vulnerability Daktronics Controller Firmware This CISA advisory details a vulnerability in Daktronics Controller Firmware versions up to v10.34.x.x, allowing unauthenticated users to gain root-level access and potentially execute arbitrary code due to a lack of pro… CISA Advisories · Jun 25, 2026 Critical CVE-2026-28701CVE-2026-33560CVE-2026-31928USfirmwareroot accessfile upload
vulnerability Horner Automation Cscape This advisory details a critical vulnerability in Horner Automation’s Cscape software, specifically versions prior to 10.2_SP3. The vulnerability allows for out-of-bounds reads, potentially leading to information disclos… CISA Advisories · Jun 25, 2026 Critical CVE-2026-12897UScscapeout-of-boundsvulnerability
vulnerability Delta Electronics DTM Soft A vulnerability has been identified in Delta Electronics’ DTM Soft software, allowing for potential arbitrary code execution via deserialization of untrusted data. This poses a risk to critical manufacturing operations g… CISA Advisories · Jun 25, 2026 High CVE-2026-12578WOdeserializationcwe-502critical manufacturing
vulnerability Schneider Electric PowerLogic P7 Schneider Electric has identified and addressed vulnerabilities within its PowerLogic™ P7 protection and control platform. Specifically, the product is susceptible to CWE-476 (NULL Pointer Dereference), CWE-78 (Improper… CISA Advisories · Jun 25, 2026 High CVE-2026-9716CVE-2026-9717CVE-2026-9718FRcwefirmwareindustrial control
vulnerability pydicom pynetdicom Library View CSAF Summary Successful exploitation of this vulnerability could allow an unauthenticated attacker to write to arbitrary file paths. The following versions of pydicom pynetdicom Library are affected: pynetdicom >=v1… CISA Advisories · Jun 25, 2026 Medium CVE-2026-56445
vulnerability Yokogawa FAST/TOOLS and CI Server This advisory details a vulnerability in Yokogawa FAST/TOOLS and CI Server software, specifically versions R9.01 to R10.04, that allows an attacker to potentially retrieve CI Server setting information. The vulnerability… CISA Advisories · Jun 25, 2026 Medium CVE-2026-11833USweb servercwe-319vulnerability
vulnerability OHIF Viewers DICOM This advisory details a vulnerability in the OHIF Viewers DICOM framework, specifically versions up to v3.12.0, that allows attackers to steal authenticated user tokens via crafted links. The vulnerability stems from unc… CISA Advisories · Jun 25, 2026 High CVE-2026-12473USssrfdicomweboidc
vulnerability Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning The exploited flaw, CVE-2025-67038, is one of the vulnerabilities disclosed in April as part of the BRIDGE:BREAK research project. The post Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warni… SecurityWeek · Jun 25, 2026 CVE-2025-67038
vulnerability GitLab Patches Code Execution, Information Disclosure Vulnerabilities The latest GitLab CE/EE updates address 13 vulnerabilities, including three high-severity defects. The post GitLab Patches Code Execution, Information Disclosure Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jun 25, 2026 High CVE-2026-10086CVE-2026-10712CVE-2026-12053
vulnerability 25-Year-Old Vulnerability Patched in Curl The latest version of the open source data transfer tool resolves 18 medium and low-severity vulnerabilities. The post 25-Year-Old Vulnerability Patched in Curl appeared first on SecurityWeek . SecurityWeek · Jun 25, 2026 High CVE-2026-8932CVE-2026-8926CVE-2026-8925
vulnerability Chrome 149 Update Resolves 18 Severe Vulnerabilities More than half of the bugs are use-after-free defects, which can potentially lead to remote code execution. The post Chrome 149 Update Resolves 18 Severe Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jun 25, 2026 High
vulnerability Cisco SD-WAN Zero-Day Exploited Months Before Patching CVE-2026-20245, the 7th Cisco SD-WAN vulnerability exploited in 2026, was used for months prior to its disclosure and patching. The post Cisco SD-WAN Zero-Day Exploited Months Before Patching appeared first on SecurityWe… SecurityWeek · Jun 25, 2026 Critical CVE-2026-20245CVE-2026-20127CVE-2026-20182
vulnerability Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access A Mandiant report details how attackers exploited a zero-day vulnerability (CVE-2026-20245) in Cisco SD-WAN Manager, Controller, and Validator software to gain root access on targeted devices. The attackers initially gai… BleepingComputer · Jun 24, 2026 High CVE-2026-20245CVE-2026-20127CVE-2026-20182USzero-dayprivilege escalationroot access
vulnerability Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure Attackers exploited a critical vulnerability in Cisco Catalyst SD-WAN Controller (CVE-2026-20245) approximately two months before Cisco publicly disclosed it. The vulnerability, stemming from insufficient input validatio… Dark Reading · Jun 24, 2026 High CVE-2026-20245CVE-2026-20182CVE-2026-20127USsd-wanprivilege escalationzero-day
vulnerability CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000 Series devices, urging Federal Civilian Executive Branch (… The Hacker News · Jun 24, 2026 Critical CVE-2025-67038CVE-2026-34908CVE-2026-34909
vulnerability macOS Weaknesses Chained to Silently Disable Endpoint Security Agents A standard non-admin account is sufficient to conduct an attack that exploits legitimate OS behavior rather than software vulnerabilities. The post macOS Weaknesses Chained to Silently Disable Endpoint Security Agents ap… SecurityWeek · Jun 24, 2026 CVE-2026-39118
vulnerability Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs Critical vulnerabilities were discovered in Ubiquiti UniFi devices, specifically CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, allowing for unauthorized access and command injection. While patches were released in… SecurityWeek · Jun 24, 2026 Critical CVE-2026-34908CVE-2026-34909CVE-2026-34910USvulnerabilitycommand injectionauthentication
vulnerability Using SASE in a Modern TIC 3.0 Solution Using SASE in a Modern TIC 3.0 Solution CISA’s guidance, The Journey to Zero Trust – Using Secure Access Service Edge in a Modern TIC 3.0 Solution, details how the Trusted Internet Connections (TIC) 3.0 initiative is hel… CISA Advisories · Jun 24, 2026
vulnerability Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME).… The Hacker News · Jun 24, 2026 Medium CVE-2026-20230CVE-2026-20262
vulnerability Hackers Exploiting Cisco Unified CM Vulnerability Cisco noted that a PoC had been available for CVE-2026-20230 when it announced patches in early June. The post Hackers Exploiting Cisco Unified CM Vulnerability appeared first on SecurityWeek . SecurityWeek · Jun 24, 2026 Medium CVE-2026-20230CVE-2026-20045