vulnerability Xiiaozet LK100W The CISA has issued an advisory regarding critical vulnerabilities in the Xiiaozet LK100W device. Exploitation could allow an attacker to gain full control over the device by leveraging authentication bypass and command injection flaws. Users are strongly urged to update to version 2.1.240 to mitigate the risk. CISA Advisories · 3d ago Critical CVE-2026-78037CVE-2026-78239CVE-2026-76943vulnerabilitycommand injectionauthentication bypass
vulnerability Ebyte NA111-M A series of vulnerabilities have been identified in Ebyte NA111-M devices, primarily related to authentication and configuration management. These flaws allow unauthenticated attackers to access sensitive information, mo… CISA Advisories · 3d ago High CVE-2026-73125CVE-2026-76179CVE-2026-75814CHauthenticationconfigurationvulnerability
threat-intel CISA Adds Six Known Exploited Vulnerabilities to Catalog The CISA has expanded its Known Exploited Vulnerabilities (KEV) Catalog with six new vulnerabilities, many of which are actively being exploited. Federal agencies are urged to prioritize patching these vulnerabilities, p… CISA Advisories · 4d ago High CVE-2015-3246CVE-2015-5287CVE-2019-1068vulnerabilitypatchrisk
vulnerability CISA Warns of Exploited Gitea Vulnerability The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a publicly exploited Gitea vulnerability (CVE-2026-60004) that allows remote code execution. Organizations are urged to patch this fl… SecurityWeek · 4d ago Critical CVE-2026-60004CVE-2026-20896vulnerabilitygitcisa
vulnerability PayRange API A critical vulnerability in the PayRange API allows unauthorized access to sensitive device information and potential denial-of-service attacks. The vulnerability stems from a lack of proper authorization on management e… CISA Advisories · 5d ago Critical CVE-2026-18965USCAvulnerabilityicscontrol systems
vulnerability Siemens SIMATIC IoT2050 Advanced A vulnerability in Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed allows unauthenticated remote attackers to create malicious flows and execute arbitrary code on the underlying ser… CISA Advisories · 5d ago Critical CVE-2026-58115vulnerabilityindustrial control systemsnode-red
vulnerability CISA Warns of Exploited Oracle WebLogic Vulnerability The CISA has issued a critical warning to federal agencies about a widely exploited vulnerability in Oracle WebLogic servers (CVE-2026-21962). This flaw allows attackers to execute code remotely without authentication, a… SecurityWeek · 5d ago Critical CVE-2026-21962CNoracleweblogicvulnerability
threat-intel Lawmakers call for investigation into impact of CISA staffing cuts Lawmakers are demanding a Government Accountability Office (GAO) investigation into the impact of significant staffing cuts at the Cybersecurity and Infrastructure Security Agency (CISA). These cuts, totaling nearly one-… The Record · Aug 21, 2026 High cisacybersecuritycritical infrastructure
vulnerability Johnson Controls Simplex Incident Manager A critical vulnerability in Johnson Controls Simplex Incident Manager allows a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading… CISA Advisories · Aug 20, 2026 Critical CVE-2026-27875memory-dumpingcredential theftbuilding automation
vulnerability CISA gives feds 3 days to fix actively exploited Ray RCE bug The Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency advisory to federal agencies, demanding they address a rapidly exploited Remote Code Execution (RCE) vulnerability in Ray Ray, a widely… The Register · Aug 18, 2026 High CVE-2025-62593ray rayrcevulnerability
vulnerability CISA Malcolm Several vulnerabilities in CISA Malcolm allow for denial-of-service attacks and arbitrary code execution. Versions prior to 26.06.1 and 26.07.1 are affected. The vulnerabilities stem from issues related to unbounded file… CISA Advisories · Aug 18, 2026 High CVE-2026-55676CVE-2026-63133CVE-2026-63134vulnerabilitynginxlua
vulnerability Siemens License Server (SLS) Siemens License Server (SLS) versions prior to 5.3 are vulnerable to two separate attacks: a local privilege escalation due to an insecure sudoers policy, allowing an attacker to execute arbitrary commands and plant mali… CISA Advisories · Aug 13, 2026 Critical CVE-2026-69108CVE-2026-69109vulnerabilitysudopath traversal
vulnerability Haiwell IoT Cloud HMI Gateway A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway, version 3.40.1.12. Exploitation could allow an attacker to execute arbitrary OS commands with root privileges, posin… CISA Advisories · Aug 13, 2026 Critical CVE-2026-19188cwe-78iotcommand injection
vulnerability Siemens Simcenter Femap Siemens Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads BMP files. An attacker could exploit these flaws to execute code within the current process, potentiall… CISA Advisories · Aug 13, 2026 High CVE-2026-59700CVE-2026-59701vulnerabilitycontrol-systemfile-parsing
vulnerability Johnson Controls Metasys A vulnerability in Johnson Controls Metasys allows a low-privilege user to inject malicious code via a crafted URL, potentially leading to session hijacking and unauthorized access across multiple versions. The vulnerabi… CISA Advisories · Aug 13, 2026 Critical CVE-2026-34491cve-2026-34491xsscisa
vulnerability ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access A security researcher, Chaotic Eclipse, has released a proof-of-concept (PoC) demonstrating a patch bypass for a Microsoft Defender zero-day vulnerability, dubbed ShieldBreak. This vulnerability, CVE-2026-50656 (RoguePla… The Hacker News · Aug 12, 2026 High CVE-2026-50656CVE-2026-62832CVE-2026-68820zero-daypatch-bypassprivilege escalation
vulnerability CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies to patch a critical vulnerability (CVE-2026-8037) in Progress LoadMaster and related products. This vulnerab… SecurityWeek · Aug 10, 2026 Critical CVE-2026-8037CVE-2026-33691command-injectionremote-code-executionpatch
vulnerability Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts A critical command injection vulnerability in Progress Kemp LoadMaster has been added to CISA's KEV catalog, following reports of widespread exploitation attempts. The vulnerability allows unauthenticated attackers to ex… The Hacker News · Aug 8, 2026 Critical CVE-2026-8037AUCHINcommand injectionload balancerpatching
vulnerability CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild A critical vulnerability (CVE-2026-63077) in JetBrains TeamCity, allowing unauthenticated remote code execution, is currently being actively exploited in the wild. CISA has issued a Binding Operational Directive requirin… The Hacker News · Aug 6, 2026 Critical CVE-2026-63077cveremote code executiondeserialization
vulnerability Acrisure KARR BT and DR-100 A critical vulnerability has been identified in Acrisure KARR BT and DR-100 automotive anti-theft systems, allowing an attacker within Bluetooth range to potentially control vehicle functions, including door unlocking an… CISA Advisories · Aug 4, 2026 Critical CVE-2026-18411USbluetoothfirmwarecwe-321