vulnerability Siemens CADRA Siemens CADRA is affected by multiple vulnerabilities within the zlib library, primarily stemming from improper input validation and integer overflows. These vulnerabilities could lead to denial-of-service crashes, heap… CISA Advisories · Jul 21, 2026 High CVE-2005-2096CVE-2016-9840CVE-2016-9841zlibvulnerabilitybuffer overflow
vulnerability Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW Palo Alto Networks has identified vulnerabilities in PAN-OS software affecting Siemens RUGGEDCOM APE1808 devices when used with their Virtual NGFW solution. These vulnerabilities include cross-site scripting, privilege e… CISA Advisories · Jul 21, 2026 High CVE-2026-0266CVE-2026-0272CVE-2026-0273GEvulnerabilityindustrial control systemscybersecurity
threat-intel Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy A collaborative research effort between Palo Alto Networks and Siemens has uncovered a critical, chained exploit within the Siemens ROX II operational technology (OT) switches. The vulnerability chain consists of three z… Palo Alto Unit 42 · Jul 17, 2026 Critical CVE-2025-40948CVE-2025-40947CVE-2025-40949otvulnerabilitycommand-injection
threat-intel Siemens SICAM 8 Siemens has released security advisories detailing multiple vulnerabilities in its SICAM 8 industrial control system firmware and related components. These vulnerabilities could allow an attacker to cause denial of servi… CISA Advisories · Jul 16, 2026 High CVE-2026-54798CVE-2026-54799CVE-2026-54800vulnerabilityfirmwareindustrial control systems
vulnerability F5 Patches Multiple NGINX, BIG-IP Vulnerabilities F5 has released out-of-band security patches to address eight critical vulnerabilities affecting NGINX and BIG-IP. These flaws could lead to denial-of-service attacks, memory leaks, and potentially allow remote code exec… SecurityWeek · Jul 16, 2026 High CVE-2026-42533nginxbig-ipvulnerability
threat-intel ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell This Patch Tuesday saw significant security updates released by Siemens, Schneider Electric, Rockwell Automation, ABB, and Mitsubishi Electric to address a range of vulnerabilities in their industrial control systems (IC… SecurityWeek · Jul 15, 2026 High GEicspatch tuesdayvulnerability
threat-intel ISC Stormcast For Wednesday, July 8th, 2026 https://isc.sans.edu/podcastdetail/9998, (Wed, Jul 8th) The SANS Internet Storm Center’s latest Stormcast highlighted a significant increase in malicious activity targeting industrial control systems (ICS) and operational technology (OT) environments. Specifically, the report… SANS Internet Storm Center · Jul 8, 2026 High icsotvulnerability
vulnerability Siemens Mendix Studio Pro Siemens has issued an advisory regarding a critical file parsing vulnerability in Mendix Studio Pro. Versions prior to V10.24.21 and V11.6.7 are susceptible to code execution if a user opens and runs a maliciously crafte… CISA Advisories · Jul 7, 2026 Critical CVE-2026-48192code-injectionindustrial-control-systemics
threat-intel Siemens SINEC OS Siemens has released a security advisory regarding multiple vulnerabilities within its SINEC OS and related products, including the RUGGEDCOM RST2428P. These vulnerabilities, ranging from stack-based buffer overflows to… CISA Advisories · Jul 7, 2026 High CVE-2025-1352CVE-2025-1376CVE-2025-6052vulnerabilitybuffer overflowpath traversal
threat-intel ISC Stormcast For Tuesday, July 7th, 2026 https://isc.sans.edu/podcastdetail/9996, (Tue, Jul 7th) The SANS Internet Storm Center’s latest Stormcast highlighted a significant increase in malicious activity targeting industrial control systems (ICS) and operational technology (OT) environments. The report indicated a s… SANS Internet Storm Center · Jul 7, 2026 High icsotvulnerability
threat-intel ISC Stormcast For Monday, July 6th, 2026 https://isc.sans.edu/podcastdetail/9994, (Mon, Jul 6th) The SANS Internet Storm Center’s latest Stormcast highlighted a significant increase in malicious activity targeting industrial control systems (ICS) and operational technology (OT) environments. Specifically, the report… SANS Internet Storm Center · Jul 6, 2026 High icsotindustrial control systems
vulnerability Siemens WinCC Certificate Manager A vulnerability has been identified in Siemens WinCC Certificate Manager, specifically versions V16 through V21, that allows an attacker to potentially extract sensitive information due to insufficient protection of key… CISA Advisories · Jun 23, 2026 High CVE-2026-24349GEcertificatekey managementindustrial control systems
vulnerability Siemens Products using OpenSSL A stack-based buffer overflow vulnerability (CVE-2025-15467) has been identified in various Siemens products utilizing OpenSSL. This vulnerability allows a remote attacker to potentially cause a denial-of-service or exec… CISA Advisories · Jun 23, 2026 High CVE-2025-15467DEUSCNopensslbuffer overflowdenial of service
threat-intel Siemens SINEC INS This CISA advisory details a critical vulnerability affecting Siemens SINEC INS versions prior to V1.0 SP2 Update 6. The vulnerability stems from improper input sanitization, allowing for command injection, path traversa… CISA Advisories · Jun 23, 2026 Critical CVE-2026-46746CVE-2026-46747CVE-2026-46748DEcommand injectionpath traversalpassword cracking
vulnerability Siemens SIPROTEC 5 Using DIGSI5 Protocol This CISA advisory details a vulnerability in Siemens SIPROTEC 5 devices, specifically utilizing the DIGSI5 protocol, that allows authenticated users to upload arbitrary files. This could lead to denial-of-service condit… CISA Advisories · Jun 23, 2026 High CVE-2025-40808relayprotocoldenial of service
data-breach FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices. A significant data leak, dubbed "FortiBleed," has exposed approximately 73,932 Fortinet VPN credentials for firewall URLs across numerous organizations worldwide. The leak, discovered by Bob Diachenko, reveals a multi-op… BleepingComputer · Jun 17, 2026 High USGBJPvpncredentialsbreach
vulnerability Siemens KACO Blueplanet Inverters This advisory from CISA details vulnerabilities within Siemens KACO Blueplanet Inverters, a series of industrial inverters used in energy systems. The vulnerabilities, specifically a CRC16-based algorithm for generating… CISA Advisories · Jun 9, 2026 High CVE-2025-40946CVE-2026-41125WOindustrial control systemsvulnerabilityauthentication
vulnerability Siemens RUGGEDCOM APE1808 Devices A buffer overflow vulnerability (CVE-2026-0300) has been identified in Siemens RUGGEDCOM APE1808 devices, specifically the User-ID™ Authentication Portal service within Palo Alto Networks PAN-OS software. This vulnerabil… CISA Advisories · May 19, 2026 High CVE-2026-0300DEbuffer overflowcaptive portalroot privilege
vulnerability Siemens SENTRON 7KT PAC1261 Data Manager A vulnerability has been identified in the Siemens SENTRON 7KT PAC1261 Data Manager software, specifically within the Go Project’s net/http package. This allows an attacker to potentially gain administrative control over… CISA Advisories · May 14, 2026 High CVE-2025-22871DEhttprequest smugglingindustrial control systems
vulnerability Siemens SIMATIC A vulnerability (CVE-2026-27662) has been identified in Siemens SIMATIC HMI Unified Comfort Panels. The flaw allows an unauthenticated attacker to gain access to the web browser through the help link, potentially enablin… CISA Advisories · May 14, 2026 High CVE-2026-27662hmiindustrial controlweb browser