vulnerability CISA: Splunk Enterprise flaw actively exploited, patch by Sunday CISA has urged U.S. federal agencies to secure their systems by Sunday against a critical Splunk Enterprise vulnerability that is being exploited in attacks. BleepingComputer · Jun 19, 2026 Critical CVE-2026-20253
vulnerability Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure CISA has given federal agencies only three days to patch CVE-2026-20253, which can be exploited for unauthenticated remote code execution. The post Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosu… SecurityWeek · Jun 19, 2026 High CVE-2026-20253
vulnerability F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution F5 has released security patches to address two critical vulnerabilities (CVE-2026-42530 and CVE-2026-42055) in its NGINX Open Source and NGINX Plus products. These vulnerabilities, which allow for remote code execution,… The Hacker News · Jun 18, 2026 Critical CVE-2026-42530CVE-2026-42055CVE-2026-42945nginxcode executionremote vulnerability
vulnerability AzeoTech DAQFactory This advisory details a Type Confusion vulnerability (CVE-2026-12390) in AzeoTech DAQFactory versions up to 21.1, allowing for potential arbitrary code execution via specially crafted .ctl files. The vulnerability affect… CISA Advisories · Jun 18, 2026 High CVE-2026-12390UStype confusioncwe843code execution
vulnerability AVer PTC cameras This advisory from CISA details a critical vulnerability (CVE-2026-40624) affecting AVer PTC cameras. The flaw allows for remote, unauthenticated code execution via specially crafted web requests due to improper input va… CISA Advisories · Jun 18, 2026 Critical CVE-2026-40624WOremote code executioninput validationfirmware
vulnerability Mitsubishi Electric MELSEC iQ-F Series This advisory from CISA details a vulnerability (CVE-2026-8805) in the Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP Module. The vulnerability, stemming from an integer overflow, allows a remote attacker to… CISA Advisories · Jun 18, 2026 High CVE-2026-8805JPethernet/ipdenial of serviceinteger overflow
vulnerability Rockwell Automation FactoryTalk Historian Site Edition This advisory from CISA details vulnerabilities in Rockwell Automation’s FactoryTalk Historian Site Edition software, specifically versions through 11.00. Exploitation could lead to denial-of-service attacks or authentic… CISA Advisories · Jun 18, 2026 Medium CVE-2025-13036CVE-2025-44019CVE-2025-36539USfactorytalkhistorianrockwellautomation
vulnerability Schneider Electric EasyLogic T150 and Saitel DP This advisory details a vulnerability (CVE-2026-6865) affecting Schneider Electric’s EasyLogic T150 and Saitel DP Remote Terminal Units & Controllers. The vulnerability, a CWE-22 ‘Path Traversal’ flaw, allows an attacker… CISA Advisories · Jun 18, 2026 High CVE-2026-6865FRpath traversalfirmwareremote terminal unit
vulnerability Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT This CISA advisory details a vulnerability in the Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT, specifically version 0x0110_v1.1.0. The device is susceptible to unauthorized interception of sensitive health… CISA Advisories · Jun 18, 2026 High CVE-2026-50034CVE-2026-52866INbluetoothbleglucose
vulnerability Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module This advisory from CISA details a denial-of-service (DoS) vulnerability in Mitsubishi Electric's MELSEC iQ-F Series FX5-ENET/IP Ethernet Module. The vulnerability, CVE-2026-8806, allows a remote attacker to overwhelm the… CISA Advisories · Jun 18, 2026 High CVE-2026-8806JPdenial-of-serviceethernetcve-2026-8806
vulnerability CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory regarding a widespread compromise of credentials associated with Fortinet devices, dubbed ‘FortiBleed.’ Approximately 74,000 Forti… CISA Advisories · Jun 18, 2026 High USGBcredentialsfirewallvpn
vulnerability Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products Schneider Electric has identified a vulnerability (CVE-2026-4827) in several of its industrial automation products, including Easergy, EcoStruxture, PowerLogic, and Saitel systems. The vulnerability, a CWE-331 Insufficie… CISA Advisories · Jun 18, 2026 High CVE-2026-4827upsindustrial controlsession management
vulnerability F5 issues out-of-band patches for critical NGINX vulnerabilities Cybersecurity company F5 has released out-of-band security updates to address multiple NGINX web server vulnerabilities, including two critical-severity flaws that could allow attackers to execute code on vulnerable syst… BleepingComputer · Jun 18, 2026 CVE-2026-42530CVE-2026-42055CVE-2026-11311
vulnerability Atlassian, Splunk Patch Critical Vulnerabilities Splunk patched an OS command injection in AI Toolkit, while Atlassian fixed dozens of flaws in third-party dependencies. The post Atlassian, Splunk Patch Critical Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jun 18, 2026 CVE-2026-20266CVE-2026-20265CVE-2026-42043
vulnerability Critical Command Execution Vulnerability Patched in Cisco ISE Insufficient validation of user input allows an attacker to gain access to the underlying OS and elevate their privileges to root. The post Critical Command Execution Vulnerability Patched in Cisco ISE appeared first on… SecurityWeek · Jun 18, 2026 Medium CVE-2026-20181CVE-2026-20190
vulnerability F5 Patches Critical, High-Severity NGINX Vulnerabilities Critical flaws in NGINX could allow remote, unauthenticated attackers to cause a restart and potentially execute arbitrary code. The post F5 Patches Critical, High-Severity NGINX Vulnerabilities appeared first on Securit… SecurityWeek · Jun 18, 2026 Critical CVE-2026-42530CVE-2026-42055CVE-2026-11311
vulnerability Multiples vulnérabilités dans Mattermost Desktop App (18 juin 2026) Multiple vulnerabilities have been discovered in the Mattermost Desktop App, potentially allowing for remote denial-of-service attacks and an unspecified security issue. These vulnerabilities affect older versions of the… CERT-FR · Jun 18, 2026 Medium CVE-2026-8075CVE-2026-9602vulnerabilitymattermostdesktop app
vulnerability Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development Microsoft has formally disclosed that it's working to release a patch to address a Defender zero-day codenamed RoguePlanet. The vulnerability has now been assigned the CVE identifier CVE-2026-50656 (CVSS score: 7.8), wit… The Hacker News · Jun 17, 2026 Critical CVE-2026-50656CVE-2026-33825CVE-2026-45498
vulnerability Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software The industrial automation giant has fixed security holes in Logix, CompactLogix, Flex, RSLinx, and FactoryTalk products. The post Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software appeared first… SecurityWeek · Jun 17, 2026 CVE-2021-22681
vulnerability Microsoft Working on Patch for ‘RoguePlanet’ Zero-Day The public PoC code exploits a race condition in Microsoft Defender to spawn a command prompt with System privileges. The post Microsoft Working on Patch for ‘RoguePlanet’ Zero-Day appeared first on SecurityWeek . SecurityWeek · Jun 17, 2026 Critical CVE-2026-50656CVE-2026-33825CVE-2026-41091