vulnerability Siemens RUGGEDCOM APE1808 Devices A buffer overflow vulnerability (CVE-2026-0300) has been identified in Siemens RUGGEDCOM APE1808 devices, specifically the User-ID™ Authentication Portal service within Palo Alto Networks PAN-OS software. This vulnerabil… CISA Advisories · May 19, 2026 High CVE-2026-0300DEbuffer overflowcaptive portalroot privilege
vulnerability SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access SEPPMail Secure E-Mail Gateway has been found to contain multiple critical vulnerabilities, including remote code execution (RCE) and unauthorized access to mail traffic. These flaws, detailed in a report by InfoGuard La… The Hacker News · May 19, 2026 Critical CVE-2026-2743CVE-2026-7864CVE-2026-44125remote code executionemail securitylog rotation
vulnerability Multiples vulnérabilités dans les produits Mattermost (19 mai 2026) Multiple vulnerabilities have been discovered in Mattermost products, including desktop apps and server versions. These vulnerabilities could allow an attacker to elevate privileges, compromise data confidentiality, and… CERT-FR · May 19, 2026 Medium CVE-2026-3433CVE-2026-6046CVE-2026-6689vulnerabilitypatchsecurity
vulnerability Zero-Day Exploit Against Windows BitLocker A new zero-day exploit, dubbed YellowKey, has been discovered targeting Windows BitLocker encryption. The vulnerability allows attackers to bypass BitLocker's security measures with physical access to the affected device… Schneier on Security · May 18, 2026 High zero-dayencryptionbitlocker
vulnerability MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege escalation zero-day flaw that grants attacker… The Hacker News · May 18, 2026 Critical CVE-2020-17103CVE-2025-62221
vulnerability CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-42897 Microsoft Exchange Server Cross-Site Scripting Vulnerability This type… CISA Advisories · May 15, 2026 Medium CVE-2026-42897
vulnerability Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities Cisco Talos has identified ongoing exploitation of vulnerabilities within Cisco Catalyst SD-WAN Controller and Manager, specifically CVE-2026-20182 and a set of related vulnerabilities (CVE-2026-20133, CVE-2026-20128, an… Cisco Talos · May 14, 2026 High CVE-2026-20182CVE-2026-20133CVE-2026-20128sd-wanciscoauthentication
vulnerability Siemens Simcenter Femap A heap-based buffer overflow vulnerability has been identified in Siemens Simcenter Femap, specifically within the Datakit library. The vulnerability, reported by TrendAI Zero Day Initiative, allows for remote code execu… CISA Advisories · May 14, 2026 High CVE-2025-12659GEheap-overflowremote-code-executionipt
vulnerability Siemens Teamcenter Siemens Teamcenter versions 2312, 2406, 2412, and 2506 are affected by multiple vulnerabilities, including a PDF.js flaw and hardcoded credentials. These vulnerabilities could allow for arbitrary code execution and unaut… CISA Advisories · May 14, 2026 High CVE-2026-33862CVE-2026-33893CVE-2024-4367DEpdfjscredentialscve-2024-4367
vulnerability Siemens Ruggedcom Rox A vulnerability has been identified in Siemens Ruggedcom Rox devices, specifically within the feature key installation process. This flaw allows authenticated remote attackers to execute arbitrary commands with root priv… CISA Advisories · May 14, 2026 Critical CVE-2025-40947DEinput validationremote code executionroot privilege
vulnerability Siemens SIPROTEC 5 This CISA advisory details a critical vulnerability in Siemens SIPROTEC 5 devices due to the use of insufficiently random session identifiers. An unauthenticated remote attacker could potentially exploit this weakness to… CISA Advisories · May 14, 2026 Critical CVE-2024-54017session_hijackingauthenticationrandomness
vulnerability Siemens SIMATIC A vulnerability (CVE-2026-27662) has been identified in Siemens SIMATIC HMI Unified Comfort Panels. The flaw allows an unauthenticated attacker to gain access to the web browser through the help link, potentially enablin… CISA Advisories · May 14, 2026 High CVE-2026-27662hmiindustrial controlweb browser
vulnerability Siemens SIMATIC S7 PLC Web Server This CISA advisory details multiple vulnerabilities discovered within Siemens SIMATIC S7 PLCs, specifically within their web servers. These vulnerabilities, identified as CVE-2026-25786 through CVE-2026-25789, allow for… CISA Advisories · May 14, 2026 Medium CVE-2026-25786CVE-2026-25787CVE-2026-25789plcwebserverxss
vulnerability Siemens Ruggedcom Rox A vulnerability has been identified in Siemens Ruggedcom Rox devices, specifically within the Scheduler functionality, allowing authenticated remote attackers to execute arbitrary commands with root privileges. This is d… CISA Advisories · May 14, 2026 Critical CVE-2025-40949DEinput validationroot privilegescheduler
vulnerability Siemens Siemens ROS# This advisory details a critical vulnerability in Siemens ROS# (version 2.2.2 and earlier) due to a path traversal flaw. An attacker could potentially access and modify arbitrary files on a system hosting the ROS# file_s… CISA Advisories · May 14, 2026 Critical CVE-2026-41551DEpath traversalindustrial control systemscwe-23
vulnerability Siemens SENTRON 7KT PAC1261 Data Manager A vulnerability has been identified in the Siemens SENTRON 7KT PAC1261 Data Manager software, specifically within the Go Project’s net/http package. This allows an attacker to potentially gain administrative control over… CISA Advisories · May 14, 2026 High CVE-2025-22871DEhttprequest smugglingindustrial control systems
vulnerability Siemens Ruggedcom Rox This CISA advisory details a vulnerability affecting Siemens Ruggedcom Rox devices. The devices, specifically versions prior to 2.17.1, contain multiple third-party vulnerabilities, including those listed in CVEs from 20… CISA Advisories · May 14, 2026 Medium CVE-2019-13103CVE-2019-13104CVE-2019-13106vulnerabilitypatchingcve
vulnerability CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-20182 Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability Th… CISA Advisories · May 14, 2026 Medium CVE-2026-20182
vulnerability Siemens Industrial Devices This article details a vulnerability (CVE-2025-40833) affecting multiple Siemens industrial devices, including IE/PB LINK HA, SCALANCE M series routers, and RuggedCom RM1224 LTE devices. The vulnerability allows an attac… CISA Advisories · May 14, 2026 High CVE-2025-40833industrial controldenial of servicefirmware update
vulnerability Siemens Opcenter RDnL This advisory details a critical vulnerability in Siemens Opcenter RDnL software, specifically related to missing authentication in the ActiveMQ Artemis component. An attacker within an adjacent network could exploit thi… CISA Advisories · May 14, 2026 Critical CVE-2026-27446DEauthenticationcore protocolactivemq artemis