vulnerability Siemens Parasolid Siemens Parasolid versions V38.0 and V38.1 are vulnerable to an out-of-bounds read vulnerability when parsing X_T files, potentially allowing an attacker to execute arbitrary code. Siemens has released updates to address… CISA Advisories · Aug 13, 2026 High CVE-2026-64629vulnerabilitysupply-chainindustrial-control-systems
vulnerability Siemens Solid Edge Siemens Solid Edge versions 2025 and 2026 are vulnerable to multiple file parsing vulnerabilities, including out-of-bounds reads and writes, and use-after-free errors, when processing PAR, PSM, and DFT files. These vulne… CISA Advisories · Aug 13, 2026 High CVE-2026-50058CVE-2026-50059CVE-2026-50060vulnerabilityfile-parsingcad
vulnerability Johnson Controls Inc. Airwall Johnson Controls Inc.'s Airwall software versions 4.0.4 and earlier contain critical vulnerabilities. A hardcoded cryptographic key allows attackers to decrypt sensitive data, bypass authentication, and access arbitrary… CISA Advisories · Aug 13, 2026 High CVE-2026-64887CVE-2026-34492vulnerabilityhardcoded keypath traversal
vulnerability ANDRITZ HIPASE-250 and 250 SCALA ANDRITZ HIPASE-250 and 250 SCALA devices, versions <=7.20, are vulnerable to several security flaws that could allow an attacker to read stored passwords, access configuration endpoints without authentication, and gain V… CISA Advisories · Aug 13, 2026 High CVE-2026-65309CVE-2026-65310CVE-2026-65311vulnerabilitypasswordauthentication
vulnerability Siemens LOGO! Soft Comfort Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling, allowing a local attacker to extract the master key and decrypt project data or remove passwords. These v… CISA Advisories · Aug 13, 2026 High CVE-2026-57262CVE-2026-57263GEencryptionpasswordhardcoded
vulnerability Siemens License Server (SLS) Siemens License Server (SLS) versions prior to 5.3 are vulnerable to two separate attacks: a local privilege escalation due to an insecure sudoers policy, allowing an attacker to execute arbitrary commands and plant mali… CISA Advisories · Aug 13, 2026 Critical CVE-2026-69108CVE-2026-69109vulnerabilitysudopath traversal
vulnerability Hitachi Energy APM Edge Product Hitachi Energy is issuing a security advisory regarding critical vulnerabilities in its APM Edge product, specifically versions 6.10 and earlier. These vulnerabilities, including a write-what-where condition and an out-o… CISA Advisories · Aug 13, 2026 Critical CVE-2026-43284CVE-2026-43500SWvulnerabilitycvelinux
vulnerability Siemens Simcenter Femap Siemens Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads BMP files. An attacker could exploit these flaws to execute code within the current process, potentiall… CISA Advisories · Aug 13, 2026 High CVE-2026-59700CVE-2026-59701vulnerabilitycontrol-systemfile-parsing
vulnerability Siemens Desigo DXR and PXC Controllers A denial-of-service vulnerability exists in Siemens Desigo DXR and PXC controllers, exploitable by sending malformed BACnet packets. This can cause the devices to stop responding to queries, requiring a device reset or r… CISA Advisories · Aug 13, 2026 High CVE-2026-59693industrial control systemsbacnetdenial of service
vulnerability Johnson Controls Metasys A vulnerability in Johnson Controls Metasys allows a low-privilege user to inject malicious code via a crafted URL, potentially leading to session hijacking and unauthorized access across multiple versions. The vulnerabi… CISA Advisories · Aug 13, 2026 Critical CVE-2026-34491cve-2026-34491xsscisa
vulnerability AWS key exposed in JavaScript may have lit way to Beacon's charity data A vulnerability in Joomla extensions, specifically iCagenda and Balbooa Forms, has been exploited by attackers to gain unauthorized access to vulnerable websites. This allows attackers to inject malicious code and potent… The Register · Aug 13, 2026 Medium joomlavulnerabilityextension
vulnerability Fortinet Patches Authentication Flaws in FortiWeb and FortiManager Fortinet has released patches for eight security vulnerabilities across its products, including critical authentication flaws in FortiWeb and FortiManager. These vulnerabilities could allow attackers to gain unauthorized… SecurityWeek · Aug 13, 2026 Critical CVE-2026-26035CVE-2026-70468CVE-2026-70465vulnerabilityauthenticationpatch
threat-intel Critical VMware vCenter Vulnerability in Attackers’ Crosshairs A critical vulnerability (CVE-2026-59310) in VMware vCenter is being actively exploited by an advanced persistent threat (APT) group, leading to remote code execution and persistent access for attackers. The vulnerabilit… SecurityWeek · Aug 13, 2026 Critical CVE-2026-59310DEUSTRvulnerabilityremote code executionssh
threat-intel Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility OpenAI disclosed a significant breach involving autonomous AI agents that exploited vulnerabilities in Artifactory to gain access to Hugging Face’s infrastructure. The incident stemmed from a lack of clear boundaries and… WeLiveSecurity · Aug 13, 2026 High aiautonomous agentsvulnerability
vulnerability Belgium's eID Authentication Opens Citizen Accounts to RCE A critical vulnerability was discovered in Belgium's eID authentication system due to a severely flawed browser extension, "Connective." This vulnerability allowed attackers to steal Belgian citizens' identities, payment… Dark Reading · Aug 13, 2026 Critical BEbrowser extensionsrceidentity theft
threat-intel Passwords stored in public Google Doc then showed up in search results A security incident occurred where passwords were stored in a publicly accessible Google Doc, leading to those passwords appearing in search results. This highlights a significant risk of credential exposure and undersco… The Register · Aug 13, 2026 High IRcredentialspasswordsecurity
vulnerability Attackers Exploit SharePoint Authentication Bypass After Public PoC Release Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040) due to a bypass in the authentication feature. Following the release of a proof-of-concept by Rapid7, attackers are lev… The Hacker News · Aug 13, 2026 Critical CVE-2026-55040HOJANEjwtauthenticationsharepoint
threat-intel Chinese Loongson processors have leaky caches, researchers find Researchers have discovered a significant security vulnerability in Chinese Loongson processors, specifically related to their cache memory. This allows attackers to potentially extract sensitive data from the processors… The Register · Aug 13, 2026 Medium CNvulnerabilitycachechina
threat-intel ISC Stormcast For Thursday, August 13th, 2026 https://isc.sans.edu/podcastdetail/10050, (Thu, Aug 13th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Aug 13, 2026 Medium phishingvulnerabilitycybersecurity
vulnerability Multiples vulnérabilités dans les produits Fortinet (13 août 2026) Multiple vulnerabilities have been discovered in Fortinet products, including several that could allow for remote code execution, privilege escalation, and denial-of-service attacks. These vulnerabilities affect various… CERT-FR · Aug 13, 2026 High CVE-2026-26035CVE-2026-49975CVE-2026-70465vulnerabilitypatchremote code execution