability New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking CISA has published an advisory to inform organizations about three vulnerabilities found by a researcher in Daktronics controllers. The post New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking appe… SecurityWeek · Jun 30, 2026
vulnerability Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild A critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber. The vulnerability, tracked as CVE-2026-46817 (CVSS score: 9.8), refers to an improper… The Hacker News · Jun 30, 2026 Critical CVE-2026-46817CVE-2025-61882CVE-2026-35273
vulnerability Factoring RSA Keys with Many Zeros Interesting research on a new class of weak RSA keys: keys with lots of zeros. It turns out that these keys are out in the wild. The badkeys project is an open-source service that checks public keys for known vulnerabili… Schneier on Security · Jun 29, 2026 High
vulnerability ‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access A critical vulnerability, dubbed ‘DirtyClone,’ has been identified in the Linux kernel, allowing local users to gain root access. This flaw, similar to previous ‘DirtyFrag’ and ‘Fragnesia’ vulnerabilities, stems from how… SecurityWeek · Jun 29, 2026 Critical CVE-2026-43503CVE-2026-43284CVE-2026-43500linuxkernelroot
vulnerability Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw A critical vulnerability, CVE-2026-55200, has been discovered in libssh2, a client-side SSH library embedded in various applications like curl, Git, and PHP. The flaw allows for code execution via an integer overflow, po… The Hacker News · Jun 29, 2026 Critical CVE-2026-55200CVE-2019-3855CVE-2026-55199GBsshlibssh2code execution
vulnerability CISA sets urgent deadline to fix Cisco flaw exploited in attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited. BleepingComputer · Jun 26, 2026 Critical CVE-2026-20230CVE-2026-12569
vulnerability Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories A high-severity vulnerability was discovered in the Amazon Q Developer extension for Visual Studio Code, allowing attackers to steal cloud credentials through malicious code repositories. The extension’s automatic execut… SecurityWeek · Jun 26, 2026 Critical CVE-2026-12957CVE-2026-12958USaivscodecredentials
vulnerability Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk A vulnerability (CVE-2024-2658) has been identified in Schneider Electric’s Floating License Manager (FLM), specifically the FlexNet Publisher component, due to an uncontrolled search path element. This allows a local, n… Securelist · Jun 26, 2026 High CVE-2024-2658USopensslprivilege escalationindustrial control systems
vulnerability CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue CISA has added a critical remote code execution (RCE) vulnerability, CVE-2026-12569, affecting PTC Windchill PDMlink and FlexPLM to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability, stemming from imp… The Hacker News · Jun 26, 2026 Critical CVE-2026-12569rcewindchillweb shell
vulnerability New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets A new vulnerability, CVE-2026-43503, has been discovered in the Linux kernel related to the DirtyClone variant of the DirtyFrag family. This flaw allows local users to gain root access by exploiting a cloned network pack… The Hacker News · Jun 26, 2026 High CVE-2026-43503CVE-2026-31431CVE-2026-43284linuxkernelprivilege escalation
vulnerability Linux Foundation Unveils New Open Source Security Project Akrites It will provide the tools and channels to report, patch, and disclose open source software vulnerabilities. The post Linux Foundation Unveils New Open Source Security Project Akrites appeared first on SecurityWeek . SecurityWeek · Jun 26, 2026 High
vulnerability First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild CISA has added the remote code execution flaw CVE-2026-12569 to its Known Exploited Vulnerabilities catalog. The post First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild appeared first on Securi… SecurityWeek · Jun 26, 2026 High CVE-2026-12569CVE-2026-4681
vulnerability H.VIEW HV-500S6 IP Camera This CISA advisory details a critical vulnerability in H.VIEW HV-500S6 IP cameras, specifically version IPCAM_V4.06.88.251229. The vulnerability allows authenticated users to upload malicious files and execute arbitrary… CISA Advisories · Jun 25, 2026 Critical CVE-2026-55975CVE-2026-56414CHcertificateinput validationcommand injection