vulnerability XZ Utils vulnerability impacting B&R Products This advisory details a critical vulnerability (CVE-2025-31115) affecting versions of XZ Utils used in B&R Industrial Automation products, specifically the PPC3100, C50, C80, FT50, MT50, T30, T80, and T50. The vulnerabil… CISA Advisories · Jun 30, 2026 Critical CVE-2025-31115CHxzmemory corruptionheap
vulnerability StoneFly Storage Concentrator This report details a critical vulnerability affecting StoneFly Storage Concentrator versions prior to 8.0.4.29, exposing the system to significant risks including unauthorized access, command execution, and data theft.… CISA Advisories · Jun 30, 2026 Critical CVE-2026-56415CVE-2026-55721CVE-2026-50040UScredentialcommand injectionsql injection
vulnerability Schneider Electric EasyLogic T150 and Saitel DP RTU This advisory details vulnerabilities in Schneider Electric's EasyLogic T150 and Saitel DP RTU devices, specifically versions through 11.06.37. These vulnerabilities, classified as CWE-522 and CWE-732, allow for unauthor… CISA Advisories · Jun 30, 2026 Medium CVE-2026-9650CVE-2026-9651FRcredentialsfirmwareiot
vulnerability Schneider Electric PowerLogic P7 Schneider Electric has identified and addressed vulnerabilities within its PowerLogic™ P7 protection and control platform. Specifically, the product is susceptible to CWE-476 (NULL Pointer Dereference), CWE-78 (Improper… CISA Advisories · Jun 25, 2026 High CVE-2026-9716CVE-2026-9717CVE-2026-9718FRcwefirmwareindustrial control
vulnerability Delta Electronics DTM Soft A vulnerability has been identified in Delta Electronics’ DTM Soft software, allowing for potential arbitrary code execution via deserialization of untrusted data. This poses a risk to critical manufacturing operations g… CISA Advisories · Jun 25, 2026 High CVE-2026-12578WOdeserializationcwe-502critical manufacturing
vulnerability Yokogawa FAST/TOOLS and CI Server This advisory details a vulnerability in Yokogawa FAST/TOOLS and CI Server software, specifically versions R9.01 to R10.04, that allows an attacker to potentially retrieve CI Server setting information. The vulnerability… CISA Advisories · Jun 25, 2026 Medium CVE-2026-11833USweb servercwe-319vulnerability
vulnerability Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs Critical vulnerabilities were discovered in Ubiquiti UniFi devices, specifically CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, allowing for unauthorized access and command injection. While patches were released in… SecurityWeek · Jun 24, 2026 Critical CVE-2026-34908CVE-2026-34909CVE-2026-34910USvulnerabilitycommand injectionauthentication
vulnerability CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution CISA has added a critical vulnerability, CVE-2026-48907, to its Known Exploited Vulnerabilities catalog affecting the Widget Factory Joomla Content Editor (JCE) due to improper access control. This flaw allows for PHP co… The Hacker News · Jun 17, 2026 Critical CVE-2026-48907TUjoomlaphpcode execution
vulnerability Rockwell Automation RSLinx Rockwell Automation has issued a security advisory regarding a vulnerability in its RSLinx Classic software. The flaw, a stack-based buffer overflow (CVE-2020-13573), allows for remote code execution and could lead to de… CISA Advisories · Jun 16, 2026 High CVE-2020-13573WObuffer overflowremote code executioncve-2020-13573
vulnerability Vulnérabilité dans LibreNMS (11 juin 2026) A critical vulnerability has been identified in LibreNMS, allowing attackers to execute arbitrary code remotely. This affects versions 21.6.x through 26.x, and requires immediate patching to prevent exploitation. CERT-FR · Jun 11, 2026 Critical CVE-2026-55182librenmsremote code executionvulnerability
vulnerability Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flaws Microsoft released its June 2026 Patch Tuesday updates, addressing a significant number of vulnerabilities across its product suite. The updates included three previously unknown zero-day exploits and a total of 200 othe… BleepingComputer · Jun 9, 2026 High zero-daypatchmicrosoft
vulnerability Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws Microsoft released its June 2026 Patch Tuesday updates, addressing a significant number of vulnerabilities across its product suite. The updates include five publicly disclosed zero-day vulnerabilities, one of which is c… BleepingComputer · Jun 9, 2026 High zero-daypatchvulnerability
vulnerability Patch Now: Another Palo Alto Auth Bypass Bug Under Active Exploit A vulnerability in Palo Alto Networks' PAN-OS GlobalProtect VPN technology, tracked as CVE-2026-0257, is currently being actively exploited. Attackers are leveraging a configuration flaw to bypass authentication and gain… Dark Reading · Jun 1, 2026 Critical CVE-2026-0257CVE-2025-0108USvpnauthenticationcookie
threat-intel Critical Windows Netlogon RCE flaw now exploited in attacks A critical Remote Code Execution (RCE) vulnerability (CVE-2026-41089) in Windows Netlogon is now being actively exploited in attacks, according to Belgium's national cybersecurity authority, the Centre for Cybersecurity… BleepingComputer · Jun 1, 2026 Critical CVE-2026-41089CVE-2026-45585CVE-2026-33825BErcenetlogonwindows
vulnerability Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks Palo Alto Networks is warning of an actively exploited vulnerability (CVE-2026-0257) in its GlobalProtect VPN software, allowing attackers to bypass authentication and establish unauthorized VPN connections. The flaw, in… BleepingComputer · May 30, 2026 High CVE-2026-0257USvpnauthenticationcookie
vulnerability Multiples vulnérabilités dans les produits Mattermost (29 mai 2026) Multiple vulnerabilities have been discovered in Mattermost Server, allowing attackers to compromise data confidentiality and bypass security policies. These vulnerabilities, detailed in Mattermost security bulletins, re… CERT-FR · May 29, 2026 Medium CVE-2026-3472CVE-2026-4339vulnerabilitymattermostsecurity
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa
vulnerability Multiples vulnérabilités dans les produits Mattermost (22 mai 2026) Multiple vulnerabilities have been discovered in Mattermost products, allowing an attacker to bypass security policies and potentially lead to an unspecified security issue. These vulnerabilities affect various versions… CERT-FR · May 22, 2026 Medium CVE-2026-5139CVE-2026-6062CVE-2026-6517vulnerabilitysecuritypatch
vulnerability Microsoft warns of new Defender zero-days exploited in attacks Microsoft has released security patches for two zero-day vulnerabilities, CVE-2026-41091 (RedSun) and CVE-2026-45498 (UnDefend), that are being actively exploited in attacks. These flaws, affecting Microsoft Defender and… BleepingComputer · May 21, 2026 High CVE-2026-41091CVE-2026-45498USzero-dayprivilege escalationdefender
threat-intel Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare Drupal has announced an upcoming core security release scheduled for May 20, 2026, urging users to prepare and update their systems proactively. The release addresses potential vulnerabilities that could be exploited qui… The Hacker News · May 19, 2026 High drupalsecurityupdate